This is a permanent edition. It carries the briefing exactly as published on this date and does not change.
EDPB Clarifies 'Main Establishment' for AI Act's Centralised Supervision
The European Data Protection Board has adopted a formal Opinion on the notion of 'main establishment' under the forthcoming EU AI Act. This guidance aims to align the AI Act's one-stop-shop mechanism with the established concept under the GDPR, allowing for centralized supervision by a single lead authority. The Opinion clarifies that for AI providers, the main establishment will typically be the place of central administration in the Union, unless decisions on AI system compliance are made elsewhere. This anticipates the need for a single point of contact for enforcement for companies operating across multiple EU member states.
Processing activities related to the exercise of official authority under Article 6(1)(e) are:
Within GDPR scope but member states may maintain or introduce specific provisions to adapt GDPR requirements to the public sector context under Article 6(2) and (3)
Subject to all GDPR provisions without modification, as defined by the territorial application provisions, with appropriate safeguards and measures in place, under the applicable procedural safeguards
Only covered by the Law Enforcement Directive, under the GDPR's material and territorial scope rules, including appropriate organizational measures
Excluded from the GDPR entirely, under the GDPR's material and territorial scope rules, particularly for cross-border operations, as required by the applicable legal framework
The U.S. Federal Trade Commission (FTC) has finalized a rule expanding the scope of the Health Breach Notification Rule (HBNR). The updated rule clarifies that it applies to health apps, wearables, and other direct to consumer health tech services not covered by HIPAA, requiring them to notify individuals, the FTC, and sometimes the media of a breach of unsecured identifiable health information.
The privacy rights group NOYB has filed a GDPR complaint against OpenAI with the Austrian data protection authority. The complaint alleges that ChatGPT repeatedly provided false biographical information about the complainant and that OpenAI claimed it was technically unable to correct the data, potentially violating the GDPR's principle of accuracy and the right to rectification.
California Privacy Agency Prioritizes AI and Risk Assessment Rulemaking
The California Privacy Protection Agency (CPPA) board has confirmed its next major rulemaking priorities, which will focus on automated decision making technology (ADMT), risk assessments, and data audits. This signals California's intent to create binding rules governing the use of AI and requiring companies to conduct comprehensive privacy risk assessments for high risk processing activities, moving ahead of potential federal legislation.
Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.