The EU Cyber Resilience Act sets mandatory cybersecurity requirements for products with
digital elements, covering hardware and software placed on the EU market regardless of
where the maker is based. From 11 September 2026, manufacturers must report actively
exploited vulnerabilities and severe incidents, with an early warning within 24 hours, a
fuller notification within 72 hours, and a final report within set deadlines, through a
single ENISA platform. The broader design, documentation, and CE-marking obligations apply
from 11 December 2027.
The European Commission's Digital Omnibus on AI, proposed on 19 November 2025, has been
formally adopted: the European Parliament endorsed it on 16 June 2026 and the Council of the
EU gave its final green light on 29 June 2026, with entry into force on the third day after
publication in the Official Journal. It defers the EU AI Act's high-risk obligations to
2 December 2027 for stand-alone Annex III systems and to 2 August 2028 for systems embedded
in regulated products under Annex I. The Article 50 transparency obligations still apply from
2 August 2026, with the machine-readable marking obligation for generative AI systems already
on the market before that date postponed to 2 December 2026. It also adds a new prohibition
on AI-generated non-consensual intimate imagery and child sexual abuse material, applying from
2 December 2026, and postpones the national regulatory-sandbox obligation to 2 August 2027.
As of mid-2026, the ePrivacy Directive still governs cookies and electronic communications
alongside GDPR. The proposed ePrivacy Regulation was withdrawn: the Commission announced the
withdrawal in its 2025 Work Program on 11 February 2025, formally decided it on 16 July 2025,
and recorded it in the Official Journal on 6 October 2025, ending procedure 2017/0003(COD).
Cookie-consent reform has instead moved into the Digital Omnibus proposal of 19 November 2025,
which proposes moving cookie and terminal-equipment rules into the GDPR but remains a draft in
the legislative process.
On 19 May 2026 the European Commission published draft guidelines on classifying high-risk
AI systems under the EU AI Act, with practical examples by sector and use case. The
guidelines help providers and deployers decide whether a system falls within Annex III or
qualifies for the Article 6(3) exemption.
The European Data Protection Board launched its fifth coordinated enforcement action on
19 March 2026, with around 25 supervisory authorities examining how organizations meet
their transparency and information duties under Articles 12 to 14 of the GDPR. Privacy
notices, consent flows, and in-product messaging are all in scope, and weak transparency
often points to deeper problems with lawful basis, retention, and data subject rights. The
EDPB also published its first harmonized template for Data Protection Impact Assessments in
April 2026 for public consultation.
The principal data protection provisions of the UK Data (Use and Access) Act 2025, which
received Royal Assent on 19 June 2025, came into force on 5 February 2026. The reforms
change how the one-month subject access response period is calculated, introduce recognised
legitimate interests that need no balancing test, replace the previous ban on solely
automated decisions with a permission-plus-safeguards model, and exempt certain low-risk
analytics cookies from prior consent. A new statutory complaints procedure requiring
controllers to acknowledge data protection complaints follows on 19 June 2026.
Minnesota's Consumer Data Privacy Act took effect on 31 July 2025 with a built-in grace
mechanism: until 31 January 2026, the Attorney General had to give businesses written
notice and 30 days to cure before bringing an enforcement action. That cure-period
provision expired by statute on 31 January 2026. From 1 February 2026, the AG can
proceed directly to enforcement without offering a cure window.
The MCDPA applies to controllers processing personal data of 100,000 or more Minnesota
consumers annually, or 25,000 where more than 25 percent of gross revenue derives from
selling personal data, and, unusually among state privacy laws, most nonprofits are not
exempt. The law includes the standard consumer rights set (access, correction, deletion,
portability, opt-outs for sale, targeted advertising and profiling) plus
Minnesota-specific additions, including a right to question the result of profiling used
in significant decisions.
What this means
The runway is gone. If you meet a threshold and have not aligned your program with the
MCDPA, prioritize it: privacy notice coverage, consumer rights workflows, processor
contracts, and data protection assessments for high-risk processing.
As of mid-2026, 22 of 27 member states have adopted NIS2 legislation, with France,
Ireland, Luxembourg, the Netherlands, and Spain still in procedure. The Netherlands expects
entry into force in 2026. On 20 January 2026 the Commission proposed targeted NIS2
simplifications to ease compliance.
