Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

Massachusetts Legislates Against Sale of Precise Location Data

Massachusetts has passed a new privacy rights bill that explicitly prohibits the sale of precise location data. This legislative action marks a significant step in enhancing consumer privacy protections at the state level. It reflects growing concerns over the tracking and commercialization of highly sensitive personal information. The bill could set a precedent for other states considering similar restrictions on data brokers and advertisers. It underscores the increasing demand for stronger regulatory frameworks to govern data collection and usage.

Today's question

Biometric data processing for identification purposes requires:

  1. Standard administrative procedures fulfill the relevant obligations, under the monitoring regulatory framework
  2. A lawful basis under Article 6 and an Article 9(2) exception, as biometric data for identification is special category data under Article 9(1)
  3. Consent from the data subject in all cases without exception, in accordance with the systematic observation requirements
  4. Only a legitimate interest assessment, in accordance with the systematic observation requirements, in keeping with the principle of transparency

Answer this question on the site

Worth knowing

  1. WhatsApp Alleges NSO Group Ongoing Spyware Attacks Despite Legal Action

    WhatsApp has reported new spyware attacks linked to the NSO Group, accusing the Israeli firm of violating court orders. This resurgence of activity highlights the persistent threat posed by sophisticated surveillance tools and the challenges in enforcing legal restrictions against their use by state backed actors. The situation raises significant concerns about individual privacy and security on widely used communication platforms.

  2. Oxford University Student Data Breached Again Via Career Platform

    Oxford University student data has reportedly been compromised for a second time, this instance occurring through a breach of a third party career platform. This incident underscores the ongoing vulnerability of educational institutions to cyberattacks, particularly those involving third party vendors and their supply chain. It highlights the critical importance of robust vendor due diligence and continuous security monitoring for organizations that handle sensitive personal data.

  3. Attacks Against AI Developers Through Hacked Open Source Tools and Fake Job Offers Indicate New Threat Vectors

    AI developers are being targeted through sophisticated methods including hacked open source tools on platforms like GitHub and elaborate fake job offers. These attacks aim to steal credentials and cryptocurrency, highlighting a critical vulnerability in the AI development ecosystem. The incidents underscore the need for enhanced security practices for developers and organizations leveraging artificial intelligence, especially concerning supply chain security and phishing awareness.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.