Blog

RSS

Featured

AI Regulation

TIDA Deadline Passed—But AI Video Platforms' Deepfake Compliance Is Just Beginning

From TIDA takedown obligations and FTC disclosure guidelines to South Korea's watermark mandate—three new red lines are turning platform content governance from voluntary best practice into enforceable regulatory obligation.

·5 min
Laws & Guides

Privacy Alert | Vietnam’s Personal Data Protection Law (PDPL) Officially Enacted

Vietnam’s Personal Data Protection Law (PDPL), enacted in June 2025 and effective from January 1, 2026, establishes a comprehensive national framework for personal data protection, replacing the 2023 Decree No. 13/2023/NĐ-CP. Applicable to both domestic and foreign entities processing Vietnamese citizens’ or residents’ data, the PDPL introduces strict penalties (up to 10 times illegal proceeds for data trading or 5% of annual revenue for cross-border violations), a narrow “legitimate rights and interests” processing basis, and exemptions for micro-enterprises. It mandates explicit consent, data processing and transfer impact assessments (DPIA and TIA), and robust data subject rights, including access, correction, and deletion. Enterprises must implement consent mechanisms, data security measures, and compliance with data localization under the Cybersecurity Law, with specific rules for sensitive data like children’s or health information, and a 72-hour breach reporting requirement.

·6 min
Cookies & Consent

Avoiding GDPR Cookie Policy Violations: A Guide for Enterprises

The Mirror’s cookie banner, which charges £1.99/month to reject non-essential cookies, violates GDPR’s requirement for freely given consent, risking fines and reputational damage. GDPR mandates transparent, opt-in cookie policies with easy withdrawal, and tools like Kaamel’s Risk Management solution help enterprises ensure compliance through automated audits and developer-friendly workflows. Enterprises must prioritize user-friendly consent mechanisms to avoid legal and trust issues.

·5 min
More

Australia Releases Draft Digital Duty of Care

Australia’s draft digital duty of care covers product design, child protection, recommendation choices and ongoing risk assessments. We explain the proposed requirements.

·9 min
Laws & Guides

Indonesia’s PDPL Implementing Regulation: Key GDPR Differences

How Indonesia’s PP 33/2026 and PDPL differ from the GDPR on contracts, individual rights, processing records, breach notices and international transfers.

·10 min
Enforcement & Fines

Ofcom Fines Xgroovy £730,000 for Age-Check and Information Failures

Ofcom has fined Xgroovy for age assurance and information request failures. The case raises questions about age-check implementation and investigation duties.

·6 min
Laws & Guides

ChatGPT Is Now a VLOSE Under the DSA: What Changes?

The European Commission has designated ChatGPT as a very large online search engine. We explain the DSA threshold and six additional duties that follow.

·5 min
Enforcement & Fines

Brazil Fines TikTok Over Minors’ Data Processing

Brazil’s ANPD fined ByteDance BRL 153.7 million over TikTok’s handling of minors’ data, citing weak legal bases, age controls, and safeguard evidence.

·10 min
Enforcement & Fines

Uber Fined Nearly €825 Million Over Automated Driver Deactivations

Dutch regulator fines Uber nearly €825 million over automated driver deactivations. We examine the facts, legal grounds and effective human review.

·7 min

Laws & Guides

16
View all →

Enforcement & Fines

21
View all →
Enforcement & Fines

FTC Sues Hims & Hers Over Health Data Sharing

The FTC alleges that Hims & Hers shared sensitive health information with ad platforms despite its privacy claims and without clear disclosure.

·10 min
Enforcement & Fines

Privacy Bulletin: SHEIN SMS Violates Do-Not-Call Directive, Faces Class Action Lawsuit

On July 12, 2025, a class action lawsuit was filed against SHEIN for allegedly violating the Telephone Consumer Protection Act (TCPA) by sending marketing text messages to numbers listed on the National Do-Not-Call Registry without prior consent. The plaintiff, whose number was registered in April 2025, continued receiving promotional texts in June, well past the required 31-day buffer. The case emphasizes that TCPA rules apply not only to calls but also to automated SMS marketing, requiring companies to prove consent, honor opt-outs, and now comply within 10 business days following an FCC order in April 2025. This lawsuit highlights stricter enforcement of consumer privacy protections against unsolicited marketing communications.

·2 min
Enforcement & Fines

South Korea Fines Meta for Violating Personal Data Laws

South Korea's Personal Information Protection Commission fined Meta 21.6232 billion KRW for improperly collecting and processing sensitive user information, denying access requests, and causing a data leak. The Commission ordered Meta to implement stronger data protections and ensure lawful handling of sensitive data.

·3 min

AI Regulation

10
View all →

Security

1

Cookies & Consent

6
View all →

Cross-border Data

5
View all →

Compliance

1

Biometrics

3

Children's Privacy

7
View all →

Start your compliance journey

Talk to the security and privacy veterans at Kaamel

Kaamel
info@kaamel.com
340 E Middlefield Rd, Mountain View, CA 94043
AICPA Drata
© 2026 Kaamel Inc. All rights reserved.