June's developments reveal a regulatory landscape that is becoming increasingly interventionist, preventative, and outcome-focused. Regulators are no longer satisfied with requiring organizations to be transparent about risks; they are increasingly expecting those risks to be anticipated, designed against, and actively mitigated.
A notable trend is the growing convergence of privacy, cybersecurity, consumer protection, and online safety. Digital regulation is moving beyond the traditional question of how data is processed to address how digital products are designed, governed, and experienced by users. This is particularly evident in measures aimed at protecting children, regulating high-risk digital environments, and embedding privacy and safety considerations into products from the outset.
At the same time, accountability expectations continue to mature. Governance structures, incident response capabilities, data-sharing practices, and technical safeguards are increasingly becoming matters of regulatory scrutiny. As enforcement becomes more sophisticated and sector-specific obligations continue to emerge, organizations will need to move beyond compliance checklists and adopt a more integrated approach to digital trust, risk management, and responsible innovation.
North & South America Jurisdiction
1. Florida AG and Roku Reach Resolution Under the Florida Digital Bill of Rights
June 26, 2026 Florida, United States
Florida Attorney General James Uthmeier and Roku, Inc. announced a negotiated resolution of an enforcement action brought under the Florida Digital Bill of Rights (FDBR). Under the agreement, Roku will enhance its child protection features to provide parents with greater control over their children's streaming experience.
As part of the resolution, Roku has committed to investing an estimated $25 million in engineering resources to implement these enhancements. The changes are expected to be deployed nationwide within the next 12 months.
The resolution does not include any finding of wrongdoing or the imposition of a civil penalty. The Attorney General's Office noted that the agreement advances consumer and child privacy protections while providing a framework for compliance. The matter highlights the continued regulatory focus on children's privacy and parental controls in digital entertainment and streaming services.
2. New Hampshire Prohibits Sale of Children's Online Personal Data
June 24, 2026 New Hampshire, United States
New Hampshire Governor Kelly Ayotte has signed House Bill 1460 into law, prohibiting businesses from selling the online personal data of children under the age of 13 to third parties. The law amends New Hampshire's existing consumer data privacy framework and strengthens protections for children's personal information.
The legislation reflects a continued trend among U.S. states to enhance privacy protections for minors and impose stricter limitations on the collection, use, and disclosure of children's data. Businesses that process children's personal information should review their data-sharing practices to ensure compliance with the new requirements.
3. HHS Settles HIPAA Ransomware Investigation with Employer-Sponsored Health Plan
June 18, 2026 United States
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has settled a HIPAA enforcement action with Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans following a ransomware attack that potentially affected the protected health information of 10,023 individuals.
OCR's investigation identified potential HIPAA Privacy and Security Rule violations, including failures to conduct an adequate risk analysis and implement appropriate safeguards before the incident occurred. Under the settlement, the health plan agreed to pay $450,000 and undertake a two-year corrective action plan that includes risk assessments, policy updates, and workforce training.
The action reflects OCR's continued focus on ransomware preparedness and compliance with HIPAA security requirements.
4. Vermont Data Privacy & Online Surveillance Act Signed Into Law
June 16, 2026 Vermont, United States
Vermont has enacted the Vermont Data Privacy and Online Surveillance Act, becoming the twenty-fourth U.S. state to pass a comprehensive privacy law in 2026. The law will take effect on January 1, 2028, and applies to organizations meeting specified data processing thresholds.
The legislation grants consumers rights to access, correct, delete, and obtain copies of their personal data, as well as opt out of targeted advertising, the sale of personal data, and certain profiling activities. It also introduces obligations relating to data minimization, consent for sensitive data processing, data protection assessments, and privacy notices.
Notably, the law requires businesses to disclose whether personal data is used to train large language models (LLMs) and prohibits the sale or use of personal data for targeted advertising purposes for individuals aged 13 to 17. The Vermont Attorney General has exclusive enforcement authority, with a 60-day cure period available until June 30, 2029.
5. Vermont Enacts Genetic Privacy Law for Direct-to-Consumer Testing Companies
June 15, 2026 Vermont, United States
Vermont has enacted H.639, a new genetic privacy law regulating direct-to-consumer genetic testing companies and their service providers. The law establishes requirements for the collection, use, disclosure, and retention of consumers' genetic data and biological samples.
