Logo

Your trusted compliance partner

Logo

Your trusted compliance partner

Logo

Your trusted compliance partner

Back To Home

Research Team (Tsaaro)

New Mexico Seeks Up to $40 Billion in Penalties Against Meta Over Privacy Violations

The State of New Mexico has asked a US court to order Meta Platforms to pay between $35 billion and $40 billion following a jury verdict that found the company had misled Facebook users about the privacy of their data. The case arose from the Cambridge Analytica controversy, in which personal data of up to 87 million Facebook users was obtained through a third-party application without their consent.  

The jury found 26 of 29 statements made by Meta to be misleading, amounting to more than 43 million alleged violations of New Mexico consumer protection law. Although state law permits penalties of up to $5,000 per violation, New Mexico has proposed a lower aggregate amount. Meta has opposed the request, arguing that the proposed penalty is excessive and that users did not suffer demonstrable harm. 

The case could become one of the largest privacy-related financial penalties sought against a technology company in the United States. The final amount remains subject to the court’s determination. 

Source: New Mexico Seeks Up to $40 Billion in Penalties Against Meta Over Privacy Violations 

News of the Week 

1. EDPB Issues Guidelines on Web Scraping for Generative AI 

The European Data Protection Board (EDPB) has adopted Guidelines 03/2026 on web scraping in the context of generative AI, addressing the GDPR implications of large-scale automated extraction of information from publicly accessible websites. The guidelines clarify that where web scraping involves personal data, activities such as collection, storage, organisation and retrieval fall within the scope of the GDPR.  

The EDPB highlights purpose limitation, transparency, accuracy and data minimisation as key considerations. It also provides guidance on the use of legitimate interests as a legal basis for AI training and reiterates that scraping special-category data generally requires both an Article 6 legal basis and an Article 9 exception. The guidelines are currently open for public consultation until 30 October 2026, making them particularly relevant for organisations developing or training AI systems using web-derived datasets. 

Source: EPDB Issues Guidelines on Web Scraping for Generative AI 

2. UK’s ICO Functions Transferred to the New Information Commission 

Image credits 

The United Kingdom has formally replaced the Information Commissioner’s Office (ICO) with a new Information Commission, marking a significant change to the institutional structure of the country’s data protection regulator. The transition follows reforms introduced under the Data (Use and Access) Act 2025 and took effect on 30 September 2026. 

The new body assumes the ICO’s existing statutory functions relating to data protection and information rights. However, its governance structure has been altered, with the Information Commission operating through a corporate framework overseen by an Information Commission Board, replacing the previous corporation-sole model. 

The reform represents an institutional shift rather than a wholesale change to the UK's underlying data protection obligations. Organisations operating in the UK will therefore continue to face the existing compliance framework while engaging with the newly constituted regulator. 

Source: UK’s ICO Functions Transferred to the New Information Commission 

3. Governments Examine Restrictions on Smart Glasses Over Privacy Concerns 

Camera-equipped smart glasses are facing growing regulatory scrutiny as governments and courts consider whether existing privacy safeguards adequately address the possibility of people being recorded without their knowledge. Australia is examining restrictions on their use in government workplaces, while courts in England and Wales have prohibited their use in court premises. 

Norway is considering a temporary ban on AI-enabled smart glasses in locations including parks, museums, healthcare facilities and public events. In the United States, New York's court system has prohibited camera- and microphone-equipped smart glasses across court facilities. 

The European Data Protection Board has also commissioned research into the “social acceptability” of smart glasses. The developments highlight emerging challenges around transparency, consent and covert recording as cameras, microphones and AI capabilities become increasingly integrated into wearable devices. 

Source: Governments Examine Restrictions on Smart Glasses Over Privacy Concerns 

4. US Closes Airline Data Privacy Review Without Penalties 

The US Department of Transportation has concluded its review of the data privacy practices of the country's ten largest airlines without imposing penalties. The review examined how airlines collect and use passenger information and whether their practices complied with applicable legal requirements and published privacy policies.  

