Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Tuesday, June 16, 2026 · 6:48 PM EDT

Key developments

TIME

UK plans under-16 social media restrictions

The UK government announced plans to restrict under-16s from major social media platforms, with initial regulations expected before year-end and implementation planned for spring 2027. Time's Callum Sutherland and IAPP's Lexie White reported the framework is expected to cover Instagram, YouTube, TikTok, Snapchat, Facebook and X, with exemptions including YouTube Kids, Google Classroom, WhatsApp and Signal. Ofcom would oversee age assurance, while explicit AI romantic-companion chatbots would face an 18-plus restriction.

Why it matters

The proposal would make age verification a central privacy and platform-compliance issue for UK children’s online services.

Sources & driving stories

TIME · Callum Sutherland

Time coverage

IAPP · Lexie White

IAPP coverage
IAPP

Canada introduces sweeping private-sector privacy bill

Canada introduced Bill C-36, the Protecting Privacy and Consumer Data Act, to overhaul private-sector privacy enforcement. IAPP's Lexie White reported the bill would recognize privacy as a fundamental right, strengthen consent, expand deletion rights, treat children’s personal information as sensitive, require privacy impact assessments and address risks tied to AI deepfakes and automated decisions. It would also create the Digital Safety and Data Protection Commission of Canada with binding enforcement powers and penalties up to CAD 10 million or 3% of global revenue, or CAD 25 million or 5% for serious offences.

Why it matters

The bill would materially reshape Canadian privacy enforcement by moving private-sector complaints from the OPC to a new penalty-capable regulator.

Sources & driving stories

IAPP · Lexie White

IAPP coverage
CLAIMS JOURNAL

Google sues alleged AI-assisted smishing operation

Google filed a lawsuit against the alleged Outsider Enterprise cybercrime operation, which Claims Journal reported is suspected of sending 2.5 million fraudulent Android text messages over two weeks in May. Google alleged the group coordinated through Telegram, used fake websites posing as trusted brands and encouraged use of Gemini to generate malicious website code. The complaint cited 9,000 fake websites and more than 1 million fraudulent URLs, with Google saying it worked with AT&T, T-Mobile US and Verizon to block the texts.

Why it matters

The case gives a concrete example of generative AI being folded into large-scale credential and personal-data theft infrastructure.

Sources & driving stories

Worth noting

WORTH NOTING

EU approves AI Act changes

The European Parliament approved amendments delaying some AI Act obligations while banning AI systems that generate CSAM or nonconsensual intimate depictions of identifiable people.

WORTH NOTING

Novo Nordisk faces ransom claim

Insurance Business's Matthew Sellers reported FulcrumSec threatened to sell more than 1 TB of allegedly stolen Novo Nordisk data after a claimed $25 million ransom demand, including alleged clinical trial, employee, physician and drug information.

WORTH NOTING

Maine breach portal hit by hoaxes

TechRadar reported Maine’s Attorney General temporarily disabled public access to its breach notification portal after fake disclosures impersonating Discord and VRChat were submitted and published.

Still unclear

OPEN QUESTION

Can child age checks avoid data overcollection?

The UK proposal depends on robust age assurance, but age verification systems can create new identity, tracking and circumvention risks, including VPN-driven avoidance.

OPEN QUESTION

How verifiable is AI-enabled privacy abuse?

Google’s lawsuit, the EU nudifier ban and voice-cloning research all point to a growing enforcement problem: proving when AI systems generated, amplified or personalized harmful misuse of personal data.