<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[GiladYaron.com]]></title><description><![CDATA[Data Protection Matters is a consulting firm specializing in data privacy, responsible AI & GRC.]]></description><link>https://www.data-protection-matters.com/insights</link><generator>RSS for Node</generator><lastBuildDate>Sat, 10 Oct 2026 22:23:41 GMT</lastBuildDate><atom:link href="https://www.giladyaron.com/blog-feed.xml" rel="self" type="application/rss+xml"/><item><title><![CDATA[Why Ethical AI Is an Engineering Problem, Not Just a Policy One]]></title><description><![CDATA[Ethical AI is not just about policy and regulation. It is fundamentally an engineering challenge. Learn why fairness, transparency, and security need to be treated with the same rigor as performance and reliability in the AI development lifecycle.]]></description><link>https://www.data-protection-matters.com/post/ethical-ai-engineering-problem</link><guid isPermaLink="false">69c92780f8d5a811544df1db</guid><category><![CDATA[AI & Govrenance]]></category><pubDate>Sun, 29 Mar 2026 15:07:13 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/dabbbb_b88e3161bc3c46b492b848c208e1ed50~mv2.png/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[Vietnam’s New Data Privacy Frontier: A Comprehensive Guide to Law No. 91/2025/QH15]]></title><description><![CDATA[Vietnam is no longer just a manufacturing alternative; it has officially emerged as a mature technology hub with a rigorous legal framework to match. As of January 1, 2026, the new Law on Personal Data Protection is in full effect, introducing GDPR-style mandates, mandatory DPIAs, and aggressive revenue-based fines. Is your organization ready for the 'Brussels Effect' in Southeast Asia?]]></description><link>https://www.data-protection-matters.com/post/vietnam-s-new-data-privacy-frontier-a-comprehensive-guide-to-law-no-91-2025-qh15</link><guid isPermaLink="false">69c50c161f04cf599d60f8cd</guid><category><![CDATA[Global Regulations]]></category><pubDate>Thu, 26 Mar 2026 10:56:05 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/dabbbb_f6ee47a95a1c41c2b4410de4a3cd6255~mv2.jpg/v1/fit/w_1000,h_559,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[Accountability in Motion: OpenAI Appeals and Age Assurance]]></title><description><![CDATA[This week features a major legal win for OpenAI as an Italian court canceled its €15 million fine, signaling a more mature phase in AI enforcement. Meanwhile, the UK ICO’s penalty against Reddit underscores that "self-declaration" for age checks is no longer sufficient; platforms must implement robust age assurance. Across Europe, a growing push for "joined-up" regulation highlights that privacy, AI, and competition laws must now be managed as a single strategic ecosystem.]]></description><link>https://www.data-protection-matters.com/post/ai-accountability-openai-age-assurance</link><guid isPermaLink="false">69c390ecdbf1d5b60130a9b4</guid><category><![CDATA[AI & Govrenance]]></category><category><![CDATA[Global Regulations]]></category><category><![CDATA[EU Data Strategy & GDPR]]></category><pubDate>Wed, 25 Mar 2026 07:59:30 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/dabbbb_fb89592540984a42a21e0b861a076007~mv2.jpg/v1/fit/w_1000,h_878,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[Guest Checkout: No Longer a Luxury, but a GDPR Requirement]]></title><description><![CDATA[The EDPB's new guidelines clarify that forcing users to create an account for one-time purchases often violates GDPR. Unless strictly necessary for the contract, guest checkout should be the default. Personalization and administrative convenience do not justify mandatory registration. This shift pushes retailers to adopt "privacy by design" by offering guest modes to ensure data minimization and respect user choice.]]></description><link>https://www.data-protection-matters.com/post/guest-checkout-gdpr-requirement</link><guid isPermaLink="false">6942b042609c61c19031d310</guid><category><![CDATA[EU Data Strategy & GDPR]]></category><pubDate>Wed, 17 Dec 2025 15:37:51 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/dabbbb_2361ad87989b417cb73ab949b8afc209~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[Simplifying the GDPR: The EU Digital Omnibus and EdTech Privacy]]></title><description><![CDATA[The EU’s new "Digital Omnibus" aims to simplify GDPR and AI laws by refining personal data definitions and streamlining consent. Simultaneously, the EU Court is re-evaluating the US-EU data flow agreement, creating potential residency risks for global firms. In the US, the FTC’s settlement with Illuminate Education over student data misuse underscores a shift toward aggressive enforcement in the EdTech sector, demanding stricter retention and security protocols for minors' data.]]></description><link>https://www.data-protection-matters.com/post/gdpr-digital-omnibus-edtech-privacy</link><guid isPermaLink="false">69315903a7a4d87bcf12775b</guid><category><![CDATA[Industry Spotlights]]></category><category><![CDATA[EU Data Strategy & GDPR]]></category><pubDate>Thu, 04 Dec 2025 10:18:30 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/dabbbb_05724f10121040d192ae088f5de25b38~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[Mandatory User Accounts: The EDPB Challenges Common E-commerce Practices]]></title><description><![CDATA[This week we review how regulation, innovation and risk continue to pull in opposite directions across global privacy. Europe is signalling a possible rollback of key digital rules, India is tightening data-collection obligations, and scrutiny over AI training-data practices is intensifying. Together these developments highlight the growing need for organisations to adapt quickly, refine governance, and prepare for regulatory shifts in both directions.
