This website uses cookies

Read our Privacy policy and Terms of use for more information.

One obligation switched on this week and two more came into view. Today, China's Network Data Security Risk Assessment Measures (CAC/MIIT/MPS Order No. 24) enter into force — handlers of "important data" now owe an annual, documented risk assessment and a report filed with their sector regulator within 20 working days. Three weeks out, 11 September has become a double gate: the EU Cyber Resilience Act's Article 14 vulnerability-and-incident reporting duties begin, and South Korea's PIPA overhaul takes effect with a punitive fine track reaching 10% of turnover and personal responsibility pinned on the CEO. Between now and then, California's AB 1651 sits on the Governor's desk with its clock expiring around 22 August, the CFTC proposed to ease fund-adviser registration, and California's privacy regulator brought its first data-broker fines under both the CCPA and the Delete Act. Abroad, France's under-15 social-media ban was struck down. Here is the week that matters — and what to do about it.

At a Glance

  • China's data-risk clock starts. Order No. 24 is in force today; "important data" handlers must run an annual assessment and file within 20 working days.

  • Two regimes land 11 September. EU CRA Article 14 reporting and Korea's PIPA overhaul both take effect the same day, 22 days out.

  • CalPrivacy fines two data brokers. First actions under both the CCPA and the Delete Act — $116,490 for LocateSmarter, $52,400 for Cybba.

  • AI bill on Newsom's desk. AB 1651's gubernatorial clock expires ~22 August; it would impose an AI-disclosure duty on the State Bar from 2028.

  • France's teen ban struck down. The Conseil constitutionnel voided the operative under-15 ban on 14 August; the 2026–27 start dates are void.

  • CFTC eases fund-adviser registration. A new NPRM proposes CPO/CTA exemptions and doubles the small-pool threshold to $800,000. (CFTC Release 9284-26)

Critical Actions (next 10 days)

1. China Order No. 24 — determine your "important data" exposure now (in force today).

The tri-department Network Data Security Risk Assessment Measures (CAC/MIIT/MPS, issued 18 June 2026) take legal effect today, 20 August. Handlers of "important data" must run a documented annual risk assessment (plus a special assessment on any significant posture change), file the report with their sector regulator — or, absent one, the provincial/national cyberspace authority — within 20 working days, and retain it at least three years. The CAC published an implementation Q&A naming accredited assessment bodies and the filing channel. Article 19 allows a suspension order where identified risks go unremediated.

Do this: confirm whether your China environments handle "important data," stand up an annual assessment methodology, and identify your filing channel by 19 September.

2. AB 1651 (California) — watch for enactment on or about 22 August (2 days).

AB 1651 (Dixon), "State Bar of California: artificial intelligence," was presented to the Governor on 10 August; the twelve-day gubernatorial clock expires ~22 August, and without action it becomes law. From 1 January 2028 it would require the State Bar to disclose AI-generated content used in developing or administering the bar exam and study materials — a June amendment narrowed the duty to content developed by or at the State Bar's explicit direction, and human revision does not extinguish it. The floor-amendment cliff (21 August) also freezes SB 867 and SB 813 text.

Do this: check for signature, veto or default enactment on/about 22 August; if enacted, map the 2028 State Bar AI-disclosure duty.

3. Two financial comment windows close now — UK PSR CoP (today) and US stablecoin CIP (tomorrow).

The UK PSR's Confirmation of Payee — Specific Direction 17 (CP26/2) consultation closes today, 20 August. The US stablecoin-issuer Customer Identification Program (CIP) proposed rule closes 21 August.

Do this: file both comment letters before the windows close if either regime touches your payments or stablecoin operations.

Enforcement Watch

California's privacy regulator opened a new front this week — the first data-broker enforcement actions brought under both the CCPA and the Delete Act, two decisions in three days.

LocateSmarter LLC — $116,490 (11 August). CalPrivacy ordered the Iowa-based data broker to pay $116,490 for failing to register by the 31 January 2026 deadline and, separately, for requiring consumers to submit the last four digits of their Social Security number before exercising opt-out rights — treated as a CCPA data-minimization violation applied to the opt-out mechanism itself. It is CalPrivacy's first action to arise under both statutes.

Cybba, Inc. — $52,400 (13 August). The Boston-based firm was ordered to pay $52,400 for failing to register, and required to publish privacy-rights metrics and process deletion requests through the DROP platform going forward.

