This Week In Privacy: August 31 - September 6, 2026

RS
River Starnes
A brass hand bell beside a bundle of letters sealed with red wax — the week's privacy news, delivered

A brass hand bell beside a bundle of letters sealed with red wax — the week's privacy news, delivered

This week's privacy news kept returning to two themes: regulators pressing on paper and legacy records as hard as digital systems, and a widening enforcement push against data brokers who get their registration paperwork wrong. Add a major DSA designation for a generative AI chatbot, movement on Australia's next Privacy Act overhaul, and a reminder from Connecticut that ad-tech data sharing is still squarely in AG crosshairs.

Enforcement

Ireland's Data Protection Commission closed out an inquiry into the country's Health Service Executive, fining the HSE €645,000 after paper medical records were left insecure at two disused psychiatric hospitals and were later improperly accessed. Alongside the fine, the DPC issued a formal reprimand and compliance orders. The case is a useful reset for any organization that treats GDPR's security obligations as an IT-systems problem — legacy paper archives and decommissioned facilities carry the same duty of care, and the DPC treated the failure to secure them as seriously as it would a network breach.

California's data broker crackdown is escalating from "did you register" to "did you register correctly." The California Privacy Protection Agency fined Virginia-based SalesIntel Research $36,400 for missing its 2025 Delete Act registration deadline and ordered it onto the DROP deletion platform — one more entry in what CalPrivacy is openly calling an enforcement "blitz" against unregistered out-of-state brokers. More notably, the agency also issued Enforcement Advisory 2026-01, its first advisory aimed specifically at brokers who did register but filed inaccurate or incomplete information, warning of fines up to $200/day. For any data broker registered in California, an accuracy audit of what's actually on file now matters as much as confirming registration happened at all.

Connecticut's Attorney General reached a $275,000 settlement with TaxAct over allegations that the tax-prep company shared taxpayer data with advertising platforms without adequate disclosure or consent — another sign that state AGs continue to treat tax and financial data flowing into ad-tech pipelines as a high-priority enforcement target.

Legislation and Regulatory Developments

Australia moved into the next phase of Privacy Act reform this week: the Attorney-General's Department published its second-wave reform package, with consultation open through September 18. The headline proposal is a new "fair and reasonable" test for collecting and using personal information that goes beyond simple consent, alongside a proposed right to erasure and an "IDLock" digital-identity protection scheme. This follows 2024's first-wave amendments and is worth tracking closely for any organization processing Australian personal data through analytics, ad tech, or AI systems — the fair-and-reasonable standard in particular would shift the compliance bar from "did we get consent" to "was this use appropriate in context."

Effective August 31, the European Commission designated ChatGPT a Very Large Online Search Engine and Reddit and Roblox Very Large Online Platforms under the Digital Services Act. The designations pull all three into the DSA's toughest tier of systemic-risk assessment, transparency, and audit obligations — the first time a generative AI chatbot has been brought into this regime, and a signal that EU regulators are willing to fit conversational AI products into existing platform-governance frameworks rather than waiting solely on the AI Act.

China's Ministry of Public Security issued new Cyberspace Security Inspection rules, effective October 1, expanding police authority to inspect companies' cybersecurity and data-compliance practices and formally replacing the rules it operated under since 2018. Companies running networks or processing data in China should expect broader and more direct inspection authority once the new rules take effect.

The FTC extended by seven days the comment period on its proposed policy statement addressing personalized and algorithmic pricing, keeping the rulemaking active rather than closing the window. Organizations using dynamic or personalized pricing models should treat this as a continued, live opportunity to weigh in before the FTC firms up its position.

California lawmakers, meanwhile, advanced a CalPrivacy-backed bill to strengthen consumer deletion rights under the CCPA/Delete Act framework as the legislative session heads toward its close. Combined with this week's broker-registration enforcement push, it's a reminder that California continues to build out both the substantive deletion-rights framework and the enforcement machinery behind it in parallel.

The Takeaway

The throughline this week is that regulators are auditing the quality of compliance, not just its existence — CalPrivacy penalizing inaccurate broker registrations rather than only missing ones, and Ireland's DPC treating unsecured paper archives with the same weight as a digital breach. Meanwhile, the EU's DSA designation for ChatGPT shows regulators reaching for existing platform-governance tools to bring AI products into scope now, rather than waiting for AI-specific rules to catch up. Organizations should take this as a cue to revisit registration accuracy, legacy and physical record security, and ad-tech data-sharing disclosures — the areas where this week's enforcement actually landed.

Related Posts

Enjoyed this article?

Subscribe to our newsletter for more privacy insights and updates.