Cybersecurity, Privacy, Data Protection, Internet Law and Policy.
Data Matters Privacy Blog Cybersecurity, Privacy, Data Protection, Internet Law and Policy
- Trending Issues in State AI Regulation as Seen Through Connecticutâs Omnibus AI Law (SB5)by Colleen T. Brown, Sheri Porath Rockwell and Stephanie Y. Lim on August 21, 2026 at 7:01 pm
Earlier this year, Connecticut enacted its Online Safety Act (âSB5â), now retitled the Connecticut Artificial Intelligence Responsibility and Transparency Act (the âCART Actâ), which represents one of the most wide-ranging omnibus state artificial intelligence (âAIâ) and online-safety laws enacted to date. The broad multi-topic nature of the law contrasts with the recent state legislative trend of more targeted laws and regulations focusing on a particular context, specific digital risk, or broadly impactful player within the AI or online ecosystem. For example, Coloradoâs revised AI Act now focuses exclusively on automated decision-making technologies, a number of states (e.g., Georgia, Iowa, Nebraska) have enacted laws focused on AI chatbots, and New York and California have been engaged in rulemaking to operationalize those statesâ social media focused law. The post Trending Issues in State AI Regulation as Seen Through Connecticutâs Omnibus AI Law (SB5) appeared first on Data Matters Privacy Blog.
- South Carolina Takes a Hard Line on Age-Appropriate Design â Audits, Parental Controls, Employee Personal Liability, and Moreby Sheri Porath Rockwell, Michael C. Hochman and Jonathan M. Wilan on July 31, 2026 at 5:34 pm
The recently enacted South Carolina Age Appropriate Design Code Act (S.C. Code Sec. 39-80-10 et seq.) (the âActâ) has the potential to become one of the countryâs most consequential privacy laws. It combines prescriptive privacy-by-design controls with restrictions on facilitating targeted advertising to minors under 18, and requires annual independent compliance audits and reports that are publicly posted, coupled with unusually aggressive penalties, including potential personal liability for officers and employees for âwillful and wantonâ violations. Unlike some other statesâ privacy laws that have given entities time to make technical and policy changes before their effective date, South Carolina took a different route. The Act took effect immediately upon enactment in February 2026, and the first audit reports were required to be submitted to the South Carolina Attorney General by July 1, 2026. The post South Carolina Takes a Hard Line on Age-Appropriate Design â Audits, Parental Controls, Employee Personal Liability, and More appeared first on Data Matters Privacy Blog.
- EDPB Publishes Draft Guidelines on Anonymisationby Francesca Blythe and Matthias Bruynseraede on July 27, 2026 at 6:21 pm
On 7 July 2026, the European Data Protection Board published its long-awaited draft Guidelines 02/2026 on Anonymisation. The draft Guidelines â which are intended, once finalised, to replace the former Article 29 Working Partyâs Opinion 05/2014 on Anonymisation Techniques â adopt a ârelativeâ approach to identifiability, as endorsed by the EU Court of Justice in the EDPS v SRB case. The practical consequence is that the same dataset can be considered personal data for one party and anonymous for another (i.e., anonymity is not an intrinsic property of the data itself but depends on who holds it and what they can realistically do with it). Organisations that work with data they regard as anonymised (e.g., training AI models or sharing research datasets) may find the draft Guidelines a helpful reference point for reviewing and strengthening existing practices. The post EDPB Publishes Draft Guidelines on Anonymisation appeared first on Data Matters Privacy Blog.
- What Do the European Data Protection Boardâs Web Scraping Guidelines Mean for AI Training Datasets?by Francesca Blythe and Eleanor Dodding on July 23, 2026 at 4:33 pm
On July 7, 2026, the European Data Protection Board (EDPB) published draft guidelines on web scraping for generative AI (Guidelines). The Guidelines are intended to provide practical GDPR guidance in one of the more complex areas of AI development and will be of direct relevance to any organization building or procuring generative AI systems trained on internet-sourced data. The post What Do the European Data Protection Boardâs Web Scraping Guidelines Mean for AI Training Datasets? appeared first on Data Matters Privacy Blog.
- White House Issues Executive Orders on Quantum Innovation and Securityby David Lashway, John Woods, Cole R. Rianda, Philip Robbins and James Atlas on July 1, 2026 at 4:18 pm
On June 22, 2026, the White House issued two Executive Orders:Â Ushering in the Next Frontier of Quantum Innovation and Securing the Nation Against Advanced Cryptographic Attacks. By harnessing properties of quantum physics, advanced quantum computers are capable of solving certain classes of computational problems much faster than classical computers, opening new pathways for innovation and new threats to widely used cryptographic security systems. The post White House Issues Executive Orders on Quantum Innovation and Security appeared first on Data Matters Privacy Blog.
