Future of Privacy Forum Launches the FPF Center for Artificial Intelligence
The FPF Center for Artificial Intelligence will serve as a catalyst for AI policy and compliance leadership globally, advancing responsible data and AI practices for public and private stakeholders
Today, the Future of Privacy Forum (FPF) launched the FPF Center for Artificial Intelligence, established to better serve policymakers, companies, non-profit organizations, civil society, and academics as they navigate the challenges of AI policy and governance. The Center will expand FPF’s long-standing AI work, introduce large-scale novel research projects, and serve as a source for trusted, nuanced, nonpartisan, and practical expertise.
FPF’s Center work will be international as AI continues to deploy globally and rapidly. Cities, states, countries, and international bodies are already grappling with implementing laws and policies to manage the risks.“Data, privacy, and AI are intrinsically interconnected issues that we have been working on at FPF for more than 15 years, and we remain dedicated to collaborating across the public and private sectors to promote their ethical, responsible, and human-centered use,” saidJules Polonetsky, FPF’s Chief Executive Officer. “But we have reached a tipping point in the development of the technology that will affect future generations for decades to come. At FPF, the word Forum is a core part of our identity. We are a trusted convener positioned to build bridges between stakeholders globally, and we will continue to do so under the new Center for AI, which will sit within FPF.”
The Center will help the organization’s 220+ members navigate AI through the development of best practices, research, legislative tracking, thought leadership, and public-facing resources. It will be a trusted evidence-based source of information for policymakers, and it will collaborate with academia and civil society to amplify relevant research and resources.
“Although AI is not new, we have reached an unprecedented moment in the development of the technology that marks a true inflection point. The complexity, speed and scale of data processing that we are seeing in AI systems can be used to improve people’s lives and spur a potential leapfrogging of societal development, but with that increased capability comes associated risks to individuals and to institutions,” saidAnne J. Flanagan, Vice President for Artificial Intelligence at FPF. “The FPF Center for AI will act as a collaborative force for shared knowledge between stakeholders to support the responsible development of AI, including its fair, safe, and equitable use.”
The Center will officially launch at FPF’s inaugural summit DC Privacy Forum: AI Forward. The in-person and public-facing summit will feature high-profile representatives from the public and private sectors in the world of privacy, data and AI.
FPF’s new Center for Artificial Intelligence will be supported by a Leadership Council of leading experts from around the globe. The Council will consist of members from industry, academia, civil society, and current and former policymakers.
See the full list of founding FPF Center for AI Leadership Council members here.
I am excited about the launch of the Future of Privacy Forum’s new Center for Artificial Intelligence and honored to be part of its leadership council. This announcement builds on many years of partnership and collaboration between Workday and FPF to develop privacy best practices and advance responsible AI, which has already generated meaningful outcomes, including last year’s launch of best practices to foster trust in this technology in the workplace. I look forward to working alongside fellow members of the Council to support the Center’s mission to build trust in AI and am hopeful that together we can map a path forward to fully harness the power of this technology to unlock human potential.
Barbara Cosgrove, Vice President, Chief Privacy Officer, Workday
I’m honored to be a founding member of the Leadership Council of the Future of Privacy Forum’s new Center for Artificial Intelligence. AI’s impact transcends borders, and I’m excited to collaborate with a diverse group of experts around the world to inform companies, civil society, policymakers, and academics as they navigate the challenges and opportunities of AI governance, policy, and existing data protection regulations.
Dr. Gianclaudio Malgieri, Associate Professor of Law & Technology at eLaw, University of Leiden
“As we enter this era of AI, we must require the right balance between allowing innovation to flourish and keeping enterprises accountable for the technologies they create and put on the market. IBM believes it will be crucial that organizations such as the Future of Privacy Forum help advance responsible data and AI policies, and we are proud to join others in industry and academia as part of the Leadership Council.”
Christina Montgomery, Chief Privacy & Trust Officer, AI Ethics Board Chair, IBM
The Future of Privacy Forum (FPF) is a global non-profit organization that brings together academics, civil society, government officials, and industry to evaluate the societal, policy, and legal implications of data use, identify the risks, and develop appropriate protections.
FPF believes technology and data can benefit society and improve lives if the right laws, policies, and rules are in place. FPF has offices in Washington D.C., Brussels, Singapore, and Tel Aviv. Learn more at fpf.org.
FPF Develops Checklist & Guide to Help Schools Vet AI Tools for Legal Compliance
FPF’s Youth and Education team has developed a checklist and accompanying policy brief to help schools vet generative AI tools for compliance with student privacy laws. Vetting Generative AI Tools for Use in Schools is a crucial resource as the use of generative AI tools continues to increase in educational settings. It’s critical for school leaders to understand how existing federal and state student privacy laws, such as the Family Educational Rights and Privacy Act (FERPA) apply to the complexities of machine learning systems to protect student privacy. With these resources, FPF aims to provide much-needed clarity and guidance to educational institutions grappling with these issues.
“AI technology holds immense promise in enhancing educational experiences for students, but it must be implemented responsibly and ethically,” said David Sallay, the Director for Youth & Education Privacy at the Future of Privacy Forum. “With our new checklist, we aim to empower educators and administrators with the knowledge and tools necessary to make informed decisions when selecting generative AI tools for classroom use while safeguarding student privacy.”
The checklist, designed specifically for K -12 schools, outlines key considerations when incorporating generative AI into a school or district’s edtech vetting checklist.
These include:
assessing the requirements for vetting all edtech;
describing the specific use cases;
preparing to address transparency and explainability; and
determining if student PII will be used to train the large language model (LLM).
By prioritizing these steps, educational institutions can promote transparency and protect student privacy while maximizing the benefits of technology-driven learning experiences for students.
The in-depth policy brief outlines the relevant laws and policies a school should consider, the unique compliance considerations of generative AI tools (including data collection, transparency and explainability, product improvement, and high-risk decision-making), and their most likely use cases (student, teacher, and institution-focused).
The brief also encourages schools and districts to update their existing edtech vetting policies to address the unique considerations of AI technologies (or to create a comprehensive policy if one does not already exist) instead of creating a separate vetting process for AI. It also highlights the role that state legislatures can play in ensuring the efficiency of school edtech vetting and oversight and calls on vendors to be proactively transparent with schools about their use of AI.
Check out the LinkedIn Live with CEO Jules Polonetsky and Youth & Education Director David Sallay about the Checklist and Policy Brief.
To read more of the Future of Privacy Forum’s youth and student privacy resources, visitwww.StudentPrivacyCompass.org.
FPF Releases “The Playbook: Data Sharing for Research” Report and Infographic
Facilitating data sharing for research purposes between corporate data holders and academia can unlock new scientific insights and drive progress in public health, education, social science, and a myriad of other fields for the betterment of the broader society. Academic researchers use this data to consider consumer, commercial, and scientific questions at a scale they cannot reach using conventional research data-gathering techniques alone. This data also helped researchers answer questions on topics ranging from bias in targeted advertising and the influence of misinformation on election outcomes to early diagnosis of diseases through data collected by fitness and health apps.
The playbook addresses vital steps for data management, sharing, and program execution between companies and researchers. Creating a data-sharing ecosystem that positively advances scientific research requires a better understanding of the established risks, opportunities to address challenges, and the diverse stakeholders involved in data-sharing decisions. This report aims to encourage safe, responsible data-sharing between industries and researchers.
“Corporate data sharing connects companies with research institutions, by extension increasing the quantity and quality of research for social good,” said Shea Swauger, Senior Researcher for Data Sharing and Ethics. “This Playbook showcases the importance, and advantages, of having appropriate protocols in place to create safe and simple data sharing processes.”
In addition to the Playbook, FPF created a companion infographic summarizing the benefits, challenges, and opportunities of data sharing for research outlined in the larger report.
As a longtime advocate for facilitating the privacy-protective sharing of data by industry to the research community, FPF is proud to have created this set of best practices for researchers, institutions, policymakers, and data-holding companies. In addition to the Playbook, the Future of Privacy Forum has also opened nominations for its annual Award for Research Data Stewardship.
“Our goal with these initiatives is to celebrate the successful research partnerships transforming how corporations and researchers interact with each other,” Swauger said. “Hopefully, we can continue to engage more audiences and encourage others to model their own programs with solid privacy safeguards.”
Shea Swauger, Senior Researcher for Data Sharing and Ethics, Future of privacy Forum
Established by FPF in 2020 with support from The Alfred P. Sloan Foundation, the Award for Research Data Stewardship recognizes excellence in the privacy-protective stewardship of corporate data shared with academic researchers. The call for nominations is open and closes on Tuesday, January 17, 2023. To submit a nomination, visit the FPF site.
FPF has also launched a newly formed Ethics and Data in Research Working Group; this group receives late-breaking analyses of emerging US legislation affecting research and data, meets to discuss the ethical and technological challenges of conducting research, and collaborates to create best practices to protect privacy, decrease risk, and increase data sharing for research, partnerships, and infrastructure. Learn more and join here.
FPF Testifies Before House Subcommittee on Energy and Commerce, Supporting Congress’s Efforts on the “American Data Privacy and Protection Act”
This week, FPF’s Senior Policy Counsel Bertram Lee testified before the U.S. House Energy and Commerce Subcommittee on Consumer Protection and Commerce hearing, “Protecting America’s Consumers: Bipartisan Legislation to Strengthen Data Privacy and Security” regarding the bipartisan, bicameral privacy discussion draft bill, “American Data Privacy and Protection Act” (ADPPA). FPF has a history of supporting the passage of a comprehensive federal consumer privacy law, which would provide businesses and consumers alike with the benefit of clear national standards and protections.
Lee’s testimony opened by applauding the Committee on its efforts towards comprehensive federal privacy legislation and emphasized the “time is now” for its passage. As it is written, the ADPPA would address gaps in the sectoral approach to consumer privacy, establish strong national civil rights protections, and establish new rights and safeguards for the protection of sensitive personal information.
“The ADPPA is more comprehensive in scope, inclusive of civil rights protections, and provides individuals with more varied enforcement mechanisms in comparison to some states’ current privacy regimes,” Lee said in his testimony. “It also includes corporate accountability mechanisms, such as the requiring privacy designations, data security offices, and executive certifications showing compliance, which is missing from current states’ laws. Notably, the ADPPA also requires ‘short-form’ privacy notices to aid consumers of how their data will be used by companies and their rights — a provision that is not found in any state law.”
Lee’s testimony also provided four recommendations to strengthen the bill, which include:
Additional funding and resources for the FTC;
Developing a more iterative process to ensure that the bill can keep up with evolving technologies;
Clarifying the intersection of ADPPA with other federal privacy laws (COPPA, FERPA, HIPAA, etc.); and
Establishing clear definitions and distinctions between different types of covered entities, including service providers.
Many of the recommendations would ensure that the legislation gives individuals meaningful privacy rights and places clear obligations on businesses and other organizations that collect, use and share personal data. The legislation would expand civil rights protections for individuals and communities harmed by algorithmic discrimination as well as require algorithmic assessments and evaluations to better understand how these technologies can impact communities.
Reading the Signs: the Political Agreement on the New Transatlantic Data Privacy Framework
The President of the United States, Joe Biden, and the President of the European Commission, Ursula von der Leyen, announced last Friday, in Brussels, a political agreement on a new Transatlantic framework to replace the Privacy Shield.
This is a significant escalation of the topic within Transatlantic affairs, compared to the 2016 announcement of a new deal to replace the Safe Harbor framework. Back then, it was Commission Vice-President Andrus Ansip and Commissioner Vera Jourova who announced at the beginning of February 2016 that a deal had been reached.
The draft adequacy decision was only published a month after the announcement, and the adequacy decision was adopted 6 months later, in July 2016. Therefore, it should not be at all surprising if another 6 months (or more!) pass before the adequacy decision for the new Framework will produce legal effects and actually be able to support transfers from the EU to the US. Especially since the US side still has to pass at least one Executive Order to provide for the agreed-upon new safeguards.
This means that transfers of personal data from the EU to the US may still be blocked in the following months – possibly without a lawful alternative to continue them – as a consequence of Data Protection Authorities (DPAs) enforcing Chapter V of the General Data Protection Regulation in the light of the Schrems II judgment of the Court of Justice of the EU, either as part of the 101 noyb complaints submitted in August 2020 and slowly starting to be solved, or as part of other individual complaints/court cases.
If you are curious about what the legal process will look like both on the US and EU sides after the agreement “in principle”, check out this blog post by Laila Abdelaziz of the “Privacy across borders project” at American University.
After the agreement “in principle” was announced at the highest possible political level, EU Justice Commissioner Didier Reynders doubled down on the point that this agreement is reached “on the principles” for a new framework, rather than on the details of it. Later on he also gave credit to Commerce Secretary Gina Raimondo and US Attorney General Merrick Garland for their hands-on involvement in working towards this agreement.
In fact, “in principle” became the leitmotif of the announcement, as the first EU Data Protection Authority to react to the announcement was the European Data Protection Supervisor, who wrote that he “Welcomes, in principle”, the announcement of a new EU-US transfers deal – “The details of the new agreement remain to be seen. However, EDPS stresses that a new framework for transatlantic data flows must be sustainable in light of requirements identified by the Court of Justice of the EU”.
Of note, there is no catchy name for the new transfers agreement, which was referred to as the “Trans-Atlantic Data Privacy Framework”. Nonetheless, FPF’s CEO Jules Polonetsky submits the “TA DA!” Agreement, and he has my vote. For his full statement on the political agreement being reached, see our release here.
Some details of the “principles” agreed on were published hours after the announcement, both by the White House and by the European Commission. Below are a couple of things that caught my attention from the two brief Factsheets.
The US has committed to “implement new safeguards” to ensure that SIGINT activities are “necessary and proportionate” (an EU law legal measure – see Article 52 of the EU Charter on how the exercise of fundamental rights can be limited) in the pursuit of defined national security objectives. Therefore, the new agreement is expected to address the lack of safeguards for government access to personal data as specifically outlined by the CJEU in the Schrems II judgment.
The US also committed to creating a “new mechanism for the EU individuals to seek redress if they believe they are unlawfully targeted by signals intelligence activities”. This new mechanism was characterized by the White House as having “independent and binding authority”. Per the White House, this redress mechanism includes “a new multi-layer redress mechanism that includes an independent Data Protection Review Court that would consist of individuals chosen from outside the US Government who would have full authority to adjudicate claims and direct remedial measures as needed”. The EU Commission mentioned in its own Factsheet that this would be a “two-tier redress system”.
Importantly, the White House mentioned in the Factsheet that oversight of intelligence activities will also be boosted – “intelligence agencies will adopt procedures to ensure effective oversight of new privacy and civil liberties standards”. Oversight and redress are different issues and are both equally important – for details, see this piece by Christopher Docksey. However, they tend to be thought of as being one and the same. Being addressed separately in this announcement is significant.
One of the remarkable things about the White House announcement is that it includes several EU law-specific concepts: “necessary and proportionate”, “privacy, data protection” mentioned separately, “legal basis” for data flows. In another nod to the European approach to data protection, the entire issue of ensuring safeguards for data flows is framed as more than a trade or commerce issue – with references to a “shared commitment to privacy, data protection, the rule of law, and our collective security as well as our mutual recognition of the importance of trans-Atlantic data flows to our respective citizens, economies, and societies”.
Last, but not least, Europeans have always framed their concerns related to surveillance and data protection as being fundamental rights concerns. The US also gives a nod to this approach, by referring a couple of times to “privacy and civil liberties” safeguards (adding thus the “civil liberties” dimension) that will be “strengthened”. All of these are positive signs for a “rapprochement” of the two legal systems and are certainly an improvement to the “commerce” focused approach of the past on the US side.
Lastly, it should also be noted that the new framework will continue to be a self-certification scheme managed by the US Department of Commerce.
What does all of this mean in practice? As the White House details, this means that the Biden Administration will have to adopt (at least) an Executive Order (EO) that includes all these commitments and on the basis of which the European Commission will draft an adequacy decision.
Thus, there are great expectations in sight following the White House and European Commission Factsheets, and the entire privacy and data protection community is waiting to see further details.
In the meantime, I’ll leave you with an observation made by my colleague, Amie Stepanovich, VP for US Policy at FPF, who highlighted that Section 702 of the FISA Act is set to expire on December 31, 2023. This presents Congress with an opportunity to act, building on such an extensive amount of work done by the US Government in the context of the Transatlantic Data Transfers debate.
Privacy Best Practices for Rideshare Drivers Using Dashcams
FPF & Uber Publish Guide Highlighting Privacy Best Practices for Drivers who Record Video and Audio on Rideshare Journeys
FPF and Uber have created a guide for US-based rideshare drivers who install “dashcams” – video cameras mounted on a vehicle’s dashboard or windshield. Many drivers install dashcams to improve safety, security, and accountability; the cameras can capture crashes or other safety-related incidents outside and inside cars. Dashcam footage can be helpful to drivers, passengers, insurance companies, and others when adjudicating legal claims. At the same time, dashcams can pose substantial privacy risks if appropriate safeguards are not in place to limit the collection, use, and disclosure of personal data.
Dashcams typically record video outside a vehicle. Many dashcams also record in-vehicle audio and some record in-vehicle video. Regardless of the particular device used, ride-hail drivers who use dashcams must comply with applicable audio and video recording laws.
The guide explains relevant laws and provides practical tips to help drivers be transparent, limit data use and sharing, retain video and audio-only for practical purposes, and use strict security controls. The guide highlights ways that drivers can employ physical signs, in-app notices, and other means to ensure passengers are informed about dashcam use and can make meaningful choices about whether to travel in a dashcam-equipped vehicle. Drivers seeking advice concerning specific legal obligations or incidents should consult legal counsel.
Privacy best practices for dashcams include:
Give individuals notice that they are being recorded
Place recording notices inside and on the vehicle.
Mount the dashcam in a visible location.
Consider, in some situations, giving an oral notification that recording is taking place.
Determine whether the ride sharing service provides recording notifications in the app, and utilize those in-app notices.
Only record audio and video for defined, reasonable purposes
Only keep recordings for as long as needed for the original purpose.
Inform passengers as to why video and/or audio is being recorded.
Limit sharing and use of recorded footage
Only share video and audio with third parties for relevant reasons that align with the original reason for recording.
Thoroughly review the rideshare service’s privacy policy and community guidelines if using an app-based rideshare service, and be aware that many rideshare companies maintain policies against widely disseminating recordings.
Safeguard and encrypt recordings and delete unused footage
Identify dashcam vendors that provide the highest privacy and security safeguards.
Carefully read the terms and conditions when buying dashcams to understand the data flows.
Uber will be making these best practices available to drivers in their app and website.
Many ride-hail drivers use dashcams in their cars, and the guidance and best practices published today provide practical guidance to help drivers implement privacy protections. But driver guidance is only one aspect of ensuring individuals’ privacy and security when traveling. Dashcam manufacturers must implement privacy-protective practices by default and provide easy-to-use privacy options. At the same time, ride-hail platforms must provide drivers with the appropriate tools to notify riders, and carmakers must safeguard drivers’ and passengers’ data collected by OEM devices.
In addition, dashcams are only one example of increasingly sophisticated sensors appearing in passenger vehicles as part of driver monitoring systems and related technologies. Further work is needed to apply comprehensive privacy safeguards to emerging technologies across the connected vehicle sector, from carmakers and rideshare services to mobility services providers and platforms. Comprehensive federal privacy legislation would be a good start. And in the absence of Congressional action, FPF is doing further work to identify key privacy risks and mitigation strategies for the broader class of driver monitoring systems that raise questions about technologies beyond the scope of this dashcam guide.
12th Annual Privacy Papers for Policymakers Awardees Explore the Nature of Privacy Rights & Harms
The winners of the 12th annual Future of Privacy (FPF) Privacy Papers for Policymakers Award ask big questions about what should be the foundational elements of data privacy and protection and who will make key decisions about the application of privacy rights. Their scholarship will inform policy discussions around the world about privacy harms, corporate responsibilities, oversight of algorithms, and biometric data, among other topics.
“Policymakers and regulators in many countries are working to advance data protection laws, often seeking in particular to combat discrimination and unfairness,” said FPF CEO Jules Polonetsky. “FPF is proud to highlight independent researchers tackling big questions about how individuals and society relate to technology and data.”
This year’s papers also explore smartphone platforms as privacy regulators, the concept of data loyalty, and global privacy regulation. The award recognizes leading privacy scholarship that is relevant to policymakers in the U.S. Congress, at U.S. federal agencies, and among international data protection authorities. The winning papers will be presented at a virtual event on February 10, 2022.
The winners of the 2022 Privacy Papers for Policymakers Award are:
Privacy Harms, by Danielle Keats Citron, University of Virginia School of Law; and Daniel J. Solove, George Washington University Law School
This paper looks at how courts define harm in cases involving privacy violations and how the requirement of proof of harm impedes the enforcement of privacy law due to the dispersed and minor effects that most privacy violations have on individuals. However, when these minor effects are suffered at a vast scale, individuals, groups, and society can feel significant harm. This paper offers language for courts to refer to when litigating privacy cases and provides advice as to when privacy harm should be considered in a lawsuit.
In this paper, Green analyzes the use of human oversight of government algorithmic decisions. From this analysis, he concludes that humans are unable to perform the desired oversight responsibilities, and that by continuing to use human oversight as a check on these algorithms, the government legitimizes the use of these faulty algorithms without addressing the associated issues. The paper offers a more stringent approach to determining whether an algorithm should be incorporated into a certain government decision, which includes critically considering the need for the algorithm and evaluating whether people are capable of effectively overseeing the algorithm.
The Surprising Virtues of Data Loyalty, by Woodrow Hartzog, Northeastern University School of Law and Khoury College of Computer Sciences, Stanford Law School Center for Internet and Society; and Neil M. Richards, Washington University School of Law, Yale Information Society Project, Stanford Center for Internet and Society
The data loyalty responsibilities for companies that process human information are now being seriously considered in both the U.S. and Europe. This paper analyzes criticisms of data loyalty that argue that such duties are unnecessary, concluding that data loyalty represents a relational approach to data that allows us to deal substantively with the problem of platforms and human information at both systemic and individual levels. The paper argues that the concept of data loyalty has some surprising virtues, including checking power and limiting systemic abuse by data collectors.
Smartphone Platforms as Privacy Regulators, by Joris van Hoboken, Vrije Universiteit Brussels, Institute for Information Law, University of Amsterdam; and Ronan Ó Fathaigh, Institute for Information Law, University of Amsterdam
In this paper, the authors look at the role of online platforms and their impact on data privacy in today’s digital economy. The paper first distinguishes the different roles that platforms can have in protecting privacy in online ecosystems, including governing access to data, design of relevant interfaces, and policing the behavior of the platform’s users. The authors then provide an argument as to what platforms’ role should be in legal frameworks. They advocate for a compromise between direct regulation of platforms and mere self-regulation, arguing that platforms should be required to make official disclosures about their privacy-related policies and practices for their respective ecosystems.
China enacted the first codified personal information protection law in China in late 2021, the Personal Information Protection Law (PIPL). In this paper, Wang compares China’s PIPL with data protection laws in nine regions to assist overseas Internet companies and personnel who deal with personal information in better understanding the similarities and differences in data protection and compliance between each country and region.
Cameras are everywhere, and with the innovation of video analytics, there are questions being raised about how individuals should be notified that they are being recorded. This paper studied 123 individuals’ sentiments across 2,328 video analytics deployments scenarios to inform their conclusion. In their conclusion, the researchers advocate for the development of interfaces that simplify the task of managing notices and configuring controls, which would allow individuals to communicate their opt-in/opt-out preference to video analytics operators.
From the record number of nominated papers submitted this year, these six papers were selected by a diverse team of academics, advocates, and industry privacy professionals from FPF’s Advisory Board. The winning papers were selected based on the research and solutions that are relevant for policymakers and regulators in the U.S. and abroad.
In addition to the winning papers, FPF has selected two papers for Honorable Mention: Verification Dilemmas and the Promise of Zero-Knowledge Proofs by Kenneth Bamberger, University of California, Berkeley – School of Law; Ran Canetti, Boston University, Department of Computer Science, Boston University, Faculty of Computing and Data Science, Boston University, Center for Reliable Information Systems and Cybersecurity; Shafi Goldwasser, University of California, Berkeley – Simons Institute for the Theory of Computing; Rebecca Wexler, University of California, Berkeley – School of Law; and Evan Zimmerman, University of California, Berkeley – School of Law; and A Taxonomy of Police Technology’s Racial Inequity Problems by Laura Moy, Georgetown University Law Center.
