Global Compliance Update: FCA NFM Weeks Away, EU Approves AI Act, EEOC Pivots in July 2026

Global compliance is on the move, and regulators are not waiting for employers to keep up

If May was the month of stalled talks and long lead times, July is the month global compliance deadlines become real. From the UK to EU to China and the U.S., regulators around the world are revamping expectations for non-financial misconduct, data privacy, policy enforcement, and more. Read more to explore critical compliance updates and key deadlines every global employer should know.

4 new global compliance updates in July 2026

#1. FCA non-financial misconduct rule changes weeks away

When we covered the Financial Conduct Authority (FCA) in May, firms had 106 days to prepare. 

That number is now 34. 

Starting 1 September, the rules outlined in Policy Statement PS25/23 expand the definition of misconduct to include non-financial misconduct, even when it occurs on social media. In a matter of weeks, roughly 37,000 employers will be responsible for proactively preventing workplace misconduct both at work and online. 

This means bullying, harassment, violence, and other types of non-financial misconduct can impact Fitness and Propriety, whether the behaviour occurs at work or on personal social media channels. 

In March, the regulator launched a dedicated practical guidance hub to help firms prepare. They also finalised the date for the Senior Managers & Certification Regime reforms so the NFM-related changes land on the same 1 September date. 

Perhaps most consequential of all: Substantiated non-financial misconduct must now be disclosed in regulatory references, meaning misconduct history follows individuals between firms.

Firms still in “wait and see” mode are running out of runway. Policies, investigation procedures, fitness and propriety assessments, and screening programs all need to comply with the new standard before 1 September. The FCA has already discussed next steps.

Learn how to prepare in our FCA Countdown Resource Center or in our upcoming webinar with Giant Screening. 

#2. Europe approves the AI Act, the Netherlands and Germany raise the bar

The EU AI Act carve out is now (almost) law 

The stalled negotiations we flagged in May were resolved as the European Parliament endorsed the Digital Omnibus on AI on 16 June. The Council gave its final green light on June 29, with publication expected imminently. 

For employers, obligations for high-risk AI systems, are now deferred from 2 August 2026 to 2 December 2027. This change means recruitment, promotion, and workforce management tools have more time to make appropriate changes. The update also impacts other AI uses. For one, obligations for AI embedded in regulated products are deferred to August 2028. Even more, the update creates a carve-out that largely exempts AI covered by the Machinery Regulation.

Understanding what has changed is important, but it's also important to understand what did not change. While most obligations for high-risk systems are deferred, transparency obligations under Article 50 still take effect on 2 August 2026. AI chatbots and AI-generated content that touch candidates or employees also need clear disclosures this summer. As the extension is simply a deferral and not a repeal, organisations should still plan to adopt the risk-based architecture and use the extension to update assessment and documentation processes.

Germany: new federal privacy chief and age requirements for social media

Germany’s Bundestag elected Prof. Dr. Moritz Hennemann as the new Federal Commissioner for Data Protection (BfDI) on June 25. He succeeds Louisa Specht-Riemenschneider, who steps down at the end of September. Dr. Hennemann favours a more economy-oriented approach to data protection.

In the same week, the federal expert commission on youth protection recommended several key changes to social media access. They recommend a statutory minimum age of 13 for social media use, backed by age verification for enforcement. This adds to momentum behind the European Commission’s age verification app expected before the end of 2026. 

Key takeaways: For companies operating consumer platforms in Germany, self-declared age checks will not cut it. By the end of 2026, expect to focus on certified age assurance. There's no direct action for HR teams here, but it's a marker of how quickly European regulators are moving from principles to verification.

Netherlands: record complaints, crowdsourced supervision, and conditions for fraud signals

The Dutch DPA (Autoriteit Persoonsgegevens) reported 13,500 complaints and tips in 2025, a 75% increase in privacy complaints year over year. The most common grievances:

  1. organisations are not transparent about the data they use.
  2. organisations are ignoring deletion requests. 

At the same time, the AP has been actively crowdsourcing public opinion to shape its algorithm supervision. Nearly 1,500 residents surveyed revealed that 2 in 5 were not aware they have a right to human intervention in automated decisions. The AP has also been running public consultations on the right to explanation in automated decision-making.

