Key trends
- UK: New duty on handling data protection complaints in force since 23 June 2026. Court of Appeal in RTM v Bonne Terre confirms consent is assessed objectively.
- EU: US Supreme Court ruling on FTC commissioner removal threatens the EU US Data Privacy Framework. EDPB issues draft guidance on anonymisation, web scraping, blockchain and a harmonised breach notification template.
- Middle East: UAE bans social media for under 15s and sets up a federal AI and Data Authority.
- Asia: China mandates cyber and data security risk assessments for processors of “Important Data”.
Must reads
- DSAR: What changes for data controllers after the Italian DPA's decision, by Matteo Susta
- Regulating data: EU Data Act & more – July 2026 edition, by Christopher Götz and Jakob Auer
- China issues new regulatory data protection measures, by Jiayi Wang, and Reking Chen
Regional Updates
UK
New data protection complaints law now in force
A new legal duty on data protection complaints handling now applies to all organisations processing personal data in the UK. From 23 June 2026, organisations must provide individuals with a clear route to raise a data protection complaint, acknowledge it within 30 days, investigate it appropriately and communicate the outcome.
The ICO has published data protection complaints guidance aimed at organisations of all sizes, setting out expectations and practical examples for common types of complaint such as subject access requests, inaccurate personal data and direct marketing concerns. The ICO’s stated focus is on helping organisations embed good practice rather than catching businesses out, but it notes that prompt, fair handling of complaints reduces the risk of issues escalating and helps to build trust, transparency and good customer relationships.
These changes form part of the broader package introduced by the Data (Use and Access) Act 2025 (DUAA), which has now fully commenced. Over the past year, the ICO has prioritised practical guidance on the areas most affected by the Act, including complaints handling, direct marketing, recognised legitimate interests, research and automated decision making.
Organisations should ensure they have documented, transparent and fair complaints handling processes in place, aligned with the new legal requirements, and monitor forthcoming ICO guidance and consultations via the ICO’s guidance and codes of practice pipelines.
For more information, see the ICO's update here.
Evolving regulatory sandboxes for AI and emerging technologies
The ICO has published a blog setting out its plans to evolve its Regulatory Sandbox and broader innovation services to better support AI and other fast moving technologies. The Sandbox, which has operated for more than eight years, allows organisations to test new ideas, explore data protection risks and build privacy by design into products and services.
The ICO notes that traditional sandbox models have limits – including constraints on using live personal data in projects that push the boundaries of data protection principles, and the difficulty of dealing with issues that span multiple regulators (for example, privacy and competition). These limits can slow regulatory certainty, innovation and understanding of how data protection rights apply to new technologies.
To address this, the ICO is:
- working with other UK and international regulators (including the Singapore PDPC and DRCF partners such as the FCA) and supporting initiatives like the Advisory AI Growth Lab for legal services and the FCA’s AI Lab;
- piloting multi agency approaches through the DRCF AI and digital hub; and
- publishing findings from a project with the Regulatory Innovation Office’s AI Capability Fund on the feasibility of a data protection Statutory Regulatory Sandbox (SRS).
The ICO’s research concludes that a data protection SRS – an experimentation regime providing time limited flexibility from parts of data protection law – is feasible but would require legislative change and careful safeguards. Key points include the need to protect the ICO’s independence, ensure individuals’ rights are transparently safeguarded through equivalent accountability mechanisms, focus on innovations with clear public benefit, and recognise that although demand may be niche, the potential economic and societal impact could be significant.
In parallel, the ICO is committing to improving its existing sandbox offering to deliver faster engagement and clearer outcomes. Any SRS would ultimately depend on government decisions under forthcoming initiatives such as the Regulating for Growth Bill and the AI Growth Lab, but organisations developing AI and other emerging technologies should expect the ICO to continue refining its sandbox and multi regulator support to help them navigate complex, high risk data uses.
For more information, see the ICO's blog post here.
Draft ICO Corporate Strategy 2026-2028
The draft ICO corporate strategy sets out how the ICO – soon to become the “Information Commission” with a Chair, Board and CEO (rather than an individual Information Commissioner) based on changes under the UK Data (Use and Access) Act 2025 – will build trust in responsible UK data use and innovation over 2026–2028.
The strategy summarises the ICO’s statutory duties under various laws relating to data protection, freedom of information and cyber security (among others), its core responsibilities in those areas and its pan-sector role as both protecting individuals’ rights and enabler of responsible innovation. It adopts a risk-based regulatory approach using a mix of education, guidance, cooperation, investigations and enforcement, with an emphasis on prevention and early intervention and focusing resources on areas of highest risk and systemic importance.
