Announcing Agent Commander - The First Integrated solution from Veeam + Securiti.ai enabling the scaling of safe AI agents

View

Veeamon Tour'26 - Data & AI Trust CONVERGE for the Agentic Era

View

Privacy Regulation Roundup: Top Stories of May 2026

Watch: May's Privacy Pulse - All Major Highlights

A quick overview of global privacy headlines you cannot afford to miss.

Play Video
Contributors

Yasir Nawaz

Digital Content Producer at Securiti

Aiman Kanwal

Assoc. Data Privacy Analyst at Securiti

Faqiha Amjad

Associate Data Privacy Analyst at Securiti

Aamina Shekha

Associate Data Privacy Analyst at Securiti

Published June 9, 2026 / Updated June 15, 2026

Editorial

From Reactive Compliance to Proactive Accountability

Privacy regulators worldwide are increasingly moving beyond traditional notice-and-consent models toward proactive accountability and risk prevention. This month's developments reveal three clear trends: heightened scrutiny of children's privacy and online safety, stronger enforcement of data minimization and retention obligations, and growing expectations for organizations to embed privacy controls into products, AI systems, and digital infrastructure by design. Regulators in jurisdictions such as South Korea, the UK, California, and the EU are focusing less on isolated compliance failures and more on whether organizations can demonstrate ongoing governance, effective safeguards, and responsible use of personal data. At the same time, governments are advancing digital identity frameworks, AI oversight measures, and cybersecurity requirements, signaling greater integration between privacy, security, and digital governance.

Organizations should expect regulators to increasingly assess not just what data is collected, but whether the entire data ecosystem has been designed to manage risk before harm occurs.

North & South America Jurisdiction

1. Connecticut Governor Signs Bill Expanding Consumer Data Privacy Rights

May 29, 2026
Connecticut, United States

The Connecticut Consumer Privacy and Protection Act (SB 4) has been signed into law by Governor Ned Lamont. This legislation expands upon Connecticut's existing framework to introduce statutory consumer data protections, mandate registration requirements for corporate data brokers, and establish regulatory limits on commercial surveillance pricing and media broadcast volumes.

The law regulates the operations of third-party data brokers by mandating them to register annually with the state and pay a mandatory operational fee. In addition, the legislation directs the Department of Consumer Protection to establish a centralized, statewide deletion registry, which will allow state residents to simultaneously demand the erasure of their personal files from all registered corporate databases at once. Furthermore, SB 4 creates strict consumer barriers against the unauthorized sale or transfer of precise geolocation data, facial recognition metrics, biometric tracking, and neural inputs. Under this law, commercial entities utilizing automated data profiling must provide consumers with explicit disclosures when implementing individualized pricing systems for consumer goods.

Private entities and tech firms operating in Connecticut must prepare for a structured compliance rollout, as the core privacy provisions and restrictions are scheduled to take effect on October 1, 2026, with the full rollout of the data broker registration registry finalized by January 1, 2027.

Read More

2. California Attorney General Sues Chrome Holding Co. Over Genetic Data Breach

May 28, 2026
California, United States

California Attorney General Rob Bonta filed a lawsuit against Chrome Holding Co., formerly known as 23andMe, regarding the company’s alleged failure to protect the sensitive genetic and personal information of millions of users during a 2023 data breach.

The complaint alleges that the company maintained inadequate security procedures, which allowed threat actors to operate undetected within its systems for five months by utilizing "credential stuffing" and exploiting coding errors in its "DNA Relatives" feature. Furthermore, the state contends that the company made misleading statements regarding the adequacy of its safeguards and downplayed the severity of the incident, which resulted in the unauthorized access of ancestry reports, health predispositions, and family histories. The lawsuit seeks civil penalties for alleged violations of the California Consumer Privacy Act and the Genetic Information Privacy Act.

This legal action highlights the growing regulatory focus on the unique sensitivity of genomic data, signaling that private entities holding biometric or health-related information face heightened liability and stricter enforcement of data security obligations under state privacy laws.

Read More

3. New Mexico Jury Finds Meta Liable for Endangering Minors

March 24, 2026
New Mexico, United States

The New Mexico Department of Justice announced that a jury found Meta Platforms, Inc. liable for misleading consumers regarding platform safety and endangering children. Following a 2023 investigation, the court ordered Meta to pay $375 million in civil penalties under the state’s Unfair Practices Act.

