Weekly Compliance Brief: July 27-31, 2026
This week: Greece expands AI Act enforcement, South Korea retains EU adequacy status, and accessibility deadlines approach in the US and India.
This week: Greece expands AI Act enforcement, South Korea retains EU adequacy status, and accessibility deadlines approach in the US and India.
Here are the key data privacy and accessibility developments from July 27–31, 2026. This week’s roundup covers Greece’s new AI Act enforcement framework, the EU’s review of data transfers to South Korea, new findings on privacy consent in Australia, and approaching accessibility deadlines in the US and India.

On 16 July 2026, the Hellenic Parliament adopted Law 5321/2026, establishing Greece’s national enforcement framework for the EU AI Act.
The law designates the Hellenic Data Protection Authority as the market surveillance authority for prohibited AI practices, high-risk systems, and transparency requirements covering areas such as chatbots and deepfakes.
It also brings AI Act infringements within Greece’s whistleblower protection regime and introduces fines of up to 2% of average daily global turnover for continued non-compliance.
For organisations using AI systems in Greece, the framework shows how the AI Act and data protection oversight may increasingly intersect.
The European Data Protection Board has provided further details on its draft guidance covering anonymisation and AI web scraping, with both open for public consultation until 30 October 2026.
The anonymisation guidance focuses on how likely a particular party is to re-identify an individual rather than applying an absolute test. The web scraping guidance emphasises data minimisation and considers approaches such as filtering and the use of synthetic data when training AI models.
Organisations collecting or licensing web data for AI development should review how they determine whether scraped information qualifies as personal data and how much of that data is necessary.
New enforcement powers under the EU AI Act give the European Commission’s AI Office greater authority to oversee how developers of advanced AI models identify and manage risk.
The AI Office can investigate compliance and impose penalties of up to 3% of global annual turnover for relevant infringements.
Questions remain about enforcement capacity, with concerns about whether the AI Office currently has sufficient specialist staff and technical resources to oversee increasingly advanced models.
For AI developers and organisations relying on general-purpose AI, the development marks another step from AI Act preparation toward active oversight and enforcement.
The European Commission has completed its first review of the EU’s 2021 adequacy decision for South Korea and confirmed that the country continues to provide an adequate level of protection for personal data transferred from the EU.
The Commission found that the EU and South Korean data protection frameworks have moved closer together, including through changes that strengthened data subject rights. It also recommended further improvements around onward transfers to third countries and enforcement.
For organisations transferring personal data from the EU to South Korea, the decision means those transfers can continue under the existing adequacy framework without additional transfer safeguards such as Standard Contractual Clauses.
Australia’s 2026 Community Attitudes to Privacy Survey highlights a growing disconnect between how much people value privacy and how they interact with privacy notices online.
Around 69% of Australians say they always or often agree to an organisation’s privacy policy without reading most or all of it, while 93% say protecting their personal information matters to them and 87% are more concerned about privacy than five years ago.
For organisations collecting personal information online, the findings highlight the importance of clear notices and genuine choices. Consent should support fair and transparent data practices rather than relying on users simply clicking “I agree.”

A recent analysis of more than 165,000 pages across 6,100 US and European domains found that EU websites average 25% more accessibility issues per page than their US counterparts, one year after the European Accessibility Act took effect.
Professional services, public sector, and nonprofit websites were among those showing larger accessibility gaps.
For organisations serving EU users, the findings highlight the importance of regularly testing website accessibility and addressing identified issues rather than treating EAA readiness as a one-time exercise.
The Securities and Exchange Board of India has extended the deadline for regulated organisations to remediate findings from digital accessibility audits from 31 July to 31 October 2026.
The extension applies to organisations including stock exchanges, depositories, and registered intermediaries covered by accessibility requirements under India’s Rights of Persons with Disabilities Act.
The deadline has moved, but the underlying audit and remediation requirements remain in place.
Affected financial services organisations now have additional time to address identified accessibility issues before 31 October.
Missouri’s Act Against Abusive Website Access Litigation takes effect on 28 August 2026.
The law provides businesses with a 90-day opportunity to make good-faith accessibility fixes before certain website accessibility claims can proceed.
Businesses operating in Missouri should document their current accessibility practices and have a process for responding quickly if they receive notice of an accessibility issue.
Manufacturers of covered devices and multichannel video programming distributors have until 17 August 2026 to make closed-caption display settings readily accessible to deaf and hard-of-hearing viewers.
The FCC will assess factors including proximity, discoverability, previewability, and consistency when determining whether settings are readily accessible.
Covered businesses should review how easily users can find, preview, and adjust caption settings before the deadline.
The US Access Board held its quarterly public meeting on 29 July 2026, covering board business, committee reports, and updates from federal agencies.
The Board oversees accessibility standards for information and communication technology under Section 508, along with other federal accessibility requirements.
Organisations working with federal agencies should continue monitoring the Board’s meetings and publications for potential changes affecting technical accessibility standards and procurement.

The European Commission fined AliExpress €550 million for failures related to illegal, unsafe, and counterfeit products sold through its marketplace.
According to the Commission, AliExpress did not adequately assess and mitigate these risks, including risks connected to its content review, detection systems, advertising, and recommendation systems.
AliExpress must submit a remediation plan by 20 October 2026 or potentially face additional penalty payments.
The decision shows the financial consequences marketplaces can face when the Commission determines that their systems for identifying and managing illegal content or products fall short of DSA requirements.
The European Commission has issued preliminary findings that TikTok’s default account settings for minors do not meet Digital Services Act child safety requirements.
The Commission raised concerns about unwanted contact, cyberbullying, and predatory behaviour, including how easily teenage users can make accounts public and what information remains visible on private profiles.
The Commission is seeking changes that would make content posted by users under 18 visible only to approved followers by default.
The findings are preliminary, and TikTok can respond before the Commission reaches a final decision.
This week’s developments highlight how privacy and accessibility requirements are evolving across enforcement, international data transfers, consent practices, and technical accessibility standards.
For compliance teams, keeping policies and processes aligned with these changes means looking beyond individual deadlines and regularly reviewing how data is collected, transferred, and protected, as well as how digital experiences are made accessible.
We’ll be back next week with the latest privacy, accessibility, and digital compliance developments.