]]></description><link>https://www.data-protection-matters.com/post/mandatory-accounts-ecommerce-gdpr</link><guid isPermaLink="false">691f428e35662176f698eb9e</guid><category><![CDATA[Industry Spotlights]]></category><category><![CDATA[EU Data Strategy & GDPR]]></category><category><![CDATA[AI & Govrenance]]></category><pubDate>Thu, 20 Nov 2025 16:48:29 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/dabbbb_bfa530a201be4767be1b58afa5eb1adc~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[The Hidden Ecosystem: Why Tracking Pixels are Your Biggest Legal Liability]]></title><description><![CDATA[Tracking pixels are leaking sensitive data from thousands of sites to tech giants. Meta faces legal pressure as regulators highlight "joint-controller" liability for site owners using these tools. Consequently, many organizations are switching to privacy-preserving, first-party analytics to reduce risk and restore trust.]]></description><link>https://www.data-protection-matters.com/post/tracking-pixels-legal-liability-gdpr</link><guid isPermaLink="false">690ca80db34bcf14a8c9b63e</guid><category><![CDATA[Industry Spotlights]]></category><category><![CDATA[USA laws and regulations]]></category><pubDate>Fri, 07 Nov 2025 13:44:24 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/dabbbb_b2f613c06445456fbdbaafcc5a37396a~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[The Right to be Forgotten: California’s AB 886 and New GenAI Guidance]]></title><description><![CDATA[This week highlights California’s new AB 886 law, forcing platforms to erase user data upon account deletion. Meanwhile, the EDPS issued guidance on Generative AI, stressing that GDPR principles like transparency and lawful basis apply fully to AI training and outputs. Lastly, a shift in cyber threats is noted: "silent breaches" involve long-term infiltration and slow data siphoning, requiring organizations to pivot from perimeter defense to proactive anomaly detection.]]></description><link>https://www.data-protection-matters.com/post/california-deletion-rights-genai-guidance</link><guid isPermaLink="false">6902fef6ee35ef3cde78bd96</guid><category><![CDATA[EU Data Strategy & GDPR]]></category><category><![CDATA[Cyber & Data Privay]]></category><category><![CDATA[USA laws and regulations]]></category><pubDate>Thu, 30 Oct 2025 06:24:43 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/dabbbb_db5f715212844f7ebe15c2d4b9d74d29~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[Cross-Regulatory Synergy: The Digital Clearinghouse and Ethical AI in Hiring]]></title><description><![CDATA[This week's insights cover major shifts in data governance: the EU's move toward cross-regulatory coordination (Digital Clearinghouse 2.0), the launch of responsible AI standards for the education sector (K-20 collaboration), and a shift toward ethical AI in hiring. The key takeaway is that privacy and AI governance must be context-specific, requiring organizations to unify oversight across legal frameworks to protect consumers and students effectively.]]></description><link>https://www.data-protection-matters.com/post/digital-clearinghouse-ethical-ai-hiring</link><guid isPermaLink="false">68fa1424bede580f013a68af</guid><category><![CDATA[Industry Spotlights]]></category><category><![CDATA[Global Regulations]]></category><category><![CDATA[AI & Govrenance]]></category><category><![CDATA[EU Data Strategy & GDPR]]></category><pubDate>Thu, 23 Oct 2025 11:46:31 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/dabbbb_872f8db6953b406880c8beada508bd0b~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[Bridging the CISO-DPO Divide: Uniting Cybersecurity and Data Privacy]]></title><description><![CDATA[Tired of CISO-DPO friction? Learn how to transform cybersecurity and data privacy into a powerful, unified force for stronger data protection]]></description><link>https://www.data-protection-matters.com/post/bridging-the-ciso-dpo-divide-uniting-cybersecurity-and-data-privacy</link><guid isPermaLink="false">68596f9391bd73bf18514460</guid><category><![CDATA[Frameworks & Governance]]></category><category><![CDATA[EU Data Strategy & GDPR]]></category><category><![CDATA[USA laws and regulations]]></category><category><![CDATA[Global Regulations]]></category><pubDate>Mon, 23 Jun 2025 16:02:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/dabbbb_38310161fbcc42c2bfbd784be0b5a2f7~mv2.jpeg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[Navigating the Data Maze: Understanding Processor, Controller, and Joint Controller Roles is Key to Your Data Strategy]]></title><description><![CDATA[Understanding who holds responsibility for personal data is a legal necessity under GDPR. The Data Controller decides the "why" and "how" of processing, while the Data Processor acts only on the controller's instructions. In some cases, Joint Controllers share decision-making. Clearly defining these roles in a Data Processing Agreement (DPA) is crucial for legal compliance, allocating liability in case of breaches, and building trust with customers and partners.]]