The European Data Protection Board has made checking organizations’ compliance with the GDPR’s transparency requirements a key area of focus for the coming year under its Coordinated Enforcement Framework.
Data Privacy
Virginia bans sale of personal location data
Businesses operating in Virginia are barred from selling consumers’ precise location data, under legislation signed into law Tuesday by Gov. Abigail Spanberger.
Navigating APAC data privacy laws: A compliance roadmap
Fragmented regulations across the APAC region are forcing compliance teams to rethink strategies that worked under GDPR.
Disney pays $2.75M to California for alleged privacy violations
Disney has agreed to pay $2.75 million to settle allegations by California that its streaming service sold the personal information of subscribers without their permission.
FTC warns brokers to stop selling U.S. military member data to foreign adversaries
Thirteen data brokers have been warned by the Federal Trade Commission to come into compliance with a 2024 law prohibiting the selling of the personal data of U.S. residents to foreign adversaries.
FTC puts GM’s puts connected vehicle data practices under compliance spotlight
The U.S. Federal Trade Commission finalized its order against General Motors and its OnStar subsidiary over the improper usage of geolocation and driving behavior data of drivers.
Safely leveraging generative AI: A practical guide for compliance leaders
Generative AI (GenAI) has moved rapidly from experimentation into day-to-day use across many organizations. Over the past year, teams have shifted from exploratory pilots to relying on these tools for core activities such as contract analysis, research, and software development.
EU moves to simplify GDPR and AI Act obligations, raising compliance questions for companies
For the past decade, Europe has led in creating strong but flexible rules for data use and safe AI development. The EU’s new plans to simplify key data privacy and AI governance measures have received a mixed response.
U.K. data regulator pushes transparency on investigations while businesses seek clarity on compliance
Plans to increase transparency around how the U.K.’s Information Commissioner investigates and fines companies should give businesses more clarity, but experts say the regulator still needs to explain how it will prioritize cases.
Company agrees to report to FTC for 10 years after breach of 10 million student records
A tech company that stores student information for schools has agreed to implement a data security program and report to the Federal Trade Commission for 10 years, after security failures led to data for 10 million students being breached.


