On August 28, 2026, the California Legislature passed SB 690, a significant bill aimed at curbing the flood of demand letters and lawsuits asserting “pen register” claims under the California Invasion of Privacy Act (“CIPA”). If enacted, the bill would eliminate the private right of action for website-based pen register claims and could affect many pending lawsuits filed since January 1, 2025.

Continue Reading California Legislature Passes CIPA Pen Register Reform Bill and Sends It to Governor

On August 19, 2026, Connecticut Attorney General William Tong announced a $275,000 settlement with online tax preparation company TaxAct over allegations that the company improperly disclosed taxpayer information to advertising partners through third-party tracking technologies on its website. The Attorney General alleged that, between January 2018 and December 2022, TaxAct used third-party tracking technologies for analytics and marketing purposes and, in doing so, disclosed detailed taxpayer information without informing consumers.

The settlement is notable because it highlights regulatory scrutiny over the disclosure of financial information, and also because it imposes extensive governance, monitoring, and auditing requirements on TaxAct relating to the use of third-party tracking technologies. In addition, the settlement does not specify what law was allegedly violated.

Continue Reading Connecticut Attorney General Settles with TaxAct Over Sharing Taxpayer Data

On August 12, 2026, the Administration published a National Security Presidential Memorandum (“NSPM”) (“Expanding Capabilities to Combat Transnational Cyber-Enabled Crime”) that signals the Administration’s focus on private-sector participation in offensive cyber operations by establishing a federally supervised program to enable private sector participants to conduct offensive cyber operations against “Cyber-Enabled

Continue Reading White House Releases National Security Presidential Memorandum on Expanding Capabilities to Combat Transnational Cyber-Enabled Crime

Employers increasingly rely on automated tools to help make decisions concerning hiring, promotion, discipline, and termination. In response, state legislatures and agencies have begun to regulate uses of these technologies, often referred to as automated decision-making technology (“ADMT”). These laws generally require entities that deploy ADMT in the employment context

Continue Reading ADMT Law Round-Up: What Employers Need to Know About Recent ADMT Laws

On August 14, 2026, the French Constitutional Council (the “Constitutional Council”) struck down Article 1 of France’s Act to protect minors from the risks posed by the use of social media (the “Act”), which would have barred minors under the age of fifteen from accessing online social media services. The Constitutional Council held that the prohibition infringed on the freedom of expression and communication in a manner that was not appropriate, necessary, or proportionate to the objective pursued and, separately, that the legislature failed to provide the legal safeguards required to protect the right to respect for private life in connection with the age verification process that the ban would, by necessity, have entailed.

We summarise key aspects of the decision below.

Continue Reading French Constitutional Council Strikes Down Under-15 Social Media Ban

On July 20, 2026, the French data protection authority (the Commission Nationale de l’Informatique et des Libertés, “CNIL”) published a joint exploratory note with the French AI and Digital Council (“CIANum”) on the data protection implications of agentic AI (the “Note”). The Note is exploratory rather than prescriptive: it does not purport to state definitive regulatory expectations, and it does not announce forthcoming guidance. However, it does provide helpful considerations for when the EU’s General Data Protection Regulation (“GDPR”) might come under strain in the course of processing personal data via autonomous systems, and identifies legal and technical measures that might help mitigate potential risks. The CNIL frames this exercise as connected to its engagement with several international counterparts, including through the G7 data protection authorities during the French G7 presidency.

The Note is the latest in a rapidly accumulating body of regulator commentary on agentic AI, including by the UK ICO, Spanish AEPD, and Singaporean IMDA. Below are some key takeaways.

Continue Reading French CNIL Publishes Note on Agentic AI and Data Protection

The Illinois Governor recently signed SB 2886, which expands the scope of the state’s Genetic Information Privacy Act (“GIPA”) to include “biomarker testing” and “biomarker.” GIPA currently regulates the collection, use, and disclosure of genetic testing information.

The bill defines “biomarker” as “a characteristic that is objectively measured and

Continue Reading Illinois Expands Genetic Privacy Law to Biomarkers

On July 28, 2026, the New York Office of the Attorney General released final rules (the “Rules”) implementing the Stop Addictive Feeds Exploitation (SAFE) for Kids Act, which goes into effect on January 25, 2027.

The SAFE for Kids Act requires online “addictive social media platforms,” which are defined as

Continue Reading New York Publishes Final SAFE For Kids Act Rules

On July 23, 2026, New Jersey Governor Mikie Sherrill signed A4085 (the Fair Price Protection Act) into law, which prohibits companies from charging consumers different prices for groceries based on their personal data. New Jersey will join New York, Connecticut, and Maryland in imposing prohibitions and requirements on the use

Continue Reading New Jersey Enacts Ban on Surveillance Pricing

On July 7, 2026, the European Data Protection Board (“EDPB”) adopted draft Guidelines 02/2026 on Anonymisation (“Guidelines”), updating a 2014 Opinion on Anonymization Techniques. While the EDPB maintains a cautious approach to anonymization, the new Guidelines appear to offer a more structured and practical framework for assessing whether information can be considered anonymous. The Guidelines are open for public consultation until October 30, 2026.

Continue Reading EDPB Publishes Draft Guidelines on Anonymisation