></description><link>https://www.data-protection-matters.com/post/data-controller-processor-joint-controller-gdpr</link><guid isPermaLink="false">68514c2e0daa1dfa62fb9481</guid><category><![CDATA[Frameworks & Governance]]></category><category><![CDATA[EU Data Strategy & GDPR]]></category><category><![CDATA[Global Regulations]]></category><category><![CDATA[USA laws and regulations]]></category><pubDate>Tue, 17 Jun 2025 11:17:36 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/273ef37c314b46bb9220b77cfd5769c9.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[Consent in the Digital Age: A Case Study of Meta’s “Consent or Pay” Tactic]]></title><description><![CDATA[The Essence of Consent Consent is a fundamental concept in data privacy, serving as the linchpin that aligns personal autonomy with technological advancement. It is the mechanism through which individuals exercise control over their personal information, granting or withholding permission for organizations to collect, process, and share their data. Autonomy and Informed Decision-Making  At its core, consent is about autonomy - ensuring that individuals have the power to make informed...]]></description><link>https://www.data-protection-matters.com/post/consent-in-the-digital-age-a-case-study-of-meta-s-consent-or-pay-tactic</link><guid isPermaLink="false">66067e049212c748d3c0dbc1</guid><category><![CDATA[Global Regulations]]></category><category><![CDATA[Frameworks & Governance]]></category><pubDate>Fri, 29 Mar 2024 08:40:33 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/11062b_91f2b978655241808bac54f081844ef1~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[Navigating the Complexities of Data Processing Agreementsthe Complexities of Data Processing Agreements]]></title><description><![CDATA[The Essence of DPAs Data Processing Agreements (DPAs) are the bedrock of trust and compliance in the digital ecosystem, where personal data flows between various stakeholders. These agreements are not mere documents but are foundational to establishing a clear, structured, and legally binding relationship between data controllers and data processors. The Philosophical Underpinnings of DPAs The essence of DPAs lies in their ability to translate the abstract principles of privacy and data...]]></description><link>https://www.data-protection-matters.com/post/data-processing-agreements-gdpr-guide</link><guid isPermaLink="false">660681cc305b699705f77057</guid><category><![CDATA[EU Data Strategy & GDPR]]></category><pubDate>Sun, 17 Mar 2024 22:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/11062b_d3318dd21f604338bda270908a0d9d77~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[The evolving role in the world of privacy protection: a symphony for the rights of data subjects]]></title><description><![CDATA[The world of data protection has evolved beyond a solitary endeavor. Enter Data Privacy Operations (DPOps), a harmonious assembly playing an endless symphony for the rights of data subjects. The growth of this entity is driven by:  The complex nature of privacy protection, requiring a blend of legal insight, technological innovation, and real-world applicability.  Privacy laws demand the oversight and management of vast amounts of information. Efficient, centralized information management...]]></description><link>https://www.data-protection-matters.com/post/the-evolving-role-in-the-world-of-privacy-protection-a-symphony-for-the-rights-of-data-subjects</link><guid isPermaLink="false">65ee1d7e38d768fa05358dcd</guid><pubDate>Sun, 10 Mar 2024 20:54:15 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/11062b_ecf8ff066a5346cd91f68ebc0fa283d4~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[An In-Depth Look at China Data Protection Act (PIPL) and Its Comparison with GDPR]]></title><description><![CDATA[China’s PIPL sets stringent rules for collecting and processing personal data, drawing many parallels to the GDPR. It grants individuals rights to access, correct, and delete data while imposing heavy fines for violations. Key differences include PIPL's specific focus on businesses within China and its unique consent requirements. This landmark law significantly impacts how global companies manage information, requiring strict adherence to principles like data minimization and security.]]