Among other obligations, companies must obtain consent for uses of genetic data beyond the primary purpose of the testing service, provide an easy mechanism for consumers to revoke consent, and honor requests to delete genetic data or destroy biological samples. The law also requires companies to notify third parties to delete genetic data following a consumer deletion request and places restrictions on disclosures to government entities absent a warrant or the consumer's express consent.
The law takes effect on July 1, 2026. Violations constitute unfair and deceptive acts under Vermont's Consumer Protection Act and may be enforced by the Attorney General. Consumers may also bring civil actions, subject to a 30-day cure period that remains available until June 30, 2028.
6. ANPD Reviews Age Verification Compliance by App Stores and Operating Systems
June 10, 2026 Brazil
The Brazilian data protection authority (ANPD) has officially launched a monitoring initiative to evaluate the compliance of major app store providers and operating systems with Brazil's Digital Statute for Children and Adolescents (Law No. 15.211 / Decree No. 12.880/2026).
The investigation’s main goal is to monitor the way platforms deploy age measurement solutions, evaluate the compliance of regulated tech entities, and collect technical data to guide future regulations related to children's online safety. The investigation focuses on major companies like Apple (App Store), Google (Google Play Store), and Microsoft (Windows), due to their massive presence on mobile and desktop platforms. As per the law, these platform providers must be capable of supplying age signals through secure, privacy-centric interfaces.
ANPD has provided the targeted companies with 15 business days to submit their comprehensive documentation mapping out their age verification mechanisms. All the app store providers must review their age verification mechanisms to avoid hefty penalties.
7. FTC Finalizes Order Against Illuminate Education Following Student Data Breach
June 5, 2026 United States
The U.S. Federal Trade Commission (FTC) has finalized an order against Illuminate Education Inc. over allegations that inadequate security practices led to a data breach affecting the personal information of 10.1 million students.
The FTC alleged that the company failed to implement reasonable security measures despite prior warnings about vulnerabilities and did not provide timely breach notifications as promised. Under the order, Illuminate must implement a comprehensive information security program, delete unnecessary personal data, limit data collection and retention, maintain a public data retention schedule, and refrain from misrepresenting its privacy and security practices.
The action highlights the FTC's continued focus on data minimization, retention controls, cybersecurity, and the protection of children's and students' personal information.
8. CalPrivacy’s Coalition with AGs to Oppose SECURE Data Act
June 3, 2026 California, United States
The California Privacy Protection Agency (CPPA), alongside 18 state attorneys general and state agencies, has opposed the proposed SECURE Data Act, arguing that it would preempt stronger state privacy laws and reduce existing consumer protections.
The coalition raised concerns that the legislation could limit states' ability to enforce privacy requirements, weaken protections for sensitive data and minors, and undermine state-led privacy initiatives, including California's Delete Request and Opt-out Platform (DROP).
The development reflects the continuing debate over whether a federal privacy framework should establish a nationwide standard or allow states to maintain stronger privacy protections.
9. Louisiana Enacts Kids Online Protection and Anti-Grooming Act
June 1, 2026 Louisiana, United States
Louisiana has enacted the Kids Online Protection and Anti-Grooming Act, establishing a duty of care for online platforms that contract with minors under the age of 16. The law applies to covered platforms, including social media, messaging services, and online gaming platforms, subject to certain exemptions.
The legislation requires platforms to implement privacy and safety measures for minors, including restrictions on adult-to-minor interactions, limitations on sharing a minor's precise geolocation, and privacy-protective default settings. It also grants parents and legal guardians enhanced controls over their child's account, including the ability to manage connections, account settings, and certain platform activities.
Violations may result in civil penalties of up to $10,000 per violation following notice and an opportunity to cure. The law took effect on June 1, 2026.
10. ANPD Launches Reporting Channel for Violations of Brazil's Digital Child Protection Law
June 1, 2026 Brazil
Brazil's National Data Protection Authority (ANPD) has launched a dedicated channel for reporting potential violations of the Digital Statute of Children and Adolescents (ECA Digital). The initiative aims to support enforcement of the new framework by enabling individuals to report issues such as inadequate age verification, insufficient parental controls, excessive collection of children's data, and the absence of privacy-by-design safeguards.
The ANPD stated that complaints will be analyzed collectively to identify compliance trends and determine whether regulatory or enforcement action is warranted. The new channel forms part of Brazil's broader efforts to strengthen online protections for children and adolescents and promote compliance with the ECA Digital requirements.