The evidence presented during the trial established that Meta’s design features facilitated child exploitation and were intentionally structured to foster addiction among young users. The verdict highlighted that, despite public commitments to safety, the company’s platforms exposed minors to sexual abuse and online solicitation. This legal action serves as one of the most significant state-level financial penalties against a social media entity for child safety failures.

This court decision signals a transition from regulatory warnings to severe financial consequences for design-based harms, reinforcing that private entities may be held legally accountable for the inherent architecture and addictive nature of their digital products.

Read More

4. Connecticut Attorney General Launches Investigation Into Roblox

May 22, 2026
Connecticut, United States

Attorney General William Tong launched a formal investigation into Roblox to examine the platform's safety protocols and its impact on minor users. The inquiry focuses on the company’s age-verification processes, the effectiveness of its content moderation, and its compliance with consumer protection laws regarding user safety and data privacy.

State officials have requested internal documentation and data regarding user demographics and platform revenue to assess whether current safeguards sufficiently protect younger audiences from exposure to unsuitable content. This action indicates a shift toward increased regulatory scrutiny of social gaming platforms, suggesting that private entities in the gaming sector will be held to the same compliance and safety standards as traditional social media companies.

Read More

5. Texas Attorney General Reaches Settlement With LG Electronics

May 11, 2026
Texas, United States

Texas Attorney General Ken Paxton announced a major settlement with LG Electronics U.S.A., Inc. (LG) to resolve allegations that the company violated the Texas Deceptive Trade Practices Act.

Under the terms of the settlement, LG is prohibited from collecting consumers' viewing data via Automatic Content Recognition technology without explicit, informed consent. To ensure future transparency, LG must implement upfront disclosures through prominent pop-ups on smart televisions and its official website detailing data collection practices. Furthermore, the company is required to provide streamlined opt-outs, ensuring a simple and user-friendly mechanism for consumers to withdraw from data collection agreements.

Notably, the settlement also addresses state concerns regarding international surveillance by explicitly prohibiting the transfer or sharing of any collected viewing data with the Chinese Communist Party. Following a similar agreement with Samsung, this settlement reinforces a state-led effort to eliminate 'dark patterns' in smart TV interfaces and hold manufacturers accountable for deceptive data practices.

Read More

6. California’s AG Partners With DAs & CPPA To Secure Landmark $12 Million Settlement With General Motors

May 8, 2026
California, United States

California’s Attorney General Rob Bonta has partnered with several district attorneys and the California Privacy Protection Agency (CPPA) to secure a $12.75 settlement with General Motors over its alleged sale of location and driving data of thousands of Californians to two data brokers.

The investigation revealed that between 2020 and 2024, General Motors collected sensitive geolocation and driving behavior data through its OnStar service and sold it to data brokers to create "driver-rating" products for insurance companies. Now, as part of the settlement, General Motors must pay $12.75 million in civil penalties and delete retained driving data within 180 days (unless express consent is given). It is also banned from selling driving data to brokers for the next five years.

This settlement is pivotal as it marks the first time the “data minimization” principle has been enforced by a regulator. For private entities, this reinforces the fact that keeping or repurposing consumer data beyond its original intent is a high-stakes liability.

Read More

7. CPPA Sends Letter To House Committee Opposing SECURE Data Act

May 1, 2026
California, United States

The California Privacy Protection Agency (CPPA) has issued a letter to the House Energy and Commerce Committee expressing its opposition to the proposed SECURE Data Act.

In the letter, the agency opposes the broad preemption provision in the proposed law, stating that it would supersede many existing rights under the California Consumer Privacy Act and the Delete Act, rendering the DROP platform ineffective while also expressing concern about the inability of businesses to honor opt-out signals affecting their ability to enforce consumer rights.

Read More

8. House Energy and Commerce Committee Introduces SECURE Data Act

May 1, 2026
United States

The House Energy and Commerce Committee has introduced the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act (SECURE Data Act). Registered as HR 8413, the bill seeks to establish a comprehensive federal framework for consumer privacy.