Four regulatory priorities are identified: (1) ensuring children’s data use helps, not harms, them in digital and edtech services; (2) promoting trust and transparency in AI so organisations can innovate confidently; (3) improving responsible data use and transparency in public services to support digital transformation; and (4) strengthening cyber resilience to reduce harms from data breaches and support economic and national resilience.
The ICO will also pursue internal transformation: streamlining customer services, becoming more data-driven and digitally enabled (including greater use of AI and analytics), and strengthening its people capability and culture as it moves to the new Commission governance model. Progress will be tracked through a structured impact framework, combining public trust and confidence measures, organisational behaviour and compliance indicators, transparency metrics, and data on regulatory interventions, with regular public reporting.
For more information, see the draft strategy here.
ICO publishes findings from Edtech audit programme
The ICO has published its Edtech examined report, following a two-year audit programme with 28 educational technology (edtech) providers with products widely used in UK primary and secondary schools. The audits covered a range of tools, including management information systems, safeguarding platforms, behaviour management systems and classroom learning apps. The ICO reports that providers accepted 98% of the 596 recommendations made during the programme.
While the ICO identified positive practices, particularly in relation to information security, it also found a number of recurring compliance issues across the sector. In particular, many providers had not correctly identified when they were acting as controllers rather than processors, especially where they were using children's personal information for their own purposes, such as product development, analytics, and training AI functionality. The report found that these activities were often not adequately documented, supported by an appropriate lawful basis, or clearly explained to schools, parents and pupils. The report also identified weaknesses in contractual arrangements with schools, transparency information, retention practices and DPIAs.
The findings reinforce the ICO's increasing focus on children's privacy, which has been identified as one of the regulator's four strategic priorities in its draft Corporate Strategy 2026-2028. The findings will also help inform the development of the ICO's proposed code on the processing of children's personal information in digital educational settings.
For more information, see the ICO's Edtech examined report here.
Court of Appeal brings an objective test to consent
The Court of Appeal has provided useful clarification on consent. In RTM v Bonne Terre Ltd and another [2026] EWCA Civ 488, the Court held that whether a person has consented to the use of cookies, processing of their personal data and direct marketing is to be assessed objectively. A controller is not generally required to look behind an apparently valid indication of consent and investigate the individual’s actual state of mind. The claimant, RTM, was a recovering problem gambler who had used a betting and gaming platform. He argued that, although he had outwardly indicated consent to relevant processing, his addiction impaired his ability to make a genuinely autonomous choice. The High Court accepted that argument. The Court of Appeal disagreed.
Article 4(11) GDPR requires consent to be freely given, specific, informed and unambiguous. The Court of Appeal held that those requirements are principally assessed by reference to objectively ascertainable circumstances: what the controller communicated, what choices were offered, the relationship between the parties and what affirmative action the individual took. A controller is not normally required to determine whether that outward indication of agreement corresponded with the individual’s undisclosed internal wishes or whether an unknown personal circumstance affected their decision-making.
The judgment therefore places the emphasis on the design of the consent process: clear affirmative action, appropriate information, genuine choice and sufficiently specific and unambiguous consent. However, vulnerability of the data subject is still a relevant consideration in certain aspects of data protection compliance, particularly the overarching requirement that processing is fair. RTM’s claims also raised issues concerning transparency, purpose limitation, data minimisation and storage limitation. Those questions are not answered simply by establishing that consent was valid.
For more information, see the decision here.
ICO Executes Search Warrants Over Car Finance Nuisance Marketing
The Information Commissioner's Office (ICO) has executed search warrants at residential and business premises in Bolton, Burnley, Liverpool, London and Swansea, targeting five companies believed to have sent a combined 170 million text messages to the public between September 2025 and May 2026 in connection with car finance mis-selling claims.
The action follows the wider motor finance mis-selling scandal, which centres on undisclosed commission arrangements between lenders and car dealerships that inflated interest rates for consumers without their knowledge. As redress schemes and claims activity around this scandal have grown, so has a surge in speculative and unsolicited marketing by claims management companies (CMCs), lead generators and law firms seeking to sign up claimants. The ICO reports it has received more than 12 million complaints about nuisance marketing texts since September 2025, at times up to 100,000 a day.
Although the underlying claims relate to financial mis-selling, the ICO's intervention is a data protection and electronic marketing matter. The ICO is urging claims management firms, lead generators and law firms to comply with the Privacy and Electronic Communications Regulations (PECR), under which it can apply to court for a warrant to search premises and seize evidence such as mobile phones, laptops or "sim farms". PECR regulation 21A specifically prohibits using or instigating the use of a public electronic communications service to make unsolicited direct marketing calls or messages about claims management services, unless the recipient has previously and specifically consented.
