The Resolution reaches any social media platform whose services are made available in, or directed at users in, the UAE.

By Brian A. Meenagh, Danielle van der Merwe, Ksenia Koroleva, and Fady Saleh

The United Arab Emirates (UAE) has issued Cabinet Resolution No. 106 of 2026 Regarding the Regulation of Children’s Access to Social Media Platforms (the Resolution), which prohibits children under 15 from creating, using, or operating personal accounts on social media platforms. The Resolution implements

Singapore shows strong commitment to developing practical guidance and addressing the complex legal challenges posed by emerging AI technologies.

By Rhys McWhirter, Esther Franks, and Zhaochen (Zoe) Wang

Singapore has made three decisive moves in the global AI governance landscape. In the space of just six weeks, Singapore regulators released three landmark publications that collectively articulate one of the most comprehensive national positions on agentic AI, legal responsibility for AI systems, and the use of personal data in

Organizations should prioritize compliance efforts in light of mounting regulatory scrutiny and potential fines.

By Brian A. Meenagh, Danielle van der Merwe, and Faisal Imam*

The Kingdom of Saudi Arabia’s Personal Data Protection Law (PDPL) is now firmly in its active enforcement phase. The one-year grace period granted to organizations to achieve compliance ended on September 14, 2024, and the Saudi Data and Artificial Intelligence Authority (SDAIA) has moved from awareness-building and guidance to regulatory action. Businesses operating

Organisations doing business in India should note the differences between GDPR and DPDPA requirements, including potential programmes that may need uplift to ensure compliance.

By Gail E. Crawford, Calum Docherty, Fiona M. Maclean, Rhys McWhirter, Esther Franks, Danielle van der Merwe, Bianca H. Lee, and Amy Smyth

The Parliament of India enacted the country’s first comprehensive data protection law, the Digital Personal Data Protection Act 2023 (the DPDPA), on 11 August 2023. The

The executive actions emphasize public-private partnerships, enhanced information sharing, and leveraging commercial cybersecurity capabilities.

By Jennifer C. Archie, Marissa R. Boynton, Antony (Tony) Kim, Clayton Northouse, Michael H. Rubin, and Serrin Turner

On March 6, 2026, President Trump signed an executive order titled “Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens” (the Order) that directs an interagency coalition to improve existing policy frameworks to address cyber threats and target transnational criminal organizations. The White

The law has extraterritorial reach over digital platforms and internet service providers that operate in, or target users in, the UAE.

By Brian A. Meenagh, Danielle van der Merwe, Ksenia Koroleva, and Fady Saleh

The United Arab Emirates (UAE) has enacted Federal Decree‑Law No. 26 of 2025 on Child Digital Safety (the CDS Federal Law), establishing a comprehensive framework to protect children online with extraterritorial reach over digital platforms and internet service providers that operate in, or

While the case is likely to be mentioned in upcoming non-material damages claims, its unique circumstances mean defence arguments remain robust.

By Tim Wybitul, Isabelle Brams, Timo Hager, and Thies Schmitte

On 1 October 2025, the General Court of the European Union (GCEU) held the EU liable for non‑material damage caused by the unlawful processing of personal data by an EU body. In OC v. Commission (T ‑384/20 RENV),1 which concerned a press release by the