December 2023

Data Privacy Frontline Report

December 2023

Here are key highlights from December 2023 detailing global news and regulatory updates.

US & Canada

  • Canada’s provincial privacy commissioners oppose the proposed creation of a federal privacy tribunal, arguing that this would be a waste of time and money
  • Quebec’s draft regulation for the anonymization of personal information is published in the government’s official gazette and is subject to a 45-day consultation period
  • US Department of Health and Human Services (HHS) finalizes rule establishing first of its kind transparency requirements for AI and other predictive algorithms that support hospital and office-based physician care
  • US HHS settles first-ever phishing cyberattack investigation, one that affected the electronic protected health information of close to 35,000 individuals
  • US Federal Communications Commission (FCC) launches first-ever enforcement partnerships with state attorneys general, sharing expertise and resources in conducting privacy, data protection, and cybersecurity-related investigations
  • US National Institute for Standards and Technology (NIST) publishes a report summarizing current practices, challenges, and proposed solutions for securing genomic data


  • EU reaches a deal on the world’s first comprehensive AI legislation, with pressure to finalize the text soon
  • EU Council of the European Union members agree to a negotiating stance on the proposed European Health Data Space
  • EU Court of Justice of the European Union (CJEU) clarifies legal grounds for issuing fines, finding that fines should only be given for violations committed “intentionally or negligently”
  • EU’s European Data Protection Board (EDPB) publishes a report claiming the application of the GDPR over the last five and a half years has been successful and making no call for revisions to the regulation

Gain confidence to use and share sensitive data

Find out how our advisory services can help you safely leverage data derived from information about people. Watch this 15-minute webinar.


  • South Korea’s Personal Information Protection Committee (PIPC) publishes a guide for the new amendment to the Personal Information Protection Act, which includes a requirement for private entities to participate in dispute resolution


  • Brazil’s National Data Protection Authority (ANPD) updates its regulatory agenda for 2023–2024, which includes anonymization and pseudonymization as a priority theme
  • Latin American and Caribbean authorities produce the Santiago Declaration to promote AI ethics in the region

Archiving / Destroying

Are you unleashing the full value of data you retain?

Your Challenges

Do you need help...


Value Retention

Client Success

Client: Comcast

Situation: California’s Consumer Privacy Act inspired Comcast to evolve the way in which they protect the privacy of customers who consent to share personal information with them.


Are you achieving intended outcomes from data?

Your Challenge

Do you need help...


Unbiased Results

Client Success


Situation:’s AI-powered tech helps clients improve their online experience by sharing signals about website visitor intent. They wanted to ensure privacy remained fully protected within the machine learning / AI context that produces these signals.


Do the right people have the right data?

Your Challenges

Do you need help...


Usable and Reusable Data

Client Success

Client: Novartis

Situation: Novartis’ digital transformation in drug R&D drives their need to maximize value from vast stores of clinical study data for critical internal research enabled by their data42 platform.



Are you empowering people to safely leverage trusted data?

Your Challenges

Do you need help...


Security / compliance efficiency


Client: ASCO’s CancerLinQ

Situation: CancerLinQ™, a subsidiary of American Society of Clinical Oncology, is a rapid learning healthcare system that helps oncologists aggregate and analyze data on cancer patients to improve care. To achieve this goal, they must de-identify patient data provided by subscribing practices across the U.S.


Acquiring / Collecting

Are you acquiring the right data? Do you have appropriate consent?

Your Challenge

Do you need help...


Consent / Contracting strategy

Client Success

Client: IQVIA

Situation: Needed to ensure the primary market research process was fully compliant with internal policies and regulations such as GDPR. 



Are You Effectively Planning for Success?

Your Challenges

Do you need help...


Build privacy in by design

Client Success

Client: Nuance

Situation: Needed to enable AI-driven product innovation with a defensible governance program for the safe and responsible use
of voice-to-text data under Shrems II.


Join the next 5 Safes Data Privacy webinar

This course runs on the 2nd Wednesday of every month, at 11 a.m. ET (45 mins). Click the button to register and select the date that works best for you.