Data Privacy Frontline Report

September 2026

Here are key highlights from September 2026 detailing global news and regulatory updates.

 

US & Canada
  • California expands consumer privacy protections by closing a loophole in the California Consumer Privacy Act (CCPA), requiring businesses to ensure that personal information deleted at a consumer’s request is also deleted by third parties that received it.
  • Delaware significantly revises its consumer privacy law by lowering applicability thresholds, imposing new obligations on third parties that receive personal data, and strengthening protections for sensitive data, profiling, and automated decision-making.
  • Illinois consumers file a new class action lawsuit alleging that a major retailer collected and shared consumers' voiceprints without the notice and consent required by the Illinois Biometric Information Privacy Act (BIPA).
  • Maryland unveils a new artificial intelligence framework centered on protecting individuals, supporting workers, and safeguarding children, while advancing proposals for stronger AI oversight, privacy protections, and accountability measures.
  • Texas attorney general warns businesses and nonprofits about a surge in potentially fraudulent demand letters alleging website privacy violations under the California Invasion of Privacy Act (CIPA), urging recipients to seek legal counsel before responding or making payments.
  • US Federal Trade Commission (FTC) withdraws its 2021 policy statement on breaches involving health apps and connected devices, concluding that the guidance is no longer necessary following updates to the Health Breach Notification Rule in 2024.
  • US state governors call for federal leadership and nationwide guardrails on AI, arguing that a patchwork of state-level rules cannot adequately address the risks posed by rapidly advancing AI technologies.
EMEA
  • EU European Commission spokesperson warns AI developers that incident reporting under the EU AI Act must be detailed and substantive rather than a compliance formality, emphasizing the need for clear information on incidents and corrective measures.
  • EU European Data Protection Board (EDPB) adopts a harmonized methodology for calculating GDPR fines and finalizes guidelines clarifying the interaction between the Digital Services Act (DSA) and the GDPR.
  • France’s data protection authority fines a private hospital €500,000 after a health data breach exposed the information of more than 524,000 patients, citing inadequate security measures and failures to properly notify affected individuals under the GDPR (article in French).
  • Ireland’s data protection authority fines the country’s publicly funded healthcare system €645,000 and imposes corrective measures after finding serious data protection failings in the storage and security of paper medical records following multiple unauthorized access incidents at former hospital sites.
  • Kenya's data protection authority issues new guidance on cross-border data transfers, providing organizations with detailed requirements for international data transfers while introducing Kenya-specific rules that differ in key respects from the GDPR framework.
  • Poland's data protection authority announces additional inspections of healthcare organizations following a major patient data breach, with a focus on assessing how medical providers protect sensitive health information and implement security safeguards (article in Polish).
  • UK Information Commissioner's Office (ICO) formally transitions to the new Information Commission under a board-led governance structure and opens a new headquarters in Manchester, marking a new phase in the regulator’s oversight of data protection and information rights.
Gain confidence to use and share sensitive data
Find out how our advisory services can help you safely leverage data derived from information about people. Watch this 15-minute webinar.
Watch On-Demand Now
APAC
  • Chinese regulators introduce new data security measures requiring organizations that process “important data” to conduct annual risk assessments and report the results to authorities, while strengthening regulatory oversight of data security compliance.
  • South Korea brings into force major amendments to its Personal Information Protection Act (PIPA), introducing stronger breach notification requirements, enhanced executive accountability, and significantly higher penalties for serious or repeated data protection violations.
LATAM
  • Brazil’s data protection authority launches a public consultation and hearings on proposed updates to its inspection and administrative sanctions regulations, seeking to align enforcement procedures with its expanded responsibilities for online platform oversight, children's privacy, and digital safety (article in Portuguese).
Global
  • Global health platform is found to be using pixel tracking and other web trackers that transmit information about doctor searches and appointment bookings to third-party advertising and social media platforms.