This Privacy Regulation Roundup summarizes the latest major global privacy regulatory developments, announcements, and changes. This report is updated monthly. For each relevant regulatory activity, you can find actionable Info-Tech analyst insights and links to useful Info-Tech research that can assist you with becoming compliant.
One Cyber Incident, Multiple EU Reporting Obligations
Type: Legislation
Enforced: September, 2026
Affected Region: EU
Summary: Beginning September 11, 2026, a single cybersecurity incident may trigger four separate notification obligations in the European Union (EU). This would be by virtue of the Cyber Resilience Act (CRA), NIS2 Directive, EU General Data Protection Regulation (GDPR) and EU Medical Device Regulation (MDR) requirements. Recent guidance from the European Commission (EC) highlights the complexity of determining which obligations apply.
A key challenge of this regulatory regime is highlighted with data centers. As they may be directly regulated under NIS2 while typically acting as processors under the GDPR. Yet remaining outside the CRA and MDR while they may govern downstream customer products and patient safety obligations. This creates a scenario where a data center may be the first organization to identify and describe an incident, while hospitals and medical device manufacturers later submit their own notifications.
A ransomware attack against a data center could simultaneously affect hospital scheduling systems, clinical documentation platforms, and connected medical device platforms. Each of the regulations asks a different question about the same event. NIS2 focuses on compromised network and information systems while GDPR considers whether personal data was affected. CRA considers whether a product's security was compromised whereas MDR considers whether a patient was or could have been harmed.
Analyst Perspective: The introduction of CRA reporting requirements reinforces the need for organizations to establish a coordinated incident notification process that accounts for overlapping regulatory obligations. Organizations should not treat each requirement as an isolated compliance activity. Instead, security, privacy, legal, regulatory, product, and clinical stakeholders should establish a common incident assessment process that identifies whether an event affects network and information systems, personal data, product security, or patient safety. Organizations should also incorporate a regulatory notification annex into relevant hosting and cloud and data-processing agreements to ensure suppliers provide the facts needed to assess applicable reporting obligations within the shortest statutory window.
Finally, organizations should designate a senior individual with authority over the first official account of an incident, ensuring assumptions are clearly identified, timelines are preserved, and subsequent regulatory notifications are based on consistent record. By taking a proactive and structured approach to incident notification, organizations can reduce the risk of missed reporting deadlines, inconsistent regulatory accounts and unintended discrepancies between security, privacy, product, and patient-safety notifications.
Analyst: Ahmad Jowhar, Senior Research Analyst – Security & Privacy
More Reading:
- Source Material: IAPP
- Related Info-Tech Research:
The Growing Gap Between Human Authority and Human Agency
Type: Article
Published: July 2026
Affected Region: USA
Summary: AI governance must expand beyond its traditional focus on regulatory compliance, risk management, controls, and auditability. As AI becomes increasingly embedded in organizational workflows and decision-making, governance must also consider whether people retain meaningful agency, autonomy, and independent judgment. A system can be compliant and efficient while still encouraging users to defer to automated recommendations. Over time, employees may technically retain decision authority but become less willing or able to challenge AI outputs, leaving humans formally accountable while becoming operationally passive.
Organizations may need to associate metrics with human agency. This means assessing whether people can understand and contest AI-supported decisions, whether systems encourage overdependence, whether users retain sufficient context to exercise judgment, and whether meaningful accountability remains with humans. The objective is not to resist automation, but to ensure that increasing automation does not unintentionally diminish human participation and decision-making capacity.
Analyst Perspective: Compliance does not equal control. An organization can have policies, audit trails, and a human approval step while employees increasingly defer to AI recommendations without exercising meaningful judgment. IT leaders should distinguish between having a human in the loop and keeping a human in control. Effective oversight requires people to have the authority, information, and organizational permission to question, override, or stop an AI-driven decision.
Governance should scale with autonomy and consequence. As AI moves from assisting people to recommending decisions and ultimately taking actions, organizations must strengthen decision rights, escalation paths, override mechanisms, and accountability. The goal is not to limit automation, but to ensure organizations do not automate away the human judgment they still depend on.
Analyst: John Donovan, Principal Research Director – Infrastructure and Operations
More Reading:
- Source Material: IAPP
- Related Info-Tech Research:
The CISO and Privacy Requirements in AI Controls
Type: Article
Published: September 2026
Affected Region: All Regions
Summary: Enterprise AI is drawing Chief Information Security Officers (CISOs) further into privacy operations. It introduces new paths through which information can be accessed, combined, transformed, used and retained. Connected information systems and automated actions can extend the exposure beyond the AI interface itself.
Privacy principles such as data minimization, purpose limitation, access restriction, and retention rely on capabilities managed by security and technology teams. As a result, CISO’s contribution to privacy becomes particularly important where outcomes depend on technical architecture and security controls.
Both privacy and security are concerned about third parties. That includes vendor use of enterprise data for model training, retention of prompts and outputs, audit evidence, and the treatment of personal or confidential information. Effective governance therefore requires coordination among privacy, legal, security, technology, data, and business teams. As such, the CISO’s expanded role complements rather than replaces the privacy function.
Analyst Perspective: Security policies seldom provide protection if they are not reflected in architecture, configuration, monitoring, and response processes. While legal and compliance teams usually establish privacy requirements in policies, based on applicable obligations, the CISO is increasingly responsible for overseeing their translation into technical controls that can be enforced and monitored.
Control assurance, however, should be sufficiently independent from implementation. A three lines of defense model with a qualified function to assess whether controls are appropriately designed, correctly implemented, and operating effectively have proven more effective in regulated sectors, although smaller organizations would need a more nuanced approach.
Organizations, nonetheless, must be ready to demonstrate that any existing principles and policies are actually reflected in system architecture, configuration, vendor governance, and incident management. To that end, CISOs are ideally positioned to pair with privacy in ensuring requirements are consistently applied, monitored, and tested across enterprise AI.
Analyst: Safayat Moahamad, Research Director – Security & Privacy
More Reading:
- Source Material: IAPP
- Related Info-Tech Research:
If you have a question or would like to receive these monthly briefings via email, submit a request here.