REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: privacy · clear
25 developments
High Proposed regulation Proposed United States (federal) · Oct 13, 2026 · effective Oct 13, 2026
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
The Federal Housing Finance Agency (FHFA) announced a proposal to rescind the existing System of Records Notice (SORN) FHFA-12, which covers parking program records. The agency will consolidate those records with its transit subsidy…
Federal Housing Finance Agency · Privacy Act of 1974
High Data protection authority action Decided Italy · Oct 9, 2026 · effective Sep 23, 2026
Italian DPA fines IQVIA €7 million for unlawful processing of patients’ health data
The Italian Data Protection Authority imposed an administrative fine of EUR 7,000,000 on IQVIA Solutions Italy S.r.l. for processing health data without a legal basis, inadequate information to patients, and missing DPIA and retention…
Italian Data Protection Authority · General Data Protection Regulation
High Fine In effect Italy · Oct 9, 2026 · effective Jul 3, 2026
Italian DPA fines BBVA €5.508 million for ignoring customer objection to direct marketing
The Italian Data Protection Authority issued an administrative fine of €5,508,000 against BBVA's Italian branch for failing to honor a customer's right to object to direct marketing. The violation lasted seven months, during which the…
Italian Data Protection Authority · General Data Protection Regulation
High Data protection authority action Decided Greece · Oct 8, 2026
Hellenic DPA fines Ministry and EETAA for data breach
The Hellenic Data Protection Authority issued a final decision on 28/07/2026 imposing administrative fines of EUR 200,000 on the Ministry of Social Cohesion and Family Affairs and EUR 150,000 on E.E.T.A.A. S.A. for security deficiencies.…
Hellenic Data Protection Authority · General Data Protection Regulation
High Fine Published Netherlands · Oct 8, 2026
Dutch DPA fines Uber €824.99 million for unlawful automated decision‑making
The Autoriteit Persoonsgegevens imposed an administrative fine of €824,990,000 on Uber for violating GDPR Article 22 by automatically deactivating drivers’ accounts and for failing to provide sufficient information under Article 13. The…
Autoriteit Persoonsgegevens · General Data Protection Regulation
High Proposed regulation Proposed United States (federal) · Oct 7, 2026 · effective Nov 6, 2026
Treasury proposes new system of records for federal student aid data
The Department of the Treasury proposes to establish a new system of records titled “Department of the Treasury .033--Federal Student Aid Portfolio Research, Analysis, Oversight, Reporting, and Compliance Records.” The system would allow…
Department of the Treasury · Privacy Act of 1974
High Proposed regulation Proposed United States (federal) · Oct 6, 2026 · effective Nov 16, 2026
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
The National Archives and Records Administration (NARA) proposes to revise its System of Records NARA 44, updating the system manager and location. The revision would expand the record type to include reasonable accommodation requests…
National Archives and Records Administration · Privacy Act of 1974
High Final regulation Announced United States (federal) · Oct 6, 2026 · effective Nov 5, 2026
Treasury exempts new tip intake records from certain Privacy Act provisions
The Department of the Treasury issued a final rule exempting the system of records titled "Treasury .032--Federal Program Waste, Fraud, and Abuse Tip Intake and Referral Records" from specific provisions of the Privacy Act of 1974. The…
Department of the Treasury · Privacy Act of 1974
High Guidance In effect United States (federal) · Oct 2, 2026 · effective Nov 2, 2026
DOI establishes new matching program under Privacy Act of 1974
The U.S. Department of the Interior announced a new matching program that will compare records from 20 DOI programs with the Treasury's Do Not Pay Working System. The program aims to verify prepayment or pre‑award eligibility, prevent…
U.S. Department of the Interior · Privacy Act of 1974
High Guidance Published France · Oct 1, 2026 · effective Oct 1, 2026
CNIL and Cybermalveillance.gouv.fr release guide for individuals on personal data breach response
The French data protection authority (CNIL) and Cybermalveillance.gouv.fr have published a practical support document titled “Violation de données personnelles, que faire en 3 étapes clés ?”. The guide provides a three‑step checklist for…
CNIL