The ICO is acting alongside the Financial Conduct Authority, the Advertising Standards Authority and the Solicitors Regulation Authority as part of a joint taskforce addressing poor handling of motor finance claims. Andy Curry, the ICO's Head of Investigations, said the searches "send a clear message to the claims management sector: comply with the law or expect to hear from us."
For more information, see ICO's statement here.
EU
US Supreme Court ruling prompts further scrutiny of the EU–US Data Privacy Framework
On 29 June 2026, the US Supreme Court decided that the President may remove Federal Trade Commission (FTC) commissioners at will, rather than only for "inefficiency, neglect of duty, or malfeasance in office" as previously set by statute. In essence, this means that officials of the FTC – including its commissioners – are now subject to direct removal by the President, reflecting the “unitary executive” theory in US constitutional law.
This development could have an impact on the EU–US Data Privacy Framework (DPF), since the European Commission’s adequacy decision relies in part on oversight by the FTC. The FTC is responsible for enforcing the DPF principles, investigating complaints from data subjects, and taking action against non-compliant organisations. Its perceived independence has been key to the Commission’s finding that US companies participating in the DPF provide an “essentially equivalent” level of protection for personal data of EU data subjects.
Following the Supreme Court ruling, privacy NGO NOYB sent a letter to the Commission urging it to plan for an “orderly exit” from the DPF, including repeal of the adequacy decision with transitional arrangements. NOYB has also announced its intention to bring a legal challenge, aiming for judicial review of the DPF before the CJEU – raising the prospect of a further round of Schrems-style litigation.
Questions about the DPF’s validity are already before the courts. In particular, a challenge to the adequacy decision led by Philippe Latombe, a member of the French Parliament, is currently under appeal. Latombe argued that the US does not provide sufficient protection for EU personal data or adequate judicial remedies for EU individuals. Although the General Court dismissed his challenge – upholding the Commission’s adequacy decision – the case is now before the Court of Justice of the European Union (CJEU) on appeal. It remains unclear how the recent Supreme Court decision could affect the outcome of this pending appeal.
The adequacy decision remains fully in force and continues to permit data transfers to US organisations certified under the DPF, unless and until it is revoked by the Commission or annulled by the CJEU. For transfers to US recipients relying on other mechanisms, such as standard contractual clauses, the relevant transfer impact assessment may need to be revisited where it addresses the independence of the FTC.
For more information, see the US Supreme Court decision here and NOYB’s press release here.
EDPB publishes new guidance on anonymisation, web scraping and blockchain
On 7 July 2026, the European Data Protection Board (EDPB) adopted two new sets of draft guidelines for public consultation: one on anonymisation and one on web scraping in the context of generative AI. On the same day, it also adopted the final version of its guidelines on the processing of personal data through blockchain technologies, following public consultation.
The anonymisation guidelines are particularly timely. They update the earlier Article 29 Working Party approach in light of recent CJEU case law, including EDPS v SRB (C-413/23), and confirm that whether data is anonymous may depend on the perspective of the relevant entity: information may be anonymous for one party, but still personal data for another. The EDPB translates this into a practical assessment framework: in broad terms, organisations should assess whether the data still allows individuals to be isolated, linked with other information, or inferred from the dataset. The guidelines can be applied through a contextual approach, which looks at the means reasonably likely to be used by each relevant entity, or through a more conservative simplified approach, which disregards those entity-specific differences and may therefore lead organisations to treat data as personal even where it could be anonymous for some recipients. This sits against the backdrop of the current GDPR reform debate: the Commission’s Digital Omnibus proposal seeks to reflect the EDPS v SRB logic in the GDPR definition of personal data, although it remains disputed by some whether this would merely codify existing case law or go further in narrowing the concept of personal data.
The draft web scraping guidelines focus on scraping publicly available internet sources for the training or fine-tuning of generative AI models by private entities. The EDPB confirms that the GDPR applies where scraping involves personal data, and highlights challenges around transparency, data minimisation, accuracy, legal basis and special category data. In practice, the guidelines are likely to be most relevant for AI developers relying on legitimate interests, as they set out factors to consider in the balancing test and examples of mitigating measures, such as excluding certain sources or categories of data, improving transparency, facilitating rights requests, and deleting or anonymising data as soon as possible.
The final blockchain guidelines take a similarly practical approach. They emphasise that controllers should first assess whether blockchain is necessary and proportionate for the intended processing, and should consider the type of blockchain, the allocation of roles, international transfers, retention periods, security and data subject rights from the design stage. The EDPB also strongly discourages storing personal data in plain text on-chain and recommends, where possible, keeping additional personal data off-chain and using privacy-enhancing techniques to reduce compliance risks.
For more information, see the EDPB anonymisation guidelines here, the web scraping guidelines here and the final blockchain guidelines here.
