Announcing Agent Commander - The First Integrated solution from Veeam + Securiti.ai enabling the scaling of safe AI agents

View

Privacy Regulation Roundup: Top Stories of July 2026

Watch: July's Privacy Pulse - All Major Highlights

A quick overview of global privacy headlines you cannot afford to miss.

Play Video
Contributors

Yasir Nawaz

Digital Content Producer at Securiti

Rohma Fatima Qayyum

Associate Data Privacy Analyst at Securiti

Faqiha Amjad

Associate Data Privacy Analyst at Securiti

Aamina Shekha

Associate Data Privacy Analyst at Securiti

Published August 12, 2026

Editorial

From Policy to Execution: Privacy's New Enforcement Era

If July’s global regulatory updates tell us anything, it is that the era of relying on polished privacy policies and surface-level controls is officially over. Regulators around the world are no longer taking written promises at face value. They are digging directly into the underlying technical machinery. From cracking down on vague security excuses that stall consumer record requests to fining automated platform moderation that lets systemic harms slide, authorities are actively penalizing the gap between what companies say and what their systems actually do. With age-assurance standards tightening, supply-chain accountability expanding, and cross-border transfer frameworks facing renewed legal scrutiny, the message is unmissable: static compliance playbooks won’t cut it anymore. Moving forward, privacy must be engineered directly into your operational architecture, or regulators will hold you accountable for the disconnect.

North & South America Jurisdiction

1. FTC and State Regulators Sue Hims & Hers Over Health Privacy and Subscription Practices

July 29, 2026
United States

The U.S. Federal Trade Commission (FTC), together with California and Utah, filed a lawsuit against telehealth provider Hims & Hers, alleging that the company shared consumers' sensitive health information with third-party advertising platforms, including Meta and Snap, despite representing that it would protect patient privacy. The complaint also alleges deceptive billing and subscription practices, including charging consumers before consultations, enrolling them in recurring subscriptions without clear consent, and making cancellations unnecessarily difficult.

This is significant because the action reinforces regulatory scrutiny of health data practices, online tracking technologies, and subscription models. Organizations handling sensitive personal information should ensure privacy notices accurately reflect data sharing practices, obtain appropriate consent where required, and maintain transparent billing and cancellation processes..

Read More

2. New York Finalizes SAFE for Kids Act Rules for Social Media Platforms

July 28, 2026
New York, United States

New York Attorney General Letitia James released the final implementing rules for the SAFE for Kids Act, setting out how social media platforms must comply with restrictions on algorithmically personalized feeds and nighttime notifications for users under 18. The rules establish age-assurance and parental-consent requirements, mandate privacy-preserving age-verification methods, and prohibit the use of age-verification data for other purposes. The SAFE for Kids Act will take effect on January 25, 2027.

This is significant because the rules provide one of the most comprehensive state-level frameworks governing youth online safety, requiring platforms to balance child protection with privacy-preserving age assurance and to strengthen accountability for addictive platform design.

Read More

3. California Privacy Protection Agency Launches First Sectoral Privacy Audit

July 21, 2026
California, United States

The California Privacy Protection Agency (CPPA) launched its first formal sector-wide privacy audit, focusing on gig economy platforms operating in California. The audit will assess compliance with the California Consumer Privacy Act (CCPA), particularly whether workers and consumers can effectively exercise their right to access personal information, including data used by algorithmic systems to make decisions affecting earnings, performance, and account status.

This is significant because it marks the CPPA's first proactive audit initiative, signaling increased enforcement through sector-specific reviews and heightened scrutiny of how organizations operationalize privacy rights in practice, particularly where automated decision-making affects individuals.

Read More

4. Multistate Settlement Requires 23andMe to Strengthen Genetic Data Security

July 14, 2026
United States

New York Attorney General Letitia James and a bipartisan coalition of 42 other attorneys general secured an $18 million settlement with 23andMe over its 2023 data breach, which exposed the sensitive genetic information of approximately 6.9 million customers. The settlement requires enhanced security measures, including stronger cybersecurity controls, governance enhancements, ongoing consumer deletion rights, and improved protection of genetic data under the company's successor entity.

This is significant because it reinforces regulators' expectations that organizations processing highly sensitive personal data implement robust cybersecurity safeguards and maintain appropriate governance to protect individuals from data breaches and misuse.

