
Indian Man Arrested for AI Deepfake Images of Ex-Girlfriend
Man arrested in Assam, India for using AI tools to create explicit deepfake images of his ex-girlfriend and selling access online. Indian deepfake laws explained.
Loading...
119 articles · page 2 of 2

Man arrested in Assam, India for using AI tools to create explicit deepfake images of his ex-girlfriend and selling access online. Indian deepfake laws explained.

Indonesia's Personal Data Protection Law (UU PDP, Law 27/2022) is fully in force since October 2024. Guide covers supervisory authority status, data subject rights, breach notification, cross-border transfers, criminal and administrative penalties, and compliance steps.

Indonesia's UU PDP is fully in force, but its supervisory authority and PP regulation are not yet built. GDPR comparison, penalties, breach rules.

Ireland's DPC enforces GDPR for Meta, Google, TikTok and more. Learn about the Data Protection Act 2018, record fines exceeding 4 billion euros, the three commissioners, AI Act obligations, cross-border transfer rules, and your rights.

Complete guide to Israel data privacy laws. Covers the Protection of Privacy Law 1981, Amendment 13 (effective August 14, 2025), PPA enforcement, EU adequacy renewal, DPO requirements, and compliance.

Italy enforces data privacy through the GDPR, the Privacy Code (D.Lgs. 196/2003), and the Garante. Covers Law 132/2025 AI law, criminal penalties, Enel EUR 79M fine, and 2025-2026 enforcement.

Complete guide to Jamaica's Data Protection Act 2020 -- the OIC, eight data protection standards, phased commencement, registration, data subject rights, breach notification, cross-border transfers, and penalties.

How Japan's APPI differs from GDPR: the Article 27 opt-out transfer regime, pseudonymization tiers, EU/UK Supplementary Rules, and the 2026 reform.

Japan's APPI governs personal data with mandatory breach reporting, cross-border transfer rules, and EU mutual adequacy. The January 2026 PPC reform policy introduces administrative fines for the first time, with implementation expected by 2028.

Kenya enforces data privacy through the Data Protection Act 2019 and the ODPC. Learn about the registration regime, data subject rights, 72-hour breach notification, cross-border transfer rules, and ODPC enforcement actions including KES 26M+ in fines through 2024.

Latvia data privacy laws explained: GDPR + Personal Data Processing Law, DVI enforcement (EUR 1.2M TET fine upheld 2024, EUR 300K ZZ Dats fine 2025), EU AI Act overlay, criminal penalties, and compliance steps.

Complete guide to Liechtenstein data protection: GDPR via EEA, the 2018 Data Protection Act (DSG), Datenschutzstelle enforcement, DPO rules, financial sector compliance, blockchain, AI Act, and 2024–2026 updates.

Lithuania implements GDPR through its 2018 Law on Legal Protection of Personal Data. Learn about the VDAI, the EUR 2.4M Vinted fine, constitutional basis, data subject rights, DPO requirements, cross-border transfers, the EU AI Act overlay, and 2024-2025 enforcement trends.

Luxembourg data privacy laws explained: GDPR implementation, Law of 1 August 2018, CNPD enforcement powers, the EUR 746M Amazon fine and its annulment on appeal, EU AI Act, financial sector rules, and 2024-2026 developments.

Malaysia enforces data privacy through the PDPA 2010 (Act 709) and its 2024 amendments. Learn about JPDP enforcement, 7 data protection principles, breach notification, and penalties up to RM 1 million.

How Malaysia's PDPA differs from the GDPR: the government exemption, narrower scope, the 2024 Amendment Act, and penalties through 2025.

Malta data privacy laws: GDPR, Cap. 586, and IDPC enforcement. Covers the age-13 digital consent rule, iGaming sector compliance, EU AI Act designation, and cross-border transfer rules.

Mexico replaced its 2010 data privacy law in March 2025. New LFPDPPP, INAI dissolved, SABG enforces. ARCO rights, penalties up to MXN 37.5M, AI provisions explained.

Morocco data protection under Law 09-08: CNDP registration rules, constitutional basis, legal bases, data subject rights, cross-border transfers, penalties, and 2025-2026 developments.

