Earlier this year, we published our Global Data Privacy Laws: The Current Environment and What to Look for in 2026, highlighting the key legislative developments organizations should be watching throughout the year. Now, at the year’s midpoint, it’s a good time to revisit the evolving privacy landscape and examine what’s changed, what’s taken effect, and what organizations should continue monitoring during the second half of 2026.
As organizations collect increasing volumes of personal data to improve services, personalize experiences, and fuel AI initiatives, compliance with global data privacy laws has become significantly more complex. In 2026, lawmakers around the world are revising current laws and introducing new requirements to govern AI, cross-border data transfers, children’s privacy, and consumer rights.
For organizations operating across multiple jurisdictions, staying abreast of these changes is critical, especially with the drive toward greater adoption of AI and Generative AI. Here are some of the most significant global data privacy developments to watch in 2026.
United States
The U.S. continues to have no federal law governing data privacy. As a result, many individual states have taken on a broader responsibility for protecting personal data. According to multiple publicly available trackers from IAPP, as of June 2026, comprehensive data privacy laws have been passed in 23 states. Four of those states — Alabama, Louisiana, Oklahoma, and Vermont—have passed privacy legislation that will become enforceable in the next two years.
Takeaway: Organizations operating nationally will continue to face a growing patchwork of state privacy requirements and a growing complexity in AI laws, making consistent governance programs more essential than ever.
European Union (EU)
As of May 24, 2026, it has been 10 years since the General Data Protection Regulation (GDPR) was adopted, marking a decade of reshaping global data privacy. During the remainder of 2026, the EU is focusing on simplifying enforcement to reduce administrative burdens, updating privacy laws, and AI governance.
The EU Council and Parliament have agreed on timeline extensions for the EU AI Act, initially set to take full effect on August 2, 2026. Deadlines for deploying “high-risk” AI systems, e.g., those used in HR and employment, have been pushed back to December 2, 2027. Existing models now have until December 2, 2026, to comply with watermarking and labeling requirements for AI-generated content.
Takeaway: While some AI deadlines have been extended, organizations should view the additional time as an opportunity to strengthen governance, not delay compliance efforts.
China
The amended Cybersecurity Law of China (CSL) became law on January 1, 2026. The first major changes to the law since it took effect in 2017, these amendments set the penalties for breaches of the CSL, expand the Chinese government’s power to enforce against activities jeopardizing country’s cybersecurity, and specify certain policy and regulatory goals related to developing and applying AI. The protection of minors’ personal information has also been a focus, following the directive issued by the Cyberspace Administration of China that requires companies that collect minors’ personal information to complete compliance audits and submit findings to their local CAC office.
Takeaway: Organizations doing business in China should expect continued government oversight of cybersecurity, AI deployment, and data localization.
India
The Digital Personal Data Protection (DPDP) Act, India’s foremost data protection law enacted in 2023, is being rolled out, with critical phases being enforced in 2026. Enacted in 2023, the DPDP protects digital personal data and gives individuals the right to consent, access, and correct their data. It also contains strict provisions on cross-border data transfers and the processing of children’s data. The Consent Manager’s Framework will become operational on November 13, 2026, allowing organizations to register as third-party intermediaries enabling users to securely manage, review, and revoke their consent across platforms. The full compliance regime takes effect on May 13, 2027.
Takeaway: Companies collecting data from consumers in India should prepare for more robust consent management and expanded compliance obligations over the next year.
Brazil
The Brazilian General Data Protection Law (LGPD in Portuguese) took effect in 2020, unifying 40 existing laws into a single data protection framework. Since that time, data privacy updates in Brazil have focused on international data transfer, child safety, and AI. As of 2025, the Brazilian Data Protection Authority became the Brazilian Data Protection Agency (ANPD), a national regulatory body with technical, administrative, and financial independence. The ANPD is responsible for enforcing the Brazilian Minors’ Online Safety Law (ECA Digital), enacted in September 2025 to protect children’s rights online.
Takeaway: The strengthened independence of Brazil’s privacy regulator signals the country’s continued investment in enforcement, particularly regarding children’s online privacy.
Canada
On June 15, 2026, the Government of Canada introduced the Protecting Privacy and Consumer Data Act (PPCDA) amending the Personal Information Protection and Electronic Documents Act (PIPEDA) to provide greater regulation over AI and protect the data of minors. If passed, the PPCDA would be the most significant overhaul of Canada’s privacy laws in more than 25 years. It would help mitigate the risk associated with digital technology, establish strict new rules for how businesses collect, use, and disclose personal information, and modernize and replace parts of the PIPEDA.
Takeaway: Although the legislation has not yet passed, businesses should begin evaluating how the PPCDA might affect existing compliance programs.
Data Protection: A Global Priority
Although privacy laws continue to evolve independently across jurisdictions, a clear pattern is emerging. Regulators are demanding greater transparency, stronger governance over AI, expanded consumer rights, and more accountability for companies handling personal information. Organizations that build flexible, risk-based privacy programs will be better positioned to adapt as new regulations continue to arise.
Are you ready to learn more about 2026 updates to global privacy law and how they might impact your organization? Contact us at and schedule a consultation today.


