Securiti leads GigaOm's DSPM Vendor Evaluation with top ratings across technical capabilities & business value.

View

Privacy Regulation Roundup: Top Stories of June 2025

Contributors

Yasir Nawaz

Digital Content Producer at Securiti

Aiman Kanwal

Assoc. Data Privacy Analyst at Securiti

Syeda Eimaan Gardezi

Associate Data Privacy Analyst at Securiti

Aswah Javed

Associate Data Privacy Analyst at Securiti

Securiti’s Privacy Regulation Roundup summarizes the latest significant global privacy regulatory developments, announcements, and changes. These developments will be added to our website monthly. You can find a link to related resources at the bottom for each relevant regulatory activity.

Editorial Note

Privacy Regulation Ramps up Worldwide

June brought a surge of privacy activity worldwide. In the US, states advanced new laws while regulators clarified rules on data security and privacy practices. Europe stayed active with major fines for Spotify and Vodafone and fresh guidance on issues like diversity data and legitimate interest. New laws in Vietnam and Malaysia, along with guidance from Hong Kong and Singapore, are reshaping privacy landscapes in Asia.
Looking ahead, consultations and new rules on topics like children’s privacy, biometric data, and digital identity are unfolding across regions. As global standards tighten, businesses face growing pressure to keep pace with evolving laws and rising enforcement risks. Organizations everywhere must stay alert as global standards tighten and regulators keep privacy firmly in focus.

Watch: June's Privacy Pulse - All Major Highlights

A quick overview of global privacy headlines you cannot afford to miss.

North & South America Jurisdiction

1. EPIC Releases New Report on Algorithmic & Privacy Risk Assessments

June 25, 2025
United States

The Electronic Privacy Information Center (EPIC) released its new report, titled "Assessing the Assessments: Maximizing the Effectiveness of Algorithmic & Privacy Risk Assessments". In it, they respond to the California Privacy Protection Agency’s (CPPA) ongoing work to develop risk assessment rules under CCPA. The report also highlights the privacy harms that can result from personal data being collected without meaningful oversight, especially in the case of behavioral advertising and surveillance pricing, and automated decision-making in critical sectors such as employment, healthcare, housing, education, and law enforcement.

The report calls for a robust risk assessment framework to give consumers greater visibility and control over how their data is used.

Read More.

2. Connecticut's Senate Bill 1295 Signed Into Law

June 25, 2025
Connecticut, United States

On June 25, 2025, Connecticut’s Senate Bill 1295 was signed into law, introducing significant amendments to the state’s consumer privacy framework.

The new law modifies applicability thresholds, exemptions, definitions, consumer rights, data minimization requirements, and provisions related to children’s privacy. Notably, the consumer threshold for applicability has been lowered from 100,000 to 35,000 consumers. Additionally, it removes the prior requirement that a controller must process data from at least 25,000 consumers and derive over 25% of gross revenue from selling personal data. As a result, the law now applies to any entity that offers consumers’ personal data for sale in trade or commerce.

These changes mark an important expansion of privacy protections in Connecticut and could have significant implications for businesses operating in the state. The amendments are set to take effect on July 1, 2026.

Read More.

3. Amended COPPA Rules Take Effect, Expanding Children’s Privacy Protections

June 23, 2025
United States

On June 23, 2025, the amended rules under the Children’s Online Privacy Protection Act (COPPA) officially came into effect, strengthening protections for children’s personal data online.

The new rules require verifiable parental consent before sharing children’s data with third parties for targeted advertising. They also mandate that personal information be retained only as long as necessary for its original purpose. Additionally, COPPA Safe Harbor programs must now disclose their membership lists and report compliance details to the Federal Trade Commission (FTC).

Other changes expand the definition of personal information to include biometric data and government-issued identifiers. These updates signal a significant step forward in safeguarding children’s privacy in the digital age.

Read More.

