REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: targeted advertising · clear
57 developments
Moderate Enforcement Filed European Union · Feb 28, 2023
noyb files complaints against data brokers for refusing cookie‑based authentication of GDPR access requests
noyb lodged a series of complaints against websites and data brokers that denied or complicated GDPR access requests by requiring additional identification beyond cookies. The complaints argue that, under GDPR and EDPB guidance, users…
EDPB · General Data Protection Regulation
Moderate Fine Announced Ireland · Jan 27, 2023
Irish DPC announces €390 million fine on Meta for GDPR consent breach
The Irish Data Protection Commission announced a €390 million fine against Meta, ordering it to obtain valid consent for personalized advertising after the European Data Protection Board issued a binding decision. The fine illustrates…
Irish Data Protection Commission · General Data Protection Regulation
Moderate Enforcement Published Ireland · Jan 11, 2023
Irish DPC fines Meta €60m for unlawful processing and €150m for transparency breaches
The Irish Data Protection Commission (DPC) issued a final decision imposing a €150 million fine on Facebook for transparency failures and a €60 million fine on Meta for lacking a legal basis to process personal data. The decision also…
Irish Data Protection Commission · General Data Protection Regulation
Moderate Enforcement Announced European Union · Jan 4, 2023
EU EDPB bans Meta from using personal data for personalized ads, imposes €390 million fine
The European Data Protection Board (EDPB) decided that Meta (Facebook and Instagram) may not use personal data for personalized advertising and must obtain opt‑in consent. The decision also imposes a total fine of €390 million on Meta.…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate Fine In effect Ireland · Jan 4, 2023 · effective Jan 4, 2023
EU data protection board fines Meta €390 million and bans personalized ads
The European Data Protection Board, following the Irish Data Protection Commission, ruled that Meta's use of personal data for personalized advertising violated the GDPR and imposed a €390 million fine. Meta must obtain opt‑in consent and…
European Data Protection Board · General Data Protection Regulation
Moderate Enforcement Announced European Union · Dec 6, 2022
EU Data Protection Board rules Meta's consent bypass for personalized ads illegal
The European Data Protection Board (EDPB) decided that Meta cannot force users to accept personalized ads and must obtain a yes/no consent option. The decision overturns a previous draft decision by the Irish Data Protection Commission and…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate Court ruling Published European Union · Oct 13, 2022
CJEU Advocate General opinion may limit GDPR non‑material damages compensation
The Advocate General of the Court of Justice of the EU issued an opinion that could restrict the right to claim non‑material damages under the GDPR. The opinion questions whether Article 82 allows damages without material loss and suggests…
EDPB · General Data Protection Regulation
Moderate Fine In effect Norway (EEA) · Dec 15, 2021 · effective Dec 15, 2021
Norwegian DPA fines Grindr €6.3 M for illegal sharing of sensitive data
The Norwegian Data Protection Authority imposed a fine of 65 Mio NOK on Grindr for sharing sensitive personal data without valid consent. The authority found the consent mechanism invalid and highlighted the lack of a genuine opt‑out. The…
Norwegian Data Protection Authority · General Data Protection Regulation
Moderate Guidance Published Ireland · Dec 4, 2021
Irish DPC tried to embed Facebook consent bypass into EDPB Guidelines, but final 2019 guidelines omitted it
A letter shows the Irish DPC held ten meetings with Facebook and agreed on a GDPR bypass by moving consent into terms and conditions. The DPC then drafted EDPB guideline language to allow this approach, but other DPAs criticised it…
Irish Data Protection Commission (DPC) · General Data Protection Regulation
Moderate Enforcement Announced Ireland · Oct 15, 2021
Irish DPC orders noyb to remove draft decision from website
The Irish Data Protection Commission sent a take‑down request to privacy activist group noyb on 14 Oct 2021, ordering removal of a draft decision that allegedly strips Facebook users of GDPR rights. noyb refused, citing Austrian law and…
Irish Data Protection Commission · General Data Protection Regulation
Moderate Enforcement Filed European Union · Aug 13, 2021
noyb files complaints against cookie paywalls of seven German and Austrian news sites over unlawful consent
noyb filed complaints against the cookie paywalls of SPIEGEL.de, Zeit.de, heise.de, FAZ.net, derStandard.at, krone.at and t-online.de, arguing that the "pay or okay" model violates the GDPR's requirement for freely given consent. The…
EDPB · General Data Protection Regulation
Moderate Court ruling Decided Austria · Jul 20, 2021
Austrian Supreme Court refers Facebook case to CJEU over consent vs contract and awards €500 symbolic damages
The Austrian Supreme Court (OGH) referred four questions to the Court of Justice of the EU concerning Facebook's reliance on contract instead of consent under the GDPR. In a partial judgment, the court awarded Max Schrems €500 for lack of…
EDPB · General Data Protection Regulation
Moderate Enforcement Filed European Union · May 26, 2021 · effective May 25, 2018
Digital Rights alliance files legal complaints across Europe against facial recognition company Clearview AI
Noyb and other EU digital‑rights groups submitted complaints to data‑protection authorities in France, Austria, Italy, Greece and the United Kingdom to halt Clearview AI's mass facial‑recognition surveillance. The regulators have three…
EDPB · General Data Protection Regulation
Moderate Fine In effect Norway (EEA) · Jan 26, 2021
Norwegian DPA fines Grindr €9.63 million for illegal sharing of sensitive data
The Norwegian Data Protection Authority imposed a fine of 100 Mio NOK on Grindr for sharing personal and sensitive data without valid consent. The authority found Grindr's consent mechanism invalid and highlighted the company's lack of…
Norwegian Data Protection Authority · General Data Protection Regulation
Moderate Fine In effect France · Jun 19, 2020
French court upholds €50 million CNIL fine against Google
The French Data Protection Authority (CNIL) imposed a €50 million fine on Google for insufficient information and lack of valid consent for personalized ads. The Conseil d’État confirmed the CNIL's decision and affirmed its jurisdiction…
CNIL · General Data Protection Regulation
Moderate Enforcement Filed Austria · May 13, 2020
noyb files GDPR complaint against Google over Android Advertising ID tracking
noyb filed a formal GDPR complaint against Google for tracking users via the Android Advertising ID without a valid legal basis. The complaint was submitted on behalf of an Austrian citizen to the Austrian Data Protection Authority. GDPR…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate Enforcement Filed European Union · May 25, 2018 · effective May 25, 2018
noyb files GDPR complaints against Google, Instagram, WhatsApp and Facebook for forced consent
On 25 May 2018, the privacy NGO noyb filed four complaints with DPAs in France, Belgium, Germany and Austria alleging that Google, Instagram, WhatsApp and Facebook use forced consent that violates GDPR Article 7(4). The complaints argue…
EDPB · General Data Protection Regulation
← Newer
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13