Compliance Updates — Latest Regulatory News
Dated news items on privacy, cybersecurity and AI regulations as they change, linked to the regulation they affect.
- — Kentucky Consumer Data Protection Act (KCDPA): A 2026 amendment, effective July 1, 2027, classifies **automated content recognition (ACR) data from Smart TVs and smart monitors as sensitive data**, expanding KCDPA’s sensitive data scope and prompting media and ad‑tech companies to revisit consent and data handling practices.[8] (source)
- — Privacy Act 2020: ACC’s article says Australian entities will need to update privacy policies for automated decision-making disclosures from 10 December 2026. This is outside the Privacy Act 2020 jurisdiction, but it shows the direction of regional privacy reform and industry compliance planning. (source)
- — eIDAS 2.0 and the EU Digital Identity Wallet: Euronews reports that every EU country must provide at least one **certified EU Digital Identity Wallet** by December 2026, built to common standards for cross‑border interoperability, highlighting both convenience and security/privacy concerns for citizens and businesses in sectors like cybersecurity and finance.[7] (source)
- — Estonia NIS2 Transposition (Cybersecurity Act amendments): EU‑wide implementation tracker updated on 2026-09-12 listing Estonia as “in force” and “complete” for NIS2 via amendments to the 2018 Cybersecurity Act, identifying RIA and CERT‑EE as key authorities and signaling to industry that Estonia is now in the enforcement and compliance‑ramp‑up phase rather than legislative drafting.[13][14] (source)
- — Vermont Data Privacy and Online Surveillance Act (Act 145): Overview of Act 145 as a comprehensive Vermont consumer data privacy law, detailing scope, covered entities, exemptions, and key consumer rights, and confirming core provisions effective January 1, 2028 with enforcement by the Attorney General and no private right of action.[12] (source)
- — Finnish Transport and Communications Agency Cybersecurity Framework: From 2026-09-11, manufacturers must report actively exploited vulnerabilities and severe security incidents to Traficom within 24 hours of becoming aware of them. This is likely to have operational impact on transportation technology suppliers using connected devices and software. [6] (source)
- — EU Cyber Resilience Act (CRA): CRA vulnerability and incident reporting obligations apply: manufacturers must file 24-hour early warnings and 72-hour notifications through the ENISA Single Reporting Platform. (source)
- — Oregon Companion Chatbot Disclosure Act (SB 1546): A policy-monitoring entry continues to track SB 1546 as an adopted Oregon AI companions measure, signaling ongoing regulatory attention rather than a new substantive change. (source)
- — Vermont Data Privacy and Online Surveillance Act (Act 145): Analysis of the Vermont Data Privacy and Online Surveillance Act’s general applicability, including threshold criteria (35,000 consumers; 3,000 sensitive-data or data-sale thresholds), comparison to other state privacy laws, and confirmation of its in-force date of January 1, 2028.[8] (source)
- — EU Product Liability Directive (Directive (EU) 2024/2853): This regulatory tracker says the directive extends strict liability to software, AI systems, and digital manufacturing files, including cybersecurity vulnerabilities and failure to supply updates. It reports that Member States must transpose the directive by 2026-12-09. (source)
- — Australia Cyber Security Act 2024 (Ransomware Payment Reporting): Australia’s Home Affairs has moved into the second phase of the mandatory ransomware and cyber extortion payment reporting program under the Cyber Security Act 2024, with more active regulatory enforcement for non‑compliance and fines of up to 60 penalty units (currently A$19,800) for failing to report payments within 72 hours. (source)
- — Canada Critical Cyber Systems Protection Act (Bill C-8): SecurityBrief’s commentary frames C-8 as a major reboot of Canada’s cyber law and notes that industry observers expect the regime to broaden compliance expectations across finance, energy, and transport. (source)
- — Sweden NIS2 Transposition (Cybersäkerhetslagen): RISE highlights that Sweden’s new **Cybersäkerhetslagen** implementing NIS2 has applied since 2026-01-15, replacing the previous NIS law, and stresses that organizations must now meet stricter governance, risk management and incident-reporting requirements, prompting extensive readiness work across critical sectors.[6][3] (source)
- — EU Adequacy Decision for Brazil: Hunton Andrews Kurth reports that Brazil and the EU reached agreement on mutual adequacy in personal data protection, enabling free flow of personal data without additional transfer mechanisms and highlighting the November 2025 EDPB opinion that paved the way for the final decision.[14][11] (source)
- — Australia Privacy Amendment (Personal Data Protection) Bill 2026 (Tranche 2 exposure draft): Allen Overy Shearman & Sterling analyses the exposure draft released on 31 August 2026, highlighting major changes such as the broader definition of **personal information**, a new **fair and reasonable** handling test, tighter consent requirements and 72-hour breach notification, and outlines practical impacts for businesses and compliance programs[5][2][1]. (source)
