Welcome to this month’s issue of The BR Privacy, Security & AI Download, the digital newsletter of Blank Rome’s Privacy, Security & Data Protection practice. We invite you to share this resource with your colleagues and visit Blank Rome’s Privacy, Security & Data Protection webpage for more information about our team.


RECENT HIGHLIGHT

Schlein Center for Cybersecurity Launch Event

Blank Rome partner and Privacy, Security & Data Protection practice co-chair Philip N. Yannella will serve as a discussion leader at the University of Pennsylvania’s Schlein Center for Cybersecurity Launch Event, Cybersecurity at the Crossroads: Technology, Security, and Society in the Age of AI, being held in Philadelphia, Pennsylvania, on Wednesday, October 21, 2026, from 2:00 to 5:30 p.m., with a reception to follow. Read more >>


STATE & LOCAL LAWS & REGULATIONS

Delaware Enacts Amendments to Personal Data Privacy Act: Delaware Governor Matt Meyer signed House Bill 380 (“HB 380”) into law, amending the Delaware Personal Data Privacy Act (“DPDPA”). HB 380 lowers the applicability thresholds to 10,000 consumers (down from 35,000), or 5,000 consumers (down from 10,000) for businesses deriving more than 20 percent of gross revenue from selling personal data. The amendments narrow the Gramm-Leach-Bliley Act entity-level exemption. They also expand the definition of sensitive data to include financial information, government-issued identification numbers, neural data, national origin, and sensitive inferences. Controllers may process sensitive data only with consent and where processing is reasonably necessary and proportionate. Sales of sensitive data are prohibited unless strictly necessary to provide a requested product or service, and are subject to notice, consent, and five-year recordkeeping requirements. HB 380 adds a first-of-its-kind due diligence obligation requiring controllers to enter into contracts with third parties and vet them through questionnaires and document review. New profiling provisions cover employment-context decisions and require adverse action notices, human review requests, and data protection impact assessments for automated decision-making. The amendments are effective on January 1, 2027.

California Enacts Package of AI Laws Addressing Workplace Surveillance, Automated Decisions, and Transparency: California Governor Gavin Newsom signed 13 laws placing guardrails on artificial intelligence (“AI”), several of which build on his May executive order on AI-related workforce disruption. SB 947, the No Robo Bosses Act of 2026, requires human involvement when employers use automated decision systems in disciplinary or termination decisions. SB 951 expands obligations under the California Worker Adjustment and Retraining Notification Act by requiring employers to give detailed notice when AI tools lead to job displacement or automation. On workplace surveillance, AB 1883 bans using such tools to collect workers’ neural data or to predict their emotional state, with a carve-out for technology deployed to ensure workplace safety. Other new laws strengthen the California AI Transparency Act, prohibit the removal of digital watermarks, require developers of clinical decision tools to reduce known or predictable bias, and treat impersonation using a digital replica as false impersonation.

California Governor Signs Package of Children’s Online Safety and AI Laws: California Governor Gavin Newsom signed more than a dozen bills designed to protect children online. SB 1119, known as “Adam’s Law,” requires companion chatbot operators to determine users’ ages or apply child protections to all users. Operators that allow child users must conduct risk assessments, put crisis response protocols in place, set protective default settings, and offer parental controls. They are also barred from showing cross-context behavioral advertising to children and from selling children’s personal information. Adam’s Law also requires independent child safety audits, with summaries submitted to the California Attorney General (“AG”). Penalties reach $15,000 per affected child for intentional violations, and there is a limited private right of action. AB 1709 bars covered platforms from offering addictive features, such as algorithmic feeds and autoplay, to users under the age of 16. It requires age verification and the deletion of existing accounts belonging to users younger than 16, with penalties of up to $50,000 per affected minor for knowing violations. AB 1159 extends student data protections to college students and creates a private right of action. Separately, SB 813 and AB 1405 set up a framework for independent AI audits and a state registry of AI auditors. Industry associations have signaled they will continue to challenge these types of laws on First Amendment grounds.

