The biggest email and privacy story of the month is a Gmail policy change, not a law. Google’s Verified Sender Program opens on 8 September 2026 and lets approved political committees skip the spam filter. Around it: a 825 million euro GDPR fine for Uber, an FTC move on personalised pricing, and California switching on data broker deletion.
Key takeaways
- Google’s Gmail Verified Sender Program launches on 8 September 2026 for qualifying candidates, parties and PACs, with a spam complaint ceiling of 0.3% over 14 days.
- The Dutch data protection authority fined Uber 825 million euros on 21 August 2026 over automated driver account suspensions, the second largest GDPR penalty ever issued.
- The FTC published a draft enforcement policy statement on personalised pricing on 19 August 2026 and extended the comment window to 18 September, signalling that undisclosed data-driven pricing can be a deceptive practice.
- California data brokers have had to process deletion requests through DROP since 1 August 2026, and CalPrivacy passed half a million consumer sign-ups on 25 August.
- The FTC finalised orders totalling 930,000 dollars on 27 August 2026 against Cox Media Group and two partners over the “Active Listening” ad targeting claims.
- India’s Cabinet Secretary put every central ministry, state and union territory on a time-bound DPDP implementation plan in a letter dated 20 August 2026, and MeitY has ruled out an extension for startups.
- Self-hosted email fell from 44.6% of the top million domains in 2016 to 22.4% in 2026, with Google Workspace and Microsoft 365 now handling 38.6% between them.
Gmail opens a lane for political senders
18 August 2026 · Source: The New York Times
What happened. Google confirmed a Gmail Verified Sender Program that lets qualifying candidates, political parties, PACs and other political committees have their mail delivered outside the normal spam filter. It starts on 8 September 2026, ahead of the US midterms. Entry is conditional: a verified sending domain, authentication and security standards, and a spam complaint rate held under 0.3% measured over 14 days. Break the threshold and you are out. Recipients keep every control they had, so they can still report spam, block the sender or unsubscribe.
Why it matters. Two things here should interest a commercial email team, and neither is the politics. First, Google has now put a public number on what “too many complaints” means in a programme it runs itself. 0.3% over a rolling fortnight is stricter than the 0.3% ceiling most senders treat as a soft warning line, because here it is a removal trigger. Second, this is a reminder that Gmail’s filtering is a policy product as much as a machine learning one, and policy can move.
What to do. Pull your Google Postmaster Tools complaint rate for the last 30 days and look at the worst single day, not the average. If any segment is flirting with 0.3%, cut it out of the send now rather than in November when your holiday volume triples. Our email and SMS marketing guide covers the full sender reputation checklist, including one-click unsubscribe and DMARC alignment.
Two companies now run most business email
26 August 2026 · Source: The Register
What happened. Artem Berezin, who works at the business email firm Live Direct Marketing, analysed MX, SPF and DMARC records for the top one million domains using daily DNS snapshots from the OpenINTEL project. Self-hosted mail dropped from 44.6% of those domains in 2016 to 22.4% in 2026. Google Workspace is now on 21.8% and Microsoft 365 on 16.8%. Berezin told The Register the decline is still running at roughly half a percentage point every 30 days.
Why it matters. Deliverability advice keeps getting narrower for a reason. If Gmail and Outlook decide where nearly four in ten business inboxes sit, their sender rules are not one input among many. They are the rules. Testing against a spread of exotic providers is a poor use of an hour.
What to do. Split your deliverability reporting by receiving domain and treat Google and Microsoft as two separate programmes with separate warm-up curves and separate complaint budgets.
Uber’s 825 million euro GDPR fine
21 August 2026 · Source: TechCrunch
What happened. The Dutch Autoriteit Persoonsgegevens fined Uber 825 million euros, about 966 million dollars, over automated suspension of driver accounts without adequate human involvement. NL Times reported the decision on the day; CPO Magazine called it the second largest GDPR penalty on record. The case turned on decisions made by algorithm that carried real consequences for individuals.
