This website uses cookies

Read our Privacy policy and Terms of use for more information.

🎙️ Episode 34 is live — ~8 min

China's Data Clock Starts, Two Regimes Loom. One obligation switched on this week and two more came into view.

In this episode

  • China Order No. 24 in force today. Handlers of "important data" owe a documented annual risk assessment, filed with their sector regulator within 20 working days and retained 3 years. CAC Order No. 24

  • EU Cyber Resilience Act Article 14 reporting begins 11 September. Actively exploited vulnerabilities and severe incidents reported via ENISA's Single Reporting Platform: 24h early warning, 72h full notification, 14-day final report. EC CRA reporting

  • South Korea PIPA overhaul takes effect 11 September. A punitive fine track reaching 10% of total annual turnover; the business owner/representative named ultimately responsible; board approval and PIPC reporting for CPO appointments at large-scale controllers. PIPC (Korea)

  • California's first data-broker fines under both the CCPA and the Delete Act. LocateSmarter — $116,490; Cybba — $52,400. CalPrivacy

  • AB 1651 on California's Governor's desk. The 12-day gubernatorial clock expires on or about 22 August; from 1 January 2028 it would require the State Bar to disclose AI-generated content in the bar exam — and human revision does not extinguish the duty.

Also this week: France's Conseil constitutionnel struck down the operative under-15 social-media ban (14 August); the CFTC proposed easing fund-adviser registration; the UK PSR Confirmation of Payee consultation closes today; the US stablecoin-issuer CIP proposed rule closes 21 August.

Full brief and every source in the CyberEyeQ newsletter.