- — Utah App Store Accountability Act (SB 142): This item reflects continued industry and political attention to Utah’s app-store age-verification model, with supporters praising the law as a child-safety measure. It is less directly about a new policy change than about ongoing public reaction to SB 142. (source)
- — EU Adequacy Decision for Brazil: Crowell & Moring analyzes the EU–Brazil mutual adequacy as a key milestone for global data flows and Latin America’s digital positioning, noting that recognition of “essentially equivalent” protection frameworks will significantly ease and legally secure personal data transfers and deepen EU–Mercosur ties.[10][1] (source)
- — Louisiana Data Privacy Act (HB 977): Updated legal guide noting that the Louisiana Data Privacy Act (SB 386) was signed on 2026-05-29 as Act No. 502 and takes effect on 2027-01-01. The page also notes a right-to-cure window through 2027-07-31 and summarizes the law’s compliance timeline. (source)
- — EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026): The European Commission’s CRA reporting page confirms that, as of 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents through the CRA’s reporting process. It states the 24-hour early warning, 72-hour notification, and final report deadlines, and says the Single Reporting Platform will be operational by the reporting start date. (source)
- — EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026): Intertek published a practical update explaining that Article 14 reporting begins on 11 September 2026 and detailing the phased deadlines for early warning, fuller notification, and final report. The article frames this as a major compliance milestone for manufacturers subject to the CRA. (source)
- — EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026): Skadden’s client update highlights the same reporting timetable and notes that the CRA introduces new vulnerability and incident reporting duties for manufacturers of connected products. It presents the change as an immediate readiness issue for legal and compliance teams. (source)
- — EU Digital Omnibus on Data (GDPR, ePrivacy, NIS2, DORA simplification): Analysis of the 1,840 amendments tabled on the Digital Omnibus package, detailing how it simultaneously modifies GDPR, ePrivacy, NIS2, DORA, the Data Act, eIDAS and the Critical Entities Resilience Directive, with a focus on simplifying and harmonizing digital obligations and breach reporting.[9] (source)
- — Taiwan Artificial Intelligence Basic Act: A regulatory tracker notes that the **Artificial Intelligence Basic Act** has been in force since 2026‑01‑14 and that government agencies must complete risk assessments for all public‑facing AI applications by July 2026, signaling concrete implementation deadlines and internal‑control obligations for the public sector.[8] (source)
- — Australia Privacy Amendment (Personal Data Protection) Bill 2026 (Tranche 2 exposure draft): Colin Biggers & Paisley provides an expert legal perspective on the Tranche 2 exposure draft, emphasising expanded privacy protections, simplification of some existing obligations, and measures to enhance OAIC efficiency, and notes the short consultation window closing on 18 September 2026[12][1][8]. (source)
- — Australia Privacy Amendment (Personal Data Protection) Bill 2026 (Tranche 2 exposure draft): Dentons describes the Bill as a substantial rewrite of Australia’s privacy framework, explaining the new purpose-built **personal information** definition covering behavioural and device-generated data, the single fair and reasonable test replacing multiple APP rules, and other structural changes that will significantly reshape data handling practices[2]. (source)
- — Utah App Store Accountability Act (SB 142): CCIA’s Utah challenge remains a key industry-reaction source, describing SB 142 as unconstitutional and arguing it imposes a sweeping age-verification and parental-consent regime. The association said the law would burden lawful speech and intrude on privacy. (source)
- — Canada Critical Cyber Systems Protection Act (Bill C-8): Digital Policy Alert records the CCSPA as having received royal assent on 2026-06-15 and becoming Statutes of Canada, 2026, chapter 9, confirming the law’s formal enactment status. (source)
- — Oregon Companion Chatbot Disclosure Act (SB 1546): The bill tracker still shows SB 1546 as active law with an effective date of 2027-01-01, indicating no later repeal or amendment has overtaken the enacted framework. (source)
- — EU Product Liability Directive (Directive (EU) 2024/2853): The tracker summarizes the directive as modernizing EU product liability rules for software, digital files, and AI systems and says Member States have until 2026-12-09 to transpose it. It also notes that the new regime applies to products placed on the market or put into service after that date. (source)
- — Australia Privacy Amendment (Personal Data Protection) Bill 2026 (Tranche 2 exposure draft): Baker McKenzie characterises the Draft Bill as a significant expansion of the Privacy Act, noting that it implements many 2022 Review proposals plus new measures targeting emerging technologies, and discusses expected alignment with global standards and increased regulatory risk for organisations processing personal data[4][2]. (source)