Read More

5. Mexico Fines Football Federation for FAN ID Biometric Privacy Violations

July 12, 2026
Mexico

Mexico's Secretariat for Anti-Corruption and Good Governance fined the Mexican Football Federation (FMF) 42.8 million pesos for violating personal data protection laws related to its FAN ID system. The authority found that the FMF failed to identify biometric data as sensitive personal data in its privacy notice and did not obtain valid express written consent for its processing, as required under Mexican law.

This is significant because it reinforces the heightened regulatory expectations for organizations processing biometric data, highlighting the importance of transparent privacy notices, proper classification of sensitive personal data, and obtaining valid consent before processing.

Read More

6. FTC Settles with Amazon Over Identity Theft Records Violations

July 1, 2026
United States

The U.S. Federal Trade Commission (FTC) secured a $2.25 million settlement with Amazon over allegations that it violated the Fair Credit Reporting Act (FCRA) by failing to provide identity theft victims with records of fraudulent transactions made using their personal information. The settlement requires Amazon to comply with statutory record disclosure obligations, improve its procedures for handling identity theft requests, and notify affected consumers of their rights.

This is significant because it highlights regulators' expectations that organizations maintain effective processes to support individuals exercising their statutory privacy rights, particularly where identity theft and fraud are involved.

Read More

7. Connecticut Data Privacy Act Amendments Take Effect

July 1, 2026
Connecticut, United States

Amendments to the Connecticut Data Privacy Act (CTDPA) took effect on July 1, expanding the law's scope, broadening the definition of sensitive data, and enhancing consumer rights, including access to profiling information and third-party disclosures. Separately, Connecticut enacted legislation establishing a data broker registration program, prohibiting the sale of precise geolocation data, and introducing additional obligations for data brokers, direct-to-consumer genetic testing companies, and surveillance pricing practices, with phased implementation beginning October 2026 and January 2027.

This is significant because the amendments substantially broaden Connecticut's privacy framework, requiring organizations to reassess data governance, consumer rights processes, and compliance obligations for sensitive data and data brokerage activities.

Read More

8. Utah Digital Choice Act Takes Effect

July 1, 2026
Utah, United States

Utah's Digital Choice Act took effect on July 1, 2026, introducing new data portability and interoperability requirements for social media platforms. The law enables users to transfer their personal data and social graph between platforms and expands consumer rights under the Utah Consumer Privacy Act by allowing individuals to correct inaccurate personal information. The Act aims to reduce barriers to switching platforms while promoting competition and user control over personal data.

This is significant because it is among the first state laws to mandate interoperability and data portability for social media platforms, strengthening consumer choice and potentially setting a model for similar legislation in other jurisdictions.

Read More

Europe & Africa Jurisdiction

9. European Commission Renews South Korea’s Adequacy Decision

July 23, 2026

The European Commission completed its first review of the 2021 EU adequacy decision for South Korea, concluding that the country continues to provide an adequate level of protection for personal data transferred from the EU. The review noted that South Korea's data protection framework has further aligned with EU standards and recommended additional improvements regarding onward international data transfers and enforcement.

This is significant because it preserves the uninterrupted flow of personal data between the EU and South Korea, providing legal certainty for organizations engaged in cross-border data transfers and reinforcing confidence in South Korea's privacy framework.

Read More

10. European Commission Fines AliExpress €550 Million Under the Digital Services Act

July 20, 2026

The European Commission fined AliExpress €550 million for failing to comply with the Digital Services Act (DSA) by inadequately assessing and mitigating risks posed by illegal, unsafe, and counterfeit products on its platform. The Commission found deficiencies in AliExpress's risk assessments, content moderation, trader enforcement, and product compliance processes, and ordered the company to implement corrective measures.

This is significant because it marks one of the most significant enforcement actions under the DSA, reinforcing the EU's expectation that online platforms proactively identify and mitigate systemic risks through effective governance, risk assessment, and content moderation practices.

