This month’s privacy news roundup highlights the continuing drive to regulate personal data use in AI across global markets, tightening rules for data brokers in the US. Australia reported an all-time high for breach notifications in 2025, highlighting the ongoing value of personal data to cybercriminals.
Europe and the UK
The European Data Protection Board (EDPB) has opened a public consultation for its guidelines on web scraping in the context of generative AI. The guidelines place responsibility on data controllers - those capturing the data through web scraping - to uphold purpose limitation and minimization principles. Organizations need to have mechanisms in place to control the data being collected before model development begins and before web content is ingested by the model. This includes verifying whether scraped datasets contain personal or sensitive information and replacing it with synthetic data or excluding it from the model.
Meanwhile, the UK’s new data protection complaints requirements came into force. The new law requires organizations to offer a clear way to report data protection complaints, and acknowledge the complaint within 30 days. In an update published on 23 July, the ICO noted that more than two thirds of businesses aware of the country’s new Data (Use and Access) Act don’t know that the law applies to them. Twelve months on from commencement of the DUAA, all provisions are now in force.
North America
From August 1, registered data brokers will be required to process deletion requests submitted through California’s Delete Request and Opt-out Platform. DROP allows residents to send a single request to more than 600 brokers, which must then identify matching records and delete the relevant personal information. This means data brokers will need to locate records across multiple systems, resolve identities using the available identifiers, address copies and derived data and prevent deleted information from being repopulated through later collection.
New Jersey has introduced similar legislation requiring data brokers and data collectors to participate in an annual registration and disclosure process. This includes certain businesses that have a direct relationship with consumers but sell personal data to data brokers. The law also restricts the sale or licensing of sensitive personal data and introduces substantial registration fees and penalties.
Asia
Singapore’s PDPC has published guidelines on the use of personal data in generative AI. The guidance clarifies how the PDPA applies to personal data throughout the development, deployment and integration of AI systems. They also outline the data responsibilities of key AI stakeholders and how organizations should handle individual requests concerning the processing of their data in AI models.
Elsewhere, South Korea’s PIPC issued administrative fines against three organizations for failing to implement adequate safeguards that resulted in theft of personal information affecting more than 1.5 million people.
Australia
The Office of the Australian Information Commissioner (OAIC) reported that data breach notifications increased to an all-time high in 2025. The Commissioner’s office received 1,205 breach notifications, representing an 8% increase over 2024. A majority of breaches were the result of malicious or criminal activity, with healthcare organizations the most commonly targeted. Healthcare accounted for almost 20% of all notifications, followed by financial services (13%).
Separately, more organizations are now in scope of expanded anti-money laundering / Counter-terrorism financing (AML/CTF) controls, including lawyers, accountants and real estate companies. Organizations under the regime need to complete stringent identity verification checks. However, once checks are complete they should not continue retaining full identity documents as part of AML/CTF recordkeeping.
To find out how Ground Labs can help you discover and protect personal information for privacy compliance, request a demo or book a call with one of our experts today.