The global data protection landscape has entered a new phase in 2026. For several years the business was able to reasonably treat privacy compliance as a matter of formulating policies, appointing a privacy officer, altering consent language and keeping a watch on new legislation. That approach is progressively harder to defend. Regulators are now going beyond whether an organisation has a privacy policy and asking a more uncomfortable question: can the organisation demonstrate how its data practices work in reality? This shift is manifest across jurisdictions.
The European Union is considering the Digital Omnibus, which proposes significant changes to elements of the GDPR and the overall digital regulatory framework. California's updated privacy regulations have introduced requirements regarding risk assessments, cybersecurity audits and automated decision-making technology. Colorado has replaced its previous AI regulatory framework with a new regime focused on automated decision-making in consequential decisions. The United Arab Emirates has consolidated its artificial intelligence, data and digital-government functions under a new Federal Authority for Artificial Intelligence and Data. India, meanwhile, has finally moved from the Digital Personal Data Protection Act to the operational stage with the notification of the DPDP Rules, 2025.
The important development is therefore not that there are more privacy laws. It is that the nature of compliance itself is changing. Businesses are being pushed towards evidence, governance, risk assessment, accountability and operational controls rather than policies that predominantly exist on paper.
For Indian businesses this is important even for domestic operations. A company that sells products to European consumers, provides services to Californians, uses automated decision-making tools in Colorado or maintains international technology vendors may find itself facing several privacy regimes at the same time. India is now to enter the same regulatory conversation through its DPDP framework.
From Having a Privacy Policy to Proving Compliance
Privacy law has traditionally operated through a blend of statutory obligations, consent requirements, notices, security standards and individual rights. What is changing is the evidential expectation around those obligations.
A corporation may claim that it gathers just essential information, deletes data after its purpose is met, and maintains adequate security precautions. The most essential question in a regulatory examination is whether such assertions can be proven using records, technical controls, contractual arrangements, risk assessments, audit reports, and internal decision making.
This is because modern data ecosystems are rarely confined to a single company. A customer may provide information to an online platform, which may use a cloud service provider, an analytics vendor, a payment processor, an advertising technology company and an artificial intelligence tool. The legal question is no longer who collected the information but also who determines the purposes and means of processing, who receives the information, what each recipient can actually do with it and whether the organisation can demonstrate that the entire chain is governed appropriately.
The Court of Justice of the European Union's decision in EDPS v SRB, Case C-413/23 P, illustrates the complexity particularly well. The case concerned pseudonymised comments submitted by shareholders and creditors in proceedings following the resolution of Banco Popular Español. The Single Resolution Board had transmitted those comments to Deloitte for analysis.
The Court rejected the idea that pseudonymised information is automatically non-personal data for every recipient. At the same time it rejected the opposite proposition that pseudonymised information must always be personal data for every person in every circumstance. The relevant question is whether the individual is identifiable from the perspective of the person processing the information and by means reasonably likely to be used.
Paragraph 68 sets out the central issue, namely whether pseudonymised information should be automatically treated as personal data simply because information exists somewhere that could identify the individual. Paragraph 69 states that application of the regulatory framework requires an examination of whether the data subject is identified or identifiable by the information concerned. Paragraphs 80 to 82 reinforce the importance of the "reasonably likely" test and objective factors such as time, cost, labour and available technology.
The decision becomes particularly important when data moves between organisations. Paragraphs 85 and 86 are clear that pseudonymised data should not be automatically regarded as personal data for every recipient, because pseudonymisation can, depending on circumstances, prevent a recipient from identifying the individual. However the analysis must be conducted in relation to the particular actor and the particular processing operation.
This is not merely a technical distinction. It demonstrates why privacy compliance is increasingly becoming an exercise in documenting how an organisation actually processes information.
Infographic 1: The New Compliance Test
|
Traditional Approach |
Emerging Regulatory Approach |
|
"We have a privacy policy." |
"Show us how the policy operates in practice." |
|
"The data is pseudonymised." |
"Who can actually identify the individual, using what means?" |
|
"Our vendor handles the data." |
"What does the contract require, and what does the vendor actually do?" |
|
"We obtained consent." |
"What information was provided, how was consent obtained, and can it be withdrawn with comparable ease?" |
|
"We have security measures." |
"What technical and organisational safeguards exist, and what evidence demonstrates their operation?" |
|
"Our AI vendor makes the decision." |
"Who deployed the system, what data was used, what decision resulted and what rights does the affected person have?" |
eams are increasingly required to preserve a evidentiary trail rather than just a collection of documents. Data maps, processing records, vendor agreements, risk assessments, deletion schedules, incident records and decision logs are becoming as important to compliance as the privacy notice itself.
