Securiti launches Gencore AI, a holistic solution to build Safe Enterprise AI with proprietary data - easily

View

Privacy Regulation Roundup: Top Stories of November 2024

Contributors

Anas Baig

Product Marketing Manager at Securiti

Muhammad Ismail

Assoc. Data Privacy Analyst at Securiti

Syed Tatheer Kazmi

Associate Data Privacy Analyst, Securiti

CIPP/Europe

Salma Khan

Data Privacy Analyst

CIPP/Asia

Rohma Fatima Qayyum

Assoc. Data Privacy Analyst

Usman Tariq

Data Privacy Analyst at Securiti

CIPP/US

Securiti has started a Privacy Regulation Roundup summarizing the latest significant global privacy regulatory developments, announcements, and changes. These developments will be added to our website monthly. You can find a link to related resources at the bottom for each relevant regulatory activity.

North and South America Jurisdiction

1. Bermuda’s Minister Announces New Sections To PIPA Amendment Act Become Effective On January 1

Date: November 7, 2024
Summary: Bermuda's Minister for Information and Communication Technologies Policy and Innovation has announced that Sections 3-25, 30-34, and 37-50 of the Personal Information Protection Amendment Act (the PIPA Amendment Act) will become effective on January 1, 2025, in the Official Gazette. Read More.

2. CFPB’s New Report Highlights Need For Greater Protection For Consumers’ Financial Data In The US

Date: November 12, 2024
Summary: The Consumer Financial Protection Bureau (CFPB) has issued a report on state privacy laws and monetization of consumer financial data.

The report highlights the new rights and protections provided by these laws but singles out the exemption for financial institutions and data covered by the Gramm-Leach-Bliley Act (GLBA) and Fair Credit Reporting Act (FCRA) for allowing institutions such as banks and consumer reporting agencies to operate outside these state laws and limit consumer rights over their financial data.

The current federal financial data privacy protection frameworks consist mainly of the Gramm-Leach-Bliley Act (GLBA) and the Fair Credit Reporting Act (FCRA). The GLBA's regulatory framework is based mainly on disclosures and opt-out requirements that do not adequately address the challenges posed by modern data surveillance. This means that most data remains outside the scope of most new state-law protections, such as the right under state law for consumers to rectify or delete incorrect or outdated information or requirements related to opt-in consent models for sensitive data.

The CFPB encourages state policymakers to revisit and limit or remove these exemptions. The report highlights how only California restricts the GLBA exemption specifically to data governed by the GLBA, as opposed to other state privacy laws, such as Virginia, which exempts both the financial institutions and the data governed by the GLBA. Read More.

EMEA Jurisdiction

3 UK’s ICO And CMA Release Joint Paper On Harmful Online Designs

Date: 4 November, 2024
Summary: The ICO and CMA have released a joint paper. The paper "Harmful Design in Digital Markets" is meant for UX designers and firms that create online interfaces that may potentially influence consumer choice and control over their data. Among other things, the paper outlines how certain design choices may lead to data protection, consumer, and competition issues, potentially violating ICO and CMA regulations. Some examples of such practices include "harmful nudges," "confirmshaming," "biased framing," "bundled consent," and restrictive "default settings". Lastly, the paper advises all firms to avoid such practices to protect privacy, ensure compliance with data protection laws, and promote fair competition. Read More.

4. Administrative Court In Slovenia Issues Judgement Declaring GPS Tracking as Data Processing Under GDPR

Date: 5 November, 2024
Summary: On October 14, 2024, the Administrative Court issued judgment no. II U 197/2023-20, wherein it states that continuous GPS tracking of company vehicles amounts to data processing under the GDPR. As such, it requires a lawful basis. The judgment followed after a complaint was made to the Information Commissioner. The Commissioner ordered the controller to cease such collections, who made an appeal to the Court. The Court's ruling confirms that under Article 6(1)(f) of the GDPR, a legitimate interest can justify GPS tracking only if it meets three conditions:

  • The interest must be real and legal;
  • The data processing must be necessary and proportional;
  • It must not infringe on individuals' rights. Read More.

Date: 5 November, 2024
Summary: The Data State Inspectorate (DVI) has issued guidance on proper cookie banner practices. Some of the key points of the guidance include the following:

  • Cookie banners should be simple, straightforward, and free from misleading information;
  • Functional cookies that do not need consent should contain a brief description with an acknowledgment button, like "got it";
  • Users must be able to opt out of non-essential cookies;
  • All cookie banners must use clear language, avoid pre-selected options, and provide easy opt-out options.

Lastly, the guidance advises against bad practices like omitting opt-out options, providing inadequate information, or using pre-checked boxes. Read More.

