From Reactive Compliance to Proactive Accountability
Privacy regulators worldwide are increasingly moving beyond traditional notice-and-consent models toward proactive accountability and risk prevention. This month's developments reveal three clear trends: heightened scrutiny of children's privacy and online safety, stronger enforcement of data minimization and retention obligations, and growing expectations for organizations to embed privacy controls into products, AI systems, and digital infrastructure by design. Regulators in jurisdictions such as South Korea, the UK, California, and the EU are focusing less on isolated compliance failures and more on whether organizations can demonstrate ongoing governance, effective safeguards, and responsible use of personal data. At the same time, governments are advancing digital identity frameworks, AI oversight measures, and cybersecurity requirements, signaling greater integration between privacy, security, and digital governance.
Organizations should expect regulators to increasingly assess not just what data is collected, but whether the entire data ecosystem has been designed to manage risk before harm occurs.
North & South America Jurisdiction
1. Connecticut Governor Signs Bill Expanding Consumer Data Privacy Rights
May 29, 2026 Connecticut, United States
The Connecticut Consumer Privacy and Protection Act (SB 4) has been signed into law by Governor Ned Lamont. This legislation expands upon Connecticut's existing framework to introduce statutory consumer data protections, mandate registration requirements for corporate data brokers, and establish regulatory limits on commercial surveillance pricing and media broadcast volumes.
The law regulates the operations of third-party data brokers by mandating them to register annually with the state and pay a mandatory operational fee. In addition, the legislation directs the Department of Consumer Protection to establish a centralized, statewide deletion registry, which will allow state residents to simultaneously demand the erasure of their personal files from all registered corporate databases at once. Furthermore, SB 4 creates strict consumer barriers against the unauthorized sale or transfer of precise geolocation data, facial recognition metrics, biometric tracking, and neural inputs. Under this law, commercial entities utilizing automated data profiling must provide consumers with explicit disclosures when implementing individualized pricing systems for consumer goods.
Private entities and tech firms operating in Connecticut must prepare for a structured compliance rollout, as the core privacy provisions and restrictions are scheduled to take effect on October 1, 2026, with the full rollout of the data broker registration registry finalized by January 1, 2027.
2. California Attorney General Sues Chrome Holding Co. Over Genetic Data Breach
May 28, 2026 California, United States
California Attorney General Rob Bonta filed a lawsuit against Chrome Holding Co., formerly known as 23andMe, regarding the company’s alleged failure to protect the sensitive genetic and personal information of millions of users during a 2023 data breach.
The complaint alleges that the company maintained inadequate security procedures, which allowed threat actors to operate undetected within its systems for five months by utilizing "credential stuffing" and exploiting coding errors in its "DNA Relatives" feature. Furthermore, the state contends that the company made misleading statements regarding the adequacy of its safeguards and downplayed the severity of the incident, which resulted in the unauthorized access of ancestry reports, health predispositions, and family histories. The lawsuit seeks civil penalties for alleged violations of the California Consumer Privacy Act and the Genetic Information Privacy Act.
This legal action highlights the growing regulatory focus on the unique sensitivity of genomic data, signaling that private entities holding biometric or health-related information face heightened liability and stricter enforcement of data security obligations under state privacy laws.
3. New Mexico Jury Finds Meta Liable for Endangering Minors
March 24, 2026 New Mexico, United States
The New Mexico Department of Justice announced that a jury found Meta Platforms, Inc. liable for misleading consumers regarding platform safety and endangering children. Following a 2023 investigation, the court ordered Meta to pay $375 million in civil penalties under the state’s Unfair Practices Act.
The evidence presented during the trial established that Meta’s design features facilitated child exploitation and were intentionally structured to foster addiction among young users. The verdict highlighted that, despite public commitments to safety, the company’s platforms exposed minors to sexual abuse and online solicitation. This legal action serves as one of the most significant state-level financial penalties against a social media entity for child safety failures.
This court decision signals a transition from regulatory warnings to severe financial consequences for design-based harms, reinforcing that private entities may be held legally accountable for the inherent architecture and addictive nature of their digital products.