Europe
The Digital Omnibus of the European Union is one of the most significant developments to watch because it presents an unusual tension in contemporary privacy regulation. The European Commission seeks to reduce regulatory complexity and compliance costs while maintaining the fundamental objectives of European data protection law.
The Commission's proposal proposes amendments to the GDPR alongside several other pieces of digital legislation. The Commission's stated objective is to simplify the digital rulebook and reduce unnecessary administrative burdens.
It is important, however, not to conflate the Digital Omnibus as if it were already binding law. The GDPR-related Digital Omnibus remains an ongoing legislative proposal. The European Parliament and Council are still required to complete the legislative process. The European Parliament's Legislative Observatory identifies procedure as ongoing.
One of the most debated elements concerns the definition of personal data and the treatment of pseudonymised information. The proposed approach seeks to take greater account of the position of the particular entity processing the data and whether it has reasonable means of identifying the individual.
That debate is particularly interesting after EDPS v SRB. The judgment itself makes clear that the concept of personal data is broad, but not unlimited. Paragraph 88 expressly states that the concept cannot be treated as unlimited because the law still requires the individual to be identified or identifiable. Paragraph 89 further recognises that some obligations cannot logically be imposed upon an entity that is in no position to identify the data subject.
The significance of this decision extends beyond pseudonymisation. It reinforces a broader principle that privacy law cannot be separated from the factual architecture of a data-processing operation. The same dataset can create different legal questions depending upon who holds it, what additional information is available to that person and what means of identification are realistically accessible.
There is another important judgment in this field, IAB Europe v Gegevensbeschermingsautoriteit, the case concerned the Transparency and Consent String, a technical string recording a user's consent preferences within the advertising ecosystem. The Court held that such a string can constitute personal data where it can, by reasonable means, be associated with an identifier such as an IP address.
Paragraphs 44 to 50 are particularly useful. Paragraph 45 explains that the string becomes personal data where its association to additional information permits identification. Paragraph 46 makes clear that the fact that IAB Europe could not itself combine the string with the IP address did not necessarily take the information outside the GDPR. Paragraph 49 focuses on the availability of reasonable means of identification, while paragraph 50 confirms the conclusion that the TC String constituted personal data.
The lesson for businesses is that technical separation does not necessarily equal legal separation. Removing a name from a dataset is not the end of the analysis. People need to understand what other identifiers exist, who can access them and whether those identifiers can realistically be combined.
California
California's developments illustrate another side of the regulatory shift. The California Privacy Protection Agency adopted regulations covering CCPA updates, cybersecurity audits, risk assessments and automated decision-making technology. The regulations became effective on January of this year, although several requirements have staggered compliance dates.
Risk assessment requirements are particularly significant because they move privacy compliance towards an explicit risk-management model. Certain businesses must assess processing activities that present significant risks to consumers' privacy. The organisation is therefore expected to consider not merely whether a processing activity is legally permissible, but also what risks the activity creates and what measures are appropriate to mitigate those risks.
Cybersecurity audits add another layer. The regulatory framework requires certain businesses to conduct annual cybersecurity audits, with certification deadlines that vary according to revenue. The California Privacy Protection Agency has specified deadlines beginning in 2028 for submitting certifications.
The automated decision-making provisions are equally important, but the timing needs to be stated accurately. The regulations took effect this year, yet businesses using ADMT for significant decisions have until January 2027 for the applicable ADMT requirements.
The broader legal development is nevertheless clear. Artificial intelligence is increasingly being treated not simply as a technology issue but as a data governance issue. If an automated system influences employment, housing, education, healthcare or another significant area in a person's life, privacy law is increasingly concerned with what happens behind the system's output.
Colorado
Colorado provides an important example of how rapidly AI regulation can change before an earlier framework has fully matured.
Senate Bill 26-189, titled the Automated Decision-Making Technology Act, became a law very recently in May of this year. The legislation repealed and reenacted the earlier framework with new requirements concerning automated decision-making technology in consequential decisions.