11. Louisiana Enacts Comprehensive Data Privacy Law
June 1, 2026 Louisiana, United States
Louisiana has enacted the Louisiana Data Privacy Act (LDPA), becoming the 23rd U.S. state to adopt a comprehensive privacy law. The legislation will take effect on January 1, 2027, and applies to organizations meeting specified revenue or data processing thresholds.
The LDPA grants consumers rights to access, correct, delete, and obtain copies of their personal data, as well as opt out of targeted advertising, the sale of personal data, and certain profiling activities. The law also imposes obligations relating to data minimization, privacy notices, security safeguards, consent for sensitive data processing, and data protection assessments for high-risk processing activities.
The Louisiana Attorney General has exclusive enforcement authority. A temporary cure period will be available through July 31, 2027, after which enforcement actions may proceed without an opportunity to cure.
12. UK ICO Publishes Final Guidance on Consumer IoT Products and Services
June 11, 2026 United Kingdom
The UK's Information Commissioner's Office (ICO) has published its final guidance on consumer Internet of Things (IoT) products and services, clarifying how UK GDPR and PECR requirements apply to connected devices such as smart speakers, connected TVs, fitness trackers, smart doorbells, and other consumer IoT products.
The guidance emphasizes privacy by design, data minimization, meaningful consent, transparency, security, and the use of Data Protection Impact Assessments (DPIAs), particularly where products are likely to be used by children. It also highlights the need for ongoing security measures throughout a product's lifecycle, including regular updates, encryption, and appropriate authentication controls.
The guidance provides practical expectations for manufacturers, app developers, cloud providers, and other organizations involved in the consumer IoT ecosystem.
13. CNIL Issues Guidance on Consent Requirements for Electronic Communications
June 10, 2026 France
The French Data Protection Authority (CNIL) has published guidance clarifying the rules for electronic communications, including emails, SMS, and MMS. The guidance distinguishes between commercial prospecting, transactional communications, and relational communications, each of which may rely on a different legal basis.
CNIL confirms that commercial marketing communications generally require prior consent, subject to a limited exemption for existing customers receiving promotions for similar products or services. In contrast, transactional messages may rely on contract performance, while relational communications may be based on legitimate interests where they remain non-promotional and proportionate.
The guidance also emphasizes the importance of clear opt-out mechanisms, maintaining suppression lists, documenting consent records, and ensuring that non-marketing communications do not contain significant promotional content.
14. EDPB Adopts Harmonized Template For Data Breach Notifications
June 10, 2026 EU
The European Data Protection Board (EDPB) has adopted a draft common template for reporting personal data breaches to supervisory authorities under Article 33 of the GDPR. The initiative aims to streamline breach reporting across the EU by replacing the varying notification formats currently used by national data protection authorities.
The proposed template includes standardized fields, predefined response options, and support for phased reporting, allowing organizations to submit and update breach notifications as investigations progress. According to the EDPB, the harmonized approach is intended to reduce administrative burden and improve consistency in GDPR compliance across Member States.
The draft template is open for public consultation until August 5, 2026.
15. Irish High Court Upholds Core GDPR Findings Against TikTok, Sends Corrective Orders Back to DPC
June 3, 2026 Ireland
The Irish High Court has upheld the majority of the Irish Data Protection Commission's (DPC) findings against TikTok, confirming breaches of GDPR requirements relating to international data transfers and transparency concerning transfers of EU user data to China. The DPC's 2025 decision had imposed a €530 million fine.
While the court rejected most of TikTok's appeal arguments, it identified procedural shortcomings in the DPC's decision-making process relating to the consideration of expert evidence and the assessment of TikTok's "Project Clover" safeguards. As a result, the court set aside the DPC's corrective orders, including the suspension of data transfers, and referred the issue of appropriate corrective measures back to the DPC for reconsideration.
The ruling reinforces regulatory scrutiny of international data transfers while highlighting the importance of procedural fairness in enforcement decisions.
16. European Supervisory Authorities Publish First DORA ICT Incident Report
June 3, 2026 EU
The European Supervisory Authorities (EBA, EIOPA, and ESMA) have published their first annual report on major ICT-related incidents reported under the Digital Operational Resilience Act (DORA). The report analyzes 3,383 major incidents reported across the EU financial sector during 2025.
