Blog
RSSFeatured
TIDA Deadline Passed—But AI Video Platforms' Deepfake Compliance Is Just Beginning
From TIDA takedown obligations and FTC disclosure guidelines to South Korea's watermark mandate—three new red lines are turning platform content governance from voluntary best practice into enforceable regulatory obligation.
Privacy Alert | Vietnam’s Personal Data Protection Law (PDPL) Officially Enacted
Vietnam’s Personal Data Protection Law (PDPL), enacted in June 2025 and effective from January 1, 2026, establishes a comprehensive national framework for personal data protection, replacing the 2023 Decree No. 13/2023/NĐ-CP. Applicable to both domestic and foreign entities processing Vietnamese citizens’ or residents’ data, the PDPL introduces strict penalties (up to 10 times illegal proceeds for data trading or 5% of annual revenue for cross-border violations), a narrow “legitimate rights and interests” processing basis, and exemptions for micro-enterprises. It mandates explicit consent, data processing and transfer impact assessments (DPIA and TIA), and robust data subject rights, including access, correction, and deletion. Enterprises must implement consent mechanisms, data security measures, and compliance with data localization under the Cybersecurity Law, with specific rules for sensitive data like children’s or health information, and a 72-hour breach reporting requirement.
Avoiding GDPR Cookie Policy Violations: A Guide for Enterprises
The Mirror’s cookie banner, which charges £1.99/month to reject non-essential cookies, violates GDPR’s requirement for freely given consent, risking fines and reputational damage. GDPR mandates transparent, opt-in cookie policies with easy withdrawal, and tools like Kaamel’s Risk Management solution help enterprises ensure compliance through automated audits and developer-friendly workflows. Enterprises must prioritize user-friendly consent mechanisms to avoid legal and trust issues.
Latest
View all articles →
Australia Releases Draft Digital Duty of Care
Australia’s draft digital duty of care covers product design, child protection, recommendation choices and ongoing risk assessments. We explain the proposed requirements.
Indonesia’s PDPL Implementing Regulation: Key GDPR Differences
How Indonesia’s PP 33/2026 and PDPL differ from the GDPR on contracts, individual rights, processing records, breach notices and international transfers.
Ofcom Fines Xgroovy £730,000 for Age-Check and Information Failures
Ofcom has fined Xgroovy for age assurance and information request failures. The case raises questions about age-check implementation and investigation duties.
ChatGPT Is Now a VLOSE Under the DSA: What Changes?
The European Commission has designated ChatGPT as a very large online search engine. We explain the DSA threshold and six additional duties that follow.
Brazil Fines TikTok Over Minors’ Data Processing
Brazil’s ANPD fined ByteDance BRL 153.7 million over TikTok’s handling of minors’ data, citing weak legal bases, age controls, and safeguard evidence.
Uber Fined Nearly €825 Million Over Automated Driver Deactivations
Dutch regulator fines Uber nearly €825 million over automated driver deactivations. We examine the facts, legal grounds and effective human review.
Laws & Guides
16
California DROP Starts August 1 with Ongoing Deletion Duties
California data brokers must process DROP requests from August 1, 2026. The rules cover 45-day cycles, ongoing deletion, matching, and vendor instructions.
FTC Enforces New "Click to Cancel" Rule for Subscription Cancellations
The FTC's new “Click to Cancel” rule mandates businesses to simplify subscription cancellations, making them as straightforward as the sign-up process.
EU Releases FAQ on Data Act Clarifying IoT Data Sharing and Relationship with GDPR
On September 6, the EU published a FAQ on the Data Act, explaining its relationship with the GDPR and addressing issues related to IoT data access and business-to-business data sharing.
Enforcement & Fines
21
FTC Sues Hims & Hers Over Health Data Sharing
The FTC alleges that Hims & Hers shared sensitive health information with ad platforms despite its privacy claims and without clear disclosure.
Privacy Bulletin: SHEIN SMS Violates Do-Not-Call Directive, Faces Class Action Lawsuit
On July 12, 2025, a class action lawsuit was filed against SHEIN for allegedly violating the Telephone Consumer Protection Act (TCPA) by sending marketing text messages to numbers listed on the National Do-Not-Call Registry without prior consent. The plaintiff, whose number was registered in April 2025, continued receiving promotional texts in June, well past the required 31-day buffer. The case emphasizes that TCPA rules apply not only to calls but also to automated SMS marketing, requiring companies to prove consent, honor opt-outs, and now comply within 10 business days following an FCC order in April 2025. This lawsuit highlights stricter enforcement of consumer privacy protections against unsolicited marketing communications.
