U S. privacy outlook for 2025: Horror vacui

Share

privacy regulation news

Algorithmic bias has been a growing concern regarding the use of AI technology for the FTC under former FTC chair, Lina Khan. If Meador is confirmed, the FTC will be led by a Republican majority for the first time since Commissioner Bedoya was confirmed in 2022. Meador has vocally supported efforts to regulate big technology companies and has called for increased antitrust enforcement.

  • While the proposal has not been formally introduced and remains in draft form, the bipartisan support suggests the bill could get serious consideration.
  • This ensures a balance between transparency and safeguarding individuals’ private information.
  • The Essential CPGs include mitigating known vulnerabilities, email security, multifactor authentication, basic workforce cybersecurity training, strong encryption for data in transit, unique credentials for all workforce members, and revoking credentials for departing workforce members.
  • At the third EU–Japan Digital Partnership Council meeting in Tokyo, both sides reaffirmed their commitment to closer collaboration on strategic technologies and digital governance.
  • Consumers gained the right to opt out of targeted advertising, data sales, and profiling.
  • Other key provisions include restrictions on data brokers and prohibitions on the discriminatory application of algorithms in violation of civil rights.

David Martin, senior legal officer at the European Consumer Organisation, an umbrella group of 43 consumer groups, says tech company lobbyists are working to influence the guidelines to interpret GDPR and weaken the ePrivacy language. Under those rules, which are in the process of being ratified into law, consent is the only legal basis for collecting personal data. In the https://www.gakuseimansion.info/getting-started-next-steps-50/ digital realm, EU consumers also have the added protection of a companion set of rules, called the ePrivacy Directive, that govern electronic communication.

privacy regulation news

The law requires social media platforms to obtain verifiable parental consent before allowing minors to create accounts. This signals a global push to translate high-level privacy principles into concrete legal obligations and to close long-standing gaps in enforcement. Asia-Pacific jurisdictions introduced stricter cross-border transfer rules and biometric protections. A new bureau focused on data privacy would be created within the FTC, which would have the authority to enact new rules as technology changes. One provision of the proposal would allow consumers to opt out of targeted ads — i.e., advertisements sent to them based on their personal data. EU finds TikTok violates its digital rule book by failing to protect privacy of minors

Data Privacy & AI Issues To Watch For The Rest Of 2026

  • They stated that the current privacy legal landscape is a “conflicting patchwork of privacy laws” that will cost the U.S. economy over $1 trillion over the next decade.
  • The rule also requires covered entities to obtain signed attestations for specific requests related to reproductive health care and mandates that these entities update their Notice of Privacy Practices to reflect these new privacy protections.
  • Given the plethora of new legislation that has emerged globally in recent years, the directory has required some renovation.
  • If you’ve ever clicked through one of those annoying “cookie” notifications or been forced to scroll to the end of a privacy policy before you can use software, you’ve had a glimpse at how such laws can have a detrimental effect on your day-to-day experience.
  • Oregon residents can access, correct, delete, and opt out of targeted advertising, data sales, and automated profiling.

“Every time we click, these companies are trying to figure out, is this a valuable person or this is a worthless person? Now, EU consumers will have the freedom to opt in, rather than the burden of opting out. In March, Drawbridge, an ad-tech company that tracks users across devices, said it would wind down its advertising business in the EU because it’s unclear how the digital ad industry would ensure consumer consent. Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Big data brokers lobbied with millions of dollars to get the public data exemption into the CPRA so they would be allowed to sell the personal data of hundreds of millions of Americans completely legally and exempt from the CPRA. As government regulations lag behind, I believe it’s actually in businesses’ own interests to voluntarily honor privacy rights requests regardless of where the person lives or what type of business they are.

