PrivacySignal
GDPR / Intl

Italy’s government, DPA argue over legality of face biometrics retention plan

biometricupdate.com · · International · GDPR & International

Italy's government and its data protection authority are in dispute over a plan to retain facial biometric data, with the two bodies holding conflicting positions on whether the practice is legal.

Why this matters: Face biometrics are not like passwords. You cannot change your face if something goes wrong. When a government wants to store them, the stakes are permanent. Italy's data protection authority exists precisely to push back on plans like this. The fact that it is openly clashing with the government is the system working as designed. Whether the government backs down or pushes through matters for everyone whose face could end up in a state database.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

GDPR / Intl
H Hunton Andrews Kurth LLP · · International

EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence

The European Data Protection Board has called for a review of the EU-U.S. Data Privacy Framework following a U.S. Supreme Court ruling that affects the independence of the Federal Trade Commission, a key enforcement body underpinning the transatlantic data transfer agreement.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
GDPR / Intl
Information Commissioner's Office · · UK

ICO statement on Upper Tribunal decision

I need to work carefully here — the excerpt gives almost nothing beyond the headline. I'll write only what the headline and source reasonably imply: the UK's Information Commissioner's Office issued a public statement following a ruling by the Upper Tribunal, which is an appellate body that hears ch

Who should care: Lawyers · Privacy officers · AI governance

GDPR / Intl
Inside Privacy (Covington) · · International

New York Publishes Final SAFE For Kids Act Rules

On July 28, 2026, the New York Office of the Attorney General released final rules (the “Rules”) implementing the Stop Addictive Feeds Exploitation (SAFE) for Kids Act, which goes into effect on January 25, 2027. The SAFE for Kids Act requires online “addictive social media platforms,” which are defined as websites, online services, and applications... Continue Reading…

Who should care: Lawyers · Privacy officers · Compliance

#state-privacy#regulation#security Read original →
GDPR / Intl
Inside Privacy (Covington) · · International

EDPB Publishes Draft Guidelines on Anonymisation

The European Data Protection Board has released draft guidelines updating its 2014 position on anonymisation, offering a more structured framework for determining when data can be treated as truly anonymous. The guidelines reflect the EDPB's cautious stance while attempting to give organisations clearer criteria for making that assessment.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
GDPR / Intl
IAPP · · International

EDPB requests review of EU-US Data Privacy Framework following Trump v. Slaughter

The European Data Protection Board has called for a review of the EU-US Data Privacy Framework following the Trump v. Slaughter case, which relates to the dismissal of Federal Trade Commission members and raises concerns about the independence of the US enforcement body underpinning the transatlantic data transfer agreement.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
GDPR / Intl
DataBreaches.net · · International

Cyberattack hits Liechtenstein, with 31,000 records stolen

Liechtenstein's government has confirmed a cyberattack that resulted in the theft of approximately 31,000 personal records. Given the country's population of around 41,000, the breach potentially affects the majority of its residents.

Who should care: Lawyers · Privacy officers · AI governance