Global Compliance Updates August/ September 2026: Adverse Media Screenings, FCA, Dutch GDPR, & Resume Sharing with China

Enforcement, fines, and consequences: compliance stopped being theoretical

For months, we’ve tracked global compliance regulations on the horizon. Starting in August, the horizon arrived. 

The UK is enhancing fraud and non-financial misconduct mitigation protocols for regulated organisations, the Dutch DPA handed down the second-largest GDPR fine in history, and regulators from Brussels to Beijing to Trenton spent the summer converting principles into penalties. 

In this edition, you’ll walk through critical compliance updates every global employer should know, how regulators are imposing major consequences, and what it takes to stay out of their way. 

6 new compliance developments

#1. Adverse media screening becomes a 2026 compliance must in the UK

A wave of regulatory reforms in the UK including the Economic Crime and Corporate Transparency Act (ECCTA), updated National Risk Assessments, and upcoming "Failure to Prevent Fraud" offenses is forcing regulated firms to treat adverse media screening as a core compliance requirement rather than an optional check.

At the same time, AI-driven financial crime has rapidly escalated. Sophisticated threats such as synthetic identity fraud, deepfakes, and automated system exploits mean traditional identity checks are no longer sufficient to mitigate risk.

To meet heightened expectations, adverse media monitoring must look well beyond traditional press coverage. Comprehensive screening requires searching:

  • Mainstream print, online, and broadcast news
  • Social platforms (X, TikTok, LinkedIn) and public forums (Reddit, Quora)
  • Regulatory, sanctions, and law enforcement databases (such as NCA and NECC digital identity abuse reports)

While manual screening may seem like a viable option, the consensus is that it’s impossible to screen hundreds of thousands of multi-language sources by hand. As a result, employers are encouraged to leverage compliant third party screening solutions alongside ongoing sanctions and PEP monitoring.

Key takeaway
Bad actors are leveraging technology advancements to find new ways to cause harm. Regulators are keeping up by enhancing screening protocols to surface risks where they may appear early and reduce risk blind spots. Regulated organizations must adopt adverse media screening alongside AML and KYC workflows to maintain an audit-defensible compliance posture against modern financial crime.

#2. The FCA now requires proactive screening for non-financial misconduct 

Specific to Financial Services and FCA-regulated firms in the UK, Policy Statement PS25/23 is now in effect. That means ~37,000 firms are required to proactively mitigate both financial and NFM. Specifically, the Code of Conduct (COCON) is updated so behaviours such as bullying, harassment, and violence can now impact Fitness and Propriety.

One common misconception is monitoring only begins once an employee has done something wrong. In fact, this is exactly what regulators are trying to prevent.

The FCA guidance expressly states that firms do not need to proactively monitor employee social media accounts. However, it’s also clear that employee social media activity does impact Fitness and Propriety when the behavior indicates a material risk of breaching regulatory standards. That said, waiting for an incident of violence, threats, or harassment to occur before taking action means you did not take the regulatory precautions you were supposed to.

Key takeaway
The defensible position is now a documented, risk-based approach, starting with:

  • Targeted reviews of public information for senior manager, certification, and high-risk roles
  • Defined triggers such as annual assessments, promotions, or role changes, with a lawful basis, minimised scope, and human review on record.
  • Documented, proactive screening measures, findings, and consequences. 

Get insights on FCA-compliant social media screening and audit documentation templates in our latest legal ebook by Seyfarth Shaw’s Yana Komsitsky, and our Proof of Compliance Template.

#3. Europe’s enforcement engine shifts into gear, delivers a €825 million fine to Uber

The Dutch DPA fined Uber €825 million (roughly $966 million) for automatically deactivating and suspending driver accounts without sufficient human oversight, breaching GDPR’s Article 22 rules on automated decision-making. It’s the second-largest GDPR fine ever issued and Uber’s third from the Dutch regulator in three years. Uber says it will appeal, but the odds are not in their favour.

This is noteworthy because it reveals a pattern: European audits, oversight, and penalties are accelerating, and automated decisions about individuals are the priority target. The EDPB adopted its Guidelines 03/2026 on web scraping in July, confirming that publicly available data still requires: 

  • A lawful basis 
  • Case-by-case legitimate interest assessments 
  • Strict limits around special category data 

While the guidelines are scoped to generative AI training, the principles map directly onto any AI-powered screening of EU candidates and are expected to shape how DPAs assess those programmes.

This is not isolated to Europe, with two American footnotes rounding out the picture. 

The FTC issued a policy statement on August 7 formally abandoning disparate impact claims, making it harder to identify and resolve unintentional discriminatory policies and actions. Despite federal changes, state law and private Title VII litigation are still in action. 

