<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Data Compliance &amp; AI Law</title><link>https://ai.intlaws.com/en/</link><description>Recent content on Data Compliance &amp; AI Law</description><generator>Hugo</generator><language>en</language><lastBuildDate>Thu, 24 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://ai.intlaws.com/en/index.xml" rel="self" type="application/rss+xml"/><item><title>Case Collection — US CalPrivacy Data Broker Enforcement: Datamasters (Unregistered Data Broker)</title><link>https://ai.intlaws.com/en/cases/%E7%BE%8E%E5%9B%BD-calprivacy%E6%95%B0%E6%8D%AE%E7%BB%8F%E7%BA%AA%E6%89%A7%E6%B3%95-datamasters%E6%A1%88/</link><pubDate>Thu, 24 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/cases/%E7%BE%8E%E5%9B%BD-calprivacy%E6%95%B0%E6%8D%AE%E7%BB%8F%E7%BA%AA%E6%89%A7%E6%B3%95-datamasters%E6%A1%88/</guid><description>The California Privacy Protection Agency (CPPA / CalPrivacy) Board decided that Rickenbacher Data LLC (d/b/a Datamasters) violated the California Delete Act by failing to register as a data broker: a USD 45,000 fine and a ban on selling Californians&amp;rsquo; personal information. Case number and signature date verified against the archived original (2026-09-24).</description></item><item><title>Case Collection — US CalPrivacy Data Broker Enforcement: S&amp;P Global (Unregistered Data Broker)</title><link>https://ai.intlaws.com/en/cases/%E7%BE%8E%E5%9B%BD-calprivacy%E6%95%B0%E6%8D%AE%E7%BB%8F%E7%BA%AA%E6%89%A7%E6%B3%95-spglobal%E6%A1%88/</link><pubDate>Thu, 24 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/cases/%E7%BE%8E%E5%9B%BD-calprivacy%E6%95%B0%E6%8D%AE%E7%BB%8F%E7%BA%AA%E6%89%A7%E6%B3%95-spglobal%E6%A1%88/</guid><description>The California Privacy Protection Agency (CPPA / CalPrivacy) Board decided that S&amp;amp;P Global, Inc. failed to register as a data broker due to an administrative error: a USD 62,600 fine plus registration and compliance-audit procedures. Digital signature date 2025-12-30 extracted from the decision&amp;rsquo;s signature panel; case number verified (2026-09-24).</description></item><item><title>Colorado SB 26-189 (Artificial Intelligence Amendment to the Colorado Privacy Act)</title><link>https://ai.intlaws.com/en/compliance/us/%E7%A7%91%E7%BD%97%E6%8B%89%E5%A4%9Asb26-189/</link><pubDate>Thu, 24 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/us/%E7%A7%91%E7%BD%97%E6%8B%89%E5%A4%9Asb26-189/</guid><description>Official session-law text of Colorado SB 26-189 (Chapter 131, Laws of 2026), approved May 14, 2026: an amendment to the Colorado Privacy Act governing the use of artificial intelligence in consequential decisions. Obligations apply to consequential decisions made on or after January 1, 2027. English original; Chinese translation available.</description></item><item><title>General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679</title><link>https://ai.intlaws.com/en/compliance/eu/gdpr/</link><pubDate>Thu, 24 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/eu/gdpr/</guid><description>Official English text of Regulation (EU) 2016/679 (General Data Protection Regulation), as published in the Official Journal: 11 chapters, 99 articles and 173 recitals. The authentic languages of EU law are the official EU languages; there is no official Chinese text.</description></item><item><title>UK Data (Use and Access) Act 2025 — Part 5 (Data Protection and Privacy)</title><link>https://ai.intlaws.com/en/compliance/other/%E8%8B%B1%E5%9B%BD-duaa2025-part5/</link><pubDate>Thu, 24 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/other/%E8%8B%B1%E5%9B%BD-duaa2025-part5/</guid><description>Official text of Part 5 (Data Protection and Privacy) of the UK Data (Use and Access) Act 2025, comprising Chapter 1 (Data protection, sections 66–108) and Chapter 2 (PECR reform, sections 109–116): 51 sections in total. English original from legislation.gov.uk; Chinese translation in progress.</description></item><item><title>Case Collection | AI and Data Protection Enforcement in the United States (First Batch: FTC and CalPrivacy)</title><link>https://ai.intlaws.com/en/cases/us-enforcement-first-batch/</link><pubDate>Wed, 23 Sep 2026 00:30:00 +0800</pubDate><guid>https://ai.intlaws.com/en/cases/us-enforcement-first-batch/</guid><description>First batch of five enforcement/penalty cases from U.S. federal and California regulators in the fields of artificial intelligence, data privacy and data brokerage: three from the Federal Trade Commission (FTC) — accuracy claims for AI content detection, an AI-enabled review platform, and an AI security-screening system — and two from the California Privacy Protection Agency (CalPrivacy, formerly CPPA) — CCPA privacy-notice violations and data-broker registration violations. Each entry carries the four required elements, with holdings quoted verbatim from official documents and direct official links.