Welcome to this month’s issue of The BR Privacy, Security & AI Download, the digital newsletter of Blank Rome’s Privacy, Security & Data Protection practice. We invite you to share this resource with your colleagues and visit Blank Rome’s Privacy, Security & Data Protection webpage for more information about our team.
RECENT HIGHLIGHT
Blank Rome artificial intelligence vice chair Sharon R. Klein and partners Todd M. Malynn and Alex C. Nisenbaum have been named 2026 Life Sciences Visionaries by Los Angeles Times Studios in the April 2026 edition of its Business Magazine.
STATE & LOCAL LAWS & REGULATIONS
CalPrivacy Seeks Preliminary Comments on Privacy Notices, Employee Data, and Data Broker Audits: The California Privacy Protection Agency (“CalPrivacy”) has issued two invitations for preliminary comments signaling potential new rulemaking under the California Consumer Privacy Act (“CCPA”). The first initiative addresses audit requirements for data brokers under the California Delete Act, which mandates independent third-party audits of data brokers’ compliance with deletion request obligations beginning on January 1, 2028. CalPrivacy is soliciting input on auditor qualifications, documentation and recordkeeping requirements, audit methodologies (including considerations for brokers using artificial intelligence (“AI”) or agentic AI systems), and whether CalPrivacy should collect additional consumer identifiers to improve match rates on the Delete Request and Opt-Out Platform (“DROP”). Preliminary comments on audit requirements are due by May 7, 2026. The second initiative explores whether existing regulations governing privacy notices and disclosures should be amended to address consumer confusion, and whether new regulations are needed for the processing of employee and job applicant personal information. CalPrivacy is seeking feedback on the clarity and effectiveness of privacy policies, challenges businesses face in providing notices across different platforms and devices, and the experiences of employees and job applicants in receiving and exercising their CCPA rights throughout the employment lifecycle. Preliminary comments on these topics are due by May 20, 2026. These initiatives are part of CalPrivacy’s broader regulatory agenda, which includes recent enforcement actions and the continued buildout of its Audits Division.
Alabama Legislature Passes Comprehensive Data Privacy Law: The Alabama legislature passed House Bill 351, the Alabama Personal Data Protection Act (the “Act”), with no opposing votes in either chamber. If enacted by the governor, the law will take effect on May 1, 2027, making Alabama the 21st state to adopt a comprehensive data privacy statute. The Act applies to entities that control or process personal data of more than 25,000 Alabama consumers or derive more than 25 percent of gross revenue from sales of personal data involving any number of data subjects, giving it one of the lowest processing thresholds among state privacy laws. The Act grants consumers rights to access, correct, delete, and obtain portable copies of their personal data, as well as the right to opt out of targeted advertising, data sales, and profiling in furtherance of automated significant decisions. Notably, the Act’s definition of “sale” excludes disclosures for analytics services and marketing services provided solely to the controller, which are exemptions not found in other state laws. Small businesses with fewer than 500 employees and nonprofits with fewer than 100 employees are exempt, provided they do not sell personal data. Enforcement is vested exclusively in the Attorney General, with a non-sunsetting 45-day cure period and civil penalties of up to $15,000 per violation.
Virginia Amends VCDPA to Ban Sale of Precise Geolocation Data: Virginia Governor Abigail Spanberger signed S.B. 338 into law, amending the Virginia Consumer Data Protection Act (“VCDPA”) to prohibit data controllers from selling or offering for sale precise geolocation data concerning a consumer. The new provision takes effect on July 1, 2026. Notably, the VCDPA defines “sale” more narrowly than many other state comprehensive privacy laws, limiting it to the exchange of personal data for monetary consideration by the controller to a third party. Virginia joins Maryland and Oregon, which have already enacted similar geolocation data sale bans, though both states define “sale” more broadly to encompass exchanges for monetary or other valuable consideration. Several other states, including California, Massachusetts, Vermont, and Washington, have recently proposed legislation with similar prohibitions. The legislative trend follows heightened regulatory scrutiny of geolocation data sales, including the California Attorney General’s investigation into the location data industry and a 2024 Federal Trade Commissions (“FTC”) settlement banning a data broker from selling geolocation data.