The SECURE Data Act applies to any organization that meets one of two standards: it must either process the personal data of more than 200,000 consumers annually and have an annual gross revenue of $25,000,000 or more, or process the personal data of 100,000 or more consumers annually while deriving 25% or more of its annual gross revenue from the sale of personal data.

Key provisions of the SECURE Data Act include several consumer rights, such as the right to access, correct, and delete personal data, as well as the right to portability. Additionally, the Act mandates opt-out mechanisms for targeted advertising, data sales, and significant automated profiling, marking a major step toward uniform federal data protection standards.

Read More

Europe & Africa Jurisdiction

9. ICO Warns Platforms Over Inadequate Age Assurance Measures

May 21, 2026
United Kingdom

The UK ICO has raised concerns about the limited progress made by major social media platforms in preventing underage users from accessing age-restricted services. Following engagement with platforms including TikTok, Snapchat, Facebook, Instagram, YouTube, and X, the regulator stated that it does not yet have confidence that effective and privacy-friendly age assurance measures are in place.

The ICO warned that children's personal data may continue to be processed on platforms they should not be able to access and indicated it is prepared to use its enforcement powers, including formal investigations and sanctions, if progress remains insufficient.

The statement reinforces growing regulatory expectations around age assurance and children's online privacy.

Read More

10. ICO Reminds the UK Businesses to Prepare for New Data Protection Complaints Requirements

May 19, 2026
United Kingdom

The UK ICO has reminded organisations that, from 19 June 2026, the Data (Use and Access) Act 2025 will require all businesses to implement a formal data protection complaints process. Organisations must provide individuals with a clear way to submit complaints, acknowledge complaints within 30 days, investigate concerns without undue delay, keep complainants informed, and communicate outcomes.

The ICO has encouraged businesses, particularly SMEs, to review its guidance and prepare for compliance ahead of the implementation date. The regulator emphasized that effective complaint handling not only supports legal compliance but can also strengthen customer trust and reduce the likelihood of regulatory escalation.

Read More

11. ICO Advises Government on Privacy-Friendly Online Advertising Reforms

May 18, 2026
United Kingdom

The UK ICO has published advice to the government recommending changes to PECR rules governing online advertising. The regulator suggests that certain low-risk advertising activities, particularly contextual advertising that does not rely on extensive tracking or profiling, could potentially operate without consent requirements under Regulation 6.

The ICO's proposal aims to encourage the adoption of privacy-enhancing advertising models while maintaining consent requirements for more intrusive forms of behavioral advertising. Although no legal changes have been made yet and existing PECR obligations remain in force, the proposal signals a possible shift towards a more risk-based approach to online advertising regulation and the use of cookies and similar tracking technologies.

Read More

12. The EDPB Adopts Opinion Concerning the Improvement of the Finnish Ombudsman's Draft Accreditation Requirements for GDPR Certification Bodies

May 13, 2026

The EDPB has issued Opinion 13/2026 on Finland’s proposed accreditation requirements for GDPR certification bodies under Article 43 GDPR. While supporting the overall framework, the Board recommended several refinements to improve consistency across the EEA and strengthen clarity regarding the independence, expertise, and responsibilities of certification bodies.

The recommendations include clarifying personnel qualification requirements, ensuring responsibilities are appropriately assigned to certification bodies, and removing provisions that could expand assessments beyond the intended certification scope. The Finnish Data Protection Ombudsman has two weeks to respond before the accreditation requirements are finalized.

Read More

13. Russmedia Judgment Expands GDPR Responsibilities for Online Platforms

May 12, 2026
Germany

The CJEU's Russmedia ruling clarifies that online platforms may be considered GDPR controllers where they have their own commercial interest in disseminating personal data. The court held that platforms must implement effective measures to remove unlawful personal content once notified and take reasonable steps to prevent its re-publication.

According to guidance from the Hamburg DPA, these principles may also apply to social media platforms that use personal data for advertising or other commercial purposes. The decision reinforces expectations for platforms to adopt risk-based safeguards, particularly where sensitive personal data is involved, while balancing data protection obligations against freedom of expression rights.

