The EU-US Data Privacy Framework faces its most serious legal challenge since adoption. A June 29 US Supreme Court ruling permitting presidential removal of independent agency heads has prompted a coalition of civil society organizations to demand a formal reassessment of the Framework's adequacy determination. The ruling directly erodes a core structural guarantee underpinning the 2023 arrangement — independent supervisory oversight of US compliance — and the European Commission now faces mounting pressure to evaluate whether the Framework's legal architecture remains intact. Organizations relying on the DPF as a cross-border transfer mechanism should begin contingency planning for alternative transfer tools.
Watch level: PREPARE (multinational companies using EU-US Data Privacy Framework as primary transfer mechanism, EU adequacy-reliant compliance teams)
The European Commission issued a €550 million fine against AliExpress for systemic Digital Services Act failures in risk management, marking one of the largest DSA enforcement actions to date. Separately, the Commission issued a preliminary finding that Meta's Instagram and Facebook violate the DSA through addictive design features — infinite scroll, autoplay, and personalised recommender systems — targeting a failure to adequately assess risks to minors and vulnerable users. Meta now enters a formal response period before the Commission determines final measures, which could include fines of up to six percent of global annual turnover. Together, these actions confirm that the Commission is prepared to deploy DSA enforcement at scale and on systemic, design-level grounds — not merely in response to isolated incidents.
Watch level: PREPARE (very large online platform operators, platform product and compliance teams, DSA-designated services)
The European Commission's Article 50 AI Act transparency guidelines, published this week, establish the definitive compliance reference for obligations entering application on 2 August 2026. The guidelines clarify disclosure requirements for AI system interactions, machine-readable content markers, and deployer obligations to notify individuals exposed to deepfakes, AI-generated public-interest content lacking human review, and biometric categorisation systems. With enforcement exposure now days away, organizations that have not completed an Article 50 gap assessment should treat this publication as a deadline signal, not background reading.
Watch level: PREPARE (AI system providers and deployers operating in EU markets, legal and compliance teams responsible for AI Act readiness)
Two CJEU rulings issued this week materially narrow platform liability protections in ways that warrant immediate compliance attention. In Joined Cases C-188/24 and C-190/24, the Court signaled that how platforms organize and present user-generated content may strip them of intermediary liability safe harbor protections under the DSA framework — creating incentives to over-moderate lawful speech. In Case C-421/24, the Court found that Google may bear liability for YouTube creator content where a direct commercial partnership exists, distinguishing monetized creator relationships from general user-generated content. Compliance teams should assess whether content moderation architectures and platform-creator monetization arrangements now carry heightened legal exposure.
Watch level: PREPARE (platform operators with EU exposure, content moderation and legal teams, creator monetization program managers)
France's parliament has enacted legislation prohibiting social media access for users under 15, making it the first EU member state to codify such a restriction into law. Enforcement is phased, with Arcom-approved age assurance technology — including a European Commission-developed verification app — serving as the compliance mechanism. The measure directly tests the operational readiness of privacy-preserving age verification infrastructure and signals a legislative pattern likely to influence peers across the EU and inform Digital Services Act interpretation. Platform operators with significant French user bases should assess age assurance readiness now, as this is no longer a prospective regulatory risk.
Watch level: PREPARE (social media platform operators with EU/French user exposure, age verification technology vendors, DSA policy teams)
Connecticut's signed SB 5 and New Jersey's enacted data broker registration law add two significant state-level compliance obligations that took effect without extended implementation windows. Connecticut's framework — signed May 27 — addresses AI safety, transparency, employee protections, AI companions, and automated employment decisions. New Jersey's A. 5328, enacted June 30 after a 48-hour legislative sprint, establishes a data broker registration regime and restricts sensitive data sales. Organizations with operations or data processing touching either state should treat both as active compliance requirements, not emerging risks.
Watch level: PREPARE (data brokers with US operations, AI system deployers in Connecticut, HR technology vendors, companies using automated employment decisioning)
Policy Signal · policysignalhq.com · Major privacy + AI governance moves, distilled.