Click above|Follow us
Recently, at the domestic governance level, the Cyberspace Administration of China solicited public comments on the revised draft of the Administrative Measures for Internet Information Services, while the People’s Bank of China and the National Financial Regulatory Administration released consultation drafts on cybersecurity rules. Internationally, the EU continued to advance AI and data governance rules, covering the AI Act simplification package, generative AI web scraping, anonymisation, data sovereignty, NIS2 transposition and DSA platform enforcement. Several US states updated legislation or enforcement actions concerning AI safety, digital privacy, genetic data and child protection. The United Kingdom, Singapore, South Korea, France and Australia also issued policies, guidance or enforcement cases involving cyber resilience, AI agents in finance, personal information protection, employee monitoring and online protection of minors.
HOTSPOT
HOTSPOT
The Cyberspace Administration of China Releases the Revised Draft of the Administrative Measures for Internet Information Services for Public Comments
On 3 July 2026, the Cyberspace Administration of China released the Administrative Measures for Internet Information Services (Revised Draft for Comments) (the “Revised Draft”) for another round of public comments. The deadline for comments is 2 August 2026.
Since its implementation in 2000, the Administrative Measures for Internet Information Services has served as an important foundational regulation for the administration of internet information services in China. The Revised Draft responds to issues arising from internet platform governance, user account management, cyber violence governance, AI-generated and synthetic content, algorithmic recommendation, agent services, app distribution and multi-channel distribution of internet information content. It systematically revises the rules on market access, service operation, platform responsibilities, intelligent information services and legal liabilities. Overall, the Revised Draft extends the scope of internet information service regulation beyond traditional websites and apps to cover emerging content production and distribution scenarios such as agents, algorithmic recommendation, generated and synthetic content, public accounts and MCNs.
Source: Cyberspace Administration of China
Consultation Drafts on Cybersecurity Regulatory Rules in the Financial and Insurance Sectors
On July 3, 2026, the People's Bank of China (PBOC), the National Financial Regulatory Administration (NFRA), the China Securities Regulatory Commission (CSRC), and the State Administration of Foreign Exchange (SAFE) jointly released the Draft Financial Sector Cybersecurity Management Measures (hereinafter referred to as the "Draft Financial Cybersecurity Measures") for public comment, clarifying that financial institutions shall bear primary responsibility for their own cybersecurity. The Draft requires implementation of cybersecurity classified protection, strengthening of network operation monitoring, network data classification and grading together with personal information protection, and use of commercial cryptography to safeguard network and critical information infrastructure security. Targeted handling measures are also established for violations such as transmitting illegal information, failure to use commercial cryptography as prescribed, and non-cooperation with supervision and inspection.
In the same month, the NFRA released the Draft Banking and Insurance Cybersecurity Management Measures (hereinafter referred to as the "Draft Banking and Insurance Cybersecurity Measures") for public comment, setting forth clear requirements in core areas including cybersecurity governance, cybersecurity construction and operation management, cybersecurity risk monitoring, cybersecurity incident response and handling, critical information infrastructure management, and supervision and administration. The annex also specifies the classification standards for cybersecurity incidents in the banking and insurance sectors.
Together with the previously released Measures for the Administration of Data Security of Banking and Insurance Institutions and Measures for the Administration of Data Security in the Business Areas of the People's Bank of China, these two measures form the institutional matrix for cybersecurity and data security governance in China's financial industry.
Source: People's Bank of China
https://www.pbc.gov.cn/tiaofasi/144941/144979/3941920/2026070309071537722/index.html
Source: National Financial Regulatory Administration
https://www.nfra.gov.cn/cn/view/pages/ItemDetail.html?docId=1264207&itemId=951&generaltyp
EU Consults on Guidelines on Web Scraping in the Context of Generative AI
On 8 July 2026, the European Data Protection Board (EDPB) released the Guidelines 03/2026 on web scraping in the context of generative AI (the “Guidelines”) for public consultation. The deadline for comments is 30 October 2026.