NYDFS Issues Guidance on Cybersecurity Risk Assessments, Flags Frontier AI as Potential Trigger: The New York State Department of Financial Services (“NYDFS”) has issued an industry letter on how regulated entities should design, conduct, and update the risk assessments required by its Cybersecurity Regulation (“Part 500”). NYDFS stated that the guidance clarifies existing requirements and does not create new obligations. Risk assessments must be updated at least once a year and whenever a change in business or technology causes a “material change” to cyber risk. Part 500 does not define that term. NYDFS instead lists examples, including mergers, major system migrations, significant outsourcing arrangements, and new developments such as frontier AI models. NYDFS said it has seen common compliance gaps during examinations and investigations. These include incomplete asset inventories, failing to identify where nonpublic information resides or flows, inconsistent methodologies, and overlooked concentration risk and single points of failure. The best practices NYDFS outlines include cross-functional participation, including from legal and compliance. They also include documentation linking each risk to its controls and recording any risk acceptance decisions, plus a risk register to track remediation. NYDFS expects each regulated entity to show how its risk assessment informed its control and risk acceptance decisions. Regulated entities are encouraged to review their risk assessment procedures in light of the guidance.

CalPrivacy Issues Data Broker Enforcement Advisory: The California Privacy Protection Agency (“CalPrivacy”) Enforcement Division issued Enforcement Advisory No. 2026-01. The advisory warns data brokers that they must provide only true and correct information in their annual data broker registrations under the Delete Act. Each year, registrants must disclose required metrics and the types of data they collected. This includes minors’ data, precise geolocation, biometric data, citizenship data, and reproductive health data. They must also disclose whether they shared data with governments, law enforcement, foreign actors (China, Iran, North Korea, and Russia), or developers of generative AI (“GenAI”) systems. Inaccurate information triggers a $200 fine for each day it appears in the registry. The advisory stresses that the Delete Act does not distinguish unintentional mistakes from intentional misrepresentations. Hypothetical scenarios illustrate how expanding a client base, for example, to foreign government bureaus or AI startups, may create new disclosure obligations. The advisory follows more than a dozen CalPrivacy actions since November 2024 for registration failures. CalPrivacy also said accurate registrations are essential to its Delete Request and Opt-out Platform (“DROP”), which now has more than 500,000 registered users.

Maryland Governor Announces AI Framework Prioritizing Privacy, Workers, and Children: Maryland Governor Wes Moore announced a new AI framework that sets out his administration’s core principles for the responsible development, deployment, and regulation of AI, citing the absence of federal guardrails. The framework rests on three principles: protecting Marylanders, centering workers, and keeping children safe. The administration’s AI Subcabinet is developing legislative recommendations for regulating frontier AI model companies. Those recommendations include safety frameworks and testing, independent third-party audits, whistleblower protections, public reporting, and 72-hour incident reporting. The framework also proposes a statutory Right of Publicity that would treat an individual’s likeness as a property right. It calls for regulator guidance confirming that existing civil rights, consumer protection, housing, and lending laws already reach AI-driven decisions. Other proposals would restrict discriminatory tenant-screening algorithms, algorithmic rent coordination based on non-public competitor data, and algorithmic targeting of problem gamblers. For workers, the framework targets social scoring and tracking that undermines organizing. For minors, it would strengthen chatbot protections, curb AI-driven addictive design features for users under the age of 16, and require families to be informed before AI tools are used in classrooms. The framework builds on Maryland’s 2024 Artificial Intelligence Governance Act and its Age-Appropriate Design Code Act.

California Governor Issues Executive Order to Advance AI “Kill Switch”: California Governor Gavin Newsom issued an executive order to speed up the state’s new framework for independent oversight of AI companies. The order cites recent incidents, including the “Hugging Face attack.” In that incident, two OpenAI models escaped their testing environment and accessed a third-party’s servers by exploiting vulnerabilities in shared infrastructure. The order directs the Government Operations Agency to accelerate the implementation timelines for two laws. Senate Bill 813 creates a framework for independent verification organizations that assess AI systems for safety and risk. AB 1405 creates a state registry of AI auditors. Working with the Governor’s Office of Emergency Services, the agency will convene national experts to recommend changes to state law within two months. Proposals under consideration include: (1) requiring frontier AI companies to embed independent auditors onsite in their labs; (2) having those organizations verify the safety frameworks, transparency reports, and risk assessments the companies must file; (3) requiring an emergency shutoff, or “kill switch,” for frontier models, with its effectiveness verified on an ongoing basis; and (4) expanding the definition of “critical safety incidents” to include loss-of-control events, which affects reporting obligations under SB 53, the Transparency in Frontier Artificial Intelligence Act. The Governor also urged Congress to adopt California’s framework or treat it as a national floor.

