Clym Logo

Weekly Compliance Brief: July 13 – 17, 2026

Published
AS
AuthorAdam Safar
6 min read

Weekly Compliance Brief: July 13-17, 2026

This week: a binding EDPB cookie ruling, Germany's new terminal accessibility rules, and serial ADA website lawsuits.

Summarize full article with:

Here are the key data privacy and accessibility developments from July 13–17, 2026. This week’s roundup covers an EDPB ruling on a cookie banner complaint, updated accessibility rules for self-service terminals in Germany, and growing criticism of serial ADA website lawsuits.

Compliance Brief - Data Privacy

Data privacy law news

EDPB raises the standard for anonymising personal data

On 7 July 2026, the European Data Protection Board adopted draft Guidelines 02/2026 on Anonymisation, updating the framework used to determine when data falls outside the GDPR.

The draft supports a relative approach to identifiability, meaning data may be anonymous for one recipient but remain personal data for another. It also introduces a three-part re-identification risk assessment covering singling out, linkability, and inference.

Organisations using anonymised or aggregated data for analytics, advertising, or AI training may need stronger documentation and regular reassessments as re-identification techniques develop. The EDPB is accepting feedback until 30 October 2026.

Learn more

Australia prepares new transparency rules for automated decisions

Australia’s automated decision-making transparency requirements take effect on 10 December 2026 under updated Australian Privacy Principles 1.7 to 1.9.

Businesses will need to explain in their privacy policies when a computer program makes, or substantially contributes to, a decision that significantly affects a person’s rights or interests using their personal information.

The rules are not limited to AI. They may also cover rules-based systems, scoring tools, spreadsheet automation, and third-party platforms used on a business’s behalf.

Regulator guidance is expected in September 2026, leaving businesses a limited window to identify relevant systems and prepare the required disclosures.

Learn more

EDPB requires Belgian regulator to reconsider cookie banner complaint

On 14 July 2026, the European Data Protection Board published a binding decision requiring Belgium’s data protection authority to assess a cookie banner complaint against Flemish broadcaster VRT on its merits.

The complaint, submitted by privacy group noyb on behalf of an individual, had been dismissed over an alleged abuse of the GDPR complaint process. Austria’s data protection authority objected, and the EDPB agreed that the complaint should receive a substantive review.

The decision shows that procedural arguments cannot easily be used to avoid examining cookie consent complaints. The Belgian authority must now issue a new decision addressing the complaint itself.

Learn more

EDPS publishes checklist for meaningful human oversight

The European Data Protection Supervisor has published a self-assessment checklist for evaluating human oversight of automated decision-making.

The checklist makes clear that simply placing a person “in the loop” is not enough. Reviewers need appropriate training, sufficient time and information, and genuine authority to challenge or override a system’s output.

Although designed for EU institutions, the checklist may also provide a useful benchmark for organisations using automated or AI-assisted decisions that affect individuals, particularly in relation to GDPR Article 22.

It covers governance measures, escalation processes, override capabilities, sampling, and audits.

Learn more

New Hampshire bans the sale of children’s personal data

On 19 June 2026, New Hampshire Governor Kelly Ayotte signed an amendment to the state’s Data Privacy Act banning the sale of a child’s personal data, even where consent has been obtained.

The amendment defines a child consistently with COPPA as anyone under 13 and takes effect on 1 January 2027.

Businesses that collect data from known child users should review their data-sale practices, advertising arrangements, and monetisation partnerships before the new rule takes effect.

Learn more

Compliance Brief - Accessibility

Web accessibility news

Germany updates accessibility rules for self-service terminals

Germany amended its accessibility regulations on 16 July 2026 after the European Commission identified gaps in the country’s implementation of EU accessibility requirements.

Under the revised rules, self-service terminals such as kiosks, ticket machines, and payment terminals cannot require users to activate an accessibility function before they can turn on the device.

Terminals already lawfully in use before 28 June 2025 may generally remain in operation for up to 15 years. New and replacement devices must meet the updated requirements.

Businesses deploying terminals in Germany should review their equipment specifications and confirm that vendors support the revised accessibility standard.

Learn more

Serial accessibility lawsuits raise concerns among disability advocates

A series of nearly identical ADA lawsuits against small e-commerce businesses is drawing criticism from disability advocates who question whether the cases lead to meaningful accessibility improvements.

The lawsuits, reportedly filed by the same visually impaired plaintiff, often result in confidential settlements without a public record of which website issues were fixed.

The National Federation of the Blind and other advocates warn that this litigation model could encourage legislation that makes legitimate ADA claims harder to bring while doing little to improve accessibility.

For smaller website operators, the cases highlight the value of addressing accessibility issues proactively and publishing a clear accessibility statement rather than waiting for a demand letter.

Learn more

DOJ challenges the right to sue federal agencies under Section 504

In a case involving the removal of sign language interpreters from White House press briefings, the US Department of Justice argued on 16 July 2026 that individuals do not have a private right to sue federal agencies under Section 504 of the Rehabilitation Act.

Nine disability rights organisations filed a joint amicus brief opposing that position, warning that it could make disability discrimination across federal programmes and services much harder to challenge.

The case focuses on federal agencies, but the outcome could also affect organisations that receive federal funding and are subject to Section 504.

A three-judge appeals panel is expected to rule on the case, although no timeline has been announced.

Learn more

Until next week

This week’s developments show regulators placing greater emphasis on enforcement, transparency, and documented action. For website, marketing, and compliance teams, consent management, automated decision-making, and accessibility should be treated as ongoing programmes rather than one-time projects. We’ll be back next week with more privacy, accessibility, and digital compliance updates.

Adam Safar

Head of Digital Marketing

Adam is the Head of Digital Marketing at Clym, where he leverages his diverse expertise in marketing to support businesses with their compliance needs and drive awareness about data privacy and web accessibility. As one of the company’s original team members, Adam has been instrumental in shaping its journey from the very beginning. When he’s not diving into marketing strategies, Adam can be found cheering on his favorite sports teams or enjoying fishing.

Find out more about Adam