FPF also selected a paper for the Student Paper Award, A Fait Accompli? An Empirical Study into the Absence of Consent to Third Party Tracking in Android Apps by Konrad Kollnig and Reuben Binns, University of Oxford; Pierre Dewitte, KU Leuven; Max van Kleek, Ge Wang, Daniel Omeiza, Helena Webb, and Nigel Shadbolt, University of Oxford. The Student Paper Award Honorable Mention was awarded to Yeji Kim, University of California, Berkeley – School of Law, for her paper, Virtual Reality Data and Its Privacy Regulatory Challenges: A Call to Move Beyond Text-Based Informed Consent.
The winning authors will join FPF staff to present their work at a virtual event with policymakers from around the world, academics, and industry privacy professionals. The event will be held on February 10, 2022, from 1:00 – 3:00 PM EST. The event is free and open to the general public. To register for the event, visit https://bit.ly/3qmJdL2.
Organizations must lead with privacy and ethics when researching and implementing neurotechnology: FPF and IBM Live event and report release
A New FPF and IBM Report and Live Event Explores Questions About Transparency, Consent, Security, and Accuracy of Data
The Future of Privacy Forum (FPF) and the IBM Policy Lab released recommendations for promoting privacy and mitigating risks associated with neurotechnology, specifically with brain-computer interface (BCI). The new report provides developers and policymakers with actionable ways this technology can be implemented while protecting the privacy and rights of its users.
“We have a prime opportunity now to implement strong privacy and human rights protections as brain-computer interfaces become more widely used,” said Jeremy Greenberg, Policy Counsel at the Future of Privacy Forum. “Among other uses, these technologies have tremendous potential to treat people with diseases and conditions like epilepsy or paralysis and make it easier for people with disabilities to communicate, but these benefits can only be fully realized if meaningful privacy and ethical safeguards are in place.”
Brain-computer interfaces are computer-based systems that are capable of directly recording, processing, analyzing, or modulating human brain activity. The sensitivity of data that BCIs collect and the capabilities of the technology raise concerns over consent, as well as the transparency, security, and accuracy of the data. The report offers a number of policy and technical solutions to mitigate the risks of BCIs and highlights their positive uses.
“Emerging innovations like neurotechnology hold great promise to transform healthcare, education, transportation, and more, but they need the right guardrails in place to protect individuals’ privacy,” said IBM Chief Privacy Officer Christina Montgomery. “Working together with the Future of Privacy Forum, the IBM Policy Lab is pleased to release a new framework to help policymakers and businesses navigate the future of neurotechnology while safeguarding human rights.”
FPF and IBM have outlined several key policy recommendations to mitigate the privacy risks associated with BCIs, including:
Rethinking transparency, notice, terms of use, and consent frameworks to empower people around uses of their neurodata;
Ensuring that BCI devices are not allowed for uses to influence decisions about individuals that have legal effects, livelihood effects, or similar significant impacts—such as assessing the truthfulness of statements in legal proceedings; inferring thoughts, emotions or psychological state, or personality attributes as part of hiring or school admissions decisions; or assessing individuals’ eligibility for legal benefits;
Promoting an open and inclusive research ecosystem by encouraging the adoption of open standards for the collection and analysis of neurodata and the sharing of research data with appropriate safeguards in place.
Policymakers and other BCI stakeholders should carefully evaluate how existing policy frameworks apply to neurotechnologies and identify potential areas where existing laws and regulations may be insufficient for the unique risks of neurotechnologies.
FPF and IBM have also included several technical recommendations for BCI devices, including:
Providing hard on/off controls for users;
Allowing users to manage the collection, use, and sharing of personal neurodata on devices and in companion apps;
Offering heightened transparency and control for BCIs that send signals to the brain, rather than merely receive neurodata;
Utilizing best practices for privacy and security to store and process neurodata and use privacy enhancing technologies where appropriate; and
Encrypting sensitive personal neurodata in transit and at rest.
FPF-curated educational resources, policy & regulatory documents, academic papers, thought pieces, and technical analyses regarding brain-computer interfaces are available here.
Read FPF’s four-part series on Brain-Computer Interfaces (BCIs), providing an overview of the technology, use cases, privacy risks, and proposed recommendations for promoting privacy and mitigating risks associated with BCIs.
FPF Launches Asia-Pacific Region Office, Global Data Protection Expert Clarisse Girot Leads Team
The Future of Privacy Forum (FPF) has appointed Clarisse Girot, PhD, LLM, an expert on Asian and European privacy legislation, to lead its new FPF Asia-Pacific office based in Singapore as Director. This new office expands FPF’s international reach in Asia and complements FPF’s offices in the U.S., Europe, and Israel, as well as partnerships around the globe.
Dr. Clarisse Girot is a privacy professional with over twenty years of experience in the privacy and data protection fields. Since 2017, Clarisse has been leading the Asian Business Law Institute’s (ABLI) Data Privacy Project, focusing on the regulations on cross-border data transfers in 14 Asian jurisdictions. Prior to her time at ABLI, Clarisse served as the Counsellor to the President of the French Data Protection Authority (CNIL) and Chair of the Article 29 Working Party. She previously served as head of CNIL’s Department of European and International Affairs, where she sat on the Article 29 Working Party, the group of EU Data Protection Authorities, and was involved in major international cases in data protection and privacy.
“Clarisse is joining FPF at an important time for data protection in the Asia-Pacific region. The two most populous countries in the world, India, and China, are introducing general privacy laws, and established data protection jurisdictions, like Singapore, Japan, South Korea, and New Zealand, have recently updated their laws,” said FPF CEO Jules Polonetsky. “Her extensive knowledge of privacy law will provide vital insights for those interested in compliance with regional privacy frameworks and their evolution over time.”
FPF Asia-Pacific will focus on several priorities by the end of the year including hosting an event at this year’s Singapore Data Protection Week. The office will provide expertise in digital data flows and discuss emerging data protection issues in a way that is useful for regulators, policymakers, and legal professionals. Rajah & Tann Singapore LLP is supporting the work of the FPF Asia-Pacific office.
“The FPF global team will greatly benefit from the addition of Clarisse. She will advise FPF staff, advisory board members, and the public on the most significant privacy developments in the Asia-Pacific region, including data protection bills and cross-border data flows,” said Gabriela Zanfir-Fortuna, Director for Global Privacy at FPF. “Her past experience in both Asia and Europe gives her a unique ability to confront the most complex issues dealing with cross-border data protection.”
As over 140 countries have now enacted a privacy or data protection law, FPF continues to expand its international presence to help data protection experts grapple with the challenges of ensuring responsible uses of data. Following the appointment of Malavika Raghavan as Senior Fellow for India in 2020, the launch of the FPF Asia-Pacific office further expands FPF’s international reach.
Dr. Gabriela Zanfir-Fortuna leads FPF’s international efforts and works on global privacy developments and European data protection law and policy. The FPF Europe office is led by Dr. Rob van Eijk, who prior to joining FPF worked at the Dutch Data Protection Authority as Senior Supervision Officer and Technologist for nearly ten years. FPF has created thriving partnerships with leading privacy research organizations in the European Union, such as Dublin City University and the Brussels Privacy Hub of the Vrije Universiteit Brussel (VUB). FPF continues to serve as a leading voice in Europe on issues of international data flows, the ethics of AI, and emerging privacy issues. FPF Europe recently published a report comparing the regulatory strategy for 2021-2022 of 15 Data Protection Authorities to provide insights into the future of enforcement and regulatory action in the EU.
Outside of Europe, FPF has launched a variety of projects to advance tech policy leadership and scholarship in regions around the world, including Israel and Latin America. The work of the Israel Tech Policy Institute (ITPI), led by Managing Director Limor Shmerling Magazanik, includes publishing a report on AI Ethics in Government Services and organizing an OECD workshop with the Israeli Ministry of Health on access to health data for research.
In Latin America, FPF has partnered with the leading research association Data Privacy Brasil, provided in-depth analysis on Brazil’s LGPD privacy legislation and various data privacy cases decided in the Brazilian Supreme Court. FPF recently organized a panel during the CPDP LatAm Conference which explored the state of Latin American data protection laws alongside experts from Uber, the University of Brasilia, and the Interamerican Institute of Human Rights.
FPF and Leading Health & Equity Organizations Issue Principles for Privacy & Equity in Digital Contact Tracing Technologies
With support from the Robert Wood Johnson Foundation, FPF engaged leaders within the privacy and equity communities to develop actionable guiding principles and a framework to help bolster the responsible implementation of digital contact tracing technologies (DCTT). Today, seven privacy, civil rights, and health equity organizations signed on to these guiding principles for organizations implementing DCTT.
“We learned early in our Privacy and Pandemics initiative that unresolved ethical, legal, social, and equity issues may challenge the responsible implementation of digital contact tracing technologies,” said Jules Polonetsky, CEO of the Future of Privacy Forum. “So we engaged leaders within the civil rights, health equity, and privacy communities to create a set of actionable principles to help guide organizations implementing digital contact tracing that respects individual rights.”
Contact tracing has long been used to monitor the spread of various infectious diseases. In light of COVID-19, governments and companies began deploying digital exposure notification using Bluetooth and geolocation data on mobile devices to boost contact tracing efforts and quickly identify individuals who may have been exposed to the virus. However, as DCTT begins to play an important role in public health, it is important to take necessary steps to ensure equity in access to DCTT and understand the societal risks and tradeoffs that might accompany its implementation today and in the future. Governance efforts that seek to better understand these risks will be better able to bolster public trust in DCTT technologies.
“LGBT Tech is proud to have participated in the development of the Principles and Framework alongside FPF and other organizations. We are heartened to see that the focus of these principles is on historically underserved and under-resourced communities everywhere, like the LGBTQ+ community. We believe the Principles and Framework will help ensure that the needs and vulnerabilities of these populations are at the forefront during today’s pandemic and future pandemics.”
Carlos Gutierrez, Deputy Director, and General Counsel, LGBT Tech
“If we establish practices that protect individual privacy and equity, digital contact tracing technologies could play a pivotal role in tracking infectious diseases,” said Dr. Rachele Hendricks-Sturrup, Research Director at the Duke-Margolis Center for Health Policy. “These principles allow organizations implementing digital contact tracing to take ethical and responsible approaches to how their technology collects, tracks, and shares personal information.”
FPF, together with Dialogue on Diversity, the National Alliance Against Disparities in Patient Health (NADPH), BrightHive, and LGBT Tech, developed the principles, which advise organizations implementing DCTT to commit to the following actions:
Be Transparent About How Data Is Used and Shared.
Apply Strong De-Identification Techniques and Solutions.
Empower Users Through Tiered Opt-in/Opt-out Features and Data Minimization.
Acknowledge and Address Privacy, Security, and Nondiscrimination Protection Gaps.
Create Equitable Access to DCTT.
Acknowledge and Address Implicit Bias Within and Across Public and Private Settings.
Democratize Data for Public Good While Employing Appropriate Privacy Safeguards.
Adopt Privacy-By-Design Standards That Make DCTT Broadly Accessible.
Additional supporters of these principles include the Center for Democracy and Technology and Human Rights First.
To learn more and sign on to the DCTT Principles visit fpf.org/DCTT.
Support for this program was provided by the Robert Wood Johnson Foundation. The views expressed here do not necessarily reflect the views of the Foundation.
Navigating Preemption through the Lens of Existing State Privacy Laws
This post is the second of two posts on federal preemption and enforcement in United States federal privacy legislation. See Preemption in US Privacy Laws (June 14, 2021).
In drafting a federal baseline privacy law in the United States, lawmakers must decide to what extent the law will override state and local privacy laws. In a previous post, we discussed a survey of 12 existing federal privacy laws passed between 1968-2003, and the extent to which they are preemptive of similar state laws.
Another way to approach the same question, however, is to examine the hundreds of existing state privacy laws currently on the books in the United States. Conversations around federal preemption inevitably focus on comprehensive laws like the California Consumer Privacy Act, or the Virginia Consumer Data Protection Act — but there are hundreds of other state privacy laws on the books that regulate commercial and government uses of data.
In reviewing existing state laws, we find that they can be categorized usefully into: laws that complement heavily regulated sectors (such as health and finance); laws of general applicability; common law; laws governing state government activities (such as schools and law enforcement); comprehensive laws; longstanding or narrowly applicable privacy laws; and emerging sectoral laws (such as biometrics or drones regulations). As a resource, we recommend: Robert Ellis Smith, Compilation of State and Federal Privacy Laws (last supplemented in 2018).
Heavily Regulated Sectoral Silos. Most federal proposals for a comprehensive privacy law would not supersede other existing federal laws that contain privacy requirements for businesses, such as the Health Insurance Portability and Accountability Act (HIPAA) or the Gramm-Leach-Bliley Act (GLBA). As a result, a new privacy law should probably not preempt state sectoral laws that: (1) supplement their federal counterparts and (2) were intentionally not preempted by those federal regimes. In many cases, robust compliance regimes have been built around federal and state parallel requirements, creating entrenched privacy expectations, privacy tools, and compliance practices for organizations (“lock in”).
Laws of General Applicability. All 50 states have laws barring unfair and deceptive commercial and trade practices (UDAP), as well as generally applicable laws against fraud, unconscionable contracts, and other consumer protections. In cases where violations involve the mis-use of personal information, such claims could be inadvertently preempted by a national privacy law.
State Common Law. Privacy claims have been evolving in US common law over the last hundred years, and claims vary from state to state. A federal privacy law might preempt (or not preempt) claims brought under theories of negligence, breach of contract, product liability, invasions of privacy, or other “privacy torts.”
State Laws Governing State Government Activities. In general, states retain the right to regulate their own government entities, and a commercial baseline privacy law is unlikely to affect such state privacy laws. These include, for example, state “mini Privacy Acts” applying to state government agencies’ collection of records, state privacy laws applicable to public schools and school districts, and state regulations involving law enforcement — such as government facial recognition bans.
Comprehensive or Non-Sectoral State Laws. Lawmakers considering the extent of federal preemption should take extra care to consider the effect on different aspects of omnibus or comprehensive consumer privacy laws, such as the California Consumer Privacy Act (CCPA), the Colorado Privacy Act, and the Virginia Consumer Data Protection Act. In addition, however, there are a number of other state privacy laws that can be considered “non-sectoral” because they apply broadly to businesses that collect or use personal information. These include, for example, CalOPPA (requiring commercial privacy policies), the California “Shine the Light” law (requiring disclosures from companies that share personal information for direct marketing), data breach notification laws, and data disposal laws.
Congressional intent is the “ultimate touchstone” of preemption. Lawmakers should consider long-term effects on current and future state laws, including how they will be impacted by a preemption provision, as well as how they might be expressly preserved through a Savings Clause. In order to help build consensus, lawmakers should work with stakeholders and experts in the numerous categories of laws discussed above, to consider how they might be impacted by federal preemption.
Manipulative Design: Defining Areas of Focus for Consumer Privacy
In consumer privacy, the phrase “dark patterns” is everywhere. Emerging from a wide range of technical and academic literature, it now appears in at least two US privacy laws: the California Privacy Rights Act and the Colorado Privacy Act (which, if signed by the Governor, will come into effect in 2025).
Under both laws, companies will be prohibited from using “dark patterns,” or “user interface[s] designed or manipulated with the substantial effect of subverting or impairing user autonomy, decision‐making, or choice,” to obtain user consent in certain situations–for example, for the collection of sensitive data.
When organizations give individuals choices, some forms of manipulation have long been barred by consumer protection laws, with the Federal Trade Commission and state Attorneys General prohibiting companies from deceiving or coercing consumers into taking actions they did not intend or striking bargains they did not want. But consumer protection law does not typically prohibit organizations from persuading consumers to make a particular choice. And it is often unclear where the lines fall between cajoling, persuading, pressuring, nagging, annoying, or bullying consumers. The California and Colorado laws seek to do more than merely bar deceptive practices; they prohibit design that “subverts or impairs user autonomy.”
What does it mean to subvert user autonomy, if a design does not already run afoul of traditional consumer protections law? Just as in the physical world, the design of digital platforms and services always influences behavior — what to pay attention to, what to read and in what order, how much time to spend, what to buy, and so on. To paraphrase Harry Brignull (credited with coining the term), not everything “annoying” can be a dark pattern. Some examples of dark patterns are both clear and harmful, such as a design that tricks users into making recurring payments, or a service that offers a “free trial” and then makes it difficult or impossible to cancel. In other cases, the presence of “nudging” may be clear, but harms may be less clear, such as in beta-testing what color shades are most effective at encouraging sales. Still others fall in a legal grey area: for example, is it ever appropriate for a company to repeatedly “nag” users to make a choice that benefits the company, with little or no accompanying benefit to the user?
In Fall 2021, Future of Privacy Forum will host a series of workshops with technical, academic, and legal experts to help define clear areas of focus for consumer privacy, and guidance for policymakers and legislators. These workshops will feature experts on manipulative design in at least three contexts of consumer privacy: (1) Youth & Education; (2) Online Advertising and US Law; and (3) GDPR and European Law.
As lawmakers address this issue, we identify at least four distinct areas of concern:
Designs that cause concrete physical or financial harms to individuals. In some cases, design choices are implicated in concrete physical or financial harms. This might include, for example, a design that tricks users into making recurring payments, or makes unsubscribing from a free trial or other paid service difficult or impossible, leading to unwanted charges.
Designs that impact individual autonomy or dignity (but do not necessarily cause concrete physical or financial harm). In many cases, we observe concerns over autonomy and dignity, even where the use of data would not necessarily cause harm. For the same reasons that there is wide agreement that so-called subliminal messaging in advertising is wrong (as well as illegal), there is a growing awareness that disrespect for user autonomy in consumer privacy is objectionable on its face. As a result, in cases where the law requires consent, such as in the European Union for placement of information onto a user’s device, the law ought to provide a remedy for individuals who have been subject to a violation of that consent.
Designs that persuade, nag, or strongly push users towards a particular outcome, even where it may be possible for users to decline. In many cases, the design of a digital platform or serviceclearlypushes users towards a particular outcome, even if it is possible (if burdensome) for users to make a different choice. In such cases, we observe a wide spectrum of tactics that may be evaluated differently depending on the viewer and the context. Repeated requests may be considered “nagging” or “persuasion”; one person’s “clever marketing,” taken too far, becomes another person’s “guilt-shaming” or “confirm-shaming.” Ultimately, our preference for defaults (“opt in” versus “opt out”), and within those defaults, our level of tolerance for “nudging,” may be driven by the social benefits or values attached to the choice itself.
Designs that exploit biases, vulnerabilities, or heuristics in ways that implicate broader societal harms or values. Finally, we observe that the collection and use of personal information does not always solely impact individual decision-making. Often, the design of online platforms can influence groups in ways that impact societal values, such as the values of privacy, avoidance of “tech addiction,” free speech, the availability of data from or about marginalized groups, or the proliferation of unfair price discrimination or other market manipulation. Understanding how design choices may influence society, even if individuals are minimally impacted, may require examining the issues differently.
This week at the first edition of the annual Dublin Privacy Symposium, FPF will join other experts to discuss principles for transparency and trust. The design of user interfaces for digital products and services pervades modern life and directly impacts the choices people make with respect to sharing their personal information.
recast the conditions to obtain ‘safe harbour’ from liability for online intermediaries, and
unveiled an extensive regulatory regime for a newly defined category of online ‘publishers’, which includes digital news media and Over-The-Top (OTT) services.
The majority of these provisions were unanticipated, resulting in a raft of petitions filed in High Courts across the country challenging the validity of the various aspects of the Rules, including with regard to their constitutionality. On 25 May 2021, the three month compliance period on some new requirements for significant social media intermediaries (so designated by the Rules) expired, without many intermediaries being in compliance opening them up to liability under the Information Technology Act as well as wider civil and criminal laws. This has reignited debates about the impact of the Rules on business continuity and liability, citizens’ access to online services, privacy and security.
Following on FPF’s previous blog highlighting some aspects of these Rules, this article presents an overview of the Rules before deep-diving into critical issues regarding their interpretation and application in India. It concludes by taking stock of some of the emerging effects of these new regulations, which have major implications for millions of Indian users, as well as digital services providers serving the Indian market.
1.Brief overview of the Rules: Two new regimes for ‘intermediaries’ and ‘publishers’
The new Rules create two regimes for two different categories of entities: ‘intermediaries’ and ‘publishers’. Intermediaries have been the subject of prior regulations – the Information Technology (Intermediaries guidelines) Rules, 2011 (the 2011 Rules), now superseded by these Rules. However, the category of “publishers” and related regime created by these Rules did not previously exist.
The Rules begin with commencement provisions and definitions in Part I. Part II of the Rules apply to intermediaries (as defined in the Information Technology Act 2000 (IT Act)) who transmit electronic records on behalf of others, and includes online intermediary platforms (like Youtube, Whatsapp, Facebook). The rules in this part primarily flesh out the protections offered in Section 79 of India’s Information Technology Act 2000 (IT Act), which give passive intermediaries the benefit of a ‘safe harbour’ from liability for objectionable information shared by third parties using their services — somewhat akin to protections under section 230 of the US Communications Decency Act. To claim this protection from liability, intermediaries need to undertake certain ‘due diligence’ measures, including informing users of the types of content that could not be shared, and content take-down procedures (for which safeguards evolved overtime through important case law). The new Rules supersede the 2011 Rules and also significantly expand on them, introducing new provisions and additional due diligence requirements that are detailed further in this blog.
Part III of the Rules apply to a new previously non-existent category of entities designated to be ‘publishers‘. This is further classified into subcategories of ‘publishers of news and current affairs content’ and ‘publishers of online curated content’. Part III then sets up extensive requirements for publishers to adhere to specific codes of ethics, onerous content take-down requirements and three-tier grievance process with appeals lying to an Executive Inter-Departmental Committee of Central Government bureaucrats.
Finally, the Rules contain two provisions that apply to all entities (i.e. intermediaries and publishers) relating to content-blocking orders. They lay out a new process by which Central Government officials can issue directions to delete, modify or block content to intermediaries and publishers, either following a grievance process (Rule 15) or including procedures of “emergency”blocking orders which may be passed ex-parte. These Rules stem from powers to issue directions to intermediaries to block public access of any information through any computer resource (Section 69A of the IT Act). Interestingly, these provisions have been introduced separately from the existing rules for blocking purposes called the Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009.
2.Key issues for intermediaries under the Rules
2.1 A new class of ‘social media intermediaries‘
The term ‘intermediary’ is a broadly defined term in the IT Act covering a range of entities involved in the transmission of electronic records. The Rules introduce two new sub-categories, being:
“social media intermediary” defined (in Rule 2(w)) as one who “primarily or solely enables online interaction between two or more users and allows them” to exchange information; and
“significant social media intermediary” (SSMI) comprising social media intermediaries with more than five million registered users in India (following this Government notification of the threshold).
Given that a popular messaging app like Whatsapp has over 400 million users in India, the threshold appears to be fairly conservative. The Government may order anyintermediary to comply with the same obligations as SSMIs (under Rule 6) if their services are adjudged to pose a risk of harm to national security, the sovereignty and integrity of India, India’s foreign relations or to public order.
SSMIs have to follow substantially more onerous “additional due diligence” requirements to claim the intermediary safe harbour (including mandatory traceability of message originators, and proactive automated screening as discussed below). These new requirements raise privacy concerns and data security concerns, as they extend beyond the traditional ideas of platform “due diligence”, they potentially expose content of private communications and in doing so create new privacy risks for users in India.
Extensive new requirements are set out in the new Rule 4 for SSMIs.
In-country employees: SSMIs must appoint in-country employees as (1) Chief Compliance Officer, (2) a nodal contact person for 24×7 coordination with law enforcement agencies and (3) a Resident Grievance Officer specifically responsible for overseeing the internal grievance redress mechanism. Monthly reporting of complaints management is also mandated.
Traceability requirements for SSMIs providing messaging services: Among the most controversial requirements is Rule 4(2) which requires SSMIs providing messaging services to enable the identification of the “first originator” of information on their platforms as required by Government or court orders. This tracing and identification of users is considered incompatible with end-to-end encryption technology employed by messaging applications like Whatsapp and Signal. In their legal challenge to this Rule, Whatsapp has noted that end-to-end encrypted platforms would need to be re-engineered to identify all users since there is no way to predict which user will be the subject of an order seeking first originator information.
Provisions to mandate modifications to the technical design of encrypted platforms to enable traceability seem to go beyond merely requiring intermediary due diligence. Instead they appear to draw on separate Government powers relating to interception and decryption of information (under Section 69 of the IT Act). In addition, separate stand-alone rules laying out procedures and safeguards for such interception and decryption orders already exist in the Information Technology (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules, 2009. Rule 4(2) even acknowledges these provisions–raising the question of whether these Rules (relating to intermediaries and their safe harbours) can be used to expand the scope of section 69 or rules thereunder.
