Privacy & Cybersecurity #83
CNIL, UODO, Garante, Colorado, NIST, CalPrivacy, and DHS each issued major privacy and AI-related updates spanning DPO conflicts, AI deployment checklists, employee email monitoring, chatbot and ADMT rules, NVD modernization, data broker enforcement, and HELIX surveillance oversight. Together, the actions show tighter expectations for accountability, transparency, human review, data minimization, and lawful retention across workplace, consumer, and government systems. #CNIL #UODO #Garante #Piaggio #ColoradoADMTAct #ColoradoChatbotSafetyAct #NIST #NVD #CalPrivacy #LocateSmarter #HELIX #DHS #SecretService

Keypoints

  • CNIL detailed how organizations should identify and resolve DPO conflicts of interest.
  • Poland’s UODO released AI checklists for GDPR and AI Act pre-assessment.
  • Italy’s Garante fined Piaggio €460,000 for unlawful employee email monitoring and retention.
  • Colorado proposed rules for ADMT and chatbot safety, including disclosures, human review, and age assurance.
  • NIST sought input on AI-enabled modernization of the NVD, while CalPrivacy fined LocateSmarter and DHS disclosed HELIX surveillance risks.

Read More: https://keplernewsletter.substack.com/p/privacy-and-cybersecurity-83