Access Legal & IG Quarterly Update – Q3 2026

Access Legal & IG Quarterly Update – Q3 2026

Adam Koonce, ACP, Manager, Legal Research

This quarter’s legal and information governance developments share an unexpected theme: Laws requiring data deletion are also requiring organizations to create and retain proof that the deletion occurred. California’s data broker platform is the clearest example, with Connecticut, New Jersey, and Chile following similar patterns. This update covers those, along with Illinois’s AI audit requirement, the EU’s revised AI Act timetable, South Korea’s order to destroy an AI model, and Chile’s new privacy law taking effect December 1.

Continue reading to become informed of these new laws and regulations from across the globe and empower yourself with the information you need to do your job as efficiently and confidently as possible.

Connecticut: Privacy and AI Regulation Updates

Amendments to the Connecticut Data Privacy Act (CTDPA) took effect July 1, 2026, lowering coverage to businesses handling data on 35,000 residents and removing the volume threshold entirely for anyone who processes sensitive data or sells personal data [Conn. Gen. Stat. § 42-516].

A separate obligation lands August 1, 2026: controllers that profile people to make decisions carrying legal or similarly significant effects must complete a dedicated impact assessment, distinct from the data protection assessment the law already required [Conn. Gen. Stat. § 42-522].

The statute sets no retention period for either one, so in practice they last as long as the activity they describe. The Attorney General can request them, and the version that matters is the one that was in force when the assessment occurred. That makes superseded versions worth keeping, each with the dates it governed.

Additionally, Connecticut Senate Bill 4, effective October 1, 2026, amends the existing CTDPA framework banning the selling of residents’ precise location data [Conn. Gen. Stat. § 42-520, (a)(3)(A)], and directs the Department of Consumer Protection to establish a statewide accessible deletion mechanism by July 1, 2028 [Comm. Pub. Act No. 26-64, Sec. 5 (a)(1)]. This aligns Connecticut with a nearly identical provision from California obligating businesses collecting and selling consumer information to delete that information upon the subject’s request and continue deleting it, even if it’s re-acquired.

Regarding artificial intelligence, Connecticut’s new AI law starts phasing in on October 1, 2026. It says employers cannot blame the software when a hiring tool discriminates. But, if an employer has tested that tool for bias, a court can take the testing into account, looking at how good it was, how recent, what it found, and what the employer did about the results [Conn. Gen. Stat. § 46a-60(b)(1)]. Connecticut doesn’t require testing and never says how long to keep the associated records, but it can help an employer who still has it. One reading of the law lets a court hold the absence of testing against you. So, the test method, the results, and any fixes made are the record, and absent their preservation implies an employer never tested.

New Jersey Sets Deadlines for Deleting Personal Data

New Jersey’s Kids Code Act, [(P.L.2026, c.73)] signed August 11, 2026, and effective September 1, 2027, sets deadlines for getting rid of data. Data collected to confirm someone’s age must be deleted within 15 days [§(8)(b)], an account must be taken down within 10 business days of a minor’s request and permanently deleted within 45 days [§(9)], and providers may keep only the minimum data needed for features actually used [§(7)(b)]. Another obligation says minors and parents must be able to review and change the data feeding the platform’s recommendations [§(10)(a)]. These updates quietly make searchability part of compliance as organizations must be able to find the features using the minimum data retained.

New Jersey’s Assembly Bill 5328 concerning personal data, data brokers, and data collectors, signed on June 30, 2026, sets a $50,000 penalty per record of sensitive data sold, offered for sale, or licensed in violation of the sensitive data transaction ban [Sec. 5]. The law reaches companies that would never call themselves data brokers, and a penalty counted record by record can only be disputed record by record. It’s advisable to keep a transaction-level log of every data sale and license, showing the date, the buyer, the record count, and the fields transferred, and keep it as long as the state can still bring a case.

Illinois Implements Artificial Intelligence Safety Measures Act

Illinois signed the Artificial Intelligence Safety Measures Act [Pub. Act No. 104-0538] on July 6, 2026, becoming the first state to require outside audits. Large frontier developers, above $500 million in revenue [§5], must hire an independent auditor every year beginning January 1, 2028 [§10(d)], and must publish a redacted report within 30 days [§10(d)(4)(A)]. The unredacted audit report must be kept by the developer for as long as the model stays deployed, plus five years [§10(d)(3)], and any information redacted from a published document must be kept unredacted for five years [§10(g)(2)]. For those responsible for maintaining a retention schedule, the first requirement presents a challenge: it has no calculable end date while the model is still running, so the disposition date does not exist until the day you retire the model. Build that entry around a retirement event, rather than a date, and make sure the retirement itself is recorded and dated.

California Tightens Data Deletion Requirements

California’s deletion platform went live for data brokers on August 1, 2026. Every 45 days a broker must check the platform, delete the data of anyone who asked, and tell its vendors to delete their copies too [Cal Civ Code § 1798.99.86 (c)(1)(A), (C)]. If a data broker cannot confirm who is asking, they still must stop selling that person’s data, rather than just saying no [Cal Civ Code § 1798.99.86(c)(1)(B)]. The part that affects a retention schedule is that once someone’s data is deleted, the broker must keep deleting it every 45 days, forever [Cal Civ Code § 1798.99.86(d)(1)]. The law never says to keep a list of who asked, but there is no way to do this without one. A statute written entirely to erase data ends up requiring a record that can never be thrown away. Connecticut is building something similar, on the same 45-day rhythm, but they’re roughly two years behind. Both states also require an outside audit every three years, though California’s begins in 2028 and Connecticut’s in 2031, so a company in both markets may end up running two audit cycles permanently out of sync.