Read More

11. EDPB Calls for Stronger Cross-Regulatory Cooperation on GDPR Enforcement

July 17, 2026

The European Data Protection Board (EDPB) called on the European Commission to establish a clear legal basis for information sharing between regulators with different areas of competence. The Board also discussed measures to strengthen cross-border GDPR enforcement, including greater cooperation between data protection authorities, joint enforcement actions, and resource sharing to address the growing volume and complexity of cases, particularly those involving AI.

This is significant because it signals the EDPB's focus on improving coordinated enforcement across the EU, reflecting the increasing overlap among data protection, AI, and digital regulation, and on seeking greater regulatory consistency and enforcement efficiency.

Read More

12. Wind Tre Spa Fined €1.7 Million For GDPR Violations

July 16, 2026
Italy

The Italian Data Protection Authority (Garante) fined Wind Tre €1.7 million after security deficiencies led to two data breaches affecting more than 365,000 customers, including payment-related information for over 41,000 individuals. The Authority found failures in credential management, digital certificate controls, and security testing, and ordered the company to strengthen its cybersecurity measures.

This is significant because it reinforces regulators' expectations that organizations implement robust technical and organizational security measures to protect personal data and proactively identify vulnerabilities before they result in data breaches.

Read More

13. Ofcom Reports Progress on Age Assurance and Launches TikTok Investigation

July 16, 2026
United Kingdom

Ofcom reported significant progress in deploying age-assurance measures under the UK's Online Safety Act, noting that the proportion of children encountering highly effective age checks has nearly doubled. However, the regulator raised concerns about the effectiveness of age-inference methods used by some social media platforms and launched a formal investigation into TikTok's age-assurance practices. Ofcom also called on search engines and online platforms to strengthen protections ahead of proposed restrictions on social media use by under-16s.

This is significant because it signals increased regulatory scrutiny of age assurance technologies and reinforces expectations that online platforms adopt demonstrably effective, privacy-compliant methods to protect children from harmful online content.

Read More

14. Spanish DPA Issues Privacy Guidance on Smart Glasses

July 13, 2026
Spain

The Spanish Data Protection Authority (AEPD) published guidance on the responsible use of smart glasses equipped with cameras and microphones. The guidance reminds users that recordings of identifiable individuals constitute personal data and that uses beyond purely personal purposes may be subject to the GDPR. It also recommends transparency when recording, limiting data collection, configuring privacy settings, protecting audio recordings, and respecting restrictions on recording in sensitive locations.

This is significant because it highlights the growing privacy risks posed by wearable AI-enabled devices and reinforces the need for individuals and organizations using such technologies to consider data protection obligations when collecting or sharing personal data.

Read More

15. EU Parliament Advances Proposal to Reinstate ePrivacy Derogation for Child Sexual Abuse Detection

July 9, 2026

The European Parliament considered urgent action to reinstate the temporary ePrivacy derogation allowing online service providers to voluntarily detect child sexual abuse (CSA) material and related activities in private communications while negotiations on a permanent legal framework continue. The proposal follows the expiry of the previous derogation in April 2026 and aims to prevent a regulatory gap until long-term legislation is adopted.

This is significant because it reflects the EU's continued efforts to balance privacy rights with online child protection, and organizations providing communication services should closely monitor developments, as they may affect obligations related to the voluntary detection of illegal content.

Read More

16. European Commission Refers Four Member States Over NIS2 Implementation Delays

July 8, 2026

The European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union for failing to fully transpose the NIS2 Directive into national law. The Commission is seeking financial penalties, including lump-sum and daily fines, until the Member States complete implementation of the EU's strengthened cybersecurity framework.

This is significant because it demonstrates the Commission's willingness to take enforcement action to ensure the timely implementation of the NIS2 Directive, reinforcing the importance of consistent cybersecurity obligations across critical sectors in the EU.

Read More

17. EDPB Launches Consultation on Anonymization Guidelines

July 8, 2026

The European Data Protection Board (EDPB) published draft Guidelines on Anonymization for public consultation, providing clarity on the concept of anonymous data under the GDPR and a framework for assessing whether data has been effectively anonymized. The guidelines describe both contextual and simplified assessment approaches and emphasize ongoing evaluation of re-identification risks as technology and available information evolve.

This is significant because the guidance provides organizations with practical direction on implementing robust anonymization techniques and on distinguishing anonymous data from personal data under the GDPR. Comments on the draft guidelines are open until October 30, 2026.

