On July 10, 2026, New York City Mayor Zohran Mamdani and Department of Consumer and Worker Protection (“DCWP”) Commissioner Samuel Levine announced the adoption of a new “Click to Cancel” rule governing how businesses disclose, bill, and cancel subscriptions. The rule takes effect October 1, 2026.
Continue Reading New York City Adopts ‘Click to Cancel’ RuleCJEU Decides When Streaming Subscriptions Are Subject to the Right of Withdrawal
On July 9, 2026, the Court of Justice of the European Union (“CJEU” or “Court”) delivered its judgment in Sky Österreich Fernsehen (C-234/25), deciding that a streaming offering constitutes a digital service under the Consumer Rights Directive (Directive 2011/83/EU), rather than digital content, where the trader’s offering is of a dynamic nature and goes beyond the stable or continuous provision of specific content. As a result, providers of such streaming offerings cannot rely on the Consumer Rights Directive’s exception to the right of withdrawal for digital content.
The judgment has broad implications for providers of personalised digital services, as it affects whether consumers can cancel a subscription during the 14-day withdrawal period and, if they do, how much providers may charge for use of the service during that period.
Continue Reading CJEU Decides When Streaming Subscriptions Are Subject to the Right of WithdrawalCJEU Clarifies the Conditions for Seizure of Business Emails During Competition Inspections
On July 16, 2026, the Court of Justice of the European Union (“CJEU”) issued a decision clarifying that EU law does not, as a rule, prevent a national competition authority from seizing business emails stored on a company’s systems without prior authorisation from a court. However, strict legal safeguards and effective ex post judicial review must be implemented.
This blog post provides an overview of the decision.
Continue Reading CJEU Clarifies the Conditions for Seizure of Business Emails During Competition InspectionsLooking beyond the tech sovereignty package: how the EU is moving to ensure tech sector resilience
In this post, we take a closer look at the current and forthcoming EU legislative measures aimed at increasing the resilience of services provided in the EU against external, malicious influence, a key aspect of tech sovereignty. Relevant legislation falls into two broad categories: (1) laws promoting cyber resilience generally, to prevent malicious actors from disrupting services and critical infrastructure; and (2) laws focused on building supply chain resilience and reducing dependencies on certain external actors by building European industrial capacity in key tech sectors.
…
Continue Reading Looking beyond the tech sovereignty package: how the EU is moving to ensure tech sector resilienceFTC Settles with Hopper Over Hidden Fee Practices
On July 2, 2026, the Federal Trade Commission (“FTC”) announced that Hopper (USA), Inc. and its Canadian parent, Hopper Inc., agreed to a $35 million settlement resolving allegations that Hopper engaged in unfair and deceptive fee practices in violation of Section 5 of the FTC Act and the Trade Regulation…
Continue Reading FTC Settles with Hopper Over Hidden Fee PracticesDelaware General Assembly Passes HB 380, an Amendment to the Delaware Personal Data Privacy Act
On June 16, 2026, the Delaware General Assembly passed HB 380, which would amend the Delaware Personal Data Privacy Act (DPDPA). The bill is currently awaiting the Delaware governor’s signature, and if signed, the amendments would take effect on January 1, 2027. The amendment would impose the following:
Continue Reading Delaware General Assembly Passes HB 380, an Amendment to the Delaware Personal Data Privacy ActIrish NCSC Issues Cyber Governance Guidance for Management Boards Ahead of NIS2 Implementation
On July 7, 2026, the Irish National Cyber Security Centre (“NCSC”) published guidance for management boards and senior executives of organizations subject to the EU’s Network and Information Security Directive (“NIS2”). Reflecting a central theme of NIS2, the Guidance makes it clear that cybersecurity is no longer solely a technical issue, but a governance and risk-management matter that requires active oversight at “the highest levels of executive management.” It is a helpful document for organizations that are likely to be subject to NIS2, expect to be supervised in Ireland, and that are considering their governance structures and board-level oversight mechanisms.
Continue Reading Irish NCSC Issues Cyber Governance Guidance for Management Boards Ahead of NIS2 ImplementationFTC Seeks Comment on Proposed Policy Statement Addressing AI Accuracy and Output Steering
On July 1, 2026, the Federal Trade Commission (“FTC”) issued a proposed policy statement addressing what it describes as the “suppression of accuracy” in artificial intelligence (“AI”) systems and is seeking public comment through July 31, 2026. The proposal was issued pursuant to Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence, which directed the FTC to explain how Section 5 of the FTC Act applies when AI developers alter model outputs in response to state law requirements.[1]
Continue Reading FTC Seeks Comment on Proposed Policy Statement Addressing AI Accuracy and Output SteeringSupreme Court Holds FTC Removal Protections Unconstitutional
On June 29, 2026, in a 6-3 decision, the U.S. Supreme Court held that (1) the Federal Trade Commission’s (FTC) statutory “for‑cause” removal protection for Commissioners violates the Constitution’s separation of powers and (2) President Trump lawfully removed Rebecca Slaughter from the FTC. The Court concluded that because FTC Commissioners exercise executive power, they must be removable by the President at will rather than only for “inefficiency, neglect of duty, or malfeasance in office.”
Continue Reading Supreme Court Holds FTC Removal Protections UnconstitutionalRhode Island Enacts Genetic Privacy Law
In what continues to be a busy year for genetic privacy developments, Rhode Island has joined the growing number of states regulating direct-to-consumer (“DTC”) genetic testing with its recently enacted genetic privacy law, S 2203. With S 2203, Rhode Island is the fifth state to enact genetic privacy legislation this year, following Utah, South Dakota, Connecticut, and Vermont.
Continue Reading Rhode Island Enacts Genetic Privacy Law