Search for:
Category

Cybersecurity, Data and Tech

Category

On 10 December 2024, the Treasury Laws Amendment (Responsible Buy Now Pay Later and Other Measures) Act 2024 (Cth) (“BNPL Act”) received royal assent. The BNPL Act contains 6 Schedules that respectively amend a range of statutes including relevantly the National Consumer Credit Protection Act 2009 (Cth) which regulates the industry of BNPL products. Providers of BNPL products have six months before this new regulatory framework commences to apply for, or vary an existing Australian credit license as well as update their procedures, policies and contracts.

The European Accessibility Act is a directive aimed at improving the accessibility of products and services for people with disabilities across the European Union. It establishes common accessibility requirements for a wide range of products and services provided to consumers to ensure that people with disabilities have better access to digital and physical environments, thereby promoting their inclusion and participation in society.

The recent County Court of Victoria decision, Lynn Waller (A Pseudonym) v Romy Barrett (A Pseudonym) [2024] VCC 962, suggests the existence of an Australian common law cause of action for invasion of privacy.
The trial judge assessed that the right to privacy is a value distinct to the right to keep information confidential. As a result, she considered that privacy requires separate protection to breach of confidence claims. This brings Australia closer to the accepted position in the UK, US, Canada, and New Zealand.

While this article was published, the Security Bureau of the Hong Kong Government announced that the Protection of Critical Infrastructure (Computer System) Bill will be gazetted on Friday, 6 December 2024, and will be introduced into the Legislative Council for First Reading and Second Reading on 11 December 2024. We will provide an update on further developments.

The proposed amendments to the Consumer Protection Act Regulations in South Africa aim to enhance consumer privacy by regulating direct marketing practices. Open for public comment until 15 January 2025, these changes focus on creating an opt-out registry managed by the National Consumer Commission, allowing consumers to block unsolicited electronic communications. Direct marketers will be required to register, renew annually, and cleanse their databases regularly to comply with the new rules. The amendments also introduce enforcement mechanisms for non-compliance and align with the Protection of Personal Information Act, ensuring comprehensive consumer protection against unwanted marketing.

Singapore and the European Union (EU) have formalized their collaboration on Artificial Intelligence (AI) safety with the establishment of a new Administrative Arrangement (AA). This arrangement aims to enhance cooperation in promoting technological innovation and the development and responsible use of safe, trustworthy, and human-centric AI. The AA was signed by Mr Joseph Leong, Permanent Secretary of the Ministry of Digital Development and Information of Singapore, and Mr Roberto Viola, Director-General of the Directorate-General for Communications Networks, Content and Technology of the European Commission.

Singapore and the United Kingdom have signed a new Memorandum of Cooperation (MoC) to enhance the safety and reliability of artificial intelligence (AI) technologies in its development and use. This agreement aims to pave the way for greater public trust in AI advancements. The MoC was signed by Minister for Digital Development and Information, Josephine Teo, and Secretary of State for Science, Innovation, and Technology, Peter Kyle, during Minister Teo’s working visit to the UK.

On 24 September 2024, following an in-depth consultation with industry participants, the Office of the Superintendent of Financial Institutions (OSFI) and the Financial Consumer Agency of Canada (FCAC) published their findings concerning the use and adoption of artificial intelligence (AI) by federally regulated financial institutions. The report highlighted that a significant majority of financial institutions will adopt AI by 2026, and also set out a number of key risks that arise for financial institutions from AI usage. OSFI and FCAC emphasized the need for financial institutions to adopt a dynamic and responsive risk management system with respect to AI, and confirmed their commitment to work towards more specific best practices for industry participants.

The Ministry of Home Affairs introduced the Protection from Scams Bill for First Reading in Parliament on 11 November 2024. The Bill empowers the Police to issue Restriction Orders (ROs) to banks to restrict an individual’s banking transactions, if there is reasonable belief that the individual will make money transfers to scammers.

On 12 November 2024, the US Department of Justice Antitrust Division updated its Evaluation of Corporate Compliance Programs in Criminal Antitrust Investigations (ECCP). The additions include guidance such as using “managers at all levels” to “set the tone from the middle” by “demonstrating to employees the importance of compliance,” establishing policies that account for the use of “ephemeral messaging or non-company methods of communication,” applying “data analytics tools in . . . compliance and monitoring,” and involving compliance personnel in “the deployment of AI and other technologies to assess the risks they may pose.” Additionally, the ECCP now addresses its application to civil investigations.