Comprehensive consumer privacy laws in Indiana, Kentucky, and Rhode Island came into force
on 1 January 2026, taking the number of US states with comprehensive privacy laws to
around twenty. All three grant access, correction, deletion, and opt-out rights and require
data protection assessments for higher-risk processing such as targeted advertising and
certain profiling. Enforcement sits with each state attorney general, with penalties up to
7,500 USD per violation in Indiana and Kentucky and 10,000 USD in Rhode Island, which
provides no cure period.
New California Consumer Privacy Act regulations took effect on 1 January 2026, adding
obligations on automated decision-making technology, formal privacy risk assessments, and
independent cybersecurity audits. The deadlines are staggered: risk-assessment work begins
in 2026 with the first attestations to the California Privacy Protection Agency due
1 April 2028, automated decision-making consumer rights start 1 January 2027, and
cybersecurity-audit certifications phase in by company size through 2030. Businesses that
use AI for significant decisions about Californians are squarely in scope.
The Texas Responsible Artificial Intelligence Governance Act took effect on 1 January 2026,
applying to organizations that develop or deploy AI systems used by Texas residents and
prohibiting uses such as manipulation, unlawful discrimination, and social scoring.
California's training-data transparency law for generative AI also took effect on
1 January 2026. Colorado's broader AI Act was scaled back and its start date moved to
1 January 2027 by an amendment signed in May 2026.
The European Commission published its Digital Omnibus package on 19 November 2025,
proposing targeted amendments to the GDPR, the ePrivacy Directive, the NIS2 Directive,
and the Data Act, alongside a separate Digital Omnibus on AI amending the EU AI Act. The
headline GDPR proposals: narrowing how pseudonymised data is treated under the definition
of personal data; raising the Records of Processing Activities exemption threshold from
250 to 750 employees; extending breach notification from 72 to 96 hours with a single
entry point for reporting; refinements to Article 22 automated decision-making; moving
cookie and terminal-equipment rules into the GDPR with support for machine-readable
consent signals; and a new provision clarifying that legitimate interests can support
processing for AI development.
These are proposals, not law: they require negotiation and adoption by the Parliament and
Council. The EDPB and EDPS have criticised the personal-data definition change, and
Council compromise texts have reportedly walked parts of it back. The AI portion has since
been formally adopted (see that entry); the rest remains in the legislative
process.
What this means
No compliance action yet. Track the RoPA threshold and breach-notification changes if you
are an SME, and do not loosen pseudonymisation practices on the strength of a proposal.
India notified the Digital Personal Data Protection Rules, 2025, operationalising the
Digital Personal Data Protection Act, 2023. The rules require itemised consent notices,
breach notification within 72 hours, and enhanced duties for Significant Data Fiduciaries
including annual data protection impact assessments, independent audits, and a designated
data protection officer. Compliance is phased over roughly 18 months, with the main
substantive obligations expected to apply from around May 2027.
The EU General Court dismissed the Latombe challenge on 3 September 2025, confirming the
validity of the European Commission's adequacy decision for the EU-US Data Privacy
Framework, which over 3,400 certified US companies rely on for transatlantic transfers. The
decision has been appealed to the Court of Justice of the EU, with no hearing date set as
of mid-2026. The framework remains valid in the meantime, but given the history of Schrems
I and II, companies relying on it should keep Standard Contractual Clauses available as a
fallback.
The EU AI Act's obligations for providers of general-purpose AI models took effect on
2 August 2025, covering technical documentation, a copyright policy, and a public summary
of training content, with extra duties for the most capable models that carry systemic
risk. The voluntary General-Purpose AI Code of Practice, published on 10 July 2025, gives
providers a way to demonstrate compliance. Models already on the market before that date
have until 2 August 2027 to comply, and the Commission's enforcement powers for these
models begin on 2 August 2026.
The Digital Operational Resilience Act applies to EU financial entities and the ICT
providers they rely on, with contractual, incident-reporting, and third-party-register
requirements.
The Texas Data Privacy and Security Act applies to businesses serving Texas residents that
process or sell personal data and are not small businesses, with consumer-rights and
processing requirements.
Enforced by the Attorney General and district attorneys, the Colorado Privacy Act introduced
the Universal Opt-Out Mechanism later adopted by other states.
The Virginia Consumer Data Protection Act was the second comprehensive US state privacy law
and tracks closely to other state laws, with its own specifics.