REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
70 developments
Moderate Guidance Published European Union · Sep 23, 2026
EDPB adopts guidelines on GDPR fines and DSA interaction (17 Sep 2026)
On 17 September 2026 the European Data Protection Board adopted guidelines on the use of administrative fines by data protection authorities and finalised guidance on the interaction between the Digital Services Act (DSA) and the GDPR. The…
European Data Protection Board (EDPB) · Digital Services Act
Moderate Guidance Published European Union · Sep 23, 2026
EU Commission hosts fifth roundtable on Digital Services Act implementation
On 23 September 2026 the European Commission held an online roundtable with about 60 civil society organisations and researchers to discuss the implementation of the Digital Services Act. The discussion focused on systemic risks…
European Commission · Digital Services Act
Moderate Guidance Announced United States (federal) · Sep 22, 2026
WBUR reports driver’s license data appearing on dark web, raising AI‑enabled fraud risks
WBUR discussed a breach where images of driver’s licenses have been posted on the dark web. The episode highlighted risks of new account fraud, especially when combined with AI tools that can synthesize voice, images, or video. It also…
Moderate Guidance Published European Union · Sep 22, 2026 · effective Sep 22, 2026
ENISA releases 2026 Threat Landscape report highlighting AI-enabled cyber threats and supply‑chain risks
ENISA's 2026 Threat Landscape report analyses incidents from 1 January to 31 December 2025, noting a rise in ransomware, AI‑driven malicious activity, and supply‑chain attacks. The report finds public administration to be the most targeted…
ENISA · NIS2 Directive
Moderate Guidance Published France · Sep 17, 2026
CNIL outlines its status, organization and sanction powers
The CNIL, created by the 1978 Loi Informatique et Libertés, is an independent administrative authority composed of a college of 18 members. Its restricted board can impose fines up to €20 million or 4 % of global annual turnover under the…
CNIL · loi Informatique et Libertés
Moderate Guidance Announced New York · Sep 17, 2026 · effective Jan 1, 2027
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York Attorney General Letitia James issued an alert encouraging employees with knowledge of unsafe or illegal AI development to submit confidential whistleblower complaints. The alert references the Responsible AI Safety and Education…
New York Attorney General's Office · New York SHIELD Act
Moderate Guidance Published United States (federal) · Sep 16, 2026
EPIC report: Data brokers sell personal data to Disney, GM, insurers and banks
EPIC highlights that data brokers collect and sell personal information to major companies such as Disney, General Motors, insurers and banks. The article notes that brokers infer additional characteristics like finance, health…
Moderate Guidance Published KE · Sep 16, 2026
Kenya publishes new guidance on cross‑border data transfers
On 8 September 2026 Kenya’s Office of the Data Protection Commissioner released detailed Guidance Notes on cross‑border data transfers. The guidance clarifies Kenya’s transfer framework, adds operational detail, and highlights differences…
Office of the Data Protection Commissioner (ODPC) · General Data Protection Regulation
Moderate Guidance Announced European Union · Sep 11, 2026
ENISA launches Single Reporting Platform for Cyber Resilience Act reporting
ENISA has deployed the initial operating capability of the Single Reporting Platform (SRP) to support the Cyber Resilience Act (CRA) reporting obligations. From 11 September 2026 manufacturers and open‑source software stewards must report…
ENISA · Cyber Resilience Act
Moderate Guidance In effect France · Sep 10, 2026 · effective Sep 1, 2026
CNIL guidance on data‑protection obligations under the electronic invoicing reform effective 1 Sept 2026
The CNIL explains the data‑protection implications of the French electronic invoicing reform that entered into force on 1 Sept 2026. It details which personal data may be processed, the roles of issuers, receivers and certified platforms…
CNIL · réforme relative à la facturation électronique
Moderate Guidance Published France · Sep 10, 2026
CNIL releases Volume 2 of “L’Agence Privacy” to educate adolescents on cybercrime and data privacy
On 10 September 2026 the French data‑protection authority CNIL published the second volume of its educational comic series “L’Agence Privacy”. The free online and paper resource targets teenagers and parents, covering risks such as…
CNIL
Moderate Guidance Repealed United States (federal) · Sep 9, 2026 · effective Sep 9, 2026
FTC rescinds 2021 Policy Statement on Breaches by Health Apps and Connected Devices
The Federal Trade Commission announced it is rescinding the 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. The guidance is deemed obsolete and is being withdrawn. The rescission was published on 2026-09-09.
Federal Trade Commission
Moderate Guidance Announced United States (federal) · Sep 3, 2026
SEC Investor Advisory Committee to Host Sept. 10 Meeting on AI Technologies and NMS Rules
The U.S. Securities and Exchange Commission’s Investor Advisory Committee will hold a public meeting on Sept. 10, 2026 to discuss artificial intelligence technologies in the public markets and the SEC’s Regulation National Market System…
Securities and Exchange Commission · Regulation National Market System
Moderate Guidance Published United States (federal) · Aug 31, 2026
EFF guide on doxxing incident response and digital footprint protection
The Electronic Frontier Foundation published a guide outlining steps for individuals and groups to respond to doxxing attacks. It covers incident logging, team role assignment, monitoring hate forums, setting up alerts, hardening accounts…
California Delete Act
Moderate Guidance Published SG · Aug 25, 2026
PDPC publishes Advisory Guidelines on Personal Data in Generative AI at Singapore Data Festival
On July 20, 2026, Singapore’s Personal Data Protection Commission released its finalized Advisory Guidelines on the Use of Personal Data in Generative AI. The guidance clarifies the Publicly Available Exception for web‑scraping and…
Personal Data Protection Commission (PDPC) · EU AI Act
Moderate Guidance Announced United States (federal) · Aug 5, 2026
Future of Privacy Forum releases updated AI risk assessment framework and best practices for hiring
Future of Privacy Forum and leading HR software firms released Updated Best Practices for AI and Workplace Assessment Technologies, addressing generative and agentic AI in employment. The guidance outlines a risk assessment framework and…
EU AI Office · EU AI Act
Moderate Guidance Announced Spain · Jul 28, 2026
AEPD Privacy Lab invites entities to submit projects, research and initiatives
The AEPD's Privacy Lab has opened its Novedades space for publications, research projects, calls and activities related to privacy, data protection, AI and emerging technologies. Universities, research centres, public and private…
Agencia Española de Protección de Datos (AEPD) · Genetic Information Nondiscrimination Act
Moderate Guidance Announced Spain · Jul 27, 2026
AEPD announces 2026 Data Protection Awards to recognize privacy promotion
The Spanish Data Protection Agency (AEPD) has launched the ‘Premios Protección de Datos 2026’ with nine categories covering research, vulnerable groups, communication, education, best practices, legal research, social media diffusion, DPO…
Agencia Española de Protección de Datos (AEPD) · RGPD
Moderate Guidance Announced European Union · Jul 23, 2026
EDPB announces stakeholder event on upcoming data protection and competition law guidelines (15 Oct 2026)
The European Data Protection Board and the European Commission will hold a remote stakeholder event on 15 October 2026 to discuss upcoming guidelines on the interplay between competition law and data protection. The event invites…
European Data Protection Board · General Data Protection Regulation
Moderate Guidance Announced Spain · Jul 23, 2026 · effective Jul 23, 2026
AEPD reopens registration for public research network on privacy and emerging technologies
The Spanish Data Protection Agency (AEPD) has reopened enrollment for its public network of research groups and projects focused on privacy and emerging technologies. The new registration phase allows groups that missed the first call and…
Agencia Española de Protección de Datos
← NewerOlder →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13