The EU-US Data Privacy Framework is in Danger!
On Monday June, 29th, the US Supreme Court decided in Trump v. Slaughter that the US Federal Trade Commission (“FTC”) may not be independent anymore.
As the EU-US Data Privacy Framework ('DPF') relies on the fact that the FTC is an independent body, one can wonder whether the DPF will still apply.
Max Schrems: “Given that there are no independent authorities in the US anymore, we call on the European Commission to orderly withdraw the adequacy decision on the US.” Read the article from NOYB: https://noyb.eu/en/us-supreme-...
For this reason, US House Republicans explore FTC reform following Supreme Court rulings https://www.politico.com/news/...
Also, the EDPB Letter to the European Commission on US Supreme Court judgment Trump v. Slaughter https://www.edpb.europa.eu/doc...
Important updates to HIPAA's Security rule were planned for 2026 by the HHS: these updates have been postponed to July 2027 following important pushback from hospitals.
On another hand, key changes are also planned for HIPAA's Privacy Rule for August 2026.
On 10 July 2026, Fierce Healthcare released an article: https://www.fiercehealthcare.c...
HIPAA's Security rule update delayed to July 2027:
The Department of Health and Human Services (HHS) had proposed a May 2026 release for a final rule that makes significant changes to the HIPAA Security Rule.
The proposal would require that entities covered by HIPAA achieve specific technical standards like encryption, multifactor authentication and network segmentation. The requirements also mandate annual penetration tests, more prescriptive requirements for risk analyses, written security incident response plans that are tested at least annually and verification from business associates about their technical safeguards. Some of these changes will also apply to health plans and business associates.
Following a big pushback from hospitals, health systems and other healthcare organizations. the U.S. Office of Management and Budget (OMB) website was updated and indicates that the final rule was pushed back to July 2027.
Read the details of the Security Rule changes here: https://www.federalregister.go...
HIPAA's Privacy rule to come into force in August 2027:
The HHS is due to release an update to HIPAA's Privacy rule with the following goals:
Strengthen individuals’ rights to access their own protected health information, including electronic information.
Improve information sharing for care coordination and case management for individuals.
Facilitate greater family and caregiver involvement in the care of individuals experiencing emergencies or health crises
Enhance flexibilities for disclosures in emergency or threatening circumstances
Reduce administrative burdens on HIPAA covered health care providers and health plans, while continuing to protect individuals’ health information privacy interests.
3 - How will these updates impact life science organizations?
HIPAA applies only to covered entities and business associates, and to patient data collected during care. So, as explained during our webinar 'HIPAA versus GDPR' on 30 June, the planned updates of the Security Rule and of the Privacy Rule will not apply directly on Life Science organizations, that is manufacturers and developers of drugs and medical devices, CROs, CDMOs etc.
That said, in our opinion it could happen that a US hospital sharing retrospective patient data with a life science organization, for example for a retrospective study, would ask such life science organization to
unless these rules are changed
On 2 July 2026, the UK Department of Health & Social Care released a new Guidance on Safeguarding UK human genomic data.
This guidance sets out the UK government’s expectations on how HGD can be made available in a way that maximises scientific benefit while reducing risks. It is intended for major UK government-funded holders of HGD that make it available to external users.
This guidance uses the Five Safes framework, developed by the Office for National Statistics, to set recommendations for how HGD can be made available safely and securely to external users. This guidance also sets a framework to support major holders of HGD when considering whether to make data available to users outside of the UK and expectations on protective security.
The Five Safes are the following:
- Safe settings
- Safe data
- Safe people
- Safe projects
- Safe outputs
Read details about this 5 safe measures considerations for access by users based outside the UK and existing policy statements, guidance and frameworks: https://www.gov.uk/government/...
In an article published by Quanta Magazine on April 3rd 2026, writer Charlie Wood explained that researchers are getting closer to build a quantum computer able to break current encryption protocols RSA and ECC. Wood says it is not for tomorrow, but probably in a few years' time. Wood advises organizations to start looking at implementing new encryption protocols, to stay ahead of the pack and not risk a breach of personal data.Read article from Quanta Magazine: https://www.quantamagazine.org...