Why it matters. Most marketing teams read GDPR enforcement as a cookie banner problem. This one is not. It is about automated decisions, and marketing stacks are full of them: propensity scores that suppress a customer from an offer, fraud rules that block an account, dynamic pricing that quietly quotes one person more than another. And the fine size shows regulators are willing to price that harm high.
If a model in your stack can deny someone a price, a refund, a credit line or an account, write down who reviews the appeal and how fast. That record is the thing regulators ask for first.
What to do. Ask your analytics and lifecycle teams for a list of every automated rule with a consequence attached, then mark which ones a human can override. Our marketing analytics guide covers where these decisions usually hide.
The FTC draws a line on personalised pricing
19 August 2026 · Source: FTC
What happened. The Commission voted 2-0 to publish a draft enforcement policy statement on personalised pricing for public comment. The core position: collecting or using personal data to set an individual’s price, without telling them, can be an unfair or deceptive practice under the FTC Act. Showing a price as if it were the same for everyone, when it is not, is the specific deception it names. Comments run to 18 September 2026 under docket FTC-2026-1057, after the agency extended the window on 3 September.
“When consumers see a listed price, they expect it to be the same price that everyone else sees.” FTC Chairman Andrew Ferguson, 19 August 2026.
Why it matters. This is the one item on the list worth putting in front of your commercial team this week. Personalised offers, loyalty-tier pricing and AI-set discounts have spread quietly through retail and travel. New Jersey already banned surveillance pricing in grocery, and California moved on it in early September. The FTC statement gives that patchwork a federal spine.
What to do. Draw the line between a promotion anyone can claim and a price computed from an individual’s data. The first is fine. The second needs disclosure. Our ecommerce marketing guide covers where dynamic pricing sits in the wider retail stack.
“Active Listening” ends in a 930,000 dollar settlement
27 August 2026 · Source: FTC
What happened. The FTC finalised orders against CMG Media Corporation (Cox Media Group), MindSift LLC and 1010 Digital Works LLC over an AI ad product marketed as able to target ads using conversations picked up by consumers’ smart devices. The agency found the pitch was false: the targeting was not built on voice data and consumers had not opted in. Cox pays 880,000 dollars, the two smaller firms 25,000 dollars each, 930,000 dollars in total for redress to CMG customers. The orders bar all three from misrepresenting what an ad product collects, whether consumers consented, and how geographic targeting works.
Why it matters. The FTC made a neat point in passing: if the product had actually worked as advertised, that would have been illegal too. So the vendor was either lying or breaking the law. Anyone buying “AI-powered signal” from a data supplier should notice that both branches lead somewhere bad.
What to do. Ask every audience vendor for the actual source of a segment, in writing, and refuse anything that answers with a category name instead of a collection method. The same discipline applies to AI ad tools generally, which we cover in the AI in digital marketing guide.
California’s deletion platform starts biting
13 August 2026 · Source: Office of the Governor of California
What happened. DROP, the Delete Request and Opt-out Platform built under the Delete Act, opened to consumers on 1 January 2026. From 1 August 2026 registered data brokers must actually process the deletion requests it sends them. CalPrivacy then ran an enforcement run: a first-ever action under both the CCPA and the Delete Act announced on 11 August, a second within the same week, a decision against LocateSmarter LLC for demanding Social Security digits before honouring an opt-out, another action against a Virginia broker on 1 September, and Enforcement Advisory 2026-01 on inaccurate registration data on 3 September. On 25 August the agency said half a million Californians had signed up.
Why it matters. Half a million people using a single button to delete themselves from every registered broker is a structural hit to third-party audience quality in the largest US state, and the number is growing monthly. If your prospecting depends on purchased lists, your addressable pool in California is shrinking while you read this.
What to do. Get your data suppliers to state, on paper, that they are registered with CalPrivacy and processing DROP requests. Then shift budget towards first-party collection. The content marketing guide has the tools-and-newsletter approach that tends to work best for this.
