REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: privacy · clear
204 developments
Moderate Proposed regulation Proposed European Union · Jun 23, 2026
EU Council scrapes Article 88b proposal to replace cookie banners with automated signal
The European Commission proposed adding Article 88b to the GDPR to replace cookie banners with an automated consent signal. On 18 June, the Council’s position paper removed the article, keeping the existing cookie banner regime. The change…
European Commission · General Data Protection Regulation
Moderate Lawsuit filed Filed Germany · Apr 30, 2026
noyb files lawsuit against Hamburg DPA over inaction on PimEyes biometric data case
noyb has filed a lawsuit against the Hamburg Data Protection Authority, alleging that the authority has failed to act on illegal biometric data processing by PimEyes. The DPA considers PimEyes' facial recognition practices illegal but…
Hamburg Data Protection Authority · General Data Protection Regulation
Moderate Proposed regulation Proposed European Union · Apr 16, 2026
EU Digital Omnibus proposal aims to limit GDPR right of access amid 83.5% non‑compliance
The European Commission’s Digital Omnibus proposal would restrict the GDPR right of access to “data protection purposes”, citing alleged abuse. NOYB’s analysis shows that 83.5% of access requests were not properly answered, with only 16.5%…
European Commission · General Data Protection Regulation
Moderate Fine In effect France · Mar 13, 2026
French court upholds €40M GDPR fine against Criteo
The French Data Protection Authority (CNIL) fined Criteo €40 million for GDPR violations, including lack of valid consent, transparency, and failures to honor erasure and access rights. In March 2026, the Conseil d’État rejected Criteo’s…
CNIL · General Data Protection Regulation
Moderate Proposed regulation Published European Union · Mar 5, 2026
EU Commission's Digital Omnibus proposal to limit GDPR Right of Access faces criticism from DPOs
The European Commission has published a Digital Omnibus proposal that would narrow the definition of personal data, restrict the Right of Access and allow broader AI training. A survey by noyb shows data protection officers consider the…
European Commission · General Data Protection Regulation
Moderate Guidance Published European Union · Feb 11, 2026
EU DPAs reject key proposals in Digital Omnibus GDPR changes
The European Data Protection Board and the European Data Protection Supervisor issued a joint opinion rejecting the Commission's proposal to narrow the definition of personal data and to restrict the right of access. They also raised…
European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) · ePrivacy Directive
Moderate Court ruling Decided Austria · Dec 18, 2025 · deadline Dec 31, 2025
Austrian Supreme Court orders Meta to give users full data access within 14 days
The Austrian Supreme Court ruled that Meta must provide a complete copy of all personal data to any user request within 14 days, including source, recipient and purpose information. The court also required Meta to obtain explicit opt‑in…
EDPB · General Data Protection Regulation
Moderate Guidance Announced European Union · Dec 10, 2025
EU‑US data transfers face imminent risk as US legal changes could undermine TAFPF and SCCs
The blog notes that most EU‑US transfers rely on the Transatlantic Data Privacy Framework (TAFPF) or Standard Contract Clauses (SCCs), which depend on fragile US laws and executive orders. It warns that upcoming US Supreme Court decisions…
EDPB · General Data Protection Regulation
Moderate Proposed regulation Proposed European Union · Nov 22, 2025
EU Commission proposes Digital Omnibus package with new personal data definition and research exemption
The European Commission has released the Digital Omnibus proposal, introducing a narrower definition of personal data (Art. 4(1)), a broader research exemption (Arts. 4(38), 5(1)(b), 13, 89), and new AI‑related rules (Arts. 9(2)(k), 9(5)…
European Commission · General Data Protection Regulation
Moderate Proposed regulation Proposed European Union · Nov 11, 2025
Open letter warns EU Commission's Digital Omnibus draft could deregulate GDPR
Noyb, EDRi and the Irish Council for Civil Liberties sent an open letter to the European Commission criticizing a draft Digital Omnibus that would amend core GDPR provisions. The draft proposes redefining personal data, weakening data…
European Commission · General Data Protection Regulation