- — Australia Privacy Amendment (Personal Data Protection) Bill 2026 (Tranche 2 exposure draft): Colin Biggers & Paisley’s “Round 2!” article summarises the Bill’s 25 proposals uplifting privacy protections, 5 clarifying obligations, 4 simplifying measures, and 7 initiatives to improve OAIC efficiency, including the **72-hour notification** deadline for eligible data breaches and a limited **right to erasure** for large digital platforms[1]. (source)
- — Spain NIS2 Transposition (Ley de Coordinación y Gobernanza de la Ciberseguridad): Guía de obligaciones de ciberseguridad para empresas en 2026 que explica que la Ley de Coordinación y Gobernanza de la Ciberseguridad sigue en tramitación a 11 de agosto de 2026 y detalla el régimen NIS2 previsto (sectores afectados, obligaciones de gestión de riesgos, notificación y sanciones), subrayando el impacto esperado para entidades esenciales e importantes.[7] (source)
- — New Jersey A 5328 - Sensitive Data Sale Ban and Data Broker Registry: New Jersey A 5328 is analyzed as a sweeping ban on the **sale or licensing of sensitive data** by all individuals and entities, with a new **public registry for data brokers and data collectors** and a fee schedule ranging from $5,000 to $1.5 million based on consumer volume; the registry provisions take effect March 27, 2027.[1] (source)
- — Vermont Data Privacy and Online Surveillance Act (Act 145): Practical overview for organizations of Act 145’s requirements, including which businesses are covered, operational changes needed before the January 1, 2028 effective date, and explanation of the cure period running until June 30, 2029 for alleged violations.[4] (source)
- — eIDAS 2.0 and the EU Digital Identity Wallet: Eideasy’s September 1, 2026 status snapshot shows rapid national rollout progress: Romania, Croatia, Hungary, Portugal and Liechtenstein have advanced their EUDI wallet implementations, moving up readiness categories as technical documentation, pilot apps and wallet-aligned solutions go live—intensifying cybersecurity, integration and compliance work ahead of the eIDAS 2.0 deadlines.[12] (source)
- — eIDAS 2.0 and the EU Digital Identity Wallet: Biometric Update describes Europe’s digital ID wallets moving from pilots to public rollout, including Albania’s new electronic identification law aligning with eIDAS to strengthen security and trust services, and Germany’s expanded pilots funded through 2026 despite technical complexity and legislative delays—illustrating both momentum and implementation risks for cybersecurity and digital identity providers.[9] (source)
- — Australia Privacy Amendment (Personal Data Protection) Bill 2026 (Tranche 2 exposure draft): Pinsent Masons reports on the opening of consultation for the Tranche 2 Bill, explaining that more data will fall within scope, consent rules for data trading will tighten, and a fixed 72‑hour breach notification will apply, and comments that the reforms move Australia closer to **GDPR‑style** protections and may be passed by the end of 2026[11]. (source)
- — Australia Privacy Amendment (Personal Data Protection) Bill 2026 (Tranche 2 exposure draft): Colin Biggers & Paisley notes that submissions on the exposure draft are due by 18 September 2026, urging organisations to assess impacts such as broader personal information coverage, enhanced individual rights, and increased compliance burden, and to participate in the consultation process[1][8]. (source)
- — Canada Critical Cyber Systems Protection Act (Bill C-8): Osler’s update says Bill C-8 received royal assent on 2026-06-16 and that the new Critical Cyber Systems Protection Act (CCSPA) creates a mandatory federal cybersecurity regime for designated operators, with most substantive obligations coming into force later by order. (source)
- — Chile Personal Data Protection Law (Law No. 21.719): A late-August/early-September jurisdiction update says Law No. 21.719 will enter into force on 2026-12-01 and that the older Law No. 19.628 remains operative until then. The page frames this as the current baseline for Chile’s privacy regime while the reform waits to take effect. (source)
- — Chile Personal Data Protection Law (Law No. 21.719): This update says the law is set to enter into force on 2026-12-01, but notes a government bill before the Senate would postpone implementation to 2027-12-01. It is the clearest recent signal of possible legislative change to the timeline. (source)
- — EU Digital Omnibus on AI (Regulation (EU) 2026/1744): Overview of Regulation (EU) 2026/1744 entering into force on 27 July 2026, summarising its role as the Digital Omnibus on AI and outlining key changes to the AI Act’s implementation and timelines. (source)
- — CIRCIA Cyber Incident Reporting Rule (CISA): This industry update says the rule remains unfinished after years of debate, leaving critical infrastructure operators to prepare for the reporting regime. It emphasizes the operational burden of building processes for rapid incident and ransom-payment reporting. (source)
- — EU Product Liability Directive (Directive (EU) 2024/2853): Freshfields says the EU’s cyber and AI guidance is now practically relevant because liability under the revised Product Liability Directive will soon overlap with other new EU cyber rules. The article highlights the December 2026 application date as a key milestone for manufacturers in cybersecurity-sensitive sectors. (source)
