Fragmented regulations across the APAC region are forcing compliance teams to rethink strategies that worked under GDPR.
Data Privacy
Disney pays $2.75M to California for alleged privacy violations
Disney has agreed to pay $2.75 million to settle allegations by California that its streaming service sold the personal information of subscribers without their permission.
FTC warns brokers to stop selling U.S. military member data to foreign adversaries
Thirteen data brokers have been warned by the Federal Trade Commission to come into compliance with a 2024 law prohibiting the selling of the personal data of U.S. residents to foreign adversaries.
FTC puts GM’s puts connected vehicle data practices under compliance spotlight
The U.S. Federal Trade Commission finalized its order against General Motors and its OnStar subsidiary over the improper usage of geolocation and driving behavior data of drivers.
EU moves to simplify GDPR and AI Act obligations, raising compliance questions for companies
For the past decade, Europe has led in creating strong but flexible rules for data use and safe AI development. The EU’s new plans to simplify key data privacy and AI governance measures have received a mixed response.
U.K. data regulator pushes transparency on investigations while businesses seek clarity on compliance
Plans to increase transparency around how the U.K.’s Information Commissioner investigates and fines companies should give businesses more clarity, but experts say the regulator still needs to explain how it will prioritize cases.
Company agrees to report to FTC for 10 years after breach of 10 million student records
A tech company that stores student information for schools has agreed to implement a data security program and report to the Federal Trade Commission for 10 years, after security failures led to data for 10 million students being breached.
California wants whistleblower program to uncover privacy law violations within companies
A California privacy agency plans to seek a whistleblower law, to encourage corporate employees and others to step forward with complaints about egregious privacy violations at their workplaces.
Complying with the EU Data Act – What companies should know
Companies could face significant compliance challenges in trying to meet new EU legal requirements about how companies share data with third parties.
New EU Data Act may impact companies’ GDPR compliance efforts
New rules that have recently come into effect across the EU will allow for greater transfers of data between companies, though experts fear the changes could conflict with Europe’s strict privacy legislation, which protects personal information.
