Plans
Learn Library

One Month, 34 Moves: Global Privacy Regulators Are Closing the Net

A roundup of global data-privacy regulatory actions reported for a single month, covering fines, new laws, and guidance across the Americas, Europe, Africa, and Asia. It frames compliance with data rules as increasingly unavoidable for businesses.

ai-marketing
2026-09-07SupaMarketers9 min read

A while back I was combing through regulatory updates from around the world. When I got to May 1 of this year, I froze.

On that single day, Italy, Germany, the EU, China, South Korea, Vietnam, New Zealand, and Bangladesh — eight countries and jurisdictions — all made their moves at once.

Some issued new rules, some wrote fines, some published guidance, and one went ahead and passed an entirely new law.

I traced through the whole of May and tallied up the ledger: 7 key moves in the Americas, 13 in Europe and Africa, 14 in Asia.

Altogether: 34.

Unreal.

This is no longer scattered skirmishing. This is a globally synchronized closing of the net.

Whose net? The net over data. Your data, my data, everyone's data.

First, the Americas: the fines are real — and they're coming

What exactly is data brokering?

Put simply, it's a business built on collecting your data, then turning around and selling it to someone else. You've never met the buyer — yet they may know you better than you know yourself.

On May 8, the California Attorney General reached a $12.75 million settlement with General Motors over precisely this: reselling drivers' sensitive location data.

Think about it: you're driving, believing the steering wheel is in your own hands. In reality, every single route you took was packaged up and sold.

This won't bleed GM badly. But the signal is unmistakable: if you're in the business of reselling data, regulators are now showing up at your door, one by one.

That same month, the Texas Attorney General also settled with LG Electronics. From now on, if LG wants to collect TV viewing data, it must first obtain users' explicit consent. What you watch, and until what hour, is no longer free raw material for the manufacturer.

Connecticut turned its attention to children. On May 22, the state's Attorney General opened an investigation into Roblox — into age verification, and into content moderation alike. If your platform serves minors, you have to prove you can keep out the people who shouldn't be there.

And there's an old entry in the ledger. On May 28, California Attorney General Rob Bonta sued Chrome Holding Co., arguing that in the 2023 data breach, users' genetic data wasn't properly protected.

A leaked password can be changed. Leaked genetic data cannot.

One more thing happened in the Americas this month — quiet, but even more worth watching: the U.S. House Energy and Commerce Committee introduced the Safe Data Act, aiming to set a single national standard for consumer data rights. That same day, the California Privacy Protection Agency (CPPA) sent a letter in opposition, arguing the bill would weaken the protections states already have.

Washington wants uniformity; the states want to keep their higher bars. And the states aren't waiting. On May 29, Connecticut's governor signed Senate Bill 4, writing data brokering formally into the state's privacy law.

Next, Europe and Africa: one unclosed mailbox, a €176,000 fine

The most interesting European fine of May isn't the biggest one.

On May 12, Belgium's data protection authority issued two in a single day. One of them, €176,000, went to a tech company: after an employee left, the former employee's mailbox was never shut down.

One mailbox. A six-figure risk.

Run that math yourself. Closing the mailbox takes a few clicks of the mouse. Leaving it open costs €176,000. The most expensive thing in the world is often the small task anyone could have done in passing — and nobody did.

The other, €120,000, went to Isabel SA: collecting data far beyond what was needed — and losing its standing as a data processor along the way.

Europe's keyword this month was, in fact, "consent."

Italy's data protection authority, the Garante, issued new rules: tracking pixels in email — those tiny things you can't see anywhere in your inbox — may be used only after first obtaining consent that is freely given and specific. Latvia's data protection authority, the DVI, put out guidance with an even blunter message: burying the cookie opt-out behind twist after twist is a violation of user freedom.

What is consent fatigue?

It's what happens when the "Agree" button gets pressed so many times that people go numb. And once they're numb, consent stops being consent — it becomes a reflex.

Which is why the UK ICO's recommendation looks counterintuitive at first, then exactly right on reflection: for low-risk advertising, stop insisting on one-size-fits-all consent — simplify where simplification is due.

Do you see the logic here? Hand out consent too freely, and real consent stops meaning anything.

The scarcer consent is, the more it's worth. Easing the burden on consent is how you make it valuable again.

But don't get the wrong idea — the ICO isn't going soft on the big platforms. On May 19, it gave UK businesses an ultimatum: within one month, put formal data protection complaint-handling procedures in place; the new law demands it. On May 21, it went public again: when it comes to the age-verification measures of social giants like TikTok and X, it has no confidence at all.