Complete guide to Netherlands data privacy laws: GDPR, UAVG, Autoriteit Persoonsgegevens enforcement, Clearview AI EUR 30.5M fine, EU AI Act, breach rules, DPO requirements, and 2024-2026 developments.

New Zealand Privacy Act 2020: 13 IPPs, IPP 3A indirect-collection rule (May 2026), Biometric Code 2025, breach notification, IPP 12 cross-border transfer, and enforcement powers.

Complete guide to Nigeria data privacy laws: the NDPA 2023, GAID 2025, NDPC enforcement, DCPMI registration, data subject rights, breach notification, penalties up to 2% annual revenue.

Norway applies the full GDPR through the EEA Agreement. The Personal Data Act 2018 supplements it with national rules. Datatilsynet enforces with fines up to EUR 20 million. Updated 2026.

Pakistan has no enacted data protection law as of 2026. PECA 2016 (amended January 2025) and sector rules apply. Full guide to the pending Personal Data Protection Bill.

Panama's Law 81 of 2019 and Executive Decree 285 of 2021 govern personal data protection. Learn about ANTAI oversight, ARCO rights, consent rules, cross-border transfers, sectoral rules, penalties, and 2025 updates.

Peru data privacy law explained: Law 29733, DS 016-2024-JUS (March 2025), DPO requirements, 48-hour breach notification, ARCO-PD rights, penalties up to 100 UIT. Updated May 2026.

Complete guide to Philippine data privacy law under the Data Privacy Act of 2012 (RA 10173). Covers constitutional basis, NPC enforcement, administrative fines, data subject rights, breach notification, cross-border transfers, DPO requirements, and 2024-2026 NPC developments.

How the Philippines' Data Privacy Act differs from GDPR: criminal imprisonment for 8 offenses, mandatory NPC registration, and BPO extraterritorial reach.

Complete guide to Poland data privacy laws: EU GDPR, the Polish Personal Data Protection Act 2018, UODO enforcement record, constitutional basis, penalties, breach notification, and 2024-2026 developments.

Portugal data privacy law explained: GDPR implementation via Lei 58/2019, the CNPD supervisory authority, constitutional basis in Article 35, the 2019 deliberation disapplying national provisions, penalties up to €20M, and 2024–2026 enforcement.

Complete guide to Qatar data privacy laws: Law No. 13 of 2016 (PDPPL), the NCSA/CDP supervisory authority, the QFC Data Protection Regulations 2021, data subject rights, breach notification, cross-border transfers, and penalties up to QAR 5 million.

Complete guide to Romania data privacy laws: GDPR implementation via Law 190/2018, ANSPDCP enforcement, public authority fine caps, employee monitoring rules, biometric data restrictions, EU AI Act overlap, and 2024–2025 enforcement actions.

Complete guide to Russia's data privacy laws: Federal Law 152-FZ, Roskomnadzor enforcement, data localization (242-FZ), the 2025 fine increases under 420-FZ (up to 500M rubles), new criminal liability under 421-FZ (up to 10 years), breach notification, and SORM surveillance.

Complete guide to Saudi Arabia's Personal Data Protection Law (PDPL), Royal Decrees M/19 and M/148, SDAIA enforcement, data subject rights, breach notification, penalties up to SAR 5M, cross-border transfer rules, and 2025–2026 regulatory updates.

How Saudi Arabia's PDPL Data Transfer Regulation governs outbound data: the localization myth, SCCs, risk assessments, and penalties.

Compare Saudi Arabia's PDPL to the GDPR: controller registration, the missing adequacy list, rights gaps, and criminal penalties.

Singapore PDPA: the 11 data protection obligations, mandatory DPO, breach notification, penalties up to 10% of turnover, and data portability status in 2026.

Slovakia enforces data privacy through GDPR and Act No. 18/2018, overseen by the UOOU. Learn about birth number protections, enforcement, the EU AI Act overlay, and NIS2 compliance.

Slovenia was the last EU member state to adopt a GDPR implementing law. Learn how ZVOP-2 (in force January 2023), the Information Commissioner, Article 38 constitutional protection, biometric restrictions, processing logs, and the EU AI Act shape compliance in Slovenia.