This could be the GDPR effect reaching different parts of the globe, or it could be reasonably attributed to the worldwide realization of the need to protect the personal information of individuals in an age of constant digital connection. Additionally, a number of African nations, including Nigeria, Kenya and South Africa, passed comprehensive privacy legislation in the past several years. Geographically, a boom in law and policy updates has occurred in the Asia-Pacific region. Meanwhile, another group of countries, including New Zealand, Singapore and Switzerland, amended their existing privacy laws to be more robust and reflective of technological advancements since their initial passage. For instance, in the 2020s a handful of countries, including Brazil, Thailand, China, Saudi Arabia and India, enacted their first comprehensive data privacy and protection laws..

privacy regulation news

Sensitive data, ad tech and data brokers

As a representative example, Virginia provides that businesses may comply with a request to delete by “opting the consumer out of the processing of such personal data for any purpose except for those exempted pursuant to the provisions of this chapter.” Va. Profiling which is to evaluate, analyze, or predict personal aspects related to an identified or identifiable natural person’s economic situation, health, personal preferences, interests, reliability, behavior, location, or movements automated decisionmaking in furtherance of decisions that produce legal or similarly significant effects concerning the consumer.” Va. See, e.g., Virginia provides an opt out right of “the processing of the personal data for the purposes of . Plaintiffs alleged that both state privacy statutes provide a private right of action for the unlawful retention of personal information, but the Ninth Circuit disagreed, holding that neither of the privacy statutes had such a private right of action.

privacy regulation news

In 2024, the FTC continued to pursue enforcement actions against major technology companies in relation to children’s and teens’ privacy. In 2023, the FTC also sought comment on the Entertainment Software Rating Board’s (ESRB) application for a “Privacy-Protective Facial Age Estimation” technology that analyzes a user’s face to confirm their age, which would serve as a consent mechanism under COPPA’s requirement that https://www.23ch.info/how-i-became-an-expert-on-13/ parents consent to an online service collecting their children’s personal data. For example, a common settlement term requires companies to implement information privacy programs and abstain from misleading consumers about the strength and integrity of their consumer privacy measures. Pursuant to Section 6(b) of the FTC Act, the FTC issued orders to eight firms, including financial services firms, that advertise using customer information and machine learning technologies to engage in targeted pricing to consumers.

privacy regulation news

  • The policy statement specified that making unsubstantiated marketing claims regarding the validity, reliability, accuracy, performance, fairness, or efficacy of technologies relying on biometric information constitute deceptive practices under Section 5 of the FTC Act.
  • To date, public actions have only been filed in California and Texas, although other state Attorneys General continue to serve non-public violation notices, requests for information, or civil investigative demands, and this is expected to increase as more state laws go into effect.
  • Each disclosure made with patient consent must include a copy of the consent or a clear explanation of the scope of the consent.
  • It includes rules for privacy notices, data security, and bans on obtaining information under false pretenses.

A 2022 ransomware attack affected the PHI of 14,273 patients at Bryan County Ambulance Authority (BCAA), prompting OCR’s investigation into the entity’s alleged failure to conduct a proper risk analysis. The disclosure allegedly included the patient’s obstetric and gynecological history, as well as “other sensitive health information concerning reproductive health care.” The HHS complaint stated that Holy Redeemer Family Medicine violated the HIPAA privacy rule because it lacked the adequate consent for the release of the full medical record. OCR also found that Clearway Pain Solutions Institute failed to conduct a thorough risk analysis of potential vulnerabilities to electronic protected health information (ePHI) and failed to terminate former workforce members’ access to ePHI. The SEC took the position that this violated the Regulation Systems Compliance and Integrity (Reg-SCI) by preventing the subsidiary exchanges from making their own timely disclosures to the SEC. The SEC alleged that the parent company of a number of stock exchanges waited several days after learning about a cyberattack to inform compliance and legal officials at the subsidiary exchanges. The court reasoned that the SEC’s position that its authority to regulate an issuer’s “system of internal accounting controls” includes the authority to regulate cybersecurity controls was “not tenable,” and unsupported by the statute, legislative intent, or precedent.

Scroll to Top