EU Cyber Resilience Act reporting obligations approach

The EU Cyber Resilience Act sets mandatory cybersecurity requirements for products with digital elements, covering hardware and software placed on the EU market regardless of where the maker is based. From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents, with an early warning within 24 hours, a fuller notification within 72 hours, and a final report within set deadlines, through a single ENISA platform. The broader design, documentation, and CE-marking obligations apply from 11 December 2027.

EU Digital Omnibus defers the AI Act high-risk deadlines

The European Commission's Digital Omnibus on AI, proposed on 19 November 2025, has been formally adopted: the European Parliament endorsed it on 16 June 2026 and the Council of the EU gave its final green light on 29 June 2026, with entry into force on the third day after publication in the Official Journal. It defers the EU AI Act's high-risk obligations to 2 December 2027 for stand-alone Annex III systems and to 2 August 2028 for systems embedded in regulated products under Annex I. The Article 50 transparency obligations still apply from 2 August 2026, with the machine-readable marking obligation for generative AI systems already on the market before that date postponed to 2 December 2026. It also adds a new prohibition on AI-generated non-consensual intimate imagery and child sexual abuse material, applying from 2 December 2026, and postpones the national regulatory-sandbox obligation to 2 August 2027.

ePrivacy Directive still governs cookies alongside GDPR

As of mid-2026, the ePrivacy Directive still governs cookies and electronic communications alongside GDPR. The proposed ePrivacy Regulation was withdrawn: the Commission announced the withdrawal in its 2025 Work Program on 11 February 2025, formally decided it on 16 July 2025, and recorded it in the Official Journal on 6 October 2025, ending procedure 2017/0003(COD). Cookie-consent reform has instead moved into the Digital Omnibus proposal of 19 November 2025, which proposes moving cookie and terminal-equipment rules into the GDPR but remains a draft in the legislative process.

European Commission publishes draft high-risk AI classification guidelines

On 19 May 2026 the European Commission published draft guidelines on classifying high-risk AI systems under the EU AI Act, with practical examples by sector and use case. The guidelines help providers and deployers decide whether a system falls within Annex III or qualifies for the Article 6(3) exemption.

EU regulators turn their attention to transparency

The European Data Protection Board launched its fifth coordinated enforcement action on 19 March 2026, with around 25 supervisory authorities examining how organizations meet their transparency and information duties under Articles 12 to 14 of the GDPR. Privacy notices, consent flows, and in-product messaging are all in scope, and weak transparency often points to deeper problems with lawful basis, retention, and data subject rights. The EDPB also published its first harmonized template for Data Protection Impact Assessments in April 2026 for public consultation.

UK data protection reform comes into force

The principal data protection provisions of the UK Data (Use and Access) Act 2025, which received Royal Assent on 19 June 2025, came into force on 5 February 2026. The reforms change how the one-month subject access response period is calculated, introduce recognised legitimate interests that need no balancing test, replace the previous ban on solely automated decisions with a permission-plus-safeguards model, and exempt certain low-risk analytics cookies from prior consent. A new statutory complaints procedure requiring controllers to acknowledge data protection complaints follows on 19 June 2026.

Minnesota MCDPA: cure period expires, AG can enforce without prior notice

Minnesota's Consumer Data Privacy Act took effect on 31 July 2025 with a built-in grace mechanism: until 31 January 2026, the Attorney General had to give businesses written notice and 30 days to cure before bringing an enforcement action. That cure-period provision expired by statute on 31 January 2026. From 1 February 2026, the AG can proceed directly to enforcement without offering a cure window.

The MCDPA applies to controllers processing personal data of 100,000 or more Minnesota consumers annually, or 25,000 where more than 25 percent of gross revenue derives from selling personal data, and, unusually among state privacy laws, most nonprofits are not exempt. The law includes the standard consumer rights set (access, correction, deletion, portability, opt-outs for sale, targeted advertising and profiling) plus Minnesota-specific additions, including a right to question the result of profiling used in significant decisions.

What this means

The runway is gone. If you meet a threshold and have not aligned your program with the MCDPA, prioritize it: privacy notice coverage, consumer rights workflows, processor contracts, and data protection assessments for high-risk processing.

NIS2 transposition advances and the Commission proposes simplifications

As of mid-2026, 22 of 27 member states have adopted NIS2 legislation, with France, Ireland, Luxembourg, the Netherlands, and Spain still in procedure. The Netherlands expects entry into force in 2026. On 20 January 2026 the Commission proposed targeted NIS2 simplifications to ease compliance.

