March saw regulators double down on enforcement while continuing to reshape AI and online safety rules. From California’s growing enforcement streak to EU AI delays and new global child-safety laws, the month reinforced that compliance expectations are only getting stricter.
CalPrivacy fines PlayOn Sports $1.1M over student privacy violations
CalPrivacy ordered PlayOn Sports to pay $1.1 million and overhaul its practices after finding violations involving student data and forced consent mechanisms. The case marks the agency’s first enforcement action tied to schools, signaling closer scrutiny of minors’ data and consent practices. Read more
EU backs delay to key high-risk AI Act rules
EU lawmakers supported delaying obligations for high-risk AI systems, pushing timelines into 2027 and 2028 due to incomplete technical standards. The move reflects ongoing challenges in operationalizing the AI Act while balancing innovation with compliance. Read more
Oklahoma becomes the latest US state to pass a privacy law
Oklahoma approved SB 546, becoming the latest state to adopt a comprehensive privacy law following the Virginia-style framework. The law adds to the growing patchwork of US privacy regulations, with enforcement set to begin in 2027. Read more
UK fines Reddit £14.47M over children’s data practices
The UK ICO fined Reddit £14.47 million for failing to implement adequate age assurance and unlawfully processing children’s data. The decision underscores increasing regulatory pressure on platforms to balance child safety with lawful data processing. Read more
Brazil’s online child safety law takes effect
Brazil’s Digital ECA law came into force, introducing stricter rules for protecting minors online, including content controls and age safeguards. Platforms now face fines and potential bans if they fail to comply with the new requirements. Read more
CJEU says even a first DSAR can be abusive
The EU’s top court ruled that even a first data access request can be refused if proven abusive or made in bad faith. However, the ruling sets a high threshold, reinforcing that refusals must be carefully justified under GDPR. Read more
White House pushes lighter-touch AI regulation framework
The White House outlined a legislative blueprint encouraging Congress to avoid overly strict AI regulation that could hinder innovation. The framework focuses on balancing safety, economic growth, and national competitiveness in AI development. Read more
EU fails to extend child abuse detection rules in time
EU lawmakers failed to reach agreement on extending rules allowing platforms to detect child abuse material before the deadline. The lapse risks creating a regulatory gap in enforcement across member states. Read more
Colorado proposes a revised AI governance framework
Colorado’s AI workgroup proposed a new framework focusing on transparency, accountability, and human oversight in automated decisions. The revision aims to replace earlier, more complex regulatory attempts with a more practical model. Read more
Ford fined for adding friction to CCPA opt-out processes
CalPrivacy fined Ford for making it harder for users to opt out of data sharing by adding unnecessary verification steps. The case highlights regulators’ continued focus on dark patterns and friction in consent mechanisms. Read more