Proceedings initiated by Whatsapp LLC in the Delhi High Court, and Free and Open Source Software (FOSS) developer Praveen Arimbrathodiyil in the Kerala High Court have both challenged the legality and validity of Rule 4(2) on grounds including that they are ultra vires and go beyond the scope of their parent statutory provisions (s. 79 and 69A) and the intent of the IT Act itself. Substantively, the provision is also challenged on the basis that it would violate users’ fundamental rights including the right to privacy, and the right to free speech and expression due to the chilling effect that the stripping back of encryption will have.
Automated content screening: Rule 4(4) mandates that SSMIs must employ technology-based measures including automated tools to proactively identify information depicting (i) rape, child sexual abuse or conduct, or (ii) any information previousy removed following a Government or court order. The latter category is very expansive and allows content take-downs for a broad range of reasons including defamatory or pornographic content, to IP infringements, to content threatening national security or public order (as set out in Rule 3(1)(d)).
Though the objective of the provision is laudable (i.e. to limit the circulation of violent or previously removed content), the move towards proactive automated monitoring has raised serious concerns regarding censorship on social media platforms. Rule 4(4) appears to acknowledge the deep tensions that this requirement raises with privacy and free speech concerns, as seen by the provisions that require these screening measures to be proportionate to the free speech and privacy of users, to be subject to human oversight, and reviews of automated tools to assess fairness, accuracy, propensity for bias or discrimination, and impact on privacy and security. However, given the vagueness of this wording compared to the trade-off of losing intermediary immunity, scholars and commentators are noting the obvious potential for ‘over-compliance’ and excessive screening out of content. Many (including the petitioner in the Praveen Arimbrathodiyil matter) have also noted that automated filters are not sophisticated enough to differentiate between violent unlawful images and legitimate journalistic material. The concern is that such measures could create a large-scale screening out of ‘valid’ speech and expression, with serious consequences for constitutional rights to free speech and expression which also protect ‘the rights of individuals to listen, read and receive the said speech‘ (Tata Press Ltd v. Mahanagar Telephone Nigam Ltd, (1995) 5 SCC 139).
Tighter timelines for grievance redress, content take down and information sharing with law enforcement:Rule 3 includes enhanced requirements to serve privacy policies and user agreements outlining the terms of use, including annual reminders of these terms and any modifications and of the intermediaries’ right to terminate the user’s access for using the service in contravention of these terms. The Rule also has enhanced grievance redress processes for intermediaries, by expanding these requirements to mandate that the complaints system acknowledge complaints within 24 hours, and dispose of them in 15 days. In the case of certain categories of complaints (where a person complains of inappropriate images or impersonations of them being circulated), the removal of access to the material is mandated within 24 hours based on a prima facie assessment.
Such requirements appear to be aimed at creating more user-friendly networks of intermediaries. However, the imposition of a single set of requirements is especially onerous for smaller or volunteer-run intermediary platforms which may not have income streams or staff to provide for such a mechanism. Indeed, the petition in the Praveen Arimbrathodiyil matter has challenged certain of these requirements as being a threat to the future of the volunteer-led Free and Open Source Software (FOSS) movement in India, by placing similar requirements on small FOSS initiatives as on large proprietary Big Tech intermediaries.
Other obligations that stipulate turn-around times for intermediaries include (i) a requirement to remove or disable access to content within 36 hours of receipt of a Government or court order relating the unlawful information on the intermediary’s computer resources (under Rule 3(1)(d)) and (ii) to provide information within 72 hours of receiving an order from a authorised Government agency undertaking investigative activity (under Rule 3(1)(j).
Similar to the concerns with automated screening, there are concerns that the new grievance process could lead to private entities becoming the arbiters of appropriate content/ free speech — a position that was specifically reversed in a seminal 2015 Supreme Court decision that clarified that a Government or Court order was needed for content-takedowns.
3. Key issues for the new ‘publishers’ subject to the Rules, including OTT players
3.1New Codes of Ethics and three-tier redress and oversight system for digital news media and OTT players
Digital news media and OTT players have been designated as ‘publishers of news and current affairs content’ and ‘publishers of online curated content’ respectively in Part III of the Rules. Each category has been then subjected to separate Codes of Ethics. In the case of digital news media, the Codes applicable to the newspapers and cable television have been applied. For OTT players, the Appendix sets out principles regarding content that can be created and display classifications. To enforce these codes and to address grievances from the public on their content, publishers are now mandated to set up a grievance system which will be the first tier of a three-tier “appellate” system culminating in an oversight mechanism by the Central Government with extensive powers of sanction.
Some of the key issues emerging from these Rules in Part III and the challenges to them are highlighted below.
3.2 Lack of legal authority and competence to create these Rules
There has been substantial debate on the lack of clarity regarding the legal authority of the Ministry of Electronics & Information Technology (MeitY) under the IT Act. These concerns arise at various levels.
Authority and competence to regulate ‘publishers’ of original content is unclear: The definition of ‘intermediary’ in the IT Act does not extend to cover types of entities defined to be publishers. The Rules themselves acknowledge that ‘publishers’ are a new category of regulated entity created by the Rules, as opposed to a sub-category of intermediaries. Further, the commencement of the Rules also confirm that they are passed under statutory provisions in the IT Act related to intermediary regulation. It is a well established principle that subordinate rules cannot go beyond the object and scope of parent statutory provisions (Ajoy Kumar Banerjee v Union of India (1984) 3 SCC 127). Consequently, the authority of MeitY to regulate entities that create original content – like online news sources and OTT platforms – remains unclear at best.
Ability to extend substantive provisions in other statutes through the Rules: The Rules apply two codes of conduct to digital publishers of news and current affairs content, namely (i) the Norms of Journalistic Conduct of the Press Council of India under the Press Council Act, 1978; (ii) Programme Code under section 5 of the Cable Television Networks Regulation) Act, 1995. Many, including petitioners in the LiveLaw matterhave noted that the power to make Rules under the IT Act’s s 87 cannot be used to extend or expand requirements under other statutes and their subordinate rules. To bring digital news media or OTT players into existing regulatory regimes for the Press and television broadcasting, amendments to those regimes will be required led by the Ministry of Information and Broadcasting.
Validity of three-tier ‘quasi-judicial’ adjudicatory mechanism, with final appeal to Committee of solely executive functionaries: Rules 11 – 14 create a three-tier grievance and oversight system which can be used by any person with a grievance against content published by any publisher. Under this model, any person having a grievance with any material published by a publisher can complain through the publisher’s redress process. If any grievance is not satisfactorily dealt with by the publisher entity (Level I) in 15 days, it will be escalated to the self regulatory body of which the publisher is a member (Level II) which must also provide a decision to the complainant within 15 days. If the complainant is unsatisfied, they may appeal to the Oversight Mechanism (in Level III). This can be appreciated as an attempt to create feedback loops that can minimise the spread of misleading or incendiary media, disinformation etc through a more effective grievance mechanism. The structure and design of the three-tier structure have however raised specific concerns.
First, there is a concern that Level I & II result in a privatisation of adjudications relating to free speech and expression of creative content producers – which would otherwise be litigated in Courts and Tribunals as matters of free speech. As noted by many (including the LiveLaw petition at page 33), this could have the effect of overturning judicial precedent in Shreya Singhal v. Union of India ((2013) 12 S.C.C. 73) that specifically read down s 79 of the IT Act to avoid a situation where private entities were the arbiters determining the legitimacy of takedown orders. Second, despite referring to “self-regulation” this system is subject to executive oversight (unlike the existing models for offline newspapers and broadcasting).
The Inter-Departmental Committee is entirely composed of Central Government bureaucrats, and it may review complaints through the three-tier system or referred directly by the Ministry following which it can deploy a range of sanctions from warnings, to mandating apologies, to deleting, modifying or blocking content. This also raises the question of whether this Committee meets the legal requirements for any administrative body undertaking a ‘quasi-judicial’ function, especially one that may adjudicate on matters of rights relating to free speech and privacy. Finally, while the objective of creating some standards and codes for such content creators may be laudable it is unclear whether such an extensive oversight mechanism with powers of sanction on online publishers can be validly created under the rubric of intermediary liability provisions.
4. New powers to delete, modify or block information for public access
As described at the start of this blog, the Rules add new powers for the deletion, modification and blocking of content from intermediaries and publishers. While section 69A of the IT Act (and Rules thereunder) do include blocking powers for Government, they only exist vis a vis intermediaries. Rule 15 also expands this power to ‘publishers’. It also provides a new avenue for such orders to intermediaries, outside of the existing rules for blocking information under the Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009.
More grave concerns arise from Rule 16 which allows for the passing of emergency orders for blocking information, including without giving an opportunity of hearing for publishers or intermediaries. There is a provision for such an order to be reviewed by the Inter-Departmental Committee within 2 days of its issue.
Both Rule 15 and 16 apply to all entities contemplated in the Rules. Accordingly, they greatly expand executive power and oversight over digital media services in India, including social media, digital news media and OTT on-demand services.
5. Conclusions and future implications
The new Rules in India have opened up deep questions for online intermediaries and providers of digital media services serving the Indian market.
For intermediaries, this creates a difficult and even existential choice: the requirements, (especially relating to traceability and automated screening) appear to set an improbably high bar given the reality of their technical systems. However, failure to comply will result in not only the loss of a safe harbour from liability — but as seen in new Rule 7, also opens them up to punishment under the IT Act and criminal law in India.
For digital news and OTT players, the consequences of non-compliance and the level of enforcement remain to be understood, especially given open questions regarding the validity of legal basis to create these rules. Given the numerous petitions filed against these Rules, there is also substantial uncertainty now regarding the future although the Rules themselves have the full force of law at present.
Overall, it does appear that attempts to create a ‘digital media’ watchdog would be better dealt with in a standalone legislation, potentially sponsored by the Ministry of Information and Broadcasting (MIB) which has the traditional remit over such areas. Indeed, the administration of Part III of the Rules has been delegated by MeitY to MIB pointing to the genuine split in competence between these Ministries.
Finally, the potential overlaps with India’s proposed Personal Data Protection Bill (if passed) also create tensions in the future. It remains to be seen if the provisions on traceability will survive the test of constitutional validity set out in India’s privacy judgement (Justice K.S. Puttaswamy v. Union of India, (2017) 10 SCC 1). Irrespective of this determination, the Rules appear to have some dissonance with the data retention and data minimisation requirements seen in the last draft of the Personal Data Protection Bill, not to mention other obligations relating to Privacy by Design and data security safeguards. Interestingly, despite the Bill’s release in December 2019, a definition for ‘social media intermediary’ that it included in an explanatory clause to its section 26(4) closely track the definition in Rule 2(w), but also departs from it by carving out certain intermediaries from the definition. This is already resulting in moves such as Google’s plea on 2 June 2021 in the Delhi High Court asking for protection from being declared a social media intermediary.
These new Rules have exhumed the inherent tensions that exist within the realm of digital regulation between goals of the freedom of speech and expression, and the right to privacy and competing governance objectives of law enforcement (such as limiting the circulation of violent, harmful or criminal content online) and national security. The ultimate legal effect of these Rules will be determined as much by the outcome of the various petitions challenging their validity, as by the enforcement challenges raised by casting such a wide net that covers millions of users and thousands of entities, who are all engaged in creating India’s growing digital public sphere.
New FPF Report Highlights Privacy Tech Sector Evolving from Compliance Tools to Platforms for Risk Management and Data Utilization
As we enter the third phase of development of the privacy tech market, purchasers are demanding more integrated solutions, product offerings are more comprehensive, and startup valuations are higher than ever, according to a new report from the Future of Privacy Forum and Privacy Tech Alliance. These factors are leading to companies providing a wider range of services, acting as risk management platforms, and focusing on support of business outcomes.
“The privacy tech sector is at an inflection point, as its offerings have expanded beyond assisting with regulatory compliance,” said FPF CEO Jules Polonetsky. “Increasingly, companies want privacy tech to help businesses maximize the utility of data while managing ethics and data protection compliance.”
According to the report, “Privacy Tech’s Third Generation: A Review of the Emerging Privacy Tech Sector,” regulations are often the biggest driver for buyers’ initial privacy tech purchases. Organizations also are deploying tools to mitigate potential harms from the use of data. However, buyers serving global markets increasingly need privacy tech that offers data availability and control and supports its utility, in addition to regulatory compliance.
The report finds the COVID-19 pandemic has accelerated global marketplace adoption of privacy tech as dependence on digital technologies grows. Privacy is becoming a competitive differentiator in some sectors, and TechCrunch reports that 200+ privacy startups have together raised more than $3.5 billion over hundreds of individual rounds of funding.
“The customers buying privacy-enhancing tech used to be primarily Chief Privacy Officers,” said report lead author Tim Sparapani. “Now it’s also Chief Marketing Officers, Chief Data Scientists, and Strategy Officers who value the insights they can glean from de-identified customer data.”
The report highlights five trends in the privacy enhancing tech market:
Buyers desire “enterprise-wide solutions.”
Buyers favor integrated technologies.
Some vendors are moving to either collaborate and integrate or provide fully integrated solutions themselves.
Data is the enterprise asset.
Jurisdiction impacts a shared vernacular problem.
The report also draws seven implications for competition in the market:
Buyers favor integrated solutions over one-off solutions.
Collaborations, partners, cross-selling, and joint ventures between privacy tech vendors are increasing to provide buyers integrated suites of services and to attract additional market share.
Private equity and private equity-backed companies will continue their “roll-up” strategies of buying niche providers to build a package of companies to provide the integrated solutions buyers favor.
Venture capital will continue funding the privacy tech sector, though not every seller has the same level of success fundraising.
Big companies may acquire strategically valuable, niche players.
Small startups may struggle to gain market traction absent a truly novel or superb solution.
Buyers will face challenges in future-proofing their privacy strategies.
The report makes a series of recommendations, including that the industry define as a priority a common vernacular for privacy tech; set standards for technologies in the “privacy stack” such as differential privacy, homomorphic encryption, and federated learning; and explore the needs of companies for privacy tech based upon their size, sector, and structure. It calls on vendors to recognize the need to provide adequate support to customers to increase uptake and speed time from contract signing to successful integration.
The Future of Privacy Forum launched the Privacy Tech Alliance (PTA) as a global initiative with a mission to define, enhance and promote the market for privacy technologies. The PTA brings together innovators in privacy tech with customers and key stakeholders.
Members of the PTA Advisory Board, which includes Anonos, BigID, D-ID, Duality, Ethyca, Immuta, OneTrust, Privacy Analytics, Privitar, SAP, Truata, TrustArc, Wirewheel, and ZL Tech, have formed a working group to address impediments to growth identified in the report. The PTA working group will define a common vernacular and typology for privacy tech as a priority project with chief privacy officers and other industry leaders who are members of FPF. Other work will seek to develop common definitions and standards for privacy-enhancing technologies such as differential privacy, homomorphic encryption, and federated learning and identify emerging trends for venture capitalists and other equity investors in this space. Privacy Tech companies can apply to join the PTA by emailing [email protected].
Perspectives on the Privacy Tech Market
Quotes from Members of the Privacy Tech Alliance Advisory Board on the Release of the “Privacy Tech’s Third Generation” Report
“The ‘Privacy Tech Stack’ outlined by the FPF is a great way for organizations to view their obligations and opportunities to assess and reconcile business and privacy objectives. The Schrems II decision by the Court of Justice of the European Union highlights that skipping the second ‘Process’ layer can result in desired ‘Outcomes’ in the third layer (e.g., cloud processing of, or remote access to, cleartext data) being unlawful – despite their global popularity – without adequate risk management controls for decentralized processing.” — Gary LaFever, CEO & General Counsel, Anonos
“As a founding member of this global initiative, we are excited by the conclusions drawn from this foundational report – we’ve seen parallels in our customer base, from needing an enterprise-wide solution to the rich opportunity for collaboration and integration. The privacy tech sector continues to mature as does the imperative for organizations of all sizes to achieve compliance in light of the increasingly complicated data protection landscape.’’—Heather Federman, VP Privacy and Policy at BigID
“There is no doubt of the massive importance of the privacy sector, an area which is experiencing huge growth. We couldn’t be more proud to be part of the Privacy Tech Alliance Advisory Board and absolutely support the work they are doing to create alignment in the industry and help it face the current set of challenges. In fact we are now working on a similar initiative in the synthetic media space to ensure that ethical considerations are at the forefront of that industry too.” — Gil Perry, Co-Founder & CEO, D-ID
“We congratulate the Future of Privacy Forum and the Privacy Tech Alliance on the publication of this highly comprehensive study, which analyzes key trends within the rapidly expanding privacy tech sector. Enterprises today are increasingly reliant on privacy tech, not only as a means of ensuring regulatory compliance but also in order to drive business value by facilitating secure collaborations on their valuable and often sensitive data. We are proud to be part of the PTA Advisory Board, and look forward to contributing further to its efforts to educate the market on the importance of privacy-tech, the various tools available and their best utilization, ultimately removing barriers to successful deployments of privacy-tech by enterprises in all industry sectors” — Rina Shainski, Chairwoman, Co-founder, Duality
“Since the birth of the privacy tech sector, we’ve been helping companies find and understand the data they have, compare it against applicable global laws and regulations, and remediate any gaps in compliance. But as the industry continues to evolve, privacy tech also is helping show business value beyond just compliance. Companies are becoming more transparent, differentiating on ethics and ESG, and building businesses that differentiate on trust. The privacy tech industry is growing quickly because we’re able to show value for compliance as well as actionable business insights and valuable business outcomes.” — Kabir Barday, CEO, OneTrust
“Leading organizations realize that to be truly competitive in a rapidly evolving marketplace, they need to have a solid defensive footing. Turnkey privacy technologies enable them to move onto the offense by safely leveraging their data assets rapidly at scale.” — Luk Arbuckle, Chief Methodologist, Privacy Analytics
“We appreciate FPF’s analysis of the privacy tech marketplace and we’re looking forward to further research, analysis, and educational efforts by the Privacy Tech Alliance. Customers and consumers alike will benefit from a shared understanding and common definitions for the elements of the privacy stack.” — Corinna Schulze, Director, EU Government Relations, Global Corporate Affairs, SAP
“The report shines a light on the evolving sophistication of the privacy tech market and the critical need for businesses to harness emerging technologies that can tackle the multitude of operational challenges presented by the big data economy. Businesses are no longer simply turning to privacy tech vendors to overcome complexities with compliance and regulation; they are now mapping out ROI-focused data strategies that view privacy as a key commercial differentiator. In terms of market maturity, the report highlights a need to overcome ambiguities surrounding new privacy tech terminology, as well as discrepancies in the mapping of technical capabilities to actual business needs. Moving forward, the advantage will sit with those who can offer the right blend of technical and legal expertise to provide the privacy stack assurances and safeguards that buyers are seeking – from a risk, deployment and speed-to-value perspective. It’s worth noting that the growing importance of data privacy to businesses sits in direct correlation with the growing importance of data privacy to consumers. Trūata’s Global Consumer State of Mind Report 2021 found that 62% of global consumers would feel more reassured and would be more likely to spend with companies if they were officially certified to a data privacy standard. Therefore, in order to manage big data in a privacy-conscious world, the opportunity lies with responsive businesses that move with agility and understand the return on privacy investment. The shift from manual, restrictive data processes towards hyper automation and privacy-enhancing computation is where the competitive advantage can be gained and long-term consumer loyalty—and trust— can be retained.” — Aoife Sexton, Chief Privacy Officer and Chief of Product Innovation, Trūata
“As early pioneers in this space, we’ve had a unique lens on the evolving challenges organizations have faced in trying to integrate technology solutions to address dynamic, changing privacy issues in their organizations, and we believe the Privacy Technology Stack introduced in this report will drive better organizational decision-making related to how technology can be used to sustainably address the relationships among the data, processes, and outcomes.” — Chris Babel, CEO, TrustArc
“It’s important for companies that use data to do so ethically and in compliance with the law, but those are not the only reasons why the privacy tech sector is booming. In fact, companies with exceptional privacy operations gain a competitive advantage, strengthen customer relationships, and accelerate sales.” — Justin Antonipillai, Founder & CEO, Wirewheel
The right to be forgotten is not compatible with the Brazilian Constitution. Or is it?
The Brazilian Supreme Federal Court, or “STF” in its Brazilian acronym, recently took a landmark decision concerning the right to be forgotten (RTBF), finding that it is incompatible with the Brazilian Constitution. This attracted international attention to Brazil for a topic quite distant than the sadly frequent environmental, health, and political crises.
Readers should be warned that while reading this piece they might experience disappointment, perhaps even frustration, then renewed interest and curiosity and finally – and hopefully – an increased open-mindedness, understanding a new facet of the RTBF debate, and how this is playing out at constitutional level in Brazil.
This might happen because although the STF relies on the “RTBF” label, the content behind such label is quite different from what one might expect after following the same debate in Europe. From a comparative law perspective, this landmark judgment tellingly shows how similar constitutional rights play out in different legal cultures and may lead to heterogeneous outcomes based on the constitutional frameworks of reference.
How it started: insolvency seasoned with personal data
As it is well-known, the first global debate on what it means to be “forgotten” in the digital environment arose in Europe, thanks to Mario Costeja Gonzalez, a Spaniard who, paradoxically, will never be forgotten by anyone due to his key role in the construction of the RTBF.
Costeja famously requested to deindex from Google Search information about himself that he considered to be no longer relevant. Indeed, when anyone “googled” his name, the search engine provided as the top results some link to articles reporting Costeja’s past insolvency as a debtor. Costeja argued that, despite having been convicted for insolvency, he had already paid his debt with Justice and society many years before and it was therefore unfair that his name would continue to be associated ad aeternum with a mistake he made in the past.
The follow up is well known in data protection circles. The case reached the Court of Justice of the European Union (CJEU), which, in its landmark Google Spain Judgment (C-131/12), established that search engines shall be considered as data controllers and, therefore, they have an obligation to de-index information that is inappropriate, excessive, not relevant, or no longer relevant, when a data subject to whom such data refer requests it. Such an obligation was a consequence of Article 12.b of Directive 95/46 on the protection of personal data, a pre-GDPR provision that set the basis for the European conception of the RTBF, providing for the “rectification, erasure or blocking of data the processing of which does not comply with the provisions of [the] Directive, in particular because of the incomplete or inaccurate nature of the data.”
The indirect consequence of this historic decision, and the debate it generated, is that we have all come to consider the RTBF in the terms set by the CJEU. However, what is essential to emphasize is that the CJEU approach is only one possible conception and, importantly, it was possible because of the specific characteristics of the EU legal and institutional framework. We have come to think that RTBF means the establishment of a mechanism like the one resulting from the Google Spain case, but this is the result of a particular conception of the RTBF and of how this particular conception should – or could – be implemented.
The fact that the RTBF has been predominantly analyzed and discussed through the European lenses does not mean that this is the only possible perspective, nor that this approach is necessary the best. In fact, the Brazilian conception of the RTBF is remarkably different from a conceptual, constitutional, and institutional standpoint. The main concern of the Brazilian RTBF is not how a data controller might process personal data (this is the part where frustration and disappointment might likely arise in the reader) but the STF itself leaves the door open to such possibility (this is the point where renewed interest and curiosity may arise).
The Brazilian conception of the right to be forgotten
Although the RTBF has acquired a fundamental relevance in digital policy circles, it is important to emphasize that, until recently, Brazilian jurisprudence had mainly focused on the juridical need for “forgetting” only in the analogue sphere. Indeed, before the CJEU Google Spain decision, the Brazilian Supreme Court of Justice or “STJ” – the other Brazilian Supreme Court that deals with the interpretation of the Law, differently from the previously mentioned STF, which deals with the interpretation of constitutional matters – had already considered the RTBF as a right not to be remembered, affirmed by the individual vis-à-vis traditional media outlets.
This interpretation first emerged in the “Candelaria massacre” case, a gloomy page of Brazilian history, featuring a multiple homicide perpetrated in 1993 in front of the Candelaria Church, a beautiful colonial Baroque building in Rio de Janeiro’s downtown. The gravity and the particularly picturesque stage of the massacre led Globo TV, a leading Brazilian broadcaster, to feature the massacre in a TV show called Linha Direta. Importantly, the show included in the narration some details about a man suspected of being one of the perpetrators of the massacre but later discharged.
Understandably, the man filed a complaint arguing that the inclusion of his personal information in the TV show was causing him severe emotional distress, while also reviving suspects against him, for a crime he had already been discharged of many years before. In September 2013, further to Special Appeal No. 1,334,097, the STJ agreed with the plaintiff establishing the man’s “right not to be remembered against his will, specifically with regard to discrediting facts.” This is how the RTBF was born in Brazil.
Importantly for our present discussion, this interpretation is not born out of digital technology and does not impinge upon the delisting of specific type of information as results of search engine queries. In Brazilian jurisprudence the RTBF has been conceived as a general right to effectively limit the publication of certain information. The man included in the Globo reportage had been discharged many years before, hence he had a right to be “let alone,” as Warren and Brandeis would argue, and not to be remembered for something he had not even committed. The STJ, therefore, constructed its vision of the RTBF, based on article 5.X of the Brazilian Constitution, enshrining the fundamental right to intimacy and preservation of image, two fundamental features of privacy.
