One Month, 34 Global Privacy Stories: Look — Compliance Is No Longer a Final Exam
A monthly roundup of 34 global privacy enforcement actions from May 2026 across the Americas, Europe, Africa, and Asia — fines, new laws, and regulatory trends.
A while back, I opened my dashboard and idly scrolled through a full month of global privacy enforcement news from May 2026.
I figured I'd skim a few of the usual "such-and-such agency issued another guideline" items, take a sip of water, and move on.
Then I counted — 7 from the Americas, 13 from Europe and Africa combined, 14 from Asia. Thirty-four items, all in a single month.

Good grief.
I'll tell you, after reading through all of it, one feeling hit me hard: compliance has gone from an "annual final exam" to a "monthly quiz." And the proctors are getting stricter by the day — they'll fine you over the smallest thing.
Why has it come to this? Let me break it into three buckets.
1. The Americas: State Law vs. Federal Law, Already at Odds
Where to start? Here's something genuinely interesting.
In early May, the US House Energy & Commerce Committee rolled out the Secure Data Act, aimed at setting a national standard for consumer data rights across the United States.
Sounds nice, right? One federal law, one set of rules for everyone.
But — the very same day, the California Privacy Protection Agency (CPPA) fired off a letter of opposition. The reasoning was simple: the moment a national law lands, it would water down the stricter protections California already has in place at the state level.
Notice the pattern — regulators are outdoing each other. States think the feds are too soft; the feds think the states are each doing their own thing. This kind of turf war is only going to multiply.
Infighting aside, enforcement certainly isn't resting. Let me pull out a few of the most flagrant ones for you:
- May 8 — The California Attorney General reached a $12.75 million settlement with General Motors (GM). The reason? GM had been selling drivers' sensitive location data to third parties. Selling your whereabouts, for their profit.
- May 11 — The Texas Attorney General settled with LG Electronics, barring it from collecting TV viewing data without explicit consumer consent. You thought your TV was just a screen — it's actually quietly logging everything you watch.
- May 22 — The Connecticut Attorney General opened an investigation into Roblox over its age verification and content moderation.
- May 28 — California Attorney General Rob Bonta sued Chrome Holding Co. for failing to protect users' genetic data during a 2023 breach.
- May 29 — Connecticut's governor signed Senate Bill 4, formally folding data-broker provisions into the state's privacy law.
Notice the common thread? The things most personal to you — your location, your genes, what your kids watch — are exactly what regulators are watching most closely.
That's the trend.
2. Europe: From "Issuing Guidelines" to "Slapping Fines"
Europe tells the story of May 2026 particularly well.
Regulators are no longer just writing documents — they're going from talk to action.
On May 1 alone, several things landed at once:
Italy's Garante issued new rules governing tracking pixels in emails. What's a tracking pixel? It's that invisible little gadget embedded in emails that secretly records whether you opened it, when you opened it, and where you were. Garante now requires marketers to obtain explicit and separate consent before deploying them.
The same day, the Italian antitrust authority AGCM closed its investigations into DeepSeek, Nova AI, and Mistral — on the condition that these companies commit to clearly warning users in-product that "AI can hallucinate."
Germany's BSI unveiled a framework called C3A to safeguard digital sovereignty. The European Commission, meanwhile, urged all member states to roll out privacy-safe age-verification tools before year-end.
By the second week, France's CNIL had locked in a roadmap for AI-based credit scoring — and one line was especially hardline: social media data may not, under any circumstances, be used as an input for credit scoring. What you post, what you like — none of it has anything to do with your creditworthiness. Thorough thinking.
Latvia's DVI published a guide tackling "consent fatigue." Its one-line reminder to companies: making the cookie reject button hard to find is itself an infringement.
Then, on May 12, the fines started landing.
Belgium's DPA issued two in one go: EUR 176,000 against a tech company for failing to promptly deactivate a departed employee's email, and EUR 120,000 against Isabel SA — because it had classified itself as a "data controller" when it was actually a "data processor," and had hoarded data it never should have collected.
See — in Europe, you're no longer being fined for "how much you leaked." You're being fined for "whether you followed the right process." An open inbox, a misfiled role — that's enough to cost you.
