Deletion rights, AI transparency and takedowns
This week: California's CCPA deletion fix, a sensitive data ban veto, Australia's AI notice rules, Alabama's TikTok deal, and state accessibility gaps.
This week: California's CCPA deletion fix, a sensitive data ban veto, Australia's AI notice rules, Alabama's TikTok deal, and state accessibility gaps.
California expanded CCPA deletion rights, Australia clarified upcoming AI transparency requirements, and the UK set a timeline for its under-16 social media restrictions. Here are the privacy, accessibility, and digital compliance developments worth knowing this week.

Governor Gavin Newsom signed SB 923, the Expanding Privacy Rights Act, closing a gap in the California Consumer Privacy Act (CCPA) right to delete.
From January 1, 2027, businesses must delete personal information even when it came from a third party rather than the consumer, and online-only businesses must offer an online request method, such as a webform, not just an email address.
Privacy teams should check that deletion workflows reach enriched and third-party data, and that request intake meets the new standard before the law takes effect.
Governor Newsom vetoed AB 1542, which would have banned CCPA-covered businesses from selling or sharing consumers' sensitive personal information.
He called a categorical ban "a step too far," pointing to consumers' existing right to limit how this data is shared.
The current opt-out model stays in place, so businesses should keep their "Limit the Use of My Sensitive Personal Information" mechanisms working and well documented.
The Office of the Australian Information Commissioner (OAIC) published guidance on new privacy policy obligations for automated decision-making.
From 10 December 2026, organizations that use computer programs to make, or substantially inform, decisions that significantly affect individuals must disclose the kinds of personal information used and the kinds of decisions involved.
Organizations serving Australian users should map where automated tools drive decisions, such as eligibility, pricing, or fraud checks, and update privacy notices before the December deadline.
Alabama's Attorney General settled the state's case against TikTok for at least $100 million, and up to $300 million, resolving claims of addictive design and misleading safety statements.
TikTok must add stronger age assurance, a default non-personalized feed for teens, a two-hour daily limit, and overnight access restrictions.
Age assurance and privacy-protective defaults are fast becoming the expected baseline for youth-facing services, so product and privacy teams should review how their own settings compare.
Culture Secretary Lisa Nandy confirmed the UK's under-16 social media ban will take effect next March, covering platforms such as TikTok, YouTube, Instagram, Snapchat, and X.
Ofcom will set out what "highly effective age assurance" should look like by the end of October, and platforms that make their services safe enough for children may avoid the restrictions.
Services with UK users should track Ofcom's findings closely, as age checks such as facial estimation and ID matching carry their own data protection obligations.

A new National Association of State Chief Information Officers (NASCIO) survey found that 67% of states have no dedicated accessibility funding and 46% lack a chief accessibility officer.
This comes as states work toward the extended ADA Title II web accessibility deadline in April 2027, with document remediation named as the top challenge.
Vendors selling software and digital services to state governments should expect accessibility to feature more prominently in procurement and contract requirements.
The Federal Communications Commission (FCC) renewed its Consumer Protection and Accessibility Advisory Committee for another two years.
The committee advises the FCC on disability access and emerging technologies, and its recommendations can shape future accessibility rules.
Providers of communications, video, and streaming services should follow its work for early signals of new requirements.
EDUCAUSE's 2027 Top 10 IT issues for higher education places "designing human-centric technology experiences" fifth, with AI taking the top spot.
Digital accessibility compliance is named as a primary driver, as public colleges and universities prepare for ADA Title II requirements by April 2027.
Edtech vendors, publishers, and platform providers should be ready to demonstrate accessibility conformance as institutions tighten procurement.

After a deadly school attack in Torreón, President Claudia Sheinbaum announced plans for a decree requiring platforms to detect, remove, and report content that directly incites violence.
A draft is expected soon, but definitions, penalties, and the enforcing authority have not yet been published.
Platforms with Mexican users should prepare to scale their notice-and-takedown processes and review the draft text as soon as it is released.
India's Bombay High Court ordered X to remove a video posted in breach of an injunction, but refused broader orders to suspend accounts or block future uploads.
The court held that platforms can be directed to remove only identifiable content they have examined, noting that "an intermediary cannot assume the role of an adjudicator or censor."
Platforms handling court-ordered removals in India now have a clearer basis for pushing back on open-ended takedown demands.

A national YouGov poll for the Government Accountability Project and the National Whistleblower Center found that 86% of voters want Congress to prioritize stronger protections for people who report fraud, up from 81% in 2020.
The share who would vote for candidates backing stronger protections jumped to 64%, from 44%.
Rising public support adds momentum to whistleblower bills in Congress, making it a good time for compliance and HR teams to review internal reporting channels and anti-retaliation policies.
That's it for this week. We'll be back next week with the privacy, accessibility, and digital compliance developments businesses need to know.