Hence, although they utilize the same label, the STJ and CJEU conceptualize two remarkably different rights, when they refer to the RTBF. While both conceptions aim at limiting access to specific types of personal information, the Brazilian conception differs from the EU one on at least three different levels.
First, their constitutional foundations. While both conceptions are intimately intertwined with individuals’ informational self-determination, the STJ built the RTBF based on the protection of privacy, honour and image, whereas the CJEU built it upon the fundamental right to data protection, which in the EU framework is a standalone fundamental right. Conspicuously, in the Brazilian constitutional framework an explicit right to data protection did not exist at the time of the Candelaria case and only since 2020 it has been in the process of being recognized.
Secondly, and consequently, the original goal of the Brazilian conception of the RTBF was not to regulate how a controller should process personal data but rather to protect the private sphere of the individual. In this perspective, the goal of STJ was not – and could not have been – to regulate the deindexation of specific incorrect or outdated information, but rather to regulate the deletion of “discrediting facts” so that the private life, honour and image of any individual might be illegitimately violated.
Finally, yet extremely importantly, the fact that, at the time of the decision, an institutional framework dedicated to data protection was simply absent in Brazil did not allow the STJ to have the same leeway of the CJEU. The EU Justices enjoyed the privilege of delegating to search engine the implementation of the RTBF because, such implementation would have received guidance and would have been subject to the review of a well-consolidated system of European Data Protection Authorities. At the EU level, DPAs are expected to guarantee a harmonious and consistent interpretation and application of data protection law. At the Brazilian level, a DPA has just been established in late 2020 and announced its first regulatory agenda only in late January 2021.
This latter point is far from trivial and, in the opinion of this author, an essential preoccupation that might have driven the subsequent RTBF conceptualization of the STJ.
The stress-test
The soundness of the Brazilian definition of the RTBF, however, was going to be tested again by the STJ, in the context of another grim and unfortunate page of Brazilian story, the Aida Curi case. This case originated with the sexual assault and subsequent homicide of the young Aida Curi, in Copacabana, Rio de Janeiro, on the evening of 14 July 1958. At the time the case crystallized considerable media attention, not only because of its mysterious circumstances and the young age of the victim, but also because the sexual assault perpetrators tried to dissimulate it by throwing the body of the victim from the rooftop of a very high building on the Avenida Atlantica, the fancy avenue right in front of the Copacabana beach.
Needless to say, Globo TV considered the case as a perfect story for yet another Linha Direta episode. Aida Curi’s relatives, far from enjoying the TV show, sued the broadcaster for moral damages and demanded the full enjoyment of their RTBF – in the Brazilian conception, of course. According to the plaintiffs, it was indeed not conceivable that, almost 50 years after the murder, Globo TV could publicly broadcast personal information about the victim – and her family – including the victim’s name and address, in addition to unauthorized images, thus bringing back a long-closed and extremely traumatic set of events.
The brothers of Aida Curi claimed reparation against Rede Globo, but the STJ, decided that the time passed was enough to mitigate the effects of anguish and pain on the dignity of Aida Curi’s relatives, while arguing that it was impossible to report the events without mentioning the victim. This decision was appealed by Ms Curi’s family members, who demanded by means of Extraordinary Appeal No. 1,010,606, that STF recognized “their right to forget the tragedy.” It is interesting to note that the way the demand is constructed in this Appeal exemplifies tellingly the Brazilian conception of “forgetting” as erasure and prohibition from divulgation.
At this point, the STF identified in the Appeal the interest of debating the issue “with general repercussion” which is a peculiar judicial process that the Court can utilize when recognizes that a given case has particular relevance and transcendence for the Brazilian legal and judicial system. Indeed, the decision of a case with general repercussion does not only bind the parties but rather establishes a jurisprudence that must be replicated by all lower-level courts.
In February 2021, the STF finally deliberated on the Aida Curi case, establishing that “the idea of a right to be forgotten is incompatible with the Constitution, thus understood as the power to prevent, due to the passage of time, the disclosure of facts or data that are true and lawfully obtained and published in analogue or digital media” and that “any excesses or abuses in the exercise of freedom of expression and information must be analyzed on a case-by-case basis, based on constitutional parameters – especially those relating to the protection of honor, image, privacy and personality in general – and the explicit and specific legal provisions existing in the criminal and civil spheres.”
In other words, what the STF has deemed as incompatible with the Federal Constitution is a specific interpretation of the Brazilian version of the RTBF. What is not compatible with the Constitution is to argue that the RTBF allows to prohibit publishing true facts, lawfully obtained. At the same time, however, the STF clearly states that it remains possible for any Court of law to evaluate, on a case-by-case basis and according to constitutional parameters and existing legal provisions, if a specific episode can allow the use of the RTBF to prohibit the divulgation of information that undermine the dignity, honour, privacy, or other fundamental interests of the individual.
Hence, while explicitly prohibiting the use of the RTBF as a general right to censorship, the STF leaves room for the use of the RTBF for delisting specific personal data in an EU-like fashion, while specifying that this must be done finding guidance in the Constitution and the Law.
What next?
Given the core differences between the Brazilian and EU conception of the RTBF, as highlighted above, it is understandable in the opinion of this author that the STF adopted a less proactive and more conservative approach. This must be especially considered in light of the very recent establishment of a data protection institutional system in Brazil.
It is understandable that the STF might have preferred to de facto delegate the interpretation of when and how the RTBF could be rightfully invoked before Courts, according to constitutional and legal parameters. First, in the Brazilian interpretation of the RTBF, this right fundamentally insist on the protection of privacy – i.e. the private sphere of an individual – and, while admitting the existence of data protection concerns, these are not the main ground on which the Brazilian RTBF conception relays.
It is understandable that in a country and a region where the social need to remember and shed light on what happened in a recent history, marked by dictatorships, well-hidden atrocities, and opacity, outweighs the legitimate individual interest to prohibit the circulation of truthful and legally obtained information. In the digital sphere, however, the RTBF quintessentially translates into an extension of informational self-determination, which the Brazilian General Data Protection Law, better known as “LGPD” (Law No. 13.709 / 2018), enshrines in its article 2 as one of the “foundations” of data protection in the country and that whose fundamental character was recently recognized by the STF itself.
In this perspective, it is useful to remind the dissenting opinion of Justice Luiz Edson Fachin, in the Aida Curi case, stressing that “although it does not expressly name it, the Constitution of the Republic, in its text, contains the pillars of the right to be forgotten, as it celebrates the dignity of the human person (article 1, III), the right to privacy (article 5, X) and the right to informational self-determination – which was recognized, for example, in the disposal of the precautionary measures of the Direct Unconstitutionality Actions No. 6,387, 6,388, 6,389, 6,390 and 6,393, under the rapporteurship of Justice Rosa Weber (article 5, XII).”
It is the opinion of this author that the Brazilian debate on the RTBF in the digital sphere would be clearer if it its dimension as a right to deindexation of search engines results were to be clearly regulated. It is understandable that the STF did not dare regulating this, given its interpretation of the RTBF and the very embryonic data protection institutional framework in Brazil. However, given the increasing datafication we are currently witnessing, it would be naïve not to expect that further RTBF claims concerning the digital environment and, specifically, the way search engines process personal data will keep emerging.
The fact that the STF has left the door open to apply the RTBF in the case-by-case analysis of individual claims may reassure the reader regarding the primacy of constitutional and legal arguments in such case-by-case analysis. It may also lead the reader to – very legitimately – wonder whether such a choice is the facto the most efficient to deal with the potentially enormous number of claims and in the most coherent way, given the margin of appreciation and interpretation that each different Court may have.
An informed debate able to clearly highlight what are the existing options and what might be the most efficient and just ways to implement them, considering the Brazilian context, would be beneficial. This will likely be one of the goals of the upcoming Latin American edition of the Computers, Privacy and Data Protection conference (CPDP LatAm) that will take place in July, entirely online, and will aim at exploring the most pressing issues for Latin American countries regarding privacy and data protection.
If you have any questions about engaging with The Future of Privacy Forum on Global Privacy and Digital Policymaking contact Dr. Gabriela Zanfir-Fortuna, Senior Counsel, at [email protected].
FPF announces appointment of Malavika Raghavan as Senior Fellow for India
The Future of Privacy Forum announces the appointment of Malavika Raghavan as Senior Fellow for India, expanding our Global Privacy team to one of the key jurisdictions for the future of privacy and data protection law.
Malavika is a thought leader and a lawyer working on interdisciplinary research, focusing on the impacts of digitisation on the lives of lower-income individuals. Her work since 2016 has focused on the regulation and use of personal data in service delivery by the Indian State and private sector actors. She has founded and led the Future of Finance Initiative for Dvara Research (an Indian think tank) in partnership with the Gates Foundation from 2016 until 2020, anchoring its research agenda and policy advocacy on emerging issues at the intersection of technology, finance and inclusion. Research that she led at Dvara Research was cited by the India’s Data Protection Committee in its White Paper as well as its final report with proposals for India’s draft Personal Data Protection Bill, with specific reliance placed on such research on aspects of regulatory design and enforcement. See Malavika’s full bio here.
“We are delighted to welcome Malavika to our Global Privacy team. For the following year, she will be our adviser to understand the most significant developments in privacy and data protection in India, from following the debate and legislative process of the Data Protection Bill and the processing of non-personal data initiatives, to understanding the consequences of the publication of the new IT Guidelines. India is one of the most interesting jurisdictions to follow in the world, for many reasons: the innovative thinking on data protection regulation, the potentially groundbreaking regulation of non-personal data and the outstanding number of individuals whose privacy and data protection rights will be envisaged by these developments, which will test the power structures of digital regulation and safeguarding fundamental rights in this new era”, said Dr. Gabriela Zanfir-Fortuna, Global Privacy lead at FPF.
We have asked Malavika to share her thoughts for FPF’s blog on what are the most significant developments in privacy and digital regulation in India and about India’s role in the global privacy and digital regulation debate.
FPF: What are some of the most significant developments in the past couple of years in India in terms of data protection, privacy, digital regulation?
Malavika Raghavan: “Undoubtedly, the turning point for the privacy debate India was the 2017 judgement of the Indian Supreme Court in Justice KS Puttaswamy v Union of India. The judgment affirmed the right to privacy as a constitutional guarantee, protected by Part III (Fundamental Rights) of the Indian Constitution. It was also regenerative, bringing our constitutional jurisprudence into the 21st century by re-interpreting timeless principles for the digital age, and casting privacy as a prerequisite for accessing other rights—including the right to life and liberty, to freedom of expression and to equality—given the ubiquitous digitisation of human experience we are witnessing today.
Overnight, Puttaswamy also re-balanced conversations in favour of privacy safeguards to make these equal priorities for builders of digital systems, rather than framing these issues as obstacles to innovation and efficiency. In addition, it challenged the narrative that privacy is an elite construct that only wealthy or privileged people deserve— since many litigants in the original case that had created the Puttaswamy reference were from marginalised groups. Since then, a string of interesting developments have arisen as new cases are reassessing the impact of digital technology on individuals in India, for e.g. the boundaries case of private sector data sharing (such as between Whatsapp and Facebook), or the State’s use of personal data (as in the case concerning Aadhaar, our national identification system) among others.
Puttaswamy also provided fillip for a big legislative development, which is the creation of an omnibus data protection law in India. A bill to create this framework was proposed by a Committee of Experts under the chairmanship of Justice Srikrishna (an ex-Supreme Court judge), which has been making its way through ministerial and Parliamentary processes. There’s a large possibility that this law will be passed by the Indian parliament in 2021! Definitely a big development to watch.
FPF: How do you see India’s role in the global privacy and digital regulation debate?
Malavika Raghavan: “India’s strategy on privacy and digital regulation will undoubtedly have global impact, given that India is home to 1/7th of the world’s population! The mobile internet revolution has created a huge impact on our society with millions getting access to digital services in the last couple of decades. This has created nuanced mental models and social norms around digital technologies that are slowly being documented through research and analysis.
The challenge for policy makers is to create regulations that match these expectations and the realities of Indian users to achieve reasonable, fair regulations. As we have already seen from sectoral regulations (such as those from our Central Bank around cross border payments data flows) such regulations also have huge consequences for global firms interacting with Indian users and their personal data.
In this context, I think India can have the late-mover advantage in some ways when it comes to digital regulation. If we play our cards right, we can take the best lessons from the experience of other countries in the last few decades and eschew the missteps. More pragmatically, it seems inevitable that India’s approach to privacy and digital regulation will also be strongly influenced by the Government’s economic, geopolitical and national security agenda (both internationally and domestically).
One thing is for certain: there is no path-dependence. Our legislators and courts are thinking in unique and unexpected ways that are indeed likely to result in a fourth way (as described by the Srikrishna Data Protection Committee’s final report), compared to the approach in the US, EU and China.”
If you have any questions about engaging with The Future of Privacy Forum on Global Privacy and Digital Policymaking contact Dr. Gabriela Zanfir-Fortuna, Senior Counsel, at [email protected].
India: Massive overhaul of digital regulation, with strict rules for take-down of illegal content and Automated scanning of online content
On February 25, the Indian Government notified and published Information Technology (Guidelines for Intermediaries and Digital media Ethics Code) Rules 2021. These rules mirror the Digital Services Act (DSA) proposal of the EU to some extent, since they propose a tiered approach based on the scale of the platform, they touch on intermediary liability, content moderation, take-down of illegal content from online platforms, as well as internal accountability and oversight mechanisms, but they go beyond such rules by adding a Code of Ethics for digital media, similar to the Code of Ethics classic journalistic outlets must follow, and by proposing an “online content” labelling scheme for content that is safe for children.
The Code of Ethics applies to online news publishers, as well as intermediaries that “enable the transmission of news and current affairs”. This part of the Guidelines (the Code of Ethics) has already been challenged in the Delhi High Court by news publishers this week.
The Guidelines have raised several types of concerns in India, from their impact on freedom of expression, impact on the right to privacy through the automated scanning of content and the imposed traceability of even end-to-end encrypted messages so that the originator can be identified, to the choice of the Government to use executive action for such profound changes. The Government, through the two Ministries involved in the process, is scheduled to testify in the Standing Committee of Information Technology of the Parliament on March 15.
New obligations for intermediaries
“Intermediaries” include “websites, apps and portals of social media networks, media sharing websites, blogs, online discussion forums, and other such functionally similar intermediaries” (as defined in rule 2(1)(m)).
Here are some of the most important rules laid out in Part II of the Guidelines, dedicated to Due Diligence by Intermediaries:
All intermediaries, regardless of size or nature, will be under an obligation to “remove or disable access” as early as possible and no later than 36 hours of content subject to a Court order or an order of a Government agency (see rule 4(1)(d)).
All intermediaries will be under an obligation to inform users at least once per year about their content policies, which must at a minimum include rules such as not uploading, storing or sharing information that “belongs to another person and to which the user does not have any right”, “deceives or misleads the addressee about the origin of the message”, “is patently false and untrue” or “is harmful to minors” (see rules 4(1)(b) and (f)).
All intermediaries will have to provide information to authorities for the purpose of identity verification and for investigating and prosecuting offenses, within 72 hours of receiving an order from an authorised government agency (see rule 4(1)(j)).
All intermediaries will have to take all measures to remove or limit accesswithin 24 hours of receiving a complaint from a user, to any content that reveals nudity, amounts to sexual harassment, or represents a deep fake, and the content is transmitted with the intent to harass, intimidate, threaten or abuse an individual (see rule 4(1)(p)).
“Significant social media intermediaries” have enhanced obligations
“Significant social media intermediaries” are social media services with a number of users above a threshold which will be defined and notified by the Central Government. This concept is similar to the the DSA’s “Very Large Online Platform”, however the DSA includes clear criteria in the proposed act itself on how to identify a VLOP.
As for Significant Social Media Intermediaries” in India, they will have additional obligations (similar to how the DSA proposal in the EU scales obligations):
“Significant social media intermediaries” that provide messaging services will be under an obligation to identify the “first originator” of a message following a Court order or an order from a Competent Authority (see rule 5(2)). This provision raises significant concerns over end-to-end encryption and encryption backdoors.
They will have to appoint a Chief Compliance Officer for the purposes of complying with these rules and who will be liable for failing to ensure that the intermediary observes due diligence obligations; the CCO will have to hold an Indian passport and will have to be based in India;
They will have to appoint a Chief Grievance Officer, who also must be based in India.
Publish compliance reports every 6 months.
Deploy automated scanning to proactively identify all identical information to content removed following an order (under the 36 hours rule), as well as child sexual abuse and related content (see rule 5(4)).
Set up an internal mechanism for receiving complaints.
These “Guidelines” seem to have the legal effect of a statute, and they are being adopted through executive action to replace Guidelines adopted in 2011 by the Government, under powers conferred to it in the Information Technology Act 2000. The new Guidelines would enter into force immediately after publication in the Official Gazette (no information as to when publication is scheduled). The Code of Ethics would enter into force three months after the publication in the Official Gazette. As mentioned above, there are already some challenges in Court against part of these rules.
This analysis by Rahul Matthan, who raises questions with regard to “identifying the first originator” rule, arguing that it is likely the Indian Supreme Court would declare such a measure unconstitutional: “Traceability is Antithetical to Liberty”.
Another jurisdiction to keep your eyes on: Australia
Also note that, while the European Union is starting its heavy and slow legislative machine, by appointing Rapporteurs in the European Parliament and having first discussions on the DSA proposal in the relevant working group of the Council, another country is set to soon adopt digital content rules: Australia. The Government is currently considering an Online Safety Bill, which was open to public consultation until mid February and which would also include a “modernised online content scheme”, creating new classes of harmful online content, as well as take-down requirements for image-based abuse, cyber abuse and harmful content online, requiring removal within 24 hours of receiving a notice from the eSafety Commissioner.
If you have any questions about engaging with The Future of Privacy Forum on Global Privacy and Digital Policymaking contact Dr. Gabriela Zanfir-Fortuna, Senior Counsel, at [email protected].
Russia: New Law Requires Express Consent for Making Personal Data Available to the Public and for Any Subsequent Dissemination
Authors: Gabriela Zanfir-Fortuna and Regina Iminova
Source: Pixabay.Com, by Opsa
Amendments to the Russian general data protection law (Federal Law No. 152-FZ on Personal Data) adopted at the end of 2020 enter into force today (Monday, March 1st), with some of them having the effective date postponed until July 1st. The changes are part of a legislative package that is also seeing the Criminal Code being amended to criminalize disclosure of personal data about “protected persons” (several categories of government officials). The amendments to the data protection law envision the introduction of consent based restrictions for any organization or individual that publishes personal data initially, as well as for those that collect and further disseminate personal data that has been distributed on the basis of consent in the public sphere, such as on social media, blogs or any other sources.
The amendments:
introduce a new category of personal data, defined as “personal data allowed by the data subject to be disseminated” (hereinafter PDD – personal data allowed for dissemination);
include strict rules for initially making personal data available to an unlimited number of persons, but also for further processing PDD by other organizations or individuals, including for further disseminating this type of data – all of this must be done on the basis of specific, affirmative and separately collected consent from the data subject, the existence of which must be proved at any point of the use and further use;
introduce the possibility of the Russian regulator enforcing this law (“Roskomnadzor”) to record in a centralized information system the consent obtained for dissemination of personal data to an unlimited number of persons;
introduce an absolute right to opt out of the dissemination of personal data, “at any time”.
The potential impact of the amendments is broad. The new law prima facie affects social media services, online publishers, streaming services, bloggers, or any other entity who might be considered as making personal data available to “an indefinite number of persons.” They now have to collect and prove they have separate consent for making personal data publicly available, as well as for further publishing or disseminating PDD which has been lawfully published by other parties originally.
Importantly, the new provisions in the Personal Data Law dedicated to PDD do not include any specific exception for processing PDD for journalistic purposes. The only exception recognized is processing PDD “in the state and public interests defined by the legislation of the Russian Federation”. The Explanatory Note accompanying the amendments confirms that consent is the exclusive lawful ground that can justify dissemination and further processing of PDD and that the only exception to this rule is the one mentioned above, for state or public interests as defined by law. It is thus expected that the amendments might create a chilling effect on freedom of expression, especially when also taking into account the corresponding changes to the Criminal Code.
The new rules seem to be part of a broader effort in Russia to regulate information shared online and available to the public. In this context, it is noteworthy that other amendments to Law 149-FZ on Information, IT and Protection of Information solely impacting social media services were also passed into law in December 2020, and already entered into force on February 1st, 2021. Social networks are now required to monitor content and “restrict access immediately” of users that post information about state secrets, justification of terrorism or calls to terrorism, pornography, promoting violence and cruelty, or obscene language, manufacturing of drugs, information on methods to commit suicide, as well as calls for mass riots.
Below we provide a closer look at the amendments to the Personal Data Law that entered into force on March 1st, 2021.
A new category of personal data is defined
The new law defines a category of “personal data allowed by the data subject to be disseminated” (PDD), the definition being added as paragraph 1.1 to Article 3 of the Law. This new category of personal data is defined as “personal data to which an unlimited number of persons have access to, and which is provided by the data subject by giving specific consent for the dissemination of such data, in accordance with the conditions in the Personal Data Law” (unofficial translation).
The old law had a dedicated provision that referred to how this type of personal data could be lawfully processed, but it was vague and offered almost no details. In particular, Article 6(10) of the Personal Data Law (the provision corresponding to Article 6 GDPR on lawful grounds for processing) provided that processing of personal data is lawful when the data subject gives access to their personal data to an unlimited number of persons. The amendments abrogate this paragraph, before introducing an entirely new article containing a detailed list of conditions for processing PDD only on the basis of consent (the new Article 10.1).
Perhaps in order to avoid misunderstanding on how the new rules for processing PDD fit with the general conditions on lawful grounds for processing personal data, a new paragraph 2 is introduced in Article 10 of the law, which details conditions for processing special categories of personal data, to clarify that processing of PDD “shall be carried out in compliance with the prohibitions and conditions provided for in Article 10.1 of this Federal Law”.
Specific, express, unambiguous and separate consent is required
Under the new law, “data operators” that process PDD must obtain specific and express consent from data subjects to process personal data, which includes any use, dissemination of the data. Notably, under the Russian law, “data operators” designate both controllers and processors in the sense of the General Data Protection Regulation (GDPR), or businesses and service providers in the sense of the California Consumer Privacy Act (CCPA).
Specifically, under Article 10.1(1), the data operator must ensure that it obtains a separate consent dedicated to dissemination, other than the general consent for processing personal data or other type of consent. Importantly, “under no circumstances” may individuals’ silence or inaction be taken to indicate their consent to the processing of their personal data for dissemination, under Article 10.1(8).
In addition, the data subject must be provided with the possibility to select the categories of personal data which they permit for dissemination. Moreover, the data subject also must be provided with the possibility to establish “prohibitions on the transfer (except for granting access) of [PDD] by the operator to an unlimited number of persons, as well as prohibitions on processing or conditions of processing (except for access) of these personal data by an unlimited number of persons”, per Article 10.1(9). It seems that these prohibitions refer to specific categories of personal data provided by the data subject to the operator (out of a set of personal data, some categories may be authorized for dissemination, while others may be prohibited from dissemination).
If the data subject discloses personal data to an unlimited number of persons without providing to the operator the specific consent required by the new law, not only the original operator, but all subsequent persons or operators that processed or further disseminated the PDD have the burden of proof to “provide evidence of the legality of subsequent dissemination or other processing”, under Article 10.1(2), which seems to imply that they must prove consent was obtained for dissemination (probatio diabolica in this case). According to the Explanatory Note to the amendments, it seems that the intention was indeed to turn the burden of proof of legality of processing PDD from data subjects to the data operators, since the Note makes a specific reference to the fact that before the amendments the burden of proof rested with data subjects.
If the separate consent for dissemination of personal data is not obtained by the operator, but other conditions for lawfulness of processing are met, the personal data can be processed by the operator, but without the right to distribute or disseminate them – Article 10.1.(4).
A Consent Management Platform for PDD, managed by the Roskomnadzor
The express consent to process PDD can be given directly to the operator or through a special “information system” (which seems to be a consent management platform) of the Roskomnadzor, according to Article 10.1(6). The provisions related to setting up this consent platform for PDD will enter into force on July 1st, 2021. The Roskomnadzor is expected to provide technical details about the functioning of this consent management platform and guidelines on how it is supposed to be used in the following months.
Absolute right to opt-out of dissemination of PDD
Notably, the dissemination of PDD can be halted at any time, on request of the individual, regardless of whether the dissemination is lawful or not, according to Article 12.1(12). This type of request is akin to a withdrawal of consent. The provision includes some requirements for the content of such a request. For instance, it requires writing contact information and listing the personal data that should be terminated. Consent to the processing of the provided personal data is terminated once the operator receives the opt-out request – Article 10.1(13).
