Entries submitted
| Entry | Agency / Authority |
|---|---|
| Canada – Privacy Commissioner of Canada | |
| Hong Kong – Privacy Commissioner for Personal Data | |
| Ireland – Data Protection Commissioner | |
| Kenya – Office of the Data Protection Commissioner | |
| Canada – Information and Privacy Commissioner of Ontario |
Privacy Commissioner of Canada investigation into the chatbot Grok’s generation of sexualized deepfakes
Brief Description
On June 11, 2026, the Privacy Commissioner of Canada released the results of his investigation into the chatbot Grok’s generation of sexualised deepfakes. The investigation sought to determine i) whether the companies had obtained valid consent for its use of individuals’ their personal information to create explicit, sexualized deepfakes; and ii) whether this practice was appropriate in the circumstances. The investigation found that X Corp. and X.AI LLC (“xAI”) violated Canada’s federal private-sector privacy law (PIPEDA) by launching Grok’s image generation tool without adequate privacy safeguards or sufficient consideration of potential privacy harms. As a result, the companies agreed to implement a number of privacy protective measures, including to conduct more thorough privacy risk assessments prior to launching new AI initiatives, and to ensure stronger safeguards to prevent the generation of sexualized deepfakes.
Integrated Anti-Doxxing Enforcement Regime since 2021 by PCPD Hong Kong, China under the Anti-doxxing
Brief Description
The provisions criminalising doxxing acts under the Personal Data (Privacy) Ordinance (PDPO) came into effect on 8 October 2021 in Hong Kong. The amendments empower the Privacy Commissioner for Personal Data (Privacy Commissioner) to adopt a “one-stop” approach in handling doxxing-related offences, from criminal investigation, collection of evidence to prosecution. In addition, the Privacy Commissioner is empowered to issue cessation notices to request the cessation of disclosure of doxxing messages.
Since the introduction of the anti-doxxing regime, with the Office of the Privacy Commissioner for Personal Data (PCPD)’s continuous resolute enforcement and enhanced publicity and education efforts, illegal doxxing activities have significantly decreased. There has been a significant downward trend in both the number of doxxing-related complaints and doxxing messages proactively uncovered by the PCPD’s online patrols.
Precedential enforcement bringing certainty to the standards entities must meet before transferring personal data outside the European Economic Area based on appropriate safeguards
Brief Description
The DPC established clear standards regarding the obligations on entities transferring personal data to third countries in reliance on appropriate safeguards. The DPC brought enforcement that directly resulted in the seminal judgments of the CJEU in Schrems I and II. Following these judgments, the DPC commenced an inquiry into TikTok’s transfers of personal data to China in 2021. The DPC issued its Decision in April 2025 after a complex and detailed investigation.
The novel enforcement established that data controllers must first verify, guarantee and demonstrate that personal data transferred to a third country are afforded a level of protection essentially equivalent to that guaranteed within the EU before making transfers. This standard was affirmed by the Irish High Court in June 2026 in another seminal judgment. This standard is crucial to protecting the fundamental right to data protection and to making the requirements for valid transfers enforceable by DPAs in practice.
Strengthening Cross-Border Privacy Enforcement in East Africa: ODPC and PDPO Uganda Joint DTB Case Initiative
Brief Description
The Office of the Data Protection Commissioner (ODPC), Kenya initiated a cross-border enforcement action following a complaint concerning an alleged personal data protection violation involving Diamond Trust Bank Kenya (DTB Kenya) and Diamond Trust Bank Uganda (DTB Uganda). The complaint arose after the Complainant received the financial information and bank statements of an unrelated third party. Investigations established that the improperly disclosed information originated from DTB Uganda, indicating that personal data had been transferred or disclosed across borders without appropriate safeguards or controls.
In addition to the unauthorized disclosure of a third party’s personal data, the Complainant reported that since May 2025 she had been unable to access her own DTB bank statements and transaction notifications. As a result, she experienced difficulty monitoring and reconciling her financial transactions, effectively denying her the right of access to her personal data.
Early Resolution: Modern and Effective Regulation with Real-World Impact
Brief Description
The Early Resolution team at the Ontario IPC delivers fast, practical outcomes for Ontarians by resolving the vast majority of privacy matters without formal adjudication. In 2025, 1734 of the 1792 privacy related files before the tribunal (96%!) were resolved or dismissed at Early Resolution, on average in 131 days, reducing delay and avoiding lengthy formal Investigations or Adjudications.
Through Early Resolution, individuals receive timely remedies to privacy complaints, such as ensuring the containment of breaches. Regulated organizations benefit from clear, actionable guidance and recommendations from the Early Resolution team that lead to improved privacy and security postures and ensure compliance with privacy legislation.





