Tag:privacy

1
EU-US Data Privacy Framework Under the Spotlight Following FTC Independence Ruling
2
EU Digital Omnibus on AI Enters Into Force
3
Mixed Blessings: Decision on Appeal by Bunnings Against Privacy Commissioner’s Determination Re the Use of Facial Recognition Technology
4
Australia’s Privacy Regulator Beginning 2026 With Its First Compliance Sweep
5
Australian Clinical Labs fined AU$5.8 Million for 2022 Medlab Data Breach in an Australian First
6
Australian Privacy Law Reform Tranche 2: The Time for Conversation is Over
7
New EDPB Guidelines: Processing Personal Data on Blockchain
8
Privacy Awareness Week 2025
9
New EDPB Statement on Age Assurance: What You Need to Know
10
Australian Privacy Law Reform – The Wait is (Almost!) Over

EU-US Data Privacy Framework Under the Spotlight Following FTC Independence Ruling

By: Sarah Pearce and Sophie Verstraeten

The European Data Protection Board (EDPB) has called on the European Commission to assess the implications of the recent US Supreme Court decision in Trump v. Slaughter for the EU-US Data Privacy Framework (DPF), the mechanism that facilitates transfers of personal data between the EU and participating US organisations.

Read More

EU Digital Omnibus on AI Enters Into Force

By: Sarah Pearce and Thomas Nietsch

The EU has adopted its first substantive amendment to the AI Act. Regulation (EU) 2026/1744, commonly referred to as the AI Omnibus, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. While the legislation postpones certain aspects of the AI Act’s compliance timetable, it would be a mistake for organisations to view the Omnibus as a broad pause on AI regulation in Europe.

Read More

Mixed Blessings: Decision on Appeal by Bunnings Against Privacy Commissioner’s Determination Re the Use of Facial Recognition Technology

By: Cameron Abbott and Rob Pulham

The Administrative Review Tribunal of Australia (Tribunal) has partially overturned the findings of the Privacy Commissioner on Bunnings’ use of facial recognition technology (FRT) in its stores.

Read More

Australia’s Privacy Regulator Beginning 2026 With Its First Compliance Sweep

By: Rob Pulham, Cameron Abbott, and Annaliese Filippis (Graduate, Melbourne)

The Office of the Australian Information Commissioner (OAIC), Australia’s privacy regulator, is conducting its first ever privacy compliance sweep, as of this January. The compliance sweep will include a review of the privacy policies of businesses that collect information in person.

Read More

Australian Clinical Labs fined AU$5.8 Million for 2022 Medlab Data Breach in an Australian First

By Cameron Abbott, Rob Pulham and Stephanie Mayhew

The Federal Court has ordered Australian Clinical Labs (ACL) to pay AU$5.8 million in civil penalties following a 2022 data breach involving its then-newly acquired Medlab Pathology business. The breach affected over 223,000 individuals whose data was accessed and infiltrated by malicious actors and is one of Australia’s most significant healthcare cyber incidents.

Read More

Australian Privacy Law Reform Tranche 2: The Time for Conversation is Over

By: Cameron Abbott, Rob Pulham, and Stephanie Mayhew

Tranche 2 of the Australian Privacy Act reforms is expected soon (perhaps imminently), following comments from the new attorney general in the media that suggested the time for conversation and for lobbying is over. The attorney general noted in an interview last month on Sky News that the highly anticipated “second tranche” of Australian privacy law reform is coming, saying “Australians are sick and tired of their personal data being exploited” and “not being protected,” and that “we will not have our privacy reforms dictated by multinational tech giants.”

Read More

New EDPB Guidelines: Processing Personal Data on Blockchain

By: Claude-Étienne Armingaud

The European Data Protection Board recently published its draft Guidelines 02/2025, which remain open to consultation until 09 June 2025. Stakeholders in the blockchain industry are encouraged to submit any observations before the finalization of these Guidelines.

Read More

Privacy Awareness Week 2025

By: Cameron Abbott, Rob Pulham, Stephanie Mayhew and Emre Cakmakcioglu

In Australia, last week was the 2025 Privacy Awareness Week (PAW), with this year’s theme ‘Privacy – it’s everyone’s business’. Among other things in PAW, the Office of the Australian Information Commissioner (OAIC) produced a Privacy Foundations self-assessment tool, which provides a privacy maturity score on the basis of tenets such as Accountability, Transparency, Collection and Data breach management. The tool, and PAW more broadly emphasise that privacy is not just about compliance, but good business and building trust. NSW, Vic and QLD state governments have each run parallel PAW events.

Read More

New EDPB Statement on Age Assurance: What You Need to Know

By: Claude-Etienne Armingaud

On 11 February 2024, the European Data Protection Board (EDPB) adopted a new statement on age assurance. This statement, while not legally binding, will guide the enforcement of age-gating methods across the EU. Age assurance refers to the methods used to determine an individual’s age or age range with varying levels of confidence or certainty.

Read More

Australian Privacy Law Reform – The Wait is (Almost!) Over

By: Cameron Abbott, Stephanie Mayhew, and Rob Pulham

The long-awaited privacy reform has finally been introduced into the Australian Parliament today with the introduction of the Privacy and Other Legislation Amendment Bill 2024. Described as ‘Tranche 1’ of the reforms, the Bill introduces significant uplifts to several aspects of Australia’s privacy laws.

Read More

Copyright © 2026, K&L Gates LLP. All Rights Reserved.