Get a quote

Around the World in Privacy: Eight Regulatory Developments to Watch in 2026

29 September 2026

Natalie Best, Head of Legal

Blog

Data Protection

GDPR

Privacy

Data protection law is moving quickly around the world, with AI and children’s privacy the hot topics this year. Regulators are focusing increasingly on how new technologies use personal data and on stronger protections for children online.

Australia: Children’s Online Privacy Code

The OAIC (Office of the Australian Information Commissioner) is developing a statutory Children’s Online Privacy Code. The consultation has closed and the final Code must be registered by 10 December 2026. It will apply to certain online services likely to be accessed by children and will supplement the Australian Privacy Principles.

Brazil: Children, AI and a stronger privacy regulator

The ANPD’s (Agência Nacional de Proteção de Dados’s) 2026–27 enforcement priorities include children and adolescents online, AI and emerging technologies, data-subject rights and public sector processing. Brazil’s ECA Digital entered into force in March 2026, with the ANPD issuing age assurance guidance and already taking enforcement action

California: Children, social media and AI chatbots

On 10 September 2026, California signed a package of laws strengthening protections for children using social media and AI companion chatbots, including restrictions on addictive features and additional privacy protections.

China: Cross-border transfers getting more detailed

China continues to develop its cross-border personal information regime. In July 2026, the Cyberspace Administration of China (CAC) specifically addressed overseas transfers of recruitment data, saying transfers to overseas headquarters or affiliates must be necessary and limited to what is required. In September, it also clarified how cross-border certification interacts with security-assessment thresholds.

EU/EDPB: Anonymisation and AI web scraping

On 8 July 2026, the EDPB (European Data Protection Board) adopted draft Guidelines 02/2026 on anonymisation and Guidelines 03/2026 on web scraping in the context of generative AI. Both are open for consultation until 30 October 2026. The web scraping guidance addresses GDPR compliance when personal data is scraped for generative AI.

India: DPDP Rules

India notified its Digital Personal Data Protection Rules 2025 on 14 November 2025, giving practical effect to the DPDP Act 2023. The interesting fact is that organisations are now moving from watching the legislation to implementing it. Multinationals that previously treated India mainly as an outsourcing, IT support or service delivery jurisdiction now need to consider it as a separate privacy compliance regime in its own right.

Japan: Major APPI amendments

Japan enacted amendments to its personal information protection legislation in July 2026. The amendment law was promulgated on 17 July 2026, with most provisions due to take effect on a date set by Cabinet Order within two years. The biggest changes are stronger individual rights and enforcement. The reforms introduce greater flexibility for certain lower risk uses of personal information, including some statistical and research related processing, where appropriate safeguards are in place.

UK: Agentic AI and neurotechnology

The ICO (Information Commissioner’s Office) is developing dedicated guidance on agentic AI and on neurotechnology and neurodata. Agentic AI consultation is scheduled for September 2026; neurotechnology consultation is due in October 2026. These are planned guidance projects, not new legal requirements yet.

 

The importance of keeping track of your legal obligations

For businesses, the message is clear: global privacy compliance is becoming more complex and more technology driven. Organisations need to track local developments and make sure new requirements are reflected in products, contracts, systems and governance.

Data protection, delivered by experts
GRC Solutions can support your compliance with whatever privacy laws your organisation is subject to.

Our team is made up of qualified data protection professionals with extensive practical data protection compliance experience.