News

Identity & Data Regulations in 2026: DPDP, GDPR, eIDAS 2.0, AI Act & What Businesses Must Do

Moca Network
August 4, 2026

TL;DR — 2026 is the year identity and data rules tighten across every major market at once: India's DPDP Rules are in phased implementation, the EU AI Act's key obligations continue phasing in, the EU Digital Identity Wallet must launch across Member States by the end of 2026, and U.S. stablecoin regulators must promulgate GENIUS Act implementing regulations by July 18, 2026. If you handle personal data or verify identity, the safest posture is data minimization, reusable/consented verification, and provable audit trails. AIR's compliant framing is privacy-first proof, selective disclosure, consent, revocation, and audit.

The 2026 regulation map at a glance

RegionLawWhat it governsKey 2026 dateWho it affects
IndiaDPDP Act and 2025 RulesPersonal data, consentRules notified Nov 2025; consent-manager provisions around Nov 2026; broader obligations around May 2027Anyone processing Indian residents' data
EUeIDAS 2.0 / EUDI WalletDigital identity walletsWallets to be provided by end-2026Banks, platforms, verifiers, regulated relying parties
EUAI ActAI systems by riskKey obligations continue phasing in through 2026Providers/deployers of AI, including identity AI
EUGDPRPersonal dataOngoingAll who process EU personal data
USState privacy + biometric lawsConsumer & biometric dataContinued expansion across statesBusinesses touching U.S. consumers
USGENIUS ActPayment stablecoinsImplementing regulations due by Jul 18, 2026Stablecoin issuers, fintechs, regulated payment participants

India — DPDP Act & Rules: what changed

India's Digital Personal Data Protection Rules were notified in November 2025 and are now in phased implementation. Public reporting describes consent-manager provisions around November 2026 and broader substantive obligations around May 2027. The direction is clear: consent, processor contracts, security safeguards, and data minimization are becoming operational requirements, not optional policy language.

EU — eIDAS 2.0, the EU Digital Identity Wallet, AI Act & GDPR

The biggest structural change is the EU Digital Identity Wallet: the European Commission states that Member States must provide EU Digital Identity Wallets by the end of 2026. This pushes device-held, user-controlled credentials into mainstream identity infrastructure.

The EU AI Act also affects organizations that provide or deploy AI systems, including systems used in identity verification, biometrics, and decisioning. GDPR remains the baseline: the wallet model is deliberately aligned with data minimization and user control.

United States — state privacy, biometric law & GENIUS

The U.S. has no single federal privacy law, so the action remains at the state level for consumer and biometric privacy. Illinois's BIPA remains a major reference point because of its private right of action, while other state laws create consent, retention, and enforcement obligations.

On money, the GENIUS Act requires each primary federal payment stablecoin regulator to promulgate implementing regulations by July 18, 2026. That matters for agentic commerce because stablecoins are moving closer to regulated payment infrastructure.

What to pay attention to if you run a business in 2026

  • Map your data by jurisdiction. Know which users are covered by DPDP, GDPR, or U.S. state laws.
  • Minimize what you collect and store. Every regulation rewards collecting less sensitive data.
  • Fix consent now. Build granular, withdrawable consent before enforcement tightens.
  • Watch how you verify, not just that you verify. Biometric laws penalize improper capture, disclosure, and retention.
  • Prepare for digital identity wallets. If you operate in the EU, plan for wallet-based credentials.
  • Keep provable audit trails. Regulators increasingly expect evidence, not assertions.
  • Treat AI systems as regulated. If you use AI for identity or decisions, AI governance may apply.

How reusable, privacy-first identity reduces regulatory risk

Most compliance pain comes from holding too much sensitive data in too many places. Reusable, decentralized identity flips the model: the user verifies once, keeps credentials under user control, and proves specific facts with selective disclosure or zero-knowledge proofs.

AIR should be framed as supporting that lower-data posture: AIR Identity / AIR Kit provide credentials, wallet, verification programs, selective disclosure, and ZK proofs; AIR Agentic Identity adapts those proofs for agents; AIR Policy + Audit handles consent, limits, revocation, receipts, and evidence. AIR should not be described as an IDV vendor, a raw-PII store, or a payment rail.

Frequently asked questions

What are the major data privacy regulations in 2026?

India's DPDP implementation, the EU's GDPR, eIDAS 2.0 / EU Digital Identity Wallet, the EU AI Act, expanding U.S. state privacy and biometric laws, and the GENIUS Act for stablecoins.

When must EU Member States provide digital identity wallets?

The European Commission states that Member States must provide EU Digital Identity Wallets by the end of 2026.

When are GENIUS Act rules due?

Each primary federal payment stablecoin regulator must promulgate implementing regulations by July 18, 2026.

What should a business do first to prepare?

Map personal data by jurisdiction, minimize collection and retention, fix consent flows, and adopt privacy-first reusable verification where a proof is enough.

Checked references: European Commission — EUDI Regulation; India Briefing — DPDP Timeline; Congress.gov — GENIUS Act; Brookings — GENIUS payment stablecoins.

Compliance note: This article summarizes regulatory developments for general information and is not legal advice. Dates and thresholds should be confirmed against primary legal texts before action.

Digital Identity Verification in 2026: The Complete Guide

Related reading

More from AIR: AIR Identity and talk to our team, or browse the full AIR blog.

Partner with AIR

AIR is one integration suite for identity, money and loyalty. AIR Identity lets trusted issuers issue verifiable credentials and businesses verify them, so acquisition starts with users who already qualify, with minimal data custody. AIR Money embeds compliant global financial infrastructure, opening new markets without building new rails. AIR Loyalty gives brands a programmable, stable-value points engine that keeps users coming back.

Partner with us to grow your business.

AIR is built by Moca Network, the identity network of Animoca Brands.

Stay updated on AIR launches
Product updates, partner launches, and research across digital identity, fintech, and loyalty. Unsubscribe anytime.
By subscribing, you agree to our Privacy Policy and consent to receive updates.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
In this article
Blog

Read more articles

Lorem ipsum dolor sit amet, consectetur adipiscing elit.
View all
UAE and APAC identity verification rules by market. AIR blog key visual
News
UAE and APAC Digital Identity Verification Requirements: A Market-by-Market Guide for 2026
UAE and APAC identity verification rules for fintech and crypto firms: CBUAE, VARA, ADGM, MAS, HKMA, RBI, Korea and MASAK, compared market by market for 2026.
European Union flags outside an EU institution building in Brussels
News
How Zero-Knowledge Proofs Work for KYC, and What GDPR Still Requires
How zero-knowledge proofs work for KYC: issuers, predicate proofs, revocation and nullifiers, plus what GDPR and AML record-keeping rules still require.
Smartphone showing an approved identity credential beside a passport and bank cards
News
What Is Reusable KYC? How Reusable Identity Credentials Work
Reusable KYC lets a business accept proof of a check a customer already passed elsewhere. How it works, who offers it, and what FATF reliance rules require.