What regulators say the rules require, covering formal rulemaking and the advisories that often arrive first.

Brazil (LGPD)

Brazil's Encarregado Regulation: The Appointment Paperwork, the Website Notice and the Conflict Rules

September 21, 2026

The LGPD says a controller must appoint an encarregado and publish how to reach them, and leaves the rest to the regulator. Resolution CD/ANPD No. 18 of 16 July 2024 supplies it: a written, dated and signed act of appointment, a named substitute, a minimum content for the public notice, five duties the organisation owes its encarregado, and a conflict-of-interest regime that can lead to sanctions.

Read more →
China (PIPL)

China's PIPL Audit Duty Waited Four Years for a Frequency, a Trigger List and an Annex of 27 Checks

September 21, 2026

Article 54 of China's Personal Information Protection Law has required regular compliance audits since November 2021, without saying how often, by whom or against what. The CAC's Measures for Personal Information Protection Compliance Audits, in force since 1 May 2025, supply those answers, and add a second route by which a regulator can order an outside audit at the processor's expense.

Read more →
Cross-Border Transfers

The Justice Department's Bulk Sensitive Data Rule: Six Countries, Six Data Categories, and Two Compliance Dates in 2025

September 21, 2026

Executive Order 14117 directed the Attorney General to bar or condition transactions that give six foreign governments, and persons tied to them, access to Americans' bulk sensitive data. The resulting rule, 28 CFR part 202, took effect April 8, 2025. Its due diligence, audit and reporting duties followed on October 6, 2025. The only change to the text since publication is a one-line correction.

Read more →
India (DPDP Act)

India's DPDP Breach Rule Has No Harm Threshold and a 72-Hour Report, and It Does Not Start Until 2027

September 21, 2026

Section 8(6) of India's Digital Personal Data Protection Act requires a Data Fiduciary to tell the Data Protection Board and each affected individual about a personal data breach, and rule 7 of the 2025 Rules fills in the content and a 72-hour clock. Both sit in the commencement tranche that starts eighteen months after 13 November 2025, while CERT-In's six-hour incident reporting already applies.

Read more →
Brazil (LGPD)

The LGPD's Small-Business Regime: Who Qualifies, Who Is Excluded and Which Clocks Run at Double Speed

September 21, 2026

Resolution CD/ANPD No. 2 of 2022 gives micro and small enterprises, startups, non-profits and individuals acting as controllers or processors a lighter version of the LGPD: a simplified record of processing, no mandatory encarregado, and doubled deadlines. Three exclusions take it away, the ANPD can withdraw it case by case, and a 2024 regulation rewrote one deadline rule.

Read more →
Canada (PIPEDA)

Canada's Meaningful Consent Guidelines Sort Themselves Into Must and Should. Here Is Which Is Which

September 21, 2026

The Guidelines for obtaining meaningful consent were issued jointly by the federal Privacy Commissioner and the Alberta and British Columbia commissioners in May 2018 and last modified in August 2025. They set seven principles, four elements that must be emphasised, three triggers for express consent and an under-13 position on children, and label each item an obligation or a best practice.

Read more →
GLBA

The CFPB's Personal Financial Data Rights Rule: The Text of Part 1033 and the Injunction That Froze It

September 14, 2026

The Personal Financial Data Rights Rule, 12 CFR part 1033, requires banks, card issuers and other data providers to make consumer financial data available to consumers and authorized third parties. The rule remains on the books, but since October 29, 2025 the CFPB has been enjoined from enforcing it while it reconsiders the rule, and appeals from that order are paused.

Read more →
Dark Patterns

The FTC Negative Option Rule After Click-to-Cancel: What Was Vacated and What Part 425 Says Now

September 14, 2026

Between late 2024 and early 2026, 16 CFR Part 425 said three different things. The FTC's click-to-cancel amendments took effect, were vacated by the Eighth Circuit on procedural grounds weeks before full compliance was due, and were replaced by the 1973 book-club rule. This sets out what each version says, why the court ruled as it did, and what federal law governs online subscriptions today.

Read more →
UK Data Protection

How the ICO Calculates a UK GDPR Fine: The Five Steps in Its Data Protection Fining Guidance

September 14, 2026

The Information Commissioner's Office published its Data Protection Fining Guidance on 18 March 2024 under section 160 of the Data Protection Act 2018. It explains when the regulator issues a penalty notice and how it reaches an amount, from a seriousness band through a turnover adjustment to a final check against the statutory cap. Both are set out here.

Read more →
Ransomware

When Ransomware Encrypts Health Data, HIPAA Presumes a Breach: How the Presumption Works

September 14, 2026

HHS does not treat ransomware as a mere outage outside the breach rules. Its Office for Civil Rights reads encryption by an attacker as an acquisition of the data, which brings the incident within the regulatory presumption of breach at 45 CFR 164.402. This sets out where that presumption came from, what rebutting it involves, and the clocks that follow when it stands.

Read more →
CPPA

Where the CPPA's Rulemaking Authority Comes From, and What It Covers

September 7, 2026

Proposition 24 established the California Privacy Protection Agency in December 2020, but the power to write CCPA regulations did not move to it on that date. The transfer was conditional, it completed in April 2022, and the Attorney General's own regulatory authority was never extinguished. This traces the grant, the condition, the board that exercises it, and what the agency has adopted.

Read more →
COPPA

The Amended COPPA Rule: What the FTC Changed, and When Each Piece Bound

September 1, 2026

The FTC published amendments to the Children's Online Privacy Protection Rule on April 22, 2025. They added a separate-consent requirement for third-party disclosure, a written retention policy and a prohibition on indefinite retention, two new categories of personal information, a written security program, and staggered obligations for safe harbor programs.

Read more →
CCPA / CPRA

California's ADMT, Risk Assessment and Cybersecurity Audit Regulations: What the Final Text Says

September 1, 2026

The California Privacy Protection Agency's rulemaking package on automated decisionmaking technology, risk assessments and cybersecurity audits took effect January 1, 2026, and the obligations it creates switch on across four separate years. This reports what the approved text defines, whom each article reaches by its own terms, and the dates written into it.

Read more →
HIPAA

HHS Has Proposed the First Real Rewrite of the HIPAA Security Rule Since 2013

September 1, 2026

In January 2025 the Office for Civil Rights proposed rewriting the HIPAA Security Rule, retiring the addressable safeguard category and adding asset inventories, encryption, multi-factor authentication and annual compliance audits. Nothing has been finalised, and the Unified Agenda now carries the rulemaking as a long-term action.

Read more →
TCPA

Revoking TCPA Consent: The 2024 FCC Rule, and the Part of It Still Waived

September 1, 2026

A February 2024 FCC order codified the right to revoke TCPA consent by any reasonable means, fixed seven per se opt-out words for reply texts, capped the processing window at ten business days, and permitted one confirmation message. The cross-message-type portion of that rule has been waived twice and is now scheduled to take effect January 31, 2027.

Read more →
HIPAA

The HIPAA Security Rule Requirement That OCR Cites Most Often

August 12, 2026

The HIPAA Security Rule requires covered entities and business associates to conduct an accurate and thorough assessment of risks to electronic protected health information. The requirement recurs across HHS Office for Civil Rights resolution agreements more than almost any other provision. This sets out what the regulation says and how OCR has described the standard.

Read more →