惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
博客园_首页
博客园 - 三生石上(FineUI控件)
V
Visual Studio Blog
Hugging Face - Blog
Hugging Face - Blog
美团技术团队
小众软件
小众软件
T
Tailwind CSS Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
月光博客
月光博客
有赞技术团队
有赞技术团队
WordPress大学
WordPress大学
博客园 - 【当耐特】
Apple Machine Learning Research
Apple Machine Learning Research
罗磊的独立博客
V
V2EX
酷 壳 – CoolShell
酷 壳 – CoolShell
IT之家
IT之家
量子位
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Recent Announcements
Recent Announcements
M
MIT News - Artificial intelligence
阮一峰的网络日志
阮一峰的网络日志
The GitHub Blog
The GitHub Blog

Compliance Solutions for Websites, Apps and Organizations | iubenda

AI can build your website. It can't manage your consent. | iubenda Browser signals and machine-readable consent: what they are and what the EU’s Digital Omnibus could change California Consumer Privacy Act (CCPA): Complete Guide How to increase your cookie banner opt-in rates: 5 mistakes to fix today | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #153) Why your consent management setup is a marketing performance question Everything you need to know about GDPR The redesigned cookie banner and configurator What nobody tells you about handing over the company you built European marketers are betting on retention. Privacy could be the edge they’re not using yet. The 5 best alternatives to Didomi in 2026: Pros, cons, pricing, and comparison Looking back on 15 years: what iubenda's founder would tell his 2011 self | iubenda The best cookie policy generator in 2026 DPO Newsletter: Global Data Protection & Privacy News (issue #152) | iubenda What publishers should expect from the EU’s Digital Omnibus proposal Uncertainty is the biggest blocker to AI adoption in marketing | iubenda Everything AI app builders need to know about vibecoding and privacy compliance | iubenda Introducing 1-Click Embedding for Google Tag Manager The Essential Small Business Terms and Conditions Template: What You Need to Know Terms of Use Template | iubenda IAB Europe Raises Concerns Over GDPR Procedural Regulation Draft Report | iubenda Learn from HelloFresh's Costly Mistake: Ensure Compliance with iubenda | iubenda Understanding the Spanish DPA Guide on Audience Measurement Cookies | iubenda The Austrian Data Protection Authority's FAQs on Cookies and Privacy | iubenda DPO Newsletter: Global Data Protection & Privacy News (issue #127) | iubenda Microsoft Ensuring European Data Stays Within the EU Cloud Boundary | iubenda Businesses Beware: ICO’s Record £14.3m in Fines for Data Misuse in 2023 Understanding the Risks and Responsibilities of Model-as-a-Service Companies in AI Development Facebook's New “Link History” Feature: A Blend of Convenience and Surveillance? | iubenda OpenAI’s Strategic Move in the EU: Aligning with Data Privacy Regulations
DPO Newsletter: Data Protection & Privacy News (issue #10...
Aert Hulsebos · 2023-04-20 · via Compliance Solutions for Websites, Apps and Organizations | iubenda
DPO Newsletter: Global Data Protection & Privacy News

We’ve compiled the latest in Data Protection and Privacy news for your convenience below.

1) Newly Published Documentation

  • The EU-U.S. Data Privacy Framework and Swiss-U.S. Data Privacy Framework are under stakeholder consultation, despite MEPs’ opposition to the draft EU-US DPF adequacy decision. EU MEPs have indicated that the “proposed framework is an improvement, but not enough to justify an adequacy decision on personal data transfers” at this stage. Read here →
  • The Irish Data Protection Authority (DPA) will be making a final decision on Meta Platforms Ireland Limited (Meta IE) based on the legal assessment and binding decision adopted by the European Data Protection Board (EDPB) under Article 65 GDPR. Access here →
  • The Garante has set a deadline of April 30, 2023, for OpenAI, the owner of ChatGPT, to comply with regulations to lift the temporary ban on Italian users. OpenAI must provide transparent information on ChatGPT’s operations on its website, remove contractual performance references, process data based on consent or legitimate interest, and more. Reported here, on iubenda →
  • The Garante’s recent enforcement action, imposed against Open AI in relation to ChatGPT, has led the EDPB to launch “a dedicated task force to foster cooperation and to exchange information on possible enforcement actions conducted by data protection authorities.Read here →
  • The Irish Data Protection Commission has published four guides aimed at assisting parents with their children’s data protection rights under the GDPR. These guides form part of the Commission’s 2022-2027 Regulatory Strategy.
  • IAB Australia has published its response to the Australian Attorney General Department’s Privacy Act Review Report 2022, and while welcoming most of the Report, it has raised “concerns that the proposals set forth in the Report could severely restrict digital advertising and online publishers’ and platforms’ ability to provide free content and services to consumers.Access the report here →

