On July 7, 2026, the Irish National Cyber Security Centre (“NCSC”) published guidance for management boards and senior executives of organizations subject to the EU’s Network and Information Security Directive (“NIS2”). Reflecting a central theme of NIS2, the Guidance makes it clear that cybersecurity is no longer solely a technical issue, but a governance and
Inside Privacy
Updates on developments in data privacy and cybersecurity
Blog Authors
Latest from Inside Privacy
FTC Seeks Comment on Proposed Policy Statement Addressing AI Accuracy and Output Steering
On July 1, 2026, the Federal Trade Commission (“FTC”) issued a proposed policy statement addressing what it describes as the “suppression of accuracy” in artificial intelligence (“AI”) systems and is seeking public comment through July 31, 2026. The proposal was issued pursuant to Executive Order 14365, Ensuring a National Policy Framework for Artificial Intelligence,…
Supreme Court Holds FTC Removal Protections Unconstitutional
On June 29, 2026, in a 6-3 decision, the U.S. Supreme Court held that (1) the Federal Trade Commission’s (FTC) statutory “for‑cause” removal protection for Commissioners violates the Constitution’s separation of powers and (2) President Trump lawfully removed Rebecca Slaughter from the FTC. The Court concluded that because FTC Commissioners exercise executive power, they must…
Rhode Island Enacts Genetic Privacy Law
In what continues to be a busy year for genetic privacy developments, Rhode Island has joined the growing number of states regulating direct-to-consumer (“DTC”) genetic testing with its recently enacted genetic privacy law, S 2203. With S 2203, Rhode Island is the fifth state to enact genetic privacy legislation this year, following Utah, South…
Trump Administration Releases Two Executive Orders on Quantum
On June 22, 2026, the White House released two Executive Orders (EOs) on quantum technologies: Securing the Nation Against Advanced Cryptographic Attacks (EO 14412) and Ushering in the Next Frontier of Quantum Innovation (EO 14413). Through the first EO, the White House seeks “to safeguard America’s most sensitive data, [U.S.] critical infrastructure, and the digital…
Five Eyes Cybersecurity Agencies Issue Statement Regarding AI-Related Shifts in Cybersecurity Risks, Urging Organizational Leaders to “Act Now”
On June 22, the leaders of the cybersecurity agencies in Australia, Canada, New Zealand, the UK, and the U.S. issued a joint statement calling for an “urgent” focus on cyber resilience in anticipation of “frontier AI models . . . exceed[ing] current industry expectations” and “fundamentally transforming both offensive and defensive cyber capabilities” within a…
Vermont Enacts Privacy Legislation to Regulate Health-Related Information
Vermont recently enacted two privacy bills to regulate health-related information. These include H.639, a genetic privacy bill regulating direct-to-consumer genetic testing companies, and the Vermont Data Privacy and Online Surveillance Act (S.71), a comprehensive privacy law that extends heightened protections to “consumer health data.” You can read our full analysis of S.71 here.…
CNIL Updates Two Standards For Health Research (MR-001 and MR-003)
On May 26, 2026, the French data protection authority (“CNIL”) published updated versions of its Reference Methodology 001 (“MR-001”, available here in French) and Reference Methodology 003 (“MR-003”, available here in French), two key frameworks governing the processing of personal data in the context of health research.…
CISA Releases Binding Operational Directive on Prioritizing Security Updates Based on Risk
On June 10, the Cybersecurity & Infrastructure Security Agency (CISA) released Binding Operational Directive (BOD) 26-04 on Prioritizing Security Updates Based on Risk and the accompanying Implementation Guidance. In releasing the BOD and Implementation Guidance, CISA noted that the documents are “part of CISA’s response to the current threat landscape” and the impact of…
Vermont Data Privacy Bill Signed into Law
On June 16, 2026, the Vermont Governor signed into law the Vermont Data Privacy and Online Surveillance Act, making Vermont the fourth state to enact a comprehensive data privacy law this year. The law will take effect on January 1, 2028.…