The Guidelines focus on automated scraping of data from publicly accessible internet sources during the training or fine-tuning of generative AI models, and explain the compliance requirements under the GDPR. The EDPB states that information on publicly accessible webpages is not automatically free to scrape and use for AI training. If the scraped content involves personal data, GDPR requirements on legal bases, purpose limitation, transparency, data minimisation, accuracy, data subject rights and protection of special categories of personal data must still be complied with. The Guidelines also emphasise that controllers should adopt technical and organisational measures to reduce personal data protection risks arising from web scraping, such as limiting the sources and categories of data scraped, increasing transparency, facilitating the exercise of individual rights, and deleting, anonymising or pseudonymising personal data as early as possible where feasible.
Source: EDPB
https://www.edpb.europa.eu/system/files/2026-07/edpb_guidelines_2020603_webscraping_v1_en_0.pdf
NEWSLETTER
NEWSLETTER
(Click on the source or copy the corresponding link to view the details)
LEGISLATION
The Cyberspace Administration of China releases the Administrative Measures for Internet Information Services (Revised Draft for Comments)
Source: Cyberspace Administration of China
The Office of the Central Cyberspace Affairs Commission solicits comments on the mandatory national standard Management Requirements for Government Mobile Internet Applications (Draft for Comments)
Source: Cyberspace Administration of China
The Measures for Cybersecurity Labelling and the Interim Measures for the Administration of AI Anthropomorphic Interaction Services take effect in July
Source: Cyberspace Administration of China
The People’s Bank of China and three other authorities release the Measures for Cybersecurity Management in the Financial Sector (Draft for Comments)
Source: People’s Bank of China
https://www.pbc.gov.cn/tiaofasi/144941/144979/3941920/2026070309071537722/index.html
The National Financial Regulatory Administration releases the Measures for Cybersecurity Management in the Banking and Insurance Sectors (Draft for Comments)
Source: National Financial Regulatory Administration
https://www.nfra.gov.cn/cn/view/pages/ItemDetail.html?docId=1264207&itemId=951&generaltype=2
The National Data Administration releases the Guidelines for Data Property Rights Registration (Trial)
Source: National Data Administration
The State Administration for Market Regulation and the Ministry of Commerce release the E-Commerce Law of the People’s Republic of China (Draft Amendment for Comments)
Source: State Administration for Market Regulation
The Standardization Administration of China issues one mandatory national cybersecurity standard project plan
Source: Standardization Administration of China
TC260 releases the Cybersecurity Standard Practice Guide - Security Guidelines for Agent Deployment and Use
Source: National Information Security Standardization Technical Committee (TC260)
TC260 issues plans for 13 normative guiding technical documents
Source: National Information Security Standardization Technical Committee (TC260)
TC260 releases three draft Cybersecurity Standard Practice Guides for public comments, including the Technical Guidelines for Information Erasure on Mobile Intelligent Terminals (Draft for Comments)
Source: National Information Security Standardization Technical Committee (TC260)
TC260 releases seven national cybersecurity standards
Source: National Information Security Standardization Technical Committee (TC260)
https://www.tc260.org.cn/portal/article/2/5fd674db7cf8498bbcfe35615cfb0469
The Beijing White Paper on Informatization Standards Construction is officially released
Source: Beijing Municipal Bureau of Economy and Information Technology
INDUSTRY TRENDS
Procuratorial authorities in Beijing, Tianjin and Hebei release typical cases supporting the development of the digital economy, including a case involving the illegal deletion of approximately 89TB of AI training data
Source: Supreme People’s Procuratorate
https://www.spp.gov.cn/spp/zdgz/202607/t20260704_731271.shtml
The Office of the Central Cyberspace Affairs Commission announces a special “Qinglang” campaign to rectify disorder in online entertainment group livestreaming
Source: Cyberspace Administration of China
The Office of the Central Cyberspace Affairs Commission carries out the first phase of the “Qinglang - Rectification of AI Application Disorder” campaign
Source: Cyberspace Administration of China
The Office of the Central Cyberspace Affairs Commission launches a special rectification campaign targeting illegal information related to volunteer services on online platforms
Source: Cyberspace Administration of China
The Office of the Central Cyberspace Affairs Commission takes strict action against a batch of accounts and platforms with non-compliant short-video content labelling
Source: Cyberspace Administration of China
