May 2026 brought a significant rebalancing of digital regulation across borders, led by milestone structural anniversaries and landmark corporate data penalties. Read our comprehensive breakdown of the official regulatory developments shaping data protection parameters this month.

01

European Commission marks the ten-year publication anniversary of the GDPR


On May 24, digital compliance authorities celebrated the tenth anniversary of the General Data Protection Regulation (GDPR) entering into force. Regulators highlighted how the core regulation has irreversibly shifted corporate balances of power, established global cross-border baseline rules, and directly served as the conceptual blueprint for modern data frameworks.
Read more

02

California Attorney General finalizes record $12.75M CCPA settlement with General Motors


The California Department of Justice finalized an unprecedented $12.75 million settlement with General Motors over its connected vehicle ecosystem OnStar. The civil action resolves systemic allegations that the automaker unlawfully collected, processed, and sold driver geolocation metrics and driving behavior data to third-party insurance brokers without appropriate consumer notice or consent.
Read more

03

Federal Trade Commission extracts $35 million settlement from Shutterstock over billing dark patterns


The FTC finalized an administrative consent order requiring digital media marketplace Shutterstock to return $35 million over systemic consumer protection violations. The federal regulatory order penalizes the platform for executing hidden automatic subscription renewals on on-demand packages and setting up multi-layered cancellation dark patterns to obstruct user opt-out flows.
Read more

04

France's CNIL hits health analytics firm IQVIA with a €5 million administrative fine


The French Data Protection Authority (CNIL) issued a €5 million administrative fine against IQVIA Operations France over severe database vulnerabilities. The regulatory investigation uncovered structural failures within the company’s health data warehousing architecture, penalizing the entity for inadequate anonymization techniques and processing medical data without explicit valid grounds.
Read more

05

Federal Trade Commission begins aggressive nationwide enforcement of the Take It Down Act


The FTC officially launched formal nationwide enforcement operations targeting web portals under Section 3 of the Take It Down Act (TIDA). The commission announced strict baseline requirements for all covered platforms, mandating clear visual notice portals and a strict 48-hour compliance window to permanently remove reported non-consensual imagery and its automated duplicates.
Read more

06

Louisiana becomes the 22nd US state to establish a comprehensive data privacy law


Louisiana Governor Jeff Landry signed the Louisiana Data Privacy Act (SB 386) into law, locking in the state’s first comprehensive consumer protection regime. Effective January 1, 2027, the act introduces a California-style $25 million gross revenue applicability standard and provides residents with clear statutory rights to access, delete, and opt out of automated behavioral profiling.
Read more

07

UK Information Commissioner’s Office issues final compliance warning to businesses under the Data Act 2025


The ICO issued a high-priority enforcement alert warning companies that they have exactly one month left to establish a mandatory data protection complaints process before legal rules take effect on June 19, 2026. Under the incoming Data (Use and Access) Act provisions, all companies operating in the UK must host clear grievance submission portals and acknowledge consumer data filings within a strict 30-day window.
Read more

08

UK Information Commissioner’s Office fines South Staffordshire utility entities £963,900 over data breach


The ICO issued a final £963,900 administrative penalty against South Staffordshire Plc and South Staffordshire Water Plc following a severe corporate network intrusion. The data protection regulator penalized the companies for long-term vulnerability management and patch failures that allowed threat actors to exfiltrate the payroll and banking information of over 633,000 customers onto the dark web.
Read more

09

France's CNIL hosts G7 data protection roundtable and establishes the 2026 Action Plan


The Commission Nationale de l’Informatique et des Libertés (CNIL) published the strategic outcomes of the G7 Data Protection and Privacy Authorities Roundtable held in Paris. The comprehensive 2026 Action Plan introduces coordinated enforcement cooperation benchmarks specifically geared toward emerging AI technologies, cross-border data protection flows, and minor safety metrics.
Read more

10

FTC hits Cox Media Group with $1M fine to settle deceptive 'Active Listening' AI marketing claims


The FTC resolved regulatory charges against Cox Media Group and multiple partner marketing agencies, ordering a total penalty payment of $930,000. The administrative order penalizes the firms for making false commercial claims regarding an AI-powered tool that supposedly recorded device microphone feeds in real-time to generate localized advertising campaigns.
Read more