CJEU clarifies interplay between GDPR complaints and court actions
On 18 June 2026, the Court of Justice of the European Union (CJEU) gave guidance on how data subjects can pursue remedies under the GDPR where both administrative and judicial proceedings are possible. The Court held that a data protection authority cannot reject a complaint under Article 77 solely because judicial proceedings on the same subject matter are already pending under Article 79. The GDPR provides data subjects with parallel and independent remedy routes, and national law may not require them to choose one or the other.
The CJEU observed that rejecting a complaint simply because a court case is ongoing could leave individuals without effective protection, especially if the court does not ultimately rule on the merits. Instead, the Court suggested that, where needed, supervisory authorities may suspend their administrative procedure pending the outcome of the judicial proceedings, rather than dismissing the complaint outright.
For more information, see the judgment here.
European Health Data Space: finalised secondary use guidelines and new consultation on data enrichment and research outcomes
In June 2026, TEHDAS2 – the EU joint action supporting the implementation of the European Health Data Space (EHDS) – finalised a batch of guidelines from its second public consultation wave. Two of these are of particular relevance to health data holders. The first sets out the minimum process for health data holders once a data permit or request is approved: delivering data within the three-month statutory timeframe, limiting delivery to the scope of the permit, keeping dataset catalogue entries up to date, and excluding opted-out individuals' data, along with optional good practices to help reduce delays.
The second guideline addresses data minimisation and privacy safeguards across the access lifecycle, explaining when pseudonymisation, anonymisation or synthetic data are appropriate and clarifying that responsibility for guarding against re-identification is shared between the health data access body (HDAB) and the health data user, while the HDAB retains final oversight.
A third wave of TEHDAS2 draft guidelines was also opened for public consultation in May 2026. Two of these are of particular interest to health data users.
- The first addresses data enrichment: the addition of new variables, annotations or contextual information to a dataset once a health data user is working within a secure processing environment. It distinguishes enrichment from data linkage, discusses how enrichment can affect re-identification risk, and sets out how enrichment outputs might be documented and, in some cases, communicated back to the health data holder.
- The second concerns the handling of research outcomes: it clarifies health data users' obligations to report results to the HDAB that granted access (in principle no later than 18 months after processing is completed), the output-control rules that apply before results may leave the secure processing environment, and how intellectual property generated from secondary use interacts with these transparency obligations.
For more information, see the finalised guideline on delivering data for secondary use here, the finalised guideline on privacy safeguards here, and both the draft guideline on data enrichment and draft guideline on handling research outcomes here.
Digital Omnibus negotiations continue, with separate GDPR record-keeping simplification advancing
The Digital Omnibus – the Commission’s proposal to simplify parts of the EU digital rulebook, including the GDPR, ePrivacy Directive, Data Act, Data Governance Act and NIS2 – has not yet reached a Council negotiating mandate. The Cypriot Presidency had intended to seek a mandate for trilogue negotiations on 26 June 2026, but ultimately decided not to do so after it became clear that there was a blocking minority among Member States.
Contested amendments include changes to the definition of personal data, which the EDPB and EDPS have criticised as narrowing the concept of personal data and adversely affecting the fundamental right to data protection, as well as proposals concerning AI-related processing, data breach notifications, DPIAs and browser-level consent signals. By contrast, the proposed single-entry point for incident reporting appears to be one of the less controversial elements.
Separately, progress has been made on the Omnibus IV proposal, which includes a targeted amendment to Article 30 GDPR. Under the agreed compromise text, organisations with fewer than 1,000 employees would generally be exempt from maintaining records of processing activities, but only unless – and to the extent that – a specific processing activity is likely to result in a high risk to individuals’ rights and freedoms. Records would still be required for those high-risk activities and, in any event, for core activities requiring appointment of a DPO under Article 37(1)(b) or (c) GDPR.
These two files should be distinguished from the Digital Omnibus on AI – the set of amendments to the AI Act (see here).
For more information, see our Digital Omnibus Update on the original proposal here.
Data breach management: EDPB adopts a common EU template for personal data breach notifications under Article 33 GDPR
On 10 June 2026, at the conclusion of its 121st plenary meeting, the European Data Protection Board (EDPB) adopted a common EU template for the notification of personal data breaches under Article 33 GDPR and opened it to public consultation until 5 August 2026. The initiative implements the EDPB's "Helsinki Statement" on the simplification of GDPR compliance and on the strengthening of consistency across Member States.
In the case at hand, the EDPB acknowledged that, notwithstanding the harmonised framework set out in Article 33(3) GDPR, notification requirements and formats have historically diverged across Member States, resulting in significant operational complexity for controllers—particularly those operating on a cross-border basis. The template is designed to be implemented by national supervisory authorities through a dedicated IT tool, incorporating predefined values, drop-down menus and recommended tooltips to guide notifying controllers.