The findings show that many incidents were linked to system failures, third-party service providers, and other operational disruptions, while only a small proportion were attributed to cybersecurity events. Approximately one-third of incidents had a cross-border impact, reflecting the increasing interconnectedness of financial institutions and technology providers.
The report highlights the importance of strengthening cyber resilience, enhancing cooperation with ICT service providers, and improving consistency in incident reporting as DORA implementation continues across the EU.
17. Slovenian DPA Clarifies Processor Obligations When Returning Personal Data
June 3, 2026 Slovenia
The Slovenian Information Commissioner (IP) issued guidance on the return of personal data by processors following the termination of a data processing agreement. The authority clarified that, once a contractual relationship ends, the processor's legal basis for processing the controller's personal data also ceases and the processor must return or delete the data in accordance with the controller's instructions and the terms of the processing agreement.
The IP noted that the GDPR does not prescribe how data must be returned, the format in which it must be provided, or who bears any associated costs. These matters should be addressed contractually between the controller and processor. The guidance also reiterates that continued retention or processing of personal data after contract termination, without a valid legal basis, may constitute a GDPR violation and expose the processor to regulatory sanctions.
18. Finland’s EU CRA Implementing Act Comes into Effect
June 1, 2026 Finland
Finland's national law implementing the EU Cyber Resilience Act and the EU Cybersecurity Act has come into effect. The Act on the Cyber Resilience of Certain Products and Cybersecurity Certification (439/2026) supplements and gives domestic effect to the EU regulations, designating Traficom (Liikenne- ja viestintävirasto) as Finland's market surveillance authority under the CRA.
The Act's obligations phase in across three further dates. From June 11, 2026, rules on notified bodies and their related penalties apply. From September 11, 2026, manufacturers must report actively exploited vulnerabilities and serious security incidents, backed by corresponding administrative sanctions. From December 11, 2027, the broadest set of obligations takes hold: general product-conformity requirements and related sanctions for manufacturers, importers, and distributors.
One exception applies throughout: for high-risk AI systems that also fall within the CRA's scope, market surveillance sits not with Traficom but with the sector-specific authority responsible under Finland's AI Act implementing legislation (Act 1377/2025).
Latvia's new Biobank Law establishes a framework for biobank operations, with an emphasis on donor rights and regulatory compliance. Among other things, it establishes a legal framework for the creation and operation of biobanks to promote research and personalized medicine.
Under the new law, key provisions include dynamic consent, which allows donors to electronically track the use of their data and modify the scope of their consent. All samples and data must be properly pseudonymized, with a separate registry maintained for donor identities. The law also establishes the Latvian National Population Bank to manage a unified genome reference infrastructure, and strictly prohibits the use of biological samples and data for profit.
The law does not cover biological samples from embryos or fetuses, samples obtained for specific studies lasting less than 10 years, or samples used in accredited educational programs. The Health Inspectorate will supervise biobank managers and oversee their activities, based on opinions issued by the Central Medical Ethics Committee.
20. Germany Assigns Data Act Oversight Role to Federal Data Protection Authority
June 1, 2026 Germany
Germany's Data Act Implementation and Enforcement Act (DADG) has entered into force, granting the Federal Commissioner for Data Protection and Freedom of Information (BfDI) a new supervisory role in relation to the EU Data Act where personal data is involved.
Under the new framework, the Federal Network Agency (BNetzA) remains the primary authority responsible for enforcing the EU Data Act and serving as the main point of contact for stakeholders. The BfDI will complement this role by overseeing data protection aspects arising from the access, sharing, and use of data generated by connected products and digital services.
The legislation establishes Germany's national enforcement structure for the EU Data Act, which has applied across the European Union since September 2025.
21. CNIL Publishes Guidance on GDPR Roles in Cloud Computing
June 1, 2026 France
The French Data Protection Authority (CNIL) has issued guidance to help cloud computing providers and their customers determine whether they act as controllers, joint controllers, or processors under the GDPR.
The guidance examines three key scenarios—service provision, service improvement, and security—and explains how roles may vary depending on who determines the purposes and means of processing. CNIL notes that while customers are generally controllers and cloud providers are processors for service delivery, certain activities such as service enhancement or shared security initiatives may result in joint controllership.
The guidance is intended to help cloud ecosystem participants allocate GDPR responsibilities more accurately and ensure appropriate contractual and compliance arrangements are in place.
