Privacy & Cybersecurity #82
Germany’s BSI released updated CRA compliance guidance and SBOM specifications, while Czech and Hungarian authorities delivered notable GDPR decisions on pseudonymized data and privacy notices. The article also covers NAI’s AI-in-advertising governance guidance, a UN scientific warning that AI governance is lagging behind agentic systems, and Stanford HAI’s call for new rules for world models and spatial intelligence. #BSI #TR03183 #SBOM #CzechSupremeAdministrativeCourt #NAIH #IndependentInternationalScientificPanelonArtificialIntelligence #StanfordHAI

Keypoints

  • BSI published CRA compliance guidance and updated its SBOM specification to version 2.1.0.
  • The Czech Supreme Administrative Court clarified when pseudonymized data can still be personal data under the GDPR.
  • Hungary’s NAIH fined an online retailer for an inaccurate, template-generated privacy notice.
  • The NAI issued guidance for governing generative AI and agentic AI in network advertising.
  • UN and Stanford reports warned that AI governance must adapt to agentic systems and world models.

Read More: https://keplernewsletter.substack.com/p/privacy-and-cybersecurity-82