- — Malaysia Personal Data Protection (Amendment) Act 2024: A compliance guide updated in early September 2026 says organizations now face a 72-hour breach notification obligation and must notify affected individuals as soon as practicable. It also reiterates the RM1 million penalty ceiling and expanded compliance duties. (source)
- — Privacy Act 1988: The Attorney-General released the tranche 2 exposure draft of Privacy Act reforms, including a fair-and-reasonable test and a right of erasure. (source)
- — Australia Privacy Amendment (Personal Data Protection) Bill 2026 (Tranche 2 exposure draft): The Attorney‑General’s Department launches the official **Privacy Reform** consultation page, publishing the exposure draft of the Privacy Amendment (Personal Data Protection) Bill 2026 and consultation paper, and inviting submissions on modernising and strengthening privacy laws for the digital age by 18 September 2026[8][3]. (source)
- — Australia Privacy Amendment (Personal Data Protection) Bill 2026 (Tranche 2 exposure draft): MLex reports on the government’s unveiling of the second‑tranche privacy reforms, focusing on the new fair and reasonable test, stronger consent rules, rights to request deletion from major platforms, and measures addressing AI, smart devices and data trading, and flags the consultation period through 18 September 2026[7][6]. (source)
- — Australia Privacy Amendment (Personal Data Protection) Bill 2026 (Tranche 2 exposure draft): Privacy lawyer Peter A Clarke comments on the release of the exposure draft and consultation paper, criticising the very short consultation window (closing 18 September 2026) and highlighting the breadth of proposed changes that will require significant adjustments by regulated entities to governance, consent and breach‑response practices[14][15]. (source)
- — Chile Personal Data Protection Law (Law No. 21.719): A late-August industry explainer highlights the coming December 2026 start date, the new data protection agency, stronger rights, and fines of up to 20,000 UTM. It reflects growing private-sector focus on compliance readiness before the law takes effect. (source)
- — California Digital Age Assurance Act (AB 1043): AB 1856, passed in late August 2026, amends the California Digital Age Assurance Act (AB 1043) to exempt open‑source operating systems like Linux from age‑verification obligations, while keeping major commercial platforms such as Windows, macOS, iOS, and Android fully in scope and reaffirming the January 1, 2027 implementation date for age prompts on new and existing devices.[9][1] (source)
- — Louisiana App Store Accountability Act (HB 570): Regulatory analysis explains that while HB 570 initially created Louisiana’s App Store Accountability framework with a 2026-07-01 start date, HB 977 (Act 185 of 2026) expressly provides that Act 481 “shall not become effective” and re‑enacts the same statutory regime with **new obligations typically applying from 2027-07-01**, clarifying implementation timelines for app stores and developers.[4] (source)
- — EU Product Liability Directive (Directive (EU) 2024/2853): This industry article notes that EU cyber rules are tightening and points to the Product Liability Directive as becoming relevant on 2026-12-09. It frames the directive as part of a broader package of compliance deadlines affecting product security and AI-related documentation. (source)
- — EU Product Liability Directive (Directive (EU) 2024/2853): Although focused on the Cyber Resilience Act, this article underscores the broader cybersecurity compliance environment that will feed into product-liability risk. It emphasizes that reporting obligations begin on 2026-09-11, while the Product Liability Directive’s strict-liability era begins later in 2026. (source)
- — EU Product Liability Directive (Directive (EU) 2024/2853): Industry commentary in this piece suggests companies are aligning product documentation and AI output controls with both the AI Act and Product Liability Directive. The main impact described is increased compliance pressure on cybersecurity and product teams ahead of the 2026-12-09 application date. (source)
- — Utah App Store Accountability Act (SB 142): A regulatory tracker says Utah’s March 2026 amendment pushed the compliance deadline to May 6, 2027, expanded the law to pre-installed applications, removed the Attorney General from enforcement, and banned sharing age data with third parties. It also says the law is now in effect and private enforcement continues to phase in. (source)
- — Canada Critical Cyber Systems Protection Act (Bill C-8): Parliament’s bill text confirms that Part 2 enacts the Critical Cyber Systems Protection Act to protect critical cyber systems in federally regulated sectors tied to national security and public safety. (source)
- — Oklahoma Act Relating to Data Privacy (SB 546): Overview of Oklahoma SB 546 as the state’s new comprehensive data privacy law, enacted March 20, 2026 and taking effect January 1, 2027, including scope thresholds (100,000/25,000 consumers plus revenue test), core consumer rights, and key compliance obligations for businesses[15][12][3]. (source)