Kentucky Governor Signs Legislation Classifying Smart TV Data as Sensitive: Kentucky Governor Andy Beshear signed into law HB 120, which amends the Kentucky Consumer Data Protection Act (“KCDPA”) to add certain smart TV data to the law’s definition of “sensitive data.” Specifically, the legislation adds “automated content recognition data” and “smart monitor” to the statutory framework. “Automated content recognition data” is defined as data about a consumer’s content viewing history collected through technology that is embedded or operated through a smart television or smart monitor, integrated with internet connectivity and an operating system that identifies, in real time, the specific content displayed by analyzing audio or video fingerprints, including but not limited to content received through broadcast, cable, satellite, streaming services, or external inputs, through digital fingerprinting, watermark detection, or similar comparison techniques. The amendments take effect on July 1, 2026. Because the KCDPA requires controllers to obtain a consumer’s consent before processing “sensitive data,” the practical effect of the legislation is to require consent before collecting automated content recognition data from smart TVs. The legislation follows Texas Attorney General Ken Paxton’s December 2025 enforcement actions against major smart TV manufacturers for allegedly deceptive automatic content recognition data collection practices.
Montana Attorney General Launches Investigation into Automotive Manufacturers over Driver Data Sales: Montana Attorney General Austin Knudsen announced his office launched an investigation into Ford Motor Company (“Ford”) and Stellantis N.V. (“Stellantis”) following reports that the companies collect and sell personal driving data to third-party data and insurance companies, including LexisNexis and Verisk Analytics. The investigation is being conducted under Montana’s Consumer Protection Act. Attorney General Knudsen issued a Civil Investigative Demand (“CID”) giving both companies one month to respond. The CID demands that Ford and Stellantis identify all products, services, or platforms that collect driving data, personal information, and vehicle data used to sell, license, or share with third-party recipients. This investigation follows a broader national trend of state attorneys general scrutinizing automotive companies’ connected vehicle data practices, including the FTC’s recent consent order with General Motors resolving allegations of unlawful collection and sale of geolocation and driving behavior data without consumer consent.
Maryland Becomes First State to Ban Dynamic Pricing for Food Retailers: Governor Wes Moore signed the “Protection From Predatory Pricing Act” (HB 895) into law, making Maryland the first state to prohibit “dynamic pricing” in the food retail sector. The law, which takes effect on October 1, 2026, prohibits food retailers and third-party delivery service providers from engaging in dynamic pricing, defined as offering or setting a personalized price for a good or service specific to a consumer based on the consumer’s personal data or using personal data to set a higher price for food for a specific consumer. The Act also bars covered entities from using “protected class data” to offer, advertise, or sell consumer goods or services in a manner that withholds or denies accommodations, advantages, or privileges accorded to others. Notably, the law includes several exemptions, including promotional pricing offers, loyalty programs, location-based cost differences, and subscription-based pricing. Violations constitute unfair, abusive, or deceptive trade practices under the Maryland Consumer Protection Act, though the law does not authorize a private right of action, and alleged violators must receive a 45-day notice and cure period before enforcement can proceed.
California Governor Issues Executive Order Strengthening AI Procurement Standards: Governor Gavin Newsom issued Executive Order N-5-26 (the “EO”) directing state agencies to strengthen procurement processes and raise safety and privacy standards for AI companies seeking to do business with California. The EO requires the Department of General Services and Department of Technology to develop, within 120 days, new certifications for state contracting processes under which companies must attest to and explain their policies and safeguards to prevent misuse of their technologies. Companies must specifically address the exploitation or distribution of illegal content such as child sexual abuse material, the use of models displaying harmful bias, and violations of civil rights and civil liberties including free speech, voting rights, and protections against unlawful discrimination and surveillance. The EO also directs the state’s Chief Information Security Officer to review federal designations of companies as supply chain risks and, where such designations are deemed improper, to issue guidance enabling continued state procurement from those companies. Additionally, the EO calls for the publication of a data minimization toolkit for state agencies, the development of best practice guidance for watermarking AI-generated or manipulated images and video, and expanded use of generative AI to improve government service delivery. The EO took effect immediately upon signing on March 30, 2026.