22. European Commission Fines Temu €200 Million Under the DSA
June 1, 2026
The European Commission has imposed a €200 million fine on Temu for violations of the Digital Services Act (DSA), marking only the second non-compliance decision issued under the regulation. The Commission concluded that Temu failed to adequately assess and mitigate risks associated with the sale of illegal and unsafe products on its platform.
According to the decision, Temu's risk assessment relied on general industry information rather than platform-specific evidence, resulting in an underestimation of consumer exposure to illegal products. The Commission also found shortcomings in Temu's evaluation of how certain platform features, including its recommender systems and influencer programs, may contribute to the dissemination of unlawful goods.
Temu has until August 28, 2026 to submit an action plan addressing the identified deficiencies under the DSA.
23. Irish High Court Upholds DPC’s €430 Million Fine Against Meta
June 1, 2026 Ireland
The Irish High Court rejected Meta’s challenge against a draft decision by the country’s DPC that imposed fines of up to €430 million after a 2018 complaint about personal data being held by Meta in a digital warehouse. After the complainant requested access to this data, Meta provided him with online “tools” to assist in downloading his information. He claimed there was remaining personal data left unsent, to which he should have access.
Meta argued the watchdog exceeded its powers by turning an individual complaint into a broader "own-volition" inquiry, but the High Court has ruled that the GDPR and the Data Protection Act 2018 grant the DPC the authority and the obligation to impose system-wide corrective measures even when an investigation is triggered by a single user.
24. New Zealand OPC Reinforces Transparency Requirements Under Privacy Act
June 26, 2026 New Zealand
New Zealand's Office of the Privacy Commissioner (OPC) has reiterated the importance of transparency as a core privacy principle, emphasizing that organizations must provide clear, accessible, and meaningful information about how personal information is collected, used, and shared.
The guidance highlights the need for privacy notices that are tailored to their audience, regularly reviewed, and presented in formats that individuals can easily understand. The OPC also encourages the use of contextual communication methods, such as just-in-time notifications, phone-based explanations, and accessible formats including sign language, particularly when collecting sensitive or unexpected information.
The guidance forms part of the OPC's broader effort to promote trust, accountability, and effective privacy practices under New Zealand's Privacy Act.
25. South Korea’s PIPC Offers Support for Implementing Right to Portability Within Public Institutions
June 26, 2026 South Korea
South Korea's Personal Information Protection Commission (PIPC) announced measures to support the implementation of the "Right to Request Transmission of Data by Person," a data portability right introduced under amendments to the Personal Information Protection Act and its Enforcement Decree.
As part of the initiative, personal information held by eight public institutions across sectors including healthcare, real estate, and employment has been designated as information eligible for transmission requests. The PIPC also stated that it will continue supporting the expansion of transferable data categories and the development of systems that enable individuals to securely transmit their personal information between organizations.
The initiative is intended to enhance individuals' control over their personal information and promote greater data mobility across public services.
26. South Korea’s PIPC Releases Revised Guidelines on Information Transmission Under the MyData Framework
June 25, 2026 South Korea
The Personal Information Protection Commission (PIPC) has issued revised guidelines on the transmission of personal information under South Korea’s MyData framework.
The guidance applies to requests made directly by individuals and through authorized personal information management service providers, and clarifies procedural requirements, technical standards, identity verification measures, transmission methods, and security safeguards. The revised guidelines support the implementation of the right to request transmission of personal information and aim to promote secure, standardized, and interoperable data transfers between organizations.
Organizations subject to the framework should review their transmission processes to ensure alignment with the updated guidance.
27. Singapore Issues Commencement Notification For OSRA Act
June 24, 2026 Singapore
Singapore has issued a commencement notification for the Online Safety (Relief and Accountability) Act 2025 (OSRA), bringing into force provisions aimed at addressing serious online harms.
The Act introduces measures to combat online harassment, doxxing, online stalking, intimate image abuse, and image-based child abuse, while also establishing mechanisms for victims to seek relief and hold perpetrators accountable. The framework strengthens protections against harmful online conduct and provides authorities and affected individuals with additional tools to address digital safety risks.
Organizations operating online platforms should assess whether the new requirements impact their policies, reporting processes, and content moderation practices.
28. Saudi Arabia Gets New Data Monetization Policy
June 20, 2026 Saudi Arabia
Saudi Arabia’s Saudi Data and Artificial Intelligence Authority (SDAIA) has issued a new Data Monetization Policy aimed at supporting the growth of the Kingdom’s data economy.