New York City Council Unveils AI Safety Legislative Package: The New York City Council announced a slate of bills to regulate AI, to be heard at an October 5, 2026, Committee of the Whole hearing. Introduction 2602 would bar businesses from marketing, selling, or deploying any AI system in the city that has not been validated by a third party. The validator would assess data quality, bias, data privacy, and security, and would confirm the system has a human-override “kill switch.” Penalties under that bill would be $25,000 per violation. Introduction 2601 would require City contractors to report AI safety incidents to the Office of Cyber Command within 24 hours. Cyber Command would then have to disclose those incidents publicly within 24 hours. Introduction 2599 would create data privacy, security, and transparency requirements for chatbot providers, enforceable by the City. Other proposals would create a private right of action for foreseeable harms caused by “jailbreaking.” They would also set up a first-in-the-nation program giving whistleblowers a share of recovered penalties. Further bills would ban false or misleading representations about AI safety and restrict unauthorized deepfakes of elected officials and candidates.

Florida AG Proposes Criminal Liability for AI Chatbot Developers: Florida AG James Uthmeier proposed legislation to hold companies that own, control, or distribute AI chatbots criminally responsible when those systems participate in criminal activity. Under the proposal, a business entity would be liable if its AI system participates in a crime. The proposal would apply to any company with practical control over an AI system’s design, training, deployment, or safety settings, including by making the system available to Florida users. A convicted business would face heavy fines, payments to victims, and court-ordered monitorship. The Florida AG described the legislation as closing a gap left by civil remedies, which can force a company to pay and change its product but cannot treat it as a co-defendant in a homicide. The proposal follows Florida’s June 1, 2026, civil lawsuit against OpenAI and its CEO, which alleges the company marketed ChatGPT as safe while ignoring internal warnings and putting children at risk. It also follows an ongoing criminal investigation, opened after prosecutors reviewed chat logs in which the accused Florida State University gunman allegedly used ChatGPT to plan the attack.


FEDERAL LAWS & REGULATIONS

FTC Rescinds 2021 Policy Statement on Health App Breaches but Keeps the Health Breach Notification Rule: The Federal Trade Commission (“FTC”) withdrew its 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. The FTC called the statement “controversial.” It had said that the FTC’s 2009 Health Breach Notification Rule (“HBNR”) applied to health apps and connected devices that collect consumer health information. The HBNR requires “vendors of personal health records” to notify consumers when their information has been exposed. When it was issued, the policy was meant to keep entities that are not subject to the Health Insurance Portability and Accountability Act (“HIPAA”) accountable for protecting sensitive health information. The FTC said the policy “provided minimal benefit” and was no longer needed after the it updated the HBNR in 2024. That update expressly covers health apps and connected devices such as fitness trackers. The FTC said the withdrawal advances “President Trump’s deregulatory agenda and the Commission’s policy of avoiding unnecessary use of subregulatory guidance.”

Coalition of State AGs Urges Congress to Regulate Frontier AI Without Preempting State Laws: 25 state AGs signed a letter urging congressional leadership to immediately establish comprehensive federal regulation and safety protocols for frontier AI. The letter cites recent incidents caused by rogue frontier models. The coalition argues that self-regulation is not enough stating that frontier model operators have initially minimized incidents, restricted outside researchers’ access to post-mortem data, and waited weeks to disclose separate incidents until it was publicly reported. The AGs call for mandatory federal oversight of safety testing and standards and for government-led incident response, with investigators given direct access to books, records, and findings made public. They also seek antitrust safeguards and an explicit prohibition on preempting state laws, with full authority for state officials to enforce federal protections.