The most notable development, however, is the AP’s new advice on how public sector bodies should handle fraud signals. The AP laid out 11 baseline conditions that executive agencies and supervisory authorities must meet before processing personal data from tips and reports of suspected fraud. The conditions read as a GDPR masterclass by requiring: 

  1. a demonstrable legal basis for every processing step. 
  2. immediate deletion of special-category and criminal data received without one.
  3. strict purpose limitation. 
  4. data minimisation.
  5. reliability checks at intake.
  6. reasonable retention periods.
  7. and follow-up that stays proportionate to the seriousness of the suspicion. 

The advice is a direct response to the Fraud Signalling Facility (FSV) scandal, in which unverified fraud signals about a quarter of a million people were stored for years. While it is addressed to the government, it signals how the AP expects any organisation to treat allegations about individuals.

Key takeaway: Any organisation that receives signals, tips, or allegations about individuals must take the following steps.

  1. verify before you act.
  2. document your basis.
  3. delete what you cannot justify.
  4. keep consequences proportionate.

This should apply to risks across public complaints, a whistleblower line, or a screening process.

#3. China finalises network data security risk assessment regime

China issued new data security regulations, solidifying requirements for regular risk assessments and documentation. 

On 18 June, the Cyberspace Administration of China, jointly with the Ministry of Industry and Information Technology and the Ministry of Public Security, published the Measures for Network Data Security Risk Assessment. Beginning 20 August 2026, handlers of “important data” must conduct annual risk assessments, file reports with regulators within 20 working days of completion, and retain them for at least three years. 

Other organisations are encouraged to assess at least once every three years. The assessments must explicitly cover AI-related risks, such as excessive collection and models leaking personal data. Furthermore, the organizations must map data flows into external systems, ensuring another checkpoint for cross-border transfers of employee data.

Additionally, multinational employers must classify HR data to stay compliant. Most HR data will not qualify as important data; but you cannot demonstrate that without completing data mapping and grading. With the effective date just five weeks away, that groundwork should be a priority.

Key takeaway: China is modernizing how organisations should assess and document risks. For HR teams, the best place to start is classifying HR data as the basis of demonstrating compliance.

#4. The EEOC changes course: what this means for disparate impact and screening?

The U.S. Equal Employment Opportunity Commission (EEOC) has undergone significant changes in the last two months, impacting its independence, enforcement framework, and authority.

On June 4, the EEOC approved a new National Enforcement Plan that changes what and how the agency will enforce discrimination claims. The update targets intentional discrimination arising from broad-based policies, including those framed as DEI initiatives, and commits the agency to eliminating the use of disparate impact liability theories. 

Days later, the Department of Justice issued a formal opinion concluding that the EEOC’s disparate impact guidelines, including those underpinning its long-standing position on criminal background checks, are unconstitutional. And on June 29, the Supreme Court’s decision in Trump v. Slaughter ended the EEOC’s independence altogether, confirming the president may remove commissioners without cause.

It would be a mistake to read this as a green light to loosen screening practices. Title VII’s disparate impact provision was codified by Congress and still supports private lawsuits and state and local fair-chance, ban-the-box, and FCRA obligations are untouched. 

Key takeaway: The EEOC's enforcement priorities have shifted, but the underlying legal exposure has not disappeared. Now that agency guidance can shift overnight, employers should anchor screening programs to statute and state law and keep individualised assessment processes intact.

Future-proof global compliance in a changing regulatory environment

As regulators around the world tackle various challenges, one thing remains the same: global compliance increasingly requires evidence and documentation. Whether the FCA asks how firms handle misconduct, the AP sets conditions for acting on fraud signals, or China requires documented risk assessments, employers are now expected to provide documented evidence of legal basis, proportionality, and human judgement behind every consequential decision about a person. The organisations that thrive in this environment are the ones that can show their work.

This is where Fama comes in. Organisations need to balance effective risk mitigation, privacy-first practices, and compliance. Fama’s social media screening solutions surface relevant behaviour risks while respecting individual privacy and evolving regulatory standards. With the FCA deadline weeks away and data protection authorities raising expectations worldwide, now is the time to adopt a compliant, defensible, and transparent screening process. It's good practice, and a competitive advantage.

Learn more about Fama's compliant social media screening, request a demo.

Get the Newsletter

Recent Blog Posts

Fama in the News

No items found.