On September 8, 2026, Kenya’s Office of the Data Protection Commissioner (“ODPC”) published new Guidance Notes for Cross-border Data Transfers (“Guidance”), providing organizations with more detailed guidance on the application of Kenya’s rules governing transfers of personal data outside the
Inside Privacy
Updates on developments in data privacy and cybersecurity
Inside Privacy, published by Covington & Burling LLP, focuses on legal developments and regulatory issues related to data privacy and cybersecurity. The blog covers topics such as GDPR enforcement actions, data breach investigations, privacy compliance strategies, and the intersection of privacy law with emerging technologies like artificial intelligence. It also addresses regulatory updates from authorities worldwide, including the European Commission and national data protection agencies. The blog provides analysis of privacy-related litigation, enforcement trends, and guidance on managing privacy risks in various sectors, including technology, healthcare, and advertising.
California Legislature Advances AI Employment Bills
At the end of August, the California legislature passed three bills that would regulate the use of AI in the employment context. These bills are now on Governor Newsom’s desk, and he has until September 30 to sign or veto.…
Horizon Scan: Children’s Online Safety and Privacy (EU and Beyond)
In recent months, children’s online safety and privacy have moved to the top of the EU’s digital agenda. The European Commission is expected to outline its proposal on minors’ access to social media this week, a potentially significant development that…
California Legislature Passes CIPA Pen Register Reform Bill and Sends It to Governor
On August 28, 2026, the California Legislature passed SB 690, a significant bill aimed at curbing the flood of demand letters and lawsuits asserting “pen register” claims under the California Invasion of Privacy Act (“CIPA”). If enacted, the bill…
White House Releases National Security Presidential Memorandum on Expanding Capabilities to Combat Transnational Cyber-Enabled Crime
On August 12, 2026, the Administration published a National Security Presidential Memorandum (“NSPM”) (“Expanding Capabilities to Combat Transnational Cyber-Enabled Crime”) that signals the Administration’s focus on private-sector participation in offensive cyber operations by establishing a federally supervised program to enable…
ADMT Law Round-Up: What Employers Need to Know About Recent ADMT Laws
Employers increasingly rely on automated tools to help make decisions concerning hiring, promotion, discipline, and termination. In response, state legislatures and agencies have begun to regulate uses of these technologies, often referred to as automated decision-making technology (“ADMT”). These laws…
French Constitutional Council Strikes Down Under-15 Social Media Ban
On August 14, 2026, the French Constitutional Council (the “Constitutional Council”) struck down Article 1 of France’s Act to protect minors from the risks posed by the use of social media (the “Act”), which would have barred minors under the…
French CNIL Publishes Note on Agentic AI and Data Protection
On July 20, 2026, the French data protection authority (the Commission Nationale de l’Informatique et des Libertés, “CNIL”) published a joint exploratory note with the French AI and Digital Council (“CIANum”) on the data protection implications of agentic AI (the…
Illinois Expands Genetic Privacy Law to Biomarkers
The Illinois Governor recently signed SB 2886, which expands the scope of the state’s Genetic Information Privacy Act (“GIPA”) to include “biomarker testing” and “biomarker.” GIPA currently regulates the collection, use, and disclosure of genetic testing information.
The bill…
New York Publishes Final SAFE For Kids Act Rules
On July 28, 2026, the New York Office of the Attorney General released final rules (the “Rules”) implementing the Stop Addictive Feeds Exploitation (SAFE) for Kids Act, which goes into effect on January 25, 2027.
The SAFE for Kids Act…