Clym Logo

Weekly Compliance Brief: August 24 - 28, 2026

Published
AS
AuthorAdam Safar
6 min read

Weekly Compliance Brief: August 24-28, 2026

This week: Denmark, Brazil, Australia, Ireland, and the US hand down privacy rulings, Missouri and the FCC ease accessibility rules, and Meta settles for $17B.

Summarize full article with:

This week’s roundup covers key data privacy and accessibility developments from August 24–28, 2026. Regulators and courts in Denmark, Brazil, Australia, Ireland, and the United States addressed sensitive data disclosures, children’s privacy, tracking pixels, access requests, and biometric data.

Missouri and the FCC also introduced measures to reduce accessibility-related litigation and administrative burdens, while a major Meta child safety settlement highlighted the legal consequences of product safety decisions.

Compliance Brief - Data Privacy

Danish Supreme Court awards 30,000 kroner over health data disclosure

Denmark’s Supreme Court (Højesteret) has awarded a woman 30,000 kroner in damages after Hillerød Municipality mistakenly disclosed sensitive mental health information to her husband’s former spouse while processing a public records request.

The parties agreed the disclosure breached Denmark’s data protection rules, and the Supreme Court found that it also violated the woman’s right to privacy under the European Convention on Human Rights. The award was significantly higher than the 2,500 kroner set by the lower appeals court, reflecting the sensitivity of the information and its subsequent disclosure.

The ruling provides a clearer benchmark for assessing non-material harm in Danish data protection cases and could influence similar GDPR claims. Organizations handling sensitive personal data should account for the potential financial consequences of accidental disclosures alongside their reporting obligations.

Learn more

Brazil fines TikTok R$153.7 million over children’s data

Brazil’s National Data Protection Authority (ANPD) has fined ByteDance, TikTok’s parent company, R$153.7 million (roughly $28 million) for processing children’s and teenagers’ personal data without a valid legal basis. The decision covers TikTok’s no-login experience and its account-based feed.

ANPD also ordered TikTok to delete data collected during the violations and approved a compliance plan requiring stricter defaults for users under 16. Measures include restrictions on advertising, direct messaging, following, and livestreaming, along with stronger parental controls and age-verification measures tied to Brazil’s Digital ECA framework.

The decision reflects growing regulatory scrutiny of age assurance and privacy-by-default settings. Platforms and websites accessible to minors should consider what data they collect before registration and how they determine a user’s age.

Learn more

Australian regulator finds health websites used tracking pixels without consent

Australia’s Privacy Commissioner has found that Monash IVF and a telehealth provider breached the Australian Privacy Principles by using tracking pixels on webpages covering fertility treatment, egg donation, and medication information, then using the resulting data for targeted advertising.

The regulator found that both companies collected sensitive health information without consent, failed to adequately notify visitors, and used the data for direct marketing without permission. In one case, anonymous visitors were matched to their social media accounts. The determinations also addressed how clearer notice could have satisfied relevant transparency requirements.

The findings place responsibility on businesses deploying tracking technologies, not only the advertising platforms receiving the data. Websites covering health, fertility, or other sensitive topics should review what information their marketing and analytics tools collect and whether those tools activate before consent.

Learn more

Irish High Court upholds GDPR access request exemptions

The Irish High Court has upheld a Data Protection Commission decision allowing a consultancy firm to withhold some information requested through a GDPR access request under exemptions in Ireland’s Data Protection Act 2018. The case concerned a dossier prepared about the requester during separate litigation.

The court confirmed that the exemption for legal claims under Section 60(3)(a)(iv) and legal professional privilege under Section 162 are separate grounds for withholding data and are compatible with restrictions permitted under Article 23 of the GDPR. It also found that withholding information that would identify a third party did not amount to an unlawful blanket refusal.

The ruling provides additional clarity for organizations handling access requests connected to litigation or confidentiality obligations. These exemptions remain context-specific and should be applied narrowly, with the reasoning behind their use documented.

