In case you missed it, below are recent posts from Privacy World covering the latest developments on data privacy, security and innovation. Please reach out to the authors if you are interested in additional information.

China Introduces Simplified Personal Information Protection Regime for Small-Scale Personal Information Handlers

Upcoming CLE Opportunities with the SPB Data Team

Regulating the Irreversible: The EDPB’S Web Scraping Guidelines and the Limits of GDPR Orthodoxy

How Deep is Your Fake? A 3-Minute-Guide on Labelling Obligations under the EU AI Act

Another Omnibus package – no.’VII’ – this time on all things AI

Upcoming Events in Asia

Stay Ahead on Consumer Privacy News

Not a subscriber yet? Subscribe here to be among the first to receive timely updates on the fast-moving world of data privacy, security, and innovation—delivered straight to your inbox.

Looking for deeper insights and expert analysis? You can also subscribe here to our privacy attorneys’ marketing communications for thought leadership and rich content when you need a more comprehensive perspective.

On July 22, 2026, the Cyberspace Administration of China (CAC) and the Ministry of Public Security jointly issued the Provisions on Simplified Measures for Personal Information Protection by Small-Scale Personal Information Handlers (the “Provisions”), which will take effect on September 1, 2026.

The Provisions are designed to reduce compliance burdens for smaller businesses, while maintaining baseline personal information protection requirements. They introduce a series of streamlined compliance measures for qualifying entities in China.

Continue Reading China Introduces Simplified Personal Information Protection Regime for Small-Scale Personal Information Handlers

On August 5, 2026, Julia Jacobson, Partner (New York), and Joel Schwarz, Managing Partner, The Schwarz Consulting Group LLC, will present “Privacy and Online Safety Laws for Minors: Navigating Evolving Compliance, Business, and Technology Challenges.”  This Strafford webinar will review the growing body of laws focused on the privacy and safety of minors online and offer some tips for developing and uplifting compliance practices.  To learn more: click here.   We have a few complimentary access codes.  Please contact julia.jacobson@squirepb.com or TheSchwarzGroup@outlook.com.

On August 20, 2026, Alan Friel, Partner (Atlanta/Los Angeles), and Julia Jacobson, Partner (New York), are joined by Faye Ricci, VP & Deputy General Counsel, Boeing Employee Credit Union (BECU), for “AI and Data Privacy: Adapting Policies, Ensuring Responsible Use of Data, Mitigating Risks.”  Also sponsored by Strafford, this session will cover privacy risks associated with deployment of artificial intelligence (AI) systems.  To learn more: click here.  To request a complimentary access code, please contact your Squire Patton Boggs relationship partner or the speakers.

Kyle Dull, Senior Associate (Miami/New York), will present “AI-Assisted Advertising and Retail” to the Association of Corporate Counsel (South Florida Chapter) on August 25, 2026, in Miami, Florida. This CLE will cover consumer protection regulations; profiling and ADMT regulations; and an action plan for in-house teams. Please reach out to christina.kim@squirepb.com for more details.

On August 28, 2026, Alan Friel, Partner (Atlanta/Los Angeles), and Kyle Dull, Senior Associate (Miami/New York), will present “Consumer Privacy Requests and Wiretapping Claims Across a Patchwork of State Laws: A Defensible Response Playbook,” a live webinar Co-Sponsored by the Federal Bar Association and myLawCLE. For a free pass, please reach out to Elizabeth Roby and for further details on the webinar, click here.

Also in August, Julia Jacobson, Partner (New York), is joined by Dominic Braithwaite, a member of the firm’s Public Policy Practice, to present “The New Reasonable Security: How AI Has Changed What’s ‘Reasonable’.”  This webinar, sponsored by Law Practice CLE, will explore how AI has changed the cyber threat landscape and the challenges of complying with ‘reasonable’ security requirements in the AI age.  Please contact us for details.