While the structure of the template broadly reflects the minimum information required under Article 33(3) GDPR, the level of detail requested extends considerably beyond that threshold. The EDPB has introduced classifications of the impact on confidentiality, integrity and availability of the data, a predefined list of incident types (including inter alia ransomware, hacking, malware, phishing, data exfiltration and incorrect access permissions), and detailed categories of personal data affected (e.g. basic identification data, contact information, biometric data, employment-related health data, location data). The template also envisages the disclosure of technical and organisational measures in place at the time of the breach, such as pseudonymisation, encryption, access controls, incident logging and periodic audits.
The EDPB emphasised that the template does not modify the substantive obligations under the GDPR, nor does it alter the assessment of whether a breach is subject to notification. Its objective is rather to structure, harmonise and unify breach notification processes across the Union. Following the public consultation, the EDPB will define the timeline for the practical implementation of the template by all national Data Protection Authorities.
For more information, see here.
Data governance and data protection: EDPB adopts a mandate to develop FAQs on the interplay between the Data Act and EU data protection law
At its 121st plenary meeting held on 8-9 June 2026, the European Data Protection Board (EDPB) adopted a mandate to develop a set of Frequently Asked Questions (FAQs) on the interplay between Regulation (EU) 2023/2854 (the "Data Act") and EU data protection law, with the objective of supporting a consistent understanding of how the GDPR and the Data Act provisions apply in practice.
In the case at hand, the EDPB acknowledged that the entry into application of the Data Act on 12 September 2025 has raised a number of practical questions for controllers, processors and data holders, particularly in relation to the processing of personal data generated by connected products and related services and the exercise of data subjects' rights alongside the new "user" rights introduced by the Data Act. The FAQs are intended to complement, rather than duplicate, the existing regulatory framework, and to support a harmonised interpretation across the Union.
Although the FAQs have not yet been published, the mandate adopted by the EDPB reflects the increasing need for cross-regulatory coordination between the GDPR and the other components of the EU digital acquis. The Data Act, in particular, interacts with the GDPR on several critical aspects, including: the identification of the applicable legal basis for the making available of personal data at the request of the user; the allocation of controllership between data holders, users and third-party data recipients; the interplay between the user's right to access and share data under Article 4 and Article 5 of the Data Act and the data subject's rights under Articles 15 and 20 GDPR; and the safeguards applicable to the international transfer of non-personal data under the Data Act, where personal data may also be involved.
The mandate is part of a broader strategic effort by the EDPB to strengthen cross-regulatory cooperation, as also confirmed by the parallel adoption of a mandate on joint EDPB-AMLA Guidelines on partnerships for information sharing under Article 75 of the Anti-Money Laundering Regulation, and by the ongoing work on the interplay between the GDPR and the DSA, DMA, AI Act and Data Act.
For controllers and processors active in sectors covered by the Data Act—including manufacturers of connected products, providers of related services, data intermediation services and cloud/edge providers—these forthcoming FAQs will represent an important reference tool for aligning contractual arrangements, technical measures and internal governance frameworks with both the GDPR and the Data Act. In the meantime, organisations may consider undertaking a preliminary mapping of the personal data flows generated by their connected products and related services and reviewing their contractual documentation with users and third-party data recipients in anticipation of the EDPB guidance.
For more information, see here.
Financial services and data protection: EDPB and AMLA to develop Joint Guidelines on partnerships for information sharing under the Anti-Money Laundering Regulation
On 1 July 2026, the European Data Protection Board (EDPB) and the newly established Anti-Money Laundering Authority (the "AMLA") announced the launch of their joint work on Joint Guidelines on partnerships for information sharing under Article 75 of Regulation (EU) 2024/1624 (the "AML Regulation"). The initiative reflects the mandate adopted by the EDPB at its 121st plenary meeting of 8-9 June 2026 and represents one of the first concrete deliverables of the structured cooperation between the two authorities.
In the case at hand, the Joint Guidelines are intended to clarify the interplay between the AML framework and the GDPR with specific reference to the so-called "partnerships for information sharing"—i.e. the cooperative arrangements through which credit institutions, financial institutions and, where applicable, competent authorities may share personal data (including special categories of data, and data relating to criminal convictions and offences) for the purpose of preventing and combating money laundering and terrorist financing.
Although the Joint Guidelines have not yet been published, their expected scope covers, in particular, the following aspects:
- the identification of the legal basis for the processing of personal data within information-sharing partnerships, taking into account both the general regime of Article 6 GDPR and the specific derogations for special categories of data under Article 9 GDPR;
- the safeguards and technical and organisational measures to be implemented to ensure a level of security appropriate to the risk, including in relation to profiling and automated decision-making;
- the exercise of data subjects' rights in a context in which restrictions may apply on the basis of Article 23 GDPR and of the specific confidentiality obligations under the AML framework;
- the allocation of controllership and responsibility among the participants in the partnership, and the interplay with the sector-specific supervisory framework applicable to obliged entities.
