Key developments
FTC removal ruling unsettles EU-U.S. transfers
The U.S. Supreme Court’s 29 June decision in Trump v. Slaughter allows the president to remove FTC commissioners at will, raising questions about whether the FTC remains sufficiently independent for the EU-U.S. Data Privacy Framework. IAPP’s Lexie White reported NOYB plans a legal challenge and has urged the European Commission to exit the framework, while WSGR Data Advisor noted the Commission said it will analyze the implications and Max Schrems said the basis for EU-U.S. transfer deals is effectively dead. IAPP’s Peter Swire separately argued the ruling does not undo the DPF redress mechanism and is more limited to the commercial-transfer side involving FTC oversight.
Why it matters
Any weakening or invalidation of the DPF would force companies moving EEA personal data to the U.S. to reassess transfer mechanisms, SCCs, BCRs and transfer-impact analyses.
Sources & driving stories
IAPP · Lexie White
IAPP coverageWSGR DATA ADVISOR
WSGR Data Advisor coverageIAPP · Peter Swire
IAPP coverageFive states widen U.S. privacy obligations
Mondaq’s Gary Kibel reported that Alabama, Louisiana, Oklahoma and Vermont enacted comprehensive consumer privacy laws in 2026, adding access, correction, deletion, portability and opt-out rights for targeted advertising, data sales and certain profiling. Effective dates begin with Louisiana and Oklahoma on 1 January 2027, Alabama on 1 May 2027 and Vermont on 1 January 2028; Louisiana, Oklahoma and Vermont require data protection assessments for high-risk processing, and Vermont adds Global Privacy Control recognition, health-data sale restrictions and LLM-training disclosures. Foley & Lardner’s Samuel D. Goldstick separately reported Connecticut’s Public Act 25-113 amendments took effect 1 July 2026, with covered profiling impact assessments beginning 1 August and an expanded definition of sale covering tracking pixels, cookies and AI model-training uses.
Why it matters
The U.S. state privacy patchwork is becoming broader and more operationally specific, especially around sensitive data, profiling, targeted advertising and AI training disclosures.
Sources & driving stories
MONDAQ · Gary Kibel
Mondaq coverageFOLEY & LARDNER · Samuel D. Goldstick
Foley & Lardner coverageBombay court orders deepfake takedowns
The Bombay High Court issued an interim order directing social media platforms to remove deepfake images, AI-generated visuals, superimposed videos and morphed photographs depicting actor Preity Zinta. Justice Madhav Jamdar found prima facie infringement of her moral rights, publicity rights, personality rights and constitutionally protected right to privacy. Zinta’s petition alleged manipulated content portrayed her in fabricated and misleading ways without consent, harming her reputation and professional standing.
Why it matters
The order strengthens the use of privacy and personality rights against AI-generated impersonation and signals greater takedown responsibilities for platforms after notice.
Sources & driving stories
THE LEGAL AFFAIR
The Legal Affair coverageWorth noting
WORTH NOTING
EU breach templates advance
Ropes & Gray’s Rohan Massey noted NIS2 common incident templates were agreed 26 May and the EDPB adopted a GDPR breach-notification template 10 June for consultation until 5 August, but the reforms harmonize content rather than national reporting processes.
WORTH NOTING
Korea sets generative-AI privacy rules
The Leveraged Years’ Anthony Guerriero reported South Korea’s PIPC issued generative-AI privacy guidance and tied it to DeepSeek enforcement, including destruction of prompt data unlawfully transferred to Volcano Engine in Beijing.
WORTH NOTING
Meta AI raises consent concerns
Morning Brew’s Dave Lozo reported Meta unveiled Muse, allowing AI manipulation of public Instagram profile images when users are tagged unless opt-outs are enabled, while the New York Post’s Thomas Barrabi reported a Meta patent for emotion and medication-context tracking drew privacy criticism.
Still unclear
OPEN QUESTION
Will the Commission defend the DPF?
The European Commission’s analysis of Trump v. Slaughter will determine whether FTC-independence concerns remain a legal risk or become a practical transfer-compliance disruption.
OPEN QUESTION
Will EU reporting become less duplicative?
NIS2 and GDPR templates may standardize requested information, but companies may still face multiple portals, authorities and procedural deadlines unless a single-entry reporting point materializes.
