On July 20, 2026, the French data protection authority (the Commission Nationale de l’Informatique et des Libertés, “CNIL”) published a joint exploratory note with the French AI and Digital Council (“CIANum”) on the data protection implications of agentic AI (the “Note”). The Note is exploratory rather than prescriptive: it does not purport to state definitive regulatory expectations, and it does not announce forthcoming guidance. However, it does provide helpful considerations for when the EU’s General Data Protection Regulation (“GDPR”) might come under strain in the course of processing personal data via autonomous systems, and identifies legal and technical measures that might help mitigate potential risks. The CNIL frames this exercise as connected to its engagement with several international counterparts, including through the G7 data protection authorities during the French G7 presidency.

The Note is the latest in a rapidly accumulating body of regulator commentary on agentic AI, including by the UK ICO, Spanish AEPD, and Singaporean IMDA. Below are some key takeaways.

Continue Reading French CNIL Publishes Note on Agentic AI and Data Protection

The Illinois Governor recently signed SB 2886, which expands the scope of the state’s Genetic Information Privacy Act (“GIPA”) to include “biomarker testing” and “biomarker.” GIPA currently regulates the collection, use, and disclosure of genetic testing information.

The bill defines “biomarker” as “a characteristic that is objectively measured and

Continue Reading Illinois Expands Genetic Privacy Law to Biomarkers

On July 28, 2026, the New York Office of the Attorney General released final rules (the “Rules”) implementing the Stop Addictive Feeds Exploitation (SAFE) for Kids Act, which goes into effect on January 25, 2027.

The SAFE for Kids Act requires online “addictive social media platforms,” which are defined as

Continue Reading New York Publishes Final SAFE For Kids Act Rules

On July 23, 2026, New Jersey Governor Mikie Sherrill signed A4085 (the Fair Price Protection Act) into law, which prohibits companies from charging consumers different prices for groceries based on their personal data. New Jersey will join New York, Connecticut, and Maryland in imposing prohibitions and requirements on the use

Continue Reading New Jersey Enacts Ban on Surveillance Pricing

On July 7, 2026, the European Data Protection Board (“EDPB”) adopted draft Guidelines 02/2026 on Anonymisation (“Guidelines”), updating a 2014 Opinion on Anonymization Techniques. While the EDPB maintains a cautious approach to anonymization, the new Guidelines appear to offer a more structured and practical framework for assessing whether information can be considered anonymous. The Guidelines are open for public consultation until October 30, 2026.

Continue Reading EDPB Publishes Draft Guidelines on Anonymisation

Consistent with recent years, 2026 has proved to be a busy year for children and teens’ privacy legislation. This post recaps notable developments and trends thus far in 2026. Our mid-year and end-of-year recaps for 2025 can be found here and here.

Continue Reading State and Federal Developments in Minors’ Privacy in 2026

On July 1, 2026, a California legislative committee advanced amendments to SB 690 that would eliminate private suits asserting website-based “pen register” claims under the California Invasion of Privacy Act (“CIPA”), leaving enforcement exclusively to the California Attorney General.  The amendments come amid a surge of lawsuits and demand letters challenging the use of website technologies under the pen register provision, which the committee described as a “poster child for abusive lawsuits.”  According to the committee analysis, “[b]ecause the potential liability can be staggering,” businesses often settle quickly, thereby “encouraging vexatious litigants to continue blasting out demand letters.”

Continue Reading California Legislature Advances Bill Targeting Wave of CIPA Pen Register Lawsuits

On June 2, 2026, Colorado Governor Jared Polis vetoed HB 26-1210, a bill that would have imposed requirements for use of “surveillance data” to set individualized prices for consumers or individualized wage setting for workers. The veto is yet another action in a trend of bills focused on regulating “surveillance” or “dynamic” pricing.

Continue Reading Colorado Governor Vetoes Overly Broad Algorithmic Pricing and Wage Setting Bill

In recent weeks, several state legislatures have amended their state comprehensive privacy laws. Some of these amendments have already been enacted into law, while others have passed their state legislature and await the governor’s signature.

Continue Reading State Comprehensive Privacy Law Round-Up: Several States Amend Their Privacy Statutes

On July 14, 2026, the Trump Administration announced the launch of a federal clearinghouse, “Gold Eagle,” that is designed to facilitate the sharing of AI-derived cybersecurity vulnerability information between government agencies, “American critical infrastructure companies,” and “open-source software partners.”  

The creation of Gold Eagle is the latest in a

Continue Reading White House Launches “Gold Eagle” AI Cybersecurity Clearinghouse