Regulators and courts on both sides of the Atlantic issued record settlements and fines in July, covering data breaches, deceptive practices, and how platforms handle young users’ data. A major AI law also took effect in the EU, adding new compliance obligations for businesses to track.
EU's Digital Omnibus on AI enters into force
Regulation (EU) 2026/1744 officially took effect on July 27, easing several AI Act transparency and compliance deadlines while leaving the core rules intact.
Read more
State AGs settle 23andMe data breach claims
A coalition of 42 state attorneys general, led by Connecticut’s William Tong and Indiana’s Todd Rokita, reached a bankruptcy settlement with 23andMe recognizing $150 million in claims, though actual recovery for states is capped at $18 million due to limited bankruptcy funds. The case stemmed from a 2023 credential-stuffing breach that exposed genetic data on 6.9 million customers worldwide.
Read more
Connecticut's amended Data Privacy Act takes effect
Connecticut’s SB 1295 amendments took effect July 1, widening the definition of sensitive data and requiring businesses to disclose whether they sell or use personal data to train large language models.
Read more
California's CPPA launches its first sectoral privacy audit
The California Privacy Protection Agency opened its first-ever audit sweep, targeting gig economy platforms over compliance with consumers’ data access rights.
Read more
European Commission finds TikTok breached the DSA over minors' accounts
Brussels preliminarily determined that TikTok let minors set their accounts to public, exposing their content platform-wide in violation of the Digital Services Act’s child-safety rules.
Read more
FTC and states sue Hims & Hers over billing and health-data practices
The FTC, Utah, and Los Angeles County (for California) sued Hims & Hers, alleging it charged consumers for prescriptions without a promised doctor consultation, made subscriptions hard to cancel, and shared health data with Meta and Snap despite privacy promises. The case is pending in federal court.
Read more
Seventh Circuit vacates Clearview AI's $51.75 million biometric settlement
The Seventh Circuit threw out Clearview AI’s $51.75 million settlement on July 13. Judges found the district court approved it wrongly, and sent the case back.
Read more
South Korea fines TikTok and Apple over unlawful data use
South Korea’s PIPC fined TikTok KRW10.3 billion and Apple KRW250 million for collecting and using personal data, including voice recordings, without a valid legal basis.
Read more
EDPB adopts final guidelines on anonymisation
The European Data Protection Board adopted new anonymisation guidelines, replacing guidance that dated back to 2014. They set three tests for real anonymisation: no singling out, no linkability, and no inference. Data that’s still open to re-identification can’t be called “anonymized.”
Read more
New Jersey bans the sale of sensitive data
New Jersey’s A5328 prohibits selling sensitive data such as health, geolocation, and biometric information, and creates a new public data broker registry with fees of up to $1.5 million.
Read more