Weekly Compliance Brief: August 17-21, 2026
This week: CalPrivacy advances GPC rulemaking, Greece designates its AI Act enforcer, HIPAA turns 30, and states report accessibility resourcing gaps.
This week: CalPrivacy advances GPC rulemaking, Greece designates its AI Act enforcer, HIPAA turns 30, and states report accessibility resourcing gaps.
Here are the key data privacy and accessibility developments. California moves toward new opt-out rules, Washington publishes its first statewide privacy report, the EDPB weighs in on anonymization, and new data highlights accessibility resource gaps across U.S. states.

Washington Attorney General Nick Brown released the state’s first Data Privacy Report, highlighting concerns around personal data collection, breaches, surveillance, and consumer control. The report cites 209 data breaches in 2025 affecting more than 8 million Washington residents, with over 80% involving Social Security numbers.
In a survey of more than 700 residents, 83% said they had little or no control over who accesses their personal information. The report recommends stronger baseline protections, greater enforcement capacity, and better public digital literacy, with the AG’s office also planning plain-language guidance on data collection, cookies, and deceptive design.
The California Privacy Protection Agency has directed staff to draft rules that would explicitly name Global Privacy Control (GPC) in CCPA regulations and clarify how businesses must honor opt-out preference signals, including before deploying trackers that sell or share personal data. The agency is also pursuing independent audits of data broker deletion compliance.
Meanwhile, California’s Delete Request and Opt-out Platform (DROP) has received roughly 450,000 deletion requests covering more than 200 million identifiers. Annual data broker registration and DROP access fees will rise from $6,000 to $9,500 in 2027.
The European Data Protection Board has released draft guidelines on when information can be considered anonymous and therefore fall outside the GDPR. The guidance is open for public comment until October 30, 2026.
The EDPB says anonymization should prevent individuals from being isolated, linked across datasets, or having new information inferred about them. It also warns that data anonymous to one organization may become identifiable when shared with a recipient that has additional data or more advanced tools, including AI agents.
As HIPAA marks its 30th anniversary, HHS’s Fall 2026 Unified Agenda points to changes ahead for the Privacy Rule. A Final Rule expected in August would address information sharing for care coordination, while a Proposed Rule expected in November would revisit how quickly organizations must respond to requests for health information.
A separate Security Rule update focused on cybersecurity has moved to HHS’s long-term agenda, with a Final Rule now expected in July 2027. These dates remain estimates rather than binding deadlines.
Greece has designated the Hellenic Data Protection Authority as its market surveillance authority for key parts of the EU AI Act, including prohibited practices, certain high-risk AI systems, and Article 50 transparency requirements.
The authority will also serve as Greece’s single point of contact with EU and national regulators and help operate the country’s AI regulatory sandbox. With AI Act transparency requirements already in force, businesses using AI-powered chatbots, content generation, or similar tools in Greece now have a clearly designated national enforcement authority.

A NASCIO survey of 36 state digital accessibility officers found that at least 40 of 56 U.S. states and territories now have a designated accessibility lead, but resources remain limited. Sixty-seven percent of respondents lack a dedicated accessibility budget, while most accessibility teams have fewer than 10 staff.
Only 17% have oversight across all state agencies, and 69% said they lack the resources and staff needed to remediate all websites and applications ahead of the DOJ’s extended Title II deadline. The findings highlight the capacity challenges government agencies face as accessibility deadlines approach.
AbilityNet says the way AI systems serve disabled users is becoming an important measure of whether those systems can be trusted. The organization highlights potential bias in AI-powered hiring tools, chatbots, and content generation when accessibility isn’t considered during design and testing.
For teams introducing AI features into websites and digital products, involving disabled users and accessibility specialists earlier can help identify exclusion and bias before systems are deployed.
This week brought new developments across privacy, AI governance, and accessibility, from California’s proposed GPC rules to Greece’s AI Act enforcement framework and growing accessibility resource pressures across U.S. states.
We’ll be back next week with the latest privacy, accessibility, and digital compliance developments.