Delaware, New Jersey and the state law wave
2 September 2026 · Source: EPIC
What happened. Governor Matt Meyer signed two bills expanding Delaware’s privacy protections, including one restricting the sale of sensitive personal data. EPIC and Consumer Reports both welcomed it, and MediaPost covered the advertising angle on 3 September. It follows New Jersey’s surveillance pricing ban, signed in late July, and a California session that closed in early September with further AI and privacy measures.
| Development | Date | What changes for marketers |
|---|---|---|
| California DROP deletion obligation | 1 August 2026 | Registered brokers must process deletion requests submitted through one state platform |
| MeitY confirms no DPDP extension | 14 August 2026 | Indian startups get no additional grace on consent and notice obligations |
| FTC personalised pricing statement published | 19 August 2026 | Undisclosed data-driven pricing framed as potentially deceptive |
| Uber fined 825 million euros | 21 August 2026 | Automated decisions with consequences need genuine human review |
| ANPD fines ByteDance | 25 August 2026 | Guest and logged-out sessions count as personal data processing |
| Cox Media Group orders finalised | 27 August 2026 | Audience vendors must be able to prove how a segment was built |
| Delaware sensitive data law signed | 2 September 2026 | Another state limit on selling sensitive categories |
| Gmail Verified Sender Program opens | 8 September 2026 | 0.3% complaint ceiling stated publicly by Google |
| FTC comment deadline | 18 September 2026 | Last chance to file a position on personalised pricing |
India puts the DPDP Act on a clock
20 August 2026 · Source: KNN India
What happened. Cabinet Secretary T V Somanathan wrote to central ministries, states and union territories on 20 August 2026 directing them to prepare time-bound DPDP implementation plans, nominate nodal officers to coordinate with MeitY, build data inventories and apply privacy-by-design in new digital services. Reported on 29 August, it follows MeitY Secretary S. Krishnan telling Fortune India on 14 August that there will be no extension for startups. Separately, WhatsApp began testing age confirmation prompts for Indian users in early August, which Deccan Herald tied directly to DPDP compliance.
Why it matters. India is the market where most global brands have the loosest consent hygiene, usually because lists were built before any of this existed. Verifiable parental consent for under-18s is the part that catches consumer brands out, and WhatsApp asking for dates of birth is a preview of what your own sign-up forms will need.
What to do. Audit any Indian list segment older than two years for a consent record you could actually produce. If there is none, run a re-permission campaign now rather than defending an inherited list later.
Brazil fines ByteDance over teenagers’ data
25 August 2026 · Source: The Next Web
What happened. Brazil’s data protection authority, the ANPD, fined ByteDance roughly 29.8 million dollars over the unlawful processing of data belonging to about eight million minors, including data collected during guest browsing sessions where users were not logged in. The Economic Times reported the same figure.
Why it matters. The guest-session detail is the transferable lesson. Plenty of brands assume that an anonymous visitor is outside the scope of consent rules because there is no account attached. Regulators keep disagreeing. If you fire tracking on logged-out traffic and any meaningful slice of that traffic is under 18, you have the same exposure in a smaller form.
What to do. Check whether your consent management platform loads before, not after, your analytics and advertising tags on logged-out pages. Related platform news sits in our social media news for September 2026.
Age checks get a privacy-preserving building block
2 September 2026 · Source: Google
What happened. Google donated its Longfellow zero-knowledge proof library to the Post-Quantum Cryptography Alliance under Linux Foundation Europe. Google’s framing is that the technology lets someone prove a fact about themselves, being over 18 for example, without handing over anything else, and that vendor-neutral stewardship makes it auditable and adoptable as a quantum-safe standard for digital identity.
Why it matters. Age assurance rules are arriving in the EU and several US states at once, and the default implementation so far has been “upload your ID to a third party”, which creates a new database of sensitive documents. A shared cryptographic alternative is the difference between an age gate that adds risk and one that does not. This will not land in your consent tool this quarter, but it sets the direction.
