Categories

Archives

South Carolina Takes a Hard Line on Age-Appropriate Design – Audits, Parental Controls, Employee Personal Liability, and More

The recently enacted South Carolina Age Appropriate Design Code Act (S.C. Code Sec. 39-80-10 et seq.) (the “Act”) has the potential to become one of the country’s most consequential privacy laws. It combines prescriptive privacy-by-design controls with restrictions on facilitating targeted advertising to minors under 18, and requires annual independent compliance audits and reports that are publicly posted, coupled with unusually aggressive penalties, including potential personal liability for officers and employees for “willful and wanton” violations. Unlike some other states’ privacy laws that have given entities time to make technical and policy changes before their effective date, South Carolina took a different route. The Act took effect immediately upon enactment in February 2026, and the first audit reports were required to be submitted to the South Carolina Attorney General by July 1, 2026. (more…)

EDPB Publishes Draft Guidelines on Anonymisation

On 7 July 2026, the European Data Protection Board published its long-awaited draft Guidelines 02/2026 on Anonymisation. The draft Guidelines – which are intended, once finalised, to replace the former Article 29 Working Party’s Opinion 05/2014 on Anonymisation Techniques – adopt a “relative” approach to identifiability, as endorsed by the EU Court of Justice in the EDPS v SRB case. The practical consequence is that the same dataset can be considered personal data for one party and anonymous for another (i.e., anonymity is not an intrinsic property of the data itself but depends on who holds it and what they can realistically do with it). Organisations that work with data they regard as anonymised (e.g., training AI models or sharing research datasets) may find the draft Guidelines a helpful reference point for reviewing and strengthening existing practices.

What Do the European Data Protection Board’s Web Scraping Guidelines Mean for AI Training Datasets?

On July 7, 2026, the European Data Protection Board (EDPB) published draft guidelines on web scraping for generative AI (Guidelines). The Guidelines are intended to provide practical GDPR guidance in one of the more complex areas of AI development and will be of direct relevance to any organization building or procuring generative AI systems trained on internet-sourced data.

(more…)

White House Issues Executive Orders on Quantum Innovation and Security

On June 22, 2026, the White House issued two Executive Orders:  Ushering in the Next Frontier of Quantum Innovation and Securing the Nation Against Advanced Cryptographic Attacks. By harnessing properties of quantum physics, advanced quantum computers are capable of solving certain classes of computational problems much faster than classical computers, opening new pathways for innovation and new threats to widely used cryptographic security systems. (more…)

EU AI Act Transparency Obligations: Preparing for Compliance by 2 August 2026

From 2 August 2026, organisations will become subject to the transparency obligations set out in Article 50 of the EU AI Act (Regulation (EU) 2024/1689).

Article 50 introduces transparency requirements for providers and deployers in relation to certain AI system functionalities and use cases that may create transparency risks for individuals. Whilst much of the EU AI Act focusses on obligations on high-risk AI systems, Article 50 obligations may also apply to certain limited-risk systems. As a result, many organisations will need to implement governance, disclosure and content-labelling measures to ensure users are appropriately informed about the use of certain AI systems and AI-generated content.

(more…)

EU Lawmakers Reach Provisional Agreement to Delay Key EU AI Act Obligations

On 7 May 2026, following extensive negotiations, the European Council and European Parliament reached a provisional agreement on the EU Digital Omnibus on AI (AI Omnibus) which proposes targeted amendments to the EU Artificial Intelligence Act (AI Act). On 16 June 2026, the European Parliament voted to adopt the provisional agreement — although, formal adoption remains subject to European Council approval.

Cyber Strategy at the AI Frontier: President Trump Releases Executive Order to Promote Advanced Artificial Intelligence Innovation and Security

On June 2, 2026, President Trump issued the Executive Order, Promoting Advanced Artificial Intelligence Innovation and Security. The Executive Order carries forward several priorities included in President Trump’s Cyber Strategy for America, released in March 2026.[1] The Executive Order declares, “It is the policy of the United States to promote AI innovation and security by working collaboratively with the private sector to modernize government and private sector information systems and harden them against external threats; to protect American ingenuity and intellectual property from exploitation and theft by adversaries; and to cultivate America’s advanced AI-enabled capabilities.” (more…)

Risk Analysis in the Crosshairs: Four Recent Ransomware Resolutions Preview the HIPAA Security Rule Amendments

On April 23, 2026, the U.S. Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) announced resolution agreements and corrective action plans with four regulated entities following separate ransomware investigations under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. The settlements are the culmination of OCR investigations into separate ransomware breaches collectively affecting more than 427,000 individuals and involving the exposure of unsecured electronic protected health information (ePHI) – demographic data, Social Security numbers, financial information, lab results, medications, and diagnoses or conditions. Under the settlements, the regulated entities agreed to implement corrective action plans subject to OCR monitoring for two years and pay a total resolution amount of $1,165,000 to OCR.

Upcoming Events

Resources

 

SUBSCRIBE

To receive email alerts when we post a blog entry, please provide your name and email address.