A request to opt-out of having personal data disseminated to the public when this is done unlawfully (without the data subject’s specific, affirmative consent) can also be made through a Court, as an alternative to submitting it directly to the data operator. In this case, the operator must terminate the transmission of or access to personal data within three business days from when such demand was received or within the timeframe set in the decision of the court which has come into effect – Article 10.1(14).
A new criminal offense: The prohibition on disclosure of personal data about protected persons
Sharing personal data or information about intelligence officers and their personal property is now a criminal offense under the new rules, which amended the Criminal Code. The law obliges any operators of personal data, including government departments and mobile operators, to ensure the confidentiality of personal information concerning protected persons, their relatives, and their property. Under the new law, “protected persons” include employees of the Investigative Committee, FSB, Federal Protective Service, National Guard, Ministry of Internal Affairs, and Ministry of Defense judges, prosecutors, investigators, law enforcement officers and their relatives. Moreover, the list of protected persons can be further detailed by the head of the relevant state body in which the specified persons work.
Previously, the law allowed for the temporary prohibition of the dissemination of personal data of protected persons only in the event of imminent danger in connection with official duties and activities. The new amendments make it possible to take protective measures in the absence of a threat of encroachment on their life, health and property.
What to watch next: New amendments to the general Personal Data Law are on their way in 2021
There are several developments to follow in this fast changing environment. First, at the end of January, the Russian President gave the government until August 1 to create a set of rules for foreign tech companies operating in Russia, including a requirement to open branch offices in the country.
Second, a bill (No. 992331-7) proposing new amendments to the overall framework of the Personal Data Law (No. 152-FZ) was introduced in July 2020 and was the subject of a Resolution that passed in the State Duma on February 16, allowing for a period for amendments to be submitted, until March 16. The bill is on the agenda for a potential vote in May. The changes would entail expanding the possibility to obtain valid consent through other unique identifiers which are currently not accepted by the law, such as unique online IDs, changes to purpose limitation, a possible certification scheme for effective methods to erase personal data and new competences for the Roskomnadzor to establish requirements for deidentification of personal data and specific methods for effective deidentification.
If you have any questions on Global Privacy and Data Protection developments, contact Gabriela Zanfir-Fortuna at [email protected]
Updating the Delaware Personal Data Privacy Act: The “First State” Becomes the Latest to Get a Privacy Refresh
Delaware has become the latest state to update its comprehensive privacy law after Governor Meyer signedHB 380 on September 2, amending the Delaware Personal Data Privacy Act (DPDPA). More than half of the 23 states with comprehensive privacy laws have now amended their laws. The bill makes significant revisions to the DPDPA, including—
An expanded definition of sensitive data;
Lowered applicability thresholds;
New contractual and novel due diligence requirements for disclosing personal data to third parties;
Additional contractual requirements and rights for disclosing “reports” to third parties used in profiling decisions made about “residents,” rather than “consumers,” and extending to employee data;
Adding and modifying consumer rights; and more.
These changes will take effect January 1, 2027.
Definitions & Scope
Changes to key definitions track trends in other states. For example, HB 380 narrows the definition of “publicly available information” to exclude biometric data that was collected without the consumer’s consent. “Sensitive data” is similarly broadened to explicitly include “inferences” that reveal sensitive data categories. This bill also adds new categories of sensitive data, including national origin, medical treatment or status (in addition to diagnosis), treatment as transgender or nonbinary (in addition to “status” as such), neural data, financial account information, and government-issued identification numbers. (§ 12D-102)
This bill also lowers the law’s applicability threshold and tightens entity-level exemptions, consistent with other legislative trends from recent years. The law will now apply to any person that, in the past calendar year, controlled or processed the personal data of at least (1) 10,000 Delaware consumers (excluding data processed solely for completing payment transactions) or (2) 5,000 Delaware consumers if the person derived more than 20% of their gross revenue from the sale of personal data. These figures are down from 35,000 and 10,000 in the original law. This bill also expands the law’s scope to include “[t]hird parties who acquire personal data from a controller.” (§§ 12D-103(a), 12D-107A)
Finally, consistent with yet another legislative trend, this bill removes the law’s GLBA-entity level exemption and replaces it with several tailored exemptions for the insurance, banking, and investment industries. The bill also adds new health-related data-level exemptions, including for information in a limited data set subject to protection under 45 CFR § 164.514(e). (§ 12D-103(b)-(c))
Due Diligence for Data Sales
This bill includes new contractual requirements for disclosing personal data to third parties. The contract must specify that the personal data is disclosed only for limited and specified purposes; obligate the third party to comply with the DPDPA’s requirements; grant the controller rights to take “reasonable and appropriate steps to ensure that the third party uses the personal data . . . in a manner consistent with the controller’s obligations under [the DPDPA]”; require the third party to notify the controller if it determines that it can no longer meet its obligations under the DPDPA; and grant the controller the right, upon notice, “to take reasonable and appropriate steps to stop and remediate unauthorized use of personal data.” (§ 12D-106(a)(10))
The controller is required to conduct reasonable due diligence of third party recipients of personal data to assess the recipient’s policies and technical and organizational measures undertaken to comply with the DPDPA. This due diligence must include the use of questionnaires and review of relevant documents, and additional reasonable measures should be taken as commensurate with the sensitivity of the data disclosed. A controller is further prohibited from selling sensitive data unless the disclosure of that data is strictly necessary to provide or maintain a product or service affirmatively requested by the consumer, the controller provides clear and conspicuous notice prior to the sale, the consumer consents to the disclosure, and the controller maintains a record of consent for 5 years. These new consent records must be provided alongside data protection assessments pursuant to the AG’s investigatory powers. (§ 12D-106(a)(11)-(12))
These requirements are similar to the CCPA’s required contracts for the sale of personal information. (See Cal. Civ. Code § 1798.100, subd. (d); CCPA Rules § 7053) Delaware’s requirements may be slightly broader, however, as they apply to the “disclosure” of personal data, “including in a sale of personal data or for targeted advertising.” The more significant difference is Delaware’s novel due diligence requirements, which are not typically seen in other laws.
These new requirements also apply when the disclosure of personal data to a third party is necessary for providing a product or service requested by a consumer (which would otherwise be exempt from the definition of “sale”). (§ 12D-102)
Profiling, Reports, and Adverse Actions
In recent years, various states have introduced heightened protections and rights for consumers with respect to profiling in furtherance of decisions that produce legal or similarly significant effects concerning a consumer (“significant decisions”). Minnesota’s law, for example, includes a broad right to contest adverse profiling decisions. Connecticut’s and Vermont’s laws have a slightly narrowed version that limits aspects of the right to only decisions concerning housing.
Delaware has taken a different approach. Under the amended DPDPA, a controller will have new obligations prior to and after disclosing a report to any third party for use in connection with any significant decision concerning a resident. Key definitions:
“‘Adverse action’ means any denial, cancellation, unfavorable change, increase in charge, exclusion of benefit, or other action adverse to the interests of a consumer or resident in connection with a decision that produces legal or similarly significant effects.”
“‘Decisions that produce legal or similarly significant effects’ means decisions that result in the provision or denial of financial or lending services, housing, insurance, education enrollment or opportunity, criminal justice, employment opportunities, health-care services, or access to essential goods or services.”
“‘Report’ means any written, oral, or other communication of any personal data by a controller or processor, including recommendations, summaries, or automated decisions based on personal data or profiling.”
“‘Resident’ means any natural person residing in the State.” (§ 12D-102)
Prior to disclosing a report to a third party for use in connection with a significant decision concerning a resident, the controller must enter into a contractual agreement with the third party that imposes a number of obligations. Under this required contract, a third party must provide notice to a resident of any adverse action based in whole or in part on any information in the report; provide a description of personal data relied upon in making the adverse action; include a statement that the resident has a right to obtain certain information from the controller, with the controller’s contact information; and include a statement that the resident has a right to request the third party perform a human review of the adverse action, provided that the review must be “technically feasible” and the third party does not have to offer the review if doing so is “not in the best interest of the resident” (e.g., where delay poses a risk to the resident’s life or safety). The required contract between a controller and third party for disclosing a report is “in addition to” the bill’s other new contractual requirement for disclosing personal data to a third party. (§ 12D-106(f)(1))
Apart from entering that contract with a third party prior to disclosing a report, a controller must comply with special access and correction rights for consumers. For the access request, a controller has 30 days to provide a resident with the personal data maintained by the controller concerning the resident, the source of personal data used in profiling, and identification of all third parties who obtained a report concerning the resident in the past 24 months. The controller must also provide the resident with an opportunity to correct any incorrect personal data, although there is no timeline specified for this right. (§ 12D-106(f)(2), (3))
These new requirements apply more broadly than the rest of the law, extending to employment contexts. HB 380 narrowed the law’s data-level exemption for data processed or maintained in “the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party,” providing that the exception now does not apply for personal data processed in connection with profiling and reports under these new requirements. While the definition of “consumer” exempts individuals acting in an employment context, these new controller duties apply to the disclosure of a report for use in connection with significant decisions concerning a “resident,” defined broadly as “a natural person residing in [Delaware].” (§§ 12D-102 & 12D-103(c)(11)(a))
Although these requirements are similar in kind to those under the Fair Credit Reporting Act (FCRA), HB 380 preserves the DPDPA’s existing FCRA exemption and clarifies that nothing in this new subsection applies to a controller or third party when the report or personal data consists of an output such as a score, model, or algorithm that is a consumer report—or would be a consumer report if furnished to a third party—and is furnished or disclosed in compliance with the FCRA. (§ 12D-106(g))
New & Modified Consumer Rights
This bill modifies the DPDPA’s consumer rights in several ways, all of which are similar to changes other states have previously made to their respective laws:
The right to access now explicitly includes inferences about the consumer that are derived from personal data and information about whether the consumer’s personal data is being processed for profiling to make a significant decision. The right to access is also narrowed to prohibit a controller from disclosing certain types of information to a consumer—SSNs, government-issued ID numbers, financial account numbers, health insurance and medical ID numbers, account passwords, security questions or answers, and biometric data. Rather, a controller must inform the consumer “with sufficient particularity” that the controller processes any of these types of data.
The right to know third-party recipients of one’s personal data is modified by HB 380. A consumer now has the right to obtain a list of third parties to which the controller disclosed the consumer’s personal data, not merely the categories of such third parties. However, the right no longer applies to pseudonymous data; does not require a controller to list a third party if doing so would reveal a trade secret; and the controller can provide a list of all third-party recipients of personal data rather than a list tailored to the consumer if compiling an individualized list cannot be done with “reasonable effort.”
The right to opt out of profiling is expanded to apply to profiling in furtherance of “automated decisions” that produce legal or similarly significant effects, rather than “solely automated decisions.” (§ 12D-104)
Additional Changes
This bill makes a number of additional changes to the law, including—
Requiring a controller to limit the processing of personal data to what is “reasonably necessary and proportional” in relation to the purposes for which the data is processed, as disclosed to the consumer;
For sensitive data, adding a dual requirement that processing must be pursuant to consent and must be reasonably necessary and proportionate to the disclosed processing purposes;
Adding bias-testing language to the prohibition on processing or profiling in violation of antidiscrimination law;
Expanding the teenager opt-in requirement to include profiling in addition to targeted advertising and the sale of personal data;
Adding a link for consumers to exercise their data rights to applications, not just websites;
Adding more specificity to the required controller-processor contract;
Modifying data protection assessment requirements (which only apply to controllers that process the data of at least 50,000 consumers) and adding new impact assessments for profiling that must be conducted “on a regular basis”;
Requiring that a controller or processor undertake reasonable diligence and oversight to ensure compliance with contractual commitments if that entity wants to benefit from the safe harbor from liability for violations of the DPDPA by a processor or third-party controller that received personal data from the entity; and more.
Many of these changes are similar to those Connecticut made to the CTDPA in 2025.
FPF at the Singapore Data Festival 2026: Agentic AI, Biometrics, and the Future of Digital Trust in APAC
Co-authors: Lauren Koek and Valentina Curatella, FPF APAC Interns
From July 20 to 24, 2026, the Future of Privacy Forum (FPF) participated in the inaugural Singapore Data Festival (SDF), hosted by Singapore’s Personal Data Protection Commission (PDPC) and Infocomm Media Development Authority (IMDA). Succeeding the PDPC’s annual Personal Data Protection Week, the SDF convened around 2,000 data and AI professionals, policymakers, and business leaders from all around the world.
Throughout the week, FPF convened key engagements that brought together stakeholders from industry, government, academia, and the legal sector around top-of-mind issues for the Asia-Pacific (APAC) region, including agentic and physical AI, smart wearable devices, and biometric data. This blog post takes stock of the five cross-cutting threads that emerged from FPF’s events, our invite-only Privacy Leaders’ Luncheon, our closed-door regulators’ roundtable, and contributions to the IAPP Asia Forum.
First, governance attention on AI is shifting decisively toward agentic AI, straining notice-and-consent models and pushing regulators toward objectives like accountability, safety, and meaningful human oversight. Second, AI is reshaping the breach and threat landscape, raising the stakes for security and breach notification. Third, continuous, always-on data streams from wearables and physical AI are testing the limits of existing data protection principles, especially for bystanders and biometric data. Fourth, technical and institutional capacity has become a foundational requirement for credible data protection. Fifth, scalable, interoperable cross-border data transfer mechanisms remain vital to the regional digital economy.
FPF at the Opening Session of the Singapore Data Festival, Monday, July 20, 2026.
Theme 1: Agentic AI is straining notice-and-consent models, pushing regulators towards ensuring accountability and meaningful oversight
In the last couple of years, the focus of global AI governance discourse has expanded from generative AI toward agentic AI systems capable of autonomous multi-step actions. This development has profound implications for the notice-and-consent model at the heart of most data protection regimes. As discussions across the week made clear, the shift is also pushing regulators toward frameworks organized around governance concepts such as bounding risk, retaining visibility over agent activity, and preserving human accountability.
The PDPC’s newly-issued guiding documents illustrate how some APAC regulators are beginning to address and provide clarity on data protection issues arising from the development and deployment of modern AI systems. On July 20, 2026, at the launch of the SDF, the PDPC published its finalized Advisory Guidelines on the Use of Personal Data in Generative AI (Advisory Guidelines). The Advisory Guidelines address how generative AI models may be trained and deployed under Singapore’s Personal Data Protection Act (PDPA).
While the guidance focuses on generative AI, it would also have a bearing on a relevant issue for agentic AI: specifically, the legal bases available for the collection and processing of personal data, and how individuals and organizations should be informed at the outset about the purpose of data collection and processing. In this regard, two points in the Advisory Guidelines are worth noting. First, the Advisory Guidelines clarify that the “Publicly Available Exception” under Singapore’s PDPA is applicable to the collection of data through web-scraping. Second, the Advisory Guidelines require explicit “AI-Specific Notifications” (rather than broad and generic language on “new product development”) where consent is sought specifically from individuals to train and develop AI models.
FPF and CrowdStrike’s “All-Regulators’ Panel on the Risks and Opportunities of Agentic AI,” Wednesday, July 22, 2026.
Yet, as agentic AI systems and generative AI systems with agentic functionalities become more common, regulators are recognizing that these enhanced capabilities can exacerbate data protection issues and complicate issues around responsibility allocation. Recognizing this trend, on Wednesday, July 22, 2026, FPF and CrowdStrike co-organized an “All-Regulators’ Panel on the Risks and Opportunities of Agentic AI,” moderated by Prof. Haksoo Ko (Seoul National University; FPF Senior Fellow; former Chairperson of South Korea’s Personal Information Protection Commission). Despite operating in vastly different legal, regulatory and political contexts, the regulators on the panel converged on the same objectives — achieving transparency, accountability, safety, and trust — even as they differed on the approach.
For instance, Lori Baker (Vice President, Data Protection and Regulatory Compliance, Dubai International Financial Centre (DIFC)) described how the DIFC aims to embed human oversight at every level of agentic AI deployment through internal policy prototyping. She flagged that greater clarity is needed around AI safety so that agentic AI systems can fend off attacks and avoid unintended behavior (such as a robot guard causing physical harm on the basis of a flawed visual inference).
Meanwhile, Jose Sutton Belarmino II (Deputy Privacy Commissioner, National Privacy Commission, Philippines) posited a principles-based approach towards regulating agentic systems, anchored in continuous transparency and explainability. He reasoned that legislative processes often lagged technological development. He also noted the practical difficulty of defining “meaningful” human intervention, arguing that human involvement should begin not simply at deployment, but when a company first decides to adopt an AI system.
Conversely, Alain Herrmann (Commissioner, National Commission for Data Protection of Luxembourg) outlined the European Union’s structured and risk-based approach under the GDPR and the EU AI Act, which categorizes systems by risk and mandates market surveillance. He acknowledged that applying this approach to agentic AI may present practical challenges for organizations, such as where organizations may have to comprehensively map out how an agentic AI system is processing personal data to ensure compliance. During the audience Q&A segment, Commissioner Herrmann also noted that while the EU rules may be more demanding, all EU jurisdictions share the foundational objective of ensuring accountability, safety, and trust in the development and use of agentic AI systems.
Denise Wong (Commissioner, PDPC Singapore; Assistant Chief Executive, IMDA) explained that Singapore pairs “hard-law” obligations under data protection law with iteratively updated “soft-law” guidance, such as IMDA’s Model AI Governance Framework for Agentic AI (launched in January 2026 and updated in May 2026). She emphasized that the combination of binding law and guidance allows Singapore to remain agile as guidelines are updated iteratively based on real industry feedback and use cases.
These regulatory currents were similarly mirrored – from an industry perspective – at FPF’s Privacy Leaders’ Luncheon (which convened senior practitioners from across the region to discuss top-of-mind issues around AI and data protection). Participants repeatedly emphasized visibility as the cornerstone of any internal AI governance program (that is, knowing how AI is being used across an organization, by whom, and for what), as teams contend with “shadow AI” (the use of AI tools within an organization without the organization’s explicit knowledge, approval or oversight) and organizational pressures to adopt AI. On human oversight, most participants concurred that automation should not dilute accountability. Agentic systems remain tools, and human users remain responsible for outcomes. The depth of human scrutiny, however, should be proportionate to the risks of specific contexts and use cases.
Theme 2: AI is changing the breach and threat landscape, raising the stakes for security and notification
The same capabilities driving agentic adoption are also lowering the requirements and cost of cyber threats, even as unintentional exposure grows when employees route personal data through “shadow AI” tools. In this regard, FPF also contributed to discussions at IAPP Asia Forum 2026, where these same pressures — expanding attack surfaces and rising breach volumes — featured across both sessions FPF participated in.
Josh Lee Kok Thong (Managing Director, FPF APAC) joined experts from McDermott Will & Schulte, Meta, and CrowdStrike for a session titled “The API Crisis: Securing Agentic AI in Asia’s Fastest Growing Threat Surface.” The panel explored how Application Programming Interfaces (APIs) have become an exposed control layer and a risky failure point through shadow APIs and inconsistent multi-cloud controls, and what concrete steps can strengthen API governance and secure AI-driven data flows.
FPF’s Josh Lee Kok Thong on the IAPP panel “The API Crisis: Securing Agentic AI in Asia’s Fastest Growing Threat Surface,” Wednesday, July 22, 2026
Concerns around attack surfaces growing faster than governance measures was also a central issue in Bilal Mohamed‘s (FPF Policy Manager for India) IAPP panel on “Navigating India’s Personal Data Breach Regime in the AI Age.” This panel discussion unpacked the breach-related requirements of India’s Digital Personal Data Protection Act, 2023 (DPDPA) against a landscape in which AI is reshaping the scale, speed, and entry points of personal data breaches, making unintentional exposure more likely.
The DPDPA, unlike most data protection regimes with risk thresholds, requires data fiduciaries (equivalent to a “data controller” under the GDPR) to notify the affected individual and India’s Data Protection Board (DPB) of every breach they become aware of, regardless of severity. The panel weighed whether such an all-encompassing duty remains fit-for-purpose as the ubiquitous use of AI potentially increases the number and volume of data breaches. This issue was also thrown into relief by significant developments elsewhere, with the EU’s proposed Digital Omnibus for the GDPR looking to extend the reporting timeline and narrow breach reporting obligations to high-risk incidents only.
In this context, it was also timely that the IMDA and PDPC released an updated Guide to Data Protection Practices for ICT Systems on the first day of SDF. The updated Guide draws on lessons from recent breaches to offer organizations a practical reference for hardening systems against the kind of high-velocity AI-driven incidents envisioned by both panels.
Bilal Mohamed on the IAPP panel “Navigating India’s Personal Data Breach Regime in the AI Age,” Wednesday, July 22, 2026.
Theme 3: Existing data protection principles largely cover biometrics, wearables, and physical AI, but bystander privacy remains unresolved
The challenges and complexities of stretching the boundaries of data protection law to cover emerging technologies carried over into discussions around wearable technologies and physical AI. On Tuesday, July 21, 2026, FPF, together with Rajah & Tann (R&T) and the Singapore Academy of Law (SAL), convened an event on “Biometric Data, Wearables and Physical AI: Frontier Legal, Regulatory and Policy Issues.” The discussion, moderated by FPF’s Deputy Director for APAC Dominic Paulger, featured Zee Kin Yeong (Chief Executive, SAL; FPF Global Senior Fellow), Steve Tan (Partner, R&T), Stephy Kwan (APAC Advocacy, Privacy and Data Policy Manager, Meta), and William Malcolm (Executive Director, Regulatory Risk and Innovation, UK Information Commissioner’s Office). The central question of this discussion was: how far can the technology-neutral principles of data protection law (most of them traceable to the Fair Information Practice Principles and the 1980 OECD Guidelines on the Protection of Privacy and Transborder Flows of Personal Data) stretch to cover devices their original drafters may never have imagined?
Speakers laid out how wearables and physical AI raise hard questions about what a system can perceive, infer, and — for embodied AI — physically do. In addition, the mode of data collection is changing from episodic to being continuous and always-on. Coupled with the fact that there may be little to no interaction between the technology and the people around it, this can leave bystanders with little notice that their personal data is being processed.
In this regard, there was a consensus among the panelists that existing principles remain broad enough to reach these technologies, although greater clarity is needed in three areas.
First, on legal bases. Wearables and physical AI demand careful consideration of the legal bases for collecting and processing personal data. In Singapore, for instance, exceptions for publicly available data and personal or domestic use may leave bystanders with little recourse, while jurisdictions without such exceptions face the opposite challenge of giving meaningful effect to bases like consent. Recording-indicator lights, an increasingly common feature on wearable devices, are only meaningful if bystanders both recognize the signal and understand what is being processed.
Second, on identifying controllers. Which players should meaningfully bear obligations and liabilities under data protection law? In particular, should the manufacturer of the device be treated as the controller, or should it be the individual who chose to switch the device on?
Third, on the treatment of biometric data. Definitions and the treatment of biometric data diverge across jurisdictions and further complicate this landscape. For instance, Article 9 of the GDPR classifies biometric data as sensitive. Consequently, controllers are subject to more stringent conditions under which biometric data can be processed. By contrast, Singapore’s PDPA does not classify certain types of data as sensitive, so protections would need to be grounded in broader reasonableness and necessity requirements.
During the panel, there was also a discussion on the pitfalls and promises of biometric technologies. Because real-world biometric systems rely on probabilistic templates, they are vulnerable to degradation and spoofing. This risk is compounded when an erroneous inference is used to trigger a physical action, such as unlocking a door or dispensing medication. Nonetheless, panelists also brought up examples of how wearable devices can be genuinely life-saving, pointing therefore towards the need for nuanced and balanced policymaking in this space.
FPF, Rajah & Tann, and the Singapore Academy of Law’s joint event on “Biometric Data, Wearables and Physical AI: Frontier Legal, Regulatory and Policy Issues,” Tuesday, July 21, 2026.
Theme 4: Technical and institutional capacity is foundational to credible data protection amidst a fast-evolving technological landscape
Underlying all of the discussions above is a more fundamental question: how can regulators in general and data protection authorities (DPAs) in particular keep pace with the relentless advance of technology, while building operational capacity and fulfilling their mandate of enforcing data protection law? On Thursday, July 23, 2026, FPF hosted “Foundations and Frontiers: A Regulators’ Roundtable on Institutional Excellence in the Asia-Pacific,” a closed-door session for experienced and emerging DPAs from across the region. In keeping with the Chatham House Rule, the takeaways below are shared without attribution to individual participants.