The Department found no violations warranting enforcement action. Nevertheless, the conclusion of the review keeps attention on the privacy implications of extensive passenger-data collection within the aviation sector, particularly where information is used for commercial purposes. 

The Department has continued to emphasise that airlines must safeguard passenger information, adhere to their stated privacy practices and comply with applicable consumer protection requirements. The development illustrates the increasing regulatory scrutiny of how organisations use personal information beyond its immediate operational purpose. 

Source: US Closes Airline Data Privacy Review Without Penalties 

Want to stay ahead? 

Reach out to the experts at Tsaaro today. 


  

We Help You to Grow Your Business Faster & Easier

Our mission is to redefine Digital Trust — helping businesses stay compliant and secure across data privacy, cybersecurity, AI governance, and risk. With 150+ clients across 6 global regions and 50+ regulations covered, we've partnered with leading brands like Airtel, Adani, Titan, Godrej, Booking.com, Paytm, CRED, Nykaa, IKEA, and Flipkart & more.


  • Specialist Talent, On Demand – Privacy, Cyber, AI & GRC experts via staff augmentation, expert pods, and SME-on-demand.

  • Leadership as a Service – Fractional DPO, CISO, and AI Officer leadership, without the cost of a full-time hire.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Responsible AI Governance – Build and run AI programmes aligned to ISO/IEC 42001, the EU AI Act, and NIST AI RMF.

  • Cybersecurity Expertise – Protect your business from evolving threats with vCISO-led strategy and assessments.

  • Global Standards & Regulations – Stay ready for GDPR, DPDPA, PDPL, HIPAA, and ISO frameworks across markets.

  • Flexible & Cost-Effective – The right expertise at the right time, without permanent-hiring overhead.

  • Trusted Advisory – Led by certified privacy and security professionals.

We Help You to Grow Your Business Faster & Easier

Our mission is to redefine Digital Trust — helping businesses stay compliant and secure across data privacy, cybersecurity, AI governance, and risk. With 150+ clients across 6 global regions and 50+ regulations covered, we've partnered with leading brands like Airtel, Adani, Titan, Godrej, Booking.com, Paytm, CRED, Nykaa, IKEA, and Flipkart & more.


  • Specialist Talent, On Demand – Privacy, Cyber, AI & GRC experts via staff augmentation, expert pods, and SME-on-demand.

  • Leadership as a Service – Fractional DPO, CISO, and AI Officer leadership, without the cost of a full-time hire.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Responsible AI Governance – Build and run AI programmes aligned to ISO/IEC 42001, the EU AI Act, and NIST AI RMF.

  • Cybersecurity Expertise – Protect your business from evolving threats with vCISO-led strategy and assessments.

  • Global Standards & Regulations – Stay ready for GDPR, DPDPA, PDPL, HIPAA, and ISO frameworks across markets.

  • Flexible & Cost-Effective – The right expertise at the right time, without permanent-hiring overhead.

  • Trusted Advisory – Led by certified privacy and security professionals.

We Help You to Grow Your Business Faster & Easier

Our mission is to redefine Digital Trust — helping businesses stay compliant and secure across data privacy, cybersecurity, AI governance, and risk. With 150+ clients across 6 global regions and 50+ regulations covered, we've partnered with leading brands like Airtel, Adani, Titan, Godrej, Booking.com, Paytm, CRED, Nykaa, IKEA, and Flipkart & more.


  • Specialist Talent, On Demand – Privacy, Cyber, AI & GRC experts via staff augmentation, expert pods, and SME-on-demand.

  • Leadership as a Service – Fractional DPO, CISO, and AI Officer leadership, without the cost of a full-time hire.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Responsible AI Governance – Build and run AI programmes aligned to ISO/IEC 42001, the EU AI Act, and NIST AI RMF.

  • Cybersecurity Expertise – Protect your business from evolving threats with vCISO-led strategy and assessments.

  • Global Standards & Regulations – Stay ready for GDPR, DPDPA, PDPL, HIPAA, and ISO frameworks across markets.

  • Flexible & Cost-Effective – The right expertise at the right time, without permanent-hiring overhead.

  • Trusted Advisory – Led by certified privacy and security professionals.