REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: transparency · clear
87 developments
Moderate Enforcement Filed Norway (EEA) · Mar 20, 2025
noyb files second GDPR complaint against OpenAI over defamatory AI hallucinations in Norway
noyb filed a second complaint with the Norwegian Data Protection Authority alleging that OpenAI's ChatGPT generated false, defamatory personal data about a Norwegian user. The complaint cites violations of GDPR Article 5(1)(d) on data…
Norwegian Datatilsynet · General Data Protection Regulation
Moderate Fine Decided Netherlands · Dec 18, 2024
Dutch DPA fines Netflix €4.75 million for inadequate data‑subject information
The Dutch Data Protection Authority issued a decision imposing a €4.75 million fine on Netflix for not adequately informing customers about its data processing. The authority found Netflix failed to provide clear information and a full…
Dutch Data Protection Authority (Autoriteit Persoonsgegevens) · General Data Protection Regulation
Moderate Enforcement In effect Belgium · Sep 12, 2024
Belgian DPA orders Mediahuis news sites to add reject button to cookie banners, imposes daily penalty
The Belgian Data Protection Authority ordered four Mediahuis news sites to add a “reject” button on the first layer of their cookie banners and to change misleading button colours. Non‑compliance triggers a penalty of €50,000 per day per…
Belgian Data Protection Authority · General Data Protection Regulation
Moderate Data protection authority action Filed Austria · Aug 29, 2024
noyb files complaint with Austrian DPA over automated credit checks by KSV1870 and Unsere Wasserkraft
noyb lodged a complaint with the Austrian Data Protection Authority against credit reference agency KSV1870 and energy supplier Unsere Wasserkraft. The complaint alleges that customers are subjected to fully automated credit checks that…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Enforcement Filed European Union · Aug 12, 2024
noyb files nine GDPR complaints against X over AI training of 60 million EU users
noyb has lodged GDPR complaints in Austria, Belgium, France, Greece, Ireland, Italy, the Netherlands, Spain and Poland alleging that X used personal data of over 60 million EU/EEA users to train its AI system without consent. The Irish…
Irish Data Protection Commission · General Data Protection Regulation
Moderate Enforcement Filed European Union · Jun 6, 2024 · effective Jun 26, 2024
noyb files complaints in 11 EU DPAs to halt Meta's AI data use
noyb has lodged complaints with data protection authorities in Austria, Belgium, France, Germany, Greece, Italy, Ireland, the Netherlands, Norway, Poland and Spain, requesting an urgency procedure to stop Meta's planned use of personal…
EDPB · General Data Protection Regulation
Moderate Investigation Announced Austria · Jun 4, 2024
noyb files complaints urging Austrian DSB to investigate Microsoft 365 Education for GDPR violations affecting children
noyb has lodged two complaints with Austria's data protection authority alleging that Microsoft 365 Education breaches GDPR rights of minors by shifting responsibility to schools, providing vague privacy information, and tracking users…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Data protection authority action Published DE-BAVARIA · Feb 5, 2024
Bavarian DPA declares CRIF‑Acxiom data trading illegal under GDPR
The Bavarian data protection authority ruled that credit reference agency CRIF illegally purchased personal data from address trader Acxiom and breached GDPR purpose‑limitation and information duties. The decision follows a similar…
Bavarian Data Protection Authority · General Data Protection Regulation
Moderate Enforcement Pending European Union · Jan 28, 2024
Survey finds 74% of insiders say authorities would find GDPR violations in average EU company
A noyb survey of over 1,000 data‑protection professionals reports that 74% believe authorities would discover relevant GDPR violations during on‑site inspections. Respondents cite lack of clear DPA decisions, fines, and public enforcement…
EDPB · General Data Protection Regulation
Moderate Court ruling Decided European Union · Dec 7, 2023
CJEU rules automated credit scoring violates GDPR and expands judicial review of DPAs
The Court of Justice of the European Union issued two judgments: one confirming national courts can fully review DPA decisions, and another finding that automatically calculated credit scores breach Article 22 GDPR. The rulings require…
EDPB · General Data Protection Regulation