South Africa's POPIA vs the GDPR: correct commencement dates, the eight conditions, juristic person coverage, and real 2026 Information Regulator enforcement.

South Korea's PIPA is among the world's strictest data privacy laws. Learn about the March 2026 amendment, 10% turnover penalties, CEO accountability, PIPC enforcement, data subject rights, and cross-border transfer rules.

Compare South Korea's PIPA and the EU GDPR on criminal penalties, RRN rules, PIPC transfer-suspension power, and the 2026 penalty ceiling change.

Spain enforces data privacy through the GDPR, the LOPDGDD (Organic Law 3/2018), and the highly active AEPD. Covers digital rights, AESIA/AI Act, biometric enforcement, penalties up to 20M euros, and 2025-2026 developments.

Complete guide to Sri Lanka data privacy laws. Covers the PDPA No. 9 of 2022, Amendment Act No. 22 of 2025, the Data Protection Authority, enforcement timeline, data subject rights, penalties, and cross-border transfers.
Complete guide to EU Standard Contractual Clauses: the 2021 modular SCCs, Transfer Impact Assessments, supplementary measures, the pending Article 3(2) SCCs, UK IDTA, and 2024-2026 enforcement.

Sweden enforces GDPR through the Data Protection Act (2018:218) and IMY. Covers constitutional exemptions, offentlighetsprincipen, enforcement cases, penalties, AI Act overlay, and compliance requirements.

Complete guide to Switzerland's revised Federal Act on Data Protection (nFADP/revDSG), in force September 1, 2023. Covers FDPIC enforcement, CHF 250,000 individual criminal penalties, cross-border transfers, Swiss-US DPF, and 2025-2026 developments.

Taiwan PDPA guide: the November 2025 amendments establish the Personal Data Protection Commission (PDPC), mandatory breach notification, strengthened fines, and new DPO requirements.

Tanzania's Personal Data Protection Act 2022 is now actively enforced. Full guide: PDPC, data subject rights, DPO requirements, Zanzibar rules, penalties up to TZS 5 billion, and compliance steps.

Thailand's PDPA governs personal data collection, use, and transfer. Updated 2026 guide: PDPC enforcement record, the 2024 first fine and 2025 wave, the Emergency Decree on Technology Crimes, BCR framework, data subject rights, DPO requirements, and penalties.

Complete guide to Tunisia data protection law: Organic Law 2004-63, the INPDP authority, registration and authorization rules, Convention 108+, cross-border transfers, penalties, and the 2025 GDPR-alignment reform bill.

Turkey's KVKK (Law No. 6698) governs personal data protection. Law No. 7499 (June 2024) overhauled cross-border transfers and special-category rules. Learn about SCCs, adequacy decisions, VERBIS, 2026 fines up to 17M TRY, and KVKK Board enforcement.

Complete guide to UAE data privacy laws: federal PDPL (Decree-Law 45/2021), DIFC Data Protection Law 2020, ADGM Regulations 2021, penalties, cross-border transfers, and 2025-2026 developments.

The UAE has three data protection regimes, not one. Compare GDPR against the federal PDPL, DIFC law, and ADGM Regulations side by side.

Complete 2026 guide to UK data privacy laws: UK GDPR, Data Protection Act 2018, the Data Use and Access Act 2025 (DUAA) reforms, ICO enforcement, EU adequacy renewed to 2031, and PECR cookie changes.

Complete guide to Ukraine's data privacy laws: the 2010 Law on Personal Data Protection, the Ombudsperson as supervisory authority, Draft Law 8153 and its GDPR-alignment status, EU accession obligations, cross-border transfer rules, martial-law context, and penalties.

Complete guide to Uruguay data privacy laws: Law 18.331, Decree 414/009, DPO rules, 72-hour breach notification, EU adequacy reaffirmed 2024, Convention 108+, and URCDP enforcement.

Complete guide to Vietnam data privacy laws. Covers Law No. 91/2025/QH15 (effective January 1, 2026), Decree 356, cross-border transfers, data subject rights, and penalties.

GDPR is the EU data protection law. Learn the 7 principles, your data subject rights, who must comply, and fines up to EUR 20M or 4% of global turnover.