Israeli Privacy Authority Issues Guidelines on Data Transfers and Tracking Tags

On July 8, 2024, the Israeli Privacy Protection Authority (PPA) published a draft opinion for public comments on transferring information outside Israel, interpreting Regulation 2(4) of the Privacy Protection (Transfers of Data to Databases Abroad) Regulations, 5761-2001.

According to the regulations, personal data can generally only be transferred outside Israel if the destination country ensures a level of data protection ...

U.S. Gov’t Bans Kaspersky from the U.S. Market

The U.S. Department of Commerce’s Bureau of Industry and Security (BIS) has prohibited Kaspersky Lab, Inc., the U.S. subsidiary of a Russian cybersecurity company, from directly or indirectly providing antivirus software and cybersecurity products or services in the U.S. or to U.S. persons. This ban also extends to Kaspersky’s affiliates, subsidiaries, and parent companies.

Following an extensive investigation, BIS concluded ...

European Commission Charges Meta and X with Violations of Online Services Laws

The European Commission has notified Meta of its preliminary finding that the company’s “Subscription for no ads” advertising model does not comply with the Digital Markets Act (DMA). This model forces EU users of Facebook and Instagram to choose between paying a monthly subscription fee to access an ad-free version or using a free version with personalized ads.

The DMA ...

Apple Sanctioned for Deleting Key Siri Recordings in Privacy Class Action

A federal judge in San Francisco has sanctioned Apple by prohibiting it from asserting certain defenses in an impending privacy class action lawsuit. This decision was prompted by the company’s deletion of crucial audio recordings of users’ interactions with its Siri voice assistant, which the plaintiffs argued were essential to their case.

The class action complaint alleged that Apple violated ...

European Securities Authority Issues Guidance on AI in Retail Investment Services

The European Securities and Markets Authority (ESMA) has issued guidance on the use of Artificial Intelligence in retail investment services to ensure firms comply with Markets in Financial Instruments Directive II (MiFID II) and prioritize clients’ best interests. According to the guidelines, despite variations in AI adoption across firms and Member States, AI’s potential impact on firm behavior and investor ...

CNIL Publishes New Recommendations for AI System Development and GDPR Compliance

The French Data Protection Authority (CNIL) has released its second series of recommendations for AI system developers, emphasizing GDPR compliance. Building on the initial guidance issued last month, this new series aims to balance innovation with respect for individual rights.

The new recommendations cover the following areas –

  • Legitimate interest is the primary legal basis for AI development, necessitating risk ...

Singapore Announces Updated Model Governance Framework for Generative AI

The Singapore Infocomm Media Development Authority (IMDA) and AI Verify Foundation have announced the publication of the Model AI Governance Framework for Generative AI. Initially published in 2019 and updated in 2020, the current iteration was released for public consultation in January 2024. This version aims to address specific artificial intelligence (AI) risks associated with generative AI, such as hallucinations ...

French Privacy Regulator Publishes AI Guidelines

The French Data Protection Authority (CNIL) has published final guidelines for developing AI systems with a strong focus on data protection. These guidelines are designed to support AI ecosystem players in complying with personal data protection legislation and offer practical solutions, illustrated with examples, for applying the rules of the GDPR to AI systems.

Essential elements of the guidelines include ...