Home/ Law 101/ 29 August 2026
AI Digest
10 Sources Updated 13d ago Morning Edition 4 min read

Your Data, Their Rules: Read What You Signed

| Law, Business & Power Correspondent --- $18 billion.

AI-generated digest · 10 verified sources · Updated twice daily Add as preferred source
What You Missed Today
Dify
Dify
The AI workflow builder that replaces your development backlog. Dify.
Learn more →
Gamma
Gamma
Gamma turns a prompt into a presentation in 30 seconds. No more PowerPoint.
Learn more →
Trainual
Trainual
The SOP tool that 10,000 SMEs use to stop losing knowledge when staff leave.
Learn more →
Mercury
Mercury
Every Malta founder with a US LLC needs a US bank account. Mercury is the answer.
Learn more →
Remotive
Remotive
The remote job board that curates instead of aggregates. Tech, marketing, design.
Learn more →

By Harvey Specter Jr. | Law, Business & Power Correspondent

---

$18 billion. Write that number out longhand and it stops looking like a settlement — it starts looking like an admission. Meta just agreed to pay that figure to resolve child safety lawsuits across the United States, and buried inside the deal are two provisions that most people will miss because they're too busy reacting to the number. First: Meta must restrict how long young users can scroll. Second: those users — and their parents — cannot simply toggle off the safety settings Meta installs. The platform built the rules. You don't get to opt out of them once the regulator is watching.

This is not a privacy settlement. This is a structural consent order wearing a privacy settlement's clothes. And if you understand that distinction, you understand exactly what is about to change — not just in California, not just in America, but inside every boardroom from Brussels to Valletta where a company is still treating user data like an unlocked cabinet.

Here is what the law actually says, not in America but in the EU, which is where most of you reading this operate or consume. The General Data Protection Regulation — Regulation (EU) 2016/679 — does not permit you to bury consent inside terms that a reasonable person cannot understand. Article 7 is explicit: consent must be freely given, specific, informed, and unambiguous. Article 8 tightens it further for children under 16: parental consent is not optional, it is mandatory, and the burden of proof sits entirely with the data controller. Not with the parent. Not with the child. With the company that built the product.

Meta spent years designing systems that made it difficult to say no and invisible to say yes. The $18 billion is not a fine for collecting data. It is the price of designing systems that knew exactly what they were doing and kept doing it. The distinction matters because it tells you what the next enforcement wave looks like. Regulators are no longer interested in whether you had a privacy policy. They are interested in whether the architecture of your product was designed to circumvent the protections your privacy policy claimed to provide.

I have seen this pattern before in a different context — not in tech, but in contracts. A landlord presents a lease with seventeen clauses. Clause four gives with one hand. Clause fourteen takes with the other. The tenant signs because nobody reads clause fourteen. The landlord knows nobody reads clause fourteen. That knowledge, that intentional design around the gap between what people read and what they signed, is the same structure Meta built at planetary scale. And that structure, in EU law, is not protected by the signature. It is challenged by it.

The Oura sleep-tracking lawsuit running in parallel asks a quieter but equally sharp question: when a company markets AI-powered precision, what does it owe you when the precision fails? Under EU consumer protection law — specifically the Unfair Commercial Practices Directive 2005/29/EC — a misleading representation about a product's technical capability is an unfair practice regardless of whether the company intended to mislead. Intent is irrelevant. The gap between what was marketed and what was delivered is the entire case.

This matters for Malta specifically because we sit inside the EU enforcement architecture. The Malta Competition and Consumer Affairs Authority has powers under that Directive. Any company selling a wearable, an app, or an AI-powered service in Malta and marketing it with precision claims it cannot substantiate is not operating in a legal grey area. It is operating in a lit room with the curtains open.

The move the other side always makes in these cases is to point to the terms of service. They will show you clause nineteen, which says the device provides "estimated" data and makes "no warranty of accuracy." They will argue you consented to the limitation. Here is what that argument misses: if your marketing says "precise sleep tracking" and your terms say "estimated data," you have a contradiction that no consumer could reasonably resolve. EU law does not require you to read the footnotes in order to be protected from the headline.

The practical takeaway is one sentence worth saving: if you run a business that collects user data, markets AI-powered features, or targets anyone under 16 in Malta or anywhere in the EU, audit your consent flows against Article 7 and Article 8 of the GDPR before someone else does it for you — because the company that audits itself writes the memo; the company that doesn't writes

Harvey Specter Jr.
Harvey Specter Jr.
Law, Business & Power Correspondent
Harvey Specter Jr. has been in rooms where deals are made and rooms where lives fall apart — sometimes the same room. He found law the hard way. He never lost a case he cared about. He has two children he would burn everything down for, and he has. Twice.
View all articles →
Ilhan Irem Yuce
Edited by Ilhan Irem Yuce · Chief Editor, News Beast