Data protection law is moving quickly around the world, with AI and children’s privacy the hot topics this year. Regulators are focusing increasingly on how new technologies use personal data and on stronger protections for children online.
Australia: Children’s Online Privacy Code
The OAIC (Office of the Australian Information Commissioner) is developing a statutory Children’s Online Privacy Code. The consultation has closed and the final Code must be registered by 10 December 2026. It will apply to certain online services likely to be accessed by children and will supplement the Australian Privacy Principles.
Brazil: Children, AI and a stronger privacy regulator
The ANPD’s (Agência Nacional de Proteção de Dados’s) 2026–27 enforcement priorities include children and adolescents online, AI and emerging technologies, data-subject rights and public sector processing. Brazil’s ECA Digital entered into force in March 2026, with the ANPD issuing age assurance guidance and already taking enforcement action
California: Children, social media and AI chatbots
On 10 September 2026, California signed a package of laws strengthening protections for children using social media and AI companion chatbots, including restrictions on addictive features and additional privacy protections.
China: Cross-border transfers getting more detailed
China continues to develop its cross-border personal information regime. In July 2026, the Cyberspace Administration of China (CAC) specifically addressed overseas transfers of recruitment data, saying transfers to overseas headquarters or affiliates must be necessary and limited to what is required. In September, it also clarified how cross-border certification interacts with security-assessment thresholds.
EU/EDPB: Anonymisation and AI web scraping
On 8 July 2026, the EDPB (European Data Protection Board) adopted draft Guidelines 02/2026 on anonymisation and Guidelines 03/2026 on web scraping in the context of generative AI. Both are open for consultation until 30 October 2026. The web scraping guidance addresses GDPR compliance when personal data is scraped for generative AI.
India: DPDP Rules
India notified its Digital Personal Data Protection Rules 2025 on 14 November 2025, giving practical effect to the DPDP Act 2023. The interesting fact is that organisations are now moving from watching the legislation to implementing it. Multinationals that previously treated India mainly as an outsourcing, IT support or service delivery jurisdiction now need to consider it as a separate privacy compliance regime in its own right.
Japan: Major APPI amendments
Japan enacted amendments to its personal information protection legislation in July 2026. The amendment law was promulgated on 17 July 2026, with most provisions due to take effect on a date set by Cabinet Order within two years. The biggest changes are stronger individual rights and enforcement. The reforms introduce greater flexibility for certain lower risk uses of personal information, including some statistical and research related processing, where appropriate safeguards are in place.
UK: Agentic AI and neurotechnology
The ICO (Information Commissioner’s Office) is developing dedicated guidance on agentic AI and on neurotechnology and neurodata. Agentic AI consultation is scheduled for September 2026; neurotechnology consultation is due in October 2026. These are planned guidance projects, not new legal requirements yet.
The importance of keeping track of your legal obligations
For businesses, the message is clear: global privacy compliance is becoming more complex and more technology driven. Organisations need to track local developments and make sure new requirements are reflected in products, contracts, systems and governance.