The policy establishes principles and rules governing the development, provision, and use of data-driven products and services by government entities. It seeks to promote innovation, investment, and responsible data use while safeguarding privacy and increasing the availability of open data.
The policy applies to government-held data as well as data processed by private entities on behalf of government bodies, reinforcing Saudi Arabia’s broader framework for data governance and digital transformation.
29. UAE Approves New Resolution Regulating Children’s Access to Social Media
June 18, 2026 UAE
The UAE Cabinet has approved a new resolution regulating children’s access to social media platforms, establishing a minimum age of 15 for account creation and use, while requiring enhanced protections for users aged 15 to 16.
The framework mandates robust age-verification mechanisms, prohibits reliance on parental consent to bypass restrictions, restricts personalized advertising and behavioral profiling of children, and requires platforms to provide parental controls, conduct safety risk assessments, and report to regulators.
Social media providers will have up to 12 months to comply, with oversight by the National Media Authority and the Telecommunications and Digital Government Regulatory Authority.
30. DIFC Launches Public Consultation on AI-Focused Data Protection Amendments
June 18, 2026 UAE
DIFC has launched a public consultation on proposed amendments to its Data Protection Regulations, aimed at strengthening data governance in an increasingly AI-driven environment. The changes would enhance requirements for AI-enabled systems that process personal data, reinforce privacy-by-design and safety expectations, clarify certification obligations and the role of the Autonomous Systems Officer (ASO), and introduce new powers for the Commissioner to recognise accreditation and certification frameworks.
Building on the DIFC’s 2023 AI-related data protection reforms, the amendments seek to ensure the regulatory framework remains practical, clear, and responsive to emerging technologies while maintaining high standards of accountability and governance. The consultation is open until 18 July 2026, with the proposed changes expected to have implications for organisations using AI and data-driven systems within the DIFC.
31. South Korea Updates Health and Medical Data Utilization Guidelines
June 15, 2026 South Korea
South Korea’s Personal Information Protection Commission (PIPC) has published revised Health and Medical Data Utilization Guidelines, updating the framework for the use of health and medical data in research and public-interest activities.
The revised guidance clarifies procedures for using deceased individuals’ medical data, introduces standards for pseudonymizing unstructured data, and streamlines requirements for research involving pseudonymized information. The updates are intended to facilitate the responsible use of health and medical data while strengthening privacy protections and providing greater regulatory certainty for healthcare providers, research institutions, and other organizations engaged in data-driven research.
32. South Korea & European Union Sign Digital Trade Agreement
June 10, 2026 South Korea
The EU and South Korea have now formally signed the Digital Trade Agreement.
It is meant to modernize the foundational 2011 EU-Korea Free Trade Agreement. This high-standard pact aims to remove unjustified digital trade barriers, lower operating costs for small and medium enterprises, and foster an open, rules-based digital economy.
Some of the key provisions of this deal include strict mutual recognition for the validity and enforceability of electronic contracts and signatures, alongside robust online regulations to maximize consumer protection and safety.
33. New Zealand OPC Releases Initial Findings on Manage My Health Cyber Breach
June 10, 2026 New Zealand
New Zealand’s Office of the Privacy Commissioner (OPC) has released Phase 1 findings from its inquiry into the December 2025 cyber breach affecting the Manage My Health (MMH) patient portal.
The OPC found that both MMH and Health New Zealand failed to implement appropriate security safeguards, resulting in breaches of Rule 5 of the Health Information Privacy Code. The inquiry identified significant technical and governance shortcomings, including inadequate multifactor authentication, ineffective security monitoring, insufficient privacy risk assessments, overreliance on vendor security assurances, and weaknesses in project oversight and contracting arrangements.
The findings underscore the importance of robust security, privacy governance, and third-party risk management in healthcare systems.
34. Vietnam Publishes Guidance for Cyber Security Law
June 10, 2026 Vietnam
Vietnam’s Ministry of Public Security has published guidance supporting the implementation of the country’s Cyber Security Law.
The guidance promotes a proactive, prevention-focused approach to cybersecurity, emphasizing early risk identification and threat mitigation rather than relying solely on reactive measures. It also reinforces strict compliance expectations, confirming that both domestic and foreign organizations operating in Vietnam are subject to the same cybersecurity requirements and standards.
