Privacy Headlines
6 headlines in the database.
Data Protection Report · 9/15/2026
Anyone who contracts for internet or social-media-based advertising may have overlooked two recent actions by the California Privacy Protection Agency (CalPrivacy) and the proposed draft AI regulations from Colorado, but there are some important takeaways that should not be missed. California fines data broker over $100,000 for broker and privacy law issues California’s new data broker deletion requirements (known as the Delete Act) went into effect on August 1, 2026. On August 10, CalPrivacy announced an order against an Iowa data broker, LocateSmarter, LLC, alleging that the company violated both California’s data broker law and the California Consumer Privacy Act (CCPA). According to the order, LocateSmarter required consumers wishing to opt out of the sale or sharing of their personal data to submit not only their mailing addresses but also the last four digits of their Social Security numbers. The order found that this conduct violated CCPA because LocateSmarter: requi
Data Protection Report · 9/1/2026
As cyber incidents become more costly and complex, organisations are facing increasing exposure to personal data claims, mass actions and contractual disputes. We explore the key litigation trends, emerging risks and practical considerations shaping the UK data breach claims landscape. Read our briefing here
Data Protection Report · 8/18/2026
On August 5, 2026, the New York Department of Financial Services (NYDFS) entered into a consent order with Order Express, Inc., a money transmitter licensed by NYDFS. Although Order Express qualified for a limited exemption under the NYDFS cybersecurity regulation , NYDFS found that the company violated the regulation’s applicable requirements in three ways: (1) failure to “conduct a risk assessment sufficient to inform the design of its cybersecurity program”; (2) as a result of the risk assessment’s deficiencies, failure “to design a cybersecurity program based on the Company’s risk assessment and sufficient to identify and assess risks to NPI”; and (3) failure “to implement and maintain written cybersecurity policies addressing systems and network security.” Order Express agreed to pay $250,000. Although this consent order pertains to a limited exemption licensee, it remains relevant to larger covered entities not exempted from t
Data Protection Report · 7/21/2026
We recently published an article to commemorate AI Appreciation Day , but readers may also appreciate a law that recently passed In Rhode Island, known as the “ Use of Artificial Intelligence by Healthcare Providers Notification Act .” The bill went into effect on June 16, 2026. The law’s stated purpose is “is to ensure patients are properly notified of the use of artificial intelligence by healthcare providers.” The law contains three definitions, two for healthcare (“Healthcare providers” and “healthcare facility”), and the third definition is for AI: “any technology that can simulate human intelligence including, but not limited to, natural language processing, training language models, reinforcement learning from human feedback and machine learning systems.” Unlike many other states’ AI laws that can require multiple pages to explain, Section 23-106-3 of Rhode Island General Statutes reads in its entirety: Any
Data Protection Report · 7/16/2026
As artificial intelligence ( AI ) becomes embedded in business operations, data protection frameworks are increasingly shaping how organizations manage AI use. This update highlights key regulatory developments, including risk-based approaches and sector-specific rules, and outlines practical considerations for compliance, oversight and responsible deployment. Read the full article, “ AI Appreciation Day 2026: Regulations, risks and opportunities “.
Data Protection Report · 6/15/2026
Spain’s data protection agency, the Agencia Española de Protección de Datos ( AEPD ), has fined Amadeus IT Group, S.A. ( Amadeus ) €18 million in relation to a traveller profiling pilot project. The enforcement decision, published in May 2026, has found breaches of Article 14 and Article 6 REGULATION (EU) 2016/679 ( GDPR ). Amadeus has made a €14.4 million voluntary payment, representing a 20% reduction from the proposed total fine, and has stated that they intend to appeal the ruling. Background Amadeus is a major Global Distribution System ( GDS ) provider and is one of the largest travel booking networks used by airlines and travel agencies, responsible for processing the personal data of millions of individuals for bookings in the travel industry. Following an anonymous complaint on 26 September 2023, the AEPD initiated proceedings against Amadeus to investigate possible GDPR breaches in relation to a pilot scheme called ‘PLATAFORMA.1’ (the
Showing 1 - 6 of 6 results