Clym Logo

Weekly Compliance Brief: September 7 - 11, 2026

Published
AS
AuthorAdam Safar
5 min read

Weekly privacy and accessibility roundup

CJEU limits shareholder data access, Connecticut probes Kik Messenger, Australia sets ADM transparency rules, and ADA lawsuits hit new highs.

Summarize full article with:

Compliance Brief - Data Privacy

CJEU limits public access to shareholder data under GDPR

On 3 September 2026, the Court of Justice of the European Union (CJEU) ruled in Jautiva (Case C-798/24) that EU company law does not require companies to disclose information on every shareholder to the general public.

The case arose in Latvia, where legislation made minority shareholders' identification details, shareholding size, and voting rights freely accessible online to anyone. The Court held that the General Data Protection Regulation (GDPR) prevents this kind of unrestricted access unless it is tied to conditions, such as a demonstrated legitimate interest.

For website and platform operators that run or feed public company or ownership registries, the ruling reminds them that transparency goals do not override GDPR's necessity and proportionality requirements, and that broad, conditionless public access is unlikely to withstand scrutiny.

Continue to read

AG opinion flags new data retention risks for Irish telecoms

On 3 September 2026, Advocate General Maciej Szpunar issued an opinion in Academie Fiscale and Others (Case C-661/24), a Belgian case examining communications data retention law against the ePrivacy Directive and the EU Charter of Fundamental Rights.

The opinion argues that regulators must assess proportionality not only by looking at what data is retained, but also by how that data is technically stored and segregated. Belgium's law was found wanting because it allows broad retention of traffic and location data without requiring genuine separation between data categories.

Ireland's 2022 data retention law follows a similar approach to Belgium's, so Irish telecoms and any business relying on their data may face pressure to review technical safeguards and system architecture well ahead of any formal legislative change.

Continue to read

Connecticut investigates Kik Messenger over child safety failures

Connecticut Attorney General William Tong announced on September 8, 2026, a formal investigation into MediaLab.AI Inc., the operator of messaging app Kik, over allegedly lax age assurance and content moderation practices.

The investigation cites Kik's historical lack of email or phone verification, no technology to monitor for underage users, and a reactive rather than proactive approach to reported content, despite child safety groups reporting that test accounts received sexual solicitations within seconds. It follows a 2025 notice of violation under Connecticut's Data Privacy Act.

The case is a pointed reminder that age assurance and content moderation are increasingly treated as consumer protection and privacy issues, not just child safety issues, and that regulators are willing to act on both fronts at once.

Continue to read

Australia sets December deadline for automated decision transparency

Australia's new automated decision-making (ADM) transparency obligation takes effect on 10 December 2026, requiring entities covered by the Privacy Act to disclose their use of ADM in their privacy policies.

The obligation applies broadly wherever a computer program makes, or materially contributes to, a decision that could significantly affect a person's rights or interests using their personal information, covering everything from AI tools to standard business software. The Office of the Australian Information Commissioner is expected to release further guidance this month.

Marketing, product, and privacy teams using automated tools for eligibility, pricing, or recommendation decisions should start auditing where those systems touch personal information now, since generic privacy policy language about using technology to improve services will not meet the new disclosure standard.

Continue to read

UK court opens data protection remedy for misleading headlines

The England and Wales Court of Appeal ruled in Vince v Associated Newspapers Ltd that a misleading headline and photo combination can amount to unfair processing of personal data under the UK GDPR, even where a libel claim over the same article would fail.

The court found that fairness under the UK GDPR is a distinct, autonomous concept from defamation law, and that publishers cannot rely on an accurate article body to cure a misleading headline, image, or caption that most readers will never scroll past.

The decision opens a new legal avenue against publishers, bloggers, and other online content creators whose headlines, thumbnails, or previews present identifiable individuals in a misleading light, even when the underlying content is technically accurate.

Continue to read

Compliance Brief - Accessibility

Web accessibility news

ADA website lawsuits hit a new high at the 2026 midpoint

A mid-year report published September 9, 2026 found that federal ADA Title III lawsuits reached 5,006 filings in the first half of 2026, the highest mid-year total since 2021.

California remained the top jurisdiction with 2,426 filings, followed by Florida with 709 and Illinois with 505, continuing a multi-year climb in accessibility-related litigation against businesses with any kind of digital presence.

The numbers are a reminder for ecommerce, marketing, and website teams that inaccessible websites remain a frequent litigation target, and that proactive WCAG conformance is a stronger safeguard than reacting after a demand letter arrives.

Continue to read

FCC accessibility rules can quietly cover your live chat

A legal analysis published September 10, 2026 highlights that the Federal Communications Commission's (FCC) accessibility rules for people with disabilities extend to non-interconnected VoIP, electronic messaging, and interoperable video conferencing, not just traditional telecoms.

Because electronic messaging is defined broadly to include real-time text communication between individuals, a routine live chat customer service feature can bring a company within FCC coverage even when its core business has nothing to do with communications.

Businesses that run or plan to add live chat should confirm whether the feature falls within scope, since covered services carry accessibility, recordkeeping, annual certification, and registration obligations that are easy to overlook until a review or complaint surfaces them.

Continue to read

Until next week

This week's developments show regulators and courts on both sides of privacy and accessibility sharpening the line between transparency obligations and the practical limits of automated and moderated systems, from GDPR shareholder disclosure limits in the EU to new ADM transparency rules in Australia and record accessibility litigation in the US.

We'll be back next week with the latest privacy, accessibility, and digital compliance developments.

Adam Safar

Head of Digital Marketing

Adam is the Head of Digital Marketing at Clym, where he leverages his diverse expertise in marketing to support businesses with their compliance needs and drive awareness about data privacy and web accessibility. As one of the company’s original team members, Adam has been instrumental in shaping its journey from the very beginning. When he’s not diving into marketing strategies, Adam can be found cheering on his favorite sports teams or enjoying fishing.

Find out more about Adam