High Interpretation Published European Union · Sep 28, 2026
Commission designates ChatGPT, Reddit, Roblox as VLOPs/VLOSE under the Digital Services Act
The European Commission has designated ChatGPT as a Very Large Online Search Engine and Reddit and Roblox as Very Large Online Platforms under the DSA, citing each service’s reach of at least 45 million EU monthly users. The designated…
European Commission · Digital Services Act
High Final regulation In effect United States (federal) · Sep 28, 2026 · effective Oct 28, 2026
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
The Department of Health and Human Services is amending the Office of Refugee Resettlement's system of records for unaccompanied children. The change renames the system to "ORR Unaccompanied Alien Children Bureau (UACB) Administrative…
Department of Health and Human Services (HHS) · Privacy Act of 1974
High Guidance In effect United States (federal) · Sep 25, 2026 · effective Oct 26, 2026
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
The Peace Corps Office of Planning and Performance issued a public notice of a new system of records, the Peace Corps Customer Relationship Management (PC 38) system. The system will monitor, track, and analyze interactions with…
Peace Corps Office of Planning and Performance · Privacy Act of 1974
High Fine Decided Ireland · Sep 23, 2026 · effective Sep 21, 2026
Irish Data Protection Commission fines Google €403 million for GDPR violations over location data
The Irish Data Protection Commission issued its final decision on 21 September 2026, imposing administrative fines of €403 million on Google Ireland Limited. The DPC found infringements of GDPR principles relating to lawfulness, fairness…
Irish Data Protection Commission · General Data Protection Regulation
High Fine Decided France · Sep 11, 2026 · effective Jul 21, 2026
CNIL fines French IT firm EXTIA €300,000 for failing to honor data erasure requests
In 2024 EXTIA received 265 requests for erasure, many of which were not processed or not communicated to the requesters. The CNIL audit found breaches of Articles 12 and 17 GDPR regarding transparency and the right to erasure. The CNIL…
CNIL · General Data Protection Regulation
High Guidance Announced Spain · Sep 8, 2026 · effective Oct 6, 2026
AEPD launches “Las claves de…” series on privacy and emerging neurotechnologies
The Spanish Data Protection Agency (AEPD) announced a new audiovisual dialogue format, “Las claves de…”, to discuss privacy challenges of neurotechnologies and neurodata. The first episode will be streamed live on 6 October 2026 with AEPD…
Agencia Española de Protección de Datos (AEPD) · Reglamento General de Protección de Datos (RGPD)
High Amendment Signed Delaware · Sep 3, 2026 · effective Jan 1, 2027
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Governor Meyer signed HB 380 on September 2, amending the Delaware Personal Data Privacy Act. The amendment expands the definition of sensitive data, lowers applicability thresholds, adds new contractual and due‑diligence requirements for…
CFPB · Fair Credit Reporting Act
High Enforcement Decided Ireland · Sep 3, 2026 · effective Aug 28, 2026
Data Protection Commission issues €645,000 fine and compliance orders against HSE
The Irish Data Protection Commission issued a final decision on 28 August 2026 concerning the Health Service Executive's handling of paper medical records. The DPC found physical security and integrity failures at external storage…
Data Protection Commission · General Data Protection Regulation
High New law Signed New Jersey · Aug 12, 2026 · effective Sep 1, 2027
New Jersey enacts Age-Appropriate Design Code (A4015) signed by Governor Sherrill
On August 11, Governor Sherrill signed A4015, the New Jersey Age-Appropriate Design Code (NJAADC). The law, effective September 1, 2027, imposes safety defaults, bans dark patterns, and creates a private right of action. It applies to…
New Jersey Attorney General · Connecticut Data Privacy Act
High Fine In effect Ireland · May 24, 2024 · effective Aug 25, 2026
Irish Data Protection Commission fines HSE €645,000 for GDPR breaches over paper record storage
The Data Protection Commission (DPC) issued a final decision on 25 August 2026, fining the Health Service Executive (HSE) €645,000 for multiple GDPR infringements related to the storage and security of paper medical records. The DPC also…
Data Protection Commission (Ireland) · General Data Protection Regulation
Older →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13