Privacy Update – Q3 2026

24 September, 2026


Dear Clients and Friends,

This update highlights key privacy and data protection developments across the EU, US, and Israel, covering EDPB guidelines, major GDPR fines, a landmark Meta settlement, new California legislation, and Israeli Privacy Protection Authority (PPA) enforcement and guidance.

EU:

EDPB Issues Draft Guidelines on Anonymization and AI Web Scraping

The European Data Protection Board adopted two sets of guidelines: one regarding anonymization, and the other regarding web scraping in the context of generative AI. The anonymization guidelines, informed by a CJEU ruling in C-413/23 P EDPS v SRB, clarify that data qualifies as anonymous when it does not relate to an identified or identifiable person. They propose a practical framework, testing anonymization against three criteria: no record isolation, no linkage, and no inference. The web scraping guidelines address GDPR compliance when engaging in large-scale automated data collection for AI training, covering lawful bases, purpose limitation, transparency, and data minimization, including the processing of special categories of personal data. Both sets of guidelines are open for public consultation until 30 October 2026.

Italian Garante Issues Multiple Fines Totaling Nearly €12 Million

The Italian Data Processing Authority (DPA), Garante, imposed fines totaling around €12 million across three enforcement actions. It fined U.S. data broker Lusha Systems Inc. €2 million for unlawfully processing personal data of individuals in Italy, ordering it to cease processing and delete the data; Lusha had collected and continuously updated professional contact information from social media and other brokers, and the Garante held that legitimate interest did not constitute a valid legal basis for its activities. It fined Piaggio & C. S.p.A. €460,000 for accessing former employees’ corporate email accounts for disciplinary purposes and retaining email content for excessive periods, rejecting Piaggio’s defensive monitoring arguments where the searches extended to periods predating any specific suspicion. It also fined TIM S.p.A.. an Italian telecommunications operator, €9.5 million for unlawful telemarketing, including unsolicited calls from spoofed or unregistered numbers and insufficient controls over partners and processors.

Dutch DPA Fines Uber €824.9 Million Over Automated Driver Deactivations

The Dutch DPA (AP) fined Uber B.V. €824.9 million for violations of the GDPR, concerning the use of fully automated systems to deactivate drivers’ accounts without human review. Uber’s systems flagged drivers with consistently low ratings for permanent deactivation and suspected fraud cases for temporary suspension, with no human involvement in either process. Uber has appealed this decision.

CNIL Publishes Guidance on Geolocation Data in Mobile Apps

The French DPA (CNIL) published guidance on the collection and use of geolocation data by mobile apps, clarifying that consent is required when geolocation is not strictly necessary for the app’s core service. The CNIL calls on developers to minimize collection of such data, choose the least precise location level adequate for each use, favor on-device processing, avoid continuous background tracking, and set proportionate retention periods.

Austrian Supreme Court Rules CRIF’s Use of Marketing Data for Credit Scoring Violates Purpose Limitation

Austria’s Supreme Court ruled that credit reference agency CRIF unlawfully collected personal data from address publishers for use in credit scoring, finding that the practice violated the GDPR’s purpose limitation principle. The court confirmed that personal data originally processed for marketing purposes could not be repurposed for credit assessment, given the fundamentally different nature and consequences of those activities.

US:

Multistate Coalition Reaches $17.1 Billion Settlement with Meta Over Harmful Design Features

A coalition of U.S. state attorneys general reached a proposed settlement with Meta Platforms, Inc., pending court approval, to resolve claims that Meta designed addictive features on Instagram and Facebook that harmed children, in violation of federal Children’s Online Privacy Protection Act (COPPA) and state consumer protection laws. Under the settlement, Meta denied liability but agreed to pay up to $17.1 billion and implement extensive platform changes for users under 18, including default daily time limits, nighttime access blocks, and enhanced parental supervision tools. Separately, a New Mexico state court ordered Meta to pay approximately $942 million and implement reforms to protect minors after finding violations of the New Mexico Unfair Practices Act.

CalPrivacy Fines LocateSmarter in CCPA and DELETE Act Action

The California Privacy Protection Agency (CalPrivacy) ordered LocateSmarter LLC to pay $116,490 for failing to register as a data broker and for requiring consumers to provide the last four digits of their Social Security numbers in order to opt out of the sale of their personal information. The agency found that this practice violated the CCPA and the DELETE Act by demanding unnecessary sensitive information and potentially discouraging consumers from exercising their statutory rights.

