
We’ve compiled the latest in Data Protection and Privacy news for your convenience below.
1) Newly Published Documentation
π©πͺ Germany β BfDI Updates GDPR and BDSG Guidance Brochure
The Federal Commissioner for Data Protection updated comprehensive guidance (in German) covering GDPR-BDSG relationships, lawful processing bases, data protection principles, DPO requirements, and data subject rights with practical implementation examples.
π±πΊ Luxembourg β CNPD Publishes AI Literacy Guidance Under EU AI Act
The authority provided a framework for Article 4 AI literacy requirements, emphasizing tailored employee training based on experience levels, risk assessment for AI-affected individuals, and development of appropriate oversight mechanisms.
π³π΄ Norway β NSM Releases National Cyber Incident Response Framework
The National Security Authority established a collaborative approach between businesses and National Cyber Security Center (in Norwegian), requiring compliance with ICT security principles, third-party supplier reviews, and systematic incident handling processes.
π¨π¦ Canada β OPC Launches Children’s Privacy Code Consultation
Privacy Commissioner initiated stakeholder consultation to clarify PIPEDA obligations for children’s data until August 19, 2025. The consultation covers privacy by default and privacy rights, transparency requirements and deceptive practice avoidance.
2) Notable Case Law
πΊπΈ USA β FTC Fines Companies $145 Million for Telemarketing Violations
Assurance IQ fined $100 million and MediaAlpha $45 million for deceptive healthcare plan marketing. In addition, MediaAlpha also carried out unauthorized robocalls to Do Not Call Registry numbers, and misled consumers about coverage benefits.
3) New and Upcoming Legislation
π¬π· Greece β ADAE Issues Electronic Communications Privacy Regulations
Decision 304/2025 requires providers to establish security policies, conduct risk assessments, implement incident reporting procedures to ADAE, and maintain employee training and encryption standards for network protection (in Greek).
πΊπΈ USA (Federal) β Senate Introduces Trustworthy AI Validation Act
Legislation mandates NIST Director develop voluntary AI assurance guidelines within one year, addressing harm mitigation, consumer privacy, governance controls, and dataset quality with biennial reviews.
4) Strong Impact Tech
πΊπΈ USA β State Attorneys General Challenge Instagram Location-Sharing Feature
Multiple AGs expressed concerns about Meta’s Instagram location feature risks to vulnerable populations, recommending minor access restrictions, adult user risk alerts, and simplified disable controls for enhanced safety.
π¬π§ United Kingdom β Law Commission Examines AI Legal Personality Framework
Discussion paper explores AI autonomy, adaptiveness, and potential legal personality grants, emphasizing need for legal evolution amid rapid AI advancement while considering implications of non-personality scenarios.
Other key information from the past weeks
π«π·π³π± France/Netherlands β Air France and KLM Third-Party Data Breach
Forbes reported that a breach in a third-party customer support tool exposed passenger names, contact details, and loyalty numbers, linked to a phishing campaign targeting Salesforce platforms. Authorities have been notified.
π¨π Switzerland β PostFinance Voice Recognition Violation
The Swiss Federal Data Protection and Information Commissioner (FDPIC) ruled against PostFinance AG for unlawful biometric voice recognition collection in violation of proportionality principles. The bank used opt-out rather than express consent and was ordered to obtain proper consent and delete existing voiceprints. However, it has appealed the FDPICβs decision to the Federal Administrative Court.
πΊπΈ USA β GameStop Settles Facebook Data Sharing Case for $4.5 Million
Settlement covers unauthorized customer data sharing via Facebook tracking pixels between August 2020-April 2025 without proper consent. Claims deadline was August 15, 2025.
π Enjoyed this issue? Share it on LinkedIn and subscribe for weekly updates
Browse archive
- Issue #146
- Issue #145
- Issue #144
- Issue #143
- Issue #142
- Issue #141
- Issue #140
- Issue #139
- Issue #138
- Issue #137
- Issue #136
- Issue #135
- Issue #134
- Issue #133
- Issue #132
- Issue #131
- Issue #130
- Issue #129
- Issue #128
- Issue #127
- Issue #126
- Issue #125
- Issue #124
- Issue #123
- Issue #122
- Issue #121
- Issue #120
- Issue #119
- Issue #118
- Issue #117
- Issue #116
- Issue #115
- Issue #114
- Issue #113
- Issue #112
- Issue #111
- Issue #110
- Issue #109
- Issue #108
- Issue #107
- Issue #106
- Issue #105
- Issue #104
- Issue #103
- Issue #102
- Issue #101
- Issue #100
- Issue #99
- Issue #98
- Issue #97
- Issue #96
- Issue #95
- Issue #94
- Issue #93
- Issue #92
- Issue #91
- Issue #90
- Issue #89
- Issue #88
- Issue #87
- Issue #86
- Issue #85
- Issue #84
- Issue #83
- Issue #82
- Issue #81
- Issue #80
- Issue #79
- Issue #78
- Issue #77
- Issue #76
- Issue #75
- Issue #74
- Issue #73
- Issue #72
- Issue #71
- Issue #70
- Issue #69
- Issue #68
- Issue #67
- Issue #66
- Issue #65
- Issue #64
- Issue #63
- Issue #62
- Issue #61
- Issue #60
- Issue #59
- Issue #58
- Issue #57
- Issue #56
- Issue #55
- Issue #54
- Issue #53
- Issue #52
- Issue #51
- Issue #50
- Issue #49
- Issue #48
- Issue #47
- Issue #46
- Issue #45
- Issue #44
- Issue #43
- Issue #42
- Issue #41
- Issue #40
- Issue #39
- Issue #38
- Issue #37
- Issue #36
- Issue #35
- Issue #34
- Issue #33
- Issue #32
- Issue #31
- Issue #30
- Issue #29
- Issue #28
- Issue #27
- Issue #26
- Issue #25
- Issue #24
- Issue #23
- Issue #22
- Issue #21
- Issue #20
- Issue #19
- Issue #18
- Issue #17
- Issue #16
- Issue #15
- Issue #14
- Issue #13
- Issue #12
- Issue #11
- Issue #10
- Issue #9
- Issue #8
- Issue #7
- Issue #6
- Issue #5
- Issue #4
- Issue #3
- Issue #2
- Issue #1
About us
Attorney-level solutions to make your websites and apps compliant with the law across multiple countries and legislations.