One key takeaway is that in building institutional capacity, DPAs can look both to adjacent fields and to adjacent stakeholders. In this regard, the first session of the roundtable addressed how regulators can develop early capabilities, allocate scarce resources, and build technical capacity without disrupting day-to-day operations. For instance, in seeking to build fresh expertise in an emerging DPA, the authority could look to recruit specialized technical skills from adjacent fields like digital forensics and IT. As specialized data protection practitioners are inherently in short supply in any emerging data protection ecosystem, experts from these adjacent fields can allow DPAs to quickly gain technical capabilities and apply regulations credibly. In addition, emerging DPAs can consider fostering robust “communities of practice” by convening DPOs and practitioners across industries to provide the DPA with valuable multi-stakeholder perspectives in refining policies and approaches.
In this context, a live and relevant example might be seen in the form of India’s emerging Data Protection Board (DPB). As the IAPP panel on India’s breach notification regime (see above) highlighted, India’s DPB is in the process of being established. It is therefore interesting to follow how the DPB will leverage expertise from various sectors and domains in India to build its capacity, while addressing what an “AI-native,” digital-by-design approach to data breach management (see Rule 20 of the DPDP Rules) might look like.
Another key takeaway is that innovation and robust data protection are in fact not mutually exclusive, and that the oft-cited trade-off between both can be navigated in several ways. In the final session of the roundtable, discussants cautioned against defaulting to the creation of rigid checklists that appear to offer easy routes to compliance but may not be as robust in dealing with rapid technological change. Instead, regulators can aim for “conditional certainty” (that is, providing companies with confidence to pursue innovation so long as certain pre-requisites are met), such as leveraging controlled environments like regulatory sandboxes to build capacity, and encouraging pre-deployment consultations with the DPA.
Theme 5: Scalable, interoperable cross-border transfer mechanisms remain vital to the regional digital economy
In a region as diverse as the APAC region, it is no surprise that there has been a proliferation of regulatory frameworks governing the transfer of data between jurisdictions. The operative focus is therefore interoperability, and it was notable how transfer tools like the ASEAN Model Contractual Clauses (MCCs) and the Global Cross-Border Privacy Rules (CBPR) system are emerging as some of the APAC region’s most practical transfer tools – including for jurisdictions with emerging DPAs. This could be seen from another session during the FPF-hosted “Foundations and Frontiers: A Regulators’ Roundtable on Institutional Excellence in the Asia-Pacific.” Discussants noted how standardized or model contractual clauses like the ASEAN MCCs could function as flexible and non-binding “plug-and-play” tools across jurisdictions, even in jurisdictions without a formal DPA. The Global CBPR system was also highlighted as a scalable mechanism that, unlike regional instruments such as the ASEAN MCCs, is open to all jurisdictions. Its accountability-agent model effectively places a certified organization under the oversight of two authorities at once, extending a DPA’s practical reach beyond its own borders.
Relevantly, at the start of SDF, FPF also published its latest Issue Brief on “Navigating Cross-Border Data Transfers in the APAC Region: An Analysis of Developments from 2023 to 2026.” The Issue Brief tracks and maps the fragmented landscape for cross-border data transfers across 14 APAC jurisdictions. A key takeaway from the Issue Brief is that there appears to be a growing duality in the APAC region: convergence on shared safeguards and accountability standards, alongside divergence in data-localization and sovereignty-driven measures.
If you want to learn more about FPF APAC and our engagements on the ground, do not hesitate to be in touch at [email protected] for membership inquiries or [email protected] for media inquiries.
Clean-Up on Aisle Three: New Jersey Becomes Third State to Regulate Data-Driven Pricing This Year
Few areas of privacy and technology policy have attracted as much legislative attention this year as data-driven pricing or “surveillance pricing.” On August 4, the Senate Judiciary Committee held a hearing—“Your Data, Their Profit: The Consumer Cost of AI Surveillance Pricing”—highlighting the intense scrutiny on these practices by policymakers. In 2026 alone, FPF tracked the introduction of over 100 bills seeking to regulate some form of data-driven pricing at the state and federal levels. Despite the shared interest, these bills vary significantly in terms of both the entities who would be in scope and the technologies and data uses that would be regulated.
Three states have enacted broad data-driven pricing laws so far this year: Maryland, Connecticut, and New Jersey. These states join New York, which passed the Algorithmic Pricing Disclosure Act last year. This blog post provides an overview of each of these three new laws, covering their key definitions, scope, obligations, and enforcement:
Scope: Maryland’s law applies only to qualifying food retailers and third-party delivery service providers. Connecticut’s prohibition extends more broadly to cover all retail sellers and third-party delivery services, with disclosure requirements for any person doing business in the state. New Jersey’s law sits in-between—prohibiting surveillance pricing by any person but only with respect to “groceries and other foodstuffs.”
Obligations: Maryland prohibits using personal data or dynamic pricing to set higher prices for covered food. Connecticut prohibits surveillance pricing, subject to exceptions, and requires disclosures when personal data is used to increase a price. New Jersey prohibits using surveillance pricing to determine or vary prices and places a one-year moratorium on the new use of electronic shelf labels.
Enforcement: Maryland and Connecticut rely on AG enforcement, while New Jersey permits broader enforcement mechanisms, including a private right of action.
Effective Dates: Maryland (October 1, 2026); Connecticut (February 1, 2027); New Jersey (August 1, 2027)
Maryland
The “Protection from Predatory Pricing Act” (HB 895) was enacted in April and regulates the use of dynamic pricing by food retailers and third-party service providers. The law takes effect on October 1, 2026. The law defines several key terms that establish its scope:
“Food retailer” means a merchant operating a business establishment with a minimum of 15,000 square feet and selling food that is exempt from Maryland’s sales and use tax [§ 11-206(c) of the Maryland tax code].
“Third-party delivery service provider” means a merchant that facilitates, as a consumer service, the delivery of food that is exempt from Maryland’s sales and use tax [§ 11-206(c) of the Maryland tax code]. This does not include a food retailer.
“Dynamic pricing” means “the discriminatory practice of offering or setting a personalized price for a good or service that is specific to a consumer based on the consumer’s personal data[as defined in MODPA], regardless of whether the seller collected or purchased the personal data.”
“Protected class data” means “information about an individual or group of individuals that, alone or in combination, directly or by implication identifies a characteristic that is legally protected from discrimination under the laws of the State or under federal law.”
Under the law, a food retailer or third-party delivery service provider may not:
Engage in dynamic pricing to set a higher price for food that is exempt from Maryland’s sales and use tax (§ 11-206(c) of the Maryland tax code);
Use personal data to set a higher price for food that is exempt from Maryland’s sales and use tax (§ 11-206(c) of the Maryland tax code) for a single consumer;
Use protected class data to “offer, advertise, or sell a consumer good or service to a consumer for whom the protected class data pertains if the use of the protected class data has the effect of withholding or denying from the consumer an accommodation, an advantage, or a privilege accorded to others.”
The law includes a number of tailored exceptions for common pricing practices. Businesses are allowed to use promotional pricing offers, loyalty program benefits, or other temporary discounts or changes to pricing related to retention of existing customers. They are also allowed to set a different price based on objective costs attributable to providing goods or services (e.g., price differences based on shipping or taxes due to the consumer’s physical location); costs or differences in supply or demand associated with providing goods or services in different locations or geographies; or costs associated with the availability or supply of the goods or services. Businesses are also allowed to offer a price to a consumer through a loyalty, membership, or rewards program in which any consumer may voluntarily enroll or consent to participate, offer prices in connection with a subscription-based contract or agreement, and offer prices to a consumer who consents (as defined in Maryland’s comprehensive privacy law) to providing personal data or other information in exchange for obtaining the price. The law also exempts correcting a price resulting from a pricing error or resetting a price following a system or network outage.
The law will be enforced by the Division of Consumer Protection of the Office of the Attorney General, who must give notice of an alleged violation prior to initiating an enforcement action and allow 45 days to cure the violation. The law includes a specific disclaimer providing that nothing should be construed to authorize a private right of action under this law or any other law.
Connecticut
Connecticut passed an omnibus privacy bill (SB 4) earlier this year that included data-driven pricing regulations. These provisions take effect on February 1, 2027.
Connecticut’s law is notably broader in scope than Maryland’s, as it applies to retail beyond food. Connecticut’s pricing law has two key provisions: it bans surveillance pricing by a retail seller or third-party delivery service, subject to exceptions; and it subjects any other person engaged in surveillance pricing to mandatory disclosures.
The law defines “surveillance pricing” as establishing a customized price for a consumer good or service that is specific to a consumer (or group of consumers) based in whole or in part on the consumer’s personal data collected (A) through any technology or technological method, system, or tool [examples given include biometric monitoring, camera, device tracking, or sensor] and (B) by the person establishing the customized price, directly or indirectly. The prohibition on surveillance pricing is narrowly targeted to retail sellers and third-party delivery services.
A “retail seller” is defined as a retailer engaged in making sales, at retail, of “tangible personal property,” which includes “digital goods.” This includes retail food establishments.
A “third-party delivery service” is defined as an entity, outside of the operation of a retail food establishment’s business, that facilitates delivery or online ordering services to customers of a retail food establishment.
The following activities do not constitute “surveillance pricing,” provided that the retail seller or third-party delivery service prominently posts the discount, discounted price, and terms and conditions in language readily understandable by the average consumer:
Establishing a discounted price for purposes such as retaining a customer, reestablishing a customer, attracting a new customer, cross-selling an item, or reengaging a lapsed customer;
Establishing different prices due to justifiable differences in costs incurred in providing the good or service (e.g., due to physical location or delivery distance) or justifiable temporal differences;
Establishing a discounted price based on publicly disclosed uniform terms and conditions available to any consumer, available to all consumers in a broadly defined group (e.g., veterans) based on publicly disclosed discounts and uniform terms and conditions, or through a loyalty, membership, or rewards program that a consumer affirmatively enrolls in; and
Correcting an erroneous price.
The law also imposes a separate disclosure requirement that applies more broadly to “any person” doing business in Connecticut who (1) engages in surveillance pricing for any reason other than to establish a discounted price for a consumer good or service as part of an online transaction, and (2) advertises or promotes online the price, labels a consumer good with the price, or publishes a statement, image, or announcement disclosing the price. Similar to what’s required under New York’s Algorithmic Pricing Disclosure Act, any such person must provide a “readily visible” disclosure: “THIS PRICE WAS INCREASED USING YOUR PERSONAL DATA.” The person must also inform consumers of their rights under Connecticut’s comprehensive privacy law. The disclosure is not required if the price is the “bona fide market price.”
Violations constitute unfair or deceptive trade practices and are enforced exclusively by the Attorney General. The law does not create a private right of action.
New Jersey
New Jersey Governor Mikie Sherrill (D) signed the “Fair Price Protection Act” (FPPA) (A4085/4523) on July 23, making New Jersey the sixth state to pass legislation regulating data-driven pricing, and the third this year. The law generally prohibits the use of “surveillance pricing” in food retail and takes effect on August 1, 2027, with certain provisions taking effect earlier.
The FPPA defines “surveillance pricing” as “an action, including a pricing strategy in which the price of groceries and other foodstuffs is, in whole or in part, determined, adjusted, optimized, or recommended by an algorithm or automated system, based, in whole or in part, on using personal data, including data derived, or inferred from other data, and that results in price variation for individual consumers or groups of consumers.” The law prohibits any “person” (as defined in state’s Consumer Fraud Act) from engaging in surveillance pricing when determining or varying the sale price of “groceries and other foodstuffs,” which includes not only food but also items such as paper products, household cleaning items, health and beauty products, and pet foods and supplies. Maryland’s law, in contrast, applies more narrowly to food exempt from sales tax. As a result, New Jersey’s FPPA likely applies more broadly than Maryland’s PPPA, to more entities, more types of products, and more pricing practices.
The FPPA prohibits surveillance pricing from being used to “determine or var[y] the sale price” of groceries or other foodstuffs. This language is broader than Maryland’s prohibition on using personal data or dynamic pricing to set higher prices, as New Jersey’s prohibition is not limited to price increases.
The FPPA also contains a narrower list of exceptions than Maryland’s law, including:
Price differences resulting from reasonable costs associated with providing groceries and other foodstuffs, as long as the price is not changed more than once in a 24-hour period;
Bona fide discounts for which eligibility conditions are public, conspicuous, and uniformly offered based on criteria, and to which members of a broadly defined group are eligible; and
Bona fide discounts offered as part of a loyalty program provided that consumers voluntarily opt in, members receive benefits pursuant to uniform terms, and the program clearly discloses its benefits, discounts, and data practices.
Any person using personal data to offer different prices on groceries or other foodstuffs pursuant to the exceptions above are prohibited from using this personal data for any other purpose without the consumer’s consent.
In addition to the prohibition on surveillance pricing, the FPPA also places a one year moratorium, beginning February 1, 2027, on the new use of electronic shelf labels in food retail stores. Before and during the moratorium, the Treasury Department’s New Jersey Innovation Authority, in consultation with the Division of Consumer Affairs, is directed to conduct a study on the use of electronic shelf labels, including legislative or regulatory recommendations, which is directed to begin immediately.
The law provides the Division of Consumer Affairs with the authority to adopt rules or regulations to effectuate any provisions, including taking any “anticipatory administrative action” as necessary to carry out their duties. For violations of the law, the state Attorney General may bring civil action on behalf of residents to enjoin violative practices, enforce compliance with the law, obtain actual monetary damages for each negligent or greater violation, or obtain any other restitution or relief deemed appropriate for each violation. Additionally, because violations of the FPPA are considered “unlawful practices” under New Jersey’s Consumer Fraud Act, the law is subject to a private right of action (“PRA”) that includes treble damages. This is the first data-driven pricing law to contain a PRA, and it is unclear how a customer’s “loss” resulting from surveillance pricing would be calculated for the purposes of assessing damages.
Algorithmic Price “Collusion” Also in Focus: The same week the FPPA was enacted, Governor Sherrill also signed the Forbidding the Algorithmic Inflation of Rent (FAIR) Act into law, which makes it an unlawful violation of the New Jersey Antitrust Act for rental property owners or their agents, or other persons, to coordinate the use of an “algorithmic device” in setting rental prices, material lease terms, or occupancy levels. It also prohibits the practice of “parallel pricing coordination,” which includes a tacit or express agreement between individuals to change pricing for residential dwelling units, unless otherwise required by law. The FAIR Act preempts local laws, provides the AG with the authority to adopt rules and enforce the law, and takes effect July 1, 2027. While FPF does not typically track algorithmic rent setting legislation, it is worth noting that this has become a major trend over the past two legislative sessions.
Conclusion
The three laws enacted this year suggest that, while regulating data-driven pricing practices remains a priority for lawmakers, they have not settled on a consistent framework. Maryland, Connecticut, and New Jersey each prohibit some form of data-driven pricing, but they have not coalesced around common scope or definitions. These laws differ in the businesses they cover, the specific practices they proscribe, and their enforcement mechanisms. For example, Maryland and New Jersey primarily regulate pricing in food retail, while Connecticut’s prohibition extends across retail more broadly. Maryland targets the use of personal data or dynamic pricing to charge higher prices, whereas Connecticut’s and New Jersey’s laws apply regardless of whether the resulting price is higher or lower.
Lawmakers will continue to debate the most effective approach to data-driven pricing through the remainder of 2026, as several bills remain pending in still-active state legislatures. For example, California’s AB 2564, which has passed the Assembly, would prohibit retailers (broadly defined) from engaging in surveillance pricing, while preserving several common pricing exceptions. Meanwhile, Michigan’s HB 6098 and HB 6099 have passed the House, and Pennsylvania lawmakers are still considering several competing approaches (HB 1779, HB 2384, and SB 1205).
The recent Senate hearing, which comes after multiple congressional investigations into companies’ surveillance pricing practices, further elevated data-driven pricing as an issue of concern for federal lawmakers, and testimony emphasized how difficult these practices can be for consumers and regulators to identify. As lawmakers look toward 2027, the growing attention to this issue may keep data-driven pricing high on legislative agendas, even as states continue to take different approaches to defining and regulating the practice.
If you are interested in an informational briefing on data-driven pricing laws and legislation, please reach out to us at [email protected].
A New Design Code Takes Root in the Garden State
On August 11, New Jersey became the newest state to enact a design code law aimed at minor online safety after Governor Sherrill signed A4015, the “New Jersey Age-Appropriate Design Code” (NJAADC). The new law is among the broadest in the country, most closely resembling a blend of the design codes enacted in South Carolina and Nebraska. For example, this law has broad applicability thresholds; relies on strong protective default settings; broadly prohibits dark patterns in online services; restricts personalized recommendation practices and certain design features; and mandates mechanisms for minors to report harms in online services. This law takes effect on September 1, 2027 and includes a private right of action (PRA). This blog post covers the NJAADC’s scope, mandatory safeguards, prohibited practices, reporting mechanisms, and enforcement.
Scope & Key Definitions
Applicability: The NJAADC regulates covered online services, defined as any entity providing an online service in the state that is both reasonably likely to be accessed by a child or minor and meets one of the following annual thresholds: (1) gross revenue in excess of $25M, or (2) processes personal data of 25,000 or more consumers or households. This definition includes any person that controls a legal entity that meets this definition and shares common branding with the legal entity. (§ 3)
While design code frameworks generally draw from the California Consumer Privacy Act (CCPA) by applying to entities that collect and control personal data and meet specified revenue or processing thresholds, the NJAADC departs from the CCPA and earlier AADC models by extending coverage beyond for-profit businesses to any legal entity that owns, operates, controls, or provides an online service and meets the statutory thresholds. Nebraska and South Carolina likewise expand scope to potentially cover non-profits and other non-commercial entities. The NJAADC has a lower data processing threshold than all other design codes—requiring processing of just 25,000 consumers or households in the state.
Exemptions: This bill includes entity-level exemptions for government entities (but only “in the ordinary course of its operation”); direct messaging services or products; telecommunications services; broadband internet access services; and email services. The bill also includes data-level exemptions for data subject to GLBA; certain health records, patient identifying information, and research data; protected health information under HIPAA; and information falling under human subjects protections by the FDA. (§§ 3 & 15)
Key Definitions: The NJAADC aligns knowledge standard definitions with other recently enacted design code laws but diverges in its approach to defining age thresholds. Similar to other laws, the NJAADC defines both actual knowledge (the threshold used to determine whether a covered online service provider knew a user was a minor) and “reasonably likely to be accessed by minors” (the standard applied to determine whether a covered online service provider is within the law’s scope). Actual knowledge is defined similarly to Nebraska’s AADC as all information and inferences the covered online service holds relating to an individual’s age—such as self-identified age or any age attributed to the individual for any purpose, including marketing, advertising, or product development. Notably, age classifications used for marketing take precedence over self-declared age. The “reasonably likely to be accessed by minors” standard is defined most comparably to Vermont’s AADC, and relies on three factors—
The service, product, or feature is directed to children, as defined by COPPA and its implementing rules;
The service, product or feature is determined, based on competent and reliable evidence regarding audience composition, to be routinely accessed by an audience that is composed of at least 2% of individuals aged 2-17; or
The covered online service knew or should have known that at least 2% of the audience includes individuals aged 2-17, provided that, in making this assessment, the business shall not collect or process any personal data that is not reasonably necessary to provide an online service, product, or feature. (§ 3)
While other design code laws typically apply protections to a single age category of minors under 18, the NJAADC adopts a two-tiered age threshold, distinguishing “child,” defined as anyone under the age of 13, from “minor,” defined as anyone between 13 and 17. A covered child or minor is one whom the covered online service has actual knowledge to be a child or minor. Although the bill creates separate “children” and “minors” definitions, none of the obligations apply differently between the two age tiers. Accordingly, this divergence likely has little practical impact on how companies implement these requirements compared to other laws as it is currently written, but future amendments could introduce opportunity for substantive divergences if scoped to only one of the two defined age categories. (§ 3)
Mandatory Safeguards
Like many recent design code laws—including those in South Carolina, Nebraska, and Vermont, the NJAADC requires covered online service providers to configure certain default safety settings for covered children and minors. These settings focus on controlling personalized content recommendations, preventing unwanted contact between minors and unknown adults, and adding friction to certain design features. These settings and features can be adjusted by a covered child/minor or their parent. Key mandatory safeguards include:
Algorithmic recommendation systems must have a “prominent and accessible” user interface allowing covered children/minors to indicate content recommendation preferences and access, review, and change personal data used to provide algorithmic recommendations. (§ 10(a) & (b))
For covered online service providers that use algorithmic recommendation systems to prioritize content or contacts between users, the systems may not display the existence of a covered child’s/minor’s account, created or posted media, or allow direct messaging between a covered child/minor and an unknown adult unless the covered child, minor, or their parent “expressly and unambiguously” allows such conduct.
Covered online service providers are prohibited from displaying a covered child’s/minor’s geolocation information or connected users;
Covered online service providers need to disable search engine indexing of covered children’s/minor’s accounts and interaction counts (e.g., comments, reactions, and reshares); and
Covered online service providers need to provide a block option preventing specific users from accessing, interacting with, or communicating with a covered child’s or minor’s account.
Covered online service providers are barred from providing a single setting that makes multiple default settings less protective, or prompting a covered child/minor to disable settings unless it is necessary to provide a service or feature “expressly and unambiguously” requested by the covered child/minor or their parent. (§ 4(a)-(c))
Prohibited Practices
In addition to requiring certain default safeguards, the NJAADC also restricts covered online services from engaging in certain practices related to children’s and minors’ personal data and service design—including through purpose limitations, compulsive design restrictions, limits on data use for algorithmic recommendations, data retention caps, notification restrictions, advertising prohibitions, and dark pattern prohibitions.
Purpose Limitation: A covered online service may not use a covered child’s/minor’s personal data for any purpose beyond that for which it was collected. There is no consent alternative for this. (§ 7(a)(1))
Compulsive Design Limits: The covered online service provider must take reasonable steps to ensure that any use of the covered child’s/minor’s personal data and design of covered design features (e.g., infinite scroll, autoplay) do not result in compulsive use. (§ 12(a))
Algorithmic Recommendation Limits: A covered online service may not use a covered child’s/minor’s personal data for content recommendations unless the prioritization is based on: user settings, a search query, parent-selected settings, a user’s age or age flag, age-appropriate content policies, or a covered child’s/minor’s “express and unambiguous” request to receive certain content. (§ 7(a)(2))
Data Minimization & Retention: The NJAADC includes substantive data minimization requirements, permitting covered online service providers to process or retain only the minimum amount of data necessary to provide the specific features of an online service with which the covered child/minor is “actively and knowingly engaged.” (§ 7 (b))
Notification Curfew: Covered online service providers must disable notifications for covered child/minor notifications by default, and, if enabled, may not send notifications during late night hours (i.e., 10pm-6am) or during the school day when school is in session (i.e., 8am-4pm). (§ 6(a) & (b))
Advertising Restrictions: Covered online service providers may not target covered children/minors with advertisements involving narcotic drugs, tobacco products, gambling, or alcohol. (§ 6(c))
“Dark Patterns” Prohibitions: Similar to other design code laws, such as Nebraska’s and South Carolina’s, covered online service providers would be broadly prohibited from using “dark patterns” in regard to a covered child/minor. While these requirements are usually tied to business data practices in other laws, like Maryland’s AADC and comprehensive privacy laws, the dark patterns prohibition under this bill is framed in context of the online service as a whole. (§ 6(d))
Reporting & Unpublishing Mechanisms
The NJAADC would require covered online service providers to establish two mechanisms for covered children/minors to use for reporting and account deletion. First, covered online service providers must provide a “prominent and accessible” reporting mechanism for covered children, minors, and their parents to report harms experienced on the online service. Second, covered online service providers must establish an “unpublishing” mechanism that allows covered children/minors to quickly delete their account in fewer steps than it took to create it. This unpublishing tool mirrors the nearly identical requirement established in the Connecticut Data Privacy Act (CTDPA) in its 2023 amendments. (§§ 5 & 9)
Enforcement & Rulemaking
The law includes robust enforcement mechanisms and rulemaking. On enforcement, the NJAADC is enforceable in two ways—first, as a violation of the Consumer Fraud Act (whichincludes a PRA). Second, the bill also establishes its own PRA through which lawsuits may be brought by either the Attorney General or a parent on behalf of an injured child or minor. For any negligent or greater violations, a court would be authorized to award:
$5k per violation or treble damages (whichever is greater);
Punitive damages for reckless and knowing violations;
Injunctive relief;
Declaratory relief;
Attorney’s fees; and
Litigation costs. (§ 14(a)-(c))
On rulemaking, the Attorney General’s office has broad authority to promulgate rules necessary to guide implementation of these provisions. Additionally, the Commissioner of Health has narrow rulemaking authority to provide guidance on criteria establishing “compulsive use.” New Jersey is the third state to provide agencies with such authority—there is ongoing rulemaking on this topic under Vermont’s AADC and Colorado already approved regulations for implementing the heightened minor protections within the Colorado Privacy Act (CPA). (§ 13)
Conclusion
New Jersey’s approach to age-appropriate design code frameworks changes the model’s formula from a data protection to safety-by design focus, distinguishing it from the regulatory approach central to earlier models. Early-enacted age-appropriate design codes, like those in California and Maryland, revolved around a duty of loyalty to act in the best interests of children, default privacy settings, child data processing restrictions, and data protection impact assessments (DPIAs) primarily evaluating whether data management practices would result in children being subject to harm. The NJAADC’s emphasis on product and service design, personalization practices, and default safeguards governing minors’ platform interactions—alongside core data protections—reflects a broader regulatory shift within U.S. age-appropriate design code frameworks toward a distinct protective-by-design approach. This shift, similarly observed in South Carolina’s law, merits consideration as an emerging framework in its own right.