Read More

14. The Belgian DPA Fines Isabel SA €120,000 For GDPR Violations, Including Misqualifying Itself As a Data Processor and Collecting Excessive Data

May 12, 2026
Belgium

The Belgian DPA has fined Isabel €120,000 after it received a complaint on March 29, 2021, concerning the authentication process of TruliUs, a service developed by Isabel that enabled individuals to identify and authenticate themselves on behalf of a company on partner digital platforms.

The complainant, a company manager, raised concerns about discrepancies between the data described in TruliUs' privacy statement and the data actually collected, and questioned the relevance of collecting data such as nationality, ID card photo, place of birth, and date of birth. The complainant also reported that two emails sent to Isabel's Data Protection Officer (DPO) on March 11, 2021, and March 19, 2021, to exercise their right of access, went unanswered.

Consequently, the Belgian DPA found that Isabel violated Articles 5(1)(a), 5(1)(c), 5(2), 12(1), 13, 15(1), and 25(2) of the GDPR, by misqualifying itself as a processor for the TruliUs authentication and identification processing, when it should have been qualified as a data controller, thereby failing to assume the obligations incumbent upon a controller.

Read More

15. Belgian DPA Fines Company €176,950 for Retaining Former Employee's Active Mailbox

May 12, 2026
Belgium

The Belgian DPA has fined a technology company €176,950 after finding that it failed to deactivate a former consultant's email account for several months following her departure. While the regulator accepted that retaining the mailbox for one month to notify contacts of the individual's departure was justified, it found that the company lacked a legal basis for continued processing thereafter.

The DPA also criticized the company for failing to demonstrate that appropriate safeguards were in place to protect the confidentiality and integrity of the mailbox.  The decision highlights the importance of timely offboarding procedures, mailbox deactivation, and maintaining adequate records to demonstrate GDPR compliance.

Read More

May 8, 2026
Latvia

The Data State Inspectorate (DVI) has published a guide that addresses common issues with cookie banners and freedom of consent on websites.

In this guide, the DVI has reminded website operators that users must be given a genuine and informed choice when consenting to cookies. Following inspections and complaints, the regulator identified several recurring issues, including the use of cookies before consent is obtained, misleading cookie banner designs, incomplete information about cookie usage, and non-functional consent mechanisms.

The authority emphasized that consent for analytics and marketing cookies must be freely given, specific, informed, and unambiguous. It also reiterated that continued browsing, closing a banner, or consent obtained without a meaningful opt-out option does not constitute valid consent under data protection rules.

Read More

17. CNIL Issues Guidance on Creditworthiness Assessments and Automated Decision-Making

May 7, 2026
France

The French CNIL has published recommendations aimed at improving transparency and data protection in creditworthiness assessments. The guidance emphasizes that lenders should collect only data necessary for evaluating a borrower's ability to repay, clearly explain how personal data is used, and provide meaningful information about credit scoring and automated decision-making processes.

The CNIL also highlights individuals' rights to obtain explanations of automated decisions, request human review, and challenge outcomes. In addition, it recommends limiting the retention and use of historical payment incident data to prevent individuals from being unfairly disadvantaged over the long term.

Read More

18. EU Commission Advances Privacy-Preserving Age Verification Framework

May 1, 2026
France

The European Commission has adopted a recommendation encouraging Member States to deploy privacy-preserving age verification solutions by the end of 2026. The proposed framework allows users to prove they are above a certain age threshold without disclosing their exact age or identity, using anonymous proof-of-age technologies integrated with the European Digital Identity Wallet.

The initiative forms part of the EU's broader efforts to protect minors online and support compliance with the Digital Services Act. The Commission will also establish an EU-wide age verification scheme and a list of trusted providers to help ensure age verification solutions meet consistent privacy, security, and cybersecurity standards across the EU.

Read More

May 1, 2026
Italy

Italy's Competition Authority has concluded investigations into DeepSeek, Mistral AI, and NOVA AI after the companies agreed to strengthen transparency regarding the risk of AI-generated “hallucinations” - inaccurate or misleading outputs produced by generative AI systems. The cases were closed without findings of infringement following the acceptance of voluntary commitments.