The Ministry of Industry and Information Technology reports 32 apps and SDKs for illegal collection of personal information and excessive permission requests
Source: Ministry of Industry and Information Technology
The Cybersecurity Threat and Vulnerability Information Sharing Platform (NVDB) under the Ministry of Industry and Information Technology issues a risk alert on security backdoor risks in the AI coding tool Claude Code
Source: Cybersecurity Threat and Vulnerability Information Sharing Platform
The Cybersecurity Bureau of the Ministry of Public Security publishes a case involving a parking management system operator that failed to fulfil personal information protection obligations
Source: Cybersecurity Bureau of the Ministry of Public Security
The Ministry of State Security reports that an AI company under a well-known AR game obtained nearly 30 billion pieces of environmental scan data from users, potentially for AI model training, and that the company cooperates with the military industry of a certain country, with the relevant model potentially used for military purposes
Source: Ministry of State Security
The National Cybersecurity Notification Center reports 72 mobile applications that illegally collect and use personal information
Source: National Cybersecurity Notification Center
The Beijing Cyberspace Administration publishes information on licensed internet news information service providers as of 30 June 2026
Source: Beijing Cyberspace Administration
The Beijing Cyberspace Administration publishes an announcement on registered generative AI services dated 8 July 2026
Source: Beijing Cyberspace Administration
The Shanghai Cyberspace Administration announces the first filing case under the data export negative list, involving a membership management scenario
Source: Shanghai Cyberspace Administration
The Shanghai Cyberspace Administration carries out the first phase of the “Qinglang - Rectification of AI Application Disorder” campaign
Source: Shanghai Cyberspace Administration
Shanghai publishes an announcement on registered generative AI services dated 30 June
Source: Shanghai Cyberspace Administration
The Hainan Cyberspace Administration reports illegal collection and use of personal information by eight apps, including “DeepAI Translator”, and 11 WeChat mini-programs, including “AI Hongdan”
Source: Hainan Cyberspace Administration
Doubao and Tongyi Qianwen announce that agent functions were taken offline on the effective date of the Interim Measures for the Administration of AI Anthropomorphic Interaction Services
Source: National Business Daily
https://cd.nbd.com.cn/articles/2026-07-04/4452174.html
OVERSEAS
International: The first UN global technical regulation for automated driving systems is approved and released
Source: United Nations
https://mp.weixin.qq.com/s/-bouFfdi50Rwjm3FU1XuCg
EU:
The Council of the European Union adopts the AI Act simplification package
Source: Council of the European Union
https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/
The EDPS publishes a checklist on human intervention in automated decision-making
Source: European Data Protection Supervisor (EDPS)
https://www.edps.europa.eu/system/files/2026-05/26-05-18_checklist-on-human-intervention-of-adm_en.pdf
ENISA releases an opinion paper titled “Cybersecurity in the Age of Frontier AI”
Source: European Union Agency for Cybersecurity (ENISA)
https://www.enisa.europa.eu/publications/enisas-view-on-cybersecurity-in-the-frontier-ai-era
The EDPB adopts guidelines on anonymisation and web scraping in generative AI contexts, and adopts the final version of its guidelines on personal data processing through blockchain technologies
Source: EDPB
https://www.edpb.europa.eu/news/edpb-sheds-light-on-anonymisation-and-web-scraping-for-generative-ai-and-adopts-final-version_en
The European Commission releases an action plan on cybersecurity and artificial intelligence
Source: European Commission
https://digital-strategy.ec.europa.eu/en/library/eu-action-plan-cybersecurity-and-artificial-intelligence
The European Commission launches a targeted consultation on safeguarding the EU’s data sovereignty
Source: European Commission
https://digital-strategy.ec.europa.eu/en/consultations/targeted-consultation-safeguarding-eus-data-sovereignty
The European Commission refers Ireland, Spain and two other Member States to the Court of Justice for failing to fully transpose the NIS2 Directive
Source: European Commission
https://digital-strategy.ec.europa.eu/en/news/commission-refers-ireland-spain-france-and-netherlands-court-justice-failing-transpose-rules
The European Commission preliminarily finds that the addictive design of Instagram and Facebook breaches the Digital Services Act
Source: European Commission
https://ec.europa.eu/commission/presscorner/api/files/document/print/en/ip_26_1579/IP_26_1579_EN.pdf
The General Court of the European Union dismisses all of Apple’s claims challenging its designation as a DMA “gatekeeper”
Source: Court of Justice of the European Union
https://curia.europa.eu/site/upload/docs/application/pdf/2026-07/cp260096en.pdf?