Maine Legislature Fails to Pass Comprehensive Data Privacy Law: The Maine House of Representatives voted not to pass a comprehensive data privacy bill, marking the second consecutive legislative session in which comprehensive privacy legislation has failed to advance in the state. The bill would have adopted a data minimization standard, broadly limiting the collection of personal information to only what is necessary to fulfill the consumer service, which is the same approach used in Maryland’s recently enacted privacy law. Despite initial promise of passage, the bill faltered after significant business opposition, with industry groups arguing it would restrict their ability to conduct targeted advertising based on consumers’ search history, location, and other personal data.
FEDERAL LAWS & REGULATIONS
FCC Proposes Sweeping Rules to Restrict Offshore Call Centers: The Federal Communications Commission (“FCC”) unanimously adopted a Notice of Proposed Rulemaking (“NPRM”) that would significantly restrict the use of foreign call centers by communications service providers, imposing new disclosure, data handling, and reporting obligations. The proposed rules include mandatory onshoring requirements, including caps on the percentage of calls handled offshore; disclosure to consumers when calls are handled abroad, and a right to transfer to a U.S.-based representative upon request; financial deterrents, such as tariffs or bond requirements, to make foreign-originated scam calls economically prohibitive; and potential expansion of scope to nonvoice channels including online chat, text, and e-mail. The NPRM would require that all transactions involving sensitive consumer data, such as passwords, multi-factor authentication codes, social security numbers, and financial account information be handled exclusively at U.S.-based call centers. The FCC would also prohibit use of call centers in “foreign adversary” nations. The FCC seeks comments on whether rules should extend beyond traditional communications providers to all entities subject to the Telephone Consumer Protection Act.
HHS Releases Updated HIPAA Security Rule Guidance Materials: The U.S. Department of Health and Human Services (“HHS”), through its Office for Civil Rights (“OCR”), released updated HIPAA Security Rule guidance materials reinforcing that compliance requires demonstrated, continuous risk management rather than periodic checkbox exercises. The updated materials emphasize that risk management must be an ongoing operational discipline that actively reduces vulnerabilities to electronic protected health information (“ePHI”) to a “reasonable and appropriate level,” with regulators scrutinizing whether organizations prioritize risks based on real-world impact, implement measurable mitigation strategies, and continuously reassess evolving threats. Notably, HHS highlights the role of “recognized security practices” under the HITECH Act amendment, signaling that organizations demonstrating alignment with recognized frameworks such as NIST for at least 12 months may receive favorable consideration in enforcement actions and audits.
House Republicans Introduce SECURE Data Act, Latest Federal Comprehensive Privacy Bill: House Energy and Commerce Committee Republicans introduced the Securing and Establishing Consumer Uniform Rights and Enforcement over Data Act (“SECURE Data Act”) (HR 8413), the first major comprehensive federal consumer privacy bill of the 119th Congress. The bill, a product of the Committee’s Data Privacy Working Group convened in February 2025, would preempt state consumer privacy laws by establishing a uniform federal standard modeled on common elements of the existing state patchwork. The SECURE Data Act would apply to companies processing data of more than 200,000 U.S. consumers and would grant consumers rights to access, correct, delete, and port their personal data, as well as opt out of data sales, targeted advertising, and certain profiling. The bill treats data of children under 16 as sensitive data requiring opt-in consent, includes a data broker registration managed by the FTC, and creates a safe harbor for companies adhering to Department of Commerce-approved codes of conduct, with statutory recognition of Global Cross-Border Privacy Rules. Notably absent from the draft are a private right of action, requirements for data protection impact assessments, data protection officers, universal opt-out mechanisms, and explicit AI or automated decision-making provisions. Enforcement would be handled by the FTC and state attorneys general. The bill has drawn criticism from Democrats and some advocacy groups who argue it weakens existing state protections and lacks meaningful limits on data collection.