6. “Online Safety Act Applicable To GenAI Chatbots That Allow Sharing Of AI-Generated Content”, UK’s Ofcom Clarifies

Date: November 8, 2024
Summary: Ofcom has clarified that the Online Safety Act applies to GenAI chatbot tools and platforms that allow sharing of AI-generated content among users, including group chat functions and services that host user-created chatbots. All AI-generated content shared to a user-to-user service is treated similarly to human-generated content, including deepfakes. AI tools that can search multiple websites and databases, modify search results, or generate pornographic content are also covered in the Act.

All organizations that fall under its scope, including user-to-user and search service providers, must prepare for compliance by conducting risk assessments to evaluate exposure to harmful content, implementing appropriate risk management measures, and ensuring the easy reporting of harmful or illegal content, particularly for children.

Key compliance measures outlined in Ofcom's draft Codes of Practice include appointing a compliance officer, implementing a content moderation function for swift takedowns of illegal content, ensuring effective age assurance, and providing accessible reporting and complaints mechanisms.

The Act will initially come into effect in December 2024, when Ofcom issues its final guide and codes. Read More.

Date: November 12, 2024
Summary: The Finnish Data Protection Authority has updated its FAQs on healthcare data protection. The updates include instructions for patients on how to check, correct, and delete their health information and remind them of their right to access health records and imaging results free of charge. Any changes to patient records must consider whether such information is still required for their care, planning, monitoring, or supervision. Original entries in patient documents may be retained for oversight and monitoring reasons.

The update clarifies rules related to patient data disclosures, stating that all such disclosures must be based on legal grounds or the patients' explicit consent. Several specific scenarios are also addressed, such as correcting incorrect diagnoses, reporting suspected unauthorized access to patient records, and denying contact with healthcare providers based on scientific research findings. Read More.

8. Meta Announces Changes To Its Personalized Advertising Model In The EU

Date: November 12, 2024
Summary: Meta has announced several changes to its personalized advertising model for Facebook and Instagram users in Europe due to regulatory pressure from the EU. These updates address privacy concerns while providing users with a greater degree of control over how their data is used for advertising purposes.

One of the major updates is the introduction of "less personalized ads" for users who opt not to pay for an ad-free subscription. These ads will be based on minimal personal information and recent activity rather than extensive historical data, reducing the level of data-driven profiling involved in ad targeting.

Furthermore, Meta has revised its entire ad-free subscription model, which had been criticized for being potentially misleading since it did not adequately address privacy concerns. The new changes have lowered the subscription costs, making them more affordable and accessible.

Commenting on the new changes, Max Schrems said, "Overall, this just looks like another attempt to ignore EU law by annoying people into consent with huge unskippable ads". He added, "Users must have an equal choice between ads that use their personal data and ads that do not. We doubt that Meta's fourth iteration of trying to bypass EU law will be accepted". Read More.

9. Danish Digital Agency Publishes Whitepaper On The Development, Implementation & Use Of AI Assistants In Denmark

Date: November 14, 2024
Summary: The Danish Digital Agency (Digitaliseringsstyrelsen) has published a whitepaper titled "Responsible Use of AI Assistants in the Public and Private Sector". Created in tandem with various public and private organizations, the whitepaper provides a framework for developing, implementing, and using AI assistants in Denmark.

The whitepaper contains key procedural steps defining the AI assistant's use case. It stresses the importance of ensuring all relevant data processing activities comply with legal frameworks such as the EU Artificial Intelligence Act (AI Act) and the General Data Protection Regulation (GDPR). To ensure responsible usage, it advocates for limiting the AI assistant's abilities while implementing structured quality assurance processes and measuring and storing all relevant storage data.

Organizational implementation measures, such as staff training, follow-up, and support structures to monitor and address issues, are also emphasized. With this comprehensive approach, the paper aims to enable the ethical and effective integration of AI assistants in both the public and private sectors while ensuring alignment with legal and ethical standards. Read More.

10. European Commission Releases The First Draft Of The General-Purpose AI Code of Practice

Date: November 14. 2024
Summary: The European Commission has released the First Draft General-Purpose AI Code of Practice after the September plenary meeting on the General-Purpose Artificial Intelligence (GPAI) Code of Practice. The draft comes at the end of the first of the planned four drafting phases. The first draft will serve as the foundational document, inviting shareholder feedback to refine the content of the final code.

The draft contains key guiding principles and objectives such as transparency and copyright rules for GPAI providers, a taxonomy of systemic risks, and specific rules for providers managing systemic risks. These rules will cover various safety and security frameworks, risk assessment, technical risk mitigation, and governance measures. Systemic risks associated with GPAI are also identified such as dangerous model capabilities, dangerous propensities, and contextual elements. There's additional guidance for providers on risk identification, evidence collection, and implementing safety and mitigation measures.

A dedicated plenary week will begin on November 18, 2024. Stakeholders, including representatives from EU member states and international observers, will participate in working group meetings to review the draft and provide feedback. Different working groups will focus on different aspects. Insights from these meetings will be presented to the full plenary on November 22, 2024, for further consideration. Read More.