As age-appropriate design codes continue to coalesce around this new protective-by-design approach, it remains to be seen whether they will continue to face the same constitutional scrutiny that the earlier privacy-by-design frameworks faced. For example, California’s and Maryland’s laws were quickly subject to constitutional challenges that are still ongoing at the time of writing. South Carolina’s law was also challenged in February 2026, and it could prove to be a bellwether for this new protective-by-design model. As states continue to experiment with legal frameworks centered on regulating platform design, continued state adoption of broad protective-by-design frameworks looks likely to continue into the 2027 legislative session.
CADA: An (E)U-turn on AI regulation
The new EU Cloud and AI Development Act (CADA) proposal marks a genuine shift in the way the bloc regulates AI, as it codifies the “AI first” principle and it is as much an “AI promotion and enabling”-type of legislation as it is a cloud sovereignty one.
The European Commission published the CADA proposal at the beginning of June 2026, as part of a broader EU Tech Sovereignty package. The legislative proposal has two general objectives: to increase the competitiveness and innovation capacity of the EU in the cloud and AI ecosystems; and to increase the resilience and strategic autonomy in cloud and AI technologies of the EU.1 This analysis focuses primarily on how CADA implements the first objective related to competitiveness and innovation. So far, this part of the proposal has received significantly less attention than the way CADA deals with the second objective on strategic autonomy through laying out cloud assurance levels for public procurement, which is set to affect the complex integrations of technology stacks. This, despite the fact that the “AI promotion” part of CADA marks a fundamental shift in the way the EU regulates AI and related technologies. The analysis also looks at where the two objectives intersect: key areas where sovereignty is imbued in the proposal’s AI promotion part.
The CADA proposal is arguably the first piece of comprehensive tech regulation introduced by the EU that provides for positive obligations to enable innovation and competitiveness, including facilitating the development and widespread adoption of AI. In doing so, it attempts to mobilize data for AI training, compute power, infrastructure, including data centers and federated cloud, EU funds, national programmatic action and all-of-government approaches to AI adoption.
In fact, reading Titles II (“Research, Development and Deployment Activities for the Cloud and AI Ecosystem”) and III (“Data Centre Capacities”) of CADA, one can draw comparisons to, and find similarities with “America’s AI Action Plan” published by the White House in 2025 and Japan’s “AI Promotion Act”. Remarkably, neither of Titles II and III of CADA virtually includes any obligation for companies among their provisions. The scarcity of obligations for companies in the AI supply chain and the onus on governments to act are foundational policies connecting the three frameworks.
CADA aims to achieve its competitiveness and innovation capacity objectives through setting up “Cloud and AI Leadership Initiatives”, with obligations for Member States and the Commission, including the creation of “Centers for AI” in each Member State and adoption of National AI Strategies. Among other measures, it pledges compute support for frontier AI priority projects, it creates a framework for the “accelerated deployment of data centers”, including a streamlined local authorization process for designated data center “acceleration zones”, and pushes to make vast amounts of data available for AI training, building up on the loosened provisions proposed in the Digital Omnibus. The proposal also aims to codify verbatim the “AI first” principle that was launched as European policy in a public speech by the President of the Commission, Ursula von der Leyen, in early October 2025, before being included in the Apply AI Strategy of the Commission.
On one hand, all of this seems at odds with the significant first iteration of AI regulation proposed by the EU – the EU AI Act – which regulates AI primarily as a risk, drawing from product safety and fundamental rights legal protections, includes “red lines” for specific uses of AI, and rules for high-risk AI systems and for general purpose AI models. Following the publication of the Draghi report, the AI Act has been criticized for being over-bureaucratic and a potential barrier to AI development, with the Commission itself proposing simplification measures through an AI Omnibus. On the other hand, these AI-enabling measures included in the CADA proposal could be effective and more easily accepted throughout the EU precisely because they are not proposed in a vacuum of AI safety rules.
Below, this blog details (1) what are the markers of an AI-enabling legislation present in the CADA proposal, lays out (2) how it aims to embed the “AI first” principle into EU law, before (3) exploring how the proposal elevates making data available for AI training as a strategic goal at EU level. It then (4) analyzes how sovereignty is imbued in the “AI promotion” part of CADA, before reaching (5) conclusions.
1.Markers of AI-enabling Legislation: AI Leadership Initiatives, Centers for AI, and Streamlined Permitting for Data Centers
The CADA Proposal introduces “Cloud and AI Leadership Initiatives” as one of its main tenets, whose implementation is placed primarily on the European Commission and the Member States2. While the proposal does not define what the nature of these initiatives is, it establishes detailed operational objectives to be reached by them, from advancing the EU’s capabilities in frontier AI, to supporting the development of advanced platforms for the large-scale deployment of AI agents (see Table 1 below for the full list). It is notable that CADA also proposes legal definitions for both “frontier AI” and “AI agents”, filling thus a gap of the EU AI Act, which omits these two concepts. 3
Table 1. Operational objectives of the Cloud and AI Leadership Initiatives, Article 3(2) CADA
These eight operational objectives are each further dissected into multiple actions under Article 4, and each of them maps to one of the “Grand Challenges” listed in Annex I of the CADA proposal, to a large extent. These “Grand Challenges” are “the most strategic technological and industrial challenges” the Commission estimates that the EU is facing, and the CADA proposal wants to address them through large-scale, cross-sectoral initiatives.4 This is why it is important to read each of the operational objectives listed under Article 3(2) CADA together with the detailed actions under Article 4 and, further, their corresponding “grand challenge” in Annex I.
Take “physical AI models” for example. Annex I establishes that, in order to tackle Grand Challenge 4 – Physical AI, “the focus will be on co-designing software and its underlying hardware architectures and on combining frontier AI techniques with world models (our emphasis – n.) supporting physical reasoning for delivering robust manipulation, navigation, and interaction capabilities with minimal human supervision”. The Annex further notes that potential applications could include autonomous robots, industrial systems and drones operating in dynamic real-world environments. At the same time, Article 3(2)(d) CADA proposal designates “advancing Union’s capabilities in physical AI models and systems and fostering their deployment across the Union’s strategic sectors” as one of the operational objectives of the Cloud and AI Leadership Initiatives. To top it off, Article 4(4) CADA proposal further identifies specific actions to promote physical AI:
accelerate the development of a “European physical AI stack”, supporting model training and system development and deployment;
facilitate access to, and the collection and preparation of specific datasets for physical AI;
support the development, testing and validation in real-world environments of physical AI models and systems.
Thus, “world models” make their way into EU regulation, without being defined and with a focus on accelerating their development, including through making data available for training.
Frontier AI and Agentic AI are both targeted by CADA measures as well, with obligations for Member States and the Commission to “support the development of advanced, resilient and secure platforms for the development, deployment and orchestration of advanced AI agents at scale”, while creating a framework for the Commission to designate “Frontier AI priority projects”, if certain criteria are met – including that the project must be undertaken by a “European digital infrastructure consortium” (Article 8 CADA). Such designation would be important, given that Frontier priority projects would benefit from an obligation of the Member States and the Commission “to ensure” that sufficient computing resources are available for them within the limits of available capacity, per Article 9 CADA proposal.
The “Cloud and AI leadership initiatives” are complemented by more concrete AI-enabling obligations directed at Member States. Significantly, Member States would be under an obligation “to establish national cloud and AI strategies” within a year after the entry into force of CADA, which must include a prescriptive list of provisions. Among them, the national strategies must lay out measures to accelerate the development and adoption of cloud and AI at national, regional and local levels, measures to invest in high intensity computing infrastructure such as quantum computers, and measures to support the deployment of data center capacity, per Article 7(2) of the CADA proposal.
Additionally, Member States would be under an obligation to establish “Centers for AI”, whose objectives are to support the scaling-up of AI use cases in strategic and public sectors, accelerate a broad adoption of AI technologies at regional and local levels, and to leverage relevant infrastructure to accelerate the development and fine-tuning of AI models and systems (Article 5(1) CADA proposal).
The whole Title III of the CADA proposal focuses on data center capacities and has at its core an obligation for Member States to “designate at least one data center acceleration zone within its territory”, with a deadline of six months after the entry into force of CADA. Among other benefits, such acceleration zones would enjoy streamlined permitting procedures.
All of these characteristics squarely place CADA’s Titles II and III5 alongside AI promotion and enabling frameworks, such as Japan’s AI Promotion Act of 2025, or America’s AI Action Plan of 2025. First of all, the three frameworks – even if different in nature, varying between executive policy and adopted laws – virtually lack any significant obligations placed on companies in the AI supply chain and direct specific obligations to governments and public authorities. For instance, both the AI Action Plan and the CADA Proposal promote data center permitting acceleration6, the government as lead AI adopter7, facilitating compute access for start-ups and researchers8, or making data available for AI training9. The CADA Proposal is also similar to Japan’s AI Promotion Act through multiple elements, including the mandatory national planning and strategic cycle10.
2. Codifying the “AI First Principle”
The “AI first principle” is not yet clearly defined, even as it is making its way into EU law. The notion was brought into EU policy parlance by the President of the European Commission, Ursula von der Leyen, in a speech in October 2025 at the Italian Tech Week, where she said that the future “Apply AI” Strategy of the EU is based “on a simple, yet transformative principle: AI first”. She explained that “AI first” means that whenever a company or a public office is facing a new challenge, “the first question must always be: how can AI help?”. Von der Leyen specifically pointed out the transformative role of AI in healthcare, recalling that she is a medical doctor, and marveled at the promise of AI to save lives. She added that the Commission will “promote the same AI first approach across our strategic industries, from robotics to energy”.
Indeed, when the Apply AI Strategy was published weeks later, the document made specific reference to an “AI first policy”, stating that: “the Strategy promotes a shift in how companies and public sector organizations approach problem-solving. By adopting an AI first policy, they are encouraged to integrate AI building on European solutions.” The principle, thus, was also given a sovereignty flavor.
The Strategy went on to include subsections that “outline flagship initiatives to address the main sectoral challenges and support the AI first policy approach”, each dedicated to sectors like healthcare, defense and space, or mobility, among others. At the same time, the webpage of the European Commission which hosts the Strategy describes the document as encouraging “an ‘AI first policy’ where AI is considered as a potential solution whenever organisations make strategic or policy decisions, taking into careful consideration the benefits and the risks of the technology”.
The CADA proposal includes direct references to the “AI first principle” in its provisions, paving the way for it to be codified in EU law. One of the three objectives of the AI Centers that each Member State must establish is to “accelerate the broad adoption of cloud and AI technologies at regional and local levels, notably for SMEs (small and medium enterprises – n.), SMCs (small midcaps – n.) and public sector bodies, in line with the ‘AI first’ principle”, per Article 5(2)(b) of the CADA proposal, indicating thus that the principle is applicable both to the private and public sectors.
Additionally, the national strategies for cloud and AI that each Member State must adopt under Article 7 CADA have to include “key objectives and priorities for cloud and AI adoption, in line with the ‘AI first’ principle”. Recital 32 explains that this provision is about the “AI first principle” as “defined in the Apply AI Strategy, urging organizations to reflect on their business processes, considering the needs of and opportunities offered by AI, while taking into the consideration the potential risks”.
However, as shown above, the Apply AI Strategy refers to an AI first “policy”, not “principle”, which in any case it does not clearly define. Despite this, the animus behind it is clear enough, in the sense of enthusiasm for AI development, adoption and use. The legislative process for the CADA proposal will have opportunities for further clarification. This principle seems to also be the key explaining the push of the European Commission to make more data, including personal data, available for AI development.
3. Making data available for AI training becomes a strategic policy goal at the EU level
Among the many measures pushed by the CADA proposal to promote and enable AI, one stands out as intersectional: making data available for AI training. Recital 2 of the proposal explains the logic behind it by referring to how the EU “single market for data”, as promoted by the Data Act and the Data Union Strategy, “underpins the development of AI”. The CADA proposal has specific provisions that refer to either “personal” or “non-personal data”, which means that when it refers to “data” only, this term includes both categories.
Perhaps the biggest sign that making data available for AI training becomes a strategic policy goal in the EU is the obligation for Member States to include in their compulsory national cloud and AI strategies “measures to ensure the accessibility of high quality data for AI development, notably by preventing data bottlenecks encountered by organisations” (Article 7(2)(h) of the CADA proposal).
Two of the Grand Challenges in Annex I double down on data accessibility for AI training. While Grand Challenge 8, “Public Sector AI”, focuses on “enabling data sharing and frontier model development across national public services”, Grand Challenge 6, “Cooperative European Industrial Models”, focuses on enabling collaboration at European industrial scale to develop industrial AI models by pooling data in a “confidentiality-preserving” way. Both Challenges refer to specific privacy enhancing technologies as enablers of making data available for AI, such as “federated and distributed training approaches”, “secure execution environments”, “encryption-based processing”, “access compartmentalisation”, “anonymisation and pseudonymisation techniques”, “federated learning” or “high-fidelity synthetic data generation”.
Beyond the strategic desiderata, the CADA proposal also includes specific provisions for the operational objectives of the various “cloud and AI Leadership Initiatives” that push for making data available for AI development. As such, the relevant initiative in each case shall:
“boost data availability for AI via open-source middleware platforms underpinning common European data spaces” to support the development of EU cloud computing stacks (Article 4(2)(c) CADA proposal);
“facilitate access to, and the collection and preparation of, specific datasets for physical AI”, to advance physical AI models and systems in the EU (Article 4(4)(b) CADA proposal);
“enable secure large-scale data pooling for collaborative AI training through technologies enhancing privacy and preserving confidentiality”, to accelerate the development and uptake of industrial AI, and to implement Grand Challenge 6 (Article 4(5)(c) CADA proposal);
“promote the sharing and reusing of training data and AI models across the Union’s public services” to increase the development and adoption of AI models and systems across the EU’s public sectors (Article 4(7)(c) CADA proposal); and
“facilitate secure, privacy-enhancing health data reuse for AI models and tools in healthcare”, also with the purpose of increasing AI development and adoption in the public sector (Article 4(7)(d) CADA proposal).
This multi-layered push to make data available for AI training seems to be built upon the measures included in the Digital Omnibus proposed in November 2025 by the European Commission, which, among other things, targets the amendment of the General Data Protection Regulation (GDPR) to loosen the rules for lawfully processing personal data, including sensitive data, for the purpose of AI training and operation. In this sense, the Digital Omnibus proposed an amendment establishing a new lawful ground for processing of personal data on the basis of legitimate interests “in the context of the development and operation of an AI system”, unless national law requires consent. Additionally, a new exception that allows the processing of sensitive data would be added to Article 9(2) GDPR in the context of both the development and operation of an AI system (going thus beyond training). The Digital Omnibus is still in the middle of a lengthy legislative process, with some Member States in the EU Council pushing against exactly these amendments.
4. Sovereignty is the common thread between the AI promotion and the cloud public procurement parts of the CADA proposal
The CADA proposal is the flagship initiative of the EU “Tech Sovereignty package”, making it not surprising that sovereignty is the common thread between the AI-promotion and the cloud public procurement parts of the legislative initiative. This is nonetheless worth mentioning, because as much as the EU is pushing for development and use of AI, the focus is certainly on “European AI”.
For instance, among the operational objectives of the Cloud and AI Leadership Initiatives some are explicitly focused on promoting local AI: “advancing Union’s capabilities in frontier AI” and “advancing Union’s capabilities in physical AI models and systems” (Article 3(2)(c) and (d) CADA proposal). Perhaps the clearest indicator that the measures CADA puts in place are meant to promote European AI are the criteria for designating frontier AI priority projects, which hinge on the projects being undertaken by “a European digital infrastructure consortium […] or another legal entity eligible for funding under Union law and it involves the participation of at least three Member States” (Article 8(b) CADA proposal). Such priority projects would enjoy “sufficient AI computing resources” to be made available by the EU and Member States, pursuant to obligations under Article 9 of the CADA proposal.
Promotion of European AI development is not only emphasized by the provisions above, but also through conditions placed on cloud service providers to reach assurance levels 2 to 4 that prohibit them to use the data generated by using their service “to train or fine-tune any AI system operated by a third country or a legal entity established in a third country”.11
Finally, open source solutions are specifically promotedthrough a duty of means for Member States and the EU more broadly to “encourage” public sector bodies to use open standards and components released under an open source license when building their cloud and AI stack (Article 41 CADA proposal and following, part of Title IV).
5. Conclusion
The CADA proposal with its AI promotion part was published around the same time the AI Omnibus meant to amend the AI Act was reaching its final stages of legislative approval. Once adopted, the AI Omnibus delayed compliance with its core obligations for high-risk AI systems to December 2027, at the earliest, and even into 2028 for some AI components of devices and machinery (high-risk AI systems that are safety components of products under Annex I of the AI Act).
The CADA proposal and the AI Act Omnibus seem to converge towards relaxing the AI regulatory landscape in Europe, relying on different tools: on one hand, creating an “enabling” framework, as described above, and on the other hand postponing the enforceability of the more stringent obligations for high-risk AI systems under the AI Act. Nonetheless, the risk management and AI safety philosophy of the AI Act remain relevant, even if delayed. It is conceivable the AI-promotion provisions of the CADA proposal will be easier to implement in the EU precisely because they build on an AI safety framework.
The shift in how the European Union aims to regulate AI is visible, though, and it is more akin to industrial and economic policy. Surprisingly, it seems to draw inspiration from American and Japanese AI innovation frameworks, with the difference that the EU proposes an AI-promotion framework on top of an AI safety law.
Access to data for AI development is a key layer of this new approach to AI regulation, as is the strong sovereignty impetus percolating throughout the proposal. The interplay between sovereignty requirements and data governance frameworks is a space FPF will be watching closely.
Per Article 6(1) CADA, which also states that, where necessary, “joint undertakings” or other structures capable of achieving the listed objectives can also play a role. ↩︎
Article 2(4) CADA loosely defines “frontier AI” as “AI models or AI systems built upon such models that can perform a wide variety of tasks and that approach, reach or exceed the current state of the art”. In contrast, “AI agent” is defined with more precise terminology in Article 2(5) CADA as meaning “an AI system or a coordinated set of AI systems that can perceive and act upon their environment, with a degree of autonomy, using tools as needed to achieve specific goals and adapt to changing inputs and contexts”. ↩︎
See p. 2 of the Proposal and Article 6(2) CADA. ↩︎
And, partly, even title IV, through the Chapter dedicated to the promotion of open source technology. ↩︎
CADA proposal: Articles 10-14 CADA; America’s AI Action Plan: Pillar II, “Create Streamlined Permitting…”, p. 14 – 15. ↩︎
CADA proposal: Articles 7(2)(a) – (c); 4(7) – (8); 34; America’s AI Action Plan: Pillar I, p. 10 – 11. ↩︎
CADA proposal: Articles 7(2)(e); 8 – 9; America’s AI Action Plan: Pillar I, “Encourage Open-Source and Open-Weight AI”, p. 4 – 5. ↩︎
CADA proposal: Articles 7(2)(h); 4(2)(c), 4(4)(b), 4(7)(d); America’s AI Action Plan: Pillar I, p. 8 – 9. ↩︎
CADA proposal: Article 7; Japan’s AI Promotion Act: Article 18. ↩︎
Annex II, paragraphs 2.1(f); 3.1(f); and 4.1(f), CADA proposal. ↩︎
FPF and Leading Companies Release Risk Assessment Framework and Updated Best Practices for AI in Hiring & Employment
Expert working group updates 2023 report to account for the rise of generative AI; will host a webinar on September 28 to present an overview of best practices and risk framework
WASHINGTON, D.C. – The Future of Privacy Forum (FPF), with Dayforce, LinkedIn, UKG, Workday, and Beamery – leading HR, payroll, and employment software developers – today released Updated Best Practices for AI and Workplace Assessment Technologies. The Updated Best Practices build on Best Practices published in 2023 and address today’s widespread deployment of generative AI and agentic systems that can perform multi-step workflows with varying degrees of autonomy and oversight.
The 2023 Best Practice Framework laid the foundation of responsible AI governance, focusing on non-discrimination, transparency, data security and privacy, and human oversight as the industry was looking into the future. Today, as agents and generative AI work side-by-side with humans in consequential workflows, policymakers and practitioners need to know the full AI value chain and understand a novel risk assessment framework.
Instead of treating employment use cases as categorically either low or high risk, the Best Practices recommend a range of heightened safeguards that can be scaled with respect to an AI system’s overall functionality and intended use. In practice, risk is often dependent on context and configuration. Factors that increase risk include:
Sensitivity of Data and Inferences – Systems that ingest sensitive data or make (or are capable of making) sensitive or unexpected inferences about people should be limited or subject to heightened guardrails.
Degree of Autonomy, Discretion, and Action – Systems that operate more autonomously or independently may require greater protections to ensure transparency, auditability, and meaningful human oversight.
Proximity to Decisions – Systems that directly make decisions or exist in close proximity to human decision-making should be subject to greater protections.
Nature and Significance of Impact – Systems should be evaluated in relationship to the nature or significance of the decision being made, with the most consequential decisions (e.g. termination) requiring the greatest oversight.
FPF and the working group caution that no single risk factor is determinative, and urge organizations to assess where their AI system falls along a spectrum, considering how factors combine to elevate or reduce overall risk, as well as how each dimension may carry associated legal standards and compliance considerations.
“So much has changed around the use of AI in employment and hiring in the last few years,” said Stacey Gray, Senior Director of the FPF Center for Artificial Intelligence. “The unique risks posed by agentic and generative AI systems — such as fabricated content, reduced transparency and auditability, and the capacity to act with much less human oversight — have altered the responsibilities for developers and deployers. Safeguards like red teaming, auditing, and post-deployment monitoring are no longer optional, making this an important moment to update our previous recommendations.”
The working group’s updated best practices assign responsibilities to Developers and Deployers across the risk spectrum, including:
Responsible AI governance programs that govern, map, measure, and manage risk across the system lifecycle and account separately for predictive, generative, and agentic behavior
Non-discrimination practices that direct organizations to comply with applicable anti-discrimination law and to test proactively for unintended bias
Transparency practices that divide disclosure duties between Developers and Deployers
Data security and privacy practices that safeguard personal data alongside newer exposures such as prompt injection and agentic access to connected systems.
Human oversight practices that describe a graduated set of authority levels and require humans to remain accountable for outcomes
FPF and the expert working group will host a webinar in the coming weeks to present their updated best practices and an overview of the risk assessment framework to policymakers, staff, developers, deployers, and other interested parties. The webinar, set for September 28 at 12 pm ET, is free to attend, but registration is required. For more information and to register, click here.
“The increasing use of generative AI in the workforce presents real benefits to job seekers, employees, and employers, but can also introduce new and compounding risks,” said Sheila Jambekar, SVP, Chief Privacy Officer, Associate General Counsel at Dayforce. “Implementing AI governance can be complex, but with this new risk assessment framework from FPF, policymakers and organizations should have a better way to understand and evaluate AI governance requirements and scale their application of these updated best practices accordingly.”
“As AI becomes a more integral part of how we work, organizations need clear, practical guidance for adopting these technologies responsibly,” said Sara Harrington, VP, Legal at LinkedIn. “These updated best practices help organizations deploy AI responsibly while upholding the principles of transparency, privacy, security, and human oversight.”
“Responsible AI creates trusted AI, and trust will be the catalyst for AI adoption,” said Aditya Bharadwaj, Assistant General Counsel, AI & Data Governance, UKG. “UKG has helped organizations around the world run complex workforces in highly regulated environments for nearly 50 years, and AI is the next evolution of that responsibility. When frontline workers trust AI, organizations can move faster and with more confidence to transform how works gets done – unlocking better experiences for employees, stronger outcomes for employers, and a foundation for the next generation of frontline workforce operations.”
“Workday believes responsible AI can expand opportunity for job seekers, employees, and employers, but only when people trust it,” said Barbara Cosgrove, Chief Privacy and Digital Trust Officer at Workday. “Grounded in leading frameworks such as the NIST AI Risk Management Framework and ISO/IEC 42001, these updated best practices offer employers a practical, risk-based approach to managing generative and agentic AI, while building a foundation to collaborate with policymakers on a responsible future of work.”