What did not happen: cookies and Privacy Sandbox
Nothing. There was no new Chrome third-party cookie decision, no Privacy Sandbox announcement and no fresh deprecation timeline in August or early September 2026. The Privacy Sandbox site still points to the existing notice that some technologies are being phased out. Chrome 152 shipped on 26 August with security fixes and a CPU performance API, nothing that touches measurement.
Silence on cookies is not an all-clear. The pressure has moved from browser deprecation to regulators, state statutes and platform policy, which is harder to plan around because it arrives without a roadmap. Ad tech developments are covered in our programmatic and ad tech news for September 2026.
What to do in the next fortnight
Four jobs, in the order I would run them. Pull Postmaster Tools complaint rates by segment and cut anything approaching 0.3% before Q4 volume arrives. Write down every automated decision in your marketing stack that can deny a customer something, and name the human who reviews it. Get written confirmation from each audience vendor that they are registered in California and processing DROP deletions. And if you sell into the US with any form of individualised pricing, decide before 18 September whether you are disclosing it or dropping it.
The wider week in digital marketing is summarised in our weekly news roundup for the week of 7 September 2026.
Frequently asked questions
What is the Gmail Verified Sender Program?
How much was Uber fined under GDPR in 2026?
Is personalised pricing legal in the US?
What is California’s DROP and does it affect marketers?
When do Indian businesses have to comply with the DPDP rules?
Are third-party cookies going away in Chrome in 2026?
What was the FTC Active Listening case about?
Sources
- The New York Times: Google Just Made It Easier for Campaigns to Send You Fund-Raising Emails (18 August 2026)
- Android Authority: Gmail Verified Sender Program for political campaigns (18 August 2026)
- The Register: Self-hosted email is in steep decline, Microsoft and Google are taking over (26 August 2026)
- TechCrunch: Uber faces fine of nearly $1B over automated driver suspensions (23 August 2026)
- NL Times: Dutch regulator fines Uber 825 mil euros over algorithmic account deactivation (21 August 2026)
- CPO Magazine: Uber Draws Second-Largest Ever GDPR Fine Over Automated Driver Suspensions (28 August 2026)
- FTC: FTC Seeks Comment on Enforcement Policy Statement Regarding Personalized Pricing (19 August 2026)
- FTC: FTC Extends Public Comment on Proposed Policy Statement Regarding Personalized Pricing (3 September 2026)
- FTC: FTC Finalizes Orders with Cox Media Group, Two Other Firms Over “Active Listening” (27 August 2026)
- Office of the Governor of California: California takes historic action against data brokers (13 August 2026)
- CalPrivacy newsroom: DROP sign-ups and data broker enforcement actions (August to September 2026)
- EPIC: EPIC Commends Delaware for Strengthening Privacy Law (2 September 2026)
- Consumer Reports: Consumer Reports applauds Delaware Governor for signing key privacy bill into law (2 September 2026)
- MediaPost: Delaware Governor Signs Law Restricting Sale Of Sensitive Data (3 September 2026)
- KNN India: Centre Directs Ministries, States To Prepare Time-Bound Plans For DPDP Act Compliance (29 August 2026)
- Fortune India: DPDP Act implementation, no extension as startups face compliance deadline (14 August 2026)
- Deccan Herald: WhatsApp begins age verification in India to comply with DPDP Act (7 August 2026)
- The Next Web: Brazil fines TikTok’s owner over children’s data, including guest sessions (25 August 2026)
- The Economic Times: Brazil fines TikTok owner ByteDance for unlawful processing of teenagers’ data (25 August 2026)
- Google: Our latest Linux Foundation Europe donation will build a more private digital world (2 September 2026)
- Google: Privacy Sandbox (accessed 7 September 2026)
Last researched and updated: 7 September 2026.


Pingback: Ad Tech News September 2026: Google Remedies
Pingback: Social Media News September 2026: Meta, X, YouTube