Here are key highlights from April 2023 detailing global news and regulatory updates.
US & Canada
- Canada’s Bill C-27, the Digital Charter Implementation Act, passes second reading and is referred to a standing committee before going to third reading in the House of Commons
- Indiana becomes seventh US state to pass a comprehensive privacy law, one that closely tracks the laws in Connecticut and Virginia
- Montana and Tennessee comprehensive privacy bills clear legislatures on the same day, joining Indiana and Iowa among states to pass such bills this year. See also this article for more details on Montana’s law
- Nevada Senate passes Bill 370, a health data privacy bill that would bar healthcare companies from collecting or sharing patient health information without consumer consent
- Texas proposes a strong data privacy law that includes definitions of both de-identified and pseudonymous data
- US state privacy laws and whether they fill the void in US privacy law with respect to the protection of health information
- US health industry responds to privacy crackdown by cutting back significantly on targeted Facebook and Google ads
- US BBB National Programs to turn the Consumer Privacy Framework for Health Data into an accountability program for companies collecting and using non-HIPAA-covered consumer health data
- US FTC Chair and other departments release a joint statement on AI, pledging to uphold America’s commitment to the core principles of fairness, equality, and justice
- Washington state’s My Health My Data Act receives final approval in the House, establishing consumer rights, consent requirements for data practices concerning personal health care information, and a private right of action
EMEA
- EU and Japan complete the first review of their mutual adequacy agreement, demonstrating that the convergence between their frameworks has increased since 2019 (also in APAC)
- Finnish district court gives 3-month suspended jail sentence to therapy center ex-CEO for not pseudonymizing and encrypting patient data
- Tanzania’s Personal Information Protection Act—signed into law on November 27, 2022—is examined in detail
- UK data protection reforms and their impact in comparison to the GDPR
APAC
- Australian telecommunication giant Optus hit with class action over cybersecurity breach for failing to adequately protect customer data and destroy or de-identify the data of former customers
- China’s standard contractual clauses translated
- Japan and the EU complete the first review of their mutual adequacy agreement, demonstrating that the convergence between their frameworks has increased since 2019 (also in EMEA)
- Vietnam’s government published a Decree on Protection of Personal Data, effective July 1, which implements principles around data collection, processing and storage
LATAM
- Brazil’s data protection authority releases guidance on proper procedures for data protection impact assessments (DPIA)