Top stories this week
Australia, Delaware, and Indonesia advance privacy reforms, the EU updates its accessibility standard, and courts address platform liability.
Australia, Delaware, and Indonesia advance privacy reforms, the EU updates its accessibility standard, and courts address platform liability.

Australia’s Attorney-General’s Department has released a consultation package for the draft Privacy Amendment (Personal Data Protection) Bill 2026, building on reforms passed in 2024. Feedback is open until September 18.
A central proposal is a new “fair and reasonable” test that requires organizations to justify how they collect, use, and disclose personal information, rather than relying on consent and privacy notices alone. The package also proposes a right to erasure and a new IDLock initiative designed to give individuals greater control over identity documents.
Businesses using AI, digital marketing, or large-scale analytics in Australia should begin reviewing their governance and documentation. Under the proposal, organizations would need to demonstrate that their data handling is fair and reasonable, not simply lawful.
Both chambers of the California Legislature have passed SB 690, which would amend the California Invasion of Privacy Act (CIPA) in response to lawsuits involving common website technologies such as chat widgets, session-replay tools, and marketing pixels. The bill now heads to Governor Gavin Newsom.
SB 690 follows a surge in CIPA “pen register” and wiretapping claims against businesses and publishers using widely adopted analytics and marketing technologies. News/Media Alliance members, including the Los Angeles Times, provided testimony about the impact of these lawsuits on publishers.
If signed, the bill could provide relief to website operators facing litigation over routine tracking technologies. It would not, however, eliminate the underlying need to disclose data collection practices and obtain appropriate consent.
Delaware Governor Matt Meyer has signed HB 380, significantly revising the state’s consumer privacy law less than two years after it took effect. The changes become effective January 1, 2027.
The law lowers applicability thresholds to 10,000 consumers, or 5,000 for businesses selling personal data. It also brings third parties purchasing personal data into scope and expands sensitive data to include financial information, government ID numbers, and neural data. New requirements cover contracts and due diligence for transfers to third parties, as well as profiling disclosures.
Businesses that previously fell outside Delaware’s thresholds should reassess whether the law now applies to them. Organizations sharing personal data with ad-tech, analytics, and other third-party vendors should also review contracts and due diligence processes ahead of 2027.
The California Privacy Protection Agency (CPPA) has issued an enforcement advisory warning data brokers that inaccurate information in annual registrations can result in daily fines under the Delete Act. The agency says it has already pursued multiple enforcement actions involving reporting errors.
Data brokers that fail to register correctly can face fines of $200 per day. The advisory follows recent enforcement activity involving General Motors, Ford, and other companies over data-sharing and opt-out practices.
Businesses that qualify as data brokers under the Delete Act should review their registration information for accuracy. The CPPA has made clear that incorrect reporting, not just failure to register, is an enforcement priority.
Indonesia has published Government Regulation No. 33 of 2026, implementing its Personal Data Protection Law nearly two years after the law’s transitional period expired. The regulation was enacted in July 2026 and began circulating in late August ahead of a formal government announcement.
The rules cover four conditions for valid consent, a 13-item minimum for records of processing activities, mandatory data protection impact assessments for higher-risk processing such as AI and automated decision-making, and a three-tier framework for cross-border data transfers. They take effect on January 16, 2027.
Organizations already aligned with GDPR or similar frameworks should still assess Indonesia’s country-specific requirements. Consent, documentation, and cross-border transfer rules may require changes to existing privacy programs.

The European Telecommunications Standards Institute has published EN 301 549 V4.1.1, updating the standard underpinning the EU’s Web Accessibility Directive and European Accessibility Act. The new version, adopted on August 24, 2026, replaces V3.2.1.
The update aligns web, software, and document requirements with WCAG 2.2, including six newer success criteria covering areas such as target size, accessible authentication, and consistent help. It also significantly revises requirements for real-time text.
The EU’s Official Journal still cites V3.2.1 as the recognized benchmark for Web Accessibility Directive conformance, meaning V4.1.1 is not yet the mandatory reference. Organizations working toward European accessibility requirements should nevertheless begin tracking the newer criteria.
UK charity AbilityNet and Mova have published Inclusive by Design, examining how inaccessible digital and other services affect people with access needs. Based on in-depth interviews, the research found that repeated service failures can contribute to shame, anxiety, exhaustion, and reduced independence.
The report cites Financial Conduct Authority data indicating that 49% of UK adults, or 26.4 million people, have at least one vulnerability characteristic. It also highlights the additional burden inaccessible services can place on family caregivers. AbilityNet says it supported 20,000 people trying to access essential services in 2025.
The report recommends embedding inclusive design into governance from the outset rather than retrofitting accessibility later. For organizations providing digital services, accessibility gaps can create both compliance risks and broader human and operational costs.

The Court of Justice of the European Union (CJEU) has clarified when online platforms may lose the passive hosting safe harbor that protects intermediaries from liability for user-generated content.
In a case involving Google’s YouTube platform, the court found that reviewing channels before admitting them to a revenue-sharing partner program could amount to active knowledge inconsistent with passive hosting status. A related ruling found that algorithms controlling how content is prioritized or distributed can independently affect eligibility for hosting protection.
The decisions could have wider implications for platforms using recommendation systems, ranking tools, and monetization programs. Operators may need to assess whether these functions remain neutral technical activities or amount to active control over content.
A Mumbai civil court has ordered Meta and Reddit to remove posts describing actor Sayani Gupta’s short film as plagiarized while allowing content based on official investigations or judicial findings to remain available.
No court has yet ruled on the underlying plagiarism allegation. This leaves platforms with the difficult task of distinguishing contested allegations from content grounded in official findings while litigation remains unresolved.
The decision illustrates the challenges platforms face when courts require real-time judgments about the accuracy of user-generated content, particularly where automated moderation could remove legitimate commentary alongside defamatory material.

Honeywell Aerospace has agreed to pay more than $2 million to resolve allegations that it falsely certified compliance with federal cybersecurity requirements under a Department of Defense contract. The U.S. Department of Justice alleged that the company failed to meet NIST Special Publication 800-171 requirements on one network between 2020 and 2023.
A former Honeywell employee brought the case under the False Claims Act’s whistleblower provisions. She will receive more than $375,000, approximately 18% of the settlement, as her share of the recovery.
The settlement highlights the legal risks associated with inaccurate cybersecurity representations in government contracts. It also demonstrates how employees who identify differences between stated and actual practices can use whistleblower provisions to report those gaps.
This week’s developments show regulators and courts increasingly looking beyond written policies to how compliance measures operate in practice.
From Australia’s proposed “fair and reasonable” test and California’s scrutiny of data broker registrations to evolving accessibility standards and platform liability, organizations face growing pressure to demonstrate that their privacy, accessibility, and governance practices work as intended.
We’ll be back next week with the latest privacy, accessibility, and digital compliance developments.