Regulators are moving faster, enforcement is scaling, and AI is no longer a future concern. From cross-border data risks to child safety enforcement, compliance expectations are tightening across regions.

01

GDPR enforcement ramps up across Europe

European regulators issued €68 million in fines in early 2026, with France and the UK leading enforcement activity. This marks a shift from isolated cases to broader, consistent enforcement across industries. Read more

02

AI systems are now a direct GDPR risk

Regulators are applying GDPR principles directly to AI systems, especially around training data and automated decision-making. With the EU AI Act approaching, AI governance is quickly becoming a core compliance requirement. Read more

03

Microsoft Copilot feature raises data transfer concerns

A new Microsoft Copilot feature may route data outside the EU, even when organizations expect EU-only processing. This puts the burden on companies to reassess data flows and ensure GDPR compliance. Read more

04

New laws target precise location data sales

Virginia is moving to restrict the sale of precise geolocation data, reflecting tighter rules around sensitive data. Even consent-based data monetization is facing increased scrutiny from regulators. Read more

05

US state privacy laws continue to expand

The US introduced the SECURE Data Act and GUARD Financial Data Act on April 22, 2026, marking a major step toward stricter federal oversight of data collection, usage, and governance.California also continues to push stricter requirements, especially around automated decision-making. Read more

06

AI-generated content enters privacy enforcement scope

AI-generated content, including images and videos, is increasingly being treated as privacy risks under GDPR. This expands enforcement into areas like deepfakes, identity misuse, and training data transparency. Read more

07

Deepfake investigations put platforms under pressure

Regulators are investigating platforms over harmful AI-generated content, including deepfakes involving minors. These cases test whether platforms built sufficient safeguards into AI systems. Read more

08

Children’s data protection gains priority globally

Governments are stepping up enforcement around children’s data and harmful content online. AI-generated risks are accelerating this shift toward stricter protections. Read more

09

Cross-border data transfers face renewed scrutiny

US regulators are increasingly scrutinizing cross-border data transfers, with states like Florida and Texas targeting how sensitive data is shared outside the country, especially where foreign adversaries may be involved. Read more

10

China introduces AI rules with GDPR-like scope

China is rolling out new AI-focused regulations covering data handling, minors, and safety risks. This reflects a broader global trend toward stricter AI governance frameworks. Read more