Announcing Agent Commander - The First Integrated solution from Veeam + Securiti.ai enabling the scaling of safe AI agents

View

Privacy Regulation Roundup: Top Stories of September 2024

Contributors

Anas Baig

Product Marketing Manager at Securiti

Muhammad Ismail

Assoc. Data Privacy Analyst at Securiti

Syed Tatheer Kazmi

Data Privacy Analyst

CIPP/Europe

Salma Khan

Data Privacy Analyst at Securiti

CIPP/Asia

Usman Tariq

Data Privacy Analyst at Securiti

CIPP/US

Rohma Fatima Qayyum

Associate Data Privacy Analyst at Securiti

Published September 23, 2024 / Updated December 4, 2025

Securiti has started a Privacy Regulation Roundup summarizing the latest significant global privacy regulatory developments, announcements, and changes. These developments will be added to our website monthly. You can find a link to related resources at the bottom for each relevant regulatory activity.

North and South America Jurisdiction

1. New CPPA Advisory Makes Recommendations For Businesses To Avoid Dark Patterns On Their Platforms

Date: 4th September, 2024
Summary: The California Privacy Protection Agency (CPPA) issued Enforcement Advisory No. 2024-02, titled “Avoiding Dark Patterns: Clear and Understandable Language, Symmetry in Choice”.

This advisory clarifies the exact definition of “dark patterns.” Under the new definition, any user interfaces or choice features that substantially subvert or impair a consumer’s autonomy, decision-making, or choice will be considered such.
Additionally, the advisory recommends that the methods of gaining consumer consent and submitting CPRA-related requests be easy to read, understand, and written in clear, technical, or legal jargon-free language.

Lastly, a consumer’s path when exercising any of their privacy-protection options must not be longer, more complex, or time-consuming than the path to exercise a none privacy-protection one, as this would impair or interfere with their ability to make a free choice.

An example would be providing users the option to either say “Yes” or “Ask me later” when deciding to opt out of the sale/sharing of their personal information, as it would require more steps to opt-out. A better option, in this case, would be to provide a clear option to say “Yes” or “No” and a website banner that offers the choice to “Accept All” or “Decline All”.

All user interfaces, including those deployed via service providers such as consent management platforms, must be properly assessed and reviewed. Read more.

2. Quebec's CAI Issues Guidance on Organizational Obligations Related to Users' Right to Portability

Date: 5th September, 2024
Summary: The Quebec Commission on Access to Information (CAI) has announced legislative provisions related to the portability of personal information will come into effect on September 22, 2024.

CAI has issued guidance on organizations' obligations related to the right of portability. Per this guidance, users may request the transfer of their personal data to other authorized persons or companies. The guidance notes that while organizations are under no legal obligation to implement interoperable systems, it would facilitate smooth and efficient data transfers.

For the right to data portability to be applicable, the following conditions need to be met:

  • The data must be computerized, meaning it is structured and organized using information technology;
  • The data must have been directly or indirectly collected from the individual. This includes information generated by the individual's activities, such as purchase history or driving habits. However, created or inferred data, such as risk assessments by insurance companies, are excluded from this right, as they are not directly collected from the individual; and
  • Data obtained from third parties or generated by algorithms does not qualify for portability.

All requests for data portability will follow the same procedure as access and rectification requests. Organizations must also have appropriate security measures in place when transmitting personal information. Users may file for a review with the CAI if they feel dissatisfied with any organization's response.

The guidance states that fulfilling data portability requests will present serious practical difficulties. Hence, they will be subject to case-to-case interpretation, with factors such as excessive costs or technical complexity considered serious difficulties. Read more.

3. Canada's Court of Appeal Reverses Federal Court Order In Facebook PIPEDA Violations Case

Date: 9th September, 2024
Summary: The Federal Court of Appeal in Canada has reversed the Federal Court's decision and ruled in favor of the OPC in the case of Privacy Commissioner of Canada vs. Facebook. The Federal Court found that Facebook's practices between 2013 and 2015 violated PIPEDA's provisions on consent and security.

The OPC had filed an appeal against the Federal Court's decision, alleging that it had failed to illustrate how Facebook had breached PIPEDA. The OPC's proceedings against Facebook began in 2019 against its practice of sharing Facebook users' personal information with third-party apps hosted on Facebook. These proceedings came after OPC's investigation into the app “thisisyourdigitallife” (TYDL) scraping user data and subsequent selling of the data to Cambridge Analytica Ltd. for psychographic modeling purposes between November 2013 and December 2015.

The Court of Appeal has now determined that the Federal Court erred when it relied exclusively or in large part on the absence of expert and subjective evidence. Furthermore, the Federal Court failed to appropriately inquire into the existence or adequacy of the consent given by friends of users who downloaded such applications separate from the installation of such applications.

Consequently, the Court of Appeal has now asked both the OPC and Facebook to report back within 90 days whether they've agreed on the terms of a remedial order. Read more.

