Tag
This paper proposes CallosumNet, a biologically inspired framework for efficient unlearning in spatio-temporal graphs to comply with privacy regulations like GDPR, achieving complete unlearning with minimal accuracy loss.
The article explores the challenges of updating personal identity information in git commit histories due to life events and proposes using ATProto to manage distributed identity for better privacy and compliance.
Chinese open-weight AI models like Qwen and DeepSeek are gaining traction in Europe, particularly by companies such as Siemens, to bypass GDPR data transfer issues by self-hosting, offering an alternative to proprietary foreign APIs.
A systematic review of XAI research in the context of the EU Right to Explanation, analyzing gaps between legal requirements and technical implementations across GDPR and the AI Act.
The author argues that AI agent recall is largely solved but permission/authorization over retrieved memories is the missing layer, introducing Provem, an open-source governance layer between agents and memory stores with benchmarks showing it eliminates compliance violations.
Animam is a multi-tenant AI agent platform that lets agencies deploy personalized AI agents for clients via widget, API, voice, and MCP. The builder seeks feedback on its infrastructure approach from production users.
A travel agent's AI chatbot violated GDPR regulations without any user prompt, raising concerns about data protection compliance in AI applications.
Analysis of LLM usage in legal and compliance tasks reveals that models often produce confident but unverifiable citations, raising questions about reliable legal grounding for AI outputs.
A privacy advocate's complaint about Elkjop's forced consent for marketing led to a €1.8 million fine after five years, highlighting GDPR violations.
Google's AI strategy is criticized as a surveillance-based profiling engine that forces users into consent through mandatory login, circumventing GDPR. The article exposes Google's plan to replace traditional search with AI-generated answers and personalized tracking, calling it a legal loophole wrapped in AI hype.
The author built a Claude skill for automated PII detection during development, translating existing compliance knowledge into a tool that checks for regulations like CCPA and HIPAA. They plan to release more compliance-focused skills in the near future.
A Dutch suicide prevention hotline was found to share sensitive visitor metadata with Google and Microsoft without proper consent, leading to the suspension of tracking tools and potential GDPR violations.
The author details their personal migration of digital infrastructure to European and Swiss-based services like Proton and Matomo to enhance data sovereignty and privacy.
A researcher discovered that deleteduser.com was being used as a placeholder domain by multiple companies to overwrite user email addresses during data deletion compliance, and after acquiring the domain, received PII from 30+ organizations including gyms, hotels, energy companies, and cybersecurity firms.
OpenAI announces data residency capabilities in Europe for ChatGPT Enterprise, ChatGPT Edu, and API Platform, enabling organizations to store customer data at rest in-region and meet local data sovereignty and GDPR compliance requirements.