Data Privacy News

The Formiti Privacy News Blog delivers the latest insights, expert advice, and practical tips on global data protection laws and privacy trends. From GDPR to PDPA, we make complex regulations clear, helping you protect data, stay compliant, and build trust.


 

at a time


A Global Organization's Guide to Washington's My Health My Data Act (MHMDA)

Washington's My Health My Data Act (MHMDA) is a stringent new privacy law with global reach, impacting any organization that targets Washington consumers. The article provides a st...  more  

The Tri-Region Playbook: A Comparative Guide to UAE, Saudi & Egyptian Data Laws

This article provides a strategic comparison of the data protection laws in the UAE, Saudi Arabia (KSA), and Egypt for global organizations. It highlights that the UAE's law is fle...  more  

Navigating the 2025 US State Privacy Law Landscape: A 2025 Progress Report and 2026

2025 marked a critical turning point for US data privacy, as new comprehensive laws in Delaware, New Jersey, Iowa, New Hampshire, and Nebraska took effect. This article from Formit...  more  

A Guide to US Data Protection Impact Assessments (DPIAs) for Global Organizations

The article guides global organizations through the complex "patchwork" of US state data privacy laws, which, unlike the EU's GDPR, lack a single federal standard. It focuses on th...  more  

Understanding the 9 APEC Privacy Framework Principles

This article provides a comprehensive guide for global organisations on the Asia-Pacific Economic Cooperation (APEC) Privacy Framework. It explains the crucial difference between t...  more  

A Guide to the APEC Privacy Framework: Enabling Cross-Border Data Flows

The article explains the APEC Privacy Framework, a critical, principles-based system for global organizations doing business in the Asia-Pacific region. Unlike the mandatory GDPR, ...  more  

The New Imperative: Why Robust Vendor Assessments Are Critical for Data Protection

This article explains why robust vendor assessments are critical for data protection, stating that a breach from a third party is a direct reflection—and liability—for your busines...  more  

What the Data (Use and Access) Act 2025 Means for Your Legitimate Interest Assessments

The Data (Use and Access) Act 2025 (DUAA) significantly amends the UK GDPR by creating a new, two-tiered system for legitimate interests. The main change is the introduction of ...  more  

Do i need to complete a (DPIA) when using Microsoft Copilot or Google Gemini

Deploying generative AI like Microsoft Copilot or Google Gemini is a top priority for most organisations, but it comes with a critical compliance hurdle. Before you roll out these ...  more  

How the EU-US Data Privacy Framework Impacts Data Mapping and Vendor Risk

DPF Decoded: Impact on Data Mapping & Vendor Risk The EU-US Data Privacy Framework (DPF) creates a new path for legally transferring personal data from the EU to certified US or...  more