4. Connecticut Attorney General Launches Investigation Into Roblox
May 22, 2026 Connecticut, United States
Attorney General William Tong launched a formal investigation into Roblox to examine the platform's safety protocols and its impact on minor users. The inquiry focuses on the company’s age-verification processes, the effectiveness of its content moderation, and its compliance with consumer protection laws regarding user safety and data privacy.
State officials have requested internal documentation and data regarding user demographics and platform revenue to assess whether current safeguards sufficiently protect younger audiences from exposure to unsuitable content. This action indicates a shift toward increased regulatory scrutiny of social gaming platforms, suggesting that private entities in the gaming sector will be held to the same compliance and safety standards as traditional social media companies.
5. Texas Attorney General Reaches Settlement With LG Electronics
May 11, 2026 Texas, United States
Texas Attorney General Ken Paxton announced a major settlement with LG Electronics U.S.A., Inc. (LG) to resolve allegations that the company violated the Texas Deceptive Trade Practices Act.
Under the terms of the settlement, LG is prohibited from collecting consumers' viewing data via Automatic Content Recognition technology without explicit, informed consent. To ensure future transparency, LG must implement upfront disclosures through prominent pop-ups on smart televisions and its official website detailing data collection practices. Furthermore, the company is required to provide streamlined opt-outs, ensuring a simple and user-friendly mechanism for consumers to withdraw from data collection agreements.
Notably, the settlement also addresses state concerns regarding international surveillance by explicitly prohibiting the transfer or sharing of any collected viewing data with the Chinese Communist Party. Following a similar agreement with Samsung, this settlement reinforces a state-led effort to eliminate 'dark patterns' in smart TV interfaces and hold manufacturers accountable for deceptive data practices.
6. California’s AG Partners With DAs & CPPA To Secure Landmark $12 Million Settlement With General Motors
May 8, 2026 California, United States
California’s Attorney General Rob Bonta has partnered with several district attorneys and the California Privacy Protection Agency (CPPA) to secure a $12.75 settlement with General Motors over its alleged sale of location and driving data of thousands of Californians to two data brokers.
The investigation revealed that between 2020 and 2024, General Motors collected sensitive geolocation and driving behavior data through its OnStar service and sold it to data brokers to create "driver-rating" products for insurance companies. Now, as part of the settlement, General Motors must pay $12.75 million in civil penalties and delete retained driving data within 180 days (unless express consent is given). It is also banned from selling driving data to brokers for the next five years.
This settlement is pivotal as it marks the first time the “data minimization” principle has been enforced by a regulator. For private entities, this reinforces the fact that keeping or repurposing consumer data beyond its original intent is a high-stakes liability.
7. CPPA Sends Letter To House Committee Opposing SECURE Data Act
May 1, 2026 California, United States
The California Privacy Protection Agency (CPPA) has issued a letter to the House Energy and Commerce Committee expressing its opposition to the proposed SECURE Data Act.
In the letter, the agency opposes the broad preemption provision in the proposed law, stating that it would supersede many existing rights under the California Consumer Privacy Act and the Delete Act, rendering the DROP platform ineffective while also expressing concern about the inability of businesses to honor opt-out signals affecting their ability to enforce consumer rights.
8. House Energy and Commerce Committee Introduces SECURE Data Act
May 1, 2026 United States
The House Energy and Commerce Committee has introduced the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act (SECURE Data Act). Registered as HR 8413, the bill seeks to establish a comprehensive federal framework for consumer privacy.
The SECURE Data Act applies to any organization that meets one of two standards: it must either process the personal data of more than 200,000 consumers annually and have an annual gross revenue of $25,000,000 or more, or process the personal data of 100,000 or more consumers annually while deriving 25% or more of its annual gross revenue from the sale of personal data.
Key provisions of the SECURE Data Act include several consumer rights, such as the right to access, correct, and delete personal data, as well as the right to portability. Additionally, the Act mandates opt-out mechanisms for targeted advertising, data sales, and significant automated profiling, marking a major step toward uniform federal data protection standards.
9. ICO Warns Platforms Over Inadequate Age Assurance Measures
May 21, 2026 United Kingdom
The UK ICO has raised concerns about the limited progress made by major social media platforms in preventing underage users from accessing age-restricted services. Following engagement with platforms including TikTok, Snapchat, Facebook, Instagram, YouTube, and X, the regulator stated that it does not yet have confidence that effective and privacy-friendly age assurance measures are in place.