The enacted framework defines automated decision-making technology broadly as technology that processes personal data and uses computation to generate outputs such as predictions, recommendations, classifications, rankings or scores that are used to make, guide or assist a decision concerning an individual.
The law creates rights that are particularly relevant from a litigation perspective. A consumer affected by a covered consequential decision can obtain information concerning the system's role, request personal data and correction of factually incorrect personal data, and request meaningful human review and reconsideration following an adverse outcome.
The substantive obligations apply from 1 January 2027. This is another point where the original LinkedIn summary requires qualification. The legislation became law in May 2026, but its principal substantive duties are not simply equivalent to obligations becoming enforceable on the date of enactment.
The Colorado development is significant because it illustrates that the regulatory debate around AI is moving towards accountability for consequential decisions rather than focusing exclusively on the underlying model. The question is increasingly what the technology does to a person, not merely what technology the company happens to use.
India
For Indian businesses the most important development is the notification of the DPDP 25'
The Rules were notified by the MEIT in November last year. The commencement in structure is deliberately staggered. Rules 1, 2 and 17 to 21 came into force upon publication. Rule 4, concerning Consent Managers, is scheduled to come into force in November of this year. Rules 3, 5 to 16, 22 and 23 are scheduled to come into force in May 2027. The statutory timetable is more precise. Rule 4 becomes operative this year, while the principal operational rules follow in May of the next year.
That does not mean Indian businesses should wait until May 2027 to begin compliance work. The 18 month implementation period is precisely what makes early preparation commercially sensible.
The DPDP Rules introduce considerably more operational detail than the bare framework of the 2023 Act. Rule 3, for example, requires notices to be independently understandable and to be written in clear and plain language. The notice must include an itemised description of personal data and the specified purpose or purposes for processing. It must also include a mechanism through which the Data Principal can withdraw consent, exercise statutory rights and make a complaint to the Board.
This has an important implication for Indian businesses. A generic privacy policy buried behind several links may not be sufficient if the actual notice provided at the point of collection fails to communicate the relevant information clearly.
The Rules also impose detailed obligations around security safeguards, retention and breach management. For example Rule 7 deals with reasonable security safeguards and requires measures directed towards preventing unauthorised access and responding to compromise. Certain logs and personal data are required to be retained for specified purposes and periods. Rule 8 separately addresses circumstances in which the specified purpose is deemed to have been served and the resulting erasure obligations.
Significant Data Fiduciaries face a further compliance layer. Rule 13 requires a Significant Data Fiduciary to undertake a Data Protection Impact Assessment and an audit once in every twelve-month period from the relevant notification or classification.
The financial consequences of non-compliance are also substantial. Section 33 read with the Schedule to the DPDP Act permits penalties extending to ₹250 crore for failure to take reasonable security safeguards to prevent a personal data breach, ₹200 crore for failure to notify a personal data breach as required, ₹200 crore for specified child-related breaches and ₹150 crore for certain failures by Significant Data Fiduciaries. Other breaches may attract penalties extending to ₹50 crore.
The significance of the Indian regime becomes clearer when viewed alongside the constitutional jurisprudence on privacy.
In Justice K.S. Puttaswamy (Retd.) v UOI the Supreme Court recognised privacy as a constitutionally protected right and explained the conditions under which an invasion of privacy may be justified. Paragraph 180 of the judgement identifies the requirements of legality, legitimate state aim and proportionality. The larger constitutional discussion ultimately became an important foundation for India's later statutory movement towards data protection.
The constitutional position therefore predates the DPDP Act. The statutory regime should not be understood as creating the Indian concept of informational privacy from nothing. It gives a legislative structure to a field that had already acquired constitutional significance.
Infographic 2: India's DPDP Implementation Clock
|
Date |
What Happens |
|
13 November 2025 |
DPDP Rules, 2025 notified by MeitY, with selected provisions taking effect immediately. |
|
13 November 2026 |
Rule 4 concerning registration and obligations of Consent Managers becomes operative. |
|
13 May 2027 |
Rules 3, 5 to 16, 22 and 23 become operative, bringing the principal operational compliance framework into effect. |
|
Continuing obligation |
Organisations should use the transition period to map data, revise notices, review vendors, build rights-management processes and establish security controls. |
What the Global Developments Have in Common
Although these jurisdictions do not apply identical regulatory models, there is a common thread running through them. Regulators are becoming less interested in privacy as a document and more interested in privacy as an organisational function.