</description></item><item><title>Measures for Standard Contract for Outbound Transfer of Personal Information</title><link>https://ai.intlaws.com/en/compliance/china/personal-information-exit-standard-contract/</link><pubDate>Wed, 23 Sep 2026 00:30:00 +0800</pubDate><guid>https://ai.intlaws.com/en/compliance/china/personal-information-exit-standard-contract/</guid><description>English translation of China&amp;rsquo;s Measures for Standard Contract for Outbound Transfer of Personal Information (CAC Order No. 13, adopted 3 February 2023, effective 1 June 2023). Unofficial translation, for reference only.</description></item><item><title>Regulation (EU) 2024/1689 — Artificial Intelligence Act</title><link>https://ai.intlaws.com/en/compliance/eu/eu-ai-act-full-text/</link><pubDate>Wed, 23 Sep 2026 00:30:00 +0800</pubDate><guid>https://ai.intlaws.com/en/compliance/eu/eu-ai-act-full-text/</guid><description>Official Englishof Regulation (EU) 2024/1689 (Artificial Intelligence Act) as published in the Official Journal of the European Union (OJ L, 12.7.2024): 13 chapters, 113 articles and 13 annexes, reproduced verbatim from EUR-Lex. Unofficial Chinese translation pending.</description></item><item><title>California Transparency in Frontier Artificial Intelligence Act (TFAIA)</title><link>https://ai.intlaws.com/en/compliance/us/california-sb-53/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/us/california-sb-53/</guid><description>Official text of California Senate Bill 53 (2025–2026 session), which adds transparency and incident-reporting duties for developers of large frontier artificial intelligence models — amending the Business and Professions Code (new Chapter 25.1, commencing with Section 22757.10), the Government Code (Section 11546.8) and the Labor Code (new Chapter 5.1, commencing with Section 1107). Registered with the Secretary of State on 29 September 2025.</description></item><item><title>Convention 108</title><link>https://ai.intlaws.com/en/compliance/intl/coe-convention-108/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/intl/coe-convention-108/</guid><description>Official English text of the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (ETS No. 108), opened for signature in Strasbourg on 28 January 1981 — the first binding international instrument on data protection, comprising 20 articles. The Convention as modernised by Protocol CETS No. 223 (&amp;ldquo;Convention 108+&amp;rdquo;) is published separately in this library.</description></item><item><title>Cybersecurity Law of the People's Republic of China (2025 Amendment)</title><link>https://ai.intlaws.com/en/compliance/china/csl/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/china/csl/</guid><description>Full text of the Cybersecurity Law of the People&amp;rsquo;s Republic of China as amended on 28 October 2025 (effective 1 January 2026), 81 articles in seven chapters: the new Article 3 (CPC leadership and the holistic approach to national security), the new Article 20 on artificial intelligence, the new Article 63 on penalties for uncertified critical network equipment, and the substantially raised penalty caps (up to RMB 10 million). English translation by our editorial team (non-official).</description></item><item><title>Data Security Law of the PRC</title><link>https://ai.intlaws.com/en/compliance/china/dsl/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/china/dsl/</guid><description>Officialof the Data Security Law of the PRC: 7 chapters, 55 articles, adopted 2021-06-10, in force 2021-09-01. English text from the NPC official English site (marked &amp;ldquo;Translation for Reference Only&amp;rdquo;); Chinese original from the Cyberspace Administration of China.