Regulators and courts on both sides of the Atlantic issued record settlements and fines in July, covering data breaches, deceptive practices, and how platforms handle young users’ data. A major AI law also took effect in the EU, adding new compliance obligations for businesses to track.

01

EU's Digital Omnibus on AI enters into force

Regulation (EU) 2026/1744 officially took effect on July 27, easing several AI Act transparency and compliance deadlines while leaving the core rules intact.
Read more

02

State AGs settle 23andMe data breach claims

A coalition of 42 state attorneys general, led by Connecticut’s William Tong and Indiana’s Todd Rokita, reached a bankruptcy settlement with 23andMe recognizing $150 million in claims, though actual recovery for states is capped at $18 million due to limited bankruptcy funds. The case stemmed from a 2023 credential-stuffing breach that exposed genetic data on 6.9 million customers worldwide.
Read more

03

Connecticut's amended Data Privacy Act takes effect

Connecticut’s SB 1295 amendments took effect July 1, widening the definition of sensitive data and requiring businesses to disclose whether they sell or use personal data to train large language models.
Read more

04

California's CPPA launches its first sectoral privacy audit

The California Privacy Protection Agency opened its first-ever audit sweep, targeting gig economy platforms over compliance with consumers’ data access rights.
Read more

05

European Commission finds TikTok breached the DSA over minors' accounts

Brussels preliminarily determined that TikTok let minors set their accounts to public, exposing their content platform-wide in violation of the Digital Services Act’s child-safety rules.
Read more

06

FTC and states sue Hims & Hers over billing and health-data practices

The FTC, Utah, and Los Angeles County (for California) sued Hims & Hers, alleging it charged consumers for prescriptions without a promised doctor consultation, made subscriptions hard to cancel, and shared health data with Meta and Snap despite privacy promises. The case is pending in federal court.
Read more

07

Seventh Circuit vacates Clearview AI's $51.75 million biometric settlement

The Seventh Circuit threw out Clearview AI’s $51.75 million settlement on July 13. Judges found the district court approved it wrongly, and sent the case back.
Read more

08

South Korea fines TikTok and Apple over unlawful data use

South Korea’s PIPC fined TikTok KRW10.3 billion and Apple KRW250 million for collecting and using personal data, including voice recordings, without a valid legal basis.
Read more

09

EDPB adopts final guidelines on anonymisation

The European Data Protection Board adopted new anonymisation guidelines, replacing guidance that dated back to 2014. They set three tests for real anonymisation: no singling out, no linkability, and no inference. Data that’s still open to re-identification can’t be called “anonymized.”
Read more

10

New Jersey bans the sale of sensitive data

New Jersey’s A5328 prohibits selling sensitive data such as health, geolocation, and biometric information, and creates a new public data broker registry with fees of up to $1.5 million.
Read more