That distinction is particularly important for businesses operating across borders. A multinational organisation cannot realistically maintain five entirely separate compliance programmes without substantial duplication. At the same time, assuming that one global privacy policy will automatically satisfy every jurisdiction is equally risky. The better approach is to identify the common operational controls that can support multiple legal regimes while maintaining jurisdiction specific overlays where necessary.
Data inventories are an obvious example. A properly maintained data inventory can help an Indian data fiduciary understand its processing activities while helping a company respond to GDPR obligations or California risk-assessment requirements. Vendor due diligence can similarly aid compliance across several jurisdictions, since almost every modern privacy regime places importance on understanding what third parties do with personal data.
The same is true of incident response. A company that waits until a breach occurs before determining which systems contain personal data, which vendors have access to those systems and who is responsible for regulatory notification has already lost valuable time.
Artificial intelligence further complicates the issue. Business entities have increasingly been implementing artificial intelligence systems within marketing, customer service, anti-fraud schemes, credit analysis, employment screening, healthcare, and decision-making processes.. Before the AI system is implemented, the legal department frequently doesn't even have full knowledge about it. Maintaining that model is getting harder and harder.
The privacy consequences of an AI system processing personal data must be taken into account during the procurement process. If it makes or materially influences a consequential decision, additional AI-specific obligations may arise. If the system is operated by a vendor, the contract must establish responsibilities clearly.
If the system generates an adverse decision, the organisation may need to explain how that decision was reached and provide some form of human review, depending on the applicable law. This is where legal, compliance, technology and information-security teams can no longer work in isolation.
A Lawyer's Perspective
Speaking to LCI, Adv Amritesh Singh stated that "One thing I would tell businesses is that privacy compliance cannot be treated as a policy-writing exercise anymore. When a client tells me that they are GDPR compliant, DPDP compliant or CCPA compliant, my next question is usually very simple, that show me what happens to the data after it enters your system. That is where the real compliance story begins.
He further said that “The challenging aspect is that companies frequently lack a single individual who can provide a comprehensive response to that issue. The IT team is aware of the infrastructure, the legal team is aware of the legislation, the security team is aware of the controls, and the business team is aware of the initial purpose of data collection. There will always be gaps unless those pieces are put together.”
Lastly he said that “Additionally, I believe that businesses should take these rules seriously without waiting for an enforcement notification. It is too late to begin producing records by the time a regulator requests them. The better approach is to build the evidence while the processing is happening. If you can explain what data you collect, why you collect it, who receives it, how long you retain it, what happens if something goes wrong and who is accountable for each decision, you are already in a much stronger position."
The Compliance Question Businesses Should Be Asking in 2026
For businesses, asking to be "compliant" with a particular privacy law is becoming a much less useful way of approaching data protection. Compliance with data protection laws cannot be reduced simply to the existence of a privacy policy, the presence of a consent management tool, and a data protection officer.
Even if all of the above is present, the company is still not ready to respond to requests from users about what information is known about them. The specifics of personal data processing, where it is located, with whom it is shared, how long it is stored, how its owner can exercise his or her rights, etc. Moreover, not even a formal statement of compliance with the law is required but specific evidence that the actual processing activities taking place are consistent with it.
This is especially important because modern businesses rarely control personal data in a single technological environment. Information collected through a website may subsequently move to a customer relationship management platform, a cloud service provider, a payment processor, an analytics company and several other vendors. A company may therefore believe that it has outsourced part of its data-processing operation without appreciating that outsourcing does not necessarily eliminate its regulatory responsibilities.
The legal department needs to know what the relevant contractual arrangements provide, the technology team needs to know where the information is actually moving and the business team needs to be able to explain why the processing is taking place in the first place. Where these functions operate independently, the organisation can easily end up with the privacy policy describing one system while the actual business operates another.
The same problem becomes considerably more serious when artificial intelligence is introduced into the process. Companies are increasingly using automated systems for recruitment, customer profiling, fraud detection, credit assessment, marketing, employee monitoring and other functions that can materially affect individuals. The legal analysis cannot stop at asking whether the company uses an AI model.