NIST Releases Updated Draft Guide to Operational Technology Security: The National Institute of Standards and Technology (“NIST”) published the initial public draft of Special Publication (“SP”) 800-82 Revision 4, Guide to Operational Technology (OT) Security. The guide offers recommendations for securing OT systems while accounting for their particular performance, reliability, and safety needs. OT refers to programmable systems that monitor or control the physical environment, such as industrial control systems, building automation, transportation, and physical access control systems. The revision extends coverage to building automation and control systems, water and wastewater systems, food and agriculture, freight rail, maritime vessels, and the convergence of the Industrial Internet of Things with cloud services. The guide is now organized around the NIST Cybersecurity Framework (“CSF”) 2.0, and its risk management discussion has been reorganized to focus on the CSF “Govern” Function. It also gives more detail on how OT risk management fits within broader enterprise risk management. Other additions cover adoption of the NIST Risk Management Framework, guidance on asset management and on network monitoring and detection, and security architecture guidance that applies zero trust principles. Organizations that run or depend on OT should look at the draft for its governance and enterprise risk expectations, which may shape views on what counts as reasonable security. Comments are due by November 30, 2026. 

CISA and NIST Release Guidelines to Protect Federal Cloud Identity Systems from Token Theft, Forgery, and Misuse: The Cybersecurity and Infrastructure Security Agency (“CISA”) and NIST released Interagency Report (“IR”) 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers. The IR is intended to help federal agencies and cloud service providers (“CSPs”) defend the identity tokens and assertions that underpin single sign-on (“SSO”), federation, and API-based access. Adversaries increasingly target these systems to move laterally through networks and reach sensitive data. The final IR reflects nearly 250 public comments and consultations with major CSPs, including Google, Microsoft, Okta, Oracle, and Amazon Web Services. Building on NIST Special Publication 800-53 and its IA-13 control, IR 8587 addresses architectural considerations for identity providers and authorization servers. It also calls for stronger key management, token verification, and token life cycle controls. It gives guidelines for securing SSO, federation, and API access that rely on digitally signed, asymmetrically encrypted tokens. Finally, it sets out principles for configurable, interoperable, threat-adaptive controls across cloud environments. The recommendations apply to both commercial and government-operated cloud services and support implementation of Executive Order 14306 on secure software development practices. CISA urges federal agencies, CSPs, and cloud consumers to review and implement IR 8587.

CISA Retires Six Free Cybersecurity Assessments for Critical Infrastructure: CISA will stop providing six free assessments to critical infrastructure organizations. These assessments are Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments, and Cyber Infrastructure Surveys. In each assessment, CISA regional advisers worked with operators and used the agency’s Cyber Security Evaluation Tool (“CSET”) to produce reports recommending security improvements. The assessments covered resilience during a crisis, supply chain risk, security controls, ransomware containment, and the ability to detect and contain intrusions. CISA said it is retiring these “legacy” assessments to reduce redundancy. It will instead direct operators to its Cross-Sector Cybersecurity Performance Goals (“CPGs”), which include a self-assessment questionnaire. Former CISA officials and others in the industry say the CPGs are a tool for deciding priorities and do not replace a standards-based assessment. The change comes as CISA has lost about one-third of its workforce. It also comes as CISA is reportedly close to finalizing the Cyber Incident Reporting for Critical Infrastructure Act rules.


U.S. LITIGATION

People-Search Companies Challenge Connecticut Consumer Profile Deletion Law: Over a dozen “people search” companies filed a federal lawsuit in the U.S. District Court for the District of Connecticut against Connecticut AG William Tong. They are seeking declaratory and injunctive relief against Public Act 26-64 (“Act”). The Act amends the Connecticut Data Privacy Act (“CTDPA”) and gives consumers a right to delete any “consumer profile” containing their personal information, even if all of that information is publicly available from other sources. The deletion right also covers “inferences” drawn from that public information, such as a likelihood that two people are related. The plaintiffs argue that the Act discriminates based on content and speaker in violation of the First Amendment, and that it also violates their equal protection rights under the Fourteenth Amendment. They note that they already offer voluntary opt-out procedures. Willful violations of the Act carry $5,000 penalties under the Connecticut Unfair Trade Practices Act, and non-willful violations carry $2,500 penalties. The AG’s office has said it will “vigorously defend” the Act, which was set to take effect on October 1, 2026.