4. New York Children’s Data Protection Act Now in Effect

June 20, 2025
United States

The New York Children’s Data Protection Act took effect on June 20, 2025, strengthening privacy protections for children and young adults under 18. The law restricts digital services from collecting, selling, or disclosing personal data of individuals under 18 without consent. Covered entities must also obtain informed consent before collecting any personal information, with the consent revocable at any time through a simple, accessible process.

This new law marks a significant step in safeguarding young users’ privacy and adds important compliance responsibilities for digital service providers operating in New York.

Read More.

5. FTC Releases FAQs Clarifying Safeguards Rule Per the GLBA

June 17, 2025
United States

On June 17, 2025, the Federal Trade Commission (FTC) released a new set of FAQs to help clarify the Safeguards Rule under the Gramm-Leach-Bliley Act (GLBA). This rule requires financial institutions to maintain a documented security plan to protect customer information. Following updates in 2023, certain data breaches must now be reported directly to the FTC.

The FAQs also clarify the difference between the Safeguards Rule and the GLBA’s Privacy Rule. While the Safeguards Rule focuses on protecting customer data through security measures, the Privacy Rule requires financial institutions to provide privacy notices explaining how customer information is collected, used, and shared, particularly when consumers apply for or receive financial services.

These FAQs aim to help financial institutions better understand and comply with their obligations under the GLBA.

Read More.

6. Vermont’s Age Appropriate Online Design Code Act Signed into Law

June 12, 2025
Vermont, United States

On June 12, 2025, Vermont Governor signed the Age Appropriate Online Design Code Act (SB 69) into law. The legislation applies to businesses operating in Vermont that generate a majority of revenue from online sales, offer products or services likely to be accessed by minors, collect personal data directly or through processors, and determine the purposes and means of processing consumer personal data.

The law introduces a duty of care for covered entities, prohibiting the use of personal data in ways that could cause emotional distress or discrimination against consumers. It also includes enhanced privacy protections for minors’ online accounts.

The law is set to take effect on January 1, 2027, giving businesses time to prepare for compliance. Organizations operating in Vermont should monitor developments closely to ensure readiness.

Read More.

7. Paraguay’s Data Protection Bill of 2021 Forwarded to Senate For Final Approval

June 5, 2025
Paraguay

On June 5, 2025, Paraguay’s Chamber of Deputies approved the long-pending Data Protection Bill of 2021, sending it to the Senate for final consideration and approval, before proceeding to the President’s signature.

The bill establishes core principles for personal data processing in line with international standards, requiring adherence to principles such as accuracy, lawfulness, purpose limitation, proportionality, loyalty, transparency, and due diligence. It prohibits the publication of sensitive data, mandates prior and informed consent with the right to withdraw, sets guidelines for minors’ consent, and requires the appointment of a Data Protection Officer. Additionally, it calls for Data Protection Impact Assessments for high-risk processing activities.

If enacted, this bill would significantly reshape Paraguay’s data privacy landscape. Organizations should closely monitor their progress to prepare for timely compliance.

Read More.

8. Texas Governor Signs App Store Accountability Act Into Law

June 1, 2025
Texas, United States

On May 27, 2025, Texas Governor Greg Abbott signed SB 2420, known as the App Store Accountability Act, into law. The legislation defines app stores as publicly accessible websites, software applications, or other electronic services that distribute software applications from developers to users of mobile devices.

Under the new law, app store owners must use commercially reasonable methods to verify users’ ages and categorize them into groups: child (under 13), younger teenager (13-16), older teenager (16-18), and adult (18 and above). Additionally, the law requires that a minor’s account be affiliated with their parents’ account, with parental consent needed for each download or purchase made by the minor.

Businesses operating app stores in Texas must ensure compliance with these requirements to avoid potential penalties.

Read More.

