Data Privacy Frontline Report

July 2026

Here are key highlights from July 2026 detailing global news and regulatory updates.

 

US & Canada
  • Canada’s privacy commissioner recognizes the CHEO Research Institute’s Electronic Health Information Laboratory (EHIL) with the 2026 Privacy and Human Rights Award, honoring Dr. Khaled El Emam, founder of IQVIA’s Privacy Analytics and Director of EHIL, for pioneering privacy-enhancing technologies that enable health research, data sharing, and responsible AI.

  • Connecticut strengthens its Data Privacy Act through amendments that took effect on July 1, 2026, expanding coverage to more organizations, broadening sensitive data protections, enhancing consumer rights, and restricting the sale of precise geolocation data.

  • Illinois enacts landmark AI legislation requiring transparency, risk reporting, and first-in-the-nation annual independent audits of powerful AI systems, helping establish a state-driven national framework for AI safety when the law takes effect on January 1, 2028.

  • US Federal Trade Commission (FTC) seeks public comment on a proposed policy statement addressing concerns that AI companies may manipulate system outputs contrary to consumer expectations for objectivity and accuracy, potentially violating federal consumer protection laws.

EMEA
  • EU adopts the Digital Omnibus on AI, simplifying implementation of the AI Act by reducing regulatory overlap, extending key compliance deadlines for high-risk systems, narrowing certain classifications, and expanding support for smaller businesses.
  • EU European Commission adopts guidelines clarifying Article 50 transparency obligations under the AI Act, providing practical direction to AI providers and deployers to ensure consistent compliance when the rules take effect on August 2, 2026.

  • EU European Data Protection Board (EDPB) releases draft anonymization guidelines that help organizations apply a common approach to assessing anonymization under GDPR and has invited public feedback on the proposed framework until October 30, 2026.

  • French data protection authority and AI advisory body publish an exploratory report warning that agentic AI’s autonomous actions, persistent memory, and extensive data flows may heighten privacy, accountability, and cybersecurity risks (article in French).

  • Germany and France agree to deepen cooperation on AI safety, frontier AI model evaluation, and digital sovereignty, while jointly shaping European technology policy and supporting stronger EU capabilities for AI governance (article in German).

  • Greece enacts a national AI law supplementing the EU AI Act, establishing a supervisory framework, stricter testing and enforcement measures, a public-sector AI registry, and expanded regulatory oversight.

  • Spain's data protection authority produces guidance explaining how GDPR principles of data quality, accuracy, and data minimization apply to AI systems, emphasizing that data suitability should be assessed in relation to a processing activity’s purpose and impact on individuals (article in Spanish).

Gain confidence to use and share sensitive data
Find out how our advisory services can help you safely leverage data derived from information about people. Watch this 15-minute webinar.
Watch On-Demand Now
APAC
  • China proposes significant amendments to its national personal information protection standard, introducing enhanced AI governance requirements, expanding the scope of sensitive personal information, and strengthening compliance expectations for organizations processing personal data (article partially behind paywall).

  • Singapore’s data protection authority launches a new federated learning guide and updated synthetic data generation guidance, helping organizations adopt privacy-preserving AI, collaborate on sensitive data, and manage implementation risks.

  • South Korea’s data protection authority urges organizations to strengthen API security by applying data minimization, least-privilege access controls, and regular API reviews to prevent personal information leaks.

  • Thailand's data protection authority launches a public consultation on draft sector-specific guidelines covering 11 industries under the Personal Data Protection Act 2019, providing practical compliance guidance that, while non-binding, is expected to significantly influence regulatory enforcement and industry practices.

Global
  • Industry leaders form the Open Secure AI Alliance to develop and share open AI security tools that strengthen cybersecurity and improve trust in AI systems.

  • United Nations experts release a global scientific assessment of artificial intelligence, concluding that AI offers major societal benefits but warning that current safeguards and governance mechanisms are struggling to keep pace with rapidly advancing capabilities.