The ICO warned that children's personal data may continue to be processed on platforms they should not be able to access and indicated it is prepared to use its enforcement powers, including formal investigations and sanctions, if progress remains insufficient.
The statement reinforces growing regulatory expectations around age assurance and children's online privacy.
10. ICO Reminds the UK Businesses to Prepare for New Data Protection Complaints Requirements
May 19, 2026 United Kingdom
The UK ICO has reminded organisations that, from 19 June 2026, the Data (Use and Access) Act 2025 will require all businesses to implement a formal data protection complaints process. Organisations must provide individuals with a clear way to submit complaints, acknowledge complaints within 30 days, investigate concerns without undue delay, keep complainants informed, and communicate outcomes.
The ICO has encouraged businesses, particularly SMEs, to review its guidance and prepare for compliance ahead of the implementation date. The regulator emphasized that effective complaint handling not only supports legal compliance but can also strengthen customer trust and reduce the likelihood of regulatory escalation.
11. ICO Advises Government on Privacy-Friendly Online Advertising Reforms
May 18, 2026 United Kingdom
The UK ICO has published advice to the government recommending changes to PECR rules governing online advertising. The regulator suggests that certain low-risk advertising activities, particularly contextual advertising that does not rely on extensive tracking or profiling, could potentially operate without consent requirements under Regulation 6.
The ICO's proposal aims to encourage the adoption of privacy-enhancing advertising models while maintaining consent requirements for more intrusive forms of behavioral advertising. Although no legal changes have been made yet and existing PECR obligations remain in force, the proposal signals a possible shift towards a more risk-based approach to online advertising regulation and the use of cookies and similar tracking technologies.
12. The EDPB Adopts Opinion Concerning the Improvement of the Finnish Ombudsman's Draft Accreditation Requirements for GDPR Certification Bodies
May 13, 2026
The EDPB has issued Opinion 13/2026 on Finland’s proposed accreditation requirements for GDPR certification bodies under Article 43 GDPR. While supporting the overall framework, the Board recommended several refinements to improve consistency across the EEA and strengthen clarity regarding the independence, expertise, and responsibilities of certification bodies.
The recommendations include clarifying personnel qualification requirements, ensuring responsibilities are appropriately assigned to certification bodies, and removing provisions that could expand assessments beyond the intended certification scope. The Finnish Data Protection Ombudsman has two weeks to respond before the accreditation requirements are finalized.
13. Russmedia Judgment Expands GDPR Responsibilities for Online Platforms
May 12, 2026 Germany
The CJEU's Russmedia ruling clarifies that online platforms may be considered GDPR controllers where they have their own commercial interest in disseminating personal data. The court held that platforms must implement effective measures to remove unlawful personal content once notified and take reasonable steps to prevent its re-publication.
According to guidance from the Hamburg DPA, these principles may also apply to social media platforms that use personal data for advertising or other commercial purposes. The decision reinforces expectations for platforms to adopt risk-based safeguards, particularly where sensitive personal data is involved, while balancing data protection obligations against freedom of expression rights.
14. The Belgian DPA Fines Isabel SA €120,000 For GDPR Violations, Including Misqualifying Itself As a Data Processor and Collecting Excessive Data
May 12, 2026 Belgium
The Belgian DPA has fined Isabel €120,000 after it received a complaint on March 29, 2021, concerning the authentication process of TruliUs, a service developed by Isabel that enabled individuals to identify and authenticate themselves on behalf of a company on partner digital platforms.
The complainant, a company manager, raised concerns about discrepancies between the data described in TruliUs' privacy statement and the data actually collected, and questioned the relevance of collecting data such as nationality, ID card photo, place of birth, and date of birth. The complainant also reported that two emails sent to Isabel's Data Protection Officer (DPO) on March 11, 2021, and March 19, 2021, to exercise their right of access, went unanswered.
Consequently, the Belgian DPA found that Isabel violated Articles 5(1)(a), 5(1)(c), 5(2), 12(1), 13, 15(1), and 25(2) of the GDPR, by misqualifying itself as a processor for the TruliUs authentication and identification processing, when it should have been qualified as a data controller, thereby failing to assume the obligations incumbent upon a controller.
