USA: Senators introduce SIMS Act.
A bipartisan group of US senators has introduced the SIMS Act to impose criminal and civil penalties on AI chatbot operators that simulate minors in sexually explicit contexts.
Learn more: bit.ly/4omE162
UK: The ICO has issued final guidance clarifying how UK GDPR and PECR apply to consumer IoT products, emphasizing privacy-by-design, valid consent, transparency, DPIAs, and ongoing security.
Explore more: bit.ly/4xqSgLs
Canada: OPC finds X and xAI breached PIPEDA over Grok-generated harmful synthetic imagery and will monitor new safeguards through ongoing reporting and audits.
Check it out: bit.ly/3SDMsy0
EU: EDPB adopts common GDPR data breach notification template for public consultation to standardize and simplify Article 33 reporting for organizations and DPAs.
Check it out: bit.ly/4ecIunm
France: CNIL publishes guidance on electronic communications for prospects and customers.
CNIL's guidance clarifies rules for email and SMS prospecting, transactional messages, and relational communications.
Check it out: bit.ly/4efnkF8
Brazil: ANPD begins monitoring app stores and operating systems under Digital ECA to assess compliance with age verification and age signal duties under Brazil's Digital ECA.
Learn more: bit.ly/3QgHGWr
Canada: House of Commons reads Bill on Safe Social Media Act for first time.
Bill C-34 aims to reduce online harms and increase accountability for operators of social media, chatbot, and other online services in Canada.
Read more: bit.ly/4uZPyuB
EU: Commission publishes code of practice on marking and labeling AI-generated content.
The European Commission has published a voluntary code of practice to help AI providers and deployers meet upcoming EU AI Act transparency obligations.
Read now: bit.ly/4xv3dM7
Netherlands: AP publishes 2025 complaint report.
The report shows a 75% surge in privacy complaints, driven by transparency failures, deletion refusals, and major data breaches, particularly in the healthcare sector.
Learn more: bit.ly/4egDhLq
Turkey: The KVKK guidance addresses workplace security camera use, stressing data minimization, clear purpose limitation, and strict retention and access controls under Turkey's data protection law.
Read now: bit.ly/4oiRU5d
EU: The European Commission has imposed interim measures on Meta, ordering it to restore free WhatsApp access for rival AI assistants pending its antitrust investigation.
Read now: bit.ly/4xmrHqw
Illinois: Legislature passes Children's Social Media Safety Act.
The Act introduces device-level age assurance and strict default privacy and design safeguards for users under 18.
Check it out: bit.ly/3Q8jhm8
New York: Bill for the New York Health Information Privacy Act passes legislature.
The bill creates strict limits on processing and selling consumer health data and grants patients the rights of access and deletion, with enforcement by the AG.
Read now: bit.ly/4uwEtAm
Malta: The MFSA has issued a Dear CEO letter setting governance, risk, and prudential expectations for AI use in financial services, including a nonmandatory self-assessment framework for CEOs.
Read now: bit.ly/4urf0YX
South Korea: PIPC publishes R&D and standardization roadmap for personal information protection in the AI era.
The roadmap aims to strengthen personal data protection and AI-specific safeguards while enabling trusted data use.
Check it out: bit.ly/4oiRU5d
Thailand: ETDA announces AI 2026 strategy to promote trust in AI governance.
The strategy sets governance guidelines, safety testing, and capacity-building programs to promote responsible AI and position Thailand as a regional hub.
Explore more: bit.ly/4uUy9U8
UK: DSIT launches consultation on data intermediaries.
DSIT has launched a consultation on measures, including possible UK GDPR changes and new authorization frameworks, to support the growth of data intermediaries in the UK.
Learn more: bit.ly/4e0cNyS
Colorado: Law establishing requirements for conversational AI services signed into Act, imposing disclosure, child protection, and crisis-response obligations on operators of conversational AI services offered to consumers.
Read now: bit.ly/4xhI2wR
Slovenia: Commissioner issues opinion on personal data transfers to the US, outlining lawful transfer mechanisms, contractual duties, and cookie consent requirements.
Read now: bit.ly/4uy8zUc
Poland: Council of Ministers adopts draft act on protecting minors from adult content.
The draft act requires adult content websites to implement anonymous age verification, enforced through UKE domain blocking and monetary penalties.
Read now: bit.ly/4vzAjZl