The Court of Justice of the European Union upholds the approximately EUR 4.1 billion fine in the Google Android antitrust case
Source: Court of Justice of the European Union
https://curia.europa.eu/site/upload/docs/application/pdf/2026-07/cp260093en.pdf?
The Court of Justice of the European Union rules in Case C-199/24 that, in principle, a paid criminal judgment database does not constitute processing of personal data for “journalistic purposes”
Source: Court of Justice of the European Union
https://infocuria.curia.europa.eu/tabs/affair?lang=EN&sort=AFF_NUM-DESC&searchTerm=%22C-199%2F24%22&publishedId=C-199%2F24
The EU consults on the Guidelines on Web Scraping in the Context of Generative AI
Source: EDPB
https://www.edpb.europa.eu/system/files/2026-07/edpb_guidelines_2020603_webscraping_v1_en_0.pdf
US:
The Federal Trade Commission seeks public comment on a policy statement addressing AI accuracy
Source: FTC
https://www.ftc.gov/news-events/news/press-releases/2026/07/ftc-seeks-public-comment-policy-statement-addressing-ai-accuracy
Florida: the Attorney General announces a resolution with Roku in a digital privacy enforcement action
Source: Florida Attorney General’s Office
https://www.myfloridalegal.com/newsrelease/florida-attorney-general-james-uthmeier-and-roku-announce-resolution-digital-privacy-0
South Dakota’s genetic data privacy law takes effect on 1 July
Source: South Dakota Attorney General’s Office
https://atg.sd.gov/OurOffice/Media/pressreleasesdetail.aspx?id=3040
Montana’s bill amending the Electronic Health Record Act takes effect
Source: Montana Legislature
https://mca.legmt.gov/bills/mca/title_0500/chapter_0160/part_0080/section_0060/0500-0160-0080-0060.html
The California Attorney General secures a significant court win by defeating Meta’s motion for summary judgment in a child safety lawsuit
Source: California Attorney General’s Office
https://oag.ca.gov/news/press-releases/ahead-meta-trial-attorney-general-bonta-secures-critical-win
The Texas Attorney General announces an ongoing investigation into Carnival Cruise Line over a data breach
Source: Texas Attorney General’s Office
https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-announces-ongoing-investigation-carnival-cruise-line-over-data-breach
The Governor of Illinois signs SB 315, the Artificial Intelligence Safeguards Act
Source: Office of the Governor of Illinois
https://gov-pritzker-newsroom.prezly.com/gov-pritzker-signs-nation-leading-artificial-intelligence-safety-law
Major amendments to the Connecticut Data Privacy Act concerning scope of application, sensitive personal data, automated profiling, privacy notices, consumer rights and minors’ data protection take effect on 1 July 2026
Source: Connecticut General Assembly
https://cga.ct.gov/2025/sum/pdf/2025SUM00113-R02SB-01295-SUM.pdf
Apple sues OpenAI and two former employees for alleged trade secret theft
Source: US District Court for the Northern District of California
https://www.courtlistener.com/docket/73602437/apple-inc-v-liu/?
UK:
The UK Government launches the Cyber Resilience Pledge to encourage large companies to strengthen cyber resilience
Source: UK Government
https://www.gov.uk/government/news/businesses-across-britain-sign-up-to-cyber-resilience-pledge-as-ministers-urge-firms-to-strengthen-cyber-defences
The UK National Cyber Security Centre (NCSC) and the Department for Science, Innovation and Technology (DSIT) propose “Cyber Shield” as a path toward an agentic AI future for cyber defence
Source: UK National Cyber Security Centre (NCSC)
https://www.ncsc.gov.uk/blogs/cyber-shield-the-path-to-an-agentic-ai-future-for-cyber-defence
The UK Government publishes a report on cyber resilience in financial services
Source: UK Government
https://www.gov.uk/government/publications/the-value-of-resilience-cyber-resilience-in-financial-services/the-value-of-resilience-cyber-resilience-in-financial-services
The UK designates Microsoft, Google, Amazon and Oracle as critical third parties for the financial sector
Source: HM Treasury
https://www.gov.uk/government/news/uk-financial-system-strengthened-with-new-safeguards-for-major-technology-providers?