- — Vermont Data Privacy and Online Surveillance Act (Act 145): Law firm summary of Act 145 providing a structured overview of obligations, consumer rights, and enforcement under the Vermont Data Privacy and Online Surveillance Act, and confirming codification in 9 V.S.A. Chapter 61A, §§ 2415a–2415k, effective January 1, 2028.[5] (source)
- — CIRCIA Cyber Incident Reporting Rule (CISA): Inside Cybersecurity reported that CISA gained additional time to finalize the mandatory incident-reporting rule after stakeholder feedback. The item indicates the schedule slipped again, showing continued rulemaking uncertainty. (source)
- — EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026): This industry update says reporting becomes mandatory on 11 September 2026, but warns that the ENISA Single Reporting Platform was still being prepared and testing was expected beforehand. It reflects industry concern that firms may face a short implementation window before the reporting deadline. (source)
- — Louisiana App Store Accountability Act (HB 570): The Audio‑Visual Privacy Association lists Louisiana’s HB 570 as part of a broader trend of **app‑store accountability and age‑verification laws**, highlighting its scheduled applicability date and framing it as a key development for privacy, data‑protection, and parental‑consent obligations in digital services targeted to minors.[12] (source)
- — Malaysia Personal Data Protection (Amendment) Act 2024: A 2026 compliance update says the Personal Data Protection (Amendment) Act 2024 is now fully rolled out, with no remaining grace periods. It highlights mandatory breach notification, higher penalties, processor liability, biometric data classification, and a risk-based cross-border transfer framework. (source)
- — Canada Critical Cyber Systems Protection Act (Bill C-8): The parliamentary record shows the legislative text and structure of Bill C-8, including the CCSPA framework, which is useful for tracking the official scope of the new regime. (source)
- — Greece NIS2 Transposition (Law 5160/2024): Analysis of how Law 5160/2024, transposing NIS2, functions in practice, noting that registration with the National Cybersecurity Authority has closed, the authority is actively supervising entities, and Greek businesses face increased compliance and enforcement pressure under the new cybersecurity framework.[10] (source)
- — Netherlands NIS2 Transposition (Cyberbeveiligingswet): De Nederlandse NIS2‑implementatie, de **Cyberbeveiligingswet (Cbw)**, is volgens de overheid per **2026-08-15** in werking getreden; vanaf die datum moeten alle onder NIS2 vallende organisaties voldoen aan zorgplicht- en meldplichtverplichtingen. (source)
- — Italy NIS2 Transposition (Legislative Decree 138/2024): Whitepaper-style operational guide for NIS2 in Italy noting that **Legislative Decree 138/2024** extends rules to **18 sectors and over 80 types of public and private entities**, with practical guidance on risk management, governance, and incident-reporting processes; reflects industry concerns about the breadth of scope and the need for structured compliance programs.[6] (source)
- — UK Cyber Security and Resilience Bill: The Cyber Security and Resilience Bill is reported to have passed through the House of Commons in June 2026 and is progressing through the House of Lords, with Royal Assent expected later in 2026; the article highlights expanded scope to data centres and managed service providers, stricter 24/72‑hour incident reporting, and a new two‑tier penalty regime of up to £17m or 4% of global turnover for serious breaches.[13] (source)
- — Oregon Companion Chatbot Disclosure Act (SB 1546): A legal analysis notes Oregon’s companion chatbot law as part of a broader 2026 state trend, highlighting mandatory disclosure when a user may believe they are interacting with a natural person. (source)
- — Louisiana Data Privacy Act (HB 977): Industry group reaction opposing Louisiana’s HB 977 app-store age-verification approach, calling it legally flawed and privacy-invasive. The testimony warns the bill could expose sensitive personal data and burden app stores and users. (source)
- — Vietnam Law on Digital Technology Industry: Vietnam Briefing’s updated coverage explains that the Law on Digital Technology Industry took effect on 2026-01-01 and highlights AI compliance obligations, including high-risk categorization, technical standards, and transparency labeling. It remains a useful reference for businesses tracking implementation details. (source)
- — Vietnam Law on Digital Technology Industry: This legal update describes Vietnam’s transition from broad digital technology rules to a more detailed AI compliance regime, noting that the Digital Technology Industry Law’s AI framework is now being applied alongside later AI-specific rules. It emphasizes practical compliance steps for companies operating in Vietnam. (source)
- — Vietnam Law on Digital Technology Industry: Baker McKenzie’s analysis says the AI-specific legal framework now complements the earlier Digital Technology Industry Law, with the newer AI law taking the lead on risk-based oversight. The article is important because it explains how the Digital Technology Industry Law’s AI provisions fit into the broader regulatory architecture. (source)
