Weekly Compliance Brief: July 20-24, 2026
This week: a Swiss ruling redefines breach notice, France bans teen social media, and EU rulings reshape platform liability and accessibility rules.
This week: a Swiss ruling redefines breach notice, France bans teen social media, and EU rulings reshape platform liability and accessibility rules.
Here are the key data privacy and accessibility developments from July 20–24, 2026. This week’s roundup covers new Swiss guidance on data breach notifications, France’s proposed social media restrictions for children under 15, accessibility shortcomings among major Dutch retailers, and an EU ruling that could affect platform liability.

The Swiss Federal Administrative Court has issued its first interpretation of Article 24 of the Federal Act on Data Protection, which governs data breach notifications.
The court found that a security breach can exist even without evidence that an unauthorised person actually accessed the exposed data. It also confirmed that notifying affected individuals can be a preventive measure rather than something triggered only by proven harm.
Organisations operating in Switzerland should review how they assess and document potential data exposure when deciding whether a breach requires notification.
The European Data Protection Board has published its final guidelines on processing personal data through blockchain technologies.
The guidance makes clear that blockchain’s technical characteristics do not override GDPR requirements and recommends limiting personal data stored directly on-chain. Where personal data is involved, the EDPB also favours private or permissioned blockchain models over public ones where appropriate.
Businesses using blockchain for areas such as identity verification, loyalty programmes, or supply chains should clearly document controller and processor roles, minimise personal data, and account for international data transfers from the outset.
France’s Parliament has approved legislation that would prevent children under 15 from accessing social media platforms.
Platforms would need to verify users’ ages and prevent new underage accounts from 1 September 2026, with existing accounts belonging to children under 15 due to close by 1 January 2027.
The legislation still faces a constitutionality review. However, it adds to growing regulatory pressure around age assurance and children’s online safety in Europe.
Businesses operating platforms or digital services used by children should continue monitoring how age-verification requirements develop in France and across the EU.
The EU’s new GDPR Procedural Regulation will introduce common rules for handling cross-border GDPR complaints and investigations.
For cases opened after 2 April 2027, supervisory authorities will face clearer deadlines and procedures, while complainants and organisations under investigation will receive additional rights to be heard before decisions are issued.
The regulation is intended to make the GDPR’s cross-border enforcement process more consistent and predictable.
Organisations operating across multiple EU countries should prepare for more structured timelines and procedures when dealing with cross-border complaints.
New Jersey has introduced new registration and disclosure requirements for certain data brokers and data collectors, alongside restrictions on selling or licensing sensitive data.
Annual registration fees will vary depending on the amount of New Jersey residents’ data held and can reach as much as $1.5 million for the largest organisations.
Enforcement of the registration and fee requirements has been paused until the state registry launches in spring 2027, while restrictions involving sensitive data are already in effect.
Businesses that sell, license, or otherwise monetise personal data should assess whether their activities fall within the new definitions and requirements.

Netflix has begun offering American Sign Language interpreter overlays across 73 children’s and family titles through a partnership with SignUp Media.
The feature adds ASL interpretation alongside existing accessibility options such as subtitles, SDH, dubbing, and audio description, and is available through a Chrome extension.
The rollout highlights how video accessibility can extend beyond captions and screen-reader compatibility, particularly for younger audiences.
Organisations producing video content may want to consider whether additional formats could make their content accessible to a wider audience.
The US Department of Justice has stated that its guidance on the ADA’s integration mandate, in place since 2011, is not independently enforceable and will no longer be relied upon in Title II enforcement.
The notice follows other recent DOJ moves reconsidering how non-binding ADA guidance should be used in enforcement.
For organisations working on accessibility, the development highlights the distinction between statutory or regulatory requirements and non-binding agency guidance. Technical guidance may remain useful, but it does not necessarily reflect how an agency will approach future enforcement.
Manufacturers of televisions, streaming devices, and other video playback equipment, along with multichannel video providers, must make closed-caption display settings readily accessible by 17 August 2026.
The FCC will assess accessibility based on factors including proximity, discoverability, previewability, and consistency, while allowing companies flexibility in how they meet the requirement.
Businesses covered by the rules should review how easily users can find, preview, and adjust caption settings before the deadline.
Microsoft’s latest Xbox restructuring has significantly reduced its centralised gaming accessibility team, including funding for its accessibility testing service and several specialist roles.
Microsoft says accessibility remains a priority, but the changes have raised concerns among accessibility advocates about the loss of dedicated expertise and testing resources.
For other organisations, the restructuring highlights the risk of concentrating accessibility knowledge within a small specialist team.
Documenting accessibility practices and embedding that knowledge across product, design, development, and testing teams can help reduce that dependency.
An investigation by the Netherlands Authority for Consumers and Markets found that 61% of the country’s largest online retailers do not meet European Accessibility Act requirements.
The regulator found accessibility problems that can prevent people with disabilities from independently completing online purchases.
The ACM can impose fines of up to €900,000 or 1% of annual turnover, although it has not yet issued EAA fines against Dutch online retailers.
For ecommerce businesses, the findings highlight the importance of testing complete customer journeys, particularly product selection, checkout, and payment flows, rather than focusing only on individual pages.

A California bill that would have established a whistleblower programme for privacy violations has stalled after failing to receive a required policy committee hearing.
The proposal, sponsored by the California Privacy Protection Agency, would have allowed individuals to report companies’ data practices directly to CalPrivacy and potentially receive an award if the information led to enforcement.
The bill will not advance this session, meaning businesses have one less potential privacy enforcement channel to account for in California for now.
Similar proposals could return in future legislative sessions.

A Court of Justice of the European Union ruling in Coyote System has raised questions about when online platforms may lose liability protections for user-generated content.
The ruling considers the degree of control a platform exercises over how content is organised and presented, including the role of algorithms.
Digital rights groups have warned that a broad interpretation could affect platforms that use recommendation systems while relying on hosting liability protections.
Platforms and marketplaces operating in the EU should monitor how national courts apply the ruling before making changes to recommendation or content moderation systems.
This week’s developments show privacy and accessibility requirements continuing to evolve through legislation, court decisions, regulatory enforcement, and new technical requirements.
For businesses, that means keeping breach procedures, age-assurance practices, accessibility testing, and platform governance under regular review rather than treating compliance as a one-time exercise.
We’ll be back next week with the latest privacy, accessibility, and digital compliance developments.