From friendly persuasion to legal action — the shift in tone is now on the record.

Europe also made several long-horizon moves. France's CNIL set out a roadmap for AI credit scoring, and one line in it is particularly harsh: social media data must not be used as a scoring source. Italy's competition regulator, the AGCM, closed its investigations into DeepSeek, Nova AI, and Mistral — all three committed to giving clear warnings about AI hallucinations. Germany's BSI rolled out the C3A framework to defend digital sovereignty. And the European Commission is pressing member states: roll out age-verification tools for privacy and security by year-end.

Two more items were "soft moves." Hamburg's data protection commissioner issued guidance on the EU Court of Justice's Wirtschaftsmedien case: under GDPR, online services are data controllers. And the European Data Protection Board (EDPB) issued an opinion on Finland's requirements for GDPR certification bodies, so the whole European Economic Area doesn't end up singing from different song sheets.

Asia: South Korea turned its fines into a formula

Asia's theme this month was welding the rules into place: build frameworks, set deadlines, and do the math on fines.

The one most worth chewing on is South Korea.

On May 18, South Korea announced a sweeping overhaul of its Personal Information Protection Act (PIPA), and buried inside is a vicious little formula: the base for administrative fines is set by whichever is higher — the company's annual revenue or its three-year average revenue.

What does that mean?

The anchor for fines is now driven into your true size. However your revenue fluctuates, however the books are arranged — there's no escaping it.

And the fines didn't stop. The Korea Communications Commission (KCC) penalized Lot Card over unencrypted connection data and registration numbers that led to a large-scale breach. The Personal Information Protection Commission (PIPC) fined Forum Sanjo Development 553.9 million won — security negligence, delayed breach reporting, and over-retention of data, all stacked into one penalty. At month's end, the PIPC levied 558.6 million won on five institutions, including the Ministry of the Interior and Safety.

Even government bodies get no exemption.

South Korea is also building for the long haul. The PIPC announced a risk-tiered data inspection framework, with high-risk industries inspected first; and it wrote privacy by design directly into law. What is privacy by design? It means working out how data will be collected, used, and deleted while you're writing the first line of code — not patching things after something goes wrong.

China's moves were dense, too. From May 1, online marketing of financial products tightened: if you want to use data for AI targeting, you first clear the customer-authorization gate. Mid-month, TC260 (China's national cybersecurity standards committee) released ten national cybersecurity standards in one go. At month's end, the Ministry of Industry and Information Technology (MIIT) named 31 apps and SDKs in a public reprimand: collecting personal information improperly, and using it beyond the declared scope.

The region around them stayed busy as well. The Philippines set a hard deadline: a complete breach report must be filed within 5 days. Vietnam moved twice: Decree 88 wired lifelong learning record data into the national digital identity platform, and its parliament passed an e-commerce law. New Zealand's Privacy Principle 3A took effect, sharply raising transparency obligations for third-party data collected indirectly. Australia spoke up after the Canvas learning platform's global security incident, reminding businesses to distinguish state from federal oversight duties; and the OAIC updated its guidance on Australian Privacy Principle 3 (APP 3), tightening data minimization.

And the one most worth spotlighting: Bangladesh.

On May 1, Bangladesh formally passed its Personal Data Protection Act 2026 — with extraterritorial reach, and penalties up to 5 million taka.

Another vast, populous land has raised its own data protection law. On this map, the blank spaces keep shrinking.

What to watch next

The items still on the table at the end of May belong on your watchlist.

South Korea is proposing even tougher enforcement: bigger fines, whistleblower rewards, and expanded corporate liability. Taiwan opened a public consultation on cybersecurity requirements for non-government agencies. In Europe, the digital rights group NOYB has its sights on LinkedIn: locking access to certain personal data behind a paywall has been formally challenged; meanwhile Ireland's DPC opened an investigation into Shine's data transfers to China. In the US, California's SB 923 is pushing toward a broader right to deletion, and Louisiana's privacy act is one step away from taking effect.

Transparency. Accountability. Child protection. Data brokering. The boundary of how AI may use data.

May's 34 moves, at bottom, all answer the same question: who does the power over data actually belong to?

One Last Thing

Back to May 1. Eight countries and jurisdictions, all acting on the same day.

At first I took it for coincidence. Only after tracing all 34 moves did I understand: this is consensus.

On data, compliance isn't a cost — it's the ticket. Without a ticket, however big your business, it doesn't get on the field.

Here's wishing that your data stays yours alone. And that your company never has to learn these agencies' names from a fine.

Continue reading