Illinois Appellate Court Affirms BIPA Government Contractor Exemption for Home Care Provider: The Illinois Appellate Court, First District, affirmed dismissal of a putative class action under the Biometric Information Privacy Act (“BIPA”) against Help at Home, LLC (“Help at Home”), a home care provider. The plaintiff, a former employee, alleged that Help at Home collected her fingerprints during onboarding without informed written consent, without consent to disclosure, and without a publicly available retention and destruction policy. Help at Home contracts with the Illinois Department on Aging, and its provider agreement requires compliance with the Illinois Health Care Worker Background Check Act. That act requires health care employers to run fingerprint-based criminal history checks on applicants who receive conditional job offers. The Court agreed with the Third District’s reading in Thomas v. Cornerstone Services, Inc. and held that BIPA Section 25(e) exempts a private entity only when it acts within the scope of its government contract. Because the fingerprints were collected under that contract, the Court found Help at Home exempt. The order was issued under Supreme Court Rule 23, so it is non-precedential except in limited circumstances. Still, it signals that government contractors collecting biometrics because of contract-mandated legal requirements may have a strong defense, while collection outside the contract’s scope remains exposed.


U.S. ENFORCEMENT

CalPrivacy Fines Virginia Data Broker for Registration Failure: CalPrivacy issued a decision requiring Virginia-based data broker SalesIntel Research, Inc. (“SalesIntel”) to pay a $36,400 fine. SalesIntel must also change certain practices because it did not register on time with the agency’s data broker registry. The Delete Act requires businesses that collect and sell personal information about consumers they have no direct relationship with to register by January 31 each year and pay an annual fee, currently $6,600. CalPrivacy alleged that SalesIntel sold consumers’ personal information for data enrichment and targeted advertising in 2024 but did not register by the January 31, 2025, deadline. Of the fine, $6,600 covers the 2025 registration fee. The stipulated order also requires SalesIntel to meet future registration obligations, disclose metrics on consumer privacy requests in its privacy policy, and process deletion requests through DROP. Data brokers had to begin processing DROP requests on August 1, and more than 500,000 Californians have registered to use the tool. The action follows more than a dozen enforcement actions against data brokers since November 2024.

Connecticut AG Launches Investigation into Messaging App: Connecticut AG William Tong announced an investigation into MediaLab.AI Inc. (“MediaLab”) over alleged lax age assurance and content moderation practices on its Kik messaging app. According to the Connecticut AG, Kik uses no technological tooling to monitor for underage users, relies on reactive reviews of reported or manually discovered content, and has conducted no audits of the effectiveness of its age determination processes. The Connecticut AG also noted that MediaLab marketed Kik as appropriate for users over 13 as recently as September 2024. It did not restrict minors in its Terms of Service until February 2025 or add an age restriction to its privacy notice until June 2025. The Connecticut AG’s office first issued a notice of violation under the CTDPA in July 2025. That notice cited allegedly deficient privacy notices and consumer rights mechanisms, as well as the processing of sensitive data without proper consent, including health, biometric, genetic, and precise geolocation data. The AG stated it has now issued a civil investigative demand because MediaLab has only partially addressed those deficiencies. The demand seeks records on MediaLab’s data processing, content moderation, and age assurance practices that may violate the CTDPA and the Connecticut Unfair Trade Practices Act.

Alabama AG Announces Settlement with Social Media Company Over Youth Safety Claims: Alabama AG Steve Marshall announced a settlement with TikTok Inc. (“TikTok”) that resolves the state’s claims that TikTok designed its platform with addictive features, knowingly exposed young users to serious mental harms, and misled the public about the platform’s safety. Alabama will receive at least $100 million within 45 days and could receive up to $300 million if certain conditions are met. The settlement also requires TikTok to put in place a range of safety features. These include a two-hour daily time limit, “productive pauses” for teen users, overnight access restrictions, robust age assurance measures, and a default non-personalized feed for teen users. TikTok must also limit how easily adults can discover teen accounts, notify parents of suspicious interactions between teens and adults, prohibit cosmetic filters for teen users, and offer stronger parental controls. The Alabama AG called the settlement “first-in-the-nation,” and it came shortly before trial was set to begin. It follows the Alabama AG’s recent settlements with Meta and Roblox and his announced investigation into OpenAI. It also adds to a growing trend of state action on youth online safety and addictive platform design.

