Privacy Headlines

3 headlines in the database.

Internet privacy updates: CalPrivacy fines data brokers, Colorado proposes new AI regulations

Data Protection Report · 9/15/2026

Anyone who contracts for internet or social-media-based advertising may have overlooked two recent actions by the California Privacy Protection Agency (CalPrivacy) and the proposed draft AI regulations from Colorado, but there are some important takeaways that should not be missed. California fines data broker over $100,000 for broker and privacy law issues California’s new data broker deletion requirements (known as the Delete Act) went into effect on August 1, 2026. On August 10, CalPrivacy announced an order against an Iowa data broker, LocateSmarter, LLC, alleging that the company violated both California’s data broker law and the California Consumer Privacy Act (CCPA). According to the order, LocateSmarter required consumers wishing to opt out of the sale or sharing of their personal data to submit not only their mailing addresses but also the last four digits of their Social Security numbers. The order found that this conduct violated CCPA because LocateSmarter: requi

fine
NYDFS levies $250,000 fine on licensee for inadequate cyber risk assessment

Data Protection Report · 8/18/2026

On August 5, 2026, the New York Department of Financial Services (NYDFS) entered into a consent order with Order Express, Inc., a money transmitter licensed by NYDFS. Although Order Express qualified for a limited exemption under the NYDFS cybersecurity regulation , NYDFS found that the company violated the regulation’s applicable requirements in three ways: (1) failure to “conduct a risk assessment sufficient to inform the design of its cybersecurity program”; (2) as a result of the risk assessment’s deficiencies, failure “to design a cybersecurity program based on the Company’s risk assessment and sufficient to identify and assess risks to NPI”; and (3) failure “to implement and maintain written cybersecurity policies addressing systems and network security.” Order Express agreed to pay $250,000. Although this consent order pertains to a limited exemption licensee, it remains relevant to larger covered entities not exempted from t

fine
Record €18m fine for an IT service provider to the aviation sector – reuse of customer data

Data Protection Report · 6/15/2026

Spain’s data protection agency, the Agencia Española de Protección de Datos ( AEPD ), has fined Amadeus IT Group, S.A. ( Amadeus ) €18 million in relation to a traveller profiling pilot project. The enforcement decision, published in May 2026, has found breaches of Article 14 and Article 6 REGULATION (EU) 2016/679 ( GDPR ). Amadeus has made a €14.4 million voluntary payment, representing a 20% reduction from the proposed total fine, and has stated that they intend to appeal the ruling. Background Amadeus is a major Global Distribution System ( GDS ) provider and is one of the largest travel booking networks used by airlines and travel agencies, responsible for processing the personal data of millions of individuals for bookings in the travel industry. Following an anonymous complaint on 26 September 2023, the AEPD initiated proceedings against Amadeus to investigate possible GDPR breaches in relation to a pilot scheme called ‘PLATAFORMA.1’ (the

fine

Showing 1 - 3 of 3 results

Page 1 of 1