The companies agreed to introduce prominent warnings within their websites and applications, enhance pre-contractual information on the limitations and reliability of AI-generated content, and encourage users to verify outputs independently. DeepSeek is also committed to investing in technical measures to reduce hallucinations, while acknowledging that the risk cannot currently be eliminated entirely.

Read More

20. Germany's BSI Introduces Cloud Sovereignty Assessment Framework

May 1, 2026
Germany

Germany's Federal Office for Information Security (BSI) has published the C3A (Criteria Enabling Cloud Computing Autonomy), a new framework designed to help organizations assess the sovereignty and autonomy of cloud services. The criteria aim to provide greater transparency around factors such as provider influence, data localization, operational control, and the ability to use cloud services independently within a given risk context.

Building on the BSI's existing C5 cloud security framework and aligned with the European Cloud Sovereignty Framework (EU CSF), C3A enables cloud providers to demonstrate compliance through audits and allows customers to define sovereignty requirements based on their specific risk profiles and regulatory needs.

Read More

21. Italian DPA Issues Guidelines on Tracking Pixels in Emails

May 1, 2026
Italy

The Italian Data Protection Authority has published new guidelines governing the use of tracking pixels in emails, emphasizing the need for greater transparency and user control. The regulator clarified that tracking pixels, which enable senders to monitor when emails are opened and collect behavioral data, generally require prior, free, specific, and informed consent.

The guidelines also require organizations to provide clear privacy notices, offer simple mechanisms for withdrawing consent, and implement privacy-by-design measures to minimize user identifiability and unnecessary data sharing. Organizations using tracking pixels will have six months from publication of the guidelines to achieve compliance.

Read More

Asia Jurisdiction

22. South Korean Regulator Fines Organizations for Data Security Failures

May 28, 2026
South Korea

South Korea's Personal Information Protection Commission (PIPC) has imposed enforcement sanctions and fines totaling KRW 558.6 million against five organizations for significant personal data protection failures. The violations included inadequate security measures and insufficient oversight of entrusted data processing activities.

As part of the enforcement action, the affected organizations, including the Ministry of the Interior and Safety and Miso Tech, have been directed to address identified weaknesses, implement corrective measures, and strengthen compliance with personal information protection requirements. The decision underscores the PIPC's continued focus on accountability, security safeguards, and effective vendor oversight.

Read More

23. China Targets Apps and SDKs for Personal Information Violations

May 21, 2026
China

China's Ministry of Industry and Information Technology (MIIT) has identified 31 mobile applications and software development kits (SDKs) for violating users' personal information rights following a recent compliance inspection. The issues reportedly included unauthorized collection of personal information and improper user interface practices, such as disruptive or misleading window redirects.

The affected apps and SDK providers have been ordered to rectify the identified violations in accordance with applicable legal requirements. The MIIT warned that further enforcement measures may be taken if organizations fail to implement corrective actions effectively, reflecting China's continued focus on strengthening oversight of mobile applications and personal information protection.

Read More

24. South Korea Shifts to Risk-Based Privacy Oversight Framework

May 21, 2026
South Korea

South Korea's Personal Information Protection Commission (PIPC) has announced a transition to a prevention-oriented, risk-based privacy management system, with enhanced inspections beginning in June 2026. Under the new approach, sectors will be classified according to the level of personal data risk, with high-risk industries such as platforms, financial institutions, public bodies, edtech providers, and healthcare organizations subject to more intensive oversight.

The initiative also promotes broader adoption of Privacy by Design (PbD) principles, increased investment in privacy safeguards, stronger supply chain oversight, and enhanced monitoring of emerging technologies such as AI and IoT devices. The move reflects a growing regulatory focus on proactively identifying and mitigating privacy risks before incidents occur.

Read More

25. South Korea Strengthens PIPA Fine Calculation Framework

May 18, 2026
South Korea

South Korea's Personal Information Protection Commission (PIPC) has announced amendments to the Enforcement Decree of the Personal Information Protection Act (PIPA) and the Standards for Imposing Fines. Under the revised framework, administrative fines will be calculated based on the higher of a company's revenue from the previous fiscal year or its average revenue over the preceding three years.

The amendments, effective for violations occurring after 19 May 2026, are expected to strengthen enforcement and increase potential financial exposure for organizations that fail to comply with South Korea's personal information protection requirements.

