This Week in Privacy: August 10–14, 2026

PT
The PieEye Team
California's privacy agency notches two data broker enforcement actions in one week, Illinois widens its genetic privacy law to biomarkers, and France's top court strikes down its under-15 social media ban.

A brass hand bell beside a bundle of letters sealed with red wax — the week's privacy news, delivered

It was a quiet week on the federal and EU fronts, but state regulators and a European court kept things interesting. California's privacy agency notched two more data broker enforcement actions in a single week, Illinois widened its genetic privacy law to cover biomarkers, and France's top constitutional court struck down a flagship child-safety law over free-expression and privacy concerns. The throughline: regulators keep finding new angles into old statutes, and legislatures keep discovering how hard it is to write age-verification rules that survive a court challenge.

Enforcement

The California Privacy Protection Agency kept up what its enforcement chief called a "steady drumbeat" of data broker actions this week, bringing two decisions in the span of four days. On August 11, the agency issued its first decision against a data broker under both the CCPA and the Delete Act, ordering Iowa-based LocateSmarter LLC to pay $116,490 after the company failed to register as a data broker on time and unlawfully demanded partial Social Security numbers from Californians before letting them opt out of data sales. The SSN demand is the notable part here — CalPrivacy treated it as a data-minimization violation in its own right, a reminder that "friction added to the opt-out process" is now its own enforcement theory, not just a technicality.

Two days later, the agency announced a second action, fining Boston-based Cybba, Inc. $52,400 for missing the 2025 data broker registration deadline. Cybba sells geolocation and purchasing-behavior signals for targeted advertising, and as part of the settlement it must now connect to California's Delete Request and Opt-out Platform (DROP) and post privacy-rights metrics publicly. For compliance teams, the pattern is clear: DROP registration and timely data broker filings are no longer a paperwork afterthought — they're where CalPrivacy is actively looking for violations, and the agency has signaled this isn't slowing down.

New and Pending Legislation

Illinois's governor signed SB 2886, expanding the state's Genetic Information Privacy Act (GIPA) to cover "biomarker testing" alongside traditional genetic testing. The amendment extends GIPA's confidentiality protections, insurer and employer restrictions, and written-consent requirements to biomarker data — a category broad enough to sweep in single-analyte tests, multi-plex panels, and whole-genome sequencing. This matters because GIPA carries a private right of action with damages up to $15,000 per intentional violation, and it's already fueled a wave of employment-related litigation. Any company handling biomarker data tied to Illinois residents — health tech, life sciences, employer wellness programs — should treat this the same way they treat existing GIPA exposure. The changes take effect January 1, 2027.

Litigation

France's Constitutional Council struck down the centerpiece of the country's law barring minors under 15 from social media, ruling on August 14 that the ban was disproportionate to its goal and lacked adequate privacy safeguards for the age-verification process it would have required. The court found the ban swept too broadly (catching services with no established risk to minors), gave parents no ability to authorize access on a case-by-case basis, and left the legislature's age-verification framework too vague to protect adults' privacy rights during the verification process. This is a significant setback for one of President Macron's flagship initiatives, but not the end of it: the French government says it will draft replacement legislation aligned with the EU's DSA/DMA framework, aiming for passage by spring 2027. Any company building age-assurance or minor-protection features for the French market should watch this closely — the court's reasoning (individualized assessment, narrowly tailored scope, defined verification safeguards) is likely to shape whatever comes next.

Guidance and Rulemaking

France's CNIL, working with the French AI and Digital Council, published an exploratory note on agentic AI and data protection on July 20. It's deliberately non-prescriptive — no new binding requirements — but it flags where autonomous, multi-step AI systems could strain core GDPR concepts like purpose limitation and data minimization, and suggests technical and legal mitigations. It joins a fast-growing pile of regulator commentary on agentic AI, following similar notes from the UK's ICO, Spain's AEPD, and Singapore's IMDA. None of this is enforceable yet, but it's a strong signal of where enforcement priorities are headed as agentic AI products move from pilots to production.

What to Watch

Two dates worth flagging: France's replacement social-media-age legislation is targeted for spring 2027, and Illinois's expanded GIPA takes effect January 1, 2027. Both are far enough out that there's time to prepare — but the direction of travel on both age verification and biometric/biomarker data is unmistakable.

Compiled from PieEye's daily Privacy Reg Watch monitoring of regulators, law firms, and industry sources.

Related Posts

Enjoyed this article?

Subscribe to our newsletter for more privacy insights and updates.