South Korea:
PIPC releases the Third Basic Plan for Personal Information Protection (2027-2029)
Source: Personal Information Protection Commission of Korea (PIPC)
https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=12228
PIPC plans to amend the Enforcement Decree of the Personal Information Protection Act
Source: PIPC
https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=&nttId=12237
PIPC plans to expand the right to request third-party transfer of personal information to the education and employment sectors
Source: PIPC
https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=12237
PIPC issues a risk alert on personal information leakage in API use
Source: PIPC
https://pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=12241
France:
CNIL releases survey results on the role of DPOs in the AI era
Source: French Data Protection Authority (CNIL)
https://www.cnil.fr/fr/enquete-dpo-ia
CNIL issues a reminder on compliance rules for geolocation data in mobile applications
Source: CNIL
https://www.cnil.fr/fr/geolocalisation-applications-mobiles-quelles-regles
CNIL announces 23 sanctions imposed through its simplified sanction procedure since January 2026
Source: CNIL
https://www.cnil.fr/fr/23-nouvelles-sanctions-simplifiees
CNIL reminds mobile applications of data protection issues involving geolocation
Source: CNIL
https://www.cnil.fr/fr/geolocalisation-applications-mobiles-quelles-regles
CNIL issues compliance guidance on employee monitoring, identifying three cumulative conditions and rejecting continuous keystroke monitoring
Source: CNIL
https://www.cnil.fr/fr/controle-de-lactivite-des-personnes-employees
Australia:
The government announces stronger powers and increased penalties under the minimum age law for social media
Source: Australian Government
https://www.pm.gov.au/media/stronger-powers-and-double-penalties-world-leading-social-media-law
The OAIC releases 2025 data breach notification statistics, showing that notifications reached a record high since the mandatory notification scheme took effect
Source: Office of the Australian Information Commissioner (OAIC)
https://www.oaic.gov.au/news/media-centre/data-breach-notifications-increase-to-all-time-high-in-2025%2C-new-ndb-stats-show
Singapore:
The Minister issues the commencement notification for the Online Safety (Relief and Accountability) Act 2025
Source: Ministry of Law of Singapore
https://www.mlaw.gov.sg/online-safety-commission-and-online-safety-relief-and-accountability-act-2025-to-start-on-29-june-2026/
MDDI issues online safety service regulations
Source: Ministry of Law of Singapore
https://www.mlaw.gov.sg/the-online-safety-commission-begins-operations-on-29-june-2026/
MDDI and IMDA launch a public consultation on the draft Digital Infrastructure Bill
Source: Ministry of Digital Development and Information (MDDI) and Infocomm Media Development Authority (IMDA)
https://www.reach.gov.sg/latest-happenings/public-consultation-pages/2026/public-consultation-on-digital-infrastructure-bill/
MAS, financial institutions and fintech firms jointly publish the white paper Safeguards for Agentic Finance at Runtime (SAFR)
Source: Monetary Authority of Singapore (MAS)
https://www.mas.gov.sg/news/media-releases/2026/mas-partners-industry-to-develop-safeguards-for-ai-agents-in-finance
Japan: Japan’s PPC publishes its 2025 annual report
Source: Personal Information Protection Commission of Japan (PPC)
https://www.ppc.go.jp/news/press/2026/260707/
Germany: Germany’s BSI releases a community draft of the A5 assessment framework for trustworthy AI systems
Source: German Federal Office for Information Security (BSI)
https://www.bsi.bund.de/DE/Service-Navi/Presse/Pressemitteilungen/Presse2026/260706_KI_A5-Community-Draft.html
Italy: Italy’s data protection authority fines Character.AI EUR 158,000 and requires stronger age verification for minors