Bipartisan CHATBOT Act Would Impose Parental Controls on Children’s AI Chatbot Use: U.S. Senate Commerce Committee Chairman Ted Cruz (R-TX) and Senators Brian Schatz (D-HI), John Curtis (R-UT), and Adam Schiff (D-CA) introduced the Children’s Health, Advancement, Trust, Boundaries, and Oversight in Technology Act (“CHATBOT Act”), bipartisan legislation targeting AI chatbot companies’ interactions with minors. The bill would require covered entities, which are defined as public-facing websites, online services, or applications that primarily provide AI chatbots, to establish “family accounts” for users under age 13, with verifiable parental consent required before any teen under 18 may create an account. Family accounts must offer parents granular controls, including the ability to set time limits; disable engagement incentives such as notifications, badges, and push alerts; block in-chatbot financial transactions; access full conversation records; and set memory and data retention limits for the chatbot. Default settings must be fixed at the most protective level. Violations would be treated as unfair or deceptive acts under the FTC Act, with concurrent enforcement authority granted to state attorneys general. Several states, including California, Oregon, and Washington, have already enacted AI chatbot legislation. The bill takes effect one year after enactment and preempts conflicting state laws, though states may enact greater protections.
U.S. LITIGATION
Seventh Circuit Holds BIPA Amendment Applies Retroactively: In a highly anticipated decision, the United States Court of Appeals for the Seventh Circuit held that Illinois’ 2024 amendment to the Biometric Information Privacy Act (“BIPA”) applies retroactively to all cases pending at the time of enactment, significantly limiting damages exposure for defendants. The Court reversed three Northern District of Illinois decisions that had found the amendment substantive and therefore only prospectively applicable. BIPA authorizes statutory damages of $1,000 for negligent violations and $5,000 for reckless or intentional violations, and the Illinois Supreme Court’s 2023 decision in Cothron v. White Castle held that claims accrue with each biometric scan, raising the specter of billions of dollars in aggregate liability. The 2024 amendment clarifies that repeated collections or disclosures of the same biometric data from the same person using the same method constitute only a single violation, entitling the plaintiff to “at most, one recovery”. The Seventh Circuit concluded the amendment is remedial rather than substantive because it limits available damages without altering BIPA’s underlying compliance obligations, and found no constitutional concerns with retroactive application because the amendment reduces rather than increases potential liability. The decision eliminates the per-scan damages model in pending federal cases and is expected to significantly improve defendants’ settlement posture while potentially reducing the number of single-plaintiff cases in federal court. For a full analysis see our client alert on the case.
Delaware Chancery Court Approves $190M Privacy Settlement in Shareholder Derivative Suit: The Delaware Court of Chancery approved a $190 million settlement resolving stockholder derivative claims that Meta Platforms Inc. (“Meta”) failed to adequately oversee user privacy following the Cambridge Analytica scandal. The litigation, which spanned more than seven years and reached a partial trial, alleged that Meta’s board and executives, including CEO Mark Zuckerberg, breached their oversight duties and failed to comply with a 2012 FTC consent order governing user data. In addition to the monetary recovery, the settlement includes governance reforms requiring Meta to expand its whistleblower program to cover privacy violations, adopt a director code of conduct, and require its chief legal officer to oversee insider trading plans.
Federal Lawsuit Filed Challenging Colorado’s AI Law; Colorado Attorney General Agrees to Stay Enforcement: X.AI LLC (“xAI”), the developer of Elon Musk’s AI tool Grok, filed suit in the U.S. District Court for the District of Colorado seeking to enjoin enforcement of Senate Bill 24-205, which requires developers of “high-risk” AI systems to mitigate “algorithmic discrimination” and make related disclosures to deployers, the public, and the Colorado Attorney General. The complaint alleges that the law’s definition of “algorithmic discrimination”—which exempts differential treatment intended to “increase diversity or redress historical discrimination”—compels xAI to alter Grok’s outputs to conform to a state-endorsed viewpoint, violating the First Amendment, the Dormant Commerce Clause, the Due Process Clause, and the Equal Protection Clause. xAI contends the law’s extraterritorial reach is unconstitutional because it applies wherever a Colorado resident is affected by an AI system, regardless of where the system is developed or deployed. Following xAI’s filing, the U.S. Department of Justice sought to intervene, asserting the law violates the Fourteenth Amendment’s Equal Protection Clause. Colorado Attorney General Philip Weiser subsequently stipulated to stay enforcement of the law pending completion of rulemaking and any successor legislation, and the Court vacated all case deadlines. The law, originally passed in 2024 and delayed to take effect on June 30, 2026, imposes penalties of $20,000 per violation. The case remains pending as the Colorado General Assembly considers replacement legislation.
