A €825 million fine against Uber from the Dutch Data Protection Authority marks the largest GDPR penalty issued to a platform-economy company on algorithmic transparency grounds and reframes automated decision-making disclosure as an acute enforcement priority across the EU. The Dutch DPA cited violations of Articles 13–14 and 22 GDPR, targeting Uber's profiling practices and inadequate disclosure to drivers. Given Uber's pan-European operations, the decision carries direct compliance relevance for any platform business using algorithmic management, pricing, or driver-scoring systems — not only for the quantum of potential penalties but for the obligation to audit disclosure architecture against Articles 13–14 before enforcement attention arrives.
Watch level: PREPARE (platform-economy operators, gig-economy compliance teams, EU-facing product counsel)
California Attorney General Rob Bonta's investigative subpoena to OpenAI reinforces that state consumer protection and charitable trust authority are now operational enforcement tools against large AI developers, independent of any federal AI framework. The absence of comprehensive federal AI legislation has created a vacuum that state AGs are actively filling: the California action parallels New Mexico's companion legislative announcement and follows a sustained pattern of state-level scrutiny directed at foundation model developers. Compliance teams at AI companies with significant US consumer exposure should treat the California subpoena as an indicator of the enforcement trajectory — not an isolated event — and assess the adequacy of existing disclosure and governance documentation against state AG investigative demands.
Watch level: PREPARE (AI developers with US consumer exposure, in-house counsel at foundation model companies)
The Delaware Governor's September 2 signature on House Bill 380 amending the Delaware Personal Data Privacy Act tightens sensitive data handling obligations and vendor contract requirements, with an effective date of January 1, 2027. The amendments narrow the compliance window for covered entities to renegotiate data processing agreements and reassess sensitive data categories — a practical urgency that is easy to underestimate given the relatively short legislative cycle. Organizations already mapped to Delaware's privacy regime should initiate gap analyses immediately; the contract restructuring timelines involved in revising third-party data processing arrangements make early action necessary rather than precautionary.
Watch level: PREPARE (privacy counsel, vendor management teams, DPOs with Delaware operational exposure)
The EU Advocate General's opinion in Case C-222/25 concludes that the Law Enforcement Directive governs personal data processing by Financial Intelligence Units in their anti-money laundering and counter-terrorist financing roles, narrowing a disputed jurisdictional question about which EU data protection framework applies. The Court of Justice is not bound by Advocate General opinions but follows them in the substantial majority of cases, making this a development that FIU legal and compliance teams — and the regulated financial institutions that supply data to them — should begin incorporating into their compliance planning now. A ruling confirming the opinion would require FIUs in member states currently operating under general GDPR assumptions to reframe their lawful basis structures, retention frameworks, and data subject rights handling under the LED's more restrictive regime.
Watch level: MONITOR (FIU legal and compliance teams, AML-regulated financial institutions, EU member state supervisory bodies)
Michigan's consumer fraud suit against TP-Link Systems reflects a structural shift in how state attorneys general are using consumer protection statutes to address hardware security and foreign access risks — a enforcement vector that has historically been the province of federal national security review. The action follows congressional scrutiny of TP-Link's Chinese supply chain relationships and raises the prospect of parallel state and federal proceedings against connected hardware vendors. Compliance and procurement teams in the networking and consumer electronics sectors should treat this as an indicator that state AGs are prepared to act on foreign-access hardware concerns without waiting for federal resolution, particularly where consumer fraud hooks are available.
Watch level: MONITOR (consumer electronics vendors, enterprise network procurement teams, hardware security counsel)
Still developing: US Senate Healthcare Cybersecurity Act: no material change since last reported; the bill has passed the Senate and awaits House consideration. Oklahoma federal court suppression of Flock ALPR evidence: no material change since last reported; ruling stands as issued. Denmark CPR breach: no material change since last reported; security review and dual investigation by the data protection authority and National Special Crime Unit remain ongoing. Australia OAIC investigation into HeyCyan smart glasses developer: no material change since last reported; formal investigation with compulsory information-gathering powers remains active.
Policy Signal · policysignalhq.com · Major privacy + AI governance moves, distilled.