IAPP Weekly News 22.06.2026-26.06.2026

6/30/2026IAPP News

 Latest Worldwide Developments on Personal Data

  1. ICO fines consultancy firm for sending 5.5M unsolicited marketing texts.

The U.K. Information Commissioner's Office issued a 300,000 GBP fine to a Manchester-based consulting firm that allegedly sent more than 5.5 million unlawful marketing texts between April 2022 and May 2025. The ICO said KRA Consultancy targeted consumers who were facing financial hardship, leading to more than 60,000 complaints being made to the Mobile U.K.'s spam reporting services. The company was ordered to stop sending marketing texts without consent within 30 days. It was also not registered with the Financial Conduct Authority, despite offering debt solution services.

Click on the link for the full story.

  1. CNIL urges consumers to remain cautious about data deletion phishing scams.

France's data protection authority, the Commission nationale de l'informatique et des libertés, said consumers who have had their data breached should remain cautious about emails that offer services to delete personal data from online platforms. The CNIL said consumers should not reply to the messages because many of these services are not legitimate, even though they may contain information about individuals' personal information.

Click on the link for the full story.

  1. EDPB updates guidance on One-Stop-Shop right to erasure framework.

The European Data Protection Board updated its guidance on the One-Stop-Shop right to erasure framework. The guidance offers information on how member state data protection authorities analyze organizations' processes to comply with right to erasure requirements. It also contains insight on the most common cases where the right to erasure is violated and what corrective measures EU DPAs issued in response.

Click on the link for the full story.

  1. How 'data embassies' could be solution for data localization requirements.

Writing for the Future of Privacy Forum, Chief Executive of the Singapore Academy of Law Yeong Zee Kin highlighted potential solutions to the ongoing digital sovereignty push around the world. As data localization requirements are being considered by world governments, Zee Kin suggested that "data embassies" could be an answer. He said they would be established through government-to-government relationships and would "extend domestic laws and standards of protection to data that has been exported.”

Click on the link for the full story.

  1. Meta halts program to use employee data to train AI tools.

Meta paused its plan to use tracking technology to monitor employees and use the collected data to train its AI tools after the program faced employee pushback, the Guardian reports. More than 1,600 employees signed a petition urging the company to not use their computer data for AI training, noting collecting and sharing information, such as performance data, meeting transcripts and internal messages, "raises serious concerns around privacy, consent, and trust in the workplace.”

Click on the link for the full story.

  1. EU ambassadors delay vote on Digital Omnibus compromise text.

Council of the European Union ambassadors removed the latest Digital Omnibus compromise text from the agenda during their meeting 25 June. Diplomats cited by the publication said they were not "optimistic" the law would pass, with several countries pushing for amendments. Key sticking points include disagreements over the definition of personal data, provisions on pseudonymization, and the removal of some rules on cookie banners. These issues are expected to be addressed when Ireland assumes the Council presidency in July.

Click on the link for the full story.

  1. European Commission's Europol reforms raise privacy, security concerns.

The European Commission proposed reforms that would allow the EU Agency for Law Enforcement Cooperation's European Cybercrime Centre and the EU Agency for Cybersecurity to collaborate on cybersecurity threats, though the proposal has raised concerns about law enforcement's collection and sharing of personal data. European Digital Rights Senior Policy Adviser Chloé Berthélémy urged the EU to not implement the proposal, claiming the mandate would grant Europol access to vast amounts of individuals' personal data, "swallowing our fundamental rights, and undermining justice, safety and accountability."

Click on the link for the full story.

  1. White House pushes Senate committee to block Big Tech CEOs from testifying in children's safety hearing.

The White House quietly lobbied U.S. Senate Committee on the Judiciary Chairman Chuck Grassley, R-Iowa, to shield Meta CEO Mark Zuckerberg and Google CEO Sundar Pichai from testifying at an upcoming committee hearing on their respective companies' children's online safety practices, Politico reports. The heads of Instagram and YouTube will testify in place of their bosses in the hearing tentatively scheduled for 28 July.

Click on the link for the full story.

  1. UK DUAA's data protection compliant requirements go into effect.

The U.K. Data (Use and Access) Act's data protection compliant obligations have gone into effect, requiring organizations to implement measures to accept complaints from individuals and address concerns within 30 days. Information Commissioner's Office Deputy Commissioner for Regulatory Policy Emily Keaney said a "clear and fair complaints process helps people get their issues resolved and helps organisations identify and fix problems early," noting the measures are not "just about compliance — it's about trust, transparency and good customer relationships.

Click on the link for the full story.

  1. New Zealand's OPC explains differences between privacy statements, notices, policies.

The Office of the Privacy Commissioner of New Zealand published guidance to help consumers understand the differences between a company's privacy statement, privacy notice and privacy policy in relation to Privacy Act 2020 obligations. The OPC said a privacy statement represents an "external public facing explanation that tells individuals what personal information is collected," the reason for collection and how personal information is used. A privacy notice is a disclosure issued at the point of data collection and a privacy policy is an organization's internal document that sets out procedures for legally handling personal information.

Click on the link for the full story.