article thumbnail

Indiana Passes Comprehensive Privacy Statute

Inside Privacy

5 would take effect on January 1, 2026. 5, processors must assist controllers in meeting their obligations, including responding to consumer requests and conducting data protection impact assessments (“DPIAs”). 5 shares similarities with the state privacy laws in Virginia, Connecticut, Colorado, Utah, and most recently Iowa.

article thumbnail

The EU AI Act – Navigating the EU’s Legislative Labyrinth

Debevoise Data Blog

Despite recent challenges in the EU “trilogue negotiations”, proponents still hope to reach a compromise on the key terms of the draft EU AI Act by 6 th December, with a view to passing to the Act in 2024 and most of the provisions becoming effective sometime in 2026. To subscribe to the Data Blog, please click here.

professionals

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Critical Entities Resilience Directive (CER) – broader scope and more stringent obligations

Technology Law Dispatch

The assessment must be completed by 17 January 2026. The Member States will identify the relevant critical entities and notify them within one month of identification. The identification will be based on a risk assessment carried out by the Member States.

article thumbnail

Spain Creates AI Regulator to Enforce the AI Act

Inside Privacy

In recent years, Spain has focused its digital strategy on the implementation of initiatives for the promotion and development of an “inclusive, sustainable, and citizen-centered AI”, one of the key pillars of the 2026 Spanish Digital Agenda , and to this end has developed guidance for companies on the use of AI (see our previous blog post ).

article thumbnail

California’s DELETE Act has come into force: what are the new requirements for data brokers?

Legal IT Group

In addition to maintaining a register of brokers, the CPPA must also develop an ADM by January 1, 2026. Starting August 1, 2026, the broker must have access to the ADM and check it at least once every 45 days. Analyze your personal data collection and processing practices and align your personal data protection practices.

article thumbnail

The EU AI Act: Political Agreement Secured, We Await the Final Text

Debevoise Data Blog

If this timeline is met, the first provisions of the Act to come into force (the prohibition on “unacceptable risk” AI systems) will take effect in late 2024, followed by the requirements related to “high risk” systems in early 2025, and the remaining provisions in 2026. How to prepare.

article thumbnail

National Cybersecurity Strategy (Part 2): The White House Targets Threat Actors and Urges International Partnerships

Debevoise Data Blog

The Cybersecurity Infrastructure Security Agency (“CISA”) recently published its detailed Cybersecurity Strategic Plan for the fiscal years 2024 to 2026, which is intended to align with the National Cybersecurity Strategy. To subscribe to our Data Blog, please click here.