Federal Court Blocks Arkansas Social Media Age Verification and Addictive Practices Law: The U.S. District Court for the Western District of Arkansas granted a preliminary injunction blocking enforcement of Arkansas Act 900 of 2025 (“Act 900”), which would have imposed restrictions on social media platforms’ interactions with minors under 16. Act 900 prohibited platforms from engaging in “practices to evoke any addiction or compulsive behaviors” in minors, required default nighttime notification restrictions between 10:00 p.m. and 6:00 a.m., mandated the most protective default privacy and safety settings for minors, and required platforms to develop parental supervision dashboards. The Court found the addictive practices provision likely void for vagueness, holding that it fails to specify a standard of conduct and imposes strict liability based on even a single child’s response to an online interface. The Court also concluded that the default notification and privacy provisions fail intermediate scrutiny under the First Amendment, finding the notification restriction insufficiently tailored because parents already have the ability to take devices away at night and the privacy default allows minors themselves to change the settings. The ruling, brought by internet trade association NetChoice, follows two earlier injunctions against related Arkansas social media laws.
Illinois Appellate Court Limits Scope of BIPA Government Contractor Exemption: In Thomas v. Cornerstone Services, Inc., 2026 IL App (3d) 240568 (Apr. 28, 2026), the Illinois Appellate Court, Third District, issued a ruling narrowing the scope of the BIPA government contractor exemption under Section 25(e). The Court answered two certified questions arising from a putative class action alleging that Cornerstone Services, a disability services provider that receives over 60 percent of its revenue from the Illinois Department of Human Services, violated BIPA by disclosing employees’ fingerprint data to a third-party payroll processor without informed consent. On the first certified question, the Court held that a contractor need not work exclusively for a government entity to invoke the exemption. On the second, however, the Court concluded that the phrase “when working for” is not merely temporal but requires a nexus between the alleged BIPA violation and the scope of the contractor’s government work. The Court rejected Cornerstone’s argument that maintaining an active government contract confers categorical immunity from BIPA, noting that such an interpretation would render the exemption’s qualifying clause meaningless and undermine BIPA’s purpose of protecting the public from private entities that compromise biometric data.
Tech Trade Association Files First Amendment Challenge to Minnesota Social Media Warning Label Law: NetChoice, a trade association representing major internet companies including Meta, Google, and TikTok, filed a complaint for declaratory and injunctive relief in the U.S. District Court for the District of Minnesota challenging Article 19, Section 13 of Minnesota House File 2. The statute, enacted in June 2025 and set to take effect on July 1, 2026, requires social media platforms to display state-authored mental health warning labels each time any user, regardless of age, accesses the platform. Users cannot permanently dismiss the warning and must affirmatively “acknowledge the potential for harm” before proceeding. The law also restricts platforms from adding “extraneous information” that could “obscure the visibility or prominence” of the warning. NetChoice argues the law violates the First Amendment’s prohibition on compelled speech, citing the Supreme Court’s longstanding principle that the government may not force private actors to convey the state’s preferred message. The complaint further contends that the law’s “social media platform” coverage definition is unconstitutionally vague, leaving regulated entities uncertain about their obligations. NetChoice notes that a materially similar compelled-speech warning requirement in Colorado has already been enjoined.
U.S. ENFORCEMENT
Florida Attorney General Launches Criminal Investigation into OpenAI and ChatGPT: Florida Attorney General James Uthmeier announced that the Office of Statewide Prosecution has launched a criminal investigation into OpenAI and its AI application, ChatGPT. The investigation follows a prosecutorial review of chat logs between ChatGPT and the gunman responsible for the April 2025 shooting at Florida State University. Under Florida’s aiding and abetting statute, anyone who aids, abets, or counsels in the commission of a crime may be held equally liable as a principal. The Office of Statewide Prosecution has subpoenaed OpenAI for records including policies on user threats of harm, cooperation with law enforcement, and organizational and employee information.