15. Belgian DPA Fines Company €176,950 for Retaining Former Employee's Active Mailbox
May 12, 2026 Belgium
The Belgian DPA has fined a technology company €176,950 after finding that it failed to deactivate a former consultant's email account for several months following her departure. While the regulator accepted that retaining the mailbox for one month to notify contacts of the individual's departure was justified, it found that the company lacked a legal basis for continued processing thereafter.
The DPA also criticized the company for failing to demonstrate that appropriate safeguards were in place to protect the confidentiality and integrity of the mailbox. The decision highlights the importance of timely offboarding procedures, mailbox deactivation, and maintaining adequate records to demonstrate GDPR compliance.
16. DVI Publishes Guide On Cookie Banner & Freedom Of Consent
May 8, 2026 Latvia
The Data State Inspectorate (DVI) has published a guide that addresses common issues with cookie banners and freedom of consent on websites.
In this guide, the DVI has reminded website operators that users must be given a genuine and informed choice when consenting to cookies. Following inspections and complaints, the regulator identified several recurring issues, including the use of cookies before consent is obtained, misleading cookie banner designs, incomplete information about cookie usage, and non-functional consent mechanisms.
The authority emphasized that consent for analytics and marketing cookies must be freely given, specific, informed, and unambiguous. It also reiterated that continued browsing, closing a banner, or consent obtained without a meaningful opt-out option does not constitute valid consent under data protection rules.
17. CNIL Issues Guidance on Creditworthiness Assessments and Automated Decision-Making
May 7, 2026 France
The French CNIL has published recommendations aimed at improving transparency and data protection in creditworthiness assessments. The guidance emphasizes that lenders should collect only data necessary for evaluating a borrower's ability to repay, clearly explain how personal data is used, and provide meaningful information about credit scoring and automated decision-making processes.
The CNIL also highlights individuals' rights to obtain explanations of automated decisions, request human review, and challenge outcomes. In addition, it recommends limiting the retention and use of historical payment incident data to prevent individuals from being unfairly disadvantaged over the long term.
18. EU Commission Advances Privacy-Preserving Age Verification Framework
May 1, 2026 France
The European Commission has adopted a recommendation encouraging Member States to deploy privacy-preserving age verification solutions by the end of 2026. The proposed framework allows users to prove they are above a certain age threshold without disclosing their exact age or identity, using anonymous proof-of-age technologies integrated with the European Digital Identity Wallet.
The initiative forms part of the EU's broader efforts to protect minors online and support compliance with the Digital Services Act. The Commission will also establish an EU-wide age verification scheme and a list of trusted providers to help ensure age verification solutions meet consistent privacy, security, and cybersecurity standards across the EU.
19. AGCM Announces Closure Of Investigations into DeepSeek, Mistral, and NOVA AI After Commitments Related To Transparency Submitted
May 1, 2026 Italy
Italy's Competition Authority has concluded investigations into DeepSeek, Mistral AI, and NOVA AI after the companies agreed to strengthen transparency regarding the risk of AI-generated “hallucinations” - inaccurate or misleading outputs produced by generative AI systems. The cases were closed without findings of infringement following the acceptance of voluntary commitments.
The companies agreed to introduce prominent warnings within their websites and applications, enhance pre-contractual information on the limitations and reliability of AI-generated content, and encourage users to verify outputs independently. DeepSeek is also committed to investing in technical measures to reduce hallucinations, while acknowledging that the risk cannot currently be eliminated entirely.
Germany's Federal Office for Information Security (BSI) has published the C3A (Criteria Enabling Cloud Computing Autonomy), a new framework designed to help organizations assess the sovereignty and autonomy of cloud services. The criteria aim to provide greater transparency around factors such as provider influence, data localization, operational control, and the ability to use cloud services independently within a given risk context.
Building on the BSI's existing C5 cloud security framework and aligned with the European Cloud Sovereignty Framework (EU CSF), C3A enables cloud providers to demonstrate compliance through audits and allows customers to define sovereignty requirements based on their specific risk profiles and regulatory needs.
