Privacy Regulation Roundup

This Privacy Regulation Roundup summarizes the latest major global privacy regulatory developments, announcements, and changes. This report is updated monthly. For each relevant regulatory activity, you can find actionable Info-Tech analyst insights and links to useful Info-Tech research that can assist you with becoming compliant.

Author(s): John Donovan, Ahmad Jowhar, Safayat Moahamad

Canada's Digital Policy Wave Signals Stronger Enforcement

Type: Regulation
Announced: June 2026
Affected Region: Canada

Summary: Canada's digital policy landscape is evolving rapidly, with several major developments arriving almost simultaneously. Recent milestones include the Office of the Privacy Commissioner's Annual Report, ongoing investigations into OpenAI and Grok, and the introduction of Bills C-34 and C-36. While each initiative would typically warrant significant attention on its own, together they signal an acceleration in Canada's approach to digital governance, privacy, and AI oversight.

Bill C-34 focuses on restricting social media access for individuals under the age of 16, raising practical questions around age verification, enforcement, and implementation. Bill C-36, the long-anticipated successor to PIPEDA, largely mirrors the structure of the previous Bill C-27 but introduces a significant change to Canada's privacy enforcement model. Rather than relying primarily on the Office of the Privacy Commissioner to investigate and make recommendations, the proposed legislation shifts toward an administrative tribunal capable of issuing binding orders and imposing substantial monetary penalties.

Collectively, these developments suggest Canada is moving toward a more assertive and enforcement-driven regulatory framework, bringing it closer to the models already seen in Quebec and the European Union. For organizations, the pace of change means privacy compliance can no longer be viewed as a gradual evolution. Instead, businesses should expect a more active regulatory environment where governance, accountability, and operational readiness will become increasingly important as Canada's digital policy framework continues to mature.

Analyst Perspective: Organizations should stop asking when Canada's privacy laws will change and start asking whether their operating model is ready when they do. Whether Bill C-36 passes in its current form is almost secondary, the direction of travel is clear. The proposed enforcement transition, to the Digital Safety and Data Protection Commission, is bound to change how organizations think about privacy risk in Canada.

Unlike a recommendation-based model, a more enforcement-oriented regime ties costs to immature governance as privacy issues tend to translate into operational disruption-led formal findings. Privacy, AI governance, and accountability are becoming operational capabilities, not legal exercises. Organizations that embed these disciplines into day-to-day decision-making will adapt quickly; those relying on periodic compliance projects will find themselves constantly reacting to the next regulatory shift.

Analyst: John Donovan, Principal Research Director – Infrastructure and Operations

More Reading:

  • Source Material: IAPP
  • Related Info-Tech Research:


EU AI Act: Delayed Guidance, Delayed Deadlines

Type: Draft Guidance
Announced: May 2026
Affected Region: EU

Summary: Following a series of delays, the European Commission released draft guidelines on May 19th, aimed at helping providers, deployers, and other relevant actors determine whether an AI system falls within the high-risk classification under the Act.

The guidelines are structured in three phases, offering general principles for classification along with specific guidance on the two high-risk categories established under Article 6. Article 6(1) and Annex I address AI systems used in product safety contexts, while Article 6(2) and Annex III cover stand-alone high-risk systems deployed across eight designated areas, including biometrics, education, employment and law enforcement. The Commission noted that the examples provided within the guidance are not exhaustive and may be updated over time. A public consultation period has been opened, with comments accepted through June 23rd, 2026.

The release of these guidelines follows significant pressure from industry stakeholders, including more than 110 EU-based businesses that had lobbied for a two-year pause on the enforcement of high-risk rules, citing the absence of adequate guidance and a shrinking compliance window. The Commission had originally been expected to publish the guidelines by February 2nd, 2026, ahead of the August 2nd, 2026 enforcement date for high-risk provisions.

These delays played a central role in accelerating the development and passage of the Digital Omnibus on AI, a reform package that introduced revised compliance deadlines. Under the updated timeline, the implementation date for rules governing stand-alone high-risk AI systems has been extended to December 2nd, 2027, with systems embedded in products subject to compliance by August 2nd, 2028.

Analyst Perspective: With revised compliance deadlines now in place, organizations have a renewed but time-limited window to assess whether their AI systems fall within the high-risk categories established under the EU AI Act. The draft guidance signals that AI governance in Europe is becoming more dependent on system inventory quality, use-case classification discipline, and traceable accountability.

Classification is the gateway decision. Where high-risk classifications apply, organizations should begin aligning their governance frameworks, documentation practices and risk management processes with the requirements of the Act. Participating in the public consultation before the June 23rd deadline also presents an opportunity for organizations to contribute feedback and help shape the final guidelines.

By taking a proactive and structured approach to EU AI Act compliance, organizations will be well-positioned to meet their regulatory obligations while building the internal governance capabilities that will support responsible AI adoption over the long term.

Analyst: Ahmad Jowhar, Senior Research Analyst – Security & Privacy

More Reading:

  • Source Material: IAPP
  • Related Info-Tech Research:


Chatbot Regulation: US State Laws Converge

Type: Legislation(s)
Enacted: Various Dates
Affected Region: USA

Summary: A growing number of US states are enacting laws that regulate consumer-facing chatbots and impose broadly similar obligations on operators. As of June 2026, 11 states had passed chatbot laws, with Hawaii expected to join shortly. Across these laws, a common structure is baseline obligations for all users. This is typically focused on AI-identity transparency and crisis-response protocols, followed by additional protections for minors. This also includes repeated disclosures, intimate content restrictions, and limits on manipulative or human-like engagement. The broader trend indicates a rapidly expanding state-law patchwork governing chatbot design, transparency, and safety.

State variation remains important. Scope differs depending on whether a law captures general conversational AI, functionally defined companion chatbots, or systems specifically designed to simulate sustained relationships. Requirements also vary across age assurance, parental controls, public reporting, and enforcement. Most states vest enforcement in the attorney general, while California, Oregon, and Washington allow private rights of action, increasing potential litigation exposure.

Analyst Perspective: At the state level, a compliance model is taking shape around a common set of expectations.

  • Users must know they are engaging with AI.
  • Operators must address foreseeable safety risks.
  • Minors must receive enhanced protections.

That degree of convergence suggests organizations should begin treating chatbot compliance as a governance requirement.

Organizations must understand that model procurement is only part of the answer. Product, privacy, legal, trust and safety, as well as engineering teams, all need visibility into how conversational systems are configured, what they retain, how they respond to vulnerable users, and whether they simulate human-like or relationship-based interactions. Increasingly, enforcement scrutinizes how conversational AI behaves, not just what data it processes.

Governance will need to evaluate engagement patterns, memory, emotional framing, and vulnerability-sensitive use cases alongside more traditional privacy, security, and retention controls. States providing a private right of action raise the stakes further. Where litigation exposure exists, chatbot compliance becomes a defensibility issue as much as a regulatory readiness issue.

Analyst: Safayat Moahamad, Research Director – Security & Privacy

More Reading:


If you have a question or would like to receive these monthly briefings via email, submit a request here.