Privacy, AI, and accessibility compliance roundup
Florida sues Netflix over kids' data, the EU preps its Kids Act, EDPB advances GDPR and AI Act guidance, and the EU updates EN 301 549.
Florida sues Netflix over kids' data, the EU preps its Kids Act, EDPB advances GDPR and AI Act guidance, and the EU updates EN 301 549.
This week brought several notable developments across privacy, AI, accessibility, and online safety. Updates include lawsuits involving Netflix and Lowe’s, the EU’s planned Kids Act, new GDPR and AI Act guidance, and a UK inquiry into the Online Safety Act.
Also covered are an updated EU accessibility standard, a new WCAG 3.0 draft, a DMCA ruling, and New York’s new alert for AI whistleblowers.

The European Data Protection Board held its 123rd plenary meeting on September 17, 2026, covering an agenda spanning GDPR fines, platform regulation, and artificial intelligence.
Key items included updated guidelines on the interplay between the Digital Services Act and the GDPR following public consultation, new guidelines on how the AI Act interacts with EU data protection law, and the board's selection of a topic for its 2027 Coordinated Enforcement Framework.
For website operators and marketing teams, these guidelines preview how EU regulators expect data protection obligations to apply alongside platform and AI rules, a useful signal for compliance planning heading into 2027.
Florida Attorney General James Uthmeier filed suit against Netflix, alleging the company promised an ad-free, privacy-respecting paid service while quietly building the advertising business it said it would never create.
The complaint says Netflix collected detailed viewing and device data from children on Kids profiles despite telling parents it does not use behavioral advertising there, and later shared that data with advertisers and data brokers without the consent Florida law requires.
The case, brought under the Florida Deceptive and Unfair Trade Practices Act and the Florida Digital Bill of Rights, seeks a data purge and civil penalties and reminds companies that promises in privacy policies and children's product marketing are enforceable claims, not just messaging.
The European Commission is set to present a new legislative proposal, called the EU Kids Act, that could limit young people's access to social media platforms.
Commission President Ursula von der Leyen and Tech Commissioner Henna Virkkunen were expected to present the draft plan this week, with all 27 commissioners reviewing it before adoption by written procedure, following von der Leyen's State of the Union pledge to define an EU-wide social media age threshold for minors.
Website and platform operators serving users in the EU should watch for the specific age-verification and design requirements once the proposal is published, since it is expected to build on existing GDPR and DSA obligations around children's data and product design.
An Illinois consumer has filed a proposed class action against Lowe's, alleging the home improvement retailer captures callers' voiceprints through its customer service lines without notice or consent.
The complaint, filed in Cook County Circuit Court, says Lowe's biometric processing of call recordings violates the Illinois Biometric Information Privacy Act, which requires informed consent before collecting biometric identifiers, and follows a similar suit filed against Walmart in August.
The case is part of a growing wave of biometric privacy litigation tied to voice AI and call center technology, and it is prompting website and customer service teams to confirm whether their vendors' voice analytics tools trigger biometric consent requirements.
The House of Lords Communications and Digital Committee has opened an inquiry into how well the UK's Online Safety Act 2023 is working, pointing to serious concerns that the regime is not effectively holding platforms accountable for online harms.
England's Children's Commissioner told the committee that implementation has been too reactive and too focused on individual pieces of content rather than platform design, and the inquiry will examine Ofcom's enforcement role and whether the law itself needs amending, including its effects on freedom of expression, privacy, and accessibility.
Submissions are due September 21, 2026, giving website and platform operators a short window to weigh in before any legislative changes take shape.

The European Telecommunications Standards Institute has published EN 301 549 v4.1.1, the harmonized technical standard that underpins accessibility compliance across the EU, including under the European Accessibility Act.
The update adds six accessibility criteria drawn from WCAG 2.2, covering focus visibility, drag-and-drop alternatives, target size, consistent help, form data reuse, and accessible authentication, along with revised real-time text requirements and updated European Accessibility Act mappings.
The standard will not carry a formal presumption of conformity until it is cited in the EU Official Journal, expected by the end of November 2026, but website and digital teams should start planning now, since some national laws reference EN 301 549 without specifying a version number.
The World Wide Web Consortium has published an updated working draft of WCAG 3.0, its next-generation accessibility guidelines.
The September 2026 draft documents changes since the prior version and poses open review questions about the proposed conformance model, the framework organizations would eventually use to demonstrate compliance.
WCAG 3.0 remains in development and does not replace WCAG 2.x today, but compliance and accessibility teams should track the conformance model discussion closely, since it will shape how accessibility claims are documented once the standard matures.

The Ninth Circuit Court of Appeals rejected an attempt to stretch a copyright takedown provision, the DMCA's Section 1202, into a new liability tool against AI companies.
The plaintiffs argued that AI-generated code lacking copyright management information amounted to illegally removing that information, but the court disagreed, distinguishing between stripping copyright information from an existing work and creating a new work that never had it in the first place.
The ruling protects platforms and users engaged in remixing, search, and content adaptation from a novel and costly theory of copyright liability, and is a useful precedent for any online service weighing takedown or removal requests grounded in similar claims.

New York Attorney General Letitia James issued an alert urging employees at AI companies to report unsafe or unlawful development practices through the office's whistleblower portal.
The alert points to the state's incoming RAISE Act, which takes effect January 1, 2027, and will require large AI developers to publicly disclose safety measures and promptly report security and safety incidents, alongside existing SHIELD Act data security requirements and computer fraud enforcement authority, and notes that workers can file reports anonymously and confidentially.
The announcement signals that state regulators are building enforcement pipelines around AI safety and data security ahead of new legal requirements, giving compliance and privacy teams another reason to document AI governance and incident response practices now.
This week's developments point to regulators sharpening their focus on children's data, biometric collection, and AI accountability, while accessibility standards continue to evolve alongside the European Accessibility Act.
We'll be back next week with the latest privacy, accessibility, and digital compliance developments.