A week prior on July 29, the FTC, joined by Utah and California, sued telehealth provider Hims & Hers for sharing sensitive health data with ad platforms despite privacy promises. For anyone in healthcare-adjacent screening, this means promises made in a privacy notice are now enforcement material on both sides of the Atlantic.

Key takeaway
If an algorithm makes or shapes consequential decisions about people in your organisation, whether drivers, candidates, or employees, regulators now expect to see the human oversight, documentation, and lawful basis behind it. Failure to do so can lead to yet another Uber-sized fine.

#4. China regulates candidate resumes leaving the country

China is taking steps to limit how employers transfer candidate information overseas. In July, the Cyberspace Administration of China published official Q&A guidance regulating when and how Chinese companies can send job applicants’ resumes to an overseas headquarters or affiliate.

The policy is designed to limit unnecessary foreign data sharing: 

  • Data cannot be transferred to overseas entities that don’t play an active role in the hiring decision.
  • Data can be transferred to foreign entities that do make decisions, applying data minimization limitations on the number of candidates and data fields. 
  • The limited data still also needs to comply with China’s Personal Information Protection Law (PIPL) data transfer regulations with notice, separate consent, and an impact assessment.

The guidance is aimed at intra-group transfers, but the logic reaches further: an offshore screening or background check vendor that plays no part in the hiring decision will struggle to satisfy the same necessity test. 

Key takeaway
For global employers and screening providers, now is the time to review how you process Chinese candidate data. If you route Chinese candidate data through systems or vendors outside the mainland, now is the time to map those flows and assess necessity for each one. Screening programmes that depend on offshore processing need a China-specific answer, whether that is a local partner, local infrastructure, or a redesigned workflow. This is indicative of the larger role China is starting to play in the world’s privacy framework.

#5. Minor protection laws are multiplying across US states

As the Federal government reverses protections, three states took steps forward. New York’s Attorney General released the final rules for the SAFE for Kids Act on July 28, restricting addictive algorithmic feeds and overnight notifications for under-18s, with age assurance standards attached and the law taking effect January 25, 2027. 

Next, New Jersey’s governor signed the Kids Code Act on August 11. Effective September 2027, this law requires default-high privacy settings and limits on engagement-driving features. It also includes a private right of action. 

Similarly, Hawaii signed the AI Disclosure and Safety Act on July 14, and it took effect immediately. This requires AI chatbots to disclose they are not human, with hourly reminders and crisis protocols for minors.

Key takeaway
For companies with consumer platforms, the state-by-state patchwork now demands certified age assurance, design reviews, and AI disclosure audits. This is a pattern worth noting as initial minor protection often sets the bar for how regulators expect platforms to treat everyone’s data.

#6. Reminders about India’s consent managers and Australia’s Tranche 2

Two updates on developments we’ve covered before:

  1. In India, the DPDP’s consent manager registration with the Data Protection Board opens November 13, 2026. The remaining obligations are still on track for May 2027. Organisations processing Indian personal data should be well into their gap assessments.
  2. In Australia, the government has reconfirmed its commitment to Tranche 2 of the Privacy Act reforms, but did not set a date. The package is expected to move Australia closer to GDPR, bringing:
    • a fair and reasonable collection test
    • a right to erasure
    • stronger consent standards
    • and the removal of long-standing exemptions

While Tranche 2 doesn’t have an effective date, the Tranche 1 transparency requirements for automated decision-making take effect December 10, 2026. Tranche 2 could move quickly once a bill lands, and organisations that adopt the GDPR as their global compliance baseline should be set up for success.

Key takeaway
More than ever, organisations must take steps to ensure proactive measures. Assuming the long term status quo will remain is a recipe for risk.

When enforcement speeds up, evidence is everything

This update has two big takeaways; first, regulators now recognise signs of fraud and non-financial misconduct exist online, and that adverse media and social media screenings can proactively mitigate bad actors. 

The second, regulators are quickly showing they mean business. As regulatory effective dates approach, they are not wasting time delivering expensive penalties to enterprises. Uber’s fine, the FCA’s September deadline, and China’s necessity test all point the same way: regulators are no longer asking whether you have a policy. They are asking you to prove how it works, decision by decision, with a human accountable at each step. Employers can no longer hide behind an AI veil.

This is where Fama comes in. 

As organisations look to balance effective risk mitigation, privacy-first practices, and compliance, Fama’s social media screening solutions are designed to surface relevant behaviour risks while respecting individual privacy and evolving global compliance and regulatory standards. With enforcement accelerating on every continent, a compliant, defensible, and documented approach to screening isn’t just good practice, it’s a competitive advantage. 

It’s a design for long term stability and long term success. 

Click here to learn more about Fama today.

Get the Newsletter

Recent Blog Posts

Fama in the News

No items found.