</description></item><item><title>Executive Order 14365</title><link>https://ai.intlaws.com/en/compliance/us/executive-order-14365/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/us/executive-order-14365/</guid><description>Official text of Executive Order 14365 of 11 December 2025, &amp;ldquo;Ensuring a National Policy Framework for Artificial Intelligence&amp;rdquo;, published at 90 FR 58499 (16 December 2025), nine sections: policy of a minimally burdensome national AI framework, an AI Litigation Task Force, a Commerce Department evaluation of State AI laws, restrictions on State funding (BEAD, discretionary grants), an FCC proceeding on a Federal reporting and disclosure standard, an FTC policy statement on preemption, and a legislative recommendation that does not preempt State laws on child safety, AI compute/data-centre infrastructure, State procurement, and other topics as determined.</description></item><item><title>Interim Measures for the Administration of Generative Artificial Intelligence Services</title><link>https://ai.intlaws.com/en/compliance/china/generative-ai-interim-measures/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/china/generative-ai-interim-measures/</guid><description>Full text of the Interim Measures for the Administration of Generative Artificial Intelligence Services (promulgated 10 July 2023, effective 15 August 2023), 24 articles in five chapters: scope, training-data obligations, provider duties, obligations to users, security assessment and algorithm filing for services with public-opinion or social-mobilisation attributes, and penalties. English translation by our editorial team (non-official, cross-checked article by article against the official Chinese text).</description></item><item><title>Japan's Act on Promotion of Research, Development and Utilization of AI-Related Technologies (Act No. 53 of 2025)</title><link>https://ai.intlaws.com/en/compliance/other/japan-ai-promotion-act/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/other/japan-ai-promotion-act/</guid><description>Official Japanese text of the Act on Promotion of Research, Development and Utilization of AI-Related Technologies (Act No. 53 of 2025, promulgated 4 June 2025), 28 articles in four chapters plus 2 supplementary provisions. The Japanese text below is the authoritative version taken from the official e-Gov database; the English translation is prepared by this journal and is unofficial and for reference only.</description></item><item><title>Korea's Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust (AI Framework Act)</title><link>https://ai.intlaws.com/en/compliance/other/korea-ai-framework-act/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/other/korea-ai-framework-act/</guid><description>Official Korean text of the Framework Act on the Development of Artificial Intelligence and the Creation of a Foundation for Trust (Act No. 20676, promulgated 21 January 2025; in force 22 January 2026; amended by Act No. 21311 of 20 January 2026), six chapters and two sections, 43 articles plus three sub-numbered articles, with three sets of addenda. The English text on this page is the official translation by the Korea Legislation Research Institute (KLRI). The Korean text is authoritative.</description></item><item><title>Measures for the Labelling of AI-Generated Synthetic Content</title><link>https://ai.intlaws.com/en/compliance/china/ai-generated-content-labelling-measures/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/china/ai-generated-content-labelling-measures/</guid><description>Full text of the Measures for the Labelling of AI-Generated Synthetic Content (promulgated 14 March 2025, effective 1 September 2025), 14 articles: definitions of explicit and implicit labels, labelling duties across six content scenarios, verification duties of dissemination platforms, and the prohibition on providing tools that remove labels. English translation by our editorial team (non-official, cross-checked article by article against the official Chinese text).</description></item><item><title>Measures for the Security Assessment of Data Export</title><link>https://ai.intlaws.com/en/compliance/china/data-export-security-assessment-measures/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/china/data-export-security-assessment-measures/</guid><description>Full text of the Measures for the Security Assessment of Data Export (Cyberspace Administration of China Order No. 11, promulgated 7 July 2022, effective 1 September 2022), 20 articles: the triggers for filing, the self-assessment of risks, materials required, the assessment factors, mandatory clauses in legal documents, the 45-working-day time limit, and the two-year validity of assessment results. English translation by our editorial team (non-official, cross-checked article by article against the official Chinese text).