REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: security · clear
43 developments
Moderate Guidance Published France · Oct 9, 2026
CNIL hosts 2nd Rencontres Informatique & Libertés on connected glasses and data‑sanctions
The French data‑protection authority CNIL held its second Rencontres Informatique & Libertés on 29 September 2026, featuring panels on the privacy impact of connected glasses and the role of sanctions under the GDPR. The event gathered…
CNIL · RGPD
Moderate Guidance Announced European Union · Oct 9, 2026
Commission holds special meeting of Scientific Panel on frontier AI safety and risks
The European Commission convened a special meeting of the Scientific Panel on AI, which includes 60 independent experts. The panel advises the EU AI Office and national authorities on systemic risks, model classification, evaluation…
European Commission · EU AI Act
Moderate Fine Decided Sweden · Oct 8, 2026
Swedish DPA fines Miljödata approx EUR 160,000 for insufficient security measures
The Swedish Data Protection Authority (IMY) imposed an administrative fine of SEK 1,800,000 (≈ EUR 160,000) on IT service provider Miljödata i Karlskrona for violating Article 32(1) GDPR. The authority found the company lacked adequate…
Swedish Data Protection Authority (IMY) · General Data Protection Regulation
Moderate Enforcement Decided France · Oct 8, 2026
CNIL closes injunction against FRANCE TRAVAIL after compliance with data security measures
The French data protection authority (CNIL) closed the injunction issued on 22 January 2026 against FRANCE TRAVAIL, after the organization demonstrated compliance with the security measures required by Article 32 of the GDPR. The original…
CNIL · RGPD
Moderate Guidance Published Spain · Oct 8, 2026
AEPD publishes second issue of scientific journal “Privacy, Innovation and Technology”
The Spanish Data Protection Agency released the second issue of its scientific journal PIT, dedicated to the 10th anniversary of the GDPR. The monograph examines proactive responsibility, the right to explanation in automated decisions…
Agencia Española de Protección de Datos (AEPD) · Reglamento General de Protección de Datos (RGPD)
Moderate Proposed regulation Proposed United States (federal) · Oct 7, 2026
DOJ proposes exemption for Firearms Rights Restoration Electronic Records Database from Privacy Act provisions
The Office of the Pardon Attorney within the U.S. Department of Justice announced a notice of a new system of records called the Firearms Rights Restoration Electronic Records Database (FRRERD). The agency proposes to exempt this system…
U.S. Department of Justice · Privacy Act of 1974
Moderate Guidance Published United States (federal) · Oct 5, 2026
EPIC analysis links pixel‑tracking litigation under ECPA and CIPA to upcoming Supreme Court VPPA case
EPIC outlines how recent court decisions using the Electronic Communications Privacy Act (ECPA) and California Invasion of Privacy Act (CIPA) address non‑consensual pixel tracking and its privacy harms. The analysis cites multiple…
HHS OCR · HIPAA Privacy, Security and Breach Notification Rules
Moderate Settlement Settled United States (federal) · Oct 2, 2026
Meta’s Muse AI Agent raises privacy, security, and child safety concerns amid past FTC consent decree
Meta launched the Muse personal AI agent in September 2026, which collects extensive personal data and can act without clear user permission. EPIC reports multiple incidents where Muse accessed messages, shared home addresses, and…
Federal Trade Commission
Moderate Guidance Published France · Oct 2, 2026
CNIL explains when data‑breach victims can claim compensation under the GDPR
The CNIL outlines that individuals can seek damages only if a GDPR breach caused a real material or moral injury, and they can prove a causal link. Compensation is awarded by a judge, not the CNIL, and the regulator may only impose…
CNIL · RGPD
Moderate Proposed regulation Announced France · Oct 1, 2026
CNIL to examine draft decree on student violence questionnaire and automated vehicle sound monitoring
The CNIL plenary session on 1 October 2026 will examine a draft decree authorising personal data processing for a "Questionnaire violences sexistes et sexuelles" in schools. It will also review draft orders on sound radars and an automated…
Commission nationale de l'informatique et des libertés (CNIL) · règlement intérieur de la CNIL
