Mona Hariri Mona Hariri

EDPB Adopts Opinion on EU–Brazil Adequacy Decision, Recommending Clarifications on Transparency and Enforcement

The European Data Protection Board (EDPB) has issued its opinion on the European Commission’s draft adequacy decision for Brazil, marking a major step toward enabling free data flows between the EU and Brazil. The EDPB confirmed Brazil’s General Data Protection Law (LGPD) aligns closely with the EU GDPR but urged clarifications on Data Protection Impact Assessments, transparency limitations, onward transfers, and oversight of enforcement. Once adopted, the adequacy decision will simplify EU–Brazil data transfers and strengthen global cooperation in data protection and privacy compliance.

Read More
Mona Hariri Mona Hariri

Vietnam’s Data Privacy Evolution: Understanding Consent and Compliance Under the PDPD and Beyond

Vietnam’s Personal Data Protection Decree (PDPD) and forthcoming Personal Data Protection Law (PDPL) introduce stricter, GDPR-inspired data privacy rules. Businesses must now obtain clear, informed consent before processing personal data and comply with new security and cross-border transfer requirements. With enforcement led by the Ministry of Public Security, companies operating in Vietnam should update consent processes and privacy policies to meet the country’s fast-evolving data protection standards.

Read More
Mona Hariri Mona Hariri

AI Regulation is Here: What the Algorithmic Accountability Act of 2025 Means for Businesses, Compliance, and Risk Management

The Algorithmic Accountability Act of 2025 introduces sweeping federal oversight of AI and automated decision-making. Businesses using high-risk AI systems must conduct impact assessments, address bias, and ensure transparency. Learn how this landmark legislation could reshape compliance, data governance, and risk management in the AI era.

Read More
Mona Hariri Mona Hariri

California's SB 361: A Major Expansion of Data Broker Compliance Requirements

California’s SB 361 significantly enhances data broker regulations under the California Delete Act, introducing stricter consumer data deletion deadlines, expanded disclosure requirements, and mandatory audits starting in 2028. This law targets data sharing with foreign governments and AI developers, emphasizing transparency, consumer trust, and national security. Learn how to prepare for CPPA compliance today.

Read More
Mona Hariri Mona Hariri

EU General Court Upholds EU-U.S. Data Privacy Framework in Key Ruling

On September 3, 2025, the EU’s General Court upheld the validity of the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework, rejecting a legal challenge that questioned the independence of U.S. oversight mechanisms and the legality of bulk data collection practices. The ruling provides continued legal certainty for transatlantic data transfers, though a potential appeal to the Court of Justice of the EU could bring the framework back under review. This article explores the background of the case, the Court’s reasoning, and what it means for businesses relying on the framework.

Read More
Mona Hariri Mona Hariri

China's Major Tech Platforms Begin Labeling AI-Generated Content in Line with New Regulations

As China implements new regulations mandating the labeling of AI-generated content, major platforms like WeChat, Bilibili, and Xiaohongshu are rolling out tools to tag synthetic media. This article explores how these measures aim to enhance transparency, curb misinformation, and set a precedent for responsible AI governance. With implications for global tech policy and data privacy, China's approach offers valuable insights into the evolving relationship between AI, regulation, and public trust.

Read More
Mona Hariri Mona Hariri

The TAKE IT DOWN Act: A Federal Response to Non-Consensual Intimate Imagery and AI-Generated Deepfakes

Congress has passed the bipartisan TAKE IT DOWN Act, aimed at combating AI-generated and non-consensual intimate imagery online. While praised as a major step against digital sexual abuse, the law raises serious concerns about free speech, due process, and platform liability. It bypasses Section 230 by using FTC enforcement authority, placing sweeping obligations on platforms to remove content within 48 hours. Privacy advocates warn that it may incentivize surveillance and undermine encryption protections.

Read More
Mona Hariri Mona Hariri

Regulating Fake News and the First Amendment: Challenges, Section 230, and ISP Liability in the U.S

In today’s digital landscape “fake news” can go viral in minutes. While fake news is not a new phenomenon, what is new about it is the ease and speed at which it can be disseminated and spread to large audiences. The manufacturing of fake news causes a host of problems which stems from both a financial and ideological motivation. Most fake news is shared on social media platforms, such as Facebook, that fail to contain the spread of such misinformation, further exacerbating the problems discussed. While other countries have taken aggressive actions to stop the spread of fake news, the U.S. has been slow to embrace proactive regulatory measures as such regulation presents challenges. In addition to the public outcry on self-expression, lawmakers in the United States face a unique obstacle compared to other countries that have been able to pass aggressive laws: The First Amendment to the United States Constitution. Moreover, the enactment of Section 230 has been interpreted by the lower courts to provide a broad immunity that shields internet service providers, like Facebook, for defamatory fake news content posted on their sites. Therefore, this Article seeks to understand how and to what extent, if any, can fake news be regulated without violating the First Amendment.

Read More
Mona Hariri Mona Hariri

GDPR Real Seat Approach: How EU Data Privacy Law is Shaping Global Corporate Policies

Explore how the EU’s GDPR, through the real seat approach, is driving a “race to the top” in global corporate law and policies. This article examines GDPR’s extraterritorial impact, enforcement mechanisms, and influence on multinational companies, while highlighting the challenges and opportunities for global data privacy harmonization. Learn how GDPR compliance is transforming corporate practices across the U.S., Asia, South America, and beyond.

Read More
Mona Hariri Mona Hariri

U.S. Data Privacy Reform: Learning from GDPR to Create a Federal Privacy Law

Discover why the U.S. needs a comprehensive federal data privacy law and how the EU’s GDPR can serve as a global benchmark. This article examines the flaws of America’s patchwork privacy framework, the rising costs of non-compliance for U.S. companies, and actionable steps for harmonizing privacy regulations to protect consumers and ensure global competitiveness.

Read More