Privacy & Cybersecurity #88
The article covers major 2026 developments in GDPR enforcement, AI governance, and cybersecurity guidance, including new EDPB fine rules, an ENISA threat landscape, NIST OT security updates, and new state and federal AI policy pushes in the U.S. It also highlights incidents and warnings from Spain’s AEPD, the UK NCSC, Maryland, and DHS OIG, showing growing concern over AI agents, cloud security, and operational resilience. #EDPB #ENISA #NIST #AEPD #NCSC #DHSOIG #GroupeCanal #CNIL #OpenAI #Anthropic #Meta #SCuBA

Keypoints

  • The EDPB issued a five-step test for deciding when GDPR fines should be imposed.
  • ENISA reported DDoS, phishing, unauthorized access, and ransomware as major EU threats.
  • NIST updated OT security guidance to align with CSF 2.0 and broader enterprise risk management.
  • Spain’s AEPD warned on AI recruitment tools and reported a breach involving an AI agent.
  • U.S. state attorneys general and Maryland pushed new AI safety, transparency, and worker protection frameworks.

Read More: https://keplernewsletter.substack.com/p/privacy-and-cybersecurity-88