The NIST is even more alarmist and says: 'Now is the time to migrate to new post-quantum encryption standards, before quantum computers put today's encryption at risk.'
In 2024, the National Institute of Standards and Technology published 3 new codes that can keep secrets safe from both classical and quantum computers. And the U.S. government has laid out a plan to completely switch to these new codes by 2035. But some researchers believe that key players may need to act more quickly. Google, for instance, recently announced that it aims to stop relying on RSA and ECC by 2029.
With NIST finalizing the first post-quantum cryptographic standards in 2024—ML-KEM for key , ML-DSA for digital signatures and SLH-DSA for hash-based signatures – the building blocks now exist.
The recent U.S. government Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, reinforces a reality many organizations are already confronting: post-quantum readiness, cryptographic modernization and supply chain assurance are becoming important imperatives to ensure long-term resilience.
On 18 November 2025, Microsoft announced that Post-Quantum Cryptography (PQC) algorithms are now generally available in Windows Server 2025 and Windows 11 clients (24H2, 25H2) and .NET 10, read here: https://techcommunity.microsof...
A star-studded team of quantum physicists at the California Institute of Technology went public with a design for a quantum computer that could break encryption with only tens of thousands of qubits and said that it had formed a company to build the machine.
At the same time, The U.S. National Institute of Standards and Technology (NIST) said as quantum technology continues to accelerate, organizations are working to develop encryption tools that can not be solved by quantum computers. Read here: https://www.nist.gov/blogs/tak...
Cryptography in quantum computers is a complex topic, as it brings together several scientific domains: quantum mechanics, atomic physics, algorithms and IT to mention only a few.
If you have questions on how to prepare and migrate to quantu-resistant cryptography, contact Bertrand at b.p.lebourgeois@pharmarketing.net We have a team of engineers who can support you.
Data Protection Authorities ('DPAs') published several decisions related to the processing of health data in the past months.
Such decisions shed light on the key measures to implement to stay compliant with privacy (and healthcare) laws and avoid a critical finding.
For each decision, we propose key takeaways: use them as ideas and guidelines for your own organisations: check that such measures are implemented at your organisation, and if not, talk to your management (or talk to us!).
Many thanks to GDPR hub NOYB and to IAPP for all this valuable information!
Austria:
Fact:
The DPA fined a medical student €200 for filming a hospital patient with dementia and sharing the video with a fellow student. It found that the recording and disclosure constituted unlawful processing of health data. Read more or edit on GDPRhub...
Takeaway:
There needs to be a valid legal basis and the patient's consent to film a patient and share the recording.
Estonia:
Fact:
A dental clinic was collecting and transferring patients’ health data to Align Technology, Inc., a subcontractor. But the contract between the clinic did not contain all the mandatory data privacy language, and most of the process was imposed by Align Technology. Also, patients were not informed sufficiently on the processing of their personal data by Align Technology. The DPA from Estonia ordered the clinic to amend the contract and inform patients appropriately.
Read more: https://gdprhub.eu/index.php?t...(Estonia)_-_No._2.1-1/24/397-890-38
Takeaway:
The agreement between an organization and its sub-contractor must contain all mandatory data privacy language and remind the vendor of its obligations as per Privacy laws. Also, if a subcontractor determines the objectives and the means of the personal data processing, then the vendor is not a data processor anymore, but becomes a joint data controller.
Norway:
Fact:
Datatilsynet, the Swedish DPA found that Lab Pharma AS, a Norwegian manufacturer of dietary supplements which markets and sells its products online unlawfully continued using an influencer’s personal data after their contract expired and fined it NOK 205,000 (€18,825.20) for breaching its duty to cooperate under Article 31 GDPR. After the agreement had expired, the Lab Pharma AS continued using the influencer’s name, photographs and comments about its products on its websites. In February 2023, the data subject (the influencer) requested the erasure of her personal data under Article 17 GDPR. Lab Pharma rejected the request, claiming that the agreement entitled it to continue using the data and stating that it would not respond to further inquiries. Read more or edit on GDPRhub…
Takeaway:
Looks like the sales and marketing team who signed the contract with the influencer was not properly educated to reading contracts and complying with privacy laws. Train all your employees to privacy laws, and ask them to notify the Data Protection Officer (or a person with similar responsibilities) within 24 hours and in writing for any request they receive from a data subject.