Learn more

US appeals court limits Illinois biometric law for on-device data

The Seventh Circuit Court of Appeals has ruled that Illinois’ Biometric Information Privacy Act (BIPA) does not apply when biometric data is created and stored solely on a user’s device, siding with Samsung in a case involving its Gallery app’s facial-recognition feature.

The court found that BIPA’s requirements for collecting, capturing, or possessing biometric data depend on a company's control over that data. The plaintiffs could not show that Samsung could access, modify, or use the face templates stored locally on their phones.

The ruling highlights a potentially important distinction between on-device and company-controlled biometric processing. Because the decision is binding only within the Seventh Circuit, businesses using biometric technologies should still assess the requirements of each applicable state law.

Learn more

Compliance Brief - Accessibility

Web accessibility news

Missouri law gives businesses 90 days to address website accessibility claims

A Missouri law addressing website accessibility litigation takes effect August 28, 2026. The Act Against Abusive Website or Web Content Access Litigation gives businesses sued over alleged accessibility barriers 90 days to address the issue before a case can proceed.

If a business makes a good-faith effort to resolve the problem during that period, courts must presume the lawsuit was primarily brought to obtain payment rather than address a genuine accessibility barrier. Judges may also consider whether the plaintiff or their law firm has filed a pattern of similar lawsuits.

The law does not remove underlying accessibility obligations or prevent litigation over unresolved barriers. For businesses serving Missouri customers, it introduces an additional procedural protection while leaving the need for accessibility testing and remediation in place.

Learn more

FCC removes captioning reporting requirements for PEG channels

The Federal Communications Commission has voted to eliminate closed-captioning registration and reporting requirements for public, educational, and government (PEG) channels.

The order, adopted August 21 and announced this week, removes reporting requirements for an estimated 290,000 programmers and is expected to save about $2.5 million annually in administrative costs, according to the FCC. The change takes effect at the end of September 2026 but does not alter applicable captioning standards.

The change primarily affects community media operators, not commercial websites. Organizations distributing programming through PEG channels should review which reporting requirements have been removed while continuing to meet applicable captioning obligations.

Learn more

Compliance Brief - Whistleblowing

Whistleblowing news

Meta agrees to $17 billion child safety settlement after whistleblower testimony

Meta has agreed to pay up to $17 billion over 10 years to settle litigation brought by dozens of state attorneys general alleging that Facebook and Instagram were designed to encourage addictive use among children while the company downplayed associated risks. The trial judge approved the settlement on August 26 after the trial began, and it included testimony from former Meta engineer Arturo Bejar.

Bejar, who worked on Instagram’s wellbeing team, testified that safety features were designed as optional rather than default settings and that company decisions prioritized user growth over child wellbeing. Under the settlement, Meta must introduce measures including a default two-hour daily limit for users under 18, restrictions on notifications during certain hours, hidden “like” counts for minors, an algorithm-free feed option, and independent auditing.

The case shows how internal product and safety decisions can become evidence in litigation and influence regulatory outcomes. Organizations developing engagement-driven products for younger users should consider not only which safety controls they offer, but which protections are enabled by default.

Learn more

Until next week

This week’s developments share a common theme: regulators and courts are paying close attention to default settings and what happens before users actively make a choice, from tracking technologies and children’s data collection to product safety controls.

We’ll be back next week with the latest privacy, accessibility, and digital compliance developments.

Adam Safar

Head of Digital Marketing

Adam is the Head of Digital Marketing at Clym, where he leverages his diverse expertise in marketing to support businesses with their compliance needs and drive awareness about data privacy and web accessibility. As one of the company’s original team members, Adam has been instrumental in shaping its journey from the very beginning. When he’s not diving into marketing strategies, Adam can be found cheering on his favorite sports teams or enjoying fishing.

Find out more about Adam