From 10 December 2026, the new Australian Privacy Principle (APP) 1.7 in the Privacy Act 1988 (Cth) will require entities to disclose the use of automated (or substantially automated) decision-making (ADM) in their privacy policies.

Disclosure is required where computer programs are used to make decisions, or do things substantially and…

Continue Reading Australia: To Disclose or Not To Disclose? Preparing to meet the new ADM disclosure requirements

The UK GDPR establishes a robust framework for the protection of personal data, requiring organisations to give due regard to individuals’ data protection rights. Importantly, it recognises that the consequences of a data breach may extend beyond financial loss. Article 82 UK GDPR, supplemented by section 168 of the Data Protection Act 2018, provides a…

Continue Reading UK: Scottish courts reaffirm threshold for GDPR damages claims

On 17 September 2026, the European Commission unveiled its proposal for the EU KIDS Act (EU Keeping Internet Digital Spaces Accountable and Trustworthy), a harmonised EU framework designed to reshape how children engage with online services. The proposal goes well beyond age verification requirements and seeks to fundamentally change the design of digital services used…

Continue Reading EU: Commission proposes a new KIDS Act to protect children online

Across the Asia-Pacific region, privacy and cybersecurity regulation continues to evolve rapidly, with regulators increasingly moving from legislative build-out to practical compliance and enforcement. Recent developments in Vietnam, South Korea and Indonesia illustrate this trend and signal heightened regulatory expectations for organisations operating in the region.

Below is a snapshot of what happened, and why…

Continue Reading APAC Privacy Update: Major Regulatory Developments in Vietnam, South Korea and Indonesia Set the Stage for Enhanced Privacy Enforcement

A consultation draft has been published outlining a number of major reforms to the Australian privacy framework. If implemented in its current form, the Privacy Amendment (Personal Data Protection) Bill 2026 (Amendment Bill) would significantly reshape how Australian businesses collect, use, disclose and protect personal information under the Privacy Act 1988 (Cth) (…

Continue Reading Australia: Privacy reform – consultation draft outlines proposed next steps

The first major EU Cyber Resilience Act (the “CRA“) compliance deadline is fast approaching. From 11 September 2026, manufacturers within scope of the CRA must comply with new reporting obligations for actively exploited vulnerabilities and severe incidents. These requirements take effect more than a year before the CRA’s substantive provisions, making them an…

Continue Reading EU: Preparing for the Cyber Resilience Act’s September 2026 Reporting Obligations

On 7 July 2026, the European Data Protection Board (EDPB) adopted its draft Guidelines 02/2026 on Anonymisation for public consultation. The Guidelines provide long-awaited clarification on when data can truly be considered anonymous under the GDPR, updating the previous Article 29 Working Party’s 2014 Opinion on anonymisation to reflect significant legal, and technological…

Continue Reading EU: EDPB Publishes Draft Guidelines on Anonymisation

Today, 17 July 2026, marks an important milestone under the EU’s Critical Entities Resilience Directive (CER), as Member States are required to identify and designate the entities considered “critical” for the provision of essential services.

Understanding the CER Directive

The CER forms part of the EU’s broader effort to strengthen the resilience of…

Continue Reading EU: CER Directive enters a new phase as “critical entity” designation deadline arrives

Deepfakes (AI-generated synthetic media capable of producing highly realistic images, audio, and video of real individuals) have graduated from a mere novelty to a genuine legal concern. Using neural networks trained on visual and audio data, deepfake systems can replicate a person’s appearance and voice with remarkable fidelity, producing content that is often indistinguishable from…

Continue Reading EU and China: Deepfakes and the law: perspectives from the EU and China


The United States Supreme Court’s decision in Trump v. Slaughter significantly alters the constitutional framework governing independent regulatory agencies and may have implications for transatlantic personal data transfers.

The six-to-three decision overturns Humphrey’s Executor v. United States, a 1935 case establishing that Federal Trade Commission (FTC) commissioners could be removed by the President only…

Continue Reading US / EU: US Supreme Court overturns Humphrey’s Executor: Implications for independent agencies and US–EU data transfers