Read More

18. Denmark Urges Organizations to Reassess US Data Transfers Following Supreme Court Ruling

July 1, 2026
Denmark

Following the US Supreme Court's decision in Trump v. Slaughter, the Danish Data Protection Authority advised organizations to review their Transfer Impact Assessments (TIAs) for transfers of personal data to the US. While the EU-US Data Privacy Framework (DPF) remains valid, the Authority noted that the ruling may affect transfers relying on other mechanisms, such as Standard Contractual Clauses (SCCs), and encouraged organizations to reassess regulatory safeguards and contingency plans.

This is significant because it signals increased regulatory scrutiny of US data transfers and highlights the importance of regularly reviewing TIAs and cross-border transfer strategies as legal developments evolve.

Read More.

19. Nigeria Issues Continuous Professional Development Requirements for Data Protection Officers

July 1, 2026
Nigeria

Nigeria’s Data Protection Commission (NDPC) published guidance introducing a Continuous Professional Development (CPD) framework for certified Data Protection Officers (DPOs). To maintain their verified status, DPOs must earn at least 20 CPD points annually, including 10 points from structured training. The framework recognizes formal training, knowledge contributions, and professional engagement activities. DPOs who fail to meet the requirements will have their verification status temporarily suspended until they achieve compliance.

This is significant because it formalizes ongoing competency requirements for DPOs, reinforcing professional standards and signaling Nigeria’s commitment to strengthening the quality and accountability of its privacy workforce.

Read More

20. Latvia Clarifies That Randomly Generated Numbers Do Not Justify Telemarketing Calls

July 1, 2026
Latvia

Latvia’s Data State Inspectorate (DVI) clarified that businesses cannot rely on automatically generated phone numbers to make unsolicited marketing calls to individuals. Prior, explicit consent is required before placing commercial calls to natural persons, and consent cannot be obtained during the call itself. Organizations using randomly generated numbers must first determine whether the number belongs to a natural or legal person, as different rules apply. The DVI also confirmed that consent cannot be provided by third parties, such as friends or family members.

This is significant because it reinforces that telemarketing consent requirements cannot be circumvented through automated number generation or post-call consent practices.

Read More

Asia Jurisdiction

21. South Korea Fines KT KRW 53.98 Billion Over Major Telecom Data Breach

July 30, 2026
South Korea

South Korea’s Personal Information Protection Commission (PIPC) fined telecom operator KT KRW 53.98 billion after a cyberattack that exploited compromised femtocells, exposing the personal data of 16,647 users and leading to intercepted authentication messages and approximately KRW 240 million in fraudulent micropayments. The PIPC found KT failed to implement adequate access controls, monitor unauthorized network access, and maintain effective security governance. It also referred KT for allegedly obstructing the investigation and proposed stronger penalties for evidence destruction and failure to cooperate with regulatory investigations.

This is significant because it demonstrates South Korea’s willingness to impose substantial penalties when inadequate cybersecurity directly results in consumer harm, while signaling tougher enforcement against organizations that conceal or obstruct data-breach investigations.

Read More

22. Australia Updates Facial Recognition Guidance for Retailers

July 29, 2026
Australia

Australia’s Office of the Australian Information Commissioner (OAIC) updated its guidance on the use of facial recognition technology (FRT) in retail settings following the Administrative Review Tribunal’s decision in the Bunnings case. The guidance clarifies how consent requirements and limited exceptions for collecting biometric information should be applied, while emphasizing that each FRT deployment must be assessed on its specific circumstances under the Privacy Act.

This is significant because it reinforces Australia’s high regulatory threshold for deploying facial recognition in public retail environments and signals continued scrutiny of biometric technologies, with organizations expected to adopt a cautious, case-by-case approach to compliance.

Read More

23. Australia’s ACCC Calls for Stronger Rules on Unsolicited Sales and Lead Generation

July 28, 2026
Australia

Australia’s Competition and Consumer Commission (ACCC) published a review finding widespread use of misleading and high-pressure unsolicited sales practices, particularly through telemarketing, door-to-door sales, and online lead generation. The ACCC recommended higher penalties, an opt-in model replacing the current cooling-off period, and clearer rules to ensure consumer protections apply where personal data collected online is used to generate unsolicited sales leads.

