IAPP Weekly News 17.08.2026-21.08.2026

8/25/2026IAPP News

Latest Worldwide Developments on Personal Data

  1. New amendments to Alberta's Health Information Act reshape data sharing and AI compliance processes.

Recent amendments to the Health Information Act  in Alberta, Canada, came into force, establishing new standards for health data governance. While imposing new obligations such as patient notification and mandatory electronic logging when using AI tools, the regulation facilitates collaboration among health custodian professionals through a "shared health information" model. Additionally, the compliance burden is eased by allowing technology vendors and professional colleges to participate directly in privacy impact assessment processes.

Click on the link for the full story.

  1. Local backlash against AI data centers leads to a new infrastructure and political crisis in the US.

Surging data center projects driven by growing generative AI investments in the US face harsh backlash from local communities over electricity and water consumption as well as land use. Similar to past railroad and powerline developments, the concentration of social costs in specific regions drives the public toward protests and legal action, resulting in state-level moratoriums. The process escalates tension between local concerns and national technology goals, directly impacting political dynamics and campaign strategies.

Click on the link for the full story.

  1. The Canadian Privacy Act provides regulatory oversight against manipulative interface designs in online retail.

Manipulative interface (dark pattern) techniques on e-commerce platforms such as Temu and Shein—including misleading buttons directing users to share data, false urgency cues, and hidden marketing consents—are coming under legal scrutiny in Canada. Although the Personal Information Protection and Electronic Documents Act does not contain a standalone "dark pattern" clause, it can regulate such coercive interfaces through valid consent requirements and appropriate purpose principles. Experts recommend that companies present consent and refusal options with equal ease and prioritize transparency.

Click on the link for the full story.

  1. The EU's new Anti-Money Laundering Regulation introduces data standards aligned with the GDPR.

The European Union's new Anti-Money Laundering ("AML") Regulation, entering into force on July 10, 2027, establishes specific rules on personal data usage while strengthening the fight against financial crimes. Introducing a requirement for human intervention in automated decisions within customer due diligence and transaction monitoring, the regulation strictly prohibits using data collected for AML purposes in general commercial or marketing activities. Furthermore, processing sensitive data is permitted under strict security measures, and data retention periods are standardized to five years.

Click on the link for the full story.

  1. The EU's new Cloud and AI Development Act sets new standards for digital sovereignty.

The European Commission presented the Cloud and AI Development Act proposal to reduce the EU's reliance on foreign tech providers and bolster its digital sovereignty. Still early in the legislative process, the regulation defines four distinct assurance levels for the public sector and critical infrastructure, introducing requirements for data localization, cybersecurity certification, and EU-based infrastructure. The proposal also includes incentives to accelerate data center deployment and research-focused leadership initiatives.

Click on the link for the full story.

  1. The Australian Information Commissioner updated guidelines on facial recognition technology and data security.

The Office of the Australian Information Commissioner ("OAIC") published updated guidance on the use of facial recognition technology in the retail sector and data security management. Emphasizing that social license must be kept high alongside legal compliance for processing biometric data in public spaces, the OAIC urged companies to establish transparent governance mechanisms. The agency also announced that following an investigation into a Qantas data breach affecting approximately 5 million individuals, current security controls were deemed sufficient and no further enforcement action would be taken.

Click on the link for the full story.

  1. The European Commission launched a new consultation on digital sovereignty and international data flows.

The European Commission initiated a targeted public consultation to identify legal, technical, and organizational obstacles faced by EU-based institutions and companies in international data transfers. Open for feedback until September 8, the consultation addresses third-country data localization requirements, public authority access risks, and discriminatory practices. The initiative aims to expand the EU's digital sovereignty strategy to cover non-personal data, boosting global competitiveness and data security.

Click on the link for the full story.

  1. The US Federal Trade Commission published a draft policy statement on personal data usage in personalized pricing.

The US Federal Trade Commission ("FTC") introduced a new draft policy targeting deceptive personalized pricing systems implemented by retailers using consumer data. The draft requires businesses to clearly disclose that prices are personalized, the basis for that personalization, and the types of personal data used. Emphasizing aggressive enforcement under Section 5 of the FTC Act, the agency highlighted that businesses hiding data usage could violate the law, amidst growing pressure across states and Congress to ban such pricing methods entirely.

Click on the link for the full story.

  1. The perspective of operational cyber teams plays a vital role in AI governance programs.

While organizations building AI governance often focus on transparency, fairness, and legal compliance, operational cyber teams highlight system behaviors under adversarial pressure and degraded conditions. Experts emphasizing that technical risks like data poisoning, prompt injection, and automation bias must not be overlooked note that human oversight can also prove practically insufficient due to high workloads. To manage AI risks effectively, involving operational cyber teams in planning processes from the outset is recommended.

Click on the link for the full story.

  1. The Brazilian Data Protection Authority published a technical analysis report addressing deepfake and synthetic content risks.

The Brazilian Data Protection Authority published a Technology Radar report examining personal data protection, cybersecurity, and digital fraud risks associated with AI-generated synthetic content (deepfakes). The report emphasized that governing deepfakes cannot be limited to detection after content creation; data collection, model training, and dissemination processes must be managed holistically. Companies are advised to act cautiously regarding biometric data usage, product design, and vendor oversight to prevent risks at the source.

Click on the link for the full story.