What’s new in privacy?
Below are some of the most notable news in privacy from this month:
- Tennessee HB1181 clears state legislature. The Tennessee Information Protection Act has cleared the state legislature and is eligible for the Governor’s desk. If passed, this bill will provide privacy rights to residents of Tennessee such as the right to access, delete, correct, opt out, portability and anti-discrimination. In addition, companies that need to comply will need to update their Privacy Policies with new required disclosures. Read the full text of the bill here.
- House of Commons passes Canada’s Bill C-27. The House of Commons have passed Canada’s Bill C-27, which includes the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act and the Artificial Intelligence and Data Act. The bill aims to reform Canada’s current privacy law, PIPEDA. The bill is now headed to the Standing Committee on Industry and Technology for further consideration. Read the full text of the bill here.
- Meta prepares for GDPR fine and data transfers suspension order. In its filing to the U.S. Securities and Exchange Commission, Meta stated that it is preparing to halt operations and data transfers in the European Union. Meta is also preparing for a steep monetary fine and corrective measures from Ireland’s Data Protection Commission. Read more here.
- Maine introduces biometric privacy legislation. Members of the Maine Legislature have reintroduced a biometric information privacy bill (similar to Illinois BIPA), which would prohibit private entities from selling biometric information, would require written consent prior to the collection of biometric information, and would include a private right of action. Learn more here.
- German regulators investigate ChatGPT for GDPR compliance. The Commissioner for the northern German state of Schleswig-Holstein stated that regulators are investigating whether OpenAI has conducted a data protection impact assessment and if the data protection risks are under control as required by GDPR. Learn more here. Italy’s Data Protection Authority has ordered a temporary limitation of the processing of the data of Italian users by ChatGPT. In addition, the French Minister for Digital Transition and Telecommunications has said that ChatGPT violates GDPR.
- Italy’s Data Protection Authority publishes a guide on dark patterns. The guidance identifies the types of dark patterns in an aim to educate companies so that such dark patterns can be avoided in the future. Read more here.
- Italy’s Data Protection Authority issues a 300,000 euro fine to a marketing company. The company was fined for allegedly violating GDPR by using dark patterns on online portals to entice users to consent to the processing of personal data for marketing purposes. Read more here.
- Austrian Data Protection Authority rules against newspaper cookie paywalls. The Austrian Data Protection Authority ruled in favor of NOYB against multiple Austrian newspapers. The complaints stemmed from the newspapers using cookie paywalls that ask users to either agree to data sharing with tracking companies or pay for a tracking -free subscription. Learn more here.
- Tesla facing class-action lawsuit. Tesla is facing a class action lawsuit in the U.S. District Court for the Northern District of California for alleged privacy violations. The lawsuit alleges that Tesla employees accessed and shared videos and images recorded by customers’ vehicle cameras for their enjoyment. Read more here.
What privacy bills are we tracking?
As part of our service, we keep track of privacy bills that would affect the way Privacy Policies are written. Below is our most recent list of privacy bill proposals in the United States. You can access the privacy bill tracker any time on our blog.
- Georgia – GA HB798;
- Hawaii – HI SB1110/HB1497;
- Hawaii – HI SB 974;
- Illinois – IL HB3385;
- Indiana – IN HB 1554;
- Iowa – IA House File 2506;
- Iowa – IA House Study Bill 12;
- Kentucky – KY S 15;
- Louisiana – LA SB199;
- Maryland – MD HB807;
- Massachusetts – MA HD2281/SB745;
- Massachusetts – MA HD3263/SD1971;
- Mississippi – MS SB 2080;
- Minnesota – MN SF950;
- Montana – MT DB1086;
- New Hampshire – NH SB255;
- New York – NY S2277;
- New York – NY SB365;
- New York – NY SB3162;
- New York – NY AB4374;
- New Jersey – NJ S 332;
- New Jersey – NJ A505;
- New Jersey – NJ A 1971;
- North Carolina – NC SB525;
- Oklahoma – OK HB1030;
- Tennessee – TN SB73;
- Pennsylvania – PA HB708;
- Washington – WA HB1616;
- West Virginia – WV HB3453;
- Vermont – VT HB121
Here are some great virtual events that you can attend to learn more about the hottest issues in privacy and meet other privacy professionals:
- Transatlantic Privacy: Comparing the current state of US and EU privacy laws – May 9;
- FinTech and Data Privacy in the Metaverse – June 27;
- How to use the CNIL PIA and NIST PRAM Toolkits – May 18.
Do you have any questions on how Termageddon’s policy generation process works or how we can help you save time when drafting policies for your clients?
Please contact our President, Donata Stroink-Skillrud at Donata@termageddon.com and she’d be happy to set up a call to answer any questions that you may have.