CNIL extends AI consultations
France's data protection authority, the Commission nationale de l'informatique et des libertés, extended two consultations on AI and data protection to 1 Oct.
France's data protection authority, the Commission nationale de l'informatique et des libertés, extended two consultations on AI and data protection to 1 Oct.
The Saudi Data and Artificial Intelligence Authority published nonbinding guidance to help entities create their own privacy notices under Saudi Arabia's Personal Data Protection Law. The law requires data controllers to inform users of the privacy law and subsequent data rights prior to collecting any data.Full story
The Washington Post reports the California State Assembly passed Senate Bill 1047, an artificial intelligence safety proposal that would require companies to conduct risk assessments before launching AI technology. DeepLearning.AI founder Andrew Ng said the proposed bill "makes a fundamental mistake of regulating AI technology instead of AI applications." The bill still requires Senate concurrence and governor approval before enactment.
The Office of the Privacy Commissioner of Canada and the U.S. Federal Communications Commission signed a memorandum of understanding to improve enforcement of shared telecommunications privacy matters. The regulators will exchange information to "share knowledge and expertise on regulatory policies and technical efforts."Full story
Latvia's Data State Inspectorate discussed the need for contracts as a legal basis for processing under the EU General Data Protection Regulation and the instances in which such processing is necessary. It noted processing data for commercial purposes not related to the contract should be considered inappropriate.Full story
The European Commission announced the launch of a new agreement with China, facilitating discussion on cross-border transfers of nonpersonal data. The Cross-Border Data Flow Communication Mechanism allows the Commission and China's government to hold dialogue toward "practical solutions" for EU businesses facing transfer issues related to compliance with Chinese data laws.Full story
The Saudi Data and Artificial Intelligence Authority published rules for appointing an organizational data protection officer under the Personal Data Protection Law. The document outlines the legal requirements for appointing a DPO, clarifies when a DPO should be appointed and defines a DPO's role. Full story
The California Senate passed Assembly Bill 3048, which requires web browser developers to offer an opt-out tool for behavioral advertising, MediaPost reports. If approved, the bill would bar companies from maintaining browsers without opt-out mechanisms that are "easy for a reasonable person to locate and configure," per the legislation's text. It now returns to the state assembly for final approval.
Twenty-two U.S. state attorneys general sent a letter to the president of China-based online retailer Temu seeking information about its U.S. consumer data collection and sharing practices.
Join IAPP Managing Director, Europe, Isabelle Roccia, CIPP/E, 3 Sept. for a web conference examining the European Health Data Space. Novartis International Head Data Privacy for Europe Alexandre Entraygues and Covington & Burling Of Counsel Kristof Van Quathem will join Roccia to share insights on the key features of the EHDS, including material scope, obligations and enforcement mechanisms.Full story