Poland:
Fact:
The UODO, the Polish DPA reprimanded a hospital and its email service provider for a failure to implement technical and organisational measures following a data breach that involved health data of patients. Read more or edit on GDPRhub...
Takeaway:
First, every organization must check that its subcontractors provide sufficient guarantees, especially that it has implemented appropriate technical and organisational measures (TOMs). Second, the hospital had not put in place enough TOMs itself.
Spain:
Fact:
The Spanish DPA, the AEPD, fined 23ANDME, INC., a US genomics and biotechnology company €2.4 million for failing to adequately protect sensitive genetic and health data and for notifying the DPA about a personal data breach after the 72-hour deadline. The AEPD held that 23ANDME did not impose specific password-strength requirements or require passwords to be changed periodically. Although it had implemented multi-factor authentication (MFA), its use remained optional. Moreover, it had not introduced additional controls or limits concerning account access, access requests or the downloading of sensitive information. Read more or edit on GDPRhub...
Takeaway:
A minimum password strength and MFA are now basic security measures that all organizations should implement. We advise our readers to consult and implement the IT security guidelines from their local government agencies, or from US and UK agencies.
United States:
Fact:
The U.S. Federal Trade Commission filed a joint lawsuit with regulators in California and Utah alleging telehealth provider Hims & Hers unlawfully and deceptively shared consumers' sensitive health data with third-party advertising platforms, including Meta and Snap. Read the press release from the FTC: https://www.ftc.gov/news-event...
Takeaway:
In the US and in all countries as far as we know, healthcare laws state that patient data can be shared ONLY with people who are member of the healthcare team, or for a limited number of specific derogations like public health (e.g. pandemic), medical research, occupational medicine, law enforcement etc. In the US, the HIPAA says exactly so, and the patient data collected by Hims & Hers fall under HIPAA.
Fact:
The U.S. Consumer Product Safety Commission is reportedly demanding healthcare systems submit sensitive medical records containing personally identifiable information from patients who visit their emergency rooms, CNN reports. The agency has reportedly been pressuring hospital executives to turn over records containing patients' data to a private contractor despite healthcare systems' lawyers and other industry professionals expressing doubt the CPSC has the authority to request such information. https://edition.cnn.com/2026/0...
Takeaway:
In countries like the US, Health and Life Science organizations need to be ready to manage a request from a government agency to share sensitive patient data. So, it's important to 1) encrypt all sensitive information with the best techniques 2) be prepared to reply to such a request.
Fact:
Wyssta Services, which operates an online portal for certain Delta Dental plan members, has agreed to pay nearly $12.7 million to settle allegations that it installed advertising and analytics tracking technologies without users’ knowledge or consent. Read more here: https://www.beckersdental.com/...
Takeaway:
Privacy laws require organizations to inform data subjects that their personal data will be processed. And in some circumstances, it is mandated to get the consent from people.
Privacy News from around the Globe:
Global:
- ICH
- ICH E6(R3): On 10 July 2026 the ICH Good Clinical Practice Annex 2 was Adopted and Published; The International Council for Harmonisation (ICH) has adopted Annex 2 of ICH E6(R3): Good Clinical Practice, concluding the revision of this essential ICH Guideline. Click here for more details: https://ich.org/news/ich-e6r3-...
- ICH M8: On 30 July 2026 the ICH released the Updated support package for ICH M8: Electronic Common Technical Document (eCTD). The eCTD is the standard digital format used by pharmaceutical companies to submit regulatory applications, amendments, and reports to health authorities like the U.S. Food and Drug Administration (FDA) and the European Medicines Agency (EMA). Read here: https://ich.org/news/updated-s...