It must examine what personal information the system receives, the purpose for which that information is processed, whether the system produces a recommendation or an actual decision, whether a human being reviews its output and what happens when an individual challenges the resulting decision. The regulatory developments in California and Colorado demonstrate why this distinction matters. Automated decision-making is no longer being treated solely as an issue for technology teams. In certain circumstances, it has become a question of individual rights, organisational accountability and legal risk.
This is also why businesses should be cautious about treating privacy compliance as something that begins only after a regulator asks questions. By that stage, the organisation may already be required to reconstruct months or years of processing activity from incomplete records. A company that maintains accurate data inventories, vendor records, retention schedules, security documentation and decision-making records while its operations are running is in a much stronger position than one that attempts to create those records after an investigation or data breach has occurred. The difference is not merely administrative. Good documentation can demonstrate that an organisation understood the risks associated with its processing and took reasonable steps to address them, whereas the absence of documentation can make even a defensible processing activity considerably harder to explain.
India's transition under the DPDP framework makes this especially relevant for Indian companies. The notification of the DPDP Rules, 2025 gives organisations a defined period in which to examine their existing practices before the principal operational provisions take effect. That period should not be treated as a reason to postpone compliance. It provides an opportunity to identify the personal data being collected, examine whether existing notices accurately describe the purposes of processing, review arrangements with Data Processors, establish workable retention and deletion mechanisms and determine how requests from Data Principals will actually be handled. These are operational questions, and they cannot be answered adequately by the legal team alone.
Finally, the true test of a privacy program is whether the organization can tell a consistent story about a piece of personal data from the moment it enters the firm until it is destroyed or otherwise lawfully kept. If the company can identify why the information was collected, establish the legal basis or statutory justification for its processing, identify every material recipient, explain the safeguards used, and demonstrate what happens when the purpose of processing is met, it has the foundations of a functioning compliance program. If it can merely generate a privacy policy stating that these things occur, it has a paper, but not a compliance system.
Frequently Asked Questions
Is the EU Digital Omnibus already law?
No. The European Commission proposed the Digital Omnibus in November 2025, but the GDPR-related proposal remains under the EU legislative process as of September 2026. Businesses should therefore distinguish between the existing GDPR and proposed amendments.
When do the main DPDP Rules become operational in India?
The Rules were notified on 13 November 2025. Rule 4 concerning Consent Managers becomes operative on 13 November 2026, while Rules 3, 5 to 16, 22 and 23 become operative eighteen months after publication, on 13 May 2027.
Did California's ADMT obligations all become applicable on 1 January 2026?
No. The regulations became effective on 1 January 2026, but the applicable ADMT requirements for significant decisions have a compliance date of 1 January 2027.
Why is EDPS v SRB important for privacy lawyers?
The judgment provides important guidance on pseudonymised information and the concept of identifiability. Paragraphs 68 to 89 are particularly relevant to the Court's treatment of pseudonymised data, while paragraphs 105 to 112 address the timing and perspective relevant to information obligations concerning recipients.
Does pseudonymisation automatically take information outside data protection law?
No. EDPS v SRB makes clear that pseudonymisation does not automatically produce the same legal result for every actor. The question depends upon whether the person processing the information can identify the individual using means reasonably likely to be used in the circumstances. Paragraphs 68, 69, 80, 82 and 86 are particularly important on this point.
What should businesses do before the Indian DPDP framework becomes fully operational?
Businesses should use the transition period to map personal data, identify purposes of processing, review notices and consent mechanisms, examine processor contracts, establish retention and deletion practices, strengthen breach-response procedures and determine whether their operations could fall within the Significant Data Fiduciary framework. The Rules themselves provide detailed requirements concerning notices, security safeguards, retention, children's data and DPIAs.
Conclusion
The privacy landscape in 2026 is not simply expanding. It is becoming more operational.
The important regulatory developments across Europe, California, Colorado, India and the UAE show a common movement away from privacy compliance as a static legal document and towards privacy compliance as an ongoing governance function. The organisations that recognise this shift early will have a significant advantage because they will be able to identify problems before a regulator, customer or litigant identifies them first.
For businesses, the real test of privacy compliance is increasingly not what the privacy policy promises. It is whether the organisation can prove that its systems, contracts, people and processes actually do what the policy says.
That is likely to be the defining privacy question of the next phase of digital regulation
Join LAWyersClubIndia's network for daily News Updates, Judgment Summaries, Articles, Forum Threads, Online Law Courses, and MUCH MORE!!"
Tags :Others