Stay Ahead on Consumer Privacy News

Not a subscriber yet? Subscribe here to be among the first to receive timely updates on the fast-moving world of data privacy, security, and innovation—delivered straight to your inbox.

Looking for deeper insights and expert analysis? You can also subscribe here to our privacy attorneys’ marketing communications for thought leadership and rich content when you need a more comprehensive perspective.

Email this postTweet this postLike this postShare this post on LinkedIn

The Guidelines 03/2026 on web scraping in the context of generative AI, adopted by the European Data Protection Board “EDPB” for public consultation on 7 July 2026, are notable not only for what they require but for what they acknowledge. The document is unusually candid about three limitations: an epistemic one (the controller may not always know what it has collected), a technical one (what a model has learned cannot, today, be easily unlearned), and an institutional one (some of the assessments woven into the GDPR analysis sit, at least in part, with other authorities and courts). These acknowledgements are welcome, and they distinguish the text from more declaratory guidance. The tension is that the requirements built on top of them are not always adjusted accordingly, and that gap, between what the EDPB admits and what it nonetheless requires, is where the most interesting questions of the consultation lie.

Briefly, the Guidelines cover scraping performed by private entities, whether carried out in-house, commissioned from a third party or effected through the acquisition of pre-scraped datasets. They work through the familiar sequence: allocation of controller and processor roles, the core principles of Article 5 GDPR (purpose limitation, transparency, minimization, accuracy), the choice of legal basis, with legitimate interest under Article 6(1)(f) GDPR treated as the realistic candidate and consent all but discarded, and the treatment of special categories of data incidentally swept up in the collection, for which the EDPB adapts the CJEU’s GC & Others framework. Little of this structure will surprise anyone who has followed the Board’s recent work on AI. What rewards attention is how each of these familiar steps is made to function once the three limitations above enter the analysis.

Continue Reading Regulating the Irreversible: The EDPB’S Web Scraping Guidelines and the Limits of GDPR Orthodoxy

The EU Artificial Intelligence (AI) Act requires companies to disclose in certain cases whether content has been created or modified by AI. This also applies to companies that make use of AI such as image-generation programs for product advertising.

Given that the new rules are enforceable from 2 August 2026, with fines up to EUR 15 million or 3% of global annual turnover, the importance of compliance with these rules is now in sharp focus.

The good news is that for deployers of AI systems, besides chatbot disclosure, labelling obligations only apply in two scenarios: (i) AI-generated or manipulated texts aiming at informing the public on matters of public interest, and (ii) deep fakes[1].

Looking at all of this in more detail, what does this mean to companies that create and/or publish advertising and promotional content?

Why AI-Generated or Manipulated Texts on Public Matters Might be a Concern

As one example of AI generated or manipulated texts which inform the public on matters of public interest, the EU Commission’s Draft Guidelines (the latest version being a 2024 draft for stakeholder consultation)[2] list AI-manipulated corporate reports published on a listed company’s website which contain investor information.

By contrast, the EU Commission’s Draft Guidelines assume that the labelling obligation will not apply to:

  • AI-manipulated texts that are part of a company’s advertisements other than text that promotes any claims relating to e.g. health, consumer safety or sustainability
  • AI-generated fictional novels or poems in any genre
  • news summaries by a chatbot that are only available to the user that prompted the chatbot.

A general exemption applies to AI generated or manipulated text that has undergone human review or editorial control and for which a legal or natural person holds editorial responsibility[3].

Deep Fakes


What seems more challenging for companies promoting or selling products on their websites, in catalogues, on billboards, on TV and social media or other means of advertising, is the obligation to disclose AI generated or manipulated image, audio or video content constituting a deep fake. The term “deep fake” is defined in Article 3(60) of the AI Act as

AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful”.

Whilst there are good reasons for extending the definition of “deep fake” beyond persons, i.e. realistic natural human beings, in view of the dangers involved with simulated events without persons being involved, the inclusion of:

  • objects,
  • places,
  • entities, and
  • events

opens the door for the labelling obligations applying to a broad spectrum of content including product advertisements.