China:
China's regulation on AI companions takes force https://www.cac.gov.cn/2026-04...
The Cyberspace Administration of China (CAC) released a new regulation for assisting small processors (processors handling the personal information for fewer than 100,000 people) complying with PIPL. This new rule will enter into force 1 Sept 2026. https://www.cac.gov.cn/2026-07...
China's National Information Security Standardization Technical Committee proposed amendments to the Data Security Technology — Personal Information Security Specification, aiming to strengthen data protection standards and address concerns related to AI technology. Although nonbinding, it is recommended to draft a gap analysis of current data processing practices and take corrective measures to address any noncompliance. http://info.iapp.org/MTM4LUVaT...
The Cyberspace Administration of China published a new Personal Information Protection Law FAQ document covering requirements for processing public data and information on common sources of data leaks. https://www.cac.gov.cn/2026-08...
Croatia:
Croatia's DPA AZOP releases information on GDPR certification schemes: https://azop.hr/certificiranje...
European Union:
- 27 July 2026: the EU Commission published a Guidance to get prepared for the EU Cyber Resilience Act ('CRA') https://digital-strategy.ec.eu..., focused on SMB with 67 practical examples. Our opinion is that this Guidance is targeted at organizations developing products that embed software collecting data; for the life sciences industry, it targets medical devices, wearables, softwares etc. The CRA is in force since December 2024, but its main obligations apply from 11 December 2027, with reporting obligations already applying as of 11 September 2026. Read the press release and download the Guidance here: https://digital-strategy.ec.eu...
- 2 August 2026: a New Part of the EU AI Act entered in application:
- The AI Act introduces a risk-based framework: the higher the potential harm, the stricter the rules. Banned outright are practices such as social scoring, real-time biometric Summary surveillance in public spaces, and AI that manipulates behaviour subliminally. High-risk applications in employment, law enforcement and border control face strict requirements before deployment, and all AI systems interacting with humans must be transparent about their nature. Certain rules have already taken effect. Link to website: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- See also Rules for trustworthy artificial intelligence in the EU | EUR-Lex
- Under the AI Act, the European AI Office's authority can "request documentation, conduct evaluations and even request access to the models" while companies must assess and identify the potential risks of its AI tools.
The EU AI Omnibus was published in the Official Journal of the European Union and will take effect 27 July. https://eur-lex.europa.eu/eli/...
The package delays the effective dates for requirements on standalone high-risk models to 2 Dec. 2027, and 2 Aug. 2028 for high-risk models embedded in products: https://www.consilium.europa.e...
ENISA issues Cyber Resilience Act guidance for SMEs https://www.enisa.europa.eu/ne...
EDPB adopts guidance on anonymization, blockchain and AI web scraping https://www.edpb.europa.eu/new...
France:
Additional Updates to the MR to come:
The French DPA, the CNIL, communicated to us the following regarding the MR001 and MR003 released in May 2026:
"Depuis la publication des nouvelles méthodologies de référence MR-001 et MR-003, le service de la santé a reçu plusieurs sollicitations de la part des acteurs concernés.
Afin d'apporter des précisions au plus grand nombre, le service de la santé prévoit de mettre à jour prochainement les versions annotées de ces méthodologies de référence. Il m'a été indiqué que les interrogations que vous soulevez y seront abordées, notamment vos questions 1 à 4. Votre 5e question sera, a priori, abordée dans une fiche pratique à venir sur les destinataires.
Je vous invite donc à prendre connaissance de ces documents dès leur mise à jour ou publication, qui devrait intervenir dans les prochaines semaines. Si certaines questions devaient néanmoins subsister, vous pourrez nous recontacter soit par l'intermédiaire d’une permanence téléphonique (service DPO, ou ser released in May vice de la santé), soit via cette même adresse afin d'obtenir les précisions nécessaires."
DPO Role: France's data protection authority, the Commission nationale de l'informatique et des libertés, published a guidance to help organizations determine the additional responsibilities they can assign to their data protection officer that would not create a conflict of interest. https://www.cnil.fr/fr/dpo-ide...