21. Italian DPA Issues Guidelines on Tracking Pixels in Emails
May 1, 2026 Italy
The Italian Data Protection Authority has published new guidelines governing the use of tracking pixels in emails, emphasizing the need for greater transparency and user control. The regulator clarified that tracking pixels, which enable senders to monitor when emails are opened and collect behavioral data, generally require prior, free, specific, and informed consent.
The guidelines also require organizations to provide clear privacy notices, offer simple mechanisms for withdrawing consent, and implement privacy-by-design measures to minimize user identifiability and unnecessary data sharing. Organizations using tracking pixels will have six months from publication of the guidelines to achieve compliance.
22. South Korean Regulator Fines Organizations for Data Security Failures
May 28, 2026 South Korea
South Korea's Personal Information Protection Commission (PIPC) has imposed enforcement sanctions and fines totaling KRW 558.6 million against five organizations for significant personal data protection failures. The violations included inadequate security measures and insufficient oversight of entrusted data processing activities.
As part of the enforcement action, the affected organizations, including the Ministry of the Interior and Safety and Miso Tech, have been directed to address identified weaknesses, implement corrective measures, and strengthen compliance with personal information protection requirements. The decision underscores the PIPC's continued focus on accountability, security safeguards, and effective vendor oversight.
23. China Targets Apps and SDKs for Personal Information Violations
May 21, 2026 China
China's Ministry of Industry and Information Technology (MIIT) has identified 31 mobile applications and software development kits (SDKs) for violating users' personal information rights following a recent compliance inspection. The issues reportedly included unauthorized collection of personal information and improper user interface practices, such as disruptive or misleading window redirects.
The affected apps and SDK providers have been ordered to rectify the identified violations in accordance with applicable legal requirements. The MIIT warned that further enforcement measures may be taken if organizations fail to implement corrective actions effectively, reflecting China's continued focus on strengthening oversight of mobile applications and personal information protection.
24. South Korea Shifts to Risk-Based Privacy Oversight Framework
May 21, 2026 South Korea
South Korea's Personal Information Protection Commission (PIPC) has announced a transition to a prevention-oriented, risk-based privacy management system, with enhanced inspections beginning in June 2026. Under the new approach, sectors will be classified according to the level of personal data risk, with high-risk industries such as platforms, financial institutions, public bodies, edtech providers, and healthcare organizations subject to more intensive oversight.
The initiative also promotes broader adoption of Privacy by Design (PbD) principles, increased investment in privacy safeguards, stronger supply chain oversight, and enhanced monitoring of emerging technologies such as AI and IoT devices. The move reflects a growing regulatory focus on proactively identifying and mitigating privacy risks before incidents occur.
25. South Korea Strengthens PIPA Fine Calculation Framework
May 18, 2026 South Korea
South Korea's Personal Information Protection Commission (PIPC) has announced amendments to the Enforcement Decree of the Personal Information Protection Act (PIPA) and the Standards for Imposing Fines. Under the revised framework, administrative fines will be calculated based on the higher of a company's revenue from the previous fiscal year or its average revenue over the preceding three years.
The amendments, effective for violations occurring after 19 May 2026, are expected to strengthen enforcement and increase potential financial exposure for organizations that fail to comply with South Korea's personal information protection requirements.
26. South Korea’s PIPC Announces Almost KRW 553.9 Million In Fines Against Boram Sangjo Development
May 14, 2026 South Korea
The Personal Information Protection Commission (PIPC) of South Korea announced a total of KRW 553.9 million in fines and administrative penalties against Boram Sangjo Development Co., Ltd. and its affiliates for severe data protection failures.
An investigation into the company revealed it had neglected to implement adequate security measures, such as access control mechanisms, leaving its database vulnerable to an external hack that exposed customer information. Additionally, Boram Sangjo committed a serious compliance violation by failing to notify the affected individuals within the legally mandated statutory timeframe after discovering the breach and unlawfully retaining sensitive personal data long past its required retention period instead of securely destroying it.
27. OAIC Updates Guidance on Collection of Personal Information Under APP 3
May 13, 2026 Australia
Australia's Office of the Australian Information Commissioner (OAIC) has updated its guidance on Australian Privacy Principle (APP) 3, which governs the collection of solicited personal information. The revised guidance provides additional clarification on key requirements, including data minimisation, proportionality, fair collection practices, and the requirement to collect only information that is reasonably necessary for an organization's functions and activities.
