On September 10, 2026, the New York State Department of Financial Services (“NYDFS”) published an Industry Letter (the “Letter”) to regulated entities (“Covered Entities”) addressing what is probably the most frequently asked Part 500 question: “How to Conduct and Use Risk Assessments Required by the DFS Cybersecurity Regulation.” The risk assessment is, by all accounts, […]
Privacy & Cyber Regulatory Enforcement
EU Regulators Outline GDPR Requirements for AI Web Scraping
On July 8, 2026, the European Data Protection Board (“EDPB”), the body that coordinates the EU’s national data protection authorities, published its first draft of Guidelines 03/2026 on web scraping in the context of generative AI (the “Guidelines”). The Guidelines address practical compliance challenges for companies that develop AI models or systems and scrape personal […]
DROP Is Coming Due: What California’s Delete Act Means for Data Brokers in August
Beginning August 1, 2026, data brokers must begin accessing California’s Delete Request and Opt-Out Platform (“DROP”) at least once every 45 days to retrieve and process consumer deletion requests, as the consumer-facing launch transitions to operational obligations for data brokers. DROP allows California residents to submit a single deletion request to hundreds of registered data […]
Louisiana Delays App Store Accountability Effective Date to July 2027
On May 15, 2026, the Louisiana Governor signed HB 977 (Bill) into law, delaying the effective date of the Louisiana App Store Accountability Act (ASAA) by one year, to July 1, 2027. The amendments to the Louisiana ASAA come amid ongoing First Amendment challenges to similar laws in other states, and resemble recent developments in […]
NYDFS Issues Frontier AI Advisory and Guidance for Heightened Cyber Threat Environment
On May 21, 2026, the New York Department of Financial Services (“NYDFS”) issued two Industry Letters to the organizations it regulates (“Regulated Entities”): “Heightened Cybersecurity Risks Associated with Frontier AI Models” (the “Advisory”) and “Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat Environment” (the “Guidance”) (collectively, the “Letters”). The Letters discuss […]