The key question in the individual case is whether such content is likely to deceive or mislead a person regarding its authenticity or truthfulness. This assessment is to be conducted based on a hypothetical average person expected to be exposed to such content, which is particularly important if advertising is directed at children or groups with lower digital and AI literacy[4].

The sheer variety of options to generate and manipulate content with AI leads to various borderline cases. For example, does color correction, re-scaling, background editing, removal of elements, simulated movement, lighting or seasonal adjustment in relation to product images amount to a deep fake? Most likely not if the lack of authenticity is obvious (e.g. in case of blurred backgrounds) or the manipulation has only a minor impact on the consumer’s perception.

However, images of persons who are made to resemble a celebrity might be caught. The same question may arise in relation to depictions of real persons, for example, an advertisement may use a genuine photograph of a person while AI is merely used to place that person in a kitchen setting where the original image is not taken in a kitchen, or AI is used to change the person’s posture or the shade of the hair.

Practical Considerations

AI-generated or AI-modified content must be clearly labelled in a manner that is easily noticeable to users and remains visible when the content is viewed or shared. Until there is case law available on how strict the labelling requirements are interpreted and how they are fulfilled, the EU AI Office’s Code of Practice on Transparency of AI-Generated Content[5] provides valuable, albeit non-binding practical guidance on the topic.

  • Standardized Icons. This includes freely available standardized EU icons that companies may want to use to comply with the labelling requirements.
  • Size of Icons. As far as the icon’s size is concerned, the only guideline so far is basically that it must be “clear and distinguishable[6].
  • “AI”, “AI Generated” or “AI Modified”. Whether the designation “AI” is sufficient or – as “encouraged” in the Code of Practice (i.e. not binding but recommended) – transparency requires distinguishing between “AI Generated” and “AI Modified”, is still an open question.
  • Implementation of a second layer. According to the Code of Practice, the integration of interactive second layers to enrich the static icons with provenance data and information on what has been modified is currently explored. 
  • Placing icons on images and videos. For images and videos, the disclosure should be displayed prominently within the visible content area and embedded in the metadata; where available, AI watermarks or visual labels should also be used.
  • Audio labelling. Audio content must include a clear audible disclosure.
  • Periodic disclosure. Video and audiovisual content must be labelled at the beginning and, for content exceeding a short period of time, continuously or at regular intervals, with both visual and audio disclosures where applicable.

In view of the legal consequences of violations and sometimes huge amount of content involved, it is no wonder that some prominent retailers have already decided to take the bull by the horns and label any AI created or modified images. All of this will be of interest to manufacturers, retailers and the creators of advertising material. Besides the risk of fines, the new labelling requirements will most likely be deemed provisions intended to regulate market behavior under the laws of unfair competition, opening the door for claims by competitors and watchdog associations, with the consequence that advertising may, by way of a preliminary injunction, be prohibited literally overnight. Companies are therefore well-advised to establish internal guidelines and procedures for AI transparency and closely monitor the developments in the sector to verify on a regular basis whether existing compliance measures require updates.


[1] Article 50(4) AI Act.

[2] The consultation period ended on 3 June 2026.

[3] Article 50(4), subparagraph 2 AI Act.

[4] Cf. Draft Guidelines, p. 28.

[5] https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content.

[6] Article 50(5) AI Act.

Disclaimer: While every effort has been made to ensure that the information contained in this article is accurate, neither its authors nor Squire Patton Boggs accepts responsibility for any errors or omissions. The content of this article is for general information only, and is not intended to constitute or be relied upon as legal advice.

Consistent with the recent strategic shift in policy around EU regulations, the EU’s seventh package of changes to simplify/lighten their burden has just been approved and, with it, we will see changes to the way the EU’s Artificial Intelligence Act will be applied (although some obligations under this legislation are already in force).