The update also introduces contemporary examples covering artificial intelligence, facial recognition technology, data scraping, tracking pixels, and data brokering. The revised guidance reflects recent regulatory decisions and provides organizations with practical direction on lawful and compliant personal information collection practices.
28. Philippines NPC Clarifies Personal Data Breach Notification Procedures
May 11, 2026 Philippines
The Philippines National Privacy Commission (NPC) has issued Advisory No. 2026-02, providing additional guidance on the submission of personal data breach notifications through its Data Breach Notification Management System. The advisory clarifies the circumstances under which organizations may request postponement, exemption, alternative notification methods, or extensions relating to breach notification obligations.
The NPC emphasized that submitting such requests does not suspend an organization's existing reporting obligations unless formally approved in writing by the Commission. The guidance also reiterates that failure to comply with breach notification requirements under the Data Privacy Act and related regulations may result in administrative fines and other enforcement actions.
29. OAIC Responds to Global Cyber Incident Affecting Canvas Learning Platform
May 9, 2026 Australia
The Australian Office of the Australian Information Commissioner (OAIC) has acknowledged a global cyber incident affecting Instructure, the provider of the Canvas learning management system used by universities, vocational institutions, and some schools. The National Office of Cyber Security is coordinating the response, while affected individuals are encouraged to contact their educational institution or Instructure directly for incident-specific information.
The OAIC also reminded organizations of their privacy complaint handling obligations and encouraged affected individuals to first raise concerns directly with the relevant entity. The incident highlights the continued cybersecurity risks facing the education sector and the importance of robust incident response and user protection measures.
30. China Approves New Cybersecurity, Privacy, and AI Security Standards
May 9, 2026 China
China has approved 10 new national cybersecurity and data security standards aimed at strengthening compliance requirements across personal information protection, data governance, and artificial intelligence. Developed by the National Information Security Standardization Technical Committee (TC260), the standards address areas including sensitive personal information processing, automated decision-making systems, compliance auditing, AI model trustworthiness, and data lifecycle management.
The new standards also establish baseline requirements for data classification, data grading, and cross-border data transfers. Organizations operating in China or processing data in connection with Chinese entities should assess the impact of these developments and review their compliance frameworks accordingly.
establishing a comprehensive legal framework governing both domestic and foreign entities engaged in e-commerce activities in the country, as well as the National Standards Strategy for 2026–2035, a forward-looking initiative aimed at thoroughly modernizing the country's national standards system to foster innovation and global competitiveness.
Moreover, the Law on Electronic Commerce takes effect on July 1, 2026, and introduces stricter disclosure and registration requirements, along with defined responsibilities for platform operators, and grants authorities broad enforcement powers, including sanctions, access restrictions, and potential criminal liability for violations.
In parallel, Vietnam has launched its National Standards Strategy for 2026–2035, aimed at modernizing the country's standards framework and promoting innovation. The strategy targets greater alignment with international standards, including harmonizing 75% of national standards with global frameworks by 2030.
32. China Issues New Rules for Online Marketing of Financial Products
May 1, 2026 China
China's financial and regulatory authorities have jointly issued the Measures for the Administration of Online Marketing of Financial Products, establishing a comprehensive framework for the online promotion of financial services. Effective 30 September 2026, the rules apply to financial institutions and third-party internet platforms involved in marketing financial products.
The measures impose stricter requirements on marketing content, prohibit misleading claims such as "low threshold" or "instant approval" for loan products, and restrict unlicensed entities from using financial terminology in apps and trademarks. The framework also clarifies the responsibilities of financial institutions and online platforms, strengthens oversight of algorithmic recommendations and livestream marketing, and aims to enhance consumer protection in the digital financial services sector.
33. South Korean Regulator Fines Lotte Card Following Linked Information Data Breach
May 1, 2026 South Korea
South Korea's Broadcasting and Communications Commission (KCC) has imposed a fine of KRW 112.5 million on Lotte Card for failing to implement adequate safeguards to protect linked information (CI), a unique identifier used for online identity verification. The enforcement action followed a data breach in which hackers exploited security weaknesses and accessed personal information, including linked information and resident registration numbers.
