Clym Logo

Weekly Compliance Brief: August 10 - 14, 2026

Published
AS
AuthorAdam Safar
6 min read

Weekly Compliance Brief: August 10-14, 2026

CalPrivacy's data broker crackdown continues, Colorado opens AI rulemaking comments, and New Jersey enacts a strict new kids' privacy law.

Summarize full article with:

This week, California continued its data broker enforcement push, Colorado opened formal rulemaking on AI and chatbot safety, New Jersey adopted a new privacy law for minors, and the EU moved closer to its e-Evidence deadline.

We also cover new ICO training for small businesses, digital accessibility developments in Europe, and Missouri’s new safe harbor law for website accessibility claims.

Compliance Brief - Data Privacy

CalPrivacy fines second data broker in a single week

The California Privacy Protection Agency (CalPrivacy) ordered data broker Cybba, Inc. to pay a $52,400 fine for failing to register with the state’s Data Broker Registry by the 2025 deadline. The action came shortly after a similar decision against LocateSmarter, marking two enforcement actions against unregistered data brokers in less than a week.

Cybba sells personal information, including geolocation and internet activity data, for targeted advertising. In addition to the fine, the company must publish privacy-rights metrics on its website and connect to California’s Delete Request and Opt-Out Platform (DROP), which allows consumers to request deletion from registered data brokers through a single submission.

CalPrivacy has indicated that enforcement under the Delete Act and CCPA will continue. Businesses operating as data brokers should review their registration status and make sure their deletion and opt-out processes can handle DROP requests.

Learn more

Colorado opens comment period on AI and chatbot safety rules

The Colorado Attorney General’s Office filed proposed rules under the state’s Automated Decision-Making Technology Act and Chatbot Safety Act, opening a public comment period from August 11 through October 26, 2026. The rules are intended to clarify requirements for developers and deployers of high-risk AI systems, as well as chatbot operators, before the laws take effect on January 1, 2027.

The proposals cover areas including consumer rights to correct inaccurate data used in automated decisions, age-estimation requirements, chatbot AI disclosures, and the annual safety reports certain chatbot operators must submit to the Attorney General.

Organizations using automated decision-making tools or conversational AI should review the proposals, particularly where these systems may interact with minors. Comments submitted during the rulemaking process could influence the final requirements.

Learn more

ICO launches free data protection training for small businesses

The UK Information Commissioner’s Office (ICO) has launched Data Protection Essentials, a free, self-paced training and assessment program for small and medium-sized organizations, employees, and sole traders.

The program includes 13 modules lasting around 10 to 15 minutes each, followed by a self-assessment covering how an organization handles personal information and where improvements may be needed. Organizations that complete the program can receive a digital certificate and choose to appear on a public Data Protection Essentials register.

The training is primarily aimed at organizations with fewer than 250 employees that do not have a dedicated Data Protection Officer or carry out high-risk processing. For smaller organizations, it provides a practical way to review and document their core data protection practices.

Learn more

EU e-Evidence Regulation applies from August 18

The EU e-Evidence Regulation will apply across the European Union from August 18, 2026, following a three-year transition period. It will allow judicial authorities in one member state to request electronic evidence directly from service providers based in another, rather than relying on authorities in the provider’s home country in many cases.

Service providers must have a designated establishment or legal representative in the EU to receive these requests. Some uncertainty remains around how certain terms will be interpreted and implemented across member states.

Online platforms, cloud providers, and other covered service providers should review their designated contact arrangements and response procedures. The regulation includes tight deadlines, including eight hours for emergency requests and 10 days for standard requests.

Learn more

New Jersey adopts kids’ privacy law with private right of action

New Jersey Governor Mikie Sherrill signed the New Jersey Kids Code Act, introducing age-appropriate privacy requirements for certain online services likely to be accessed by minors. The law includes a private right of action and statutory damages of $5,000 per violation.

Covered services must use stronger privacy defaults for minors, restrict certain targeted advertising, prohibit dark patterns, limit push notifications during school hours and late at night, and provide ways for minors to delete their accounts or report harmful content. Data collected for age verification may only be used for that purpose and must be deleted within 15 days.

The law takes effect on September 1, 2027. Websites and apps that may be accessed by minors should assess whether they fall within its scope and what changes could be required before the effective date.

Learn more

Compliance Brief - Accessibility

Web accessibility news

European Central Bank builds accessibility into digital euro app

The European Central Bank (ECB) says the digital euro app now in development is being designed to go beyond the requirements of the European Accessibility Act and EN 301 549. Planned features include keyboard navigation, screen reader compatibility, simplified language options, error prevention, time-out warnings, and reduced-motion settings.

The ECB is developing the app with consumer groups and accessibility experts. Dedicated accessibility and usability testing is planned during the digital euro pilot phase in 2027, including work with the ONCE Foundation and 19 national central banks.

The project provides a useful example of accessibility being considered during product design rather than addressed after launch, particularly for organizations working with EAA and EN 301 549 requirements.

Learn more

AccessibleEU launches advanced accessible technology course

The European Commission’s AccessibleEU Centre has launched a free advanced online course for professionals who want to deepen their technical accessibility knowledge. Accessible Technology Design, Advanced opens for enrollment on September 14 and runs through December 10, 2026.

The eight-module course covers areas including semantic markup, images, visual design, responsive design and zoom, multimedia and motion, forms, dynamic content, and design requirements for different users.

For compliance, design, and development teams, the course provides a free way to build internal accessibility knowledge and supplement existing testing or audit processes.

Learn more

Missouri website accessibility safe harbor law takes effect August 28

Missouri’s Act Against Abusive Website or Web Content Access Litigation takes effect on August 28, 2026. The law addresses certain demand letters and lawsuits alleging inaccessible websites and introduces protections for businesses that respond to accessibility complaints.

Under the law, businesses can receive a 90-day safe harbor if they take substantial, good-faith steps to address an alleged accessibility issue after receiving notice. It also creates remedies against plaintiffs or law firms found to have pursued abusive litigation. Public entities are not covered.

The law does not remove underlying accessibility obligations or limit potential exposure under federal laws such as Title III of the ADA. Businesses receiving an accessibility demand should still document their response, remediation work, and any accessibility testing carried out during the 90-day period.

Learn more

Until next week

This week brought developments across data privacy, AI, children’s privacy, and web accessibility, from continued data broker enforcement in California to new accessibility protections and resources in Missouri and the EU.

For privacy, compliance, and accessibility teams, the common theme is preparation: reviewing data broker relationships, AI features, accessibility processes, and the documentation that supports them.

We’ll be back next week with the latest privacy, accessibility, and digital compliance developments.

Adam Safar

Head of Digital Marketing

Adam is the Head of Digital Marketing at Clym, where he leverages his diverse expertise in marketing to support businesses with their compliance needs and drive awareness about data privacy and web accessibility. As one of the company’s original team members, Adam has been instrumental in shaping its journey from the very beginning. When he’s not diving into marketing strategies, Adam can be found cheering on his favorite sports teams or enjoying fishing.

Find out more about Adam