The EU’s Council of Ministers and Parliament have agreed to changes and, consistently with the overall themes of previous Omnibus packages, there is an emphasis on slowing things down, reducing burdens for smaller sized companies and seeking to avoid the application of a double regulatory burden where legal obligations under other EU rules are already in place. This is similar to what the EU has done under previous packages with ESG rules under the Corporate Sustainability Reporting Directive, Corporate Due Diligence Directive and the EU Deforestation Regulation (amongst other examples). The changes should be adopted imminently given that the deadlines they are seeking to delay otherwise start to apply in August.

Recall that the approach to (high risk) AI products incorporates the tried and tested conformity assessment and CE marking system that we see with so many consumer products on the EU market. AI products, for all their world-changing promise and potential, are in effect treated no differently in this respect from your average widget that requires to have a CE mark. Thus, where the Omnibus VII package slows down the application of the law and clarifies the various overlaps with specific sectoral laws that already ensure safety (such as the Machinery Regulation), companies developing their products for the AI world, using AI as a safety component for products, or those venturing into the manufacture of products incorporating AI for the first time can be reassured that they are treading a well-worn path, albeit with slightly different considerations (noting that what is ‘high-risk’ in terms of AI does not only depend on the product-regime, but also the particularities of the AI system itself and its intended use). Lawyers are there to interpret the laws (e.g. does your AI system fall within a high-risk category? Is it borderline? What are the arguments that will work that will keep you away from additional regulatory burdens? What are the minimum legal requirements for AI?) and explain the legal value of standards and guidance documents as opposed to specific implementing regulations while, just as importantly, if not more, those same lawyers know how and when to liaise with technical consultants, your in-house experts, technical bodies, etc., as appropriate, to compile the necessary technical documentation and establish the appropriate inhouse systems. In that regard, it will help if your legal team includes lawyers who know their way around CE marking/conformity assessment rules because they do it on a daily basis by reference to the Radio Equipment Directive, or Batteries Regulation or RoHS Directive, for example as much as they are experts in data privacy and digital assets law.

Disclaimer: While every effort has been made to ensure that the information contained in this article is accurate, neither its authors nor Squire Patton Boggs accepts responsibility for any errors or omissions. The content of this article is for general information only, and is not intended to constitute or be relied upon as legal advice.

We are delighted to invite you to our forthcoming events in Asia, where you will have the opportunity to connect with industry peers and hear from our team as they explore emerging trends, regulatory developments, and practical challenges at the intersection of data privacy, AI, and cybersecurity worldwide.

  • IAPP Asia Networking Reception: On July 21 2026, 5:30-8:00 p.m., we are happy to host our annual networking reception celebrating the International Association of Privacy Professionals conference in Singapore.  This will be hosted at our Singapore office at One Marina Boulevard.  As space is limited, if you are interested, please reach out with your name, company, industry and contact details to mogana.ramasamy@squirepb.com and sheela.subramaniam@squirepb.com.
  • IAPP Asia Forum 2026: On July 22 2026, our partner Tanvi Mehta Krensel will be moderating a panel titled “(Age) Verified by Law: Privacy, Anonymity and the New Era of Online Safety”, along with Hailun Ying (Head of PrivSec, Legal at Roblox), Claire Tan Chu Wen (Lead Senior Counsel at Lenovo) and Song Yeong Ng (Deputy Director, Policy and Technology at Singapore Personal Data Protection Commission). It will be hosted at the IAPP Asia Forum between 2:45-3:45 p.m. If you are interested, please register for the Forum here.
  • Data Privacy, Cybersecurity, AI and Child Safety: On July 24 2026, 2:00-3:00 p.m., we will be hosting in our Singapore office a client update of latest developments in data privacy, cybersecurity, AI and child safety, all of which are moving swiftly in the regulatory space. This will feature many of our Data Privacy, Cybersecurity and Digital Assets team members who are visiting Singapore for the IAPP Conference.  It will be hosted at our office at One Marina Boulavard. As space is limited, if you are interested, please reach out with your name, company, industry and contact details to mogana.ramasamy@squirepb.com and sheela.subramaniam@squirepb.com.
  • 23rd China International Compliance Summit 2026: On October 28 or 29 2026, (date being set), Scott Warren will be providing an update on the latest US to China data transfer regulations, impact and class action lawsuits surrounding the US Bulk Data Transfer Rule.  For more information regarding this in-person event in Shanghai, please contact helen.su@linworld-group.com.