The investigation found that Lotte Card failed to establish key security measures, including internal policies and incident response procedures for handling linked information. The KCC also issued corrective recommendations and indicated that it will strengthen oversight of organizations processing sensitive identifiers to enhance user protection and prevent similar incidents.
34. Vietnam Expands Digital Identity & Data Governance
May 1, 2026 Vietnam
Vietnam has introduced Decree No. 88/2026/ND-CP, requiring educational institutions to create and maintain lifelong learning profiles and integrate them with the national VNeID digital identity platform. The decree expands Vietnam’s digital identity ecosystem by linking educational records to a centralized identification framework and promoting interoperability across government systems.
The initiative may support digital credential verification, workforce planning, and future AI-driven public services. Organizations processing educational data should assess whether existing governance, security, transparency, and data-sharing practices remain adequate as educational records become increasingly integrated into the national digital identity infrastructure.
35. New Zealand Introduces New Transparency Requirements for Indirect Data Collection
May 1, 2026 New Zealand
A new Information Privacy Principle (IPP 3A) under New Zealand's Privacy Act came into force on 1 May 2026, introducing notification requirements for organizations that collect personal information indirectly. Under the new rule, agencies must generally inform individuals when their personal information is obtained from a third party rather than directly from them, unless a specific exception applies.
The reform aims to increase transparency around personal information handling and address concerns identified during the European Union's assessment of New Zealand's data protection framework. The change also supports New Zealand's efforts to maintain its EU adequacy status, which facilitates the transfer of personal data from the EU.
36. Bangladesh Enacts Personal Data Protection Act
May 1, 2026 Bangladesh
Bangladesh has formally enacted the Personal Data Protection Act, 2026, replacing the Personal Data Protection Ordinance and establishing the country's first comprehensive data protection framework.
The Act applies not only to organizations operating within Bangladesh but also to entities outside the country that process personal data relating to individuals in Bangladesh, significantly expanding its territorial scope. The legislation introduces key obligations for controllers and processors, including requirements relating to lawful processing, consent, transparency, security safeguards, and accountability. It also grants individuals rights over their personal data, including rights of access, correction, and withdrawal of consent. In addition, the Act empowers the Data Protection Authority to investigate violations and impose penalties of up to BDT 5 million for non-compliance.
The enactment marks a major step in Bangladesh's evolving privacy and data governance regime.
Taiwan's Ministry of Finance has announced draft updates to cybersecurity management regulations for non-government agencies, initiating a 60-day public comment period to align the framework with the national Cyber Security Management Act.
NOYB has filed a complaint with the Austrian Data Protection Authority alleging that LinkedIn violates GDPR Article 15 by gatekeeping personal data behind a paywall. The dispute centers on profile visit data, which LinkedIn reportedly provides only to Premium members while denying free access requests. NOYB argues that personal data must be accessible at no cost and is calling for a formal investigation and fines to ensure LinkedIn complies with transparency mandates.
Ireland’s Data Protection Commission (DPC) has launched a formal inquiry into Infinite Styles Services Co. Ltd. (SHEIN Ireland) to investigate the legality of personal data transfers to China. The probe will determine if the fast-fashion giant is meeting GDPR standards regarding data processing principles, transparency, and the strict conditions for third-country transfers.
California SB 923, which extends deletion rights to include data acquired from third parties and brokers, is progressing in the legislature.
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
Enterprises are deploying autonomous AI agents into production faster than they can secure them, and the best practices for securing this complex new landscape are still being...
In 2026, the convergence of cloud expansion, SaaS proliferation, and agentic AI adoption has fundamentally changed the data security challenge, making Data Security Posture...
Explore Bangladesh’s Personal Data Protection Act, 2026, including its key provisions, data subject rights, compliance requirements, and business impact.
Access the whitepaper and learn how to operationalize core privacy controls across the AI lifecycle to ensure compliance, accountability, and defensible AI use.
Discover why disconnected security findings create hidden breach paths, why 57% of organizations can't prove data flows, and how to identify toxic risk combinations...
Map the OWASP Top 10 risks for agentic AI to enterprise-grade controls, identity, data security, guardrails, monitoring, and governance to stop autonomous AI abuse.
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...