The initiative is part of a broader effort by the EDPB to strengthen cross-regulatory cooperation with other EU authorities, as also evidenced by the parallel work on the interplay between the GDPR and other components of the EU digital and financial acquis, including the Data Act, the Digital Services Act, the Digital Markets Act and the AI Act.
For data controllers and processors active in the banking, financial services, fintech and payment services sectors, the forthcoming Joint Guidelines are expected to become a key reference tool for the design of information-sharing arrangements, internal AML/KYC procedures and related contractual documentation. In the meantime, obliged entities may consider undertaking a preliminary mapping of the personal data flows involved in existing or planned information-sharing partnerships and reviewing their AML compliance framework in anticipation of the joint guidance.
For more information, see here.
Belgium
Belgian and Spanish DPAs publish recommendations for the video games sector
On 18 June 2026, the Belgian Data Protection Authority and the Spanish Data Protection Authority jointly published Recommendations and Best Practices for Data Protection in Video Games. The authorities describe this as the first document prepared by European data protection authorities specifically to promote GDPR-compliant design, development and distribution of video games. The guidance is aimed at the broader gaming ecosystem, including developers, studios, publishers, cloud providers, analytics tools, anti-cheat systems, AI providers and legal teams.
The guidance reflects the authorities’ view that modern video games may involve extensive personal data processing, going well beyond basic account data. In particular, it highlights telemetry, behavioural inference, profiling and automated decision-making.
In terms of recommendations, the document focuses on practical GDPR compliance across the game lifecycle, including allocation of GDPR roles, lawful bases, privacy by design and default, transparency, data minimisation, data subject rights, security and record-keeping. Specific attention is given to higher-risk areas such as AI-driven and social features, children’s data, telemetry used for profiling, and monetisation models such as microtransactions, personalised offers and loot boxes.
Although the document is not EDPB guidance, it is more than a single-authority position and may become an important reference point for the gaming sector in Europe.
For more information, see the Joint Recommendations and Best Practices here.
Belgian DPA annual report highlights data brokers and AI
On 29 June 2026, the Belgian Data Protection Authority (BDPA) published its 2025 annual report, which points to several priorities likely to remain relevant in 2026. In particular, the BDPA identifies data brokers as a key area of attention, noting that the sale of personal data was an important focus in 2025 and will continue to be so in 2026. The report highlights recurring concerns around transparency, lawful basis and the complexity of data-sharing chains, as well as several enforcement actions against data brokers.
The report also confirms that AI is becoming an increasingly concrete enforcement topic. The BDPA points in particular to investigations involving model training and predictive systems, where recurring issues relate to legal bases, legitimate interest assessments, DPIAs, transparency and substantiation of anonymisation claims.
For more information, see the BDPA’s 2025 annual report here (in French).
Brussels Market Court confirms consent requirements for data brokers
On 3 June 2026, the Brussels Court of Appeal, sitting as the Market Court, ruled in a case concerning a commercial data broker. The case arose from a BDPA decision, which found that the broker had unlawfully processed and resold personal data for direct marketing purposes without demonstrating a valid legal basis, and imposed a €40,000 fine.
The Market Court upheld the finding of unlawful processing. In particular, it confirmed that the broker had failed to demonstrate valid consent for the resale of the data for direct marketing purposes. In particular, the Court accepted that the consent was based on an opt-out rather than an affirmative act, that it was not specific to resale for direct marketing, and that the broker did not adequately identify its role. The Court also confirmed that a data broker cannot meet its GDPR accountability obligations merely by relying on contractual assurances or statements from other actors in the data chain However, the Court partially annulled the BDPA’s corrective measures and reduced the fine to €5,000.
The judgment is a useful reminder of the evidential burden on data brokers relying on consent.
For more information, see the judgment here (in French).
Middle East
UAE Introduces Minimum Age Requirement for Social Media Use
On 17 June 2026, the UAE Cabinet issued Cabinet Resolution No. (106) of 2026 Regarding the Regulation of Children’s Access to Social Media Platforms, establishing a new framework governing children’s use of social media platforms in the UAE. The Resolution prohibits children under the age of 15 from creating, using, or operating personal social media accounts and requires platforms to prevent access to core interactive features. Children aged 15 to under 16 may access social media only subject to enhanced protections, including age-appropriate content filtering, restricted interactions, parental controls, usage limits, and safeguards for higher risk features such as private messaging and live streaming.
