If you’ve ever said, “I’ll focus on GDPR and sort out the rest later,” the developments of June and July 2026 are a useful reality check on how that strategy is aging.
Three developments unfolded across different legal systems and different dates: a U.S. consumer-reporting enforcement matter, Japan’s promulgation of major amendments to its privacy law, and a Dutch court’s interim ruling in an LLM-related GDPR investigation. Different jurisdictions. Different legal mechanisms. Different stages of enforcement maturity. Read together, they show that regulatory pressure is arriving through enforcement, legislation, and judicial oversight – not from one direction.
The US: the basics still bite
The FTC-referred DOJ matter involving RentGrow, a tenant-screening consumer reporting agency, is a useful example of longstanding consumer-reporting obligations. The complaint alleged that RentGrow failed to maintain reasonable procedures to ensure maximum possible accuracy, failed to disclose all information and data sources when consumers requested them, and failed to follow required procedures for handling disputes. It also alleged, under the FTC Act, that RentGrow misled some consumers about whether property managers had been notified after successful disputes. A proposed stipulated order calls for a $2.25 million civil penalty.
That’s worth sitting with. The accuracy, source-disclosure, and dispute-investigation allegations arose under the FCRA; the alleged misrepresentations about dispute outcomes were brought under the FTC Act. The FTC did not need a new statute or novel legal theory; it pursued enforcement under long-standing rules, with a proposed order requiring RentGrow to pay a $2.25 million civil penalty.
For organizations that handle consumer data and have treated “reasonable procedures” as language that takes care of itself, this settlement is worth taking seriously. The obligations that existed before the AI headlines aren’t going away because of them.
Read the full Nymity research note
Japan: writing the rules for the AI era
On July 17, 2026, Japan promulgated amendments to its Act on the Protection of Personal Information, or APPI, and related laws. Except for some provisions, the amendments will take effect on a date set by government ordinance within two years of promulgation. The detailed ordinances, PPC rules, and guidance are still being developed.
The reform creates limited consent exceptions for specified statistics-creation activities, including AI development where it falls within that framework. In defined circumstances, businesses may acquire publicly available sensitive personal information and provide personal data to third parties without consent, but only subject to transparency, contractual, and use-limitation requirements. This is not a blanket exemption for all AI training or all publicly available data.
The APPI also introduces a new administrative-surcharge regime for specified large-scale violations that generate a financial benefit. The surcharge is generally tied to the benefit obtained, subject to statutory thresholds and other conditions. It may be multiplied by 1.5 for qualifying repeat conduct within ten years, while voluntary reporting may permit a 50% reduction if the statutory conditions are met.
Read the full Nymity research note
The EU: courts start drawing lines around LLM access
The third development is the most technically complex. On June 18, 2026, the Hague District Court, sitting as a preliminary-relief judge, suspended orders issued by the Dutch Data Protection Authority in a cross-border GDPR investigation involving the licensing of EEA users’ data to LLM developers.
The AP had required two platform operators to facilitate live, regulator-directed searches of internal systems, including Jira, Google Vault, and SWAT Tables. The court did not block access to AI systems, and it did not finally decide that the AP lacked jurisdiction or that live access was unlawful. Instead, it held that the companies’ objections could not be ruled out at the interim stage.
The court accepted that the underlying processing fell within the territorial scope of the GDPR, but questioned whether directing personnel abroad to search foreign systems went beyond the AP’s enforcement powers. It also found that the proportionality of the investigative method and the practical safeguards for legally privileged information required further examination. Because the AP had not shown that immediate enforcement was necessary and the companies faced potentially irreversible consequences, the court suspended the orders pending the administrative objection proceedings.
A few things are worth tracking here. The AP was seeking live, regulator-directed searches of foreign-based corporate systems in an LLM-related GDPR investigation.The decision illustrates that a national court may scrutinize the proportionality and territorial reach of an investigative method before coercive compliance measures take effect. Jurisdiction over cross-border AI infrastructure is being contested, and courts are taking those contests seriously. These are conditions that regulators and companies will keep running into as AI investigations become more common across the EU. How courts calibrate proportionality in this space will matter for a long time.
Read the full Nymity research note
What this actually means for privacy teams
These three stories didn’t require each other. They’re not part of a coordinated global campaign. But they do point to a real shift: privacy enforcement is now a multi-jurisdictional problem where the pressure arrives in different forms simultaneously. A US regulator enforcing decades-old basics. A Japanese legislature modernizing consent rules while installing economic-benefit fines. A Dutch interim ruling scrutinizing the proportionality and territorial reach of one supervisory authority’s investigative method in an LLM-related GDPR investigation.
Taken together, these developments show three different forms of pressure: established U.S. consumer-reporting enforcement, Japan’s combination of limited data-use flexibility with a new APPI surcharge regime, and national-court scrutiny of cross-border investigative powers in an LLM-related GDPR case. A GDPR-only program is not a substitute for controls addressing the FCRA, the FTC Act, the APPI, and national procedural law. Privacy programs that want to stay ahead of what’s coming need real-time visibility into what’s moving in the US, in Asia-Pacific, and at the court level across EU member states, not just when new legislation passes.
All three articles above are sourced from Nymity Research, TrustArc’s regulatory intelligence platform, which tracks legislative, enforcement, and judicial developments across more than 180 jurisdictions. For teams managing global privacy obligations, that kind of current, structured intelligence isn’t a convenience. It’s what the job now requires.
Explore TrustArc’s Privacy Management Platform