This is significant because it highlights the increasing regulatory scrutiny of data-driven marketing and lead-generation practices, signaling potential reforms that would strengthen consumer consent requirements and limit the use of personal information for unsolicited sales.

Read More

24. China Launches Data Security Capability Maturity Model for Industrial Enterprises

July 27, 2026
China

China’s National Cybersecurity Standardization Technical Committee launched a nationwide initiative to promote its Industrial Enterprise Data Security Capability Maturity Model. Industrial enterprises are invited to participate in voluntary maturity assessments to evaluate and improve their data security capabilities, with selected organizations helping validate the framework’s practical implementation. The initiative supports compliance with China’s Data Security Law, Network Data Security Regulations, and sector-specific data security requirements.

This is significant because it signals China’s continued shift toward structured, maturity-based data security governance, encouraging organizations to benchmark their security practices and align with evolving national data security standards.

Read More

25. Australia Fines TAB AUD 2.7 Million for Spam and Telemarketing Violations

July 22, 2026
Australia

Australia’s Communications and Media Authority (ACMA) fined Tabcorp Holdings (TAB) AUD 2.7 million for breaching spam and telemarketing laws. The regulator found TAB made marketing calls to numbers on the Do Not Call Register, contacted customers outside permitted hours, failed to properly identify itself during thousands of calls, and sent over 217,000 marketing emails and SMS to customers who had unsubscribed from specific marketing channels. TAB must also implement compliance improvements under a court-enforceable undertaking.

This is significant because it reinforces Australia’s strict enforcement of direct marketing rules and highlights regulators’ expectations that organizations maintain effective systems to honor consumer consent and communication preferences.

Read More

26. South Korea Fines TikTok and Apple for Unlawful Personal Data Processing

July 22, 2026
South Korea

South Korea’s Personal Information Protection Commission (PIPC) fined TikTok KRW 10.3 billion and Apple KRW 252 million for violating the Personal Information Protection Act. The PIPC found TikTok unlawfully collected and used third-party behavioral data for personalized advertising without valid consent and failed to meet overseas transfer transparency requirements. Apple was sanctioned for using Siri voice recordings and transcribed data to improve services without a proper legal basis, and for insufficient disclosures regarding overseas data transfers.

This is significant because it reinforces South Korea’s strict consent and cross-border transfer requirements, signaling that global technology companies must ensure transparent, freely given consent and robust compliance for international data processing activities.

Read More

27. Tajikistan Establishes National Data Protection Center

July 16, 2026
Tajikistan

Tajikistan established a Data Protection Center under the Agency for Innovation and Digital Technologies to strengthen cybersecurity and protect government information systems and data centers. The Center will oversee the security of state information systems, supervise data processing activities, and implement technical safeguards for information security. Its mandate excludes information classified as state secrets.

This is significant because it reflects Tajikistan’s efforts to strengthen institutional oversight of cybersecurity and data protection as part of its broader digital transformation strategy, with a focus on improving the resilience and security of government information infrastructure.

Read More

28. South Korea’s PIPC Unveils 2026 Privacy Enforcement Priorities

July 16, 2026
South Korea

South Korea’s Personal Information Protection Commission (PIPC) published its work plan for the remainder of 2026, reaffirming its focus on implementing a prevention-centered personal information management system. The roadmap also highlights continued regulatory enforcement, including investigations, corrective actions, and sanctions following major personal data breaches.

This is significant because it signals PIPC’s shift from a reactive enforcement model towards a more proactive regulatory approach, emphasizing preventive governance, stronger organizational accountability, and enhanced compliance measures to reduce privacy risks before incidents occur.

Read More

29. Vietnam Approves National Digital Transformation Strategy 2026-2030

July 14, 2026
Vietnam

Vietnam's Prime Minister approved the National Strategy on Digital Transformation for 2026–2030, with a vision to 2045, establishing the country's long-term roadmap for digital government, digital economy, and digital society initiatives.

This is significant because the strategy reinforces Vietnam's commitment to accelerating nationwide digital transformation and is expected to drive future regulatory and governance developments in cybersecurity, data governance, AI, digital infrastructure, and public-sector digitalization. Organizations operating in Vietnam should anticipate evolving compliance expectations as the strategy is translated into sector-specific laws, regulations, and implementation measures.

