Telecommunications concessions and authorization holders and other companies that own or use telecommunications or broadcasting infrastructure must provide certain information to the Federal Telecommunications Institute through the National Information and Infrastructure System (Sistema Nacional de Información e Infraestructura (SNII)). The obligation to report such information is effective as of January 2025. The SNII is a database that will contain information on active infrastructure and means of transmission, passive infrastructure, rights of way and public and private sites used by operators providing telecommunications or broadcasting services.
Since the coming into force of Malaysia Cyber Security Act 2024 (“CSA”) on 26 August 2024, there have been substantial developments in the landscape in the past few months.
The Malaysian Communications and Multimedia Commission (MCMC) has announced that it is holding a public consultation on the draft Code of Conduct (Best Practice) for Internet Messaging Service Providers and Social Media Service Providers (“Draft Code of Conduct”).
The objective of the public consultation is to collect public opinion on the Draft Code of Conduct, which outlines the best practices for applications service provider class licence holders who offer Internet messaging and social media services in Malaysia to address harmful online content and other relevant conduct requirements.
EU Regulation 2024/1689 on Artificial Intelligence has the aim to introduce strict rules for the design, implementation and placing on the market of Artificial Intelligence systems, to be applied both to suppliers established in European territory and to suppliers established outside the European Union.
On 24 October 2024, the Monetary Authority of Singapore (MAS) and Infocomm Media Development Authority of Singapore (IMDA) announced that the Shared Responsibility Framework (SRF) for phishing scams will be implemented on 16 December 2024 via a set of guidelines. Under the SRF, financial institutions (FIs) and telecommunication operators are assigned duties to mitigate phishing scams. The MAS and IMDA expect responsible entities to bear any scam losses arising from failure to fulfill any of the relevant duties under the “waterfall” approach.
The European Council adopted the new Product Liability Directive on 10 October 2024, and it is now awaiting publication in the Official Journal of the European Union. From its entry into force, member states will have two years to transpose it into their national law. The new directive derogates Directive 85/374/CEE. Considering the current context in which digitalization and business models based on sustainability and the circular economy are booming, it was crucial to carry out an update of the rules governing the civil liability of manufacturers and other operators of defective products.
In 2023, the Australian Government released the 2023-2030 Australian Cyber Security Strategy.
9 October 2024 marked the latest in a series of legislative reforms in pursuit of that strategy, as the Cyber Security Legislative Package 2024 (Package) was introduced to Parliament. The Package has been referred to the Parliamentary Joint Committee on Intelligence and Security for inquiry and report.
The first phase of the Government’s proposed implementation of long-anticipated reforms to the Privacy Act 1988 (Cth) (“Privacy Act”) was tabled in Parliament on 12 September 2024. The Privacy and Other Legislation Amendment Bill 2024 (“Bill”) comes two years after the Attorney-General Department’s report (“Review”) proposed 116 recommendations to reform the Privacy Act. The Government’s response to the Review, in September 2023 (“Response”), “agreed” 38 proposals to be implemented first and this Bill addresses 23 of those proposals.
As AI capabilities and applications continue to advance, the National Institute of Standards and Technology’s Artificial Intelligence Risk Management Framework has emerged as a vital tool for organizations to responsibly develop and use AI systems.
Various agencies led by the Department of Trade and Industry (DTI) have signed Joint Administrative Order No. 24-03, Series of 2024 containing the Implementing Rules and Regulations (IRR) of Republic Act No. 11967, or The Internet Transactions Act of 2023 (ITA).
The ITA is intended to regulate e-commerce, protect consumer rights and data privacy, and uphold intellectual property rights.
The IRR clarifies the scope and coverage of the ITA, the enforcement powers of the DTI vis-à-vis other agencies, and the applicable procedure for imposition of fines.