The Updated Best Practices are intended to serve as a holistic practitioner framework, and draw throughout on the NIST AI Risk Management Framework and related NIST guidance, ISO/IEC 42001 and 42005, relevant provisions of the EU AI Act, and emerging U.S. state frameworks, including those in California, Colorado, and Connecticut. It is designed to help Developers and Deployers meet current obligations under civil rights, employment, and privacy law while preparing for a governance environment that continues to evolve.
For more information about the Future of Privacy Forum, visit www.fpf.org.
# # #
About Future of Privacy Forum (FPF)
FPF is a global non-profit organization that advances principled and pragmatic data protection, AI and digital governance practices. We convene leaders across industry, academia, and the public sector to provide expert analysis, benchmarking, and best practices that support responsible innovation and regulatory compliance. FPF has offices in Washington D.C., Brussels, and Singapore. Follow FPF on X and LinkedIn.
The Center for Artificial Intelligence at the Future of Privacy Forum is dedicated to navigating the complex landscape of AI governance and its intersection with privacy and data protection law. Drawing on expertise from a global Leadership Council comprising industry leaders, academics, civil society, and policymakers, the Center provides sophisticated, practical policy analysis to help organizations align innovation with responsible implementation while meeting evolving regulatory requirements. Learn more about the FPF Center for AI at https://fpf.org/ai.
FPF Statement on the Senior Chatbot Protection Bill
As artificial intelligence chatbots and voice assistants become increasingly integrated into the daily support networks of older adults, baseline consumer protections and transparency measures are essential to ensure these tools foster independence and interpersonal trust rather than introduce new risks. It is encouraging to see Congress recognizing the unique intersections of privacy and data protections, consumer technology, and aging with the introduction of the bipartisan Senior Chatbot Protection Act by Senator Mark Kelly (D-AZ). Building on our ongoing Agetech research, including our consumer survey and guiding questions for policymakers, FPF welcomes efforts to develop clear guardrails to facilitate the advancement of responsible AgeTech – so older adults can benefit from AI-driven independence without sacrificing their privacy or autonomy. – Jordan Wrigley, Senior Technologist
The AI Act Implementation Timeline: What Changes Under the AI Omnibus?
The implementation timeline of the EU AI Act has been significantly modified through the recently adopted AI Omnibus, which pushes compliance with the obligations for high-risk AI systems to December 2027 (Annex III) and August 2028 (Annex I), from the initial date of 2 August 2026. Changes of the AI Act include, among others, the addition of new prohibited practices under Article 5, measures that further allow the processing of special categories of personal data for bias detection and correction in AI systems, and revises post-market monitoring requirements.
Since the AI Act’s entry into force in August 2024, several provisions have already begun to apply: the rules on prohibited AI practices and AI literacy, and the obligations for providers of general-purpose AI models. Others, especially the rules on high-risk AI systems, will take effect over the next several years.
In November 2025, the European Commission presented the AI Omnibus proposal, aiming to reduce administrative burden and provide additional time to comply with certain obligations. Following several months of negotiations, the European Parliament and the Council of the European Union reached a political agreement on the AI Omnibus in May 2026. One of their main priorities was to agree on the revised implementation timelines ahead of the AI Act’s next milestone, envisioned for 2 August 2026.
The European Parliament adopted the agreed text of the AI Omnibus on 16 June 2026, and the Council adopted it on 29 June 2026. The AI Omnibus was published in the Official Journal of the EU on 24 July 2026.
To reflect these developments, we have updated the AI Act Implementation Timeline and incorporated both the original AI Act milestones and the changes introduced by the AI Omnibus.
This accompanying blog outlines several milestones already achieved under the AI Act, such as adopted guidelines and market surveillance authorities (MSAs) appointed thus far, and provides an overview of key changes introduced by the AI Omnibus. Key takeaways include:
While several countries including Italy and Ireland have established MSAs and communicated their Single Points of Contact to the European Commission, several remaining Member States are yet to appoint national competent authorities for the supervision of certain AI systems;
One of the driving factors of the AI Omnibus was the postponement of requirements for high-risk AI systems, most of which have been delayed to 2 December 2027;
The AI Omnibus slightly amends the language of the AI literacy obligation in Article 4 AI Act, so that providers and deployers are no longer required to ensure a sufficient level of AI literacy, but rather have to support the development of AI literacy for staff and other individuals dealing with the operation and use of an AI system;
A new prohibited AI practice is introduced covering AI systems that generate child sexual abuse material (CSAM) and non-consensual intimate material;
The legal basis for processing special category data for bias detection and correction is expanded to providers and deployers of all AI systems and models, rather than applying only to high-risk AI;
The AI Omnibus significantly expands the powers of the AI Office, which will now have exclusive competence over systems built on GPAI models not only when both the system and the model are developed by the same provider, but “also where they are developed by providers that form part of the same undertaking”;
The AI Omnibus follows the competitiveness and innovation logic pursued by the European Commission by ensuring that certain exemptions, including for simplified technical documentation, will apply to SMCs in addition to SMEs and start-ups.
1. AI Act implementation has already begun: an overview of the milestones achieved so far
Although it entered into force as a whole, the application of the AI Act provisions follows a phased timeline, with different obligations becoming applicable at different points over the following years.
The first institutional deadline followed soon after the AI Act’s adoption when, by November 2024, Member States were required to identify the public authorities or bodies responsible for supervising or enforcing the EU law protecting fundamental rights, make the list publicly available, and notify it to the European Commission and other Member States. In practice, this was not a single designation event happening at the same time at EU level. National implementation proceeded at varying speeds, and the European Commission established a consolidated list of appointed fundamental rights agencies, to be updated as Member States provide or revise their information.
The next governance milestone came on 2 August 2025, when Member States were required to designate at least one MSA and at least one notifying authority. The designation and notification of these authorities did not occur simultaneously across the EU, with some Member States experiencing significant delays. The European Commission maintains a list of designated Single Points of Contact which is updated continuously as Member States submit or revise their notifications. At the time of writing, only a limited number of Member States had notified their designated Single Points of Contact. These include Cyprus, Ireland, Italy, Latvia and Lithuania, and notifications from Luxembourg, Slovenia and Spain are published subject to the final adoption of the national designation decision.
The first provisions of the AI Act became applicable on 2 February 2025. These referred to the scope and definitions, the rules on prohibited AI practices, and the AI literacy obligations. The European Commission published Guidelines soon after on prohibited AI practices under Article 5 AI Act (4 February 2025), and on the definition of an AI system(6 February 2025).
Also in February of the same year, the AI Office launched a living repository of AI literacy practices. Important to note is that the repository does not create a presumption of compliance, but rather gives an indication of how the European Commission expects organizations to approach the obligation in practice. The AI Omnibus also introduces some significant changes to the AI literacy obligation, including by foreseeing an increased role of the European Commission and Member States, as further explored in Section 2.2 below.
The next milestone came on 2 August 2025, when the rules on general-purpose AI (GPAI) models, the governance framework, confidentiality obligations, and the provisions on penalties became applicable. The implementation of the GPAI framework extended beyond the envisaged application date. Article 56(9) required that the GPAI Code of Practice be ready by 2 May 2025. Although this deadline was not met, the European Commission published the GPAI Code of Practice on 10 July 2025. Soon after, the Commission also published the Guidelines on the scope of obligations for providers of GPAI models.
On 26 September 2025, the European Commission launched a public consultation on draft guidance and a reporting template on serious AI incidents under Article 73, later than the original deadline established for August 2025. The final guidance has not yet been published and the Commission published a reporting template for serious incidents involving GPAI models with systemic risk on 4 November 2025.
On 22 May 2026, the European Commission published its first review under Article 112(1), assessing whether the lists of prohibited AI practices and high-risk AI systems should be amended. It concluded that no immediate changes to Annex III were necessary and that it was still too early to assess the operation of the prohibited AI practices due to the limited implementation time. However, it identified a potential regulatory gap for AI systems generating child sexual abuse material and non-consensual intimate content, which was later addressed by the AI Omnibus through the introduction of a new prohibited AI practice (see Section 2.1 below).
The Guidelines on Transparency of AI-generated content under Article 50 were published on 20 July 2026. While Article 50 becomes generally applicable on 2 August 2026, the AI Omnibus postpones Article 50(2) (transparency obligations for GPAI models generating synthetic content) to 2 December 2026. These are complemented by a Code of Practice on Transparency of AI-generated content. The European Commission also published draft Guidelines on the classification of high-risk AI systems on 19 May 2026, with stakeholder consultations being open until 23 July 2026.
The implementation of the AI Act also revealed some of the challenges associated with this Regulation. Delays in the development of harmonized European standards and the need for additional implementation guidance became central during the legislative process and negotiations on the AI Omnibus. These developments ultimately shaped the decision to postpone the application of certain obligations for high-risk AI systems.
2. The AI Omnibus changes the timelines initially envisaged in the AI Act beyond high-risk AI
Before diving into the specifics of the changes to the AI Act timeline, it is useful to understand what the AI Omnibus is and why it was adopted. It was originally proposed by the European Commission in November 2025 as part of its broader Digital Omnibus package, aiming to reduce certain administrative burdens and facilitate the implementation of the AI Act, as part of the broader competitiveness push of the European Commission. The current text of the AI Omnibus is the result of the compromise between the European Parliament and the Council of the European Union in the legislative process, reached in May 2026. The agreed text was adopted by the European Parliament on 16 June and by the Council on 29 June.
The AI Omnibus provides for more than the postponement of implementation deadlines. It introduces a number of amendments that apply upon its entry into force, including new provisions on the supervisory and enforcement powers of the AI Office. It amends Article 113 of the AI Act (which regards the entry into force and application) to postpone the application of certain provisions, such as those concerning the requirements for high-risk AI systems, and leaves others subject to the AI Act’s existing application timeline.
The key highlights of the timeline as proposed by the AI Omnibus are the following:
2 August 2026: the AI Act becomes generally applicable.
2 December 2026: the new prohibited AI practice introduced by the AI Omnibus and the transitional transparency obligation for certain existing AI systems under Article 50(2) become applicable.
2 August 2027: providers of GPAI models placed on the market before 2 August 2025 must comply with the AI Act. Member States must ensure that their competent authorities establish at least one AI regulatory sandbox, operational by this date. The European Commission must also publish guidelines on the classification of high-risk AI systems under Article 6 and guidance on the implementation of Articles 8(2), 9(10), and 17(3). The Commission must also adopt delegated acts specifying the high-risk AI systems concerned, the applicable requirements or obligations, the conditions of any limitation, and its scope.
2 December 2027: Chapter III, Sections 1-3 (rules on the classification of high-risk AI systems, the requirements applicable to those systems, and the obligations of providers and other operators) become applicable to high-risk AI systems referred to in Article 6(2) and Annex III (AI systems classified as high-risk under Article 6(2), such as AI systems used in employment, education, law enforcement, migration, access to essential services, and the administration of justice, as listed in Annex III).
2 August 2028: The same Chapter III rules become applicable to high-risk AI systems referred to in Article 6(1) and Annex I (AI systems classified as high-risk under Article 6(1) because they are safety components of products, or are themselves products, covered by the Union harmonization legislation listed in Annex I).
Indeed, perhaps the most impactful change introduced by the AI Omnibus is the postponement of Chapter III, Sections 1-3 AI Act, which set out the rules on the classification of high-risk AI systems, the requirements applicable to those systems, and the obligations of providers and other operators. For the high-risk AI systems referred to in Article 6(2) and Annex III, the Chapter III requirements will apply from 2 December 2027 rather than 2 August 2026. For high-risk AI systems referred to in Article 6(1) and Annex I, the same provisions will apply from 2 August 2028 rather than 2 August 2027.
The AI Omnibus also brings some changes on substance to the AI Act. While not significant changes, they further shape AI law in the EU and are a first concrete expression of the European Commission’s push for “simplification” of regulation as part of its competitiveness agenda. Below, the blog explores some of the key changes in substance:
2.1. New prohibited AI practice focused on AI-generated CSAM and non-consensual intimate material
The AI Omnibus expands the list of prohibited AI practices under Article 5 AI Act by introducing a new prohibition covering AI systems that generate child sexual abuse material (CSAM) and non-consensual intimate material. Unlike the original Article 5 prohibitions, which have applied since 2 February 2025, this new prohibition applies from 2 December 2026. This gives providers and deployers falling within its scope approximately four months from the entry into force of the AI Omnibus to comply with the prohibition.
Given that Article 96 AI Act continues to require the European Commission to develop guidelines on the prohibited AI practices referred to in Article 5, the Guidelines on prohibited AI practices published in February 2025 will likely be updated to reflect the new prohibition introduced by the AI Omnibus. To better understand the prohibited AI practices, FPF’s “Red Lines under the AI Act” blog series breaks down each prohibition, as well as their interplay with existing EU law such as the GDPR and the Digital Services Act, and is available here.
2.2. Changes to the AI literacy obligation
Article 4 AI Act originally stated that “providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf” (emphasis added). The new Article 4(1) of the AI Omnibus has changed slightly the wording of this provision so that providers and deployers of AI systems “shall take measures to support the development of AI literacy…” (emphasis added). The same Article 4(1) also introduces a new sentence explaining that this obligation “does not require providers or deployers to guarantee any specific level of AI literacy of any individual.” In this way, the AI literacy requirement is seemingly presented less as a strict obligation through which providers or deployers shall ensure a sufficient, measurable level of AI literacy, and more as an obligation through which some level of AI literacy should be achieved.
Coupled with the new Article 4(2) of the AI Omnibus, which introduces a role for the Commission and Member States in issuing guidance and practical examples on how the AI literacy obligation should be fulfilled, it remains to be seen how the AI literacy requirement will be implemented in practice.
2.3. Processing of special categories of personal data for bias detection and correction
The AI Omnibus introduces a new Article 4a, which allows providers of high-risk AI systems to exceptionally process special categories of personal data where this is strictly necessary to detect and correct bias. The bias detection provision originally foreseen for high-risk AI systems in Article 10(5)(a) – (f) AI Act remains unchanged by the new Article 4a of the AI Omnibus.
Where a change can be seen is in the expansion of this provision to AI systems not classified as high-risk. Indeed Article 4a introduces a new point (2) allowing “providers and deployers of otherAI systems and models” (emphasis added) to exceptionally process special category data “to the extent that such processing is strictly necessary to ensure bias detection and correction in view of possible biases that are likely to affect the health and safety of persons, have a negative impact on fundamental rights or lead to discrimination” (new Article 4a (2)(a) AI Omnibus). While the applicable safeguards for this processing remain the same as those for high-risk AI systems, the legal basis for processing special category data is expanded to providers and deployers of all AI systems and models, including general-purpose AI models.
Interestingly, the new Article 4a of the AI Omnibus also adds a new sentence which clarifies that “This paragraph does not create any obligation to conduct such bias detection and correction”, leaving bias detection to the discretion of providers and deployers. The new Article 4a applies upon the entry into force of the AI Omnibus, and must continue to be applied alongside the GDPR and other applicable data protection rules.
2.4. New powers for the AI Office
The AI Office sees its supervisory role significantly expanded under the AI Omnibus. Recital 31 of the AI Omnibus states that clarifying the role of the AI Office is necessary in order to strengthen the governance of AI systems, and that it should have exclusive competence over systems built on GPAI models not only when both the system and the model are developed by the same provider, but “also where they are developed by providers that form part of the same undertaking” (emphasis added). The AI Omnibus amends Article 75 AI Act to this effect.
The AI Office will also act as the MSA for AI systems constituting or embedded in Very Large Online Platforms and Very Large Online Services as designated under the Digital Services Act (DSA) (see Recital 32 of the AI Omnibus). The same Recital also explicitly includes the requirement of regulatory cooperation between the AI Office and the European Commission unit responsible for DSA enforcement.
The AI Omnibus also introduces several new Commission guidance obligations. By 1 August 2027, the Commission must publish guidelines on the classification of high-risk AI systems under Article 6 and guidance on the practical implementation of Articles 8(2) (requirements for high-risk AI systems), 9(10) (risk management system) and 17(3) (quality management system). In addition, by 2 September 2027, the Commission must publish guidance on the post-market monitoring plan for high-risk AI systems. The extended timelines provide the Commission with significantly more time to publish and adopt interpretative guidelines to support the implementation of the AI act.
2.5. Sandboxes and other “competitiveness” markers
In view of the European Commission’s overall competitiveness agenda, the AI Omnibus similarly aims to address and facilitate innovation. A core part of this goal is the extension of certain simplified requirements from applying only to SMEs to include small mid-cap enterprises (SMCs). The Commission defines SMCs as having fewer than 750 employees and an annual turnover not exceeding EUR 150 million (see Commission Recommendation 2025/1099 of May 2025). The introduction of a new SMC category and definition is aimed at supporting the transition of enterprises from SME to SMC, recognizing that the latter may continue to face similar regulatory burdens as the former and should therefore continue to benefit from simplified requirements.
In this context, certain AI Act exemptions applicable to SMEs will also apply to SMCs, namely:
Technical documentation for high-risk AI systems – SMCs may also use the simplified template for providing technical documentation under Annex IV AI Act (amended Article 11(1) AI Act);
Quality management systems – SMCs can also benefit from the proportionality requirement in Article 17 AI Act, by which the implementation of quality management systems should be proportionate to the size of the provider’s organization;
Priority to AI regulation sandboxes – alongside startups and SMEs (Recital 24 AI Omnibus, and amendments made to Article 57).
In addition to the role expansion foreseen for the AI Office, as explored above, the AI Omnibus also introduces a requirement for it to establish an AI regulatory sandbox at the Union level for systems based on GPAI models. The reasoning behind this change is a recognition that sandboxes act as regulatory tools to foster clarity and consistency in the governance of AI systems, and to foster innovation (see Recitals 24-26 AI Omnibus).
3. Concluding reflections
The simplification and competitiveness agenda of the European Commission has been so far translated for the AI Act into more generous timelines for compliance, support for sandboxes, easing of compliance bureaucracy for medium-sized enterprises and easing of the AI literacy obligations. It is notable that the amendment of the AI Act was swift – it took only about nine months for the EU legislative machine to convert the proposal into law. On the other hand, the amendments are a targeted intervention, given that the core obligations and legislative philosophy of the AI Act were not touched.
One visible structural shift achieved by the AI Omnibus was the enhancement of supervisory powers of the AI Office, which aligns with the European Commission’s inclination to centralize under its authority supervisory powers within the digital acquis. The supervisory structure of the DSA for VLOPS and VLOSES, as well as that of the Digital Markets Act follow the same trend.
The AI Omnibus does not change the AI Act’s phased implementation, but it provides a larger window for compliance readiness to providers of high-risk AI systems, addressing some of the AI Act’s deadlines and milestones. Beyond the rules for high-risk AI, prohibited practices under Article 5 are already in force and applicable, as are transparency requirements for GPAI model providers (Article 53) and systemic risk rules (Article 51).
As the implementation of the AI Act continues, keeping track of the changes provided by the AI Omnibus and the new guidance will be essential. For requirements regarding AI literacy in particular, ensuing Commission and Member States’ guidance will determine how the obligation will apply in practice.
The updatedFPF AI Act Implementation Timelineprovides an overview of the revised implementation timeline, key AI Omnibus amendments, and the remaining AI Act provisions that continue to apply.
FPF Submits Comments to Inform Colorado Automated Decision-Making Technology and Chatbot Rulemaking Processes
On July 13, FPF submitted comments in response to the Colorado Department of Justice’s (the Department’s) pre-rulemaking process for the Colorado Automated Decision-making Act (SB 189) and the Chatbot Safety Act (HB 1263). As lawmakers continue to calibrate a proportionate approach to consumer protection from risks of AI-related harms, Colorado’s two new laws each take a distinctive approach. FPF’s comments seek to ensure that Colorado’s regulations adequately clarify compliance ambiguities while supporting interoperability with existing state and federal privacy frameworks.
Colorado Automated Decision-Making Act
Enacted in 2026 to repeal and replace the Colorado AI Act (CAIA), SB 189 incorporates several revisions recommended by the Colorado AI Policy Working Group convened by Governor Polis to address concerns raised against the prior law. As amended, the law has three main obligations: (1) imposing documentation obligations on developers of covered automated decision-making technology (ADMT) when it is marketed or advertised to materially influence a consequential decision; (2) requiring deployers to provide notice of use and specific post-adverse-outcome disclosures when such technology is used to make consequential decision; and (3) creating consumer rights to access and correct personal data used in an adverse consequential decision made by a covered ADMT, and an opportunity for meaningful human review of that decision. The law takes effect January 1, 2027, and the Department has opened a pre-rulemaking process to gather stakeholder input on rules clarifying and implementing these core requirements.
With these goals in mind, FPF recommended that the Department focus on clarifying requirements to ease points of tension between the Colorado Automated Decision-making Act (“ADM Act”) and the Colorado Privacy Act (“CPA”), including by:
Aligning the scope and definition of automated decision-making technology;
Clarifying transparency obligations to enable compliance under both laws; and
Streamlining consumer rights.
Chatbot Safety Act
Also enacted in 2026, HB 1263 regulates “conversational AI services” by requiring operators to implement age estimation and tools for minors or parents to adjust privacy and account settings; prohibit engagement-based rewards targeting minors; disclose to users that the service is AI, not human; and prevent the service from producing sexual content, simulating emotional dependence, or engaging in sexually explicit interactions with minors. The law is subject to tiered effective dates, with the law as a whole taking effect on August 12, 2026, the substantive operator obligations taking effect January 1, 2027, and annual reporting requirements taking effect July 1, 2027. The Department’s pre-rulemaking questions addressed HB 1263’s scope and key terms, age estimation requirements, and protocols related to suicidal ideation and self-harm, among other topics.
In response to these questions, FPF outlined three recommendations for the Department’s consideration to improve the law’s clarity and implementation:
Clarifying key exemptions and terms, including the exemption for services limited to a “narrow and discrete topic”;
Ensuring age estimation rules are both flexible and interoperable with the recently enacted Digital Age Assurance Act; and
Specifying rules regarding the creation and implementation of suicide and self-harm crisis intervention protocols.
FPF Releases New Issue Brief on U.S. “Data Broker” Regulatory Landscape
Data brokers have been the subject of intense scrutiny in recent years, including through critical media coverage, public hearings, private lawsuits, regulatory enforcement actions, and new state and federal regulatory frameworks. Despite all this public attention, there is little consensus as to who is a “data broker,” what risks and benefits are associated with data brokerage, and how the evolving privacy regulatory landscape affects this industry.
The data broker industry is diverse, and the risks posed to individuals vary depending on data use cases, sensitivity, and companies’ practices. Data brokerage also enables services widely regarded as beneficial, such as combating fraud and other illegal activities as well as enabling access to financial services. It also supports personalized marketing, toward which consumers and other stakeholders have a range of views.
To help make sense of this rapidly evolving regulatory space, FPF is releasing a new issue brief, The Boundaries of Data Brokerage: An Overview of the U.S. Regulatory Landscape. This issue brief provides an overview of the emerging regulatory landscape—focusing on recently enacted state and federal laws that specifically regulate the data broker industry—as well as key considerations for policymakers and industry actors.
Inconsistent Scope: New U.S. data broker laws define a data broker as either a business that sells personal data that the business did not collect directly from the consumer or sells the data of a consumer with whom the business does not have a direct relationship. Both approaches attempt to exclude the sale of data that was collected in a first-party interaction but differ in their formulation.
Requirements Include Registration, Security, and Targeted Prohibitions: Data brokers are typically required to register with the state annually. Some of these laws include additional obligations such as maintaining adequate security or targeted prohibitions such as bans on fraudulent acquisition of personal data.
Accessible Deletion Mechanisms Are Paradigm-Changing: Exercising deletion or opt-out rights on a company-by-company basis can be difficult and time-consuming for consumers. California’s new accessible deletion mechanism, soon to be replicated in Connecticut, changes this calculus for consumers by enabling deletion requests en masse. Nevertheless, these tools may pose a risk to consumers in-and-of themselves if not implemented securely.
Existing Consumer Protection Law Remains Relevant: As states experiment with data broker registries and Congress focuses on limiting the flow of sensitive data to foreign adversaries and countries of concern, longstanding consumer protection laws like the FTC Act remain an avenue for enforcement actions against data brokers.
The issue brief concludes with ongoing policy considerations that may prove valuable for future legislative efforts as well as industry practices. For policymakers, key questions include the appropriate scope of new regulations (both in terms of the types of data and entities who should be regulated), whether new frameworks should broadly define “data brokerage” or focus on specific harmful use cases, and how existing legal and technical protections can be better enforced or inform future regulatory frameworks. For industry, they include the extent to which organizations should adopt voluntary practices for transparency and data stewardship in order to deepen customer and public trust.