Moderate Enforcement Filed European Union · Nov 16, 2023
noyb files complaint with EDPS over EU Commission’s political micro‑targeting ads on X
noyb lodged a complaint with the European Data Protection Supervisor alleging the EU Commission used unlawful micro‑targeting on X to promote its chat‑control proposal. The ads targeted users based on political views and religious beliefs…
European Data Protection Supervisor (EDPS) · General Data Protection Regulation
Moderate Fine Decided Norway (EEA) · Sep 29, 2023
Norwegian Privacy Appeals Board upholds €5.8 million fine against Grindr
The Norwegian Privacy Appeals Board confirmed the Norwegian Data Protection Authority's fine of NOK 65 million against the dating app Grindr for sharing sensitive personal data with third parties. The fine, approximately €5.8 million…
Norwegian Data Protection Authority · General Data Protection Regulation
Moderate Proposed regulation Proposed European Union · Jul 4, 2023
EU Commission proposes GDPR Procedures Regulation that may limit citizens' procedural rights
The European Commission has issued a proposal to create a GDPR Procedures Regulation to address cooperation gaps among DPAs. Critics say the draft strips citizens of procedural rights and gives companies extensive participation rights. The…
European Commission · General Data Protection Regulation
Moderate Amendment Passed Ireland · Jun 28, 2023
Ireland passes amendment to Data Protection Act allowing DPC to declare GDPR cases confidential
The Irish government has passed an amendment to the Data Protection Act, creating Section 26A which permits the Data Protection Commission to declare documents relating to pending GDPR procedures confidential and criminalise their…
Irish Data Protection Commission (DPC) · General Data Protection Regulation
Moderate Amendment Proposed Ireland · Jun 26, 2023
Irish Parliament debates amendment to criminalise reporting on DPC procedures
A last‑minute amendment (Section 26A) was added to the Courts and Civil Law (Miscellaneous Provisions) Bill 2022 that would allow the Irish Data Protection Commissioner to declare its procedures confidential and make reporting on them a…
Irish Data Protection Commissioner · General Data Protection Regulation
Moderate Amendment Pending Ireland · Jun 26, 2023
Irish government adds Section 26A to Data Protection Act, criminalising reporting on DPC procedures
A last‑minute amendment (Section 26A) was inserted into the Courts and Civil Law (Miscellaneous Provisions) Bill 2022, allowing the Irish Data Protection Commissioner to declare most of its procedures confidential. The amendment would make…
Irish Data Protection Commissioner (DPC) · General Data Protection Regulation
Moderate Enforcement Filed Belgium · Jun 23, 2023
noyb files complaint against TeleSign for unlawful profiling of mobile users
noyb filed a complaint with the Belgian Data Protection Authority alleging that TeleSign receives phone data from BICS and creates reputation scores without consent, violating the GDPR. The complaint cites the use of AI-generated trust…
Belgian Data Protection Authority · General Data Protection Regulation
Moderate Fine In effect France · Jun 22, 2023
French CNIL fines Criteo €40 million for GDPR violations
The French Data Protection Authority (CNIL) fined Criteo €40 million for violating the GDPR, including lack of valid consent, transparency, and failure to respect the right to erasure and access. The enforcement followed complaints filed…
CNIL · General Data Protection Regulation
Moderate Fine In effect Sweden · Jun 13, 2023
Swedish Data Protection Authority fines Spotify €5 million for GDPR access violations
The Swedish Data Protection Authority (IMY) imposed a fine of 58 million Swedish crowns (≈ €5 million) on Spotify for not fully complying with users' right of access under the GDPR. The authority ordered Spotify to provide the complete set…
Swedish Data Protection Authority (IMY) · General Data Protection Regulation
Moderate Data protection authority action Announced Malta · May 17, 2023
Maltese DPA orders C-PLANET to disclose data source within 20 days or face fine
The Maltese Data Protection Authority (IDPC) ordered IT company C-PLANET to provide details on the source of personal data collected on voters within 20 days. Failure to comply will result in a proportionate and dissuasive fine under the…
Maltese Data Protection Authority (IDPC) · General Data Protection Regulation
← NewerOlder →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13