Read More

26. South Korea’s PIPC Announces Almost KRW 553.9 Million In Fines Against Boram Sangjo Development

May 14, 2026
South Korea

The Personal Information Protection Commission (PIPC) of South Korea announced a total of KRW 553.9 million in fines and administrative penalties against Boram Sangjo Development Co., Ltd. and its affiliates for severe data protection failures.

An investigation into the company revealed it had neglected to implement adequate security measures, such as access control mechanisms, leaving its database vulnerable to an external hack that exposed customer information. Additionally, Boram Sangjo committed a serious compliance violation by failing to notify the affected individuals within the legally mandated statutory timeframe after discovering the breach and unlawfully retaining sensitive personal data long past its required retention period instead of securely destroying it.

Read More

27. OAIC Updates Guidance on Collection of Personal Information Under APP 3

May 13, 2026
Australia

Australia's Office of the Australian Information Commissioner (OAIC) has updated its guidance on Australian Privacy Principle (APP) 3, which governs the collection of solicited personal information. The revised guidance provides additional clarification on key requirements, including data minimisation, proportionality, fair collection practices, and the requirement to collect only information that is reasonably necessary for an organization's functions and activities.

The update also introduces contemporary examples covering artificial intelligence, facial recognition technology, data scraping, tracking pixels, and data brokering. The revised guidance reflects recent regulatory decisions and provides organizations with practical direction on lawful and compliant personal information collection practices.

Read More

28. Philippines NPC Clarifies Personal Data Breach Notification Procedures

May 11, 2026
Philippines

The Philippines National Privacy Commission (NPC) has issued Advisory No. 2026-02, providing additional guidance on the submission of personal data breach notifications through its Data Breach Notification Management System. The advisory clarifies the circumstances under which organizations may request postponement, exemption, alternative notification methods, or extensions relating to breach notification obligations.

The NPC emphasized that submitting such requests does not suspend an organization's existing reporting obligations unless formally approved in writing by the Commission. The guidance also reiterates that failure to comply with breach notification requirements under the Data Privacy Act and related regulations may result in administrative fines and other enforcement actions.

Read More

29. OAIC Responds to Global Cyber Incident Affecting Canvas Learning Platform

May 9, 2026
Australia

The Australian Office of the Australian Information Commissioner (OAIC) has acknowledged a global cyber incident affecting Instructure, the provider of the Canvas learning management system used by universities, vocational institutions, and some schools. The National Office of Cyber Security is coordinating the response, while affected individuals are encouraged to contact their educational institution or Instructure directly for incident-specific information.

The OAIC also reminded organizations of their privacy complaint handling obligations and encouraged affected individuals to first raise concerns directly with the relevant entity. The incident highlights the continued cybersecurity risks facing the education sector and the importance of robust incident response and user protection measures.

Read More

30. China Approves New Cybersecurity, Privacy, and AI Security Standards

May 9, 2026
China

China has approved 10 new national cybersecurity and data security standards aimed at strengthening compliance requirements across personal information protection, data governance, and artificial intelligence. Developed by the National Information Security Standardization Technical Committee (TC260), the standards address areas including sensitive personal information processing, automated decision-making systems, compliance auditing, AI model trustworthiness, and data lifecycle management.

The new standards also establish baseline requirements for data classification, data grading, and cross-border data transfers. Organizations operating in China or processing data in connection with Chinese entities should assess the impact of these developments and review their compliance frameworks accordingly.

Read More

31. Vietnam Gets Two New Laws On E-commerce & Innovation

May 2, 2026
Vietnam

Vietnam’s National Assembly has passed the Law on Electronic Commerce (Law No. 122/2025/QH15),

establishing a comprehensive legal framework governing both domestic and foreign entities engaged in e-commerce activities in the country, as well as the National Standards Strategy for 2026–2035, a forward-looking initiative aimed at thoroughly modernizing the country's national standards system to foster innovation and global competitiveness.

Moreover, the Law on Electronic Commerce takes effect on July 1, 2026, and introduces stricter disclosure and registration requirements, along with defined responsibilities for platform operators, and grants authorities broad enforcement powers, including sanctions, access restrictions, and potential criminal liability for violations.

