June saw regulators intensifying their focus on data transfer enforcement, educational privacy, and AI compliance while the US privacy map continued to expand. From landmark comprehensive laws in Vermont to the EDPB’s push for standardized data breach reporting, compliance margins are growing noticeably tighter.

01

Vermont becomes the 24th US state to pass a comprehensive data privacy law


Vermont enacted the Data Privacy and Online Surveillance Act, introducing strict data minimization rules and expansive definitions for sensitive data. The legislation also uniquely requires businesses to disclose if they process personal data for training large language models.
Read more

02

Irish High Court upholds €530M fine against TikTok over China data transfers


The Irish High Court dismissed TikTok’s appeal, confirming that the platform violated the GDPR when transferring European user data to China. The ruling reinforces that organizations must comprehensively verify and demonstrate adequate safeguards when using Standard Contractual Clauses.
Read more

03

EU Parliament adopts ‘Digital Omnibus’ changes to the AI Act


European lawmakers approved amendments to the AI Act to reduce overlapping compliance burdens for industrial AI systems already covered by sector-specific legislation. The compromise aims to streamline safety requirements while introducing stricter prohibitions on synthetic illicit content.
Read more

04

FTC finalizes data security order against Illuminate Education over 10M student breach


The FTC finalized an order directing the K-12 software vendor to improve its data security measures and explicitly implement data minimization practices following a massive 2021 cyberattack. The enforcement action underscores the FTC’s expectation that EdTech companies must back their privacy promises with enforceable technical controls.
Read more

05

FTC opens public comment on X Corp.'s petition to modify privacy consent order


The FTC opened a public comment period regarding a petition from X Corp. (formerly Twitter) requesting modifications to its data security and privacy consent order. The company is challenging the regulator’s ongoing oversight, arguing that circumstances have fundamentally changed since the initial settlement.
Read more

06

FTC penalizes Amazon $2.25 million over Fair Credit Reporting Act violations


Amazon agreed to a $2.25 million civil penalty to settle allegations that it repeatedly refused to provide identity theft victims with required transaction records. The FTC stated the company knowingly ignored its FCRA obligations, prioritizing internal privacy policies over legally mandated fraud support.
Read more

07

FTC secures agreement with Havas to resolve advertising collusion


Advertising agency Havas Media Group agreed to an FTC order resolving allegations that it unlawfully colluded to set common brand safety standards. The settlement completes the FTC’s enforcement sweep against the “Big Six” ad agencies to restore competition in the digital advertising ecosystem.
Read more

08

EDPB launches public consultation on a common data breach notification template


The European Data Protection Board adopted and opened for public consultation a unified template for personal data breach notifications. Designed to be implemented via an IT tool across Data Protection Authorities, the template aims to streamline reporting requirements and harmonize compliance for organizations operating across multiple EU member states.
Read more

09

FTC sues sprawling enterprise operating unlawful subscription schemes


A federal court halted a 15-corporation enterprise following an FTC lawsuit targeting deceptive negative option billing and fake tech support scams. The enforcement action underscores the FTC’s escalating crackdown on dark patterns and subscription traps that defraud consumers.
Read more

10

UK DUAA shifts data complaint handling responsibilities to organizations


The UK’s newly enacted Data (Use and Access) Act introduced a mandatory requirement for businesses to implement formal internal data privacy complaint procedures. The June rollout shifts the initial burden of resolving data subject concerns from the ICO directly onto organizations.
Read more