On July 8, 2026, the European Data Protection Board (“EDPB”), the body that coordinates the EU’s national data protection authorities, published its first draft of Guidelines 03/2026 on web scraping in the context of generative AI (the “Guidelines”). The Guidelines address practical compliance challenges for companies that develop AI models or systems and scrape personal […]
Privacy & Cyber Regulatory Enforcement
DROP Is Coming Due: What California’s Delete Act Means for Data Brokers in August
Beginning August 1, 2026, data brokers must begin accessing California’s Delete Request and Opt-Out Platform (“DROP”) at least once every 45 days to retrieve and process consumer deletion requests, as the consumer-facing launch transitions to operational obligations for data brokers. DROP allows California residents to submit a single deletion request to hundreds of registered data […]
Louisiana Delays App Store Accountability Effective Date to July 2027
On May 15, 2026, the Louisiana Governor signed HB 977 (Bill) into law, delaying the effective date of the Louisiana App Store Accountability Act (ASAA) by one year, to July 1, 2027. The amendments to the Louisiana ASAA come amid ongoing First Amendment challenges to similar laws in other states, and resemble recent developments in […]
NYDFS Issues Frontier AI Advisory and Guidance for Heightened Cyber Threat Environment
On May 21, 2026, the New York Department of Financial Services (“NYDFS”) issued two Industry Letters to the organizations it regulates (“Regulated Entities”): “Heightened Cybersecurity Risks Associated with Frontier AI Models” (the “Advisory”) and “Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat Environment” (the “Guidance”) (collectively, the “Letters”). The Letters discuss […]
May Flowers Bring Fresh Insight from CalPrivacy
Increased scrutiny of data brokers, rapid scaling of enforcement operations and active opposition to federal privacy preemption are in bloom in the Golden State. On May 1, 2026, the California Privacy Protection Agency (the “Agency”) Board (the “Board”) held a public meeting to review and discuss enforcement activities, legislative developments, and international data transfer issues. […]