Securiti leads GigaOm's DSPM Vendor Evaluation with top ratings across technical capabilities & business value.

View

Privacy Regulation Roundup: Top Stories of April 2024

Contributors

Anas Baig

Product Marketing Manager at Securiti

Omer Imran Malik

Data Privacy Legal Manager, Securiti

FIP, CIPT, CIPM, CIPP/US

Securiti has started a Privacy Regulation Roundup that summarizes the latest major global privacy regulatory developments, announcements, and changes. These developments will be added to our website monthly. For each relevant regulatory activity, you can find a link to related resources at the bottom.

Asia Jurisdiction

1. Philippines' National Privacy Commission Issues New Circulars

Date: 1st April, 2024
Summary: The National Privacy Commission (NPC) issued two separate circulars related to the protection of personal data in the Philippines. The first, NPC Circular 2023-05, provides useful information for subject organizations and certification bodies (CBs) in the Philippine Privacy Mark (PPM) Certification Program, such as the requirement for information controllers (PICs) or processors (PIPs) to attain ISO/IEC 27001 and ISO/IEC 27701 certifications. Similarly, CBs must meet ISO/IEC 17021-1 standards for accreditation. The second, NPC Circular 2023-06, necessitates updated security standards for all personal data being handled in the public and private sectors. These standards are related to obligations such as the appointment of a data protection officer, regular privacy impact assessments, and privacy management programs. Other provisions include storage protocols, access controls, and the deployment of a reliable Business Continuity Plan to counter any issues arising from disruptions. Read more.

2. Singaporean Cybersecurity Bill Read For The First Time

Date: 4th April, 2024
Summary: The Cybersecurity Amendment Bill was read for the first time in Singapore. The bill proposes several amendments to the Cybersecurity Act of 2018, which include requirements for foundational digital infrastructure services providers to uphold cybersecurity standards, reporting of cybersecurity incidents to the Cyber Security Agency of Singapore (CSA), requirements for Critical Information Infrastructure (CII) owners to maintain responsibility for cybersecurity and cyber resilience, the introduction of two new regulated entity classes, i.e., Entities of Special Cybersecurity Interest (ESCI) & Foundational Digital Infrastructure (FDI), and oversight expansion to cover Systems of Temporary Cybersecurity Concern (STCCs). Read more.

3. Office Of The Privacy Commissioner Of New Zealand Announces New Draft Rules

Date: 11th April, 2024
Summary: The Office of the Privacy Commissioner of New Zealand (OPC) has announced new draft rules related to the use of biometric technologies. These draft rules have been opened for consultation. The OPC has stated that these new rules will be targeted at organizations within New Zealand that use biometric technologies. Read more.

EU jurisdiction

4. Amazon Loses Appeal In EU Court

Date: 1st April, 2024
Summary: Amazon Services Europe, a subsidiary of Amazon, was designated as a very large online platform per the Regulation on a Single Market for Digital Services. Consequently, Amazon was required to make its online advertising practices public. Amazon approached the General Court of the European Union, seeking a suspension of the obligation which was granted. However, this decision was overturned despite Amazon’s claims that it would seriously jeopardize Amazon’s fundamental rights related to respect for private life and the freedom to conduct business as an organization. Read more.

5. New Ukrainian Data Law Comes Into Effect

Date: 2nd April, 2024
Summary: The Law of 10 August 2023 No. 3321-IX came into effect in March 2024. The law provides critical information related to the relationship between consumers and digital content/service providers. Particularly, the law addresses situations where the digital content/service providers offer their product/service to consumers and consumers agree to provide their personal data without intending for such data to be used for any other purpose. However, aspects related to electronic communication, medical, and financial services, among others, are not covered. Read more.

6. Ethiopian Parliament Announces The Passage Of The Personal Data Protection Bill

Date: 8th April, 2024
Summary: Per the Ethiopian Parliament’s Facebook announcement, the Personal Data Protection Bill has been passed in Ethiopia. The Bill establishes critical data privacy principles such as the data rights of data subjects, principles for personal data processing, obligations when processing the personal data of minors, and a supervisory authority that regulates data protection across the country. The bill will apply to all data controllers and processors operating in Ethiopia as well as the data processing of devices located in Ethiopia, even if the data is not intended to leave the country’s jurisdiction. Read more.

