Nine days, four regulators, three continents, and one recurring shape.
Children
TikTok and ByteDance agreed to pay $400 million to settle the Justice Department’s COPPA case, announced 21 August. $300 million immediately; $100 million contingent on an order vacating the prior Musical.ly consent decree. The allegations: millions of under-13s admitted to the platform without verifiable parental consent, an age gate a child defeated by trying again with a different birthdate, and — the worst of it — parents’ deletion requests that were not honoured.
It is the largest COPPA recovery ever obtained. It is also about 1.7% of an estimated $23 billion in annual revenue, or roughly six days of trading. Full analysis.
New Jersey took the other route. Governor Sherrill signed the Kids Code Act on 11 August, effective 1 September 2027: highest privacy settings by default for known minors, no notifications during school hours or overnight, a ban on design features engineered for compulsive engagement, data minimization, and limits on targeted advertising. The provision industry fought hardest: a private right of action worth $5,000 per violation — the first in any American design code.
One model produces a headline every few years. The other produces an uninsurable liability that scales with your user base. Guess which one gets lobbied against. Full analysis.
Money
The FTC named surveillance pricing on 19 August, in a proposed enforcement policy statement open for 30 days of comment, authorised 2–0. Personalized pricing: using browsing history, location, demographics and purchase patterns to set an individual price based on estimated willingness to pay or likelihood of comparison shopping.
The legal theory is deception under Section 5, not unfairness — because consumers expect the price they see is the price everyone sees, and implying a static price that varies by person is deceptive. That choice makes disclosure the safe harbour and leaves the underlying practice intact, but it does something valuable anyway: it puts a dollar figure on data broker inputs, at the federal level, on the record. Full analysis.
Brokers
CalPrivacy fined two data brokers in three days. Cybba, Inc. paid $52,400 for never registering under the Delete Act. LocateSmarter, LLC paid $116,490 — a $79,890 CCPA fine, a $30,600 Delete Act fine, and the $6,000 registration fee — in CalPrivacy’s first action alleging both statutes together.
The CCPA half is the one that travels. LocateSmarter required consumers to supply their full name, mailing address, and the last four digits of their Social Security number in order to submit an opt-out. The agency held that data minimization applies to the privacy request process itself — you may collect only what is reasonably necessary and proportionate to the specific request, and an opt-out of sale does not warrant SSN-grade verification.
Every over-engineered privacy request form on the internet just became a liability. Full analysis.
Cameras
Santa Barbara’s Flock Safety contract ended 23 August. The council moved to replace 12 automated licence plate readers with Verkada CB53 units at $56,810.09 — a closed-circuit architecture where the department owns the tenant, sets retention, and no outside agency queries the pool by default.
The objection that killed the Flock contract was never the sensor; it was the network, and the discovery that a routine municipal purchase had enrolled the city in a national mesh whose sharing rules were set elsewhere, including in searches connected to federal immigration enforcement.
What the swap fixes: automatic outward sharing. What it does not: the cameras still read every plate, retention is a setting rather than a guarantee, a closed database is still subpoenable, and Verkada’s own history includes a 2021 breach exposing feeds from roughly 150,000 cameras. A closed system with no audit is a national database with one extra phone call. Full analysis.
Emergencies
New Orleans confirmed that an automated voice agent has been answering 911 calls since 2023. Callers were never notified. Seattle does not tell medical 911 callers that AI is analysing the call. Long Beach is deploying AI to score dispatcher performance on recorded calls.
There is no federal standard requiring a 911 centre to disclose AI involvement. State AI legislation is moving faster in 2026 than in any prior year and none of it addresses 911 dispatch. Meanwhile 81% of Americans already believe AI is being used on them secretly, and a 2025 survey found 16% specifically suspected undisclosed AI on 911 lines. They were right.
Consent is structurally impossible here — there is one number and you call it at the worst moment of your life — which is an argument for a higher disclosure duty, not a waived one. Full analysis.
Europe
The AI Act’s flagship date arrived without its flagship rules. The Digital Omnibus (Regulation (EU) 2026/1744) entered into force 27 July, five days ahead, deferring Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028.