- — Vietnam Law on Digital Technology Industry: Duane Morris’ update explains that AI systems in sensitive sectors may benefit from phased compliance periods, with different grace periods depending on the sector. This matters for industry because it affects timing, budgeting, and product rollout decisions. (source)
- — EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026): This policy commentary says the Commission’s implementation guidance arrived ahead of the 11 September 2026 reporting deadline and responds to concerns raised by cybersecurity stakeholders. It suggests the guidance is intended to reduce uncertainty before the CRA reporting obligations take effect. (source)
- — EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026): Cloudsmith’s update focuses on engineering readiness and explains the operational impact of the reporting obligations on product teams. It emphasizes that teams need logging, triage, and patch workflows in place before the 24-hour and 72-hour deadlines begin. (source)
- — GDPR Procedural Regulation (Regulation (EU) 2025/2518): Analysis of the GDPR Procedural Regulation explains that Regulation (EU) 2025/2518 introduces detailed procedural rules for GDPR enforcement, including clearer complaint handling standards and cross‑border cooperation requirements, and notes that the Regulation will apply from 2027-04-02 for new cases.[4] (source)
- — GDPR Procedural Regulation (Regulation (EU) 2025/2518): Industry commentary outlines what organisations should expect under the GDPR Procedural Regulation, emphasizing that the new rules will apply to complaints lodged after 2027-04-02 and will significantly affect handling of cross‑border processing complaints, timelines, and complainant participation.[8] (source)
- — CIRCIA Cyber Incident Reporting Rule (CISA): Industry-facing commentary describes organizations preparing for eventual compliance with CIRCIA’s 72-hour incident reporting and 24-hour ransomware payment deadlines. The broader impact is increased readiness planning by critical infrastructure operators ahead of finalization. (source)
- — EU Product Liability Directive (Directive (EU) 2024/2853): Reed Smith describes the EU product liability regime as part of an emerging enforcement framework for cybersecurity and consumer IoT. It states that the revised Product Liability Directive takes effect on 2026-12-09 and sits alongside the EU Cyber Resilience Act and Data Act in the compliance timeline. (source)
- — Hong Kong Protection of Critical Infrastructures (Computer Systems) Ordinance: The government’s ordinance page was updated, signaling continued maintenance of the official implementation materials. No major substantive policy change is evident from the page snippet, but it confirms the regime remains active and publicly administered. (source)
- — Hong Kong Protection of Critical Infrastructures (Computer Systems) Ordinance: Industry-facing legal commentary emphasized that operators must maintain security controls, report material changes, and implement compliance processes. The practical impact is increased governance, audit, and incident-response burdens for designated critical infrastructure operators. (source)
- — Malaysia Personal Data Protection (Amendment) Act 2024: Baker McKenzie reports that Malaysia’s Personal Data Protection Commissioner has issued new guidelines following 2025 consultations. The guidelines cover Data Protection Impact Assessments and Data Protection by Design, signaling continuing regulatory implementation of the amendment package. (source)
- — Canada Critical Cyber Systems Protection Act (Bill C-8): Honeywell’s industry analysis says Bill C-8 is now in force at the statute level and highlights the CCSPA’s phased implementation approach, signaling that operators in critical sectors should prepare now for upcoming compliance obligations. (source)
- — Canada Critical Cyber Systems Protection Act (Bill C-8): Public Safety Canada’s statement says the CCSPA will be implemented gradually and that it creates a regulatory framework for designated operators in finance, telecommunications, energy, and transportation. (source)
- — Canada Critical Cyber Systems Protection Act (Bill C-8): Earlier industry reporting highlighted criticism that Canada moved slowly on the legislation, reflecting long-standing concern in the market about delayed cyber-infrastructure protections. (source)
- — Alabama Personal Data Protection Act (HB 351): Recent practitioner coverage continues to focus on compliance readiness rather than any change to the statute. The ongoing industry impact is that companies are using the lead time before 2027-05-01 to align privacy notices, consumer request workflows, and vendor contracts. (source)
- — Italy NIS2 Transposition (Legislative Decree 138/2024): Analysis of **Decree 138/2024 sanctions regime**, explaining ACN’s supervisory powers, the tiered penalty system (up to 10M EUR or 2% of worldwide turnover), and expanded scope across 11 highly critical and 7 other critical sectors, including public administration, waste management, medical devices, automotive, postal/courier, and ICT/B2B service providers; discusses expected enforcement focus and risk-based supervision.[4] (source)
