
It was an enforcement-heavy week, with regulators going after design choices and disclosure gaps rather than breaking new legal ground. Meta reached a multistate settlement over teen-safety design, the FTC and Connecticut's AG both caught companies overstating what they told consumers about data use, and California advanced a targeted fix to a deletion-rights loophole.
Enforcement
Meta reached a landmark settlement — up to $17.1 billion, pending court approval — with a coalition of state attorneys general over claims that Instagram and Facebook's addictive design harmed teens, including COPPA-related claims↗. The deal requires sweeping changes within months: default time limits and midnight-to-6am blocks for under-18 accounts, a non-personalized feed option, no visible like counts, no cosmetic filters, faster response to harmful content, and five years of independent audits. Meta is reportedly pressuring TikTok and YouTube to adopt similar standards, which could reshape teen-platform design norms industry-wide and inform other pending platform-addiction litigation.
The FTC also finalized $930,000 in orders↗ against Cox Media Group and two other firms over deceptive "Active Listening" marketing — claims that their ad-targeting service could target consumers based on eavesdropping through their devices, with purported opt-in consent that didn't hold up. It's a reminder that unsubstantiated "your device is listening to you" ad-tech claims remain an active enforcement target.
Separately, Connecticut's Attorney General settled with TaxAct for $275,000↗ over allegations that the tax-prep company shared taxpayer data with advertising partners without proper consent — another sign that tax and financial data-sharing practices are a live target for state AG enforcement.
New and Pending Legislation
California's legislature passed SB 923, the Expanding Privacy Rights Act↗, which would extend the CCPA's right-to-delete to cover personal data that businesses purchased from third parties — data currently exempt from deletion obligations. The bill now heads to the Governor. If signed, it's a real scope expansion for any organization handling deletion requests: third-party-sourced data would no longer get a pass.
The Takeaway
This was an enforcement-heavy week, and the throughline is accountability for design and disclosure choices rather than novel legal theories: Meta's settlement targets how a product is built for minors, the FTC and Connecticut actions both turn on companies overstating what they told consumers about data use, and California's SB 923 is a targeted fix to a deletion loophole rather than a rewrite of the CCPA. Together they're a good checklist for any privacy program — verify marketing claims about data use match reality, and make sure deletion workflows already anticipate purchased third-party data becoming in-scope.
Compiled from PieEye's daily Privacy Reg Watch monitoring of regulators, law firms, and industry sources.