Explore Securiti's Privacy Regulation roundup for the latest updates on global privacy developments. We're committed to providing you with timely updates and essential information to help you understand the evolving privacy regulatory landscape. You can also visit our dedicated page, offering an overview of global data privacy laws.

Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox


Share


More Stories that May Interest You

Videos

View More

Mitigation OWASP Top 10 for LLM Applications 2025

Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...

View More

DSPM vs. CSPM – What’s the Difference?

While the cloud has offered the world immense growth opportunities, it has also introduced unprecedented challenges and risks. Solutions like Cloud Security Posture Management...

View More

Top 6 DSPM Use Cases

With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...

View More

Colorado Privacy Act (CPA)

What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...

View More

Securiti for Copilot in SaaS

Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...

View More

Top 10 Considerations for Safely Using Unstructured Data with GenAI

A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....

View More

Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes

As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...

View More

Navigating CPRA: Key Insights for Businesses

What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...

View More

Navigating the Shift: Transitioning to PCI DSS v4.0

What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...

View More

Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)

AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 46:02

Building Safe Enterprise AI: A Practical Roadmap

Watch Now View
Spotlight 13:32

Ensuring Solid Governance Is Like Squeezing Jello

Watch Now View
Spotlight 40:46

Securing Embedded AI: Accelerate SaaS AI Copilot Adoption Safely

Watch Now View
Spotlight 10:05

Unstructured Data: Analytics Goldmine or a Governance Minefield?

Viral Kamdar
Watch Now View
Spotlight 21:30

Companies Cannot Grow If CISOs Don’t Allow Experimentation

Watch Now View
Spotlight 2:48

Unlocking Gen AI For Enterprise With Rehan Jalil

Rehan Jalil
Watch Now View
Spotlight 13:35

The Better Organized We’re from the Beginning, the Easier it is to Use Data

Watch Now View
Spotlight 13:11

Securing GenAI: From SaaS Copilots to Enterprise Applications

Rehan Jalil
Watch Now View
Spotlight 47:02

Navigating Emerging Technologies: AI for Security/Security for AI

Rehan Jalil
Watch Now View
Spotlight 59:55

Building Safe
Enterprise AI

Watch Now View

Latest

Automating EU AI Act Compliance View More

Automating EU AI Act Compliance: A 5-Step Playbook for GRC Teams

Artificial intelligence is revolutionizing industries, driving innovation in healthcare, finance, and beyond. But with great power comes great responsibility—especially when AI decisions impact health,...

Gencore AI Customers Can Now Securely Use DeepSeek R1 View More

Gencore AI Customers Can Now Securely Use DeepSeek R1

Enterprises are under immense pressure to use Generative AI to deliver innovative solutions, extract insights from massive volumes, and stay ahead of the competition....

Navigating Data Regulations in India’s Telecom Sector View More

Navigating Data Regulations in India’s Telecom Sector: Security, Privacy, Governance & AI

Gain insights into the key data regulations in India’s telecom sector and how they impact your business. Learn how Securiti helps ensure swift compliance...

Best Practices for Microsoft 365 Copilot View More

Data Governance Best Practices for Microsoft 365 Copilot

Learn key governance best practices for Microsoft 365 Copilot to ensure security, compliance, and effective implementation for optimal business performance.

5-Step AI Compliance Automation Playbook View More

EU AI Act: 5-Step AI Compliance Automation Playbook

Download the whitepaper to learn about the EU AI Act & its implication on high-risk AI systems, 5-step framework for AI compliance automation and...

A 6-Step Automation Guide View More

Say Goodbye to ROT Data: A 6-Step Automation Guide

Eliminate redundant obsolete and trivial (ROT) data with a strategic 6-step automation guide. Download the whitepaper today to discover how to streamline data management...

Texas Data Privacy and Security Act (TDPSA) View More

Navigating the Texas Data Privacy and Security Act (TDPSA): Key Details

Download the infographic to learn key details about Texas’ Data Privacy and Security Act (TDPSA) and simplify your compliance journey with Securiti.

Oregon’s Consumer Privacy Act (OCPA) View More

Navigating Oregon’s Consumer Privacy Act (OCPA): Key Details

Download the infographic to learn key details about Oregon’s Consumer Privacy Act (OCPA) and simplify your compliance journey with Securiti.

Gencore AI and Amazon Bedrock View More

Building Enterprise-Grade AI with Gencore AI and Amazon Bedrock

Learn how to build secure enterprise AI copilots with Amazon Bedrock models, protect AI interactions with LLM Firewalls, and apply OWASP Top 10 LLM...

DSPM Vendor Due Diligence View More

DSPM Vendor Due Diligence

DSPM’s Buyer Guide ebook is designed to help CISOs and their teams ask the right questions and consider the right capabilities when looking for...

What's
New