Alabama Attorney General Announces $12.2 Million Settlement with Gaming Platform Over Child Safety: Alabama Attorney General Steve Marshall announced a $12.2 million settlement with interactive gaming platform Roblox, securing child safety enhancements and funding for school resource officers statewide through the Attorney General’s Safe School Initiative. Under the settlement, all Roblox users must undergo age verification using facial age estimation technology and government-issued identification, supplemented by behavioral monitoring to identify users who may have been aged incorrectly. The agreement expands parental controls, enabling parents to manage who their children communicate with, restrict in-game currency transfers from non-trusted adults, and set default content protections for minor users without a linked parent account. Adults and minors under 16 may not chat unless designated as “trusted friends,” with parental consent required for users under 13. Notably, communications involving minors may not be encrypted, facilitating law enforcement efforts to combat child exploitation. A “most favored nation” clause entitles Alabama to any improved terms later agreed to by Roblox and any other state. The settlement is one of several recent state attorneys general actions against Roblox, including deals with Nevada and West Virginia, and ongoing litigation by Florida, Louisiana, Texas, Kentucky, Nebraska, and Iowa.
HHS OCR Settles Four HIPAA Security Rule Ransomware Investigations: The HHS OCR announced settlements with four entities following separate ransomware investigations under the HIPAA Security Rule. The ransomware breaches collectively affected over 427,000 individuals and exposed unsecured ePHI, including demographic data, Social Security numbers, financial information, lab results, medications, and diagnoses. The settling entities—Regional Women’s Health Group, LLC ($320,000), Assured Imaging ($375,000), Consociate, Inc. ($225,000), and Star Group, L.P. Health Benefits Plan ($245,000)—paid a combined $1,165,000 and agreed to implement corrective action plans subject to two years of OCR monitoring. OCR’s investigations found that all four entities failed to conduct an accurate and thorough risk analysis to determine potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. OCR Director Paula M. Stannard emphasized that proactive implementation of the HIPAA Security Rule is a regulated entity’s “best opportunity to prevent or mitigate the harmful effects of a successful cyberattack.” The resolutions mark OCR’s 19th completed ransomware breach investigation and 13th completed investigation under its Risk Analysis Initiative.
INTERNATIONAL LAWS & REGULATIONS
European Commission AI Act Service Desk Issues Guidance on Agentic AI: The European Commission’s (“Commission”) AI Act Service Desk (“Service Desk”) updated its frequently-asked-questions guide to address the regulatory treatment of AI agents and agentic AI under the EU AI Act (“AI Act”). The guidance clarifies that while “AI agent” is not a separately defined category under the AI Act, such systems fall within the existing definitions of “AI system” under Article 3(1) and “general-purpose AI model” under Article 3(63), meaning existing AI Act obligations apply. The Service Desk highlighted that the AI Act’s prohibitions on harmful manipulation and exploitation of vulnerabilities under Article 5(1) are “particularly relevant” to agentic AI, and compliance may require design-level safeguards to avoid prohibited practices reasonably likely to cause significant harm. The guidance also notes that the level of autonomy or tool use of a model underlying an AI agent can be decisive in designating it as a model with systemic risk, triggering heightened risk management obligations. The Commission characterized its regulatory considerations as “preliminary” given the rapidly evolving nature of AI agent technology.
UK ICO Updates Guidance on Automated Decision-Making under the UK GDPR: The United Kingdom’s Information Commissioner’s Office (“ICO”) published updated guidance on automated decision-making (“ADM”) under the UK GDPR, effective on March 31, 2026. The guidance clarifies that ADM encompasses any solely automated processing, including profiling, which produces legal or similarly significant effects on individuals, regardless of whether the system employs complex algorithms or AI. Organizations must assess whether their processing involves a decision about a person, whether that decision carries significant effects, and whether it is solely automated without meaningful human involvement. The guidance highlights key risks, including discrimination from biased training data, lack of transparency, and heightened vulnerability for children and other at-risk populations. Organizations deploying ADM systems likely to result in high risk must conduct data protection impact assessments. The ICO noted it will further address ADM requirements through a forthcoming code of practice on AI and ADM.