Social media platforms must implement reliable age-verification mechanisms, monitor and disable non-compliant accounts, and are prohibited from using children’s personal data for behavioural advertising or profiling. The Resolution also places obligations on caregivers not to circumvent age verification measures and confirms that parental consent cannot be used to override restrictions. Compliance will be overseen by the National Media Authority (the “NMA”) and the Telecommunications and Digital Government Regulatory Authority (the “TDRA”), with platforms being granted a 12-month transition period to achieve compliance.
For more information, see the Cabinet Resolution No. (106) of 2026 Regarding the Regulation of Children’s Access to Social Media Platforms here.
DIFC Consults on Amendments to Data Protection Regulations for AI Governance and Certification Frameworks
On 18 June 2026, the Dubai International Financial Centre Authority (the “DIFCA”) launched Consultation Paper No. 3 of 2026 proposing amendments to the DIFC Data Protection Regulations to strengthen the governance of artificial intelligence and autonomous systems processing personal data. The proposed amendments support DIFC’s ambition to become the world’s first AI native financial centre and seek to clarify the requirements applicable to organisations deploying AI systems.
Key proposals include (i) updating Regulation 10 to enhance privacy by design and responsible AI requirements; (ii) introduction “Safety” as a core design principle alongside fairness, transparency, security, ethics and accountability; (iii) expanding governance obligations for organisations deploying autonomous and semi-autonomous systems; (iv) clarifying the role, responsibilities and competencies of the Autonomous Systems Officer (“ASO”), including additional regulatory, technical and organisational expertise requirements for high-risk AI processing activities; and (v) introducing a new Regulation 11 empowering the Commissioner of Data Protection to recognise accreditation and certification frameworks, including privacy and AI-related certification schemes.
The proposed amendments were posted for a 30-day public consultation period with the deadline for providing comments ending on 18 July 2026, following which DIFCA will consider stakeholder feedback before finalising and implementing the amendments.
For more information, see the DIFC consultation announcement here, and the Consultation Paper No. 3 of 2026 – Updated Data Protection Regulations here, and the proposed changes Annex here.
UAE Establishes Federal Artificial Intelligence and Data Authority
On 14 June 2026, the UAE Cabinet approved the establishment of the Artificial Intelligence and Data Authority, a new federal body that will serve as the UAE’s central authority for artificial intelligence, data governance and digital government. Reporting directly to the Cabinet and chaired by Omar Sultan Al Olama, the Authority consolidates the functions previously carried out by the Office of Artificial Intelligence, Digital Economy and Remote Work Applications, the Digital Government Sector of the Telecommunications and Digital Government Regulatory Authority (the “TDRA”), and the UAE Data Office.
Its mandate includes developing and implementing the national AI strategy, proposing legislation and policies relating to AI and data governance, managing government data, establishing AI and data standards, overseeing compliance across federal entities, supporting digital transformation initiatives, and strengthening international cooperation in AI and digital government. The creation of the Authority signals the UAE’s move toward a more centralised and coordinated approach to AI and data regulation and is expected to accelerate the development of the country’s broader regulatory framework for artificial intelligence and personal data protection.
For more information, see the UAE Cabinet announcement here.
China
Regulators issued measures for cyber/data security risk assessment
On 18 June, the Cyberspace Administration of China (CAC), the Ministry of Industry and Information Technology and the Ministry of Public Security jointly issued the Measures on Cyber/Data Security Risk Assessment (Measures). To take effect on 20 August 2026, the Measures aim to implement the risk assessment obligations set out under China’s Data Security Law (DSL) and Administrative Regulation on Network Data Security (NDSR).
Pursuant to the DSL and the NDSR, the processors of “Important Data” (such data that once leaked, damaged, tampered with or illegally used, may directly harm national security or public interest) must carry out risk assessments annually and prior to certain processing activities. The specific scope of Important Data is to be set out in the catalogues formulated by regional and sectoral regulators.
The Measures further introduce the below provisions, among others:
- if there is a material change affecting the security status of Important Data, a supplementary assessment must be conducted promptly for the affected activities;
- sectoral regulators shall periodically organise risk assessment inspections within their sectors and review how the Important Data processors conduct their assessments;
- the Important Data processors may conduct the risks assessments by themselves or entrust a third-party institution to do so, provided that the same institution (and its affiliates) may not perform more than three consecutive annual assessments for the same Important Data processor;
- annual risk assessment reports must be reported to the sectoral regulator within 20 working days after completing the assessment, or to the CAC or its provincial counterparts if there isn’t a competent sectoral regulator;
- annual risk assessment reports must be retained for at least three years; and
- authorities may order rectification where Important Data processing activities pose risks to national security or the public interest. For serious failures, authorities may require the processor to stop processing Important Data.