Moderate Enforcement Filed Austria · Oct 28, 2025
noyb files criminal complaint against Clearview AI in Austria
noyb filed a criminal complaint with Austrian public prosecutors against Clearview AI and its managers for alleged GDPR violations. The complaint relies on Article 84 GDPR and Austria's § 63 Data Protection Act, which allow criminal…
Austrian public prosecutors · General Data Protection Regulation
Moderate Data protection authority action Announced Ireland · Sep 18, 2025
Former Meta lobbyist Niamh Sweeney appointed Irish DPC commissioner
Niamh Sweeney, a former senior Meta lobbyist, is set to join the Irish Data Protection Commission (DPC) as a commissioner in October. The DPC is the EU lead privacy regulator for major US tech firms. The appointment raises concerns about…
Irish Data Protection Commission · General Data Protection Regulation
Moderate Fine In effect France · Sep 4, 2025
CNIL fines Google €325 million for unsolicited Gmail advertising
The French data protection authority CNIL has issued a decision siding with privacy NGO noyb and fined Google €325 million for sending unsolicited advertising emails to Gmail users without consent. The authority also ordered Google to stop…
CNIL · ePrivacy Directive
Moderate Data protection authority action Decided Austria · Aug 29, 2025
Austrian DPA orders YouTube to comply with GDPR Article 15 access request
The Austrian Data Protection Authority issued a decision ordering YouTube (Google) to provide the complainant with full access to his personal data, including purpose, storage periods, recipients and tracking cookies, under Article 15…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Court ruling Decided Austria · Aug 18, 2025
Austrian Federal Administrative Court rules DerStandard's "pay or okay" consent model illegal
The Austrian Federal Administrative Court (BVwG) confirmed the Data Protection Authority's finding that DerStandard violated the GDPR by offering a "pay or okay" choice. The court held that the newspaper did not obtain valid, granular…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Court ruling Decided European Union · Jul 31, 2025
CJEU ruling C‑446/21 limits use of personal data for online advertising and repurposing publicly available data
The European Court of Justice issued ruling C‑446/21, fully backing a lawsuit against Meta's Facebook service. The court massively limits the use of personal data for online advertising and restricts the reuse of publicly available…
EDPB · General Data Protection Regulation
Moderate Enforcement Filed European Union · Jul 17, 2025
noyb files GDPR complaints against TikTok, AliExpress and WeChat for denying data access
noyb has lodged complaints with the data protection authorities in Belgium, Greece and the Netherlands alleging that TikTok, AliExpress and WeChat violated Articles 12 and 15 of the GDPR by failing to provide full data access. The…
Data Protection Authorities (Belgium, Greece, Netherlands) · General Data Protection Regulation
Moderate Data protection authority action Decided Ireland · Jul 16, 2025
DPC issues final decision reprimanding Children’s Health Ireland for GDPR security breaches
The Irish Data Protection Commission concluded that Children’s Health Ireland (CHI) at Tallaght University Hospital breached GDPR security and confidentiality obligations. CHI was reprimanded and ordered to bring its processing into…
Data Protection Commission (Ireland) · General Data Protection Regulation
Moderate Data protection authority action Filed Austria · Jun 26, 2025
noyb files complaint against Bumble for unlawful AI Icebreakers in Austria
noyb lodged a complaint with the Austrian Data Protection Authority alleging that Bumble's AI Icebreakers process personal data without valid consent and rely on an invalid legitimate‑interest claim. The complaint cites violations of GDPR…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Class action Announced Austria · Jun 3, 2025
noyb seeks participants for potential GDPR class action against Austrian credit agency CRIF
noyb alleges that CRIF processes personal data of millions of Austrians to calculate credit scores based on age, gender and address, potentially violating the GDPR. The organization plans a scientific review and, if evidence supports it…
Austrian Data Protection Authority · General Data Protection Regulation
← NewerOlder →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13