Data protection digest 18 Jun – 2 Jul 2026: UK DUAA right to complain takes effect & US data transfers latest

· Source: TechGDPR · Field: Legal & Regulatory — Compliance & Risk Management, Regulatory Affairs & Government Relations · Depth: Intermediate, medium

Summary

The "Data protection digest 18 Jun – 2 Jul 2026" details significant global privacy developments. Privacy group NOYB is challenging the EU-US Data Privacy Framework (DPF) due to a US Supreme Court ruling affecting the independence of US oversight bodies like the FTC, impacting data transfers. The UK's Data Use and Access Act 2025 (DUAA) is now active, requiring organizations to implement new data protection complaint handling procedures. The European Data Protection Board (EDPB) launched a tool for reporting GDPR interpretation inconsistencies and updated its case digest on rights to object and erasure. In the US, four new comprehensive state privacy laws in Oklahoma, Louisiana, Alabama, and Vermont bring the total to 23, emphasizing impact assessments and automated decision-making disclosures. Regulators also issued guidance for tourist accommodations, EdTech, and video games. Fines included Emirates (€180,000) for inadequate health data transparency and KRA Consultancy Ltd (£300,000) for 5.5 million unlawful spam texts. Emerging privacy concerns in extended reality and neurodata processing are also under review.

Key takeaway

For Legal Professionals and Directors of AI/ML managing international data transfers, the EU-US Data Privacy Framework's instability demands immediate attention. You must re-evaluate your reliance on US oversight bodies and conduct thorough transfer impact assessments, considering evolving US legal interpretations. Proactively review your data processing activities, especially those involving automated decision-making and sensitive data. Ensure compliance with new state laws and emerging guidance on neurodata and extended reality applications.

Key insights

Global data protection frameworks face increasing legal challenges and regulatory scrutiny, demanding robust compliance across diverse sectors.

Principles

Method

Organizations must implement multi-factor authentication for privileged users, restrict access to authorized personnel, and enforce strong password policies to prevent data breaches. Regularly update plugins and themes.

In practice

Topics

Best for: CTO, VP of Engineering/Data, Executive, Legal Professional, Consultant, Director of AI/ML

Related on AIssential

Open in AIssential →

Editorial summary, takeaway, and curation by AIssential. Original article published by TechGDPR.