Processors that process only ordinary/general data are encouraged (but not required) to conduct a risk assessment at least once every three years. Note that “processors” defined under Chinese law are equivalent to “controllers” in GDPR context.
For more information, see the legal text here and CAC’s press release here (in Chinese only).
Data classification and grading guidelines issued for financial information services (FIS)
On 13 June 2026, the CAC and several financial and statistics regulators jointly issued the Data Classification and Grading Guidelines for FIS (Guidelines), which apply to FIS providers operated within China.
Under Chinese law, FIS refers to the services that provide users engaged in financial analysis, financial transactions, financial decision-making or other financial activities with information and/or financial data that may influence the financial markets. In essence, FIS is a special type of information / data services, and the lists of registered FIS providers are published by the CAC.
The Guidelines provide criteria and guidance for FIS providers’ internal data classification (ie business data, user data, enterprise data) and grading (ie core data, Important Data, sensitive general data and non-sensitive general data). Notably, Annex A of the Guidelines provides examples of FIS data classification and grading, where the “suggested lowest grading” for certain data types is “Important Data” – for example, commodities data, industrial data or sectoral indicators, reports, industrial chain data, supply and demand figures where the coverage, time span, accuracy and other characteristics exceed those of data publicly released by the relevant authorities (including data historically made public) and reflect status at the provincial level or above.
Although the Guidelines do not impose any direct obligations on financial institutions, these organisations may still be indirectly impacted if they source data from FIS providers (eg for research and investment purposes). For example, as the cross-border transfer of Important Data requires administrative approval by the CAC, it could be more difficult for foreign organisations to source such data from the FIS providers. In addition, as the key financial service regulators (ie PBOC, NFRA, CSRC) have participated in formulating the Guidelines, the examples can reasonably be regarded as reflecting these regulators’ current thinking on the scope of Important Data in the financial services sectors.
For more information, see the official text here and CAC’s press release here (in Chinese only).
Hong Kong
HKMA issued code of practice about critical infrastructure
On 2 June 2026, the Hong Kong Monetary Authority (HKMA) issued a Code of Practice (CoP) pursuant to the Protection of Critical Infrastructures (Computer Systems) Ordinance (CI Ordinance).
The CoP provides guidance as to how would a computer system be designated as a critical computer system (CCS) under section 13 of the CI Ordinance, for example if the computer system is critical for the core function of the critical infrastructure; the destruction of the system would cause severe impact to the core function; the system stores or processes sensitive data used directly in the provision of essential services; or the system is highly related to other CI operator(s). The CoP also states that the HKMA may require information to designate a CCS, including the facts and functions, architecture, nature and volume of sensitive data and manufacture-related information.
The CoP also mentions obligations for such Authorised Institutions that are designated by the HKMA as CI operators, including the obligations to maintain office in Hong Kong, notify operator changes, set up and maintain computer-system security management unit, notify material changes to certain computer systems, submit and implement computer-system security management plan, and conduct security risk assessments and audits.
For more information, see the full CoP here.
Singapore
PDPC consults on proposed advisory guidelines on the use of personal data in Generative AI
On 2 June 2026, the Personal Data Protection Commission (PDPC) issued a public consultation on its proposed Advisory Guidelines on the use of Personal Data in Generative AI. The proposed guidelines address the application of the Personal Data Protection Act 2012 (PDPA) across the generative AI lifecycle, including model development, deployment, the allocation of responsibilities among AI ecosystem participants, and the handling of individuals' requests relating to personal data.
Key points in the guidelines include:
- Organisations may continue to rely on the existing "publicly available data” exception to collect personal data (including via web scraping) for generative AI model training without consent. This is provided that the data is genuinely publicly accessible and the use is reasonable in the circumstances. Moreover, data behind "digital barriers" (such as paywalls, logins, etc.) is not automatically excluded from this exception.
- “AI-specific Notifications” should be provided when using personal data to develop Generative AI Models, specifically for large-scale AI model training or fine-tuning. Such notifications should include details on the function of the Generative AI Model, a description of the type of personal data used, how such data will train the model, and how individuals can decline or withdraw consent. General statements stating that personal data may be used for purposes such as “new product development” are likely insufficient.
- The PDPC recognises the technical difficulty of tracing or removing personal data once it has been absorbed into training datasets in order to comply with the PDPA’s access and correction obligations. However, organisations are still expected to adopt best practices where reasonable. This includes adopting upstream data-handling measures to verify data accuracy and reviewing access and correction requests on a case-by-case basis.
For more information, see the consultation paper here.








.jpg?crop=300,495&format=webply&auto=webp)



_11zon.jpg?crop=300,495&format=webply&auto=webp)



_11zon.jpg?crop=300,495&format=webply&auto=webp)

