This Week In Privacy: September 7 - 13, 2026

RS
River Starnes

A brass hand bell beside a bundle of letters sealed with red wax — the week's privacy news, delivered

Another week of eight- and nine-figure enforcement numbers out of Europe, a health-data breach that reads like a checklist of what not to do, and a US regulator pulling back on a rule it had only recently pushed forward. Here's what mattered.

Enforcement

The Dutch Data Protection Authority fined Uber nearly €825 million (€824.99M) over automated decision-making that affected its drivers — one of the largest ADM-related GDPR fines issued to date. The size of the penalty is a signal in itself: regulators are willing to treat algorithmic management of workers (automated dispatch, deactivation, or performance scoring, for instance) as a core GDPR compliance area, not a niche edge case. Any platform business using algorithmic systems to manage drivers, couriers, or other gig workers should treat this as a warning shot.

France's CNIL fined Hôpital Privé de la Loire €500,000 over a 2025 breach that exposed records for roughly 525,000 patients and 202,000 "trusted third parties." The regulator's findings read like a security fundamentals checklist gone wrong: missing MFA and VPN protections, weak access controls, and a failure to notify all affected individuals, in violation of GDPR Articles 32 and 34. It's a clean case study for any healthcare organization on where breach-response obligations most often break down — both on the prevention side and on the notification side.

Separately, CNIL fined French recruiting and staffing firm EXTIA €300,000 for failing to honor individuals' data subject access requests. (An earlier internal note this week described EXTIA as "Uber-adjacent" — that was an error; EXTIA is an unrelated staffing and consulting firm, and the fine has nothing to do with Uber.) The case is a reminder that DSAR handling remains a live enforcement trigger in France, and that CNIL is willing to pursue mid-size companies for it, not just large platforms.

Ireland's Data Protection Commission fined the Health Service Executive €645,000, plus a reprimand and compliance orders, over insecure paper-record storage at two shuttered psychiatric hospitals that led to unauthorized access. It's a useful counterpoint to an otherwise digital-breach-heavy week: GDPR Articles 32-34 exposure applies just as much to physical records as to databases, and organizations sitting on archived paper files from closed facilities shouldn't treat that as a solved problem.

New and Pending Legislation

Delaware Governor Meyer signed HB 380, amending the Delaware Personal Data Privacy Act ahead of its January 1, 2027 effective date. The changes lower the applicability thresholds to 10,000 consumers (or 5,000 if 20%+ of revenue comes from data sales), tighten "strictly necessary" limits on selling sensitive data, and add new vendor/contracting requirements. Companies that assumed they were too small to be in scope for Delaware's law are worth a fresh look — the lower thresholds pull in a meaningfully broader set of mid-size businesses.

Guidance and Rulemaking

The FTC formally withdrew its 2021 policy statement that applied the Health Breach Notification Rule to health apps and connected devices, calling the statement obsolete now that a 2024 rule update already covers that ground directly. It's a deregulatory signal in tone, but not a rollback of the underlying rule — health and wellness app makers are still subject to HBNR breach-notification obligations under the updated 2024 rule; the FTC is simply retiring the older interpretive statement rather than the substantive requirement.

The EU Cyber Resilience Act's incident-reporting obligations took effect September 11 for manufacturers of products with digital elements. Covered manufacturers now face a 24-hour early-warning notification duty for actively exploited vulnerabilities and severe incidents, followed by more detailed follow-up reporting — a new operational burden for connected-device makers that sits alongside, and interacts with, their existing GDPR breach-notification duties.

Also worth noting

The FTC extended the comment deadline to September 25 on its proposed enforcement policy statement targeting "personalized pricing" — using personal data to set individualized prices for different consumers. Surveillance-pricing practices remain squarely on the agency's radar.

Canada's Privacy Commissioner also filed a Federal Court application seeking to force Google to implement a limited right to de-listing, following a 2025 investigation. It's the first real test of whether PIPEDA supports a de-listing right — relevant for any organization leaning on a "reasonableness" argument for PIPEDA compliance.

The Takeaway

The through-line this week is that enforcement dollar amounts keep climbing — Uber's nearly €825M fine alone dwarfs most companies' annual compliance budgets — while the underlying failures regulators keep citing are often basic: missing MFA, unanswered rights requests, unsecured paper archives. Combined with Delaware's lower thresholds and the EU's new 24-hour incident-reporting clock, the practical message for compliance teams is the same one it's been for a while — the return on shoring up access controls, DSAR response processes, and breach-notification playbooks keeps going up as the fines do.

Related Posts

Enjoyed this article?

Subscribe to our newsletter for more privacy insights and updates.