High
Proposed regulation
Proposed
United States (federal) · Oct 13, 2026 · effective Oct 13, 2026
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
The Federal Housing Finance Agency (FHFA) announced a proposal to rescind the existing System of Records Notice (SORN) FHFA-12, which covers parking program records. The agency will consolidate those records with its transit subsidy…
Federal Housing Finance Agency · Privacy Act of 1974
High
Data protection authority action
Decided
Italy · Oct 9, 2026 · effective Sep 23, 2026
Italian DPA fines IQVIA €7 million for unlawful processing of patients’ health data
The Italian Data Protection Authority imposed an administrative fine of EUR 7,000,000 on IQVIA Solutions Italy S.r.l. for processing health data without a legal basis, inadequate information to patients, and missing DPIA and retention…
Italian Data Protection Authority · General Data Protection Regulation
High
Data protection authority action
Decided
Greece · Oct 8, 2026
Hellenic DPA fines Ministry and EETAA for data breach
The Hellenic Data Protection Authority issued a final decision on 28/07/2026 imposing administrative fines of EUR 200,000 on the Ministry of Social Cohesion and Family Affairs and EUR 150,000 on E.E.T.A.A. S.A. for security deficiencies.…
Hellenic Data Protection Authority · General Data Protection Regulation
High
Enforcement
Published
Spain · Oct 6, 2026 · effective Oct 6, 2026
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The Spanish Data Protection Agency (AEPD) sent preventive warnings (AI‑00170‑2026 and AI‑00171‑2026) to two local councils regarding planned video‑surveillance systems that use automated image analysis with AI. The agency stresses that the…
Agencia Española de Protección de Datos · Reglamento General de Protección de Datos
High
Final regulation
Announced
United States (federal) · Oct 6, 2026 · effective Nov 5, 2026
Treasury exempts new tip intake records from certain Privacy Act provisions
The Department of the Treasury issued a final rule exempting the system of records titled "Treasury .032--Federal Program Waste, Fraud, and Abuse Tip Intake and Referral Records" from specific provisions of the Privacy Act of 1974. The…
Department of the Treasury · Privacy Act of 1974
High
Guidance
In effect
United States (federal) · Oct 2, 2026 · effective Nov 2, 2026
DOI establishes new matching program under Privacy Act of 1974
The U.S. Department of the Interior announced a new matching program that will compare records from 20 DOI programs with the Treasury's Do Not Pay Working System. The program aims to verify prepayment or pre‑award eligibility, prevent…
U.S. Department of the Interior · Privacy Act of 1974
High
Guidance
Published
France · Oct 1, 2026 · effective Oct 1, 2026
CNIL and Cybermalveillance.gouv.fr release guide for individuals on personal data breach response
The French data protection authority (CNIL) and Cybermalveillance.gouv.fr have published a practical support document titled “Violation de données personnelles, que faire en 3 étapes clés ?”. The guide provides a three‑step checklist for…
CNIL
High
Interpretation
Published
European Union · Sep 28, 2026
Commission designates ChatGPT, Reddit, Roblox as VLOPs/VLOSE under the Digital Services Act
The European Commission has designated ChatGPT as a Very Large Online Search Engine and Reddit and Roblox as Very Large Online Platforms under the DSA, citing each service’s reach of at least 45 million EU monthly users. The designated…
European Commission · Digital Services Act
High
Guidance
In effect
United States (federal) · Sep 25, 2026 · effective Oct 26, 2026
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
The Peace Corps Office of Planning and Performance issued a public notice of a new system of records, the Peace Corps Customer Relationship Management (PC 38) system. The system will monitor, track, and analyze interactions with…
Peace Corps Office of Planning and Performance · Privacy Act of 1974
High
Settlement
Settled
New York · Sep 24, 2026
NY AG secures $2.3M settlement and reforms from Labcorp after data breach
The New York Attorney General, together with 43 other state AGs, secured a $2.3 million settlement and mandated security reforms from Laboratory Corporation of America (Labcorp) following a 2019 breach that exposed personal and health data…
New York Attorney General's Office
High
Fine
Decided
France · Sep 11, 2026 · effective Jul 21, 2026
CNIL fines French IT firm EXTIA €300,000 for failing to honor data erasure requests
In 2024 EXTIA received 265 requests for erasure, many of which were not processed or not communicated to the requesters. The CNIL audit found breaches of Articles 12 and 17 GDPR regarding transparency and the right to erasure. The CNIL…
CNIL · General Data Protection Regulation
High
Amendment
Signed
Delaware · Sep 3, 2026 · effective Jan 1, 2027
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Governor Meyer signed HB 380 on September 2, amending the Delaware Personal Data Privacy Act. The amendment expands the definition of sensitive data, lowers applicability thresholds, adds new contractual and due‑diligence requirements for…
CFPB · Fair Credit Reporting Act
High
Enforcement
Decided
Ireland · Sep 3, 2026 · effective Aug 28, 2026
Data Protection Commission issues €645,000 fine and compliance orders against HSE
The Irish Data Protection Commission issued a final decision on 28 August 2026 concerning the Health Service Executive's handling of paper medical records. The DPC found physical security and integrity failures at external storage…
Data Protection Commission · General Data Protection Regulation
High
New law
Signed
New Jersey · Aug 12, 2026 · effective Sep 1, 2027
New Jersey enacts Age-Appropriate Design Code (A4015) signed by Governor Sherrill
On August 11, Governor Sherrill signed A4015, the New Jersey Age-Appropriate Design Code (NJAADC). The law, effective September 1, 2027, imposes safety defaults, bans dark patterns, and creates a private right of action. It applies to…
New Jersey Attorney General · Connecticut Data Privacy Act