9. Nebraska Age Appropriate Online Design Code Act Signed Into Law

June 1, 2025
Nebraska, United States

On May 30, 2025, Nebraska Governor Jim Pillen signed LB 504, the Age Appropriate Online Design Code Act, into law. The legislation applies to online businesses operating in Nebraska that determine the purposes and means of personal data processing, have annual gross revenue exceeding $25 million, process personal data of at least 50,000 consumers, or derive at least 50% of their revenue from selling or sharing personal data.

The law also requires covered entities to provide parents with tools to protect and support minors when using online services. It is set to take effect on January 1, 2026.

Organizations falling within these thresholds should prioritize compliance to avoid potential penalties.

Read More.

Europe & Africa Jurisdiction

10. EDPB Submits Comments on European Commission’s Draft Guidelines to Protect Minors Under DSA

June 25, 2025

On June 25, 2025, the European Data Protection Board (EDPB) submitted its comments on the European Commission’s draft guidelines for protecting minors online under the Digital Services Act (DSA).

The EDPB’s key recommendations for online platforms and regulatory authorities include promoting cooperation between competent authorities under both the DSA and GDPR, providing clearer guidance on platforms’ roles and responsibilities in safeguarding minors’ data, and addressing concerns about the reliability of self-declaration for age assurance compared to more precise age estimation or verification methods.

These comments reflect the EDPB’s push for stronger, coordinated regulatory measures and more effective, privacy-conscious age verification processes to protect minors online.

Read More.

11. European Commission Extends UK’s GDPR Adequacy Decision

June 24, 2025

On June 24, 2025, the European Commission extended its GDPR adequacy decision for the United Kingdom until December 27, 2025. This extension ensures that data can continue to flow freely between the EU and the UK beyond the original expiration date of June 27, 2025.

The additional time allows the Commission to review the UK’s data protection framework, particularly in light of the recently enacted Data (Use and Access) Act. The decision signals a cautious approach as the Commission assesses whether the UK’s standards remain “essentially equivalent” to the GDPR- a crucial determination for the future of seamless UK-EU data transfers.

Read More.

12. European Commission Launches Consultation on Data Retention for Criminal Proceedings

June 20, 2025

On June 20, 2025, the European Commission opened a public consultation on the impact assessment of requiring service providers to retain data for use in criminal proceedings. The consultation will remain open until September 12, 2025.

The initiative follows the Commission’s concerns that the lack of an EU-wide legal framework for mandatory metadata retention limits authorities’ ability to access critical information in a timely manner for fighting crime.

While aimed at strengthening law enforcement capabilities, the proposal is expected to spark significant debate over privacy and data protection implications across the EU.

Read More.

13. UK’s Data Use And Access Bill Receives Royal Assent

June 19, 2025
United Kingdom

On June 19, 2025, the UK’s Data Use and Access Bill became law, aiming to boost the economy through responsible data use and improve public services.

Key changes include removing opt-in consent for certain cookies, introducing “Recognised legitimate interests” for broader data processing in areas like security and crime prevention, and updating rules for Data Subject Access Requests to require only “reasonable and proportionate” searches. The Act also relaxes rules on automated decisions, applying stricter safeguards only to significant cases involving sensitive data, and adjusts standards for international data transfers.

The Act signals a shift toward a more flexible, pro-innovation data protection regime, differentiating the UK from the GDPR in key areas.

Read More.

14. European Commission Makes AliExpress’ DSA Commitments Legally Binding

June 18, 2025

On June 18, 2025, the European Commission made AliExpress’s commitments under the Digital Services Act (DSA) legally binding, following compliance concerns raised in 2024.

Key obligations include tougher monitoring to block illegal products, clearer ad labelling and targeting information, stronger seller verification, and improved user complaint systems. AliExpress must also provide researchers access to public data for studying systemic risks.

Breaching these commitments now constitutes a DSA violation, carrying the risk of significant fines tied to global turnover.

Read More.

15. EU Reaches Provisional Deal to Streamline Cross-Border GDPR Cases

June 16, 2025

On June 16, 2025, the European Parliament and Council of the EU reached a provisional deal on new rules to strengthen cooperation among national data protection authorities (DPAs) for cross-border GDPR cases.

