Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Thursday, July 9, 2026 · 6:49 PM EDT

Key developments

IAPP

FTC removal ruling unsettles EU-U.S. transfers

The U.S. Supreme Court’s 29 June decision in Trump v. Slaughter allows the president to remove FTC commissioners at will, raising questions about whether the FTC remains sufficiently independent for the EU-U.S. Data Privacy Framework. IAPP’s Lexie White reported NOYB plans a legal challenge and has urged the European Commission to exit the framework, while WSGR Data Advisor noted the Commission said it will analyze the implications and Max Schrems said the basis for EU-U.S. transfer deals is effectively dead. IAPP’s Peter Swire separately argued the ruling does not undo the DPF redress mechanism and is more limited to the commercial-transfer side involving FTC oversight.

Why it matters

Any weakening or invalidation of the DPF would force companies moving EEA personal data to the U.S. to reassess transfer mechanisms, SCCs, BCRs and transfer-impact analyses.

Sources & driving stories

IAPP · Lexie White

IAPP coverage

IAPP · Peter Swire

IAPP coverage
MONDAQ

Five states widen U.S. privacy obligations

Mondaq’s Gary Kibel reported that Alabama, Louisiana, Oklahoma and Vermont enacted comprehensive consumer privacy laws in 2026, adding access, correction, deletion, portability and opt-out rights for targeted advertising, data sales and certain profiling. Effective dates begin with Louisiana and Oklahoma on 1 January 2027, Alabama on 1 May 2027 and Vermont on 1 January 2028; Louisiana, Oklahoma and Vermont require data protection assessments for high-risk processing, and Vermont adds Global Privacy Control recognition, health-data sale restrictions and LLM-training disclosures. Foley & Lardner’s Samuel D. Goldstick separately reported Connecticut’s Public Act 25-113 amendments took effect 1 July 2026, with covered profiling impact assessments beginning 1 August and an expanded definition of sale covering tracking pixels, cookies and AI model-training uses.

Why it matters

The U.S. state privacy patchwork is becoming broader and more operationally specific, especially around sensitive data, profiling, targeted advertising and AI training disclosures.

Sources & driving stories

MONDAQ · Gary Kibel

Mondaq coverage

FOLEY & LARDNER · Samuel D. Goldstick

Foley & Lardner coverage
THE LEGAL AFFAIR

Bombay court orders deepfake takedowns

The Bombay High Court issued an interim order directing social media platforms to remove deepfake images, AI-generated visuals, superimposed videos and morphed photographs depicting actor Preity Zinta. Justice Madhav Jamdar found prima facie infringement of her moral rights, publicity rights, personality rights and constitutionally protected right to privacy. Zinta’s petition alleged manipulated content portrayed her in fabricated and misleading ways without consent, harming her reputation and professional standing.

Why it matters

The order strengthens the use of privacy and personality rights against AI-generated impersonation and signals greater takedown responsibilities for platforms after notice.

Sources & driving stories

Worth noting

WORTH NOTING

EU breach templates advance

Ropes & Gray’s Rohan Massey noted NIS2 common incident templates were agreed 26 May and the EDPB adopted a GDPR breach-notification template 10 June for consultation until 5 August, but the reforms harmonize content rather than national reporting processes.

WORTH NOTING

Korea sets generative-AI privacy rules

The Leveraged Years’ Anthony Guerriero reported South Korea’s PIPC issued generative-AI privacy guidance and tied it to DeepSeek enforcement, including destruction of prompt data unlawfully transferred to Volcano Engine in Beijing.

WORTH NOTING

Meta AI raises consent concerns

Morning Brew’s Dave Lozo reported Meta unveiled Muse, allowing AI manipulation of public Instagram profile images when users are tagged unless opt-outs are enabled, while the New York Post’s Thomas Barrabi reported a Meta patent for emotion and medication-context tracking drew privacy criticism.

Still unclear

OPEN QUESTION

Will the Commission defend the DPF?

The European Commission’s analysis of Trump v. Slaughter will determine whether FTC-independence concerns remain a legal risk or become a practical transfer-compliance disruption.

OPEN QUESTION

Will EU reporting become less duplicative?

NIS2 and GDPR templates may standardize requested information, but companies may still face multiple portals, authorities and procedural deadlines unless a single-entry reporting point materializes.