The UK's ICO changed its face this month too.
On May 18, it advised the UK government to reform online advertising rules — the gist being: for low-risk ads, don't make people click "I agree" every single time; a blanket consent requirement only frustrates users more.
On May 19, it issued an ultimatum to every business in the country: build a formal data-protection complaints process within one month.
On May 21, the sharpest line of all landed — the ICO expressed "complete lack of trust" in the age-assurance measures from TikTok and X.
From friendly negotiation to legally enforced action. Read that line twice.
3. Asia: New Laws Coming Online, Fines Pegged to Revenue
Asia in May can be summed up in four words: all guns blazing.
On May 1, several countries flipped the switch at once:
China rolled out strict compliance requirements for online marketing of financial products — you want to use AI for precision ad targeting? Get the customer's prior authorization first. Restrictions on how data may be used, spelled out in black and white.
Vietnam expanded its digital-identity infrastructure under Decree 88, folding data such as lifelong-learning records into the national platform.
New Zealand's "Information Privacy Principle 3A" (IPP 3A) officially took effect, dramatically strengthening transparency requirements for third-party data collected indirectly. In other words — data you bought from someone else, you still have to disclose clearly to users.
The most ferocious move came from Bangladesh. It formally enacted the Personal Data Protection Act 2026, extending extraterritorial reach, with fines capped at 5 million BDT. An emerging market leapt straight into the ranks of countries with enforceable data-protection law.
South Korea is the standout story this month — because it tore the ceiling off its fines.
On May 14, the PIPC fined Forum Sanjo Development KRW 553.9 million — for security lapses, delayed breach notification, and unlawful data retention.
On May 28, it slapped KRW 558.6 million on five institutions including the Ministry of the Interior and Safety — the regulator fined its own people. Feel the weight of that.
But the one that genuinely sent a chill down my spine was the May 18 announcement: South Korea is overhauling the PIPA, and the new administrative-fine calculation will be "the higher of the current year's revenue or the three-year average."
What does that mean? Big companies can no longer treat fines as a cost of doing business. The more you earn, the more you pay — and there's no upper limit.

China wasn't idle either. On May 9, TC260 approved and published 10 new national cybersecurity standards in one batch. On May 21, the MIIT named and shamed 31 apps and SDKs — every one of them for unlawful collection or misuse of personal information.
The Philippines' National Privacy Commission nailed the deadline for breach-report submission at 5 days.
Australia had two notable moments in May: first, after the global cybersecurity incident on the Canvas learning platform, the OAIC reminded companies not to lose track of whether they fell under state or federal jurisdiction; second, on May 13, it released updated guidance on APP 3, spelling out data minimization and "fair and reasonable collection" in greater detail.
What Happens Next?
I've lost count, but here are the four most worth watching:
- South Korea is proposing to raise penalties, boost whistleblower rewards, and expand corporate joint liability for data breaches.
- Europe's NOYB has sued LinkedIn for locking certain personal data behind a paid-membership paywall. The Irish DPC has opened an investigation into Shine for transferring data to China.
- California's SB 923 is advancing, set to expand the right to deletion even further.
- Louisiana's data-privacy law is a single step away from taking effect.
See the picture?
Taken together, these signal one thing: regulators' attention has shifted from "should there be rules" to "how those rules land on every transaction, every ad placement, every single user."
Transparency, accountability, cybersecurity, individual rights — those four words will be the most-repeated terms on compliance teams' lips in the year ahead.
Back to the Beginning
I keep coming back to that opening number: 34.
One month, 34 privacy stories. From General Motors selling your location, to South Korea pegging fines to revenue; from that invisible tracking pixel in your inbox, to a brand-new data-protection law in Bangladesh.
Compliance is no longer an annual final exam. It's a monthly quiz — and an open-book one at that. The questions are all on the table; whether you get fined comes down to whether you hand in your paper.
I've been thinking about this a lot these past couple of days. Maybe what we should really worry about isn't any single new law — it's the tempo itself: every month, regulators take another half-step forward; most companies look back only once a year.
That gap is the biggest risk of all.