Clym Logo

Weekly Compliance Brief: August 31 - September 4, 2026

Published
AS
AuthorAdam Safar
6 min read

Top stories this week

Australia, Delaware, and Indonesia advance privacy reforms, the EU updates its accessibility standard, and courts address platform liability.

Summarize full article with:

Compliance Brief - Data Privacy

Australia proposes second wave of Privacy Act reforms

Australia’s Attorney-General’s Department has released a consultation package for the draft Privacy Amendment (Personal Data Protection) Bill 2026, building on reforms passed in 2024. Feedback is open until September 18.

A central proposal is a new “fair and reasonable” test that requires organizations to justify how they collect, use, and disclose personal information, rather than relying on consent and privacy notices alone. The package also proposes a right to erasure and a new IDLock initiative designed to give individuals greater control over identity documents.

Businesses using AI, digital marketing, or large-scale analytics in Australia should begin reviewing their governance and documentation. Under the proposal, organizations would need to demonstrate that their data handling is fair and reasonable, not simply lawful.

Learn more

California passes bill targeting abusive CIPA tracking lawsuits

Both chambers of the California Legislature have passed SB 690, which would amend the California Invasion of Privacy Act (CIPA) in response to lawsuits involving common website technologies such as chat widgets, session-replay tools, and marketing pixels. The bill now heads to Governor Gavin Newsom.

SB 690 follows a surge in CIPA “pen register” and wiretapping claims against businesses and publishers using widely adopted analytics and marketing technologies. News/Media Alliance members, including the Los Angeles Times, provided testimony about the impact of these lawsuits on publishers.

If signed, the bill could provide relief to website operators facing litigation over routine tracking technologies. It would not, however, eliminate the underlying need to disclose data collection practices and obtain appropriate consent.

Learn more

Delaware significantly expands its consumer privacy law

Delaware Governor Matt Meyer has signed HB 380, significantly revising the state’s consumer privacy law less than two years after it took effect. The changes become effective January 1, 2027.

The law lowers applicability thresholds to 10,000 consumers, or 5,000 for businesses selling personal data. It also brings third parties purchasing personal data into scope and expands sensitive data to include financial information, government ID numbers, and neural data. New requirements cover contracts and due diligence for transfers to third parties, as well as profiling disclosures.

Businesses that previously fell outside Delaware’s thresholds should reassess whether the law now applies to them. Organizations sharing personal data with ad-tech, analytics, and other third-party vendors should also review contracts and due diligence processes ahead of 2027.

Learn more

California regulator warns data brokers over registration errors

The California Privacy Protection Agency (CPPA) has issued an enforcement advisory warning data brokers that inaccurate information in annual registrations can result in daily fines under the Delete Act. The agency says it has already pursued multiple enforcement actions involving reporting errors.

Data brokers that fail to register correctly can face fines of $200 per day. The advisory follows recent enforcement activity involving General Motors, Ford, and other companies over data-sharing and opt-out practices.

Businesses that qualify as data brokers under the Delete Act should review their registration information for accuracy. The CPPA has made clear that incorrect reporting, not just failure to register, is an enforcement priority.

Learn more

Indonesia issues long-awaited data protection rules

Indonesia has published Government Regulation No. 33 of 2026, implementing its Personal Data Protection Law nearly two years after the law’s transitional period expired. The regulation was enacted in July 2026 and began circulating in late August ahead of a formal government announcement.

The rules cover four conditions for valid consent, a 13-item minimum for records of processing activities, mandatory data protection impact assessments for higher-risk processing such as AI and automated decision-making, and a three-tier framework for cross-border data transfers. They take effect on January 16, 2027.

Organizations already aligned with GDPR or similar frameworks should still assess Indonesia’s country-specific requirements. Consent, documentation, and cross-border transfer rules may require changes to existing privacy programs.

Learn more

Compliance Brief - Accessibility

Web accessibility news

Updated EU accessibility standard aligns with WCAG 2.2

The European Telecommunications Standards Institute has published EN 301 549 V4.1.1, updating the standard underpinning the EU’s Web Accessibility Directive and European Accessibility Act. The new version, adopted on August 24, 2026, replaces V3.2.1.

