Privacy fines, consent and accessibility rules
Google's €403M GDPR fine, a CJEU opinion on partner consent, Texas CIPA letter warnings, Hawaii's draft accessibility rules, and AI whistleblower moves.
Google's €403M GDPR fine, a CJEU opinion on partner consent, Texas CIPA letter warnings, Hawaii's draft accessibility rules, and AI whistleblower moves.
This week's Weekly Compliance Brief updates include a €403 million GDPR fine for Google in Ireland, a CJEU opinion on third-party marketing consent, a Texas warning on CIPA demand letters, proposed digital accessibility rules in Hawaii, US pushback on Australia's online safety bill, and a Senate push for AI whistleblower protections.

Ireland's Data Protection Commission (DPC) fined Google €403 million under the GDPR, closing an inquiry it opened in 2020 into the company's location data practices.
The DPC found fairness, lawfulness, and accountability failures linked to the Web & App Activity, Location History, and Location Accuracy settings between May 2018 and February 2020. Google has six months to bring its processing into compliance.
Regulators treat location data as highly revealing, so teams using it for ads or personalization should check that settings, notices, and retention periods match what users are told.
Advocate General Dean Spielmann told the Court of Justice of the EU (CJEU) that consent for data to be shared with a company's unnamed "partners" does not cover direct marketing by those partners.
The case stems from a €600,000 CNIL fine against Groupe Canal+ over email campaigns sent to about 3.9 million people whose data came from two internet service providers. In his view, the marketer needs fresh consent when it wasn't identified at collection, and an unsubscribe link in the first email cannot fix that.
The opinion is not binding, but if the Court follows it, lead generation, co-registration, and data-sharing models built on "partner" consent will need a closer look.
Texas Attorney General Ken Paxton warned businesses and nonprofits about a surge in demand letters alleging violations of the California Invasion of Privacy Act (CIPA).
The letters claim that cookies, pixels, analytics tools, and search bars amount to unlawful "wiretapping" and demand quick payment, sometimes attaching website screenshots and a draft complaint. The office urges recipients to consult counsel before responding or paying, and to report suspected abuse.
The alert is also a useful prompt to review which tracking technologies run on your site and how you collect consent for them.
The UK Information Commissioner's Office (ICO) published draft guidance on anonymization and pseudonymization in research, with consultation open until 19 October 2026.
Organizations should anonymize wherever possible, use pseudonymization as a safeguard when they cannot, and assess re-identification risk with tools such as the "motivated intruder" test. Pseudonymized data remains personal data under the UK GDPR.
Although aimed at research, the guidance shows how the ICO expects teams to assess and document identifiability, which matters for any team sharing analytics or customer datasets.
Governor Gavin Newsom signed an executive order speeding up California's new AI oversight laws, SB 813 on independent verification organizations and AB 1405 on a state registry of AI auditors.
The order convenes experts to deliver recommendations within two months, including on-site independent auditors at frontier AI labs and an emergency shutoff, or "kill switch," for frontier models.
Most businesses are not directly covered, but companies using AI in customer-facing services should expect growing demand for audits, risk assessments, and vendor due diligence.

The Hawai'i Civil Rights Commission (HCRC) is seeking comments until October 30, 2026 on proposed rules for digital accessibility in places of public accommodation, as required by Act 257 (SLH 2026).
The draft follows the US Department of Justice's ADA Title II web rule. Businesses with 100 or more employees would have 24 months to comply after the rules take effect, and smaller businesses 36 months, although the HCRC is asking whether a size or revenue threshold works best.
Websites, social media, and other digital technology used by public-facing businesses would be in scope, giving Hawaii one of the clearest state-level technical standards for private companies.
The European Disability Forum (EDF) and IAAP EU marked the sixth anniversary of the Web Accessibility Directive (WAD) with online events on September 22 and 23.
September 23 is the date public sector websites across the EU first had to meet the WAD's requirements. This year's workshop focused on practical ways to test the new and revised requirements in the updated EN 301 549 standard, many of which go beyond WCAG.
For organizations now covered by the European Accessibility Act, the discussion signals how auditors and monitoring bodies are likely to test these requirements.
W3C Web Accessibility Initiative Director Shawn Lawton Henry published a blog post on the trade-offs shaping WCAG 3.
The current draft proposes a single conformance level of core requirements building on WCAG 2.2 Levels A and AA, plus supplemental requirements and policy "tags" that let regulators tailor requirements to different contexts.
WCAG 2.2 remains the benchmark in current laws, but accessibility and legal teams can follow this work to understand how future requirements may be structured.
An article on the European Commission's AccessibleEU platform explores why formal accessibility complaints remain rare, even though many websites and apps still present barriers.
It finds that users often abandon a task, switch to a competitor, or find a workaround instead of complaining, held back by limited awareness, lack of time, privacy concerns, or poor past experiences.
The takeaway for digital teams is clear: a lack of complaints is not evidence of accessibility, so regular testing and user feedback channels remain essential.
The Industry Group and the Kiosk Manufacturer Association said their accessibility committee met with the US Access Board to discuss how people use self-service systems.
The groups argued that accessibility should cover the whole transaction, from reaching the kiosk and navigating the interface to paying and getting help. They also said customers should have more than one way to complete a task, such as voice controls, mobile apps, or QR codes.
Businesses using kiosks in retail, parking, or government services should review the full customer journey, not only the screen.

The US government filed a response to Australia's consultation on the Online Safety Amendment (Digital Duty of Care) Bill 2026, which closed on September 22.
The draft would place a broad duty of care on online services and cut removal deadlines for harmful content from 48 hours to 24 hours. The US argued that vague definitions of "harm" could push platforms to remove lawful speech and that design mandates could affect users worldwide.
Platforms serving Australian users should watch the final text closely, as faster removal timelines would require quicker, well-documented notice-and-takedown processes.
Signatories of the EU Code of Conduct on Disinformation, including Google, Meta, Microsoft, and TikTok, published reports covering January to June 2026.
The reports include data on enforcement actions, election integrity safeguards, and crisis measures. Since the code became part of the Digital Services Act (DSA) framework, very large platforms report twice a year and face independent annual audits of their commitments.
The reports offer a useful benchmark for how regulators expect content moderation to be documented and measured under the DSA.

Senator Chuck Grassley sought to fast-track the bipartisan AI Whistleblower Protection Act through unanimous consent, and Senator John Curtis joined as a cosponsor.
The bill would protect employees at AI companies who report legal violations, security vulnerabilities, or public safety risks, and would stop nondisclosure agreements from blocking protected disclosures. Complaints would run through existing Department of Labor processes.
Companies building or deploying AI should review their internal reporting channels and NDAs now, so employees can raise concerns without fear of retaliation.
This week's developments share a common thread: regulators and courts are closely examining how organizations collect consent, use tracking and location data, and prove their digital services work for everyone. From Google's fine in Ireland to Hawaii's draft accessibility rules and new AI oversight in California, the expectation is clear documentation and accountability.
We'll be back next week with the latest privacy, accessibility, and digital compliance developments.