IAPP Weekly News 27.07.2026-31.07.2026

8/4/2026IAPP News

Latest Worldwide Developments on Personal Data

  1. In July, the European Union increased its audits and legal sanctions under digital package regulations.

In July, the European Union carried out an intensive audit process under the Digital Services and Digital Markets Acts (DSA/DMA). While the Court of Justice of the European Union rejected Apple’s appeal against its "gatekeeper" designation under the DMA, the European Commission announced infringement findings and fines against tech giants including Google, AliExpress, Meta, and TikTok. The process demonstrated that the EU values constructive dialogue alongside monetary fines. Furthermore, online safety for children came to the forefront, with new steps taken regarding Child Sexual Abuse Material detection and bans on AI-generated explicit content.

Click on the link for the full story.

  1. Security risks of AI systems and regulatory steps shape the global agenda.

In July, the first major cyberattack carried out by autonomous AI models tangibly demonstrated the risks these systems can pose by breaching security boundaries. Following this development, industry representatives formed open-source security alliances, while geopolitical competition between the US and China escalated through AI restrictions. Meanwhile, the European Union clarified the legal framework for corporate compliance processes and cyber resilience by enacting new transparency and labeling guidelines under its AI Act.

Click on the link for the full story.

  1. Taiwan announced a new risk classification framework under its AI Basic Act.

Taiwan's Ministry of Digital Affairs announced a new four-part AI Risk Classification Framework to guide public institutions in implementing the AI Basic Act. Excluding military applications, this regulation aims to evaluate 20 risk subtypes across a four-stage process, covering technical design flaws, post-deployment issues, and societal impacts. While restrictions are introduced for high-risk systems, a balanced, sector-oriented, flexible governance model that supports innovation has been adopted.

Click on the link for the full story.

  1. The dichotomy of personalized and contextual advertising obscures real risks in digital advertising.

In ongoing digital advertising debates across the UK and the European Union, characterizing personalized ads as "bad" and contextual ads as "safe" presents a misleading approach. Contextual ads also carry data protection risks due to location and device data, and a mandatory shift toward this advertising model threatens media diversity by reducing publisher revenues. Experts emphasize that instead of merely labeling ad formats, risk-based and strictly enforced standards focusing on how collected data is processed should be implemented. 

Click on the link for the full story.

  1. Singapore announced new trust-oriented steps in digital governance and data protection.

As part of the Singapore Data Festival and the IAPP Asia Forum 2026, Singapore unveiled its new digital strategies that view data as essential infrastructure for innovation and economic growth. Personal data usage guidelines tailored for generative AI, transparency cards for AI chatbots, and a Digital Twin Playbook for enterprises were presented to the public. Additionally, a cooperation agreement was signed with Japan to strengthen cross-border data flows, aiming to turn trust into a competitive advantage in the digital ecosystem. 

Click on the link for the full story.

  1. The EDPB opened its new draft guidelines on anonymization for public consultation.

The European Data Protection Board (EDPB) published Draft Guidelines 02/2026, clarifying anonymization processes under the General Data Protection Regulation (GDPR). Based on the CJEU's EDPS v SRB ruling, the regulation introduces a new framework testing the re-identifiability of data subjects through contextual and simplified approaches. Offering recipient-oriented flexibility in data sharing, the draft relies on criteria such as non-singling out, non-linkability, and non-inferability, while requiring continuous updates to risk assessments in the face of emerging technologies like AI. 

Click on the link for the full story.

  1. China published draft amendments to its data security standard covering AI and cross-border transfers.

China's Standardization Committee (TC260) released a draft update to the GB/T 35273 standard, which serves as a compliance benchmark for the Personal Information Protection Law, for public comment. The draft introduces strict consent requirements for AI content generation, deepfakes, and IoT devices, while clarifying legal bases where consent is not required in contract and HR processes. Furthermore, it broadens the definition of sensitive data, outlines a framework to resolve cross-border data transfer conflicts, and imposes auditable compliance obligations on companies.

Click on the link for the full story.

  1. The FTC sued health platform Hims over sensitive data sharing and deceptive marketing.

The US Federal Trade Commission (FTC), joined by the states of California and Utah, filed a lawsuit against telehealth company Hims and Hers Health. It is alleged that, contrary to its privacy promises, the company shared patients' sensitive health data and on-site activity with advertising platforms. The lawsuit demonstrates that deceptive marketing claims can constitute an infringement despite disclosures in privacy policies, proving once again that the FTC maintains a strict enforcement line based on child privacy and consumer protection laws. 

Click on the link for the full story.

  1. Email-related data breaches necessitate the redesign of system controls for security.

According to the latest quarterly report published in the Newfoundland and Labrador region of Canada, 64% of public sector privacy breaches stemmed from email mistakes. These human errors, recurring despite years of training, indicate that the issue is not merely a lack of employee awareness but a flaw in system and workflow design. Organizations aiming to minimize breaches need to facilitate safe choices by implementing technical controls and automated warning mechanisms rather than relying on flawless human behavior. 

Click on the link for the full story.

  1. The EDPB published new data protection guidance on AI model training and web scraping methods.

The EDPB issued draft guidelines regarding the GDPR compliance of personal data collected via web scraping for training AI systems. While highlighting the principles of data minimization and transparency, the guidelines point out that sensitive data collected from publicly available sources can be processed inadvertently. Organizations are encouraged to adopt syntax-based filtering and synthetic data usage to prevent violations, emphasizing that implementing risk-mitigating security measures is essential for legal compliance. 

Click on the link for the full story.