Read More

30. Australia Expands Consumer Data Right to Non-Bank Lenders

July 12, 2026
Australia

Australia has expanded its Consumer Data Right (CDR) framework to include non-bank lenders, requiring them to begin sharing standardized product information such as interest rates, fees, charges, and eligibility criteria. Consumer data sharing obligations will be phased in from 9 November 2026, depending on provider size.

This is significant because the expansion strengthens Australia's open banking ecosystem by increasing transparency and competition in the lending market. It enables consumers to compare a broader range of financial products more easily while placing new compliance obligations on non-bank lenders to meet CDR data quality, security, and interoperability requirements.

Read More

31. Japan's House Of Councillors Passes Bill No. 54 To Amend The Act On The Protection Of Personal Information

July 10, 2026
Japan

Japan's House of Councillors has passed Bill No. 54, introducing significant amendments to the Act on the Protection of Personal Information (APPI). The reforms permit certain non-consensual disclosures of personal data for statistical analysis while strengthening protections for minors' data, biometric information, and regulatory enforcement.

This is significant because the amendments reflect Japan's effort to balance data-driven innovation with stronger privacy safeguards. Organizations processing personal data in Japan should prepare for enhanced compliance obligations, particularly regarding children's data, biometric processing, and increased regulatory enforcement, with higher administrative and criminal penalties.

Read More

32. South Korea's PIPC Issues API Security Guidance to Prevent Data Breaches

July 8, 2026
South Korea

South Korea's Personal Information Protection Commission (PIPC) issued new guidance urging organizations to strengthen API security as the use of application programming interfaces expands across digital services. The guidance emphasizes privacy-by-design, least-privilege access controls, authorization management, continuous API inventory reviews, and the minimization of personal information transmitted through APIs.

This is significant because the PIPC is placing greater regulatory focus on API governance following several high-profile data breaches. Organizations are expected to embed security and data minimization into API design and operations, reinforcing that APIs are now a critical compliance and cybersecurity priority rather than solely a technical concern.

Read More

33. South Korea Expands Data Portability to Education and Employment

July 6, 2026
South Korea

South Korea's Personal Information Protection Commission (PIPC) proposed amendments to expand the right to request the transfer of personal information to the education and employment sectors. If adopted, individuals will be able to transfer university records, academic credentials, and employment information directly to third-party service providers, while specialized intermediary organizations will be permitted to facilitate secure data transfers.

This is significant because the proposal broadens South Korea's data portability framework beyond healthcare, telecommunications, and energy, reinforcing user control over personal data while supporting digital services such as employment matching and credential verification. It also introduces governance measures to ensure secure and standardized personal data transfers.

Read More

34. China Flags 32 Apps and SDKs for Privacy Violations

July 2, 2026
China

China's Ministry of Industry and Information Technology (MIIT) identified 32 mobile apps and software development kits (SDKs) for illegally collecting personal information and requesting excessive user permissions during a nationwide enforcement campaign under the Personal Information Protection Law (PIPL) and related cybersecurity regulations. The affected organizations have been ordered to rectify the identified issues or face regulatory action.

This is significant because it demonstrates China's continued focus on mobile app privacy compliance, with regulators actively scrutinizing excessive data collection and permission practices. App developers and SDK providers should ensure data collection is lawful, proportionate, and limited to what is necessary for service delivery.

Read More

35. Australia Updates Quick Reference Guide for Notifiable Data Breaches

July 1, 2026
Australia

The Office of the Australian Information Commissioner (OAIC) published an updated Quick Reference Guide to help organizations respond to data breaches and determine whether an incident must be reported under Australia's Notifiable Data Breaches (NDB) scheme. The guide outlines a four-step response process - contain, assess, notify, and review and provides practical guidance for assessing serious harm, notification obligations, applicable exceptions, and reporting requirements.

This is significant because the updated guidance reinforces regulatory expectations for timely breach response and risk assessment, emphasizing that organizations should have clear incident response processes to evaluate notification obligations and minimize harm to affected individuals.

