Kelley Drye Ad Law Access Podcast

IAPP Global Privacy Summit 2026- State AI Trends, FTC Signals, California’s DROP Build-Out, and the Hard Work of Cookie Compliance

·10 min·1 clip
Prince Harry and Salman Rushdie discuss personal privacy challenges at the IAPP Global Privacy Summit.
["The episode opens with host Simone Rouge noting the IAPP Global Privacy Summit coincided with Washington's cherry blossom season.", "Keynote speakers Prince Harry and Salman Rushdie discussed their personal privacy challenges, setting the conference tone.", "For privacy professionals, 2026 is shaping up as a year of proving compliance programs work in practice, not just on paper.", "FTC Commissioner Mark Miodor's fireside chat with IAPP Vice President Caitlin Fennessy revealed a pragmatic enforcement posture.", "Miodor explained his primary question when evaluating remedies: whether they adequately solve the harm alleged in complaints.", "He also noted building mechanisms to enforce the Take It Down Act is a top FTC priority.", "State AI legislation is moving from sweeping proposals to narrower obligations tied to risk, youth harms, and specific deployment contexts.", "Connecticut State Senator James Maroney noted only about 200 of over 1,000 AI-related bills directly impact privacy regulation.", "Transparency and human oversight remain central themes, with regulators pushing back against automated decision-making black boxes.", "Maroney expects agentic AI and pricing to be active legislative areas in the next cycle, with future laws tailored to specific use cases.", "A separate session with in-house counsel from the New York Times and Univision focused on practical AI governance challenges.", "Panelists highlighted recurring issues including accuracy concerns, IP problems, and evolving vendor contract negotiations.", "They recommended companies look beyond standard data processing agreements to address model training restrictions and responsibility for AI harms.", "California's DROP system has processed over 262,000 deletion requests from consumers since implementation.", "The system clarifies that companies can be treated as data brokers even with direct consumer relationships if they also buy or sell third-party data.", "Data brokers have until August 1, 2026 to implement DROP through API integration or manual list downloads, with technical documentation expected by April.", "Failure to delete violations carry penalties of $200 per consumer per day, creating significant potential exposure.", "Cookie compliance remains challenging with no settled playbook, where small misalignments between banners, policies, and actual behavior trigger enforcement.", "Common pitfalls include cookies firing outside intended scopes, inconsistent behavior between authenticated and unauthenticated site portions, and misclassified trackers.", "Regulators penalize companies for excessive verification requirements, treating GPC signals as device-specific, and continuing tracking after user opt-outs.", "Penalties have reached seven figures with remedial obligations including quarterly scans, cookie inventories, and senior officer certifications.", "The broader takeaway emphasizes that compliance requires ongoing maintenance, engineering controls, and documentation matching actual practices."]
Listen to the show on