Key changes include unified criteria for assessing complaints across the EU, clearer rights for complainants and businesses, and set deadlines of 15 months for investigations, extendable for complex cases. A new early resolution mechanism will allow DPAs to close cases swiftly if corrective actions are taken and the complainant agrees.

Once formally adopted, these new EU rules will streamline and speed up cross-border GDPR enforcement, enhancing cooperation and clarity for DPAs, complainants, and organizations.

Read More.

16. Norway’s Data Protection Authority Fined Kristiansand Municipality for Unlawful Use of Tracking Pixels

June 12, 2025
Norway

Norway’s Data Protection Authority (Datatilsynet) has fined Kristiansand Municipality NOK 250,000 (approx. $25,120) for GDPR violations on its Alarmophone website.

An investigation found the municipality used tracking pixels and cookies without user consent, failed to disclose cookie use in its privacy policy, and lacked a legal basis for processing children’s personal data, which was shared with third parties.

These breaches violated GDPR Articles 6, 12, and 13. The case highlights that public bodies must uphold the same data protection standards as private organizations, especially when handling sensitive data.

Read More.

17. French Data Protection Authority Publishes Recommendations for Employers Collecting Diversity Data in Employee Surveys

June 10, 2025
France

France’s CNIL has published recommendations for employers conducting diversity surveys, emphasizing privacy safeguards. Employers should avoid collecting identifying details, ensure participation is voluntary, and use pseudonymization or anonymity where possible.

Direct collection of racial or ethnic data remains prohibited, but related information can be gathered through objective measures like place of birth. CNIL also advises using trusted survey providers and sharing only aggregated results.

These guidelines help employers collect diversity data lawfully under GDPR while protecting employee privacy.

Read More.

18. EDPB Publishes Guidelines on Article 48 of GDPR Addressing Foreign Data Requests

June 5, 2025

On June 5, 2025, the European Data Protection Board (EDPB) issued guidelines clarifying how organizations should handle requests from third-country authorities for personal data transfers under GDPR Article 48. The guidance aims to help businesses navigate conflicts between GDPR obligations and foreign government data demands.

Key points include the non-recognition principle, meaning foreign decisions aren’t automatically enforceable in the EU without a legal framework; reliance on international agreements where they exist; and the need for case-by-case assessments if no agreement applies. The guidelines also outline legal bases for transfers, including legal obligations, consent, or specific exceptions under Articles 6(1)(c) through (f).

These guidelines equip organizations to handle foreign data requests while remaining GDPR-compliant.

Read More.

19. Finland Fines Yliopiston Apteekki €1.1 Million for Mishandling Sensitive Pharmacy

June 4, 2025
Finland

On June 4, 2025, Finland’s Data Protection Ombudsman fined Yliopiston Apteekki €1.1 million after a University of Turku researcher uncovered privacy violations at Finnish online pharmacies. An investigation into practices between May 2018 and September 2022 found serious GDPR breaches.

The pharmacy had used cookies and tracking technologies that transmitted sensitive data, including prescription details, over-the-counter purchases, and customer IP addresses to Google and Meta.

The case highlights that pharmacy websites cannot deploy standard tracking tools without robust safeguards, as purchase data can reveal highly sensitive health information, making even basic cookies a significant privacy risk.

Read More.

20. Swedish Court Upholds $6 Million Fine Against Spotify for GDPR Transparency Failures

June 3, 2025
Sweden

Sweden's Court of Appeal backed the data protection authority's decision to fine Spotify SEK 58 million ($6 million) for several GDPR violations. The streaming giant failed on three key transparency requirements: users couldn't easily understand how to exercise their data rights, Spotify didn't explain safeguards for international data transfers, and the company never disclosed how long it keeps user data or why.

This ruling emphasizes that GDPR transparency isn't just about having a privacy policy, but users must also be able to actually understand and act on their rights, with clear explanations of data handling practices.