Moderate Proposed regulation Announced United States (federal) · Oct 1, 2026
HUD announces intent to establish eVMS system of records under the Privacy Act
The Department of Housing and Urban Development (HUD) issued a Federal Register notice announcing its intent to create a new Privacy Act system of records called the Enterprise Voucher Management System (eVMS). The system will manage…
Department of Housing and Urban Development (HUD) · Privacy Act of 1974
Moderate Guidance Published United States (federal) · Oct 1, 2026
Federal Register limits automated access; CAPTCHA required for flagged requests
The Federal Register website warns that programmatic requests are flagged as potentially automated and must complete a CAPTCHA to proceed. Users are directed to the FederalRegister.gov and eCFR.gov API documentation for legitimate…
Moderate Proposed regulation Proposed United States (federal) · Oct 1, 2026
Federal Register proposes limiting automated scraping, requiring API use and CAPTCHAs
The notice warns that aggressive automated scraping of FederalRegister.gov and eCFR.gov will be restricted to access via developer APIs. Human users must complete a CAPTCHA to request access, and occasional re‑verification is expected as a…
National Archives and Records Administration
Moderate Proposed bill Introduced United States (federal) · Sep 30, 2026
Senator Markey Introduces Facial Recognition and Biometric Technology Moratorium Act of 2026
Senators Markey and Merkley, together with Representatives Jaypal, Pressley, and Tlaib, introduced legislation to halt federal use of biometric surveillance, including facial recognition. The Facial Recognition and Biometric Technology…
Moderate Guidance Published United States (federal) · Sep 29, 2026
Federal Register restricts automated scraping; requires API use and CAPTCHA verification
The Federal Register warns that programmatic access to FederalRegister.gov and eCFR.gov is limited to its developer APIs due to aggressive automated scraping. Users must use the APIs or complete a CAPTCHA to verify they are human. The…
Privacy Act of 1974
Moderate Guidance Proposed United States (federal) · Sep 29, 2026
Agency seeks comment on proposed information collection for protection of human subjects
The agency announced a proposed collection of information related to the protection of human subjects and Institutional Review Boards and is requesting public comment. The notice also notes that programmatic access to FederalRegister.gov…
Food and Drug Administration · Paperwork Reduction Act of 1995
Moderate Proposed bill Proposed United States (federal) · Sep 28, 2026
U.S. lawmakers introduce AI AGENT Act and California SB 1106 defining AI agents
This summer U.S. lawmakers released two of the first legislative proposals for regulating AI agents: the federal AI AGENT Act and California SB 1106. The AI AGENT Act would establish a consumer‑facing framework based on the agent’s…
CPPA · California Consumer Privacy Act (as amended by CPRA)
Moderate Final regulation Published California · Sep 28, 2026
California Privacy Protection Agency adopts multiple regulations including Conflict of Interest Code Amendments and Data Broker Registration Fee
The CPPA has adopted several regulations, such as the Conflict of Interest Code Amendments Regulation (September 2026) and Data Broker Registration Fee Regulation (December 2025). These were adopted through the Administrative Procedures…
California Privacy Protection Agency · California Consumer Privacy Act (as amended by CPRA)
Moderate Guidance Published United States (federal) · Sep 28, 2026
Federal Register restricts automated scraping, requires CAPTCHA and API use
The Federal Register warns that aggressive automated scraping of its sites is limited to access via developer APIs. Human users must complete a CAPTCHA to continue, and may be asked to do so repeatedly as a security measure.
Department of Defense · Privacy Act of 1974
Moderate Guidance Published United States (federal) · Sep 25, 2026
DoD updates SORN for DON Child and Youth Program to align with cybersecurity policies
The Department of Defense is modifying and reissuing the system of records titled "DON Child and Youth Program" (NM01754-3) under the Privacy Act of 1974. The updates incorporate DoD standard routine uses A through J, expand the collection…
Department of Defense · Privacy Act of 1974
Older →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13