2) Notable Case Law

  • The Italian Data Protection Authority (Garante) has fined the digital marketing company Ediscom SpA 300,000 euros for using dark patterns to obtain users’ consent for data processing and communication with third parties. Ediscom was unable to adequately show that it had obtained consent to send promotional messages. Read about the decision here → (in Italian)
  • The Spanish Agencia Española de Protección de Datos (AEPD) has initiated an investigation into ChatGPT’s owner, OpenAI, for a possible breach of data protection regulations. The AEPD requested the EDPB to discuss ChatGPT at its upcoming plenary meeting. Reported here, on iubenda →
  • The Office of the Information and Privacy Commissioner of Alberta, Canada (OIPC) published an Order P2023-01, concerning corrective measures on Acuren Group Inc. pursuant to the Personal Information Protection Act, SA 2003 (PIPA), following a request for inquiry. Access here →

3) New and Upcoming Legislation

  • The Data Protection and Digital Information (No. 2) Bill was read for the second time this week in the U.K.’s Parliament, and the legislative process will run until the end of 2023. The Bill brings a number of changes to the current regulatory regime under the U.K. General Data Protection Regulation. Reported here →
  • The UK ICO has published a response to the Government’s AI white paper. The ICO emphasized the importance of reducing additional complexity for businesses, therefore welcoming close collaboration with the Government. Read the response here →
  • US Law Updates
    • Indiana: Senate Bill 5 on consumer data protection has been approved by Senate with amendments.
    • Arkansas: Senate Bill 396 on social media safety was signed by the Governor and comes into effect on September 1, 2023 and Senate Bill 66 on the protection of minors was sent to the Governor for signing.
    • California: Senate Bill 362 on data brokers was introduced to Senate.
    • Maine: Senate Bill 1629 proposing introduction of right to privacy in the Constitution of Maine introduced to Legislature.
    • Tennessee: House Bill 1181 concerning the Information Protection Act was passed on First Consideration in Senate and House Bill 1310 on genetic information privacy was passed by House and Senate.
    • Oregon: Senate Bill 619 on consumer data protection was recommended for passage with amendments.
    • New York: Assembly Bill 6319 establishing consumers’ foundational data privacy rights was introduced to the State Assembly.
  • The Government of Guyana to introduce the draft Data Protection Bill 2023 to the National Assembly. This will be followed by public consultation with national stakeholders, who can provide their recommendations to the draft bill.

4) Strong Impact Tech

  • The first state-wide TikTok ban was approved in the unprecedented Senate Bill 419 by the Montana House of Representatives. The state ban is still pending the Governor’s signature, and if signed, will follow suit of the previous ban on government-issued devices and state universities. Read about this on our blog →
  • Brightline, Inc. has been reported by the Maine Attorney General to have experienced a data breach that compromised the personal information of about 27,742 people. The Attorney General clarified that the breach took place at one of Brightline’s vendors and involved personal data such as names and other identifying information, along with social security numbers. Reported here →

Other key information from the past weeks

  • The UK’s ICO has fined TikTok £12.7M for the unlawful use of children’s data, in particular children under the age of thirteen years, which held an account contrary to the terms of service.
  • The UK’s National Cyber Security Centre (NCSC) and the Information Commissioner’s Office (ICO) have addressed several cyber risk concerns emanating from large language models such as ChatGPT.
  • The Swiss Federal Data Protection and Information Commission (FDIPC) has issued a statement concerning the use of ChatGPT and AI-supported apps.

About us

iubenda

Attorney-level solutions to make your websites and apps compliant with the law across multiple countries and legislations.

www.iubenda.com