Read More.

21. German DPA Fines Vodafone €45 Million for GDPR Violations

June 3, 2025
Germany

On June 3, 2025, Germany’s Data Protection Authority (BfDI) fined Vodafone €45 million for GDPR violations related to poor partner oversight and inadequate security measures. Vodafone failed to properly monitor partner agencies handling customer data, breaching GDPR Article 28(1). Additionally, its ‘MeinVodafone’ portal contained authentication flaws, violating Article 32(1). The fine was split, with €15 million for partner oversight failures and €30 million for security weaknesses.

Vodafone has since upgraded systems, cut ties with non-compliant partners, and improved audit processes. BfDI plans a follow-up audit to ensure compliance.

The case highlights that outsourcing data processing does not absolve companies of GDPR responsibilities- they remain accountable for partners’ actions and must maintain strong security and oversight practices.

Read More.

22. Georgia’s PDPS Issues Guidelines on Processing Minors’ Data in Schools

June 3, 2025
Georgia

On June 3, 2025, Georgia’s Personal Data Protection Service (PDPS) released guidelines for handling minors’ data under the DPA 2023 and GDPR. The guidance targets schools, administrators, and parents, outlining legal obligations for collecting and processing student data.

Schools must establish a legal basis for data collection, seek explicit parental consent for sensitive information like health or disciplinary records, and ensure data is collected only as needed, kept secure, and retained for limited periods. Institutions are required to inform guardians about data use and sharing, and report any data breaches to the PDPS within 72 hours.

These guidelines aim to help educational institutions protect student privacy while maintaining efficient operations.

Read More.

23. Estonian DPA Issues Guidance on Using Legitimate Interest for Data Processing

June 1, 2025
Estonia

Estonia’s Data Protection Inspectorate (DPA) has issued guidance on using legitimate interest for data processing. Unlike consent or contracts, legitimate interest is initiated by the controller for their own or third-party benefit and requires a documented balancing test to protect individuals’ rights.

The guidance highlights areas where legitimate interest may apply, such as property protection, fraud prevention, and legal compliance. However, it cannot be used by public authorities for core legal tasks, for sensitive data like health information, or in cases involving minors unless clearly in the child’s interest.

These insights help organizations apply legitimate interest responsibly under privacy laws.

Read More.

24. Maltese IDPC Issues FAQs on Employee Data Processing

June 1, 2025
Malta

Malta’s Information and Data Protection Commissioner (IDPC) has published FAQs to help employers navigate GDPR compliance when processing employee data.

Key topics include limits on using biometric data due to workplace power imbalances, proper handling of police certificates and medical checks, strict conditions for employee monitoring, recommendations against automatic email forwarding for former employees, and guidance on data retention periods.

The FAQs urge employers to reassess traditional HR practices to align with GDPR standards.

Read More.

Asia Jurisdiction

25. Vietnam Passes Personal Data Protection Law

June 26, 2025
Vietnam

On June 26, 2025, Vietnam’s National Assembly passed the Law on Personal Data Protection, which will take effect on January 1, 2026. The new law establishes a comprehensive data governance framework, defines roles for state authorities, and sets obligations for data controllers and processors. It also bans unauthorized trading of personal data and imposes stricter rules on cross-border data transfers.

To support economic growth, the law allows small businesses and startups to defer some obligations for five years, with partial exemptions for micro-enterprises and household businesses.

Read More.

June 16, 2025
India

On June 16, 2025, the Telecom Regulatory Authority of India (TRAI), in collaboration with the Reserve Bank of India (RBI), launched a pilot project to enhance digital consent management for commercial communications.

The initiative aims to reduce spam calls, particularly in the banking sector, by requiring businesses to secure explicit, verifiable consumer consent. It signals TRAI’s move toward a stronger consent-driven model to curb data misuse and close gaps in offline consent practices.

Read More.