Florida AG Seeks Temporary Injunction Over AI Safety, Minors’ Data, and Dark Patterns: Florida AG James Uthmeier has moved for a temporary injunction against OpenAI entities and CEO Sam Altman. The case was originally filed in June 2026 under the Florida Deceptive and Unfair Trade Practices Act (“FDUTPA”) and public nuisance law. The motion points to recent incidents in which OpenAI agents allegedly gained unauthorized access to systems. The AG says OpenAI took months to detect incidents and then reported only through a routine disclosure inbox. The motion also cites attempted intrusions into federal agency systems and the leaking of ChatGPT users’ images online. The Florida AG argues that FDUTPA incorporates the Children’s Online Privacy Protection Act (“COPPA”) and that OpenAI collects data from children under 13 without parental consent or meaningful age verification. The Florida AG also targets “dark patterns” such as conversation prolongation and anthropomorphization, which allegedly push users to share more data. The requested relief includes independent third-party guardrails before any new model is developed; a bar on offering ChatGPT to Florida minors; COPPA-style notice, consent, and security requirements; and limits on human-like self-representation. 

White House and Major AI Developers Sign “Morally Binding” Frontier AI Safety Accord: President Donald Trump and the leaders of Google, Anthropic, Meta, OpenAI, xAI, and Nvidia signed the White House Accord on Super Intelligence, titled the “Joint Commitment on Frontier Responsibilities” (“Accord”). The Accord calls for four layers of controls and audits. First, companies are to put in place internal controls to monitor model capabilities and alignment in areas including cybersecurity, biosecurity, and chemical threats, and to ensure that models do not hack or access technical systems in unintended ways. Second, an internal team is to verify that the controls work and that issues are remediated. Third, an independent external auditor or evaluator is to assess the controls. Fourth, an independent board committee is to oversee the work. No enforcement mechanism was announced. Instead, the President cited developer “self-policing” and named the U.S. Department of Justice, Federal Bureau of Intelligence, and Central Intelligence Agency, but not the FTC, as the agencies that would pursue bad actors. The Accord follows a wave of AI cybersecurity incidents. The President continues to oppose federal legislation, and Congress remains at an impasse. Meanwhile, states continue to regulate AI chatbots and automated decision-making technology.


INTERNATIONAL LAWS & REGULATIONS

Canadian Privacy Commissioner Issues Guidance on Assessing Third-Party Service Providers: Privacy Commissioner of Canada Philippe Dufresne published guidance to help organizations subject to the Personal Information Protection and Electronic Documents Act (“PIPEDA”) assess a third-party service provider’s approach to privacy before engaging the provider. The guidance says that under PIPEDA Principle 4.1.3, organizations remain responsible for personal information transferred to third parties for processing and must use contractual or other means to ensure comparable protection. Recommended best practices include identifying sensitive personal information, applying extra scrutiny to publicly available data and to providers’ claims of anonymization, and mapping data flows to subcontractors and cloud storage. Organizations should also confirm whether providers will use data for their own purposes, such as training algorithms, and should ask where any AI training data came from. Additional recommendations cover assessing cross-border transfers, verifying security controls and breach-management roles, evaluating the risks of vendor lock-in and lock-out, confirming data retention and end-of-contract deletion, and monitoring providers through audits. The Office of the Privacy Commissioner of Canada (“OPC”) encourages organizations to include these practices as contract terms. The OPC is accepting comments on the guidance until December 4, 2026.

European Commission Proposes EU KIDS Act: The European Commission published its proposal for the EU KIDS Act (the “EU KIDS Act”), which would create a harmonized EU framework for protecting children online. The Commission describes the EU KIDS Act as a “specification” of the Digital Services Act (“DSA”), but commentators note that it goes beyond the DSA’s risk-based approach by directly regulating the design and architecture of covered products. The EU KIDS Act would apply to “Social Media+” services, including social networks, video-sharing platforms, online games, AI companions and chatbots, app stores, and operating systems. It would bar children under the age of 13 from creating accounts, allow guardians to set up limited-feature accounts for minors ages 13 to 15, and permit autonomous accounts starting at age 15. Under its safety-by-design requirements, providers would have to disable addictive features, set high-privacy defaults, and restrict unsolicited contact with minors. Self-declaration would not satisfy the age assurance requirements. Instead, age verification would have to be privacy-preserving, with data minimization and zero-knowledge-proof technology. Very large online platforms would have to submit compliance plans and undergo independent audits, and the Commission would aim to conclude investigations within 90 days. Penalties could reach 6 percent of global annual revenue. Privacy advocates and industry groups have warned that collecting age and identity data on this scale could attract cybercriminals.