Also this week, a multistate COPPA trial against Meta opened (18 August), with states alleging violations of the children's-data rule — litigation to watch rather than a settled penalty. The message: registration is table stakes, and the friction you build into a consumer opt-out is now itself an enforcement target.

Deadline Watch (next 60 days)

Date

Days

Domain

Item

20 Aug

0

China / Cyber / Privacy / Cloud

China Order No. 24 in force — annual risk assessment; 20-working-day filing

20 Aug

0

Financial

UK PSR Confirmation of Payee (SD17 / CP26/2) — comments close

21 Aug

1

Financial

US stablecoin-issuer CIP proposed rule — comments close

21 Aug

1

AI Gov

California floor-amendment cliff — SB 867 / SB 813 text freezes

22 Aug

2

AI Gov

AB 1651 (CA) gubernatorial clock expires — sign, veto, or default enactment

25 Aug

5

Age Verif

Australia Senate committee report on SMMA enforcement bill (A$99M penalty)

28 Aug

8

China

Anti-Cyber Violence Law draft — comments close

1 Sep

12

China / Privacy

Small PI Processor simplified measures (Order No. 25) effective

7 Sep

18

China / Privacy

Large PI Processor consolidated draft (>10M individuals) — comments close

8 Sep

19

Financial

Fed AML/CFT program NPRM (Reg H, Docket R-1835) — comments close

8 Sep

19

Cloud

FedRAMP RFC-0032 "Offerings By Government" — comments close

11 Sep

22

Cyber

EU CRA Article 14 vulnerability/incident reporting begins (24h/72h/14d; ENISA SRP)

11 Sep

22

Privacy

South Korea PIPA overhaul effective (up to 10% turnover fines; CEO liability)

16 Sep

27

AI Gov

NIST AI 300-1 initial public draft — comments close

16 Sep

27

Healthcare

FDA ISH companion-diagnostic reclassification effective

21 Sep

32

AI Gov

Education Dept accreditation NPRM (AI-and-teaching) — comments close

~1 Oct

42

China

MPS Order No. 176 cyberspace inspection measures effective (Order 151 repealed)

~2 Oct

~43

Financial

CFTC Part 4 CPO/CTA registration NPRM — comments close (verify FR pub date)

19 Oct

60

Financial

Treasury GENIUS Act section-3 NPRM — comments close

Around the World

🇫🇷 France — The Conseil constitutionnel struck down the operative under-15 social-media ban (Article 1) in decision No. 2026-911 DC of 14 August 2026. The previously announced start dates — 1 September 2026 and 1 January 2027 — are void. PM Sébastien Lecornu has been tasked with a durable rewrite targeted before spring 2027. Treat the ban as dead pending new legislation.

🇨🇳 China — Beyond Order No. 24, Beijing ran a full regulatory sprint: the Anti-Cyber Violence Law draft closes for comment 28 August; Small PI Processor simplified measures (Order No. 25) take effect 1 September; a consolidated Large PI Processor draft — defining a "large" processor at more than 10 million individuals — closes for comment 7 September; and MPS Order No. 176 takes effect 1 October, repealing Order 151.

🇦🇺 Australia — The Senate committee report on the Strengthening Enforcement for the Social Media Minimum Age Bill 2026 is due 25 August. The bill would double the maximum civil penalty to A$99 million and extend eSafety's powers to age-assurance providers and app stores — widening exposure to the age-verification supply chain.

🇺🇸 United States — The Department of Education published an 82-page accreditation-recognition NPRM (34 CFR part 602) whose preamble says AI must not supplant teaching and instruction. Comments close 21 September. Caveat: whether "artificial intelligence" appears in the operative text or only the preamble is unconfirmed — retrieve the full text first.

Deep Dive 1 — South Korea's PIPA Overhaul: 10% Turnover Fines and a Named CEO

Privacy · South Korea · CRITICAL

On 11 September 2026 South Korea's amended Personal Information Protection Act — signed 10 March 2026 — takes effect, and it changes the shape of privacy risk for anyone processing Korean personal data. The headline is the money: alongside the existing baseline penalty of up to 3% of relevant revenue, the amendment adds a punitive fine track reaching 10% of a company's total annual turnover. That upper band is reserved for the worst conduct — intentional or grossly negligent violations repeated within three years, breaches affecting ten million or more individuals, or failure to comply with a PIPC corrective order where a breach results — but its existence resets the ceiling that Korean data risk is measured against.