27. New Zealand Privacy Commissioner Releases Guidance on How Privacy Act Applies to Clubs & Societies

June 13, 2025
New Zealand

On June 13, 2025, New Zealand’s Privacy Commissioner released guidance on how the Privacy Act 2020 applies to clubs and societies. Any group collecting personal data must comply with principles like purpose limitation, data minimization, direct collection, and transparency.

Clubs must secure personal data, limit access to authorized members, and uphold individuals’ rights to access and correct their information. The guidance encourages clubs to review practices around member databases, email lists, and event registrations to avoid compliance risks.

Read More.

28. Singaporean PDPC Releases Guide on Anonymization

June 11, 2025
Singapore

On June 11, 2025, Singapore’s PDPC launched its Guide to Getting Started with Anonymization during the 63rd APPA meeting. The guide outlines a five-step process for anonymizing personal data, covering removal of direct identifiers, use of context-specific techniques, risk assessment for re-identification, and alignment with ISO/IEC 27559 standards.

This guide aims to help organizations use data responsibly for innovation while protecting individual privacy.

Read More.

29. Credit Base (HK) Limited Convicted for Unlawful Direct Marketing in Hong Kong

June 11, 2025
Hong Kong

Hong Kong’s PCPD announced the conviction of Credit Base (HK) Limited for using personal data in direct marketing without user consent. The company had sourced personal data from District Court filings in November 2023 and used it to promote debt collection services without notifying individuals or obtaining required consent, violating sections 35C(1) and 35F(1) of the PDPO.

Credit Base also failed to inform individuals of their right to opt out of direct marketing free of charge. The company was fined HKD 5,000 after pleading guilty. This conviction underscores that public records cannot be used to bypass direct marketing rules under the PDPO.

Read More.

30. China Issues Regulations on Government Data Sharing

June 4, 2025
China

On June 4, 2025, China’s State Council issued new Regulations on Government Data Sharing, set to take effect on August 1, 2025. The rules govern data sharing among government agencies and approved entities, excluding state secrets.

A key provision prohibits agencies from duplicating data collection if shared data meets their needs, aiming to reduce redundancy and improve efficiency. These regulations mark a significant step in formalizing China’s public sector data governance while balancing security and privacy considerations.

Read More.

31. Malaysia PDPA Amendment Act Comes Into Effect

June 1, 2025
Malaysia

As of June 1, 2025, Malaysia’s PDPA Amendment Act is fully in force. Organizations are now required to appoint a Data Protection Officer (DPO), notify authorities of data breaches, and strengthen their data protection measures.

Earlier amendments also introduced obligations for data processors, expanded definitions to cover biometric data, and increased penalties for non-compliance.

Read More.

32. China’s Security Measures Restrict Use of Facial Recognition Technology

June 1, 2025
China

China’s Security Management Measures for Facial Recognition Technology took effect on June 1, 2025. The rules limit facial recognition mainly to research and public settings, requiring consent, security safeguards, and risk assessments.

These measures reflect China’s effort to balance innovation with privacy protection and introduce new compliance obligations for entities using facial recognition technology.

Read More.

WHAT'S NEXT: Key Privacy Developments to Watch For

  • Minnesota’s Consumer Data Privacy Act will take effect on July 31, 2025, following Tennessee’s TIPA on July 1, 2025.
  • Consultations are underway on privacy guidance for IoT products in the UK (comments due by September 7, 2025), email tracking pixels in France (due July 24, 2025), and children’s online privacy in Australia (due July 31, 2025). Norway’s deadlines are approaching on July 1, 2025, for data center registration and feedback on a proposed 15-year social media age limit.
  • The EDPB and EDPS will issue a joint opinion within weeks on simplifying GDPR for small businesses- a key development to reduce compliance burdens.
  • South Korea’s consultation on PIPA amendments closes July 9, 2025, and New Zealand’s new standard for sharing government-held data takes effect on July 1, 2025. China’s new identity authentication rules will come into force on July 15, 2025.
  • Public comments are open until August 1, 2025, for New Jersey’s new privacy rules, and until July 30, 2025, for NIST’s updates on privacy, cybersecurity, and supply chain risks. NIST’s whitepaper on 5G security is open for feedback until July 17, 2025.
  • Brazil is consulting on biometric data rules until July 2, 2025, and considering updates to define “sensitive biometric data.”
  • Watch Canada’s Bill C-8, aiming to strengthen cybersecurity protections under the Telecommunications Act.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox


Share

More Stories that May Interest You
Videos
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...
AWS Startup Showcase Cybersecurity Governance With Generative AI View More
AWS Startup Showcase Cybersecurity Governance With Generative AI
Balancing Innovation and Governance with Generative AI Generative AI has the potential to disrupt all aspects of business, with powerful new capabilities. However, with...

Spotlight Talks

Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Spotlight 47:42
Cybersecurity – Where Leaders are Buying, Building, and Partnering
Rehan Jalil
Watch Now View
Spotlight 27:29
Building Safe AI with Databricks and Gencore
Rehan Jalil
Watch Now View
Spotlight 46:02
Building Safe Enterprise AI: A Practical Roadmap
Watch Now View
Spotlight 13:32
Ensuring Solid Governance Is Like Squeezing Jello
Watch Now View
Latest
Navigating the Data Minefield: Essential Executive Recommendations for M&A and Divestitures View More
Navigating the Data Minefield: Essential Executive Recommendations for M&A and Divestitures
The U.S. M&A landscape is back in full swing. May witnessed a significant rebound in deal activity, especially for transactions exceeding $100 million, signaling...
Simplifying Global Direct Marketing Compliance with Securiti’s Rules Matrix View More
Simplifying Global Direct Marketing Compliance with Securiti’s Rules Matrix
The Challenge of Navigating Global Data Privacy Laws In today’s privacy-first world, navigating data protection laws and direct marketing compliance requirements is no easy...
What to Know About Quebec’s Act Respecting Health and Social Services Information (AHSSS) View More
What to Know About Quebec’s Act Respecting Health and Social Services Information (AHSSS)
Learn more about Quebec's AHSSS, including its obligations on healthcare providers, researchers, and technology providers, with Securiti's latest blog.
View More
What is Automated Decision-Making Under CPRA Proposed ADMT Regulations
Learn more about automated decision-making (ADM) under California's CPRA, its regulatory approach to the technology, and how to ensure compliance.
View More
Is Your Business Ready for the EU AI Act August 2025 Deadline?
Download the whitepaper to learn where your business is ready for the EU AI Act. Discover who is impacted, prepare for compliance, and learn...
View More
Getting Ready for the EU AI Act: What You Should Know For Effective Compliance
Securiti's whitepaper provides a detailed overview of the three-phased approach to AI Act compliance, making it essential reading for businesses operating with AI.
View More
Enabling Safe Use of Data with Amazon Q
Learn how robust DSPM can help secure Amazon Q data access, automate sensitive data tagging, eliminate ROT data, and maximize AI productivity safely.
Singapore’s PDPA & Consent: Clear Guidelines for Enterprise Leaders View More
Singapore’s PDPA & Consent: Clear Guidelines for Enterprise Leaders
Download the essential infographic for enterprise leaders: A clear, actionable guide to Singapore’s PDPA and consent requirements. Stay compliant and protect your business.
Gencore AI and Amazon Bedrock View More
Building Enterprise-Grade AI with Gencore AI and Amazon Bedrock
Learn how to build secure enterprise AI copilots with Amazon Bedrock models, protect AI interactions with LLM Firewalls, and apply OWASP Top 10 LLM...
DSPM Vendor Due Diligence View More
DSPM Vendor Due Diligence
DSPM’s Buyer Guide ebook is designed to help CISOs and their teams ask the right questions and consider the right capabilities when looking for...
What's
New