In parallel, Vietnam has launched its National Standards Strategy for 2026–2035, aimed at modernizing the country's standards framework and promoting innovation. The strategy targets greater alignment with international standards, including harmonizing 75% of national standards with global frameworks by 2030.

Read More

32. China Issues New Rules for Online Marketing of Financial Products

May 1, 2026
China

China's financial and regulatory authorities have jointly issued the Measures for the Administration of Online Marketing of Financial Products, establishing a comprehensive framework for the online promotion of financial services. Effective 30 September 2026, the rules apply to financial institutions and third-party internet platforms involved in marketing financial products.

The measures impose stricter requirements on marketing content, prohibit misleading claims such as "low threshold" or "instant approval" for loan products, and restrict unlicensed entities from using financial terminology in apps and trademarks. The framework also clarifies the responsibilities of financial institutions and online platforms, strengthens oversight of algorithmic recommendations and livestream marketing, and aims to enhance consumer protection in the digital financial services sector.

Read More

33. South Korean Regulator Fines Lotte Card Following Linked Information Data Breach

May 1, 2026
South Korea

South Korea's Broadcasting and Communications Commission (KCC) has imposed a fine of KRW 112.5 million on Lotte Card for failing to implement adequate safeguards to protect linked information (CI), a unique identifier used for online identity verification. The enforcement action followed a data breach in which hackers exploited security weaknesses and accessed personal information, including linked information and resident registration numbers.

The investigation found that Lotte Card failed to establish key security measures, including internal policies and incident response procedures for handling linked information. The KCC also issued corrective recommendations and indicated that it will strengthen oversight of organizations processing sensitive identifiers to enhance user protection and prevent similar incidents.

Read More

34. Vietnam Expands Digital Identity & Data Governance

May 1, 2026
Vietnam

Vietnam has introduced Decree No. 88/2026/ND-CP, requiring educational institutions to create and maintain lifelong learning profiles and integrate them with the national VNeID digital identity platform. The decree expands Vietnam’s digital identity ecosystem by linking educational records to a centralized identification framework and promoting interoperability across government systems.

The initiative may support digital credential verification, workforce planning, and future AI-driven public services. Organizations processing educational data should assess whether existing governance, security, transparency, and data-sharing practices remain adequate as educational records become increasingly integrated into the national digital identity infrastructure.

Read More

35. New Zealand Introduces New Transparency Requirements for Indirect Data Collection

May 1, 2026
New Zealand

A new Information Privacy Principle (IPP 3A) under New Zealand's Privacy Act came into force on 1 May 2026, introducing notification requirements for organizations that collect personal information indirectly. Under the new rule, agencies must generally inform individuals when their personal information is obtained from a third party rather than directly from them, unless a specific exception applies.

The reform aims to increase transparency around personal information handling and address concerns identified during the European Union's assessment of New Zealand's data protection framework. The change also supports New Zealand's efforts to maintain its EU adequacy status, which facilitates the transfer of personal data from the EU.

Read More

36. Bangladesh Enacts Personal Data Protection Act

May 1, 2026
Bangladesh

Bangladesh has formally enacted the Personal Data Protection Act, 2026, replacing the Personal Data Protection Ordinance and establishing the country's first comprehensive data protection framework.

The Act applies not only to organizations operating within Bangladesh but also to entities outside the country that process personal data relating to individuals in Bangladesh, significantly expanding its territorial scope. The legislation introduces key obligations for controllers and processors, including requirements relating to lawful processing, consent, transparency, security safeguards, and accountability. It also grants individuals rights over their personal data, including rights of access, correction, and withdrawal of consent. In addition, the Act empowers the Data Protection Authority to investigate violations and impose penalties of up to BDT 5 million for non-compliance.

The enactment marks a major step in Bangladesh's evolving privacy and data governance regime.

