This Week in Privacy: Jul 20-26, 2026

·12 events covered
FacebookGoogleIndustryRedditTikTok

Big Tech faced serious regulatory pushback this week as Europe doubled down on enforcing its digital rulebook. Google absorbed a nearly €900 million fine for violating the Digital Markets Act, while regulators across multiple continents targeted platforms over data handling, content moderation, and child safety. The message was clear: the era of self-regulation is over.

Top Stories

The European Commission hit Google with an €890 million fine on July 23 for violating the EU's Digital Markets Act. The Commission found Google gave preferential treatment to its own services in search results and prevented app developers from telling users about cheaper purchasing options outside the Google Play store. Google has 60 days to end these practices or face penalty payments reaching 5% of its worldwide revenue. This is one of the first major enforcement actions under the DMA, which took effect in 2023 to curb the power of tech giants. The size of the fine and the tight compliance deadline signal that European regulators are serious about making big platforms play by new rules.

Australia became the first country to ban social media for children under 16, with Parliament passing landmark legislation on July 21. Platforms including TikTok, Facebook, Instagram, Snapchat, Reddit, and X face fines up to $33 million for systemic failures to prevent minors from holding accounts. Companies have one year to implement age verification systems before enforcement begins. The law breaks new ground globally, but raises thorny questions about how platforms will verify ages without collecting intrusive biometric or identification data from all users, including adults.

Origin Energy confirmed a data breach on July 23 affecting Australia's largest electricity and gas retailer, which serves 4.8 million customers. A threat actor claiming to hold data on 2 million customers contacted media outlets demanding Origin respond within two weeks or face public release of the stolen information. The exposed data includes customer names, addresses, dates of birth, phone numbers, account information, and partial financial details including the last four digits of credit cards. Origin is working with the Australian Federal Police, the Australian Cyber Security Centre, and the Office of the Australian Information Commissioner to investigate.

South Korea fined TikTok approximately $7 million on July 24 for collecting behavioral data from 9.45 million users through tracking tools on third-party websites and apps, then using this information to personalize advertisements without properly notifying users. The ruling from South Korea's Personal Information Protection Commission underscores growing global scrutiny of how platforms track users across the internet, a practice that often happens invisibly to consumers.

In Brief

  • The European Commission fined AliExpress over $625 million under the Digital Services Act for failing to remove illegal, unsafe, and counterfeit products, with content moderators given as little as tens of seconds to review flagged items.
  • UK healthcare billing software maker Craneware disclosed a cyberattack in which hackers extracted employee records, customer data, and partner information from systems that handle 147 million patient records.
  • Reddit sued Perplexity AI and three data scraping companies for allegedly bypassing technological protections to harvest millions of user comments, then selling this data to AI companies without authorization.
  • The U.S. Department of Justice reversed its ban on TikTok for federal employees after the app's U.S. operations transferred to an Oracle-led consortium, reducing ByteDance to a 19.9% minority stake.
  • A 15-year-old Florida plaintiff dropped his lawsuit against Meta alleging Instagram caused addiction and mental health harm, with no payment received but after settling similar claims against TikTok, Snapchat, and YouTube.

The Big Picture

This week revealed a fundamental shift in how governments approach tech regulation. Rather than warnings or modest penalties, we're seeing billion-dollar fines enforced within tight deadlines, first-of-their-kind age restrictions with serious financial consequences, and regulatory agencies coordinating across borders. Meanwhile, the 23andMe breach reminder that resurfaced this week, affecting 6.9 million customers' genetic data in 2023, shows that even the most sensitive personal information remains vulnerable. The simultaneous enforcement push and continued breach disclosures suggest we're entering a period where companies face both tighter rules and higher stakes for failures, whether from regulators or attackers. The question is whether these pressures will drive meaningful security improvements or simply redistribute risk and liability.

This Week in Privacy: Jul 20-26, 2026 | PrivacyWire