7. CJEU Decision Offers Clarification On Compensation For GDPR Infringements

Date: 11th April, 2024
Summary: The CJEU’s decision in case C‑741/21 addresses the issue of compensation for non-material damages occurring as a result of a GDPR infringement. The case involves an individual who had withdrawn their consent to receiving advertisement-related communications but kept on receiving such materials. In the ruling, the court clarified that three conditions must be met for a GDPR infringement to lead to non-material damage compensation. These include the existence of damage, a GDPR infringement, and a causal link between the two. Additionally, the court stated that the criteria for setting administrative fines under the GDPR do not directly apply when determining compensation, which each instance of infringement subject to separate assessments. Moreover, the controller cannot avoid liability in such instances by blaming an individual who may have acted under their authority. Read more.

8. German Federal Court Rules On Right Of Access Case

Date: 16th April, 2024
Summary: The Federal Court of Germany announced its verdict in case number VI ZR 330/21, providing clarification on the interpretation of “copies of personal data” under the GDPR.

The plaintiff in the case had requested copies of their personal data held by the defendants, including emails, letters, telephone notes, and minutes. Per the court’s decision, data subjects have the right of access to copies of letters and emails they authored. However, letters, emails, telephone notes, and minutes from data controllers may not qualify as personal data even if they contain the data subject’s information. The data subject may request copies of the entire document if it is necessary for comprehension through contextualization and the exercise of rights. The plaintiff, in this instance, failed to explain the necessity of contextualization. Read more.

Date: 17th April, 2024
Summary: The EDPB has finally adopted its opinion on the highly debated pay-or-consent model approach. The EDPB has determined that it will not be possible for large online platforms to comply with the relevant valid consent requirements if the only choice they’re allowed to present to users is between consenting to the processing of their personal data or paying a fee. The EDPB recommends large online platforms develop alternatives to the consent or pay model with an equivalent alternative that does not require users to pay. Additional recommendations include possible advertising models that rely on minimal or no personal data processing, allowing for appropriate privacy rights protection and seamless access to online services. Read more.

10. Paderborn Court Rules On Unsolicited Advertising Communications

Date: 15th April, 2024
Summary: The Paderborn Regional Court passed its judgment in case number 2 O 325/23, where the defendant was found to have violated both the Act Against Unfair Competition (UWG) and the General Data Protection Regulation (GDPR) owing to their unsolicited advertising communications with the plaintiff. The defendant violated the UWG by continuing to send marketing emails despite the plaintiff’s objection. The Court added that the GDPR provides for a period of up to one month for the provision of information but not for the implementation of the objection as the defendant had claimed. Read more.

North and South America Jurisdiction

11. New Cybersecurity Act Provides Relief For Companies That Suffer A Data Breach

Date: 2nd April, 2024
Summary: The Cybersecurity Incident Liability Act was passed in Florida, ensuring immunity for covered entities that suffer a data breach. However, this immunity will depend on a range of factors, including compliance with the relevant data breach notification requirements per the Florida Information Protection Act, adoption and consistent updates of relevant cybersecurity programs per industry standards, and the burden of proof being on the defendant to prove their compliance. Read more.

12. Maryland Gets Its Data Privacy Regulation

Date: 6th April, 2024
Summary: The Maryland Online Data Privacy Act (MODPA) has been passed by the legislature, ensuring Maryland will become either the sixteenth or seventeenth state to pass a comprehensive data privacy act, owing to a similar bill awaiting the Governor’s signature in Nebraska. The Act will come into effect in October 2025, providing consumers with a greater degree of protection in comparison to similar regulations in other states, such as Connecticut, Colorado, Oregon, and Delaware, due to data minimization and other such requirements. Read more.