Read More

WHAT'S NEXT:
Key Privacy Developments to Watch For

  • South Korea’s PIPC is shifting toward a prevention-oriented personal information management system, which will introduce heightened sanctions, a whistleblower reward system, and default corporate liability for data breach damages.
  • Taiwan's Ministry of Finance has announced draft updates to cybersecurity management regulations for non-government agencies, initiating a 60-day public comment period to align the framework with the national Cyber Security Management Act.
  • NOYB has filed a complaint with the Austrian Data Protection Authority alleging that LinkedIn violates GDPR Article 15 by gatekeeping personal data behind a paywall. The dispute centers on profile visit data, which LinkedIn reportedly provides only to Premium members while denying free access requests. NOYB argues that personal data must be accessible at no cost and is calling for a formal investigation and fines to ensure LinkedIn complies with transparency mandates.
  • Ireland’s Data Protection Commission (DPC) has launched a formal inquiry into Infinite Styles Services Co. Ltd. (SHEIN Ireland) to investigate the legality of personal data transfers to China. The probe will determine if the fast-fashion giant is meeting GDPR standards regarding data processing principles, transparency, and the strict conditions for third-country transfers.
  • California SB 923, which extends deletion rights to include data acquired from third parties and brokers, is progressing in the legislature.
  • The Louisiana Data Privacy Act (SB 386) has been passed and now awaits the Governor’s signature.

Analyze this article with AI

Prompts open in third-party AI tools.
Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox



More Stories that May Interest You
Videos
View More
Rehan Jalil, Veeam on Agent Commander : theCUBE + NYSE Wired: Cyber Security Leaders
Following Veeam’s acquisition of Securiti, the launch of Agent Commander marks an important step toward helping enterprises adopt AI agents with greater confidence. In...
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...

Spotlight Talks

Spotlight 1:02:06
Consent by proxy: When AI agents start deciding for us
Watch Now View
Spotlight 1:00:41
Future-Proofing for the Privacy Professional
Watch Now View
Spotlight 50:52
From Data to Deployment: Safeguarding Enterprise AI with Security and Governance
Watch Now View
Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Spotlight 47:42
Cybersecurity – Where Leaders are Buying, Building, and Partnering
Rehan Jalil
Watch Now View
Latest
What Anthropic’s Zero Trust for AI Agents Means for the Data Layer View More
What Anthropic’s Zero Trust for AI Agents Means for the Data Layer
Enterprises are deploying autonomous AI agents into production faster than they can secure them, and the best practices for securing this complex new landscape are still being...
DSPM in 2026: Why It Matters More Than Ever View More
DSPM in 2026: Why It Matters More Than Ever
In 2026, the convergence of cloud expansion, SaaS proliferation, and agentic AI adoption has fundamentally changed the data security challenge, making Data Security Posture...
Data Risk Management View More
What Is Data Risk Management?
Learn the ins and outs of data risk management, key reasons for data risk and best practices for managing data risks.
View More
An Overview of Bangladesh’s Personal Data Protection Act, 2026
Explore Bangladesh’s Personal Data Protection Act, 2026, including its key provisions, data subject rights, compliance requirements, and business impact.
EU AI Act: What Changes Now vs What Starts in 2026 View More
EU AI Act: What Changes Now vs What Starts in 2026
Understand the EU AI Act rollout—what obligations apply now, what phases in by 2026, and how providers and deployers should prepare for risk tiers,...
AI Governance Fails When Privacy Controls Stay Disconnected View More
AI Governance Fails When Privacy Controls Stay Disconnected
Access the whitepaper and learn how to operationalize core privacy controls across the AI lifecycle to ensure compliance, accountability, and defensible AI use.
You Can’t Protect What You Can’t See View More
You Can’t Protect What You Can’t See
Discover why disconnected security findings create hidden breach paths, why 57% of organizations can't prove data flows, and how to identify toxic risk combinations...
Agentic AI Security: OWASP Top 10 with Enterprise Controls View More
Agentic AI Security: OWASP Top 10 with Enterprise Controls
Map the OWASP Top 10 risks for agentic AI to enterprise-grade controls, identity, data security, guardrails, monitoring, and governance to stop autonomous AI abuse.
View More
Take the Data Risk Out of AI
Learn how to prepare enterprise data for safe Gemini Enterprise adoption with upstream governance, sensitive data discovery, and pre-index policy controls.
View More
Navigating HITRUST: A Guide to Certification
Securiti's eBook is a practical guide to HITRUST certification, covering everything from choosing i1 vs r2 and scope systems to managing CAPs & planning...
What's
New