Japan Cabinet Approves Revisions to Personal Data Protection Law to Promote AI Development: Japan’s Cabinet approved a bill to revise the country’s personal information protection law, easing restrictions on the use of individual data to accelerate the development and adoption of AI technology. The revisions would make it easier for companies to acquire and use personal data while introducing fines and other punishments for violations. Currently, the law prohibits providing an individual’s sensitive personal information, such as medical history or criminal record, to a third party without consent. Under the proposed revisions, consent would no longer be required where data is used for AI development purposes that do not identify individuals, or in cases where there is no clear infringement on a person’s rights or interests. The revised law would also introduce new enforcement mechanisms, authorizing the government to fine individuals or entities that obtain or use the personal data of more than 1,000 people, with fines equivalent to the profits gained from the improperly obtained information. The changes follow the Japanese government’s approval of the AI basic plan in December, which seeks to position Japan as the world’s most AI-friendly country. Japan’s personal data protection law is reviewed every three years.
EDPB Adopts Standardized DPIA Template for Public Consultation: The European Data Protection Board (“EDPB”) announced it had adopted a template for Data Protection Impact Assessments (“DPIAs”), intended to help organizations structure, harmonize, and document their DPIA reporting processes. The template aligns with the EDPB’s Helsinki Statement commitment to simplify GDPR compliance and strengthen consistency across EU Member States. The template guides controllers through the DPIA process step by step, covering the systematic description of the processing, lawfulness analysis, data minimization and quality measures, necessity and proportionality considerations, risk assessment and management, involvement of interested parties, and conclusion and decision. While not mandatory, the template provides predefined fields intended to prompt complete and structured responses, minimizing the risk of errors and saving time. The EDPB also published a companion explainer document providing concise guidance on how to effectively complete the template, including for controllers unfamiliar with DPIA methodology. The template is subject to public consultation until June 9, 2026, after which all Data Protection Authorities will adopt it either as their sole standard or as a “meta-template” to which national-specific templates will align.
Cyberspace Administration of China Announces Compliance Sweep Results Targeting 33 Apps for Personal Information Violations: The Cyberspace Administration of China (“CAC”) published the results of a compliance sweep examining the personal information collection and use practices of 33 apps. The enforcement action, conducted pursuant to the Cybersecurity Law, the Personal Information Protection Law (“PIPL”), and the Regulations on the Management of Network Data Security, identified violations across four categories. Fifteen apps either lacked personal information collection and used rules entirely or failed to prompt users to review such rules through pop-ups or other conspicuous methods upon first use. Two apps failed to individually list software development kits (“SDKs”) that collect personal information and did not obtain user consent for such collection. Four apps violated the principle of necessity by collecting personal information unrelated to the services they provided. Twelve apps failed to provide effective account cancellation mechanisms or imposed unreasonable conditions on account deletion. The CAC directed all affected app operators to complete remediation within 15 working days of the notification and stated that it will conduct verification checks and pursue further enforcement actions as warranted.
RECENT PUBLICATIONS & MEDIA COVERAGE
Seventh Circuit Issues Seminal Decision Holding BIPA Amendment Applies Retroactively
Blank Rome partners Daniel R. Saeedi and Rachel L. Schaller, and associates Amanda M. Noonan and Gabrielle N. Ganze authored this alert discussing the recent Seventh Circuit ruling that Illinois’ 2024 BIPA amendment applies retroactively, curbing per-scan damages and significantly reducing defendants’ exposure in pending cases.
AI’s Impact in California Courts and Why Judges and the Legislature Are at Odds
Blank Rome vice chair of artificial intelligence Sharon R. Klein and partner Mark S. Adams authored this Daily Journal article discussing the rapidly developing intersection of AI and the courts, an issue fueling one of California’s most significant institutional legal clashes.
Blank Rome partner Harrison Brown and associate Alycia S. Tulloch authored this alert discussing how Washington’s new HB 2274 curbs, but does not eliminate, the recent surge of email subject line lawsuits by lowering damages and adding a knowledge requirement, while leaving retailers exposed in pending cases and other states.
Blank Rome partner Philip N. Yannella was featured in this Cybersecurity Law Report article discussing the FTC’s new COPPA policy, which promotes privacy protective age verification practices by limiting enforcement when personal data is used solely to confirm users’ ages and required conditions are met.
© 2026 Blank Rome LLP. All rights reserved. Please contact Blank Rome for permission to reprint. Notice: The purpose of this update is to identify select developments that may be of interest to readers. The information contained herein is abridged and summarized from various sources, the accuracy and completeness of which cannot be assured. This update should not be construed as legal advice or opinion, and is not a substitute for the advice of counsel.
