European Privacy Regulators Opine on Personal Data Processing in AI Model Training

The European Data Protection Board (EDPB) issued a detailed opinion on privacy implications for AI models under the GDPR. The opinion outlines key considerations including the application of the GDPR to AI Models trained on personal data, the applicability of the “legitimate interest” legal basis for training AI models on personal data, and the implications for AI models unlawfully trained ...

Bank of Israel Issues Proper Conduct of Banking Business Directive on Cybersecurity

Israel’s Supervisor of Banks has released a new directive – Proper Conduct of Banking Business Directive No. 364 – which consolidates and replaces three previous directives on information technology management, cybersecurity, and data protection (Directives 357, 361, and 363). This comprehensive update reflects the banking sector’s need to deal with the growing sophistication of cyber threats and the evolving privacy ...

New Australian Cyber Law Requires Notification of Ransomware Payouts

Australia has enacted a new law designed to improve cyber security for the country. The law addresses several key areas including mandatory security standards for internet-connectable products, ransomware reporting obligations, information sharing for significant cyber incidents, and the establishment of a Cyber Incident Review Board.

The law mandates security standards for relevant internet-connectable products. Manufacturers and suppliers of these products ...

Public Consultation on the Use of AI in the Financial Sector in Israel

An interdepartmental task force in Israel has released a draft interim report for public consultation addressing the integration of artificial intelligence (AI) in the financial sector, associated risks from predicted use in decision-making or human interactions, and proposed regulatory measures. The consultation period will end on December 15, 2024.

Key issues highlighted by the task force include transparency and explainability, ...

FTC Introduces "Click to Cancel" Rule for Easy Subscription Cancellation

The U.S. Federal Trade Commission (FTC) has announced a new "Click to Cancel" rule, mandating that businesses offer consumers a simple and straightforward way to cancel subscriptions at least as easily as signing up. The rule, primarily targeting "negative option" programs—where subscriptions automatically renew unless actively canceled by the consumer—will mostly come into effect in March 2025, 180 days after ...

New European Directive on Liability in Digital Products, Software, and AI Technology

The European Union Directive on liability for defective products came into force in December 2024 and will become effective from December 2026. It establishes common rules for the liability of economic operators for damages caused by defective products. The directive aims to enhance the EU market and ensure high consumer protection by addressing innovative technologies such as AI and global ...

UK Regulator Issues Guidance on Use of AI in Recruitment

The UK Information Commissioner’s Office (ICO) has published a report outlining recommendations for the fair and lawful use of artificial intelligence in screening job applicants. Following a sector-wide review, the ICO emphasized the importance of fairness, data minimization, and increased transparency in processing personal information for recruitment purposes.

AI tools can streamline recruitment by filtering unqualified candidates, scoring applicants against ...

U.S. Proposes Rules to Limit Sensitive Data Transfers to Foreign Adversaries

The U.S. Department of Justice (DoJ) has released a draft of new regulations aimed at restricting government agencies and private entities from transferring sensitive personal data to countries deemed adversaries to the U.S., namely China, Russia, North Korea, Iran, Venezuela, and Cuba. These rules are designed to implement a presidential executive order from February 2024.

The draft regulations target categories ...