Data Privacy Frontline Report

August 2026

Here are key highlights from August 2026 detailing global news and regulatory updates.

 

US & Canada
  • California’s privacy regulator takes its first enforcement action under both the CCPA and Delete Act, fining an Iowa data broker $116K for failing to register as a data broker and unlawfully requiring partial Social Security numbers before Californians could exercise their opt-out rights.
  • US House Energy and Commerce Committee Republicans launch a review of the Federal Trade Commission (FTC), seeking input on possible reforms following Supreme Court rulings that curtailed the agency’s powers, independence, and regulatory authority.
  • US Senate lawmakers advance bipartisan legislation to extend HIPAA-like privacy, security, and breach-notification protections to consumer health data, including information from wearables, apps, and AI-enabled health technologies.
  • US National Institute of Standards and Technology (NIST) seeks public feedback on a new human-centered cybersecurity initiative aimed at improving security outcomes by designing programs and controls around people’s needs, abilities, workflows, and limitations.
  • US organizations launch PACT AI, a coalition of enterprises, AI assurance providers, insurers, and civil society groups aimed at developing standards, policy, and independent verification to promote trustworthy AI adoption.
  • Washington’s Attorney General releases the state’s first Data Privacy Report, highlighting risks from data overcollection, weak consent practices, sensitive-data sales, and data brokers, while recommending stronger privacy protections, enforcement, and public education.
EMEA
  • France’s data protection authority issues guidance on identifying and managing conflicts of interest for Data Protection Officers, emphasizing independence, case-by-case assessments, and remediation measures where DPO responsibilities overlap with decision-making roles (article in French).
  • Latvia’s data protection authority publishes guidance outlining how organizations should respond to personal data leaks, emphasizing risk assessment, breach management, and compliance with GDPR notification and mitigation requirements.
  • Netherlands’ data protection authority urges organizations to prepare for mandatory Fundamental Rights Impact Assessments (FRIAs) for high-risk AI systems by 2027, launching guidance and a pilot program to build practical experience (article in Dutch).
  • Poland’s data protection authority publishes practical AI readiness checklists to help organizations assess GDPR compliance before deploying or using AI systems, while highlighting the need for risk, privacy, and fundamental-rights impact assessments (article in Polish).
  • UK’s National Cyber Security Centre issues guidance on managing the risks of agentic AI, urging organizations to use safeguards, sandboxing, monitoring, and human oversight to prevent unintended autonomous actions while realizing productivity benefits.
  • UK data protection authority launches a public consultation on draft guidance for anonymization and pseudonymization in research, archiving, and statistical uses, seeking feedback to improve clarity and practical support before final publication. 

Gain confidence to use and share sensitive data
Find out how our advisory services can help you safely leverage data derived from information about people. Watch this 15-minute webinar.
Watch On-Demand Now
APAC
  • Australia releases proposals for a second wave of Privacy Act reforms that would expand individual rights, strengthen digital identity protections, introduce a “fair and reasonable” test for data handling, and enhance organizational accountability.
  • Australia publishes a report from the AI Safety Institute outlining a framework to assess and manage risks from interacting AI agents, identifying governance tiers, potential failures, controls, and responsibility gaps.
  • China proposes enhanced data protection rules for organizations handling the personal information of more than 10 million individuals, requiring stronger governance, stricter data localization, expanded transparency, and heightened compliance oversight.
  • Hong Kong’s privacy commissioner issues new guidance on agentic AI, outlining privacy risks and practical safeguards while emphasizing that organizations remain accountable for compliance with personal data protection requirements.
  • Indonesia publishes the long-awaited implementing regulation for its Personal Data Protection Law, introducing detailed requirements for consent, records management, DPIAs, cross-border transfers, and privacy governance ahead of its January 2027 effective date.
  • South Korea approves a new AI data-use framework that permits, with regulatory approval, the use of personal data beyond anonymized and pseudonymized datasets for certain public-interest AI development projects.
LATAM
  • Argentina reintroduces a comprehensive reform of its personal data protection law, proposing stronger accountability measures, updated consent rules, refined erasure rights, and new conditions for international data transfers.