- — Oregon Companion Chatbot Disclosure Act (SB 1546): Industry advocates continue to frame SB 1546 as a major AI safety win, emphasizing protections for children and crisis-response obligations for chatbot operators. (source)
- — Oregon Companion Chatbot Disclosure Act (SB 1546): A law-firm update says SB 1546 creates a private right of action and statutory damages of $1,000 per violation, underscoring meaningful enforcement risk for AI companies. (source)
- — Oregon Companion Chatbot Disclosure Act (SB 1546): Practitioner commentary describes the law as one of the first chatbot statutes with “real teeth,” pointing to the combination of disclosure, suicide-prevention, and minor-protection obligations as likely to affect product design and compliance planning. (source)
- — Oregon Companion Chatbot Disclosure Act (SB 1546): A March legal summary says the measure was designed to regulate consumer-facing interactive AI and previews the operational compliance burden now associated with disclosure, crisis-response, and minor-specific safeguards. (source)
- — Oregon Companion Chatbot Disclosure Act (SB 1546): A compliance-focused update explains that Oregon’s law targets AI companions that could be mistaken for humans and will require clear platform notices once it takes effect in 2027. (source)
- — Vietnam Law on Digital Technology Industry: Recent commentary suggests industry reaction is focused on compliance burden, especially around labeling, risk classification, and conformity assessment. At the same time, legal advisers note the law also provides clearer rules and a more predictable framework for AI businesses. (source)
- — California Transparency in Frontier Artificial Intelligence Act (SB 53): Fortune reports that OpenAI publicly cites and supports California’s **Transparency in Frontier Artificial Intelligence Act (SB 53)** after a cybersecurity incident, framing the law’s safety and transparency requirements as necessary and even asking for more regulation, highlighting how SB 53 is shaping industry narratives on AI safety and regulatory “moats”.[13] (source)
- — CIRCIA Cyber Incident Reporting Rule (CISA): CISA is expected to finalize the CIRCIA rule in September 2026, with reporting requirements still described as 72 hours for covered cyber incidents and 24 hours for ransomware payments. The article frames the move as the latest target after prior delays and notes that the rule would affect critical infrastructure organizations. (source)
- — CIRCIA Cyber Incident Reporting Rule (CISA): CISA’s CIRCIA page reiterates the statutory framework: covered entities must report covered cyber incidents no later than 72 hours after reasonably believing an incident occurred. This remains the core policy baseline even as the final implementing rule is still pending. (source)
- — Taiwan Artificial Intelligence Basic Act: Taiwan’s Ministry of Digital Affairs outlines governance and evaluation under the **Artificial Intelligence Basic Act**, emphasizing seven core principles (sustainable development, human autonomy, privacy/data governance, cybersecurity, transparency, fairness, accountability) and policy incentives to drive secure AI innovation in the public sector.[6] (source)
- — Estonia NIS2 Transposition (Cybersecurity Act amendments): European cybersecurity industry tracker noting Estonia as having completed NIS2 transposition, listing transposition and entry‑into‑force dates and characterizing the national law (Network and Information System Security Act 2026 / amended Cybersecurity Act) as fully implementing NIS2 requirements for essential and important entities.[8] (source)
- — Vermont Data Privacy and Online Surveillance Act (Act 145): Industry-facing explainer highlighting Vermont as the 23rd U.S. state with a comprehensive consumer privacy law, outlining business compliance steps, the exclusive enforcement by the Attorney General, and the January 1, 2028 start date with a cure period through June 30, 2029.[11] (source)
- — Vermont Data Privacy and Online Surveillance Act (Act 145): Privacy counsel commentary on Vermont’s enactment of Act 145, emphasizing its broad consumer rights, data controller and processor obligations, and positioning within the wider U.S. privacy law landscape as another comprehensive state regime.[14] (source)
- — Czech Republic NIS2 Transposition (Cybersecurity Act 2025): Deloitte’s update explains that the Czech Republic missed the original NIS2 transposition deadline and finalized the Cybersecurity Act only in 2025. It frames the current issue as implementation and operational compliance rather than legislative drafting. (source)
- — Utah App Store Accountability Act (SB 142): This update says the App Store Accountability Act’s operative compliance date remained tied to the May 2026 deadline, while the private right of action was scheduled to take effect on December 31, 2026. It also notes the earlier compliance structure and the law’s age-verification and parental-consent requirements. (source)
- — Japan AI Promotion Act (Act on Promotion of Research, Development and Utilization of AI-Related Technologies): Japan’s AI policy remains centered on the AI Promotion Act, but the article says the implementing Basic Plan is still being revised, with a draft revision opened for public comment in June 2026. It highlights that the framework is still evolving rather than settled. (source)