</description></item><item><title>Personal Information Protection Law of the PRC</title><link>https://ai.intlaws.com/en/compliance/china/pipl/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/china/pipl/</guid><description>Officialof the Personal Information Protection Law of the PRC: 8 chapters, 74 articles, adopted 2021-08-20, in force 2021-11-01. English text as published on the NPC official English site (marked &amp;ldquo;Translation for Reference Only&amp;rdquo;).</description></item><item><title>Protocol amending Convention 108</title><link>https://ai.intlaws.com/en/compliance/intl/coe-convention-108-plus/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/intl/coe-convention-108-plus/</guid><description>Official English text of Protocol CETS No. 223, which modernises Convention 108 (the &amp;ldquo;Convention 108+&amp;rdquo;) — opened for signature in Strasbourg on 10 October 2018, comprising 40 articles: amendments to Convention 108 article by article (Articles 1–35) and final clauses (Articles 36–40). Per the Council of Europe Treaty Office, it enters into force upon ratification by all Parties to Treaty ETS 108, or, as from 11 October 2023, once 38 Parties to the Convention have ratified it.</description></item><item><title>Provisions on Promoting and Regulating Cross-Border Data Flows</title><link>https://ai.intlaws.com/en/compliance/china/data-cross-border-flow-provisions/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/china/data-cross-border-flow-provisions/</guid><description>Full text of the Provisions on Promoting and Regulating Cross-Border Data Flows (CAC Order No. 16, promulgated and effective 22 March 2024), 14 articles: exemption scenarios, the negative-list mechanism in pilot free trade zones, the thresholds for the security assessment and the standard contract, and the three-year validity of assessment results. English translation by our editorial team (non-official, cross-checked article by article against the official Chinese text).</description></item><item><title>Regulations on the Administration of Network Data Security</title><link>https://ai.intlaws.com/en/compliance/china/network-data-security-regulations/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/china/network-data-security-regulations/</guid><description>Full text of the Regulations on the Administration of Network Data Security (State Council Order No. 790, promulgated 24 September 2024, effective 1 January 2025), 64 articles in nine chapters: classified and graded protection, personal information processing rules, important data (security officer, annual risk assessment), cross-border transfer (assessment, certification, standard contract), obligations of large online platforms, supervision, and penalties of up to RMB 10 million. English translation by our editorial team (non-official).</description></item><item><title>Texas Artificial Intelligence Protection Act</title><link>https://ai.intlaws.com/en/compliance/us/texas-traiga-chapter-552/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/us/texas-traiga-chapter-552/</guid><description>Official text of Chapter 552 (Artificial Intelligence Protection) of the Texas Business &amp;amp; Commerce Code, enacted by HB 149 — the Texas Responsible Artificial Intelligence Governance Act (TRAIGA), effective 1 January 2026. Sixteen sections: definitions, construction, local preemption, disclosure to consumers, prohibition of manipulation of human behaviour, social scoring (governmental entities only), capture of biometric data, constitutional protection, unlawful discrimination, sexually explicit content and child protection, and enforcement by the attorney general (investigations, notice and cure, civil penalties, injunctions).</description></item><item><title>United Nations Convention against Cybercrime</title><link>https://ai.intlaws.com/en/compliance/intl/un-cybercrime-convention/</link><pubDate>Tue, 22 Sep 2026 00:00:00 +0000</pubDate><guid>https://ai.intlaws.com/en/compliance/intl/un-cybercrime-convention/</guid><description>Officialof the UN Convention against Cybercrime (UNGA resolution 79/243, 24 December 2024, annex; 9 chapters, 68 articles). Enters into force on the ninetieth day after deposit of the fortieth instrument of ratification; not yet in force. Text taken from official UN sources.</description></item></channel></rss>