Source: Italian Data Protection Authority (Garante)
https://www.garanteprivacy.it/home/docweb/-/docweb-display/docweb/10269594
Ireland: Ireland’s NCSC publishes cyber governance guidance for management boards of NIS2 entities
Source: National Cyber Security Centre of Ireland (NCSC)
https://www.gov.ie/en/department-of-justice-home-affairs-and-migration/press-releases/ncsc-launches-cyber-governance-guidance-for-management-boards-in-nis2-organisations/
Netherlands: The Dutch Senate passes the Cybersecurity Act (Cyberbeveiligingswet) and the Critical Entities Resilience Act (Wet weerbaarheid kritieke entiteiten)
Source: Senate of the Netherlands
https://www.eerstekamer.nl/wetsvoorstel/36764_cyberbeveiligingswet
Romania:
Romania’s ANSPDCP fines Banca Transilvania S.A. RON 26,172 after an employee accessed customer bank account information without authorisation at the request of a third party, violating Article 32 GDPR
Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP)
https://www.dataprotection.ro/?page=Comunicat_Presa_02_07_2026
Romania’s ANCOM launches a public consultation on draft national legislation implementing the EU Data Act
Source: National Authority for Management and Regulation in Communications of Romania (ANCOM)
https://www.ancom.ro/en/about-us/media-en/press-releases/data-act-draft-law-on-the-application-of-rules-regarding-access-to-data-generated-by-connected-products-and-related-services-open-for-public-consultation/
Slovenia:
The Slovenian Information Commissioner issues an opinion on the use of video analytics in video surveillance at public events
Source: Slovenian Information Commissioner
https://www.ip-rs.si/mnenja-zvop-2/uporaba-analitike-ob-izvajanju-videonadzora-1782991368
The Slovenian Information Commissioner issues an opinion on data protection compliance for mobile applications
Source: Slovenian Information Commissioner
https://www.ip-rs.si/mnenja-zvop-2/mnenje-informacijskega-poobla%C5%A1%C4%8Denca-1783332593
The Slovenian Information Commissioner issues a data protection opinion on an emergency NFC/QR project
Source: Slovenian Information Commissioner
https://www.ip-rs.si/mnenja-zvop-2/skladnost-projekta-s-predpisi-s-podro%C4%8Dja-varstva-osebnih-podatkov
The Administrative Court again confirms that systematic GPS tracking of employees is impermissible without a valid reason
Source: Slovenian Information Commissioner
https://www.ip-rs.si/novice/upravno-sodi%C5%A1%C4%8De-znova-potrdilo-prakso-ip-sistemati%C4%8Dno-gps-sledenje-zaposlenim-ni-dopustno-brez-tehtnega-razloga-1783415931
Sweden:
NCSC releases its 2025 annual report
Source: Swedish National Cyber Security Centre (NCSC)
https://www.ncsc.se/sv/aktuellt/arsberattelse-2025/
NCSC publishes information on new cybersecurity rules for essential services
Source: Swedish National Cyber Security Centre (NCSC)
https://www.ncsc.se/sv/aktuellt/krav-pa-sakerhetsatgarder-som-starker-cybersakerheten/
Croatia:AZOP initiates an urgent supervisory procedure in relation to the CARNET data breach
Source: Croatian Radiotelevision (HRT)
https://vijesti.hrt.hr/hrvatska/curenje-podataka-azop-pokrenuo-zurni-nadzor-nad-carnet-om-12790776
Turkey: KVKK publishes a principle decision on the processing of personal data of accident victims
Source: Official Gazette of Turkey
https://www.resmigazete.gov.tr/eskiler/2026/07/20260701-15.pdf
Hong Kong, China:Hong Kong launches an “AI sandbox for personal data protection” for AI application scenarios in primary and secondary schools
Source: Office of the Privacy Commissioner for Personal Data, Hong Kong
https://www.pcpd.org.hk/english/news_events/media_statements/press_20260706.html
Note
本文由Gen AI翻译,仅供参考。
Translated by Gen AI service. For reference only.
本期编辑:吴小旭 陈煜烺 陈曦宇 颜宇涵 张膑月 季开 张丽