- — Sweden NIS2 Transposition (Cybersäkerhetslagen): The Swedish National Cybersecurity Center (NCSC) explains that NIS2 is implemented through **Cybersäkerhetslagen (SFS 2025:1506)**, in force since 2026-01-15, outlining scope, obligations and supervision, and positioning the law as the core framework for cybersecurity for essential and important entities in Sweden.[1][10] (source)
- — Sweden NIS2 Transposition (Cybersäkerhetslagen): NCSC describes how NIS2 regulation is structured in Sweden under **Cybersäkerhetslagen**, including which sectors and entities are covered and their duties, and notes an institutional change where cyber responsibilities moved from Myndigheten för civilt försvar (MCF) to NCSC at FRA on 2026-07-01, affecting oversight and support.[12][10] (source)
- — Louisiana Data Privacy Act (HB 977): Law-firm analysis published after enactment stating Louisiana became the 22nd state with a comprehensive privacy law. It highlights the seven-month compliance runway and the January 1, 2027 effective date. (source)
- — Louisiana Data Privacy Act (HB 977): Industry commentary explaining that Louisiana’s privacy law was signed on 2026-05-29 and becomes effective on 2027-01-01. The piece frames the law as part of a continuing trend of state privacy legislation and signals compliance preparation by covered businesses. (source)
- — Vietnam Law on Digital Technology Industry: This article says Vietnam requires AI providers to self-classify products by risk level and label AI-generated images, video, and audio. It reflects industry concern that Vietnam is trying to balance innovation with tighter state oversight. (source)
- — CIRCIA Cyber Incident Reporting Rule (CISA): This update says CISA has again slipped the final-rule timeline, moving from a May 2026 target to September 2026 in the Unified Agenda. It frames the delay as another missed deadline for the long-awaited CIRCIA implementing rule. (source)
- — CIRCIA Cyber Incident Reporting Rule (CISA): The article notes that the final rule remains unresolved more than two years after the proposed rule and that companies are still preparing for mandatory reporting obligations. Industry impact centers on compliance uncertainty and continuing monitoring of CISA’s timeline. (source)
- — Taiwan Artificial Intelligence Basic Act: A legal analysis describes the **AI Basic Act** as Taiwan’s 2026 roadmap for AI, highlighting its seven guiding principles and a two‑year program for reviewing and amending existing laws and administrative measures to align with the Act, setting the foundation for future sector‑specific regulation and compliance expectations.[4] (source)
- — New Jersey A 5328 - Sensitive Data Sale Ban and Data Broker Registry: A fiscal note on A 5328 details the **annual registration fees** for data brokers and data collectors and emphasizes that each covered entity must register with the Division of Consumer Affairs and pay fees according to volume tiers, with **civil penalties of $50,000 per record** sold, offered, or licensed in violation, underscoring substantial compliance and enforcement risks.[9] (source)
- — Czech Republic NIS2 Transposition (Cybersecurity Act 2025): Industry guidance notes that the Act has been in force since 2025-11-01 and that the NÚKIB registration wave is over. It emphasizes the practical impact on regulated organizations across 18 sectors, including energy, healthcare, transport, manufacturing, waste, and IT. (source)
- — Canada Critical Cyber Systems Protection Act (Bill C-8): The Office of the Privacy Commissioner’s background material on Bill C-8 confirms the bill’s cybersecurity purpose and the requirement for designated operators to establish a cyber security program. (source)
- — Oregon Companion Chatbot Disclosure Act (SB 1546): Oregon’s SB 1546 remains listed as enacted legislation regulating AI companions, with the legislative overview describing requirements for clear notice that users are interacting with artificially generated output when a reasonable person might think they are speaking with a human. (source)
- — Louisiana Data Privacy Act (HB 977): Policy tracker entry recording the legislature’s adoption of SB 386 on 2026-05-20. It reflects the final passage milestone before gubernatorial signature and is useful for tracking the law’s progression. (source)
- — California CPPA Regulations - ADMT, Risk Assessments and Cybersecurity Audits: California Privacy Protection Agency publishes updated CCPA regulations implementing requirements for **risk assessments**, annual **cybersecurity audits**, and consumers’ rights to access and opt out of businesses’ use of **automated decisionmaking technology (ADMT)**, as well as clarifying insurance-company obligations.[1][13] (source)
- — Utah App Store Accountability Act (SB 142): A legal update reports that CCIA agreed to a stipulated dismissal of its constitutional challenge to Utah’s App Store Accountability Act after Utah amended the statute. The dismissal followed changes that altered the law’s enforcement framework. (source)
- — Canada Critical Cyber Systems Protection Act (Bill C-8): Truvo Cyber reports that Part 1 of Bill C-8 is already live while the CCSPA itself is enacted but not yet operative, and notes the 90-day compliance clock that will start once an operator is designated. (source)