- EU AI Act Transparency Obligations: Preparing for Compliance by 2 August 2026by Francesca Blythe and Eleanor Dodding on June 24, 2026 at 6:17 pm
From 2 August 2026, organisations will become subject to the transparency obligations set out in Article 50 of the EU AI Act (Regulation (EU) 2024/1689). Article 50 introduces transparency requirements for providers and deployers in relation to certain AI system functionalities and use cases that may create transparency risks for individuals. Whilst much of the EU AI Act focusses on obligations on high-risk AI systems, Article 50 obligations may also apply to certain limited-risk systems. As a result, many organisations will need to implement governance, disclosure and content-labelling measures to ensure users are appropriately informed about the use of certain AI systems and AI-generated content. The post EU AI Act Transparency Obligations: Preparing for Compliance by 2 August 2026 appeared first on Data Matters Privacy Blog.
- EU Lawmakers Reach Provisional Agreement to Delay Key EU AI Act Obligationsby William RM Long, Elisabetta Righini and Francesca Blythe on June 22, 2026 at 4:19 pm
On 7 May 2026, following extensive negotiations, the European Council and European Parliament reached a provisional agreement on the EU Digital Omnibus on AI (AI Omnibus) which proposes targeted amendments to the EU Artificial Intelligence Act (AI Act). On 16 June 2026, the European Parliament voted to adopt the provisional agreement â although, formal adoption remains subject to European Council approval. The post EU Lawmakers Reach Provisional Agreement to Delay Key EU AI Act Obligations appeared first on Data Matters Privacy Blog.
- Cyber Strategy at the AI Frontier: President Trump Releases Executive Order to Promote Advanced Artificial Intelligence Innovation and Securityby David Lashway, John Woods, Jennifer B. Seale, Michael C. Hochman, Cole R. Rianda and Philip Robbins on June 4, 2026 at 3:06 pm
On June 2, 2026, President Trump issued the Executive Order, Promoting Advanced Artificial Intelligence Innovation and Security. The Executive Order carries forward several priorities included in President Trumpâs Cyber Strategy for America, released in March 2026.[1] The Executive Order declares, âIt is the policy of the United States to promote AI innovation and security by working collaboratively with the private sector to modernize government and private sector information systems and harden them against external threats; to protect American ingenuity and intellectual property from exploitation and theft by adversaries; and to cultivate Americaâs advanced AI-enabled capabilities.â The post Cyber Strategy at the AI Frontier: President Trump Releases Executive Order to Promote Advanced Artificial Intelligence Innovation and Security appeared first on Data Matters Privacy Blog.
- Risk Analysis in the Crosshairs: Four Recent Ransomware Resolutions Preview the HIPAA Security Rule Amendmentsby Michael C. Hochman, Sasha Hondagneu-Messner and Brad A. Carney on June 1, 2026 at 7:37 pm
On April 23, 2026, the U.S. Department of Health and Human Servicesâ (HHS) Office for Civil Rights (OCR) announced resolution agreements and corrective action plans with four regulated entities following separate ransomware investigations under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. The settlements are the culmination of OCR investigations into separate ransomware breaches collectively affecting more than 427,000 individuals and involving the exposure of unsecured electronic protected health information (ePHI) â demographic data, Social Security numbers, financial information, lab results, medications, and diagnoses or conditions. Under the settlements, the regulated entities agreed to implement corrective action plans subject to OCR monitoring for two years and pay a total resolution amount of $1,165,000 to OCR. The post Risk Analysis in the Crosshairs: Four Recent Ransomware Resolutions Preview the HIPAA Security Rule Amendments appeared first on Data Matters Privacy Blog.
- New York Department of Financial Services Issues Coordinated Guidance on Frontier AI Cybersecurity Risksby David Lashway, Jennifer B. Seale and Sasha Hondagneu-Messner on May 28, 2026 at 5:27 pm
On May 21, 2026, the New York State Department of Financial Services (âDFSâ) issued two coordinated Industry Letters: a letter on Heightened Cybersecurity Risks Associated with Frontier AI Models (the âAI Advisoryâ) and accompanying Guidance on Measures Regulated Entities Should Consider in a Heightened Cybersecurity Threat Environment (the âGuidance,â and together, the âMay 2026 Publicationsâ). The AI Advisory builds on DFSâs October 2024 guidance on cybersecurity risks arising from AI, but is narrower in focus. Specifically, it addresses frontier models that may materially increase the speed and effectiveness of vulnerability discovery and exploitation. The post New York Department of Financial Services Issues Coordinated Guidance on Frontier AI Cybersecurity Risks appeared first on Data Matters Privacy Blog.