The update aligns web, software, and document requirements with WCAG 2.2, including six newer success criteria covering areas such as target size, accessible authentication, and consistent help. It also significantly revises requirements for real-time text.

The EU’s Official Journal still cites V3.2.1 as the recognized benchmark for Web Accessibility Directive conformance, meaning V4.1.1 is not yet the mandatory reference. Organizations working toward European accessibility requirements should nevertheless begin tracking the newer criteria.

Learn more

Report links inaccessible digital services to psychological harm

UK charity AbilityNet and Mova have published Inclusive by Design, examining how inaccessible digital and other services affect people with access needs. Based on in-depth interviews, the research found that repeated service failures can contribute to shame, anxiety, exhaustion, and reduced independence.

The report cites Financial Conduct Authority data indicating that 49% of UK adults, or 26.4 million people, have at least one vulnerability characteristic. It also highlights the additional burden inaccessible services can place on family caregivers. AbilityNet says it supported 20,000 people trying to access essential services in 2025.

The report recommends embedding inclusive design into governance from the outset rather than retrofitting accessibility later. For organizations providing digital services, accessibility gaps can create both compliance risks and broader human and operational costs.

Learn more

Content takedown news

Content takedown news

CJEU clarifies limits of platform hosting safe harbor

The Court of Justice of the European Union (CJEU) has clarified when online platforms may lose the passive hosting safe harbor that protects intermediaries from liability for user-generated content.

In a case involving Google’s YouTube platform, the court found that reviewing channels before admitting them to a revenue-sharing partner program could amount to active knowledge inconsistent with passive hosting status. A related ruling found that algorithms controlling how content is prioritized or distributed can independently affect eligibility for hosting protection.

The decisions could have wider implications for platforms using recommendation systems, ranking tools, and monetization programs. Operators may need to assess whether these functions remain neutral technical activities or amount to active control over content.

Learn more

Mumbai court orders removal of defamatory posts while preserving factual content

A Mumbai civil court has ordered Meta and Reddit to remove posts describing actor Sayani Gupta’s short film as plagiarized while allowing content based on official investigations or judicial findings to remain available.

No court has yet ruled on the underlying plagiarism allegation. This leaves platforms with the difficult task of distinguishing contested allegations from content grounded in official findings while litigation remains unresolved.

The decision illustrates the challenges platforms face when courts require real-time judgments about the accuracy of user-generated content, particularly where automated moderation could remove legitimate commentary alongside defamatory material.

Learn more

Compliance Brief - Whistleblowing

Whistleblowing news

Honeywell pays $2 million over cybersecurity compliance allegations

Honeywell Aerospace has agreed to pay more than $2 million to resolve allegations that it falsely certified compliance with federal cybersecurity requirements under a Department of Defense contract. The U.S. Department of Justice alleged that the company failed to meet NIST Special Publication 800-171 requirements on one network between 2020 and 2023.

A former Honeywell employee brought the case under the False Claims Act’s whistleblower provisions. She will receive more than $375,000, approximately 18% of the settlement, as her share of the recovery.

The settlement highlights the legal risks associated with inaccurate cybersecurity representations in government contracts. It also demonstrates how employees who identify differences between stated and actual practices can use whistleblower provisions to report those gaps.

Learn more

Until next week

This week’s developments show regulators and courts increasingly looking beyond written policies to how compliance measures operate in practice.

From Australia’s proposed “fair and reasonable” test and California’s scrutiny of data broker registrations to evolving accessibility standards and platform liability, organizations face growing pressure to demonstrate that their privacy, accessibility, and governance practices work as intended.

We’ll be back next week with the latest privacy, accessibility, and digital compliance developments.

Adam Safar

Head of Digital Marketing

Adam is the Head of Digital Marketing at Clym, where he leverages his diverse expertise in marketing to support businesses with their compliance needs and drive awareness about data privacy and web accessibility. As one of the company’s original team members, Adam has been instrumental in shaping its journey from the very beginning. When he’s not diving into marketing strategies, Adam can be found cheering on his favorite sports teams or enjoying fishing.

Find out more about Adam