September brought new privacy and security obligations into force across Europe, North America and Asia. Applicability thresholds are falling, penalties are rising and regulators are holding firm on enforcement dates.
Europe and the UK
The EU Cyber Resilience Act reporting requirements came into force from September 11, requiring software providers to report actively exploited vulnerabilities and severe incidents. Meanwhile, under the UK’s Data (Use and Access) Act in 2025, the ICO becomes the Information Commission from September 30. While existing obligations remain for organizations, this change means published privacy notices and policies may need updating to reflect the new entity.
North America
Several changes to state privacy laws came into effect from July 1, 2026, including Connecticut, Arkansas, Virginia and Utah.
Most significantly, Connecticut lowered the threshold for applicability of its Data Privacy Act (CTDPA) for organizations from 100,000 consumers to 35,000, bringing thousands more businesses into scope of the legislation.
Similar changes have been enacted in Delaware via House Bill 380, signed September 2, reducing general applicability thresholds from 35,000 to 10,000 consumers, among other changes, coming into force from January 1, 2027.
Asia
South Korea’s PIPA amendments promulgated in March this year became enforceable from September 11. Under the changes, organizations must notify individuals without delay when they identify a potential breach. Additionally, the maximum penalty cap has been increased to 10% (from 3%) of total turnover, along with personal supervisory liability for the CEO.
Meanwhile, India’s MeitY confirmed that the enforcement timelines established for DPDP Act compliance will not be extended. The earliest obligations come into force from November 13, 2026 and full applicability from May 13, 2027.
To find out how Ground Labs can help you discover and protect personal information for privacy compliance, book a call with one of our experts today.