European Union Sees AI Regulatory Developments

The Digital Omnibus on AI [Regulation (EU) 2026/1744] took effect July 27, 2026, days before the Artificial Intelligence Act’s toughest requirements were due. Retention periods did not change; ten years of technical and quality documentation, six months of automatic logs. The start dates moved to December 2, 2027 for standalone systems and August 2, 2028 for AI inside regulated products [Art. 1, point 40]. Little else was deferred. The transparency rules requiring AI-generated content to be labeled still took effect on August 2, 2026, as originally planned. Two new prohibitions were added as well, covering AI that generates intimate imagery without consent and AI that generates child sexual abuse material, both applying from December 2, 2026 [Art. 1, Point 7].

Asia-Pacific: South Korea Orders to Destroy an AI Model

South Korea’s Personal Information Protection Act has been in force since 2011, and an amendment took effect September 11, 2026. It raises the penalty ceiling and extends accountability to executives and the board. But the more telling development is how far the regulator has shown it will go. After finding that Kakao Pay had sent the data of roughly 40 million users abroad without consent, the Personal Information Protection Commission (PIPC) ordered Alipay, which had received that data, to destroy the AI scoring model built from it. Not just the data. The model. [PIPC Sanctions Kakao Pay and Apple for Unlawful Cross-Border Data Transfer)(II)(3] For records teams, that changes what destruction can mean. If training data was gathered unlawfully, the system trained on it may have to go too, and the amended law puts far larger penalties behind that outcome. It’s not obligatory, but it would seem the only logical means to avoid liability is to keep a list of your AI models, proof of where the training data came from for each, and what gave you the right to use it. How much precedent this really sets is still an open question. Alipay is a Singapore company, largely beyond the South Korea regulator’s practical reach, and it has never appeared in a Korean court to contest an order no one is visibly enforcing.

Latin America: Chile has a New Privacy Law

Finally, the newest full scope regulation on the block will make its appearance this year in Chile. Chile’s old law asked only for entities to register their database with the government, and that led to being largely done with obligations. The new law literally throws the register out, requiring the Civil Registry to delete the whole thing in the sixty days before the new rules start. Under the old regime, the audience of your obligations was the Registry, but under the new system, you answer to anyone who visits your website. Instead of telling the government you hold data, you now must tell the public how long you keep it, and be ready to prove everything you claim.

The common hallmark of consumer and data privacy legislation allows the retention of data only as long as it’s actually needed, then it must be deleted or stripped of anything identifying, and holding it longer takes either a law permitting the act or the person’s own permission [Art. 3(c)]. The retention period for data goes on the organization’s public website and stays there, along with where the data came from, how it’s protected, and a privacy policy stamped with a date and version number [14 ter]. Anyone can also ask how long their specific data is being kept [Art. 5(d)], so a vague published answer will not survive contact with a real question. Two deletion rules run by themselves, with nobody having to ask: data tied to debts that are past their legal expiry has to go, with no request, court order, or regulator instruction needed [Art. 17, inciso 8], and vendors must delete or hand back everything when the work ends [Art. 15 bis].

Chile’s law aligns many elements with those of the GDPR, making the law feel familiar. Data controllers must prove processing was lawful [Arts. 3(a), 12, 13], keep proof of every request answered, including the date and the full text of the reply [Art. 11], keep a breach log covering what happened, who was affected and roughly how many, and what was changed afterward [Art. 14 sexies]. Data controllers must also be able to get data back quickly after a system failure, and then clearly proving protections existed and actually worked [Art. 14 quinquies].

Chile is unique in three ways. First, Chile takes risk assessments more seriously than Europe does. Both require you to assess the danger before launching high-risk processing, but only Chile puts failure to do so in its top violation tier [Arts. 15 ter, 34 quáter(k)]. Second, two things everyone expects to see in a modern privacy law are missing, no deadline for reporting a breach, only “without undue delay” [Art. 14 sexies], and, no requirement to keep an inventory of what you process. Third, Chile is also unusual in letting someone’s consent extend how long you keep their data [Art. 3(c)], a lever none of the other countries offer, and one that consequently turns consent records into part of the retention schedule.

The remaining legal traps both involve mistaking a pause for an ending. Putting a hold on data, or being ordered to stop using it, does not mean you have deleted it [Arts. 8 ter, 38]. And the window you need to plan for is far wider than any single obligation suggests. At the short end, if nobody ever complains, the state has four years from the date of the violation to come after you, and once that passes, nothing follows [Art. 40]. At the long end, the clocks stack. The four-year window can be interrupted at the last moment by the regulator opening a file, the case itself can run six months, and only when that ends does a separate five-year window open for people to sue you for damages [Arts. 40, 47]. That is a decade of exposure from a single incident, and if the problem is an ongoing practice rather than a one-off event, the first four years do not even begin until you stop doing it (Art. 40).

 To learn more about how to address records retention, data privacy, and security requirements more efficiently, request a call with an Access expert, or request a product demonstration of Access Unify® | Lifecycle.