We are proud to celebrate the recognition of 10 attorneys in Lawdragon’s 2026 500 Leading Global Cyber Lawyers Guide, a prestigious listing that honors lawyers at the forefront of privacy, cybersecurity, data protection, incident response, and related regulatory and litigation matters. Lawdragon’s guide recognizes leaders who help organizations navigate an increasingly complex digital landscape and protect critical business and consumer interests.

This year’s honorees reflect the depth and breadth of our global cyber, privacy, and data protection capabilities, advising clients on some of the most challenging issues arising from technological innovation, evolving regulations, cybersecurity incidents, and cross-border data governance.

We congratulate the following attorneys on this well-deserved recognition:

Stay Ahead on Consumer Privacy News

Not a subscriber yet? Subscribe here to be among the first to receive timely updates on the fast-moving world of data privacy, security, and innovation—delivered straight to your inbox.

Looking for deeper insights and expert analysis? You can also subscribe here to our privacy attorneys’ marketing communications for thought leadership and rich content when you need a more comprehensive perspective.

In case you missed it, below are recent posts from Privacy World covering the latest developments on data privacy, security and innovation. Please reach out to the authors if you are interested in additional information.

What GCs Should Consider for US AI Deployment in 2026

The Data (Use and Access) Act 2025 and the new right for individuals to complain to controllers: What organisations need to do before 19 June 2026

The Conflict Between the First Amendment and Online Privacy & Safety Regulation

V2.0 Certification of French Health Data Hosting Service Providers (HDS) now Fully Effective

Stay Ahead on Consumer Privacy News

Not a subscriber yet? Subscribe here to be among the first to receive timely updates on the fast-moving world of data privacy, security, and innovation—delivered straight to your inbox.

Looking for deeper insights and expert analysis? You can also subscribe here to our privacy attorneys’ marketing communications for thought leadership and rich content when you need a more comprehensive perspective.

Recently, we hosted an intimate dinner in Los Angeles with a group of general counsels and senior executive leaders to discuss the evolving challenges posed by artificial intelligence (AI), data privacy and cybersecurity, particularly as they relate to HR and production environments. The roundtable discussion was dynamic and insightful, reflecting the real-world risks and strategic considerations that organizations are currently navigating.

On June 2, 2026, President Trump signed an executive order, ‘Promoting Advanced Artificial Intelligence Innovation and Security – The White House‘, providing federal government hardening of cybersecurity defenses against AI and prioritizing enforcing existing cybercrimes laws, as well as directing a multiagency effort to develop a voluntary program for covered frontier models to be assessed prerelease for cyber risk to critical infrastructure. This light touch security-focused approach is consistent with the federal government’s ongoing prioritization of innovation over regulation, but with a new focus on critical security risk.

Our team has captured key themes and concerns raised by legal thought leaders during our discussions and offers practical perspectives on how companies can prepare for and respond to this rapidly developing landscape in What GCs Should Consider for US AI Deployment in 2026.

Squire Patton Boggs will continue to monitor and report on federal and state regulatory efforts.

Stay Ahead on Consumer Privacy News

Not a subscriber yet? Subscribe here to be among the first to receive timely updates on the fast-moving world of data privacy, security, and innovation—delivered straight to your inbox.

Looking for deeper insights and expert analysis? You can also subscribe here to our privacy attorneys’ marketing communications for thought leadership and rich content when you need a more comprehensive perspective.