Read More

36. Australia Proposes Stronger Enforcement Powers for Under-16 Social Media Ban

July 1, 2026
Australia

The Australian Government announced legislation to strengthen the eSafety Commissioner's enforcement powers and double the maximum penalty for systemic breaches of the country's under-16 social media law from AUD 49.5 million to AUD 99 million. The reforms would allow the regulator to compel platforms and third parties, including age-assurance providers and app stores, to produce evidence demonstrating compliance with age-verification obligations.

This is significant because Australia is shifting from implementing its landmark youth social media restrictions to actively enforcing them. The proposed reforms signal heightened regulatory scrutiny of platform accountability, age-assurance measures, and evidence of compliance, backed by substantially increased penalties for non-compliance.

Read More

37. Singapore Expands PDPA Exemptions for Statutory Bodies

July 1, 2026
Singapore

Singapore published the Personal Data Protection (Statutory Bodies) (Amendment) Notification 2026, amending the Schedule to the Personal Data Protection (Statutory Bodies) Notification by updating the list of statutory bodies covered under the notification.

This is significant because the amendment updates the scope of statutory bodies subject to the PDPA's sector-specific framework, ensuring the legal regime remains aligned with changes in Singapore's public sector landscape. Public entities should review whether the amendment affects their compliance obligations or applicable exemptions under the PDPA.

Read More

38. Singapore Launches Online Safety Commission

July 1, 2026
Singapore

Singapore's Online Safety Commission (OSC) commenced operations under the Online Safety (Relief and Accountability) Act 2025 (OSRAA), providing victims with a dedicated mechanism to seek relief from online harms. During its initial phase, the OSC will address five priority harms: online harassment, doxxing, online stalking, intimate image abuse, and image-based child abuse, with powers to order the removal of harmful content and restrict offending accounts.

This is significant because Singapore has introduced a dedicated regulatory framework combining administrative enforcement with new civil remedies to address online harms. The regime increases accountability for platforms and online administrators by imposing obligations to respond to harmful content and provides victims with faster, more accessible avenues for redress.

Read More

WHAT'S NEXT:
Key Privacy Developments to Watch For

Analyze this article with AI

Prompts open in third-party AI tools.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox



More Stories that May Interest You
Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 1:02:06
Consent by proxy: When AI agents start deciding for us
Watch Now View
Spotlight 1:00:41
Future-Proofing for the Privacy Professional
Watch Now View
Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight
Choosing the Right DSPM: An Industry Analyst’s Perspective
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Latest
View More
One Unrevoked Key, 37.5 Million People: What the Coupang data breach reveals about data access
Executive summary In June 2026, South Korea's Personal Information Protection Commission (PIPC) fined Coupang 624.68 billion won (approximately $409 million) which was the largest...
More Tools Does Not Mean Faster or More Accurate Insights View More
More Tools Does Not Mean Faster or More Accurate Insights
An access-review tool flags an account with more privilege than its role needs: routine, filed, forgotten. That same week, a separate scan shows that the same...
Data Security Posture Management (DSPM) Best Practices View More
Data Security Posture Management (DSPM) Best Practices
Explore DSPM best practices for discovering sensitive data, reducing exposure, governing access, prioritizing risk, and strengthening enterprise data security.
View More
The Future of DSPM: Why it’s essential?
Explore why DSPM is becoming essential for modern data security, helping organizations discover sensitive data, reduce exposure, govern access, and prepare securely for AI.
View More
Green-Light AI, Not Data Exposure
Learn the five critical data-layer controls enterprises need to prevent sensitive data exposure and enable secure, scalable AI agent adoption.
Agentic AI Readiness View More
Agentic AI Readiness: Why Your Enterprise Needs a New Data Security Paradigm
Learn how to secure Agentic AI by discovering sensitive data, mitigating AI risks, and building an enterprise-ready AI security strategy.
The Cloud Storage Bill Nobody Reads View More
The Cloud Storage Bill Nobody Reads
Hidden cloud storage costs add up fast. Learn how redundant, obsolete, and trivial data drives unnecessary spend, expands risk, and why automated data minimization...
"The Algorithm Did It" Is Now Dead in Court View More
“The Algorithm Did It” Is Now Dead in Court
Discover why organizations are now liable for AI-generated content and how ROT data minimization, AI governance, and Agent Commander reduce legal, security, and compliance...
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New