The structural change is quieter and more demanding. The amended Act names the business owner or representative as the party ultimately responsible for the processing and protection of personal information — pinning accountability at the top. It also tightens the machinery: designated large-scale controllers must obtain board approval and report to the PIPC when appointing their Chief Privacy Officer, and breach-notification timelines move earlier. (A separate strand making ISMS-P certification mandatory for qualifying private entities follows from 1 July 2027.) Here is what organisations need to do before the duty binds...

🔒 The full playbook — structuring CPO board-approval governance, where the 10%-turnover exposure attaches, and how to sequence CPO appointment, PIPC reporting and breach-notification readiness before 11 September — continues for CyberEyeQ Pro subscribers. Talk to us →

Pro recommendations:

  1. (Privacy / DPO) Confirm whether your Korean entity is a designated large-scale controller and, if so, calendar board approval and PIPC reporting for the CPO appointment before 11 September.

  2. (Legal / Compliance) Re-map worst-case penalty exposure against the new 10%-of-turnover band and document controls that keep conduct out of the "intentional / grossly negligent / repeated" trigger zone.

  3. (Board / Executive) Brief the business owner or representative on their named ultimate-responsibility status, and record the governance evidence that discharges it.

  4. (Security / IR) Tighten breach-notification runbooks to the earlier timeline and begin ISMS-P certification readiness ahead of its 1 July 2027 mandate.

Deep Dive 2 — The EU Cyber Resilience Act's 24-Hour Clock Starts 11 September

Cybersecurity · European Union · CRITICAL

Most of the Cyber Resilience Act's obligations do not bite until 2027, but one does much sooner. From 11 September 2026, manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents through ENISA's new Single Reporting Platform (SRP) — and the clock is short. An early warning is due within 24 hours of becoming aware, a full technical notification within 72 hours, and a final report within 14 days of a corrective measure (one month for severe incidents). The notification routes to the CSIRT of the manufacturer's main establishment, with the information shared simultaneously to ENISA through a single submission.

The compliance problem is operational, not legal. A 24-hour early-warning duty means the decision to report has to be made before an investigation is complete — the awareness trigger, not root-cause certainty, starts the clock — so an organisation needs a pre-agreed threshold for "actively exploited" and "severe," a named decision-owner, and a tested path into the SRP. The routing rule adds a second requirement: manufacturers must know which national CSIRT corresponds to their main establishment. The platform is slated to be operational by the 11 September start date, with testing under way, so access should be validated rather than assumed. What manufacturers should stand up now...

🔒 The Pro edition maps a 24h/72h/14-day reporting runbook to the awareness trigger, sets the "actively exploited / severe" thresholds that decide when the clock starts, and walks the main-establishment CSIRT determination. Talk to us →

Pro recommendations:

  1. (Security / PSIRT) Build the 24h/72h/14-day CRA reporting runbook against the awareness trigger, with pre-agreed "actively exploited" and "severe incident" thresholds and a named decision-owner.

  2. (Legal / Regulatory) Determine your main establishment in the EU and the corresponding national CSIRT now, so routing is settled before an incident forces the question.

  3. (IT / Compliance) Register for and test access to the ENISA Single Reporting Platform as soon as it is available.

  4. (Product) Inventory which products qualify as "products with digital elements" in scope of the CRA and align disclosure timing with the new reporting duty.

What to Do This Week

  1. Confirm your China "important data" exposure — determine scope, stand up the annual assessment methodology, and identify the sector-regulator filing channel now that Order No. 24 is in force. (Free)

  2. Watch AB 1651's enactment — check for signature/veto/default on ~22 August, and if enacted map the 2028 State Bar AI-disclosure duty. (Free)

  3. File the imminent financial comments — UK PSR Confirmation of Payee closes today, the US stablecoin-issuer CIP rule closes tomorrow. (Free)

🔒 Two more priority actions for CyberEyeQ Pro subscribers — the Korea PIPA CPO-governance build and the EU CRA reporting runbook, both with owners and timelines. Talk to us →

  1. Build the Korea PIPA CPO-governance package — board approval and PIPC reporting for the CPO appointment, plus the 10%-turnover exposure re-map, before 11 September. (Pro)

  2. Stand up the EU CRA reporting runbook — the 24h/72h/14-day flow, main-establishment CSIRT determination and ENISA SRP access, before 11 September. (Pro)

CyberEyeQ — Actionable Regulatory Intelligence. Questions or corrections: [email protected]. Compiled from primary regulatory sources; provided for information only and not legal advice. Verify every item against the issuing authority before acting.