13. Nebraska Latest US State To Get Data Privacy Regulation

Date: 17th April, 2024
Summary: The Nebraska Data Privacy Act was formally signed into law after Governor Jim Pillen formally signed Legislative Bill 1074. As a result, Nebraska became the seventeenth state to adopt such a comprehensive data privacy regulation within the United States. The Nebraska Data Privacy Act, which will come into effect in January 2025, has been mirrored closely around the Texas Data Privacy and Security Act. It applies to all entities that conduct business or provide services in Nebraska, engage in the processing or sale of personal data, and do not qualify as small businesses. Read more.

Explore Securiti's Privacy Regulation roundup for the latest updates on global privacy developments. We're committed to providing you with timely updates and essential information to help you understand the evolving privacy regulatory landscape. You can also visit our dedicated page, offering an overview of global data privacy laws.

Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox


Share

More Stories that May Interest You
Videos
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...
AWS Startup Showcase Cybersecurity Governance With Generative AI View More
AWS Startup Showcase Cybersecurity Governance With Generative AI
Balancing Innovation and Governance with Generative AI Generative AI has the potential to disrupt all aspects of business, with powerful new capabilities. However, with...

Spotlight Talks

Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Spotlight 47:42
Cybersecurity – Where Leaders are Buying, Building, and Partnering
Rehan Jalil
Watch Now View
Spotlight 27:29
Building Safe AI with Databricks and Gencore
Rehan Jalil
Watch Now View
Spotlight 46:02
Building Safe Enterprise AI: A Practical Roadmap
Watch Now View
Spotlight 13:32
Ensuring Solid Governance Is Like Squeezing Jello
Watch Now View
Latest
Simplifying Global Direct Marketing Compliance with Securiti’s Rules Matrix View More
Simplifying Global Direct Marketing Compliance with Securiti’s Rules Matrix
The Challenge of Navigating Global Data Privacy Laws In today’s privacy-first world, navigating data protection laws and direct marketing compliance requirements is no easy...
View More
Databricks AI Summit (DAIS) 2025 Wrap Up
5 New Developments in Databricks and How Securiti Customers Benefit Concerns over the risk of leaking sensitive data are currently the number one blocker...
A Complete Guide on Uganda’s Data Protection and Privacy Act (DPPA) View More
A Complete Guide on Uganda’s Data Protection and Privacy Act (DPPA)
Delve into Uganda's Data Protection and Privacy Act (DPPA), including data subject rights, organizational obligations, and penalties for non-compliance.
Data Risk Management View More
What Is Data Risk Management?
Learn the ins and outs of data risk management, key reasons for data risk and best practices for managing data risks.
View More
Getting Ready for the EU AI Act: What You Should Know For Effective Compliance
Securiti's whitepaper provides a detailed overview of the three-phased approach to AI Act compliance, making it essential reading for businesses operating with AI.
Beyond DLP: Guide to Modern Data Protection with DSPM View More
Beyond DLP: Guide to Modern Data Protection with DSPM
Learn why traditional data security tools fall short in the cloud and AI era. Learn how DSPM helps secure sensitive data and ensure compliance.
View More
Unlock Amazon Q’s Full Potential with Secure, Governed Data
Learn how robust DSPM can help secure Amazon Q data access, automate sensitive data tagging, eliminate ROT data, and maximize AI productivity safely.
Singapore’s PDPA & Consent: Clear Guidelines for Enterprise Leaders View More
Singapore’s PDPA & Consent: Clear Guidelines for Enterprise Leaders
Download the essential infographic for enterprise leaders: A clear, actionable guide to Singapore’s PDPA and consent requirements. Stay compliant and protect your business.
Gencore AI and Amazon Bedrock View More
Building Enterprise-Grade AI with Gencore AI and Amazon Bedrock
Learn how to build secure enterprise AI copilots with Amazon Bedrock models, protect AI interactions with LLM Firewalls, and apply OWASP Top 10 LLM...
DSPM Vendor Due Diligence View More
DSPM Vendor Due Diligence
DSPM’s Buyer Guide ebook is designed to help CISOs and their teams ask the right questions and consider the right capabilities when looking for...
What's
New