On 7 July 2026, the European Data Protection Board (EDPB) adopted its draft Guidelines 02/2026 on Anonymisation for public consultation. The Guidelines provide long-awaited clarification on when data can truly be considered anonymous under the GDPR, updating the previous Article 29 Working Party’s 2014 Opinion on anonymisation to reflect significant legal, and technological

Continue Reading EU: EDPB Publishes Draft Guidelines on Anonymisation

Today, 17 July 2026, marks an important milestone under the EU’s Critical Entities Resilience Directive (CER), as Member States are required to identify and designate the entities considered “critical” for the provision of essential services.

Understanding the CER Directive

The CER forms part of the EU’s broader effort to strengthen the resilience of

Continue Reading EU: CER Directive enters a new phase as “critical entity” designation deadline arrives

Deepfakes (AI-generated synthetic media capable of producing highly realistic images, audio, and video of real individuals) have graduated from a mere novelty to a genuine legal concern. Using neural networks trained on visual and audio data, deepfake systems can replicate a person’s appearance and voice with remarkable fidelity, producing content that is often indistinguishable from

Continue Reading EU and China: Deepfakes and the law: perspectives from the EU and China

“Important data” is a concept unique to China law. It refers to data relating to specific topics, groups, or regions, or data that reaches a certain level of precision and scale, the tampering, destruction, leakage or illegal acquisition or use of which may directly jeopardize national security, economic operations, social stability, public health or safety.

Continue Reading CHINA: China’s Free Trade Zone Negative Lists – Early Signal of How “Important Data” May Be Defined

For years, China’s cross-border data transfer regime was long on rules but short on consequences. Companies—both foreign and domestic—were given a relatively extended period to understand the requirements, formulate suitable strategies, and implement compliance measures. Recent enforcement actions led by the Cyberspace Administration of China (CAC), the country’s data regulator, suggest that the education phase

Continue Reading CHINA: China’s Data Regulator Means Business – The Education Phase Is Over

On 11 June 2026, the Office of the Australian Information Commissioner (OAIC) published two determinations against Medmate Australia Pty Ltd (Medmate) and Monash IVF Pty Ltd (Monash IVF), finding both entities interfered with individuals’ privacy via the use of website tracking pixels.

In the absence of an express regulatory

Continue Reading Australia: Pixel Perfect – The regulator addresses use of tracking pixels

A proposed common template for personal data breach notifications recently published by the European Data Protection Board (“EDPB“) for consultation has the potential to assist organisations in streamlining personal data breach reporting across the EU while also raising additional complexity and challenges for businesses.

In line with the EDPB’s Helsinki Statement on enhanced

Continue Reading EU: EDPB common template for breach notifications – welcome alignment or further complexity?

Quantum computing is poised to profoundly reshape the cybersecurity landscape, with significant legal and regulatory implications. By introducing fundamentally different computational methods, enabling the simultaneous processing of multiple possibilities, quantum computing has the potential to undermine and ultimately render many traditional encryption techniques ineffective. The result is a significant systemic risk across critical infrastructures, including

Continue Reading Quantum Computing and the Future of Cyber Security

The UK Government’s legislative agenda, set out in the King’s Speech on 13 May 2026, places cybersecurity and digital resilience firmly at the centre of national policy. Against a backdrop of increasing geopolitical instability and rapidly evolving technological risks, the proposed measures continue the shift towards a more interventionist and systemic approach to safeguarding the

Continue Reading UK: The King’s Speech 2026 – Cybersecurity at the Forefront

On May 8, 2026, California Attorney General Rob Bonta — joined by the District Attorneys of San Francisco, Los Angeles, Napa, and Sonoma Counties, with support from the California Privacy Protection Agency (CalPrivacy) — announced a $12.75 million settlement with General Motors and OnStar (collectively, “GM”) over the alleged unlawful sale of California drivers’ geolocation

Continue Reading U.S.: California’s GM Settlement: Has Data Minimization Finally Arrived?