This website uses cookies

Read our Privacy policy and Terms of use for more information.

Stop typing what you could say in 10 seconds.

Wispr Flow turns your voice into clean, professional text inside any app. Emails, Slack, client updates — speak once, send without editing. 4x faster than typing.

CyberEyeQ Daily

Actionable Regulatory Intelligence

Tuesday, 11 August 2026  ·  Privacy & Personal Data Protection

Today's Top Story

California SB 435 Heads to Appropriations With CPPA Backing

California's SB 435 — the bill that would strip the “publicly available” carve-out from the CCPA's sensitive-personal-information definitions — clears its next hurdle on Wednesday, 13 August when the Assembly Appropriations Committee takes it up. The bill matters because the current exemption lets data brokers and AI-training pipelines treat social security numbers, immigration status, sexual orientation, genetic data, and precise geolocation as unprotected once they appear in government records or media.

At its 6–7 August board meeting, the CPPA authorized an agency position on SB 435, signalling that California's privacy regulator wants the loophole closed. If the bill survives Appropriations, it moves to the Assembly floor before the 31 August session deadline.

What to do: If your data inventory relies on the “publicly available” exception for any category of sensitive PI, start mapping which data streams would lose that exemption. File any Appropriations Committee comments before Wednesday.

Also Today

South Korea's PIPA overhaul enters the 30-day countdown. The most consequential Asian privacy reform of 2026 — signed 10 March, effective 11 September — introduces a punitive fine ceiling of up to 10% of total annual turnover for intentional or grossly negligent violations and makes the CEO personally liable for systemic compliance failures. Companies processing Korean residents' data should complete a gap assessment against the new requirements before the enforcement date. IAPP coverage

EDPB anonymisation and GenAI web-scraping guidelines open for comment. The Board's 8 July plenary produced Guidelines 02/2026 (anonymisation) and 03/2026 (web scraping for generative AI). The anonymisation text sets a three-criteria test — no record isolation, no linkage, no inference. The web-scraping text states that public visibility is not consent and that special-category scraping is in principle prohibited. Consultation closes 30 October 2026. Re-test anonymisation pipelines and inventory any AI-training datasets sourced by scraping.

California DROP deletion duty is now live. Since 1 August, registered data brokers must access the CPPA's Delete Request and Opt-out Platform at least every 45 days, process verified deletion requests within 45 days, and report status back — or face fines of $200 per request per day of non-compliance. Confirm your DROP portal credentials and first-retrieval schedule now.

Deadline Alert

13 August 2026 (2 days) — SB 435 Assembly Appropriations Committee hearing.

11 September 2026 (31 days) — South Korea PIPA overhaul takes effect.

30 October 2026 (80 days) — EDPB anonymisation and web-scraping guidelines consultation closes.

One Thing to Do Today

Pull your data inventory and flag every field that relies on the CCPA “publicly available” exception — SB 435 could eliminate that safe harbour within weeks, and the CPPA is now on record supporting it.

Next Briefing: Wednesday brings AI Governance & Regulation.

CyberEyeQ

Actionable Regulatory Intelligence