Every month, the Privacy Gazette unpacks the stories shaking up the global data protection ecosystem. Drawing on the expertise of Pascal Vautrin, Privacy Standards Expert at Axeptio, it looks at the developments that matter and at what they mean in regulatory, economic and political terms.
This second issue covers a busy stretch. The European Commission handed down its first heavy penalties under the DMA and the DSA, Google quietly changed its legal status on reCAPTCHA, the Court of Justice confirmed that member states can make platforms pay news publishers, and the American example is a reminder that, absent a federal framework, the most structural questions get settled by judges or rest on temporary authorizations, with all the instability that implies for the companies caught in the middle.

It's Shaping Up to Be a Fine Season in Brussels
On May 28, the Commission fined Temu €200 million under the DSA. The central complaint is not that illegal products were on sale, but that Temu never seriously assessed the risk that they would be there. Designated a "very large online platform" under the DSA in 2024, the company was required to analyze that systemic risk and did not do so to an acceptable standard, particularly as regards the part played by its own recommendation systems and affiliate programs. Temu has until August 28 to put a corrective action plan to the Commission. A second investigation, into the platform's addictive design, remains open. This is only the second penalty issued under the DSA, after the €120 million imposed on X in December 2025.
A few weeks later, on July 23, round two, this time under the DMA: two non-compliance decisions against Google totaling €890 million. €460 million for self-preferencing its own services in Google Search, and €430 million for the anti-steering restrictions placed on developers who wanted to point their users toward alternative purchasing channels outside Google Play. Google has 60 days to bring itself into line.
The amounts sit well below the statutory maximums. What matters more is that Brussels is finally enforcing the rules it spent years drafting.
reCAPTCHA Is Now "Google Fraud Defense": I'm Not a Robot, but I Am the Data Controller
reCAPTCHA is the verification widget Google provides free of charge so that websites can tell a human visitor from a bot, typically on login, sign-up and payment forms. Its use has been contested in Europe for years, on the grounds that the check involves collecting more personal data than a simple bot test would call for.
Then, on April 2, Google changed the service's terms of use. It now sits within Google Cloud under a name designed to sound more reassuring: Fraud Defense. Until that date, Google treated itself as the controller of the data collected through reCAPTCHA, with the freedom to use it for its own purposes. It now declares itself a data processor, leaving its customers as the sole data controllers. Google is also asking website operators to strip references to its own privacy policy from their sites and from the reCAPTCHA badge.
Two things follow. The data collection has not gone away; only its legal label has. The compliance burden, meanwhile, has moved to the website operator: a lawful basis to document, a data processing agreement to sign, a privacy notice to rewrite.
"Processor status is not something you settle by contract. It follows from who actually determines the purposes and the means of the processing. If Google carries on using this data for its own ends, a regulator remains free to reclassify the roles. This case also raises a question about how the tool behaves when it encounters a device that has been a little too thoroughly de-Googled: a user who has chosen to do without Google's services becomes, in Google's eyes, a potential fraudster." Pascal Vautrin
Calling yourself a data processor does not make you one. But until a regulator rules on it, the website operator is the one answering for Google's technical choices.
CIPA: Land of the Free, Home of the Lawsuit
Twenty-five states will soon have a comprehensive privacy law, Louisiana and Vermont having passed theirs this spring. No federal statute has come along to tie the patchwork together, and a body of California litigation shows what that absence produces: the sector's most structural questions end up being settled by judges rather than by legislators.
The dispute concerns web tracking. CIPA, the California Invasion of Privacy Act, is a 1967 statute drafted for the age of the telephone (a device originally intended for talking to someone at the other end of a line, you may recall). It prohibits two things: listening in on the content of a conversation without the parties' consent and, following a 2015 addition, recording the technical traces of a communication, what the statute calls a pen register, meaning who called which number and when. Since 2022, American lawyers have been arguing that both prohibitions apply to the web as well. A form whose contents are captured by a third party would amount to eavesdropping; an IP address collected by a tracker would amount to a pen register. Hundreds of claims have been filed on those two grounds.
You can see where this is heading. If that reading were to prevail, collecting browsing data would in practice require the user's prior agreement, and it would apply to every company, not just those caught by the CCPA. California would shift, in effect, from opt-out to opt-in.
California courts, however, cannot agree. On May 27, the Los Angeles Superior Court sided with website operators in Blaker v. NetScout Systems: the 2015 pen register provisions were written for the telephone and do not reach software installed on a commercial website. That kills one line of attack. The eavesdropping claim, though, is untouched, and it is the one driving most of the pending litigation. Two California courts have already reached opposite conclusions on near-identical facts, a day apart.
What Is Journalism Worth? Europe's Top Court Has Started to Answer
In the first issue we looked at Australia's plan to tax Big Tech in order to fund the media. The same standoff has just played out in Europe, this time in a courtroom, and the publishers came out on top.
A quick refresher. A 2019 European directive granted news publishers what the EU calls the press publishers' right: when a platform reproduces their content online, whether article extracts, headlines or summaries, it owes them payment. The principle was settled; its application much less so. Each country had to write the rule into its own law, and Big Tech duly set about challenging the national laws that followed.
Meta did precisely that in Italy. AGCOM, the Italian communications and media regulator, had set out in 2023 the criteria for calculating what platforms owe publishers. Facebook and Instagram's parent company took that decision to the Italian courts, arguing among other things that Rome had no business imposing such a mechanism on it. Rather than rule, the Italian judge referred the question to the Court of Justice of the European Union.
The answer arrived on May 12, and it went Italy's way. A member state can indeed require platforms to pay publishers fairly. The Court set out a few common-sense limits: a publisher must remain free to refuse the use of its content, or to allow it for nothing, and no platform can be made to pay for content it does not use.
The Court also found that publishers negotiate blind. The figures needed to establish what their content actually earns sit with the platforms and nowhere else, so it accepted that states can compel those figures to be handed over. Nobody negotiates a price they have no way of measuring, and the ruling puts the first real dent in an imbalance that has held since 2019. Every European country now has case law on which to build its own model.
Unfortunately for publishers, the ruling covers the reproduction of articles by platforms, not the use of press content to train artificial intelligence. One battle at a time.