South Korea Fines Meta for Violating Personal Data Laws
South Korea's Personal Information Protection Commission fined Meta 21.6232 billion KRW for improperly collecting and processing sensitive user information, denying access requests, and causing a data leak. The Commission ordered Meta to implement stronger data protections and ensure lawful handling of sensitive data.
AI Regulation
10
When Does Public Audio Training Become Voiceprint Collection?
Google’s motion to dismiss puts a core BIPA question in focus: when does using public audio to train an AI model amount to collecting a voiceprint?
EU AI Content Transparency Code: What Claude's Plan Shows
Anthropic has detailed Claude's text watermarking and C2PA metadata. We compare the plan with the EU code's marking and detection requirements.
EU AI Act Article 50: Product Changes to Make
Article 50 of the EU AI Act applies from 2 August 2026. See how providers and deployers should adapt AI products for five transparency duties.
Security
1Cookies & Consent
6
Cookie Consent : Effective or Deceptive?
This study looked at the cookie consent practices of 64 Fortune 500 companies that directly engage with European customers. By simulating customers interacting with the website, the research scrutinizes how these global companies adhere to regulation. A staggering 70% of the evaluated websites do not comply with GDPR cookie consent requirements, indicating a substantial gap in adherence to privacy laws among even the biggest companies.
4 Common cookie banner designs are NOT-OK by GDPR authorities
Recently, NOYB has filed numerous complaints against companies using questionable consent banners. This report categorizes and critiques eight types of cookie banner designs prevalent in non-compliant practices
EDPB Issues Guidelines on 'Consent or Pay' Models
The European Data Protection Board (EDPB) has issued guidelines on 'Consent or Pay' models operated by large online platforms for behavioral advertising.
Cross-border Data
5
DOJ Issues Proposed Rule to Restrict Foreign Access to Americans' Sensitive Data
The U.S. Department of Justice has issued a proposed rule to restrict data access by specific foreign countries, following an executive order by President Biden.
Brazil's ANPD Approves New International Data Transfer Regulation and SCCs
On August 23, Brazil's National Data Protection Authority (ANPD) approved new regulations on international data transfers, including the adoption of Standard Contractual Clauses (SCCs) as a legal mechanism. These regulations require companies to ensure compliance with Brazil's LGPD and implement transparency measures for cross-border data transfers.
South Korea’s FSS Investigates Kakao Pay for Unauthorized Data Transfers to Alipay
The Financial Supervisory Service (FSS) of South Korea has found that Kakao Pay transmitted user data to Alipay in China without consent, potentially violating the Credit Information Use and Protection Act. Kakao Pay faces possible sanctions and significant penalties as the investigation continues.
Compliance
1Biometrics
3
Illinois Amends BIPA to Limit Liability and Introduce Electronic Signatures
On August 2, Illinois amended the Biometric Information Privacy Act (BIPA), reducing the number of violations counted for repeated biometric data collection from the same individual and allowing electronic signatures as a method for obtaining consent. This amendment significantly lowers potential damages in BIPA lawsuits and offers businesses more flexibility in compliance.
Meta's Landmark $1.4 Billion Biometric Data Lawsuit Settlement with Texas
Summary In February 2022, Texas Attorney General Ken Paxton sued Meta formerly known as Facebook , alleging that Meta unlawfully captured the biometric identifi
Zellmer vs. Facebook: A Unique Privacy Lawsuit Under Illinois BIPA
Zellmer sued Facebook (now Meta) under the Illinois Biometric Information Privacy Act (BIPA) for privacy violations, similar to the "In re Facebook Biometric Information Privacy Litigation" case, which resulted in a $650 million settlement.
Children's Privacy
7
FTC Sues TikTok and ByteDance for COPPA Violations and Breach of Settlement Agreement
The U.S. Federal Trade Commission (FTC) has filed a lawsuit against TikTok and its parent company ByteDance, accusing them of violating the Children’s Online Privacy Protection Act (COPPA) and a 2019 settlement agreement. The lawsuit alleges that TikTok failed to delete underage users' personal data, improperly collected data from minors without parental consent, and created obstacles for parents attempting to delete their children's data.
US Passes Landmark Legislation to Strengthen Child Online Privacy Protections
On July 30, the US passed two significant laws, the Kids Online Safety Act (KOSA) and Children and Teens' Online Privacy Protection Act (COPPA 2.0), marking a major shift in regulatory strategies for protecting children's online privacy.
California Takes Legal Action Against Tilting Point for Child Privacy Violations
California sues Tilting Point for violating child privacy laws with its game SpongeBob: Krusty Cook-Off, resulting in a $500,000 settlement and required compliance measures.