EU Jurisdiction

4. German Federal Ministry For Digital and Transport Introduces Ordinance Related To User Consent Management

Date: 4th September, 2024
Summary: The German Federal Ministry for Digital and Transport has introduced the Consent Management Ordinance. The ordinance contains requirements related to cookie banners and user consent. It requires consent management services to store user settings, provide transparent information, and allow users to revoke consent at any time. Furthermore, these services must allow users to export these settings while switching to other services, guaranteeing data protection. These consent management services must apply to the Federal Commissioner for Data Protection and Freedom of Information to be recognized. They must also declare that they will only process personal information for consent management and provide security information. The ordinance aims to ensure user-friendly consent management procedures and enters into effect on the first day of the quarter following its publication. Read more.

5. Croatia’s Data Protection Agency Issues Guidance On Employers’ Collecting Employee ID Cards

Date: 6th September, 2024
Summary:The Personal Data Protection Agency (AZOP) provided guidance on collecting employees’ identity cards, as described in the Ordinance on Content and Method of Keeping Records on Workers by Employers, citing increased inquiries on the issue.

AZOP clarified that the Ordinance does not require employers to retain a copy of an employee’s identity card, nor is it a legal obligation per Article 6(1)(c) the GDPR. Furthermore, employers must ensure the security of the employees’ personal data, and retaining copies of their identity cards represents a high risk of unauthorized or unlawful processing.

In any case, if an employer does choose to store copies of identity cards, they should have a legal basis to do so. Additionally, AZOP recommended that any personal data on the identity card that is not relevant, necessary, or appropriate for the purpose of the collection be redacted or obscured by the employer. Read more.

6. European Commission Plans to Seek Public Input on New Additions To SCCs

Date: 12th September, 2024
Summary: The European Commission announced its intention to seek public input on Standard Contractual Clauses (SCCs) under the GDPR in the last quarter of 2024. The prospective new rules will apply when the data importer, whether a controller or processor, is based in a third country but is subject to the GDPR. These new rules will complement the existing SCCs designed for data importers in third countries not bound by the GDPR. Read more.


Explore Securiti's Privacy Regulation roundup for the latest updates on global privacy developments. We're committed to providing you with timely updates and essential information to help you understand the evolving privacy regulatory landscape. You can also visit our dedicated page, offering an overview of global data privacy laws.

Analyze this article with AI

Prompts open in third-party AI tools.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox



More Stories that May Interest You
Videos
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...
AWS Startup Showcase Cybersecurity Governance With Generative AI View More
AWS Startup Showcase Cybersecurity Governance With Generative AI
Balancing Innovation and Governance with Generative AI Generative AI has the potential to disrupt all aspects of business, with powerful new capabilities. However, with...

Spotlight Talks

Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Spotlight 47:42
Cybersecurity – Where Leaders are Buying, Building, and Partnering
Rehan Jalil
Watch Now View
Spotlight 27:29
Building Safe AI with Databricks and Gencore
Rehan Jalil
Watch Now View
Spotlight 46:02
Building Safe Enterprise AI: A Practical Roadmap
Watch Now View
Latest
View More
Introducing Agent Commander
The promise of AI Agents is staggering— intelligent systems that make decisions, use tools, automate complex workflows act as force multipliers for every knowledge...
Risk Silos: The Biggest AI Problem Boards Aren’t Talking About View More
Risk Silos: The Biggest AI Problem Boards Aren’t Talking About
Boards are tuned in to the AI conversation, but there’s a blind spot many organizations still haven’t named: risk silos. Everyone agrees AI governance...
Largest Fine In CCPA History_ What The Latest CCPA Enforcement Action Teaches Businesses View More
Largest Fine In CCPA History: What The Latest CCPA Enforcement Action Teaches Businesses
Businesses can take some vital lessons from the recent biggest enforcement action in CCPA history. Securiti’s blog covers all the important details to know.
View More
AI & HIPAA: What It Means and How to Automate Compliance
Explore how the Health Insurance Portability and Accountability Act (HIPAA) applies to Artificial Intelligence (AI) in securing Protected Health Information (PHI). Learn how to...
Building A Secure AI Foundation For Financial Services View More
Building A Secure AI Foundation For Financial Services
Access the whitepaper and discover how financial institutions eliminate Shadow AI, enforce real-time AI policies, and secure sensitive data with a unified DataAI control...
Indiana, Kentucky & Rhode Island Privacy Laws View More
Indiana, Kentucky & Rhode Island Privacy Laws: What Changed & What Businesses Should Do Now
A breakdown of new data privacy laws in Indiana, Kentucky, and Rhode Island—key obligations, consumer rights, enforcement timelines, and what businesses should do now.
Agentic AI Security: OWASP Top 10 with Enterprise Controls View More
Agentic AI Security: OWASP Top 10 with Enterprise Controls
Map the OWASP Top 10 risks for agentic AI to enterprise-grade controls, identity, data security, guardrails, monitoring, and governance to stop autonomous AI abuse.
View More
Strategic Priorities For Security Leaders In 2026
Securiti's whitepaper provides a detailed overview of the three-phased approach to AI Act compliance, making it essential reading for businesses operating with AI. Category:...
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New