High
Amendment
Signed
Delaware · Sep 3, 2026 · effective Jan 1, 2027
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Governor Meyer signed HB 380 on September 2, amending the Delaware Personal Data Privacy Act. The amendment expands the definition of sensitive data, lowers applicability thresholds, adds new contractual and due‑diligence requirements for…
CFPB · Fair Credit Reporting Act
High
Enforcement
Decided
Ireland · Sep 3, 2026 · effective Aug 28, 2026
Data Protection Commission issues €645,000 fine and compliance orders against HSE
The Irish Data Protection Commission issued a final decision on 28 August 2026 concerning the Health Service Executive's handling of paper medical records. The DPC found physical security and integrity failures at external storage…
Data Protection Commission · General Data Protection Regulation
High
New law
Signed
New Jersey · Aug 12, 2026 · effective Sep 1, 2027
New Jersey enacts Age-Appropriate Design Code (A4015) signed by Governor Sherrill
On August 11, Governor Sherrill signed A4015, the New Jersey Age-Appropriate Design Code (NJAADC). The law, effective September 1, 2027, imposes safety defaults, bans dark patterns, and creates a private right of action. It applies to…
New Jersey Attorney General · Connecticut Data Privacy Act
High
Fine
In effect
European Union · Jul 29, 2024
European data protection authorities fined Meta, Spotify, Criteo and others in 2023 for GDPR violations
In 2023, the Irish DPC ordered Meta to pay €390 million and later €1.2 billion, the Swedish DPA fined Spotify €58 million SEK, and the French CNIL fined Criteo €40 million for breaches of consent and data‑subject rights under EU law.
EDPB · General Data Protection Regulation
High
Fine
In effect
Ireland · May 24, 2024 · effective Aug 25, 2026
Irish Data Protection Commission fines HSE €645,000 for GDPR breaches over paper record storage
The Data Protection Commission (DPC) issued a final decision on 25 August 2026, fining the Health Service Executive (HSE) €645,000 for multiple GDPR infringements related to the storage and security of paper medical records. The DPC also…
Data Protection Commission (Ireland) · General Data Protection Regulation
High
Penalty
Published
European Union · Aug 23, 2023
EU data protection board draft decision imposes €390 million fine on Meta for forced consent
In December 2022, the European Data Protection Board (EDPB) published a draft decision in the “forced consent” case against Meta, finding the company's practices violated the GDPR. The decision resulted in a €390 million fine. The case…
European Data Protection Board · General Data Protection Regulation
High
Data protection authority action
Filed
Spain · Jul 27, 2023
noyb files complaint with Spanish DPA over Ryanair’s facial‑recognition verification for travel‑agent bookings
noyb lodged a complaint with Spain's Data Protection Authority (AEPD) alleging that Ryanair forces customers who book via online travel agents to undergo a facial‑recognition verification process. The complaint argues that Ryanair lacks a…
Spanish Data Protection Authority (AEPD) · General Data Protection Regulation
High
Fine
In effect
Greece · Jul 13, 2022
Greek DPA fines Clearview AI €20 million and bans biometric processing
The Greek Data Protection Authority imposed a €20 million fine on Clearview AI and prohibited the company from processing biometric data of individuals in Greece. Clearview must delete all existing facial‑recognition data of Greek citizens…
Greek Data Protection Authority · General Data Protection Regulation
High
Fine
In effect
Italy · Mar 10, 2022
Italian DPA fines Clearview AI €20 million and bans biometric processing
The Italian data protection authority imposed a €20 million fine on Clearview AI and prohibited the company from processing biometric data of individuals in Italy. Clearview must delete all existing biometric data of Italian citizens and…
Italian Data Protection Authority · General Data Protection Regulation
High
Guidance
Published
European Union · Jul 24, 2020 · effective Jul 16, 2020
noyb provides step-by-step guide for EU users to stop US data transfers after Schrems II
The document outlines how data subjects can exercise GDPR rights to learn about and halt transfers of their personal data to the United States following the CJEU Schrems II judgment. It provides sample request letters for information…
European Commission · Standard Contractual Clauses