New Jersey Enacts Age-Appropriate Design Code

New Jersey enacted an Age-Appropriate Design Code imposing extensive obligations on covered online services likely to be accessed by children and minors, including high-default privacy settings, restrictions on account visibility, limits on targeted advertising and geolocation use, and mechanisms for reporting harms and requesting deletion. The Act will take effect on September 1, 2027.

California Legislature Advances Multiple Privacy Bills

The California Legislature passed Senate Bill 690 (SB 690), which would amend the California Invasion of Privacy Act (CIPA) in response to a spate of private lawsuits alleging that website and app tracking technologies, including analytics and advertising pixels, constitute unlawful “pen registers” under CIPA. If signed by the Governor, the bill would significantly limit private plaintiffs from bringing CIPA pen-register claims over these tracking tools, limit enforcement to the Attorney General, apply retroactively to recently filed claims, and create broad exemptions for data processing carried out for a commercial business purpose as defined under the California Consumer Privacy Act.

The California Legislature also approved Senate Bill 923 (SB 923), which, if signed, would expand California consumers’ right to request deletion of their personal information. Under the bill, businesses would generally be required to delete non-exempt personal information they hold about a consumer, even if the information was obtained from a third party rather than directly from the consumer. The bill would also require certain businesses that operate exclusively online and have a direct relationship with consumers to provide both an email address and an online mechanism for submitting access, correction and deletion requests.

California also advanced Assembly Bill 1542, which would prohibit businesses, service providers, and contractors from selling or sharing sensitive personal information with third parties except in limited specified circumstances.

Israel:

The Israeli PPA has been very active in recent months, utilizing its increased enforcement capabilities under Amendment 13 to the Israeli Privacy Protection Law.

PPA Fines Meuhedet NIS 256,000 for Failing to Immediately Report Serious Security Incident

The PPA imposed a NIS 256,000 fine on Meuhedet Health Services for failing to immediately report a serious security incident involving unauthorized access to sensitive medical information. The PPA emphasized that the duty of immediate reporting arises once a serious security incident becomes known and does not permit delay pending completion of a full internal investigation.

PPA Fines Company for Failing to Provide Required Privacy Notice at Data Collection

The PPA imposed a NIS 12,000 fine on a company after finding that it collected personal information through an online registration form without providing the detailed privacy notice required under Section 11 of the Privacy Protection Law, 1981. The PPA emphasized that the duty to inform data subjects at the point of collection is a fundamental obligation under Israeli privacy law, as it enables individuals to make an informed decision about whether to provide their personal data.

PPA Fines Beit Shemesh Municipality for Data Security Regulations Violations

The PPA imposed a NIS 64,000 fine on the Municipality of Beit Shemesh following a serious security incident in the municipality’s GIS system, which resulted in the exposure of personal and medical information of approximately 4,600 residents. The PPA found two violations of the Privacy Protection Regulations (Data Security), 5777-2017: first, the municipality failed to designate the processor that provided support and processing services in the company’s Database Specification Document; second, the municipality’s data security procedures did not address obligations relating to engagements with external parties granted access to the database, including the purposes of use, types of data permitted for processing, access systems, and duration of engagement. We note that the fine was imposed for relatively formalistic violations and not in connection with the security incident itself.

PPA Publishes Final Opinion on Appointment of Privacy Protection Officers Under Amendment 13

The PPA published a final legal opinion clarifying the new obligation under Amendment 13 to the Protection of Privacy Law to appoint a DPO. The opinion addresses the scope of the appointment requirement, the officer’s role and responsibilities, the qualifications and expertise required, and additional provisions governing the officer’s status within the organization. For further information, please consult the following article that we recently published: PPA Publishes Final Guidance on the DPO Appointment Obligation Under Amendment 13.


The above content is a summary provided for informational purposes only and does not constitute legal advice. It should not be relied upon without obtaining further professional legal counsel.

Want to know more?
Contact us

Shiri Menache

Head of Marketing and Business Development

Matan Bar-Nir

Press Officer, OH! PR