></description><link>https://www.data-protection-matters.com/post/an-in-depth-look-at-china-data-protection-act-pipl-and-its-comparison-with-gdpr</link><guid isPermaLink="false">66068b15ec524d41d5bd90f8</guid><category><![CDATA[Global Regulations]]></category><category><![CDATA[Frameworks & Governance]]></category><pubDate>Mon, 01 Jan 2024 22:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/11062b_2cc11ab6f649437c91e7e88543a4f6d6~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[Guidelines for Ensuring Privacy of Health-Related Data]]></title><description><![CDATA[The Council of Europe’s Recommendation CM/Rec(2019) provides a framework for protecting sensitive health data in the digital age. It emphasizes key principles: transparency, lawfulness, and fairness in data processing. Organizations must obtain explicit consent, implement "privacy by design," and ensure robust security measures. These guidelines balance the need for medical research with the fundamental right to individual privacy, ensuring public trust in healthcare technologies.]]></description><link>https://www.data-protection-matters.com/post/guidelines-for-ensuring-privacy-of-health-related-data</link><guid isPermaLink="false">660690311fd90d8ffdc1ac8a</guid><category><![CDATA[EU Data Strategy & GDPR]]></category><category><![CDATA[Frameworks & Governance]]></category><pubDate>Wed, 27 Dec 2023 22:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/11062b_f61e194a105a40d4a84c9ca71085daea~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[Elevating Security Standards: Embracing the Transition to ISO 27001:2022]]></title><description><![CDATA[ISO 27001:2022 updates the global standard for information security management. Key changes include a more risk-based approach, simplified control themes (Organizational, People, Physical, Technological), and 11 new controls like threat intelligence and cloud security. This version offers greater flexibility and addresses modern cyber threats. Transitioning helps organizations strengthen their security posture, ensure continuous improvement, and protect sensitive data in an evolving landscape.]]></description><link>https://www.data-protection-matters.com/post/elevating-security-standards-embracing-the-transition-to-iso-27001-2022</link><guid isPermaLink="false">66069c9ec72df65437fcec97</guid><category><![CDATA[Frameworks & Governance]]></category><category><![CDATA[Cyber & Data Privay]]></category><pubDate>Sat, 02 Dec 2023 22:00:00 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/bb903024e9384ce683f9815b2a7cc503.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[An In-Depth Look at South Africa's Protection of Personal Information Act (POPIA) and Its Comparison]]></title><description><![CDATA[South Africa’s POPIA regulates personal data processing with strict conditions on consent, security, and accuracy. While sharing core principles with GDPR, it has unique jurisdictional rules, different breach reporting timelines, and criminal penalties including imprisonment. Organizations must ensure compliance with eight key conditions, such as purpose limitation and data minimization, to avoid heavy fines and ensure lawful cross-border data transfers.]]></description><link>https://www.data-protection-matters.com/post/an-in-depth-look-at-south-africa-s-protection-of-personal-information-act-popia-and-its-comparison</link><guid isPermaLink="false">64650b180a0ec2db0595b45c</guid><category><![CDATA[Global Regulations]]></category><category><![CDATA[Frameworks & Governance]]></category><pubDate>Wed, 17 May 2023 17:23:16 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/11062b_8425cc71fa1549f08bedb7413938298f~mv2.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[The Importance of Responsible Use: An Overview of the Proposed AI Act]]></title><description><![CDATA[the proposed AI Act and the importance of responsible use of AI, including protecting privacy and aligning AI with human values and rights]]></description><link>https://www.data-protection-matters.com/post/the-importance-of-responsible-use-an-overview-of-the-proposed-ai-act</link><guid isPermaLink="false">643b849a18b1fc7959d05eac</guid><category><![CDATA[AI & Govrenance]]></category><pubDate>Sun, 16 Apr 2023 05:17:44 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/4fa872fd75d046b8a227a5202176ab14.jpg/v1/fit/w_1000,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item><item><title><![CDATA[EU-USA Collaboration on Encryption, and Radicalization: A Step towards Greater Security?]]></title><description><![CDATA[In a recent meeting held in Stockholm on March 16-17, 2023, senior officials from the European Union and the United States discussed the  Enhanced Border Security Partnership (EBSP)  and the potential sharing of biometric data between the two entities. The parties aim to initiate a "proof of concept" by transferring the first set of data, with hopes of improving security and border control. While the partnership may seem like a positive step towards enhanced security, concerns have been...]]></description><link>https://www.data-protection-matters.com/post/eu-usa-collaboration-on-encryption-and-radicalization-a-step-towards-greater-security</link><guid isPermaLink="false">64379ef5ab0c01ba57b50d30</guid><category><![CDATA[EU Data Strategy & GDPR]]></category><category><![CDATA[USA laws and regulations]]></category><pubDate>Thu, 13 Apr 2023 06:33:37 GMT</pubDate><enclosure url="https://static.wixstatic.com/media/dabbbb_18cab351c4f9424dac878a04d0deac32~mv2.jpg/v1/fit/w_768,h_1000,al_c,q_80/file.png" length="0" type="image/png"/><dc:creator>Gilad Yaron</dc:creator></item></channel></rss>