This Week in Privacy: August 3–7, 2026

PT
The PieEye Team
A federal health-data enforcement action, a direct challenge to the EU-US data transfer framework, and a fresh round of state legislation on kids' safety and surveillance pricing.

A brass hand bell beside a bundle of letters sealed with red wax — the week's privacy news, delivered

A federal health-data enforcement action, a direct challenge to the EU-US data transfer framework, and a fresh round of state legislation on kids' safety and surveillance pricing — this week moved the privacy compliance landscape on several fronts at once.

Enforcement

The biggest story of the week: the FTC, joined by California and Utah, sued Hims & Hers Health, alleging the telehealth company shared consumers' sensitive health data — hair loss, weight loss, sexual health — with Meta and Snap via tracking pixels despite marketing itself as "discreet," on top of deceptive subscription and cancellation practices. It's the first new FTC Section 5 privacy suit since March and a clear warning shot for any company pairing ad pixels with sensitive-health marketing claims.

In Europe, the EDPB formally requested a review of the EU-US Data Privacy Framework in light of the US Supreme Court's ruling in Trump v. Slaughter on FTC commissioner removal. The ruling bears on the independence of the US oversight bodies that underpin the DPF's adequacy finding — a real and direct risk to the legal basis many US companies rely on for EU-to-US data transfers.

New and Pending Legislation

Kids' online safety kept advancing on two fronts. The Senate Commerce Committee advanced KOSA along with companion children's AI-safety bills, moving federal kids' online safety rules a step closer to a floor vote — relevant to any platform touching minors' data. Separately, New York's Attorney General and Governor Hochul published final rules implementing the SAFE for Kids Act, setting concrete compliance obligations — age-assurance and parental-consent mechanics, restrictions on "addictive feed" designs — for platforms serving New York minors, effective January 25, 2027.

New Jersey Governor Sherrill signed the Fair Price Protection Act (A4085), banning personal-data-based differential pricing for groceries and imposing a one-year moratorium on electronic shelf labels tied to personal data. New Jersey joins New York, Connecticut, and Maryland in restricting "surveillance pricing," with the law effective August 2027.

California's DELETE Act reached a real compliance deadline: its consumer deletion request and opt-out platform, DROP, became mandatory on August 1 for the state's 600-plus registered data brokers, who must now process consumer deletion requests every 45 days. A companion bill, SB 361, doubled noncompliance fines to $200 per consumer per day. Separately, the California legislature continued advancing SB 690, which would strip the private right of action from CIPA "pen register" wiretapping claims — an attempt to cut off the current wave of website-tracking class actions at the source.

Colorado, meanwhile, went the other direction on AI regulation: the state repealed its 2024 AI Act (SB 24-205) and replaced it with a narrower framework under SB 26-189, effective January 1, 2027. The rewrite drops the original's impact-assessment mandates in favor of a more targeted automated-decision-making disclosure-and-rights regime, while keeping core transparency and consumer-rights duties intact.

Guidance and Rulemaking

The EDPB also published draft Guidelines 02/2026 on Anonymisation, updating its 2014 framework for what actually counts as anonymized (versus merely pseudonymized) data. The comment period is open through October 30 — worth a look for anyone leaning on anonymization as a basis for reduced GDPR obligations.

The Takeaway

Two things stand out. First, health data is squarely in regulators' crosshairs right now — the Hims & Hers suit is the clearest signal yet that "discreet" marketing doesn't insulate a company from pixel-sharing liability. Second, the ground under transatlantic data transfers just got shakier: an EDPB-triggered review of the EU-US Data Privacy Framework is the kind of development that could force a re-run of the Privacy Shield saga if the independence questions aren't resolved cleanly. Meanwhile, states keep pulling in different directions on AI (Colorado loosening, others tightening) and on surveillance pricing (New Jersey tightening further) — the patchwork isn't converging any time soon.

Compiled from PieEye's daily Privacy Reg Watch monitoring of regulators, law firms, and industry sources.

Related Posts

Enjoyed this article?

Subscribe to our newsletter for more privacy insights and updates.