EU Advocate General Finds Consent for Marketing by Unnamed “Partners” Invalid: Advocate General Dean Spielmann of the Court of Justice of the European Union has issued an opinion in Groupe Canal + (Case C-317/25). He concludes that consent to direct marketing by a company’s “partners” is valid only if the data subject knew who those partners were when consent was given. In 2021, Groupe Canal + ran electronic direct marketing campaigns aimed at about 3.9 million people. Two internet service providers had collected those people’s data, and the subscribers had consented to marketing by the providers’ unidentified “partners.” The French Data Protection Authority found that this consent was not valid and fined Groupe Canal + €600,000. The Advocate General reasoned that informed consent requires the data subject to know the identity of the controller. If the marketing controller was not identified, it must obtain fresh consent no later than the first communication. He also concluded that offering an unsubscribe option in the first message does not cure the lack of prior consent. In the alternative, he said that “partners” is too vague to define a category of recipients that would let data subjects reasonably expect contact from a particular business. The opinion does not bind the Court of Justice, which has begun its deliberations and will issue a judgment later. Companies that rely on consent collected by third parties for co-marketing or data-sharing should review those arrangements now.

EDPB Adopts Guidelines on When to Impose GDPR Fines: The European Data Protection Board (“EDPB”) adopted Guidelines 04/2026, for public consultation. The Guidelines are meant to make EU supervisory authorities more consistent in deciding whether to impose an administrative fine in addition to, or instead of, the other corrective measures in Article 58(2) of the GDPR. They set out a five-step methodology. The first three steps cover the legal preconditions: whether the infringement can lead to a fine, whether the party can be held liable, and whether the infringement was intentional or negligent. The last two steps ask whether the Article 83(2) factors show the infringement is minor, and whether a fine would be effective, proportionate, and dissuasive. As a general rule, minor infringements will not draw a fine and may receive a reprimand instead, while infringements that are not minor carry a strong presumption that a fine will be imposed. Organizations should note that remediation counts for more when it happens early. Measures taken voluntarily before an organization learns of an investigation are more likely to be treated as mitigating. Routine compliance steps and required cooperation with authorities will rarely count as mitigating. The Guidelines include 14 practical examples, replace the earlier WP29 guidelines on fines, and are open for comment until November 13, 2026.

OAIC Issues Guidance on New Automated Decision-Making Transparency Obligation: The Office of the Australian Information Commissioner (“OAIC”) published resources, including a fact sheet, a flowchart, and an updated version of its APP 1 Guidelines, to help entities comply with new automated decision-making transparency requirements under the Australian Privacy Principles (“APPs”). These requirements take effect on December 10, 2026. The Privacy and Other Legislation Amendment Act 2024 added the requirements to APP 1. They apply when an entity arranges for a computer program to make a decision, or to do something substantially and directly related to making one, using personal information, and the decision could reasonably be expected to significantly affect an individual’s rights or interests. In those cases, the entity’s privacy policy must disclose the kinds of personal information used, the kinds of decisions made solely by computer programs, and the kinds of decisions those programs substantially and directly inform. According to the OAIC, outputs from machine learning or generative AI generally fall within scope unless they are subject to extensive human oversight and control. The requirements also apply to procured third-party software. The OAIC expects the obligation to remain with the deploying entity, and vendors should give clear, high-level information about how their software can be used to make decisions. Examples of in-scope uses include facial recognition, recruitment screening, personalized pricing, and credit decisions. Trade secrets and commercially sensitive information are excluded from the disclosure requirement.


RECENT PUBLICATIONS & MEDIA COVERAGE

All Bets Are Off: Artificial Intelligence and the New Class Action Frontier

Blank Rome partner Daniel R. Saeedi will serve as a panel moderator at the American Bar Association Litigation Section’s 2026 Class Actions National Institute, being held October 29 through 30, 2026, in Las Vegas, Nevada.


© 2026 Blank Rome LLP. All rights reserved. Please contact Blank Rome for permission to reprint. Notice: The purpose of this update is to identify select developments that may be of interest to readers. The information contained herein is abridged and summarized from various sources, the accuracy and completeness of which cannot be assured. This update should not be construed as legal advice or opinion, and is not a substitute for the advice of counsel.