Tuesday, August 4, 2026 · Privacy & Personal Data Protection
Today's Top Story
California's DELETE Act Goes Live — Data Brokers Face $200/Day Penalties
As of August 1, California's Delete Request and Opt-Out Platform (DROP) is fully operational. Data brokers must now process consumer deletion requests submitted through the centralized system within 45 days of retrieval — and must check DROP at least every 45 days. Failure to act on a request carries penalties of $200 per request per day.
DROP is the first mechanism of its kind: a single consumer request triggers deletion obligations across every registered data broker. If your organization buys, sells, or shares consumer data and meets California's data-broker definition, compliance is no longer optional — it's overdue.
What to do: Confirm your DROP account is active, configure manual or API-based retrieval, and assign an owner for the 45-day processing cycle. Map all personal data — including inferences — subject to deletion.
Also Today
EDPB Breach Notification Template — Consultation Closes Tomorrow
The EDPB's standardized Article 33 breach notification template consultation closes August 5. The template will harmonize breach reporting across all EU supervisory authorities with predefined fields and an IT tool. If you haven't submitted feedback, today is your last chance.
Act now: Review the template against your current breach-notification workflows and submit comments via the EDPB consultation page.
CNIL Tracking-Pixel Enforcement Is Live
France's CNIL now treats email tracking pixels as requiring prior consent — the three-month grace period expired July 14. Open-tracking, profiling, and advertising pixels in emails to French recipients must be covered by a compliant consent mechanism. No further transition period.
Audit now: Review ESP/CRM pixel usage for French-audience campaigns and implement consent capture. CNIL
South Korea's 10%-of-Revenue Fines: 38 Days Out
The PIPA overhaul takes effect September 11, 2026, introducing administrative fines up to 10% of total revenue for high-severity breaches, mandatory CEO/CPO accountability, and ISMS-P certification triggers. The enforcement decree operationalizing these provisions was proposed June 2.
Prepare now: Map Korean personal-data processing, designate a CPO per the new requirements, and assess ISMS-P certification obligations. Hunton analysis
Deadline Alert
Date | What | Action |
|---|---|---|
Aug 5 | EDPB breach template consultation closes | Submit comments today |
Sep 11 | South Korea PIPA overhaul effective | Complete readiness assessment |
Oct 30 | EDPB anonymisation + GenAI scraping consultation closes | File comments |
Nov 13 | India DPDPA consent-manager provisions effective | Integrate with consent managers |
Dec 10 | Australia Children's Online Privacy Code in force | Re-engineer minor consent flows |
One Thing to Do Today
Check your DROP account. If you're a registered California data broker and haven't logged in to the platform yet, do it today — the $200/day clock is already ticking on unprocessed requests.
Cross-Cutting: AI Governance
As of August 2, the EU AI Act's Article 50 transparency obligations are live. Chatbots, deepfake generators, and emotion-recognition systems must disclose AI involvement to users. Fines: up to €15M or 3% of worldwide turnover. This directly intersects with privacy notice and consent practices. Cooley briefing
Tomorrow's focus: AI Governance — EU AI Act Article 50 enforcement landscape + EDPB GenAI web-scraping guidelines.
CyberEyeQ — Actionable Regulatory Intelligence
Questions? [email protected] · Upgrade to CyberEyeQ Pro