Germany:
Germany's Federal Office for Information Security released a technical guide with cybersecurity recommendations to streamline Cyber Resilience Act compliance. https://www.bsi.bund.de/DE/Ser...
Latvia:
Latvia's DVI released its data breach guidance https://www.dvi.gov.lv/lv/jaun...
The Netherlands:
Netherlands' DPA issued a guidance on reproductive health app use https://autoriteitpersoonsgege...
The Netherlands' data protection authority, Autoriteit Persoonsgegevens, issued guidance detailing the EU AI Act's Fundamental Rights Impact Assessment ('FRIA') obligations for high-risk AI systems. https://autoriteitpersoonsgege...
Serbia:
On 30 July 2026, the Ministry of Justice of the Republic of Serbia published a draft Law on Personal Data Protection and opened it for public consultation through 10 Sept.
- Draft law: https://mpravde.gov.rs/storage...
- Comment form: https://mpravde.gov.rs/storage...
South Korea:
South Korea's National Assembly approves PIPA amendment to support AI innovation; the amendment establishes a legal basis for processing personal information toward AI development with public and social benefits: https://www.pipc.go.kr/np/cop/...
The EU Commission finds that Republic of Korea continues to provide an adequate level of protection of personal data. The Commission confirmed South Korea maintains an adequate level of data protection to continue receiving data transfers from the EU. https://commission.europa.eu/n...
United Kingdom:
Guidance on recruiting patients: Dr Alison Knight, Data and Privacy Specialist and Research Data Policy Lead at HRA wrote a blog reflecting on the guidance and the practical things that researchers should be considering around recruitment. Read here: Find out more
New MHRA rare diseases consultation: read here: Our response to the MHRA rare disease therapies regulatory framework consultation - Health Research Authority
The HRA published a new Site Selected Email Template for sponsors to use when confirming site selection with NHS and HSC organisations in commercial contract clinical trials or clinical investigations
NHS DigiTrials is helping to improve access, increase representation and support the efficient delivery of clinical trials by enabling researchers to reach potential participants who may otherwise be unaware of research opportunities: read here: https://digital.nhs.uk/service...
Reform Party releases proposal to replace UK GDPR with 'light-touch' approach https://www.politico.eu/articl...
The ICO issued a consultation on anonymization, pseudonymization guidance in the research field. The consultation is open until 19 October 2026 https://ico.org.uk/about-the-i...
The ICO launched
'Data Protection Essentials' training program for SMEs https://ico.org.uk/for-organis...
The U.K. National Cyber Security Centre released guidelines to help businesses respond and recover following cybersecurity incidents. Read here: https://www.ncsc.gov.uk/blogs/...
United States:
HIPAA's Security Rule and Privacy Rule: read article above
Some African nations are turning down Trump aid money because it would involve sharing personal data of all patients with the US: read article from the BBC: https://www.bbc.com/news/artic...
NIST details new guideline for Identity Security and AI Agents: https://www.nist.gov/blogs/cyb...
The U.S. Senate Committee on Health, Education, Labor and Pensions approved amendments to the proposed Health Information Privacy Reform Act that would extend privacy safeguards for health information not covered under the Health Insurance Portability and Accountability Act, BankInfoSecurity reports.
https://www.bankinfosecurity.c...
Best practices to address US state regulators' cybersecurity inquiries https://ionanalytics.com/insig...
Zimbabwe:
Legislative and Regulatory Reform in Zimbabwe's Digital Sector - a Rights-Based Perspective: https://allafrica.com/stories/...

- Select a mid-size company which can support you with Privacy Compliance for Life Sciences across the World with a team of senior experienced scientific and legal consultants local experts: it's PharMarketing GDPR Life Sciences of course!.
- Post-Quantum cryptography can work only on a quantum computer: no
- Post-Quantum cryptography means an encryption technique which will be able to resist to attacks from quantum computers in the future; and as indicated in the article above, Post-Quantum cryptography can already be implemented on 'classic' computers and servers.
