On September 17, 2026, the European Commission (the “Commission”) published its proposal for a new EU framework on child safety online (the “KIDS Act”). The proposed Regulation aims to introduce EU-harmonized age-based account restrictions, safety-by-design rules, and age-assurance obligations across a broad range of digital services and systems.

The proposal is the latest of a growing body of initiatives aimed at strengthening children’s safety and privacy in the digital world, both in the EU and globally, as discussed in our recent blog post.

This post summarizes some of the KIDS Act’s key features.

Continue Reading The EU KIDS Act Proposal: Towards a New Regulatory Framework for the Protection of Children Online

On September 8, 2026, Kenya’s Office of the Data Protection Commissioner (“ODPC”) published new Guidance Notes for Cross-border Data Transfers (“Guidance”), providing organizations with more detailed guidance on the application of Kenya’s rules governing transfers of personal data outside the country.

The Guidance arrives at an interesting time for Kenya’s data protection framework. Kenya and the European Union are currently engaged in an adequacy process, and in June 2026 the European Commission welcomed progress in that process, noting the “positive assessment so far” and its intention to conclude the process as soon as possible. Against that backdrop, several features of the Guidance will look familiar to organizations accustomed to the EU General Data Protection Regulation (“GDPR”), including its treatment of adequacy, appropriate safeguards, Binding Corporate Rules (“BCRs”), assessments of third-country laws, and supplementary safeguards. But the comparison only goes so far. The Guidance also illustrates several important differences between Kenya’s cross-border transfer framework and the GDPR, including in relation to sensitive personal data, data localization, legitimate interests, and onward transfers. For multinational organizations seeking to use global transfer frameworks across jurisdictions, those differences are important.

Continue Reading Kenya Issues New Cross-Border Data Transfer Guidance: Familiar Concepts, but Important Local Differences

At the end of August, the California legislature passed three bills that would regulate the use of AI in the employment context. These bills are now on Governor Newsom’s desk, and he has until September 30 to sign or veto. Below is a summary of the three bills.

Continue Reading California Legislature Advances AI Employment Bills

In recent months, children’s online safety and privacy have moved to the top of the EU’s digital agenda. The European Commission is expected to outline its proposal on minors’ access to social media this week, a potentially significant development that would build on the recommendations of the Commission’s Special Panel on child safety online and mounting pressure from Member States.

The EU is not moving in isolation. Similar debates on minors’ access to online platforms, age assurance, and safety-by-design obligations are emerging in other jurisdictions. These include Australia and the United Kingdom, as well as a rapidly developing patchwork of state-level age-verification, app-store, and device-based age-assurance requirements in the United States.

This post provides a horizon-scanning update on the principal regulatory developments at the EU level, selected national developments, and some relevant developments outside the EU.

Continue Reading Horizon Scan: Children’s Online Safety and Privacy (EU and Beyond)

On August 28, 2026, the California Legislature passed SB 690, a significant bill aimed at curbing the flood of demand letters and lawsuits asserting “pen register” claims under the California Invasion of Privacy Act (“CIPA”). If enacted, the bill would eliminate the private right of action for website-based pen register claims and could affect many pending lawsuits filed since January 1, 2025.

Continue Reading California Legislature Passes CIPA Pen Register Reform Bill and Sends It to Governor

On August 19, 2026, Connecticut Attorney General William Tong announced a $275,000 settlement with online tax preparation company TaxAct over allegations that the company improperly disclosed taxpayer information to advertising partners through third-party tracking technologies on its website. The Attorney General alleged that, between January 2018 and December 2022, TaxAct used third-party tracking technologies for analytics and marketing purposes and, in doing so, disclosed detailed taxpayer information without informing consumers.

The settlement is notable because it highlights regulatory scrutiny over the disclosure of financial information, and also because it imposes extensive governance, monitoring, and auditing requirements on TaxAct relating to the use of third-party tracking technologies. In addition, the settlement does not specify what law was allegedly violated.

Continue Reading Connecticut Attorney General Settles with TaxAct Over Sharing Taxpayer Data

On August 12, 2026, the Administration published a National Security Presidential Memorandum (“NSPM”) (“Expanding Capabilities to Combat Transnational Cyber-Enabled Crime”) that signals the Administration’s focus on private-sector participation in offensive cyber operations by establishing a federally supervised program to enable private sector participants to conduct offensive cyber operations against “Cyber-Enabled…

Continue Reading White House Releases National Security Presidential Memorandum on Expanding Capabilities to Combat Transnational Cyber-Enabled Crime

Employers increasingly rely on automated tools to help make decisions concerning hiring, promotion, discipline, and termination. In response, state legislatures and agencies have begun to regulate uses of these technologies, often referred to as automated decision-making technology (“ADMT”). These laws generally require entities that deploy ADMT in the employment context…

Continue Reading ADMT Law Round-Up: What Employers Need to Know About Recent ADMT Laws

On August 14, 2026, the French Constitutional Council (the “Constitutional Council”) struck down Article 1 of France’s Act to protect minors from the risks posed by the use of social media (the “Act”), which would have barred minors under the age of fifteen from accessing online social media services. The Constitutional Council held that the prohibition infringed on the freedom of expression and communication in a manner that was not appropriate, necessary, or proportionate to the objective pursued and, separately, that the legislature failed to provide the legal safeguards required to protect the right to respect for private life in connection with the age verification process that the ban would, by necessity, have entailed.

We summarise key aspects of the decision below.

Continue Reading French Constitutional Council Strikes Down Under-15 Social Media Ban

On July 20, 2026, the French data protection authority (the Commission Nationale de l’Informatique et des Libertés, “CNIL”) published a joint exploratory note with the French AI and Digital Council (“CIANum”) on the data protection implications of agentic AI (the “Note”). The Note is exploratory rather than prescriptive: it does not purport to state definitive regulatory expectations, and it does not announce forthcoming guidance. However, it does provide helpful considerations for when the EU’s General Data Protection Regulation (“GDPR”) might come under strain in the course of processing personal data via autonomous systems, and identifies legal and technical measures that might help mitigate potential risks. The CNIL frames this exercise as connected to its engagement with several international counterparts, including through the G7 data protection authorities during the French G7 presidency.

The Note is the latest in a rapidly accumulating body of regulator commentary on agentic AI, including by the UK ICO, Spanish AEPD, and Singaporean IMDA. Below are some key takeaways.

Continue Reading French CNIL Publishes Note on Agentic AI and Data Protection