The guidance reflects Vietnam’s continued focus on strengthening cyber resilience and ensuring consistent security obligations across organizations operating within its jurisdiction.
35. Malaysia’s MCMC Announces Plans to Enforce Child Protection Code
June 1, 2026 Malaysia
The Malaysian Communications and Multimedia Commission (MCMC) has announced plans to enforce a Child Protection Code under the Online Safety Act 2025.
The framework will introduce a risk-based oversight approach, prioritizing digital services and platforms that present higher risks to children. The Code will embed child-safety-by-design principles into the development and operation of online platforms, requiring measures such as age verification, harmful content detection, accessible reporting mechanisms, parental controls, and privacy-protective default settings.
The initiative reflects Malaysia’s growing focus on strengthening online safety protections for children and enhancing platform accountability.
36. South Korea Announces Privacy by Design Certification Program
June 1, 2026 South Korea
South Korea’s Personal Information Protection Commission (PIPC) has announced the launch of a Privacy by Design (PbD) certification program for software products and solutions.
The program is intended to encourage the integration of privacy protections throughout the design and development lifecycle of digital products. It will provide certification pathways for a broad range of offerings, including mainstream IT products, enterprise software solutions, and specialized security products for small and medium-sized enterprises (SMEs).
The initiative reflects South Korea’s continued emphasis on proactive privacy governance and the adoption of privacy-enhancing measures at the product development stage.
37. South Korea’s PIPC Issues Draft Amendments to PIPA
June 1, 2026 South Korea
South Korea’s Personal Information Protection Commission (PIPC) has published draft amendments to the Personal Information Protection Act (PIPA) aimed at strengthening safeguards against personal data breaches and enhancing individual rights.
Key proposals include requiring board approval and PIPC notification for Chief Privacy Officer (CPO) appointments, mandating certain organizations to obtain ISMS-P certification by December 31, 2028, introducing a 72-hour deadline for notifying affected individuals of data breaches, and strengthening administrative penalties for repeat violations.
The proposed amendments form part of South Korea’s broader efforts to modernize its data protection framework and reinforce organizational accountability.
WHAT'S NEXT: Key Privacy Developments to Watch For
Japan's proposed amendments to the Act on the Protection of Personal Information (APPI) are pending approval by the Upper House, with implementation expected no earlier than 2028 if enacted. If passed, organisations using AI should prepare for new compliance requirements relating to AI training data, biometric information, children's data, and enhanced data governance obligations.
Vietnam's Resolution No. 66.17/2026/NQ-CP takes effect on July 1, 2026, bringing 142 conditional business sectors under enhanced licensing, compliance, and regulatory oversight requirements.
The Philippines' National Privacy Commission (NPC) has published a draft Circular establishing rules and is expected to finalize the Circular, providing greater clarity on compliance obligations under the Data Privacy Act.
Following the DUAA's first year, the ICO is expected to publish additional guidance and advance work on a statutory AI and automated decision-making code of practice.
The Cyprus Presidency of the Council of the European Union has revised the final compromise text on the EU Digital Omnibus, dropping the European Commission's proposal for a single ENISA-run cyber incident reporting mechanism in favor of national reporting entities managed by member states.
The European Commission's Special Panel on child safety online has concluded its final meeting, and will deliver final recommendations on July 13, potentially shaping future EU measures on youth protection and social media.
The UK government is expected to develop legislation restricting social media access for under-16s and imposing additional protections for minors online.
In Canada, Bill C-34 (the Safe Social Media Act), will progress through the legislative process, introducing proposed obligations for social media platforms, chatbot providers, and AI-generated content labeling.
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
Enterprises are deploying autonomous AI agents into production faster than they can secure them, and the best practices for securing this complex new landscape are still being...
In 2026, the convergence of cloud expansion, SaaS proliferation, and agentic AI adoption has fundamentally changed the data security challenge, making Data Security Posture...
Explore Bangladesh’s Personal Data Protection Act, 2026, including its key provisions, data subject rights, compliance requirements, and business impact.
Learn how to operationalize compliance with India's Digital Personal Data Protection Act (DPDPA) using automation for consent, data governance, security, vendor management, and data...
Discover why organizations are now liable for AI-generated content and how ROT data minimization, AI governance, and Agent Commander reduce legal, security, and compliance...
This infographic breaks down the key transparency obligations for both deployers and providers under the AI Act’s Article 50 Code of Practice. Access it...
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...