Low
Guidance
Published
Global · Sep 18, 2026
Secure Messaging and AI Remain In Conflict Despite the Promise of TEEs
The EFF warns that cloud‑based trusted execution environments (TEEs) do not provide the same privacy guarantees as end‑to‑end encryption. When AI features offload message data to TEEs, the content leaves the device and is exposed to…
Low
Guidance
Announced
Global · Sep 18, 2026
EFF warns that cloud TEEs undermine end‑to‑end encryption in messaging apps
The EFF explains that while trusted execution environments (TEEs) can protect data on cloud servers, they do not provide the same mathematical guarantees as end‑to‑end encryption. Sending message content to a TEE for AI processing creates…
Moderate
Guidance
Published
France · Sep 17, 2026
CNIL outlines its status, organization and sanction powers
The CNIL, created by the 1978 Loi Informatique et Libertés, is an independent administrative authority composed of a college of 18 members. Its restricted board can impose fines up to €20 million or 4 % of global annual turnover under the…
CNIL · loi Informatique et Libertés
Moderate
Guidance
Announced
New York · Sep 17, 2026 · effective Jan 1, 2027
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York Attorney General Letitia James issued an alert encouraging employees with knowledge of unsafe or illegal AI development to submit confidential whistleblower complaints. The alert references the Responsible AI Safety and Education…
New York Attorney General's Office · New York SHIELD Act
Moderate
Guidance
Published
United States (federal) · Sep 16, 2026
EPIC report: Data brokers sell personal data to Disney, GM, insurers and banks
EPIC highlights that data brokers collect and sell personal information to major companies such as Disney, General Motors, insurers and banks. The article notes that brokers infer additional characteristics like finance, health…
Low
Guidance
Announced
United States (federal) · Sep 16, 2026
EPIC report finds companies hinder personal data access under state privacy laws
The Electronic Privacy Information Center reports that many large firms make it difficult for consumers to obtain their personal data, despite state privacy statutes. EPIC notes that small fines and warning letters often have limited…
Low
Guidance
Announced
United States (federal) · Sep 16, 2026
EFF appoints former White House official Alexander Macgillivray to Board of Directors
The Electronic Frontier Foundation announced that Alexander "amac" Macgillivray has joined its Board of Directors. Macgillivray previously served as Deputy Assistant to the President and Principal Deputy U.S. Chief Technology Officer and…
Blueprint for an AI Bill of Rights
Moderate
Guidance
Published
KE · Sep 16, 2026
Kenya publishes new guidance on cross‑border data transfers
On 8 September 2026 Kenya’s Office of the Data Protection Commissioner released detailed Guidance Notes on cross‑border data transfers. The guidance clarifies Kenya’s transfer framework, adds operational detail, and highlights differences…
Office of the Data Protection Commissioner (ODPC) · General Data Protection Regulation
Low
Guidance
Announced
United States (federal) · Sep 15, 2026
EPIC senior counsel warns of privacy risks in unproven health technologies
The Washington Post health brief quoted EPIC senior counsel Sara Geoghegan stating that emerging health technologies are unproven and may be riddled with privacy risks. She emphasized that companies must build and demonstrate trust, noting…
Low
Guidance
Published
United States (federal) · Sep 11, 2026
Amazon Ring's 'Throw Away the Key Encryption' adds limited privacy but falls short of true end‑to‑end encryption
Amazon introduced the Throw Away the Key Encryption (TAKE) feature for Ring cameras, where encryption keys are held temporarily in the cloud and deleted after 24 hours. The system still allows Ring to decrypt footage for cloud‑based…
Moderate
Guidance
Announced
European Union · Sep 11, 2026
ENISA launches Single Reporting Platform for Cyber Resilience Act reporting
ENISA has deployed the initial operating capability of the Single Reporting Platform (SRP) to support the Cyber Resilience Act (CRA) reporting obligations. From 11 September 2026 manufacturers and open‑source software stewards must report…
ENISA · Cyber Resilience Act
Moderate
Guidance
In effect
France · Sep 10, 2026 · effective Sep 1, 2026
CNIL guidance on data‑protection obligations under the electronic invoicing reform effective 1 Sept 2026
The CNIL explains the data‑protection implications of the French electronic invoicing reform that entered into force on 1 Sept 2026. It details which personal data may be processed, the roles of issuers, receivers and certified platforms…
CNIL · réforme relative à la facturation électronique
Moderate
Guidance
Published
France · Sep 10, 2026
CNIL releases Volume 2 of “L’Agence Privacy” to educate adolescents on cybercrime and data privacy
On 10 September 2026 the French data‑protection authority CNIL published the second volume of its educational comic series “L’Agence Privacy”. The free online and paper resource targets teenagers and parents, covering risks such as…
CNIL
Low
Guidance
Announced
Global · Sep 9, 2026
EFF blog outlines digital sovereignty and its impact on privacy, data control and security
The post explains that digital sovereignty refers to the ability of individuals, nations and organizations to control their digital destiny, including data, technology and infrastructure. It highlights policy discussions in Europe and…
Low
Guidance
Announced
Global · Sep 9, 2026
EFF Announces 2026 Award Winners: Access Now, 7amleh, DeFlock, New Media Rights
The Electronic Frontier Foundation announced that Access Now, 7amleh – The Arab Center for the Advancement of Social Media, DeFlock, and New Media Rights received the 2026 EFF Awards. The award recognizes their work defending digital…
Moderate
Guidance
Repealed
United States (federal) · Sep 9, 2026 · effective Sep 9, 2026
FTC rescinds 2021 Policy Statement on Breaches by Health Apps and Connected Devices
The Federal Trade Commission announced it is rescinding the 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. The guidance is deemed obsolete and is being withdrawn. The rescission was published on 2026-09-09.
Federal Trade Commission
High
Guidance
Announced
Spain · Sep 8, 2026 · effective Oct 6, 2026
AEPD launches “Las claves de…” series on privacy and emerging neurotechnologies
The Spanish Data Protection Agency (AEPD) announced a new audiovisual dialogue format, “Las claves de…”, to discuss privacy challenges of neurotechnologies and neurodata. The first episode will be streamed live on 6 October 2026 with AEPD…
Agencia Española de Protección de Datos (AEPD) · Reglamento General de Protección de Datos (RGPD)
Moderate
Guidance
Announced
United States (federal) · Sep 3, 2026
SEC Investor Advisory Committee to Host Sept. 10 Meeting on AI Technologies and NMS Rules
The U.S. Securities and Exchange Commission’s Investor Advisory Committee will hold a public meeting on Sept. 10, 2026 to discuss artificial intelligence technologies in the public markets and the SEC’s Regulation National Market System…
Securities and Exchange Commission · Regulation National Market System
Low
Interpretation
Published
United States (federal) · Aug 31, 2026
EFF urges courts not to expand copyright protections for AI-generated works
The EFF argues that courts should resist pressure to broaden copyright law in response to generative AI, citing historical technology panics. It cites ongoing litigation such as Concord Music Group, Inc. v. Anthropic PBC and In re Mosaic…
Copyright Act
Moderate
Guidance
Published
United States (federal) · Aug 31, 2026
EFF guide on doxxing incident response and digital footprint protection
The Electronic Frontier Foundation published a guide outlining steps for individuals and groups to respond to doxxing attacks. It covers incident logging, team role assignment, monitoring hate forums, setting up alerts, hardening accounts…
California Delete Act