Three more US states bring privacy laws into force

Comprehensive consumer privacy laws in Indiana, Kentucky, and Rhode Island came into force on 1 January 2026, taking the number of US states with comprehensive privacy laws to around twenty. All three grant access, correction, deletion, and opt-out rights and require data protection assessments for higher-risk processing such as targeted advertising and certain profiling. Enforcement sits with each state attorney general, with penalties up to 7,500 USD per violation in Indiana and Kentucky and 10,000 USD in Rhode Island, which provides no cure period.

California's new CCPA rules on automated decisions, risk assessments, and cybersecurity audits take effect

New California Consumer Privacy Act regulations took effect on 1 January 2026, adding obligations on automated decision-making technology, formal privacy risk assessments, and independent cybersecurity audits. The deadlines are staggered: risk-assessment work begins in 2026 with the first attestations to the California Privacy Protection Agency due 1 April 2028, automated decision-making consumer rights start 1 January 2027, and cybersecurity-audit certifications phase in by company size through 2030. Businesses that use AI for significant decisions about Californians are squarely in scope.

US states move on AI governance

The Texas Responsible Artificial Intelligence Governance Act took effect on 1 January 2026, applying to organizations that develop or deploy AI systems used by Texas residents and prohibiting uses such as manipulation, unlawful discrimination, and social scoring. California's training-data transparency law for generative AI also took effect on 1 January 2026. Colorado's broader AI Act was scaled back and its start date moved to 1 January 2027 by an amendment signed in May 2026.

European Commission publishes Digital Omnibus package proposing GDPR, ePrivacy, NIS2, and Data Act amendments

The European Commission published its Digital Omnibus package on 19 November 2025, proposing targeted amendments to the GDPR, the ePrivacy Directive, the NIS2 Directive, and the Data Act, alongside a separate Digital Omnibus on AI amending the EU AI Act. The headline GDPR proposals: narrowing how pseudonymised data is treated under the definition of personal data; raising the Records of Processing Activities exemption threshold from 250 to 750 employees; extending breach notification from 72 to 96 hours with a single entry point for reporting; refinements to Article 22 automated decision-making; moving cookie and terminal-equipment rules into the GDPR with support for machine-readable consent signals; and a new provision clarifying that legitimate interests can support processing for AI development.

These are proposals, not law: they require negotiation and adoption by the Parliament and Council. The EDPB and EDPS have criticised the personal-data definition change, and Council compromise texts have reportedly walked parts of it back. The AI portion has since been formally adopted (see that entry); the rest remains in the legislative process.

What this means

No compliance action yet. Track the RoPA threshold and breach-notification changes if you are an SME, and do not loosen pseudonymisation practices on the strength of a proposal.

India operationalises its data protection regime

India notified the Digital Personal Data Protection Rules, 2025, operationalising the Digital Personal Data Protection Act, 2023. The rules require itemised consent notices, breach notification within 72 hours, and enhanced duties for Significant Data Fiduciaries including annual data protection impact assessments, independent audits, and a designated data protection officer. Compliance is phased over roughly 18 months, with the main substantive obligations expected to apply from around May 2027.

EU-US Data Privacy Framework survives its first challenge but faces appeal

The EU General Court dismissed the Latombe challenge on 3 September 2025, confirming the validity of the European Commission's adequacy decision for the EU-US Data Privacy Framework, which over 3,400 certified US companies rely on for transatlantic transfers. The decision has been appealed to the Court of Justice of the EU, with no hearing date set as of mid-2026. The framework remains valid in the meantime, but given the history of Schrems I and II, companies relying on it should keep Standard Contractual Clauses available as a fallback.

EU AI Act obligations for general-purpose AI models apply

The EU AI Act's obligations for providers of general-purpose AI models took effect on 2 August 2025, covering technical documentation, a copyright policy, and a public summary of training content, with extra duties for the most capable models that carry systemic risk. The voluntary General-Purpose AI Code of Practice, published on 10 July 2025, gives providers a way to demonstrate compliance. Models already on the market before that date have until 2 August 2027 to comply, and the Commission's enforcement powers for these models begin on 2 August 2026.

DORA applies to EU financial entities and their ICT providers

The Digital Operational Resilience Act applies to EU financial entities and the ICT providers they rely on, with contractual, incident-reporting, and third-party-register requirements.

Texas Data Privacy and Security Act takes effect

The Texas Data Privacy and Security Act applies to businesses serving Texas residents that process or sell personal data and are not small businesses, with consumer-rights and processing requirements.

Colorado Privacy Act in effect, introducing the Universal Opt-Out Mechanism

Enforced by the Attorney General and district attorneys, the Colorado Privacy Act introduced the Universal Opt-Out Mechanism later adopted by other states.

Virginia Consumer Data Protection Act takes effect

The Virginia Consumer Data Protection Act was the second comprehensive US state privacy law and tracks closely to other state laws, with its own specifics.