What did become enforceable on 2 August: Article 50 transparency — chatbot disclosure, machine-readable marking of synthetic content, deepfake labelling — plus GPAI enforcement powers and the full penalty regime up to €35 million or 7% of global turnover. And a new Article 5 prohibition on AI-generated non-consensual intimate imagery, which almost nobody covered.
The Article 5 bans — social scoring, workplace emotion recognition, untargeted facial scraping, real-time remote biometric ID in public — have been live since February 2025 and were untouched. Full analysis.
The World
India’s Data Protection Board can levy penalties from 13 November 2026, with full compliance due 13 May 2027 and a maximum of ₹250 crore per instance. Registration for Consent Managers — a regulated intermediary giving individuals one interface to grant, review and withdraw consent across every Fiduciary they deal with — opens the same day. There is no GDPR equivalent, and if it works it is the most consumer-favourable structural idea in modern privacy law. Full analysis.
Cumulative GDPR fines passed €7.1 billion, with six of the seven largest relating to cross-border transfers. 172 countries — 79% of the world — now have a data protection law. Brazil took EU adequacy in January and tightened its own outbound rules under Resolution 19; China’s PIPL certification route went live in January; India runs a blacklist where Europe runs a whitelist. Three theories of the border, no convergence.
And Norway’s regulator told a fitness chain on 14 August that it could not require members to hand over a photograph to check in — mandatory collection was not necessary to fulfil the membership agreement. No leaderboard will record it. It is the clearest statement of the necessity principle anyone made this month. Full analysis.
The pattern
Every story above is about a control that existed and did not control anything.
TikTok had an age gate; a child beat it by re-entering a birthdate. TikTok had a deletion process; parents wrote in and nothing happened. LocateSmarter had an opt-out; it demanded a Social Security number to use it. Retailers show a price; the price is computed from a model of what you will tolerate. Santa Barbara had a vendor policy; the sharing settings sent plates somewhere the council never voted for. New Orleans had a 911 line; the voice at the start was a machine and the disclosure was absent. The EU had a deadline; the deadline moved five days before it landed.
None of these are failures of intent. In every case there is a documented mechanism that satisfies an auditor, appears in a compliance matrix, and can be pointed at in a hearing. What is missing is the same thing in each: nobody had to prove the mechanism worked, and somebody profited from it not working.
That is why the two most consequential things this fortnight were the smallest. CalPrivacy said the request process is itself regulated. Norway said the necessity test applies to a turnstile. Both are regulators declining to accept that the existence of a control is evidence of a control.
What to do this week
-
Never give a partial SSN to exercise a privacy right. It is unlawful in California as of this month and arguable in 172 countries. Refuse, screenshot, and complain.
-
Turn on Global Privacy Control. Native in Firefox and Brave, extensions for Chrome. It is a legally binding opt-out in California that requires no form, no verification, and no cooperation from a broker who would rather you gave up.
-
Disable your mobile advertising ID. Android: Settings → Privacy → Ads → Delete advertising ID. iOS: Settings → Privacy & Security → Tracking → off. It is the identifier that feeds the pricing model the FTC just described.
-
File a comment on the FTC personalized pricing statement. Thirty days from 19 August. Concrete consumer accounts of price variation are the record the agency needs.
-
Compare a price logged out and logged in, on two networks. Then screenshot it with a timestamp. Contemporaneous evidence is what turns a policy statement into a complaint.
-
Ask your city two questions in writing: what ALPR system it operates and under what sharing policy, and whether its 911 centre uses AI to answer, analyse, or score calls. Both are public records requests. In most places, nobody has asked.
-
Set your child’s defaults tonight. Private account, no discovery by phone or email, DMs from contacts only, location off, ad personalisation off, autoplay off, notifications silenced overnight and during school. New Jersey wrote that configuration into law for September 2027. You can apply it before bed.
-
California residents: use DROP. Live for brokers since 1 August. One request reaches every registered broker, and this month proved the state will fine the ones who try to stay off the list.



