REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: consent · clear
56 developments
Moderate Settlement Settled United States (federal) · Oct 2, 2026
Meta’s Muse AI Agent raises privacy, security, and child safety concerns amid past FTC consent decree
Meta launched the Muse personal AI agent in September 2026, which collects extensive personal data and can act without clear user permission. EPIC reports multiple incidents where Muse accessed messages, shared home addresses, and…
Federal Trade Commission
Moderate Enforcement Decided Ireland · Sep 7, 2026
Irish DPC welcomes court conviction of Brown Thomas for ePrivacy breaches
The Dublin Metropolitan District Court convicted Brown Thomas Arnotts Limited on 7 September 2026 for multiple breaches of Regulation 13 of the ePrivacy Regulations. The company pleaded guilty to five sample charges, including failures to…
Data Protection Commission · ePrivacy Directive
Moderate Settlement Announced United States (federal) · Sep 1, 2026
Meta to implement age‑verification framework under $17 B settlement with 52 U.S. states
Meta has agreed to a $17 billion settlement with 52 state attorneys general that mandates age‑assurance technology for its platforms. The settlement requires Meta to apply age‑verification methods within one year, classify users into 18+…
state attorneys general · Children's Online Privacy Protection Act
Moderate Settlement Settled Connecticut · Aug 27, 2026
Connecticut AG settles with TaxAct over taxpayer data disclosures via tracking tech
On August 19, 2026, Connecticut Attorney General William Tong announced a $275,000 settlement with TaxAct for improperly disclosing taxpayer information to advertising partners through third‑party tracking technologies. The settlement…
Connecticut Attorney General
Moderate Fine In effect France · Mar 13, 2026
French court upholds €40M GDPR fine against Criteo
The French Data Protection Authority (CNIL) fined Criteo €40 million for GDPR violations, including lack of valid consent, transparency, and failures to honor erasure and access rights. In March 2026, the Conseil d’État rejected Criteo’s…
CNIL · General Data Protection Regulation
Moderate Data protection authority action Decided Austria · Jan 27, 2026
Austrian DSB orders Microsoft to stop tracking school children with cookies
The Austrian Data Protection Authority ruled that Microsoft illegally installed tracking cookies on a pupil's device without consent. The authority ordered Microsoft to cease the use of those cookies within four weeks. The decision follows…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Fine In effect France · Nov 27, 2025
CNIL fines Conde Nast €750,000 for cookie consent violations
The French data protection authority CNIL fined Conde Nast €750,000 for placing cookies on its Vanity Fair website without obtaining valid user consent. The authority also found the publisher failed to adequately inform users about the…
CNIL
Moderate Data protection authority action Decided Austria · Oct 9, 2025
Austrian DSB rules Microsoft 365 Education illegally tracks students and orders data deletion
The Austrian Data Protection Authority found Microsoft 365 Education used tracking cookies without consent and denied a data‑access request, violating GDPR. The DSB ordered Microsoft to delete the data, provide full access, and disclose…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Data protection authority action Published Austria · Sep 26, 2025
Austrian DSB bans KSV1870 from automated credit checks without consent
The Austrian Data Protection Authority ruled that KSV1870's fully automated credit rating was unlawful and prohibited the agency from conducting such checks without the data subject's consent. The authority also ordered KSV1870 to provide…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Data protection authority action Announced Ireland · Sep 18, 2025
Former Meta lobbyist Niamh Sweeney appointed Irish DPC commissioner
Niamh Sweeney, a former senior Meta lobbyist, is set to join the Irish Data Protection Commission (DPC) as a commissioner in October. The DPC is the EU lead privacy regulator for major US tech firms. The appointment raises concerns about…
Irish Data Protection Commission · General Data Protection Regulation
Moderate Fine In effect France · Sep 4, 2025
CNIL fines Google €325 million for unsolicited Gmail advertising
The French data protection authority CNIL has issued a decision siding with privacy NGO noyb and fined Google €325 million for sending unsolicited advertising emails to Gmail users without consent. The authority also ordered Google to stop…
CNIL · ePrivacy Directive
Moderate Data protection authority action Filed Austria · Jun 26, 2025
noyb files complaint against Bumble for unlawful AI Icebreakers in Austria
noyb lodged a complaint with the Austrian Data Protection Authority alleging that Bumble's AI Icebreakers process personal data without valid consent and rely on an invalid legitimate‑interest claim. The complaint cites violations of GDPR…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Enforcement Announced European Union · Jun 16, 2025
noyb warns Meta's planned WhatsApp ads may breach GDPR and DMA
noyb alleges that Meta's intention to serve ads on WhatsApp using personal data from Instagram and Facebook violates the GDPR and the EU Digital Markets Act. The organization says the proposed "Pay or Okay" model would not provide freely…
noyb · General Data Protection Regulation
Moderate Enforcement Filed Italy · Dec 19, 2024
noyb files GDPR complaint against Ryanair over mandatory biometric face scans
noyb has filed a complaint with the Italian Data Protection Authority alleging that Ryanair forces new customers to create permanent accounts and undergo a biometric facial‑recognition verification to book flights. The complaint says this…
Italian Data Protection Authority (Garante) · General Data Protection Regulation
Moderate Enforcement Decided European Union · Dec 13, 2024
EDPS finds European Commission illegally used political micro‑targeting
The European Data Protection Supervisor issued a decision that the European Commission illegally targeted ads using sensitive political data. The EDPS issued only a reprimand, noting no fine was needed as the practice stopped. The decision…
European Data Protection Supervisor (EDPS) · General Data Protection Regulation
Moderate Enforcement In effect Belgium · Sep 12, 2024
Belgian DPA orders Mediahuis news sites to add reject button to cookie banners, imposes daily penalty
The Belgian Data Protection Authority ordered four Mediahuis news sites to add a “reject” button on the first layer of their cookie banners and to change misleading button colours. Non‑compliance triggers a penalty of €50,000 per day per…
Belgian Data Protection Authority · General Data Protection Regulation
Moderate Enforcement Filed European Union · Aug 12, 2024
noyb files nine GDPR complaints against X over AI training of 60 million EU users
noyb has lodged GDPR complaints in Austria, Belgium, France, Greece, Ireland, Italy, the Netherlands, Spain and Poland alleging that X used personal data of over 60 million EU/EEA users to train its AI system without consent. The Irish…
Irish Data Protection Commission · General Data Protection Regulation
Moderate Enforcement Filed European Union · Jun 6, 2024 · effective Jun 26, 2024
noyb files complaints in 11 EU DPAs to halt Meta's AI data use
noyb has lodged complaints with data protection authorities in Austria, Belgium, France, Germany, Greece, Italy, Ireland, the Netherlands, Norway, Poland and Spain, requesting an urgency procedure to stop Meta's planned use of personal…
EDPB · General Data Protection Regulation
Moderate Investigation Announced Austria · Jun 4, 2024
noyb files complaints urging Austrian DSB to investigate Microsoft 365 Education for GDPR violations affecting children
noyb has lodged two complaints with Austria's data protection authority alleging that Microsoft 365 Education breaches GDPR rights of minors by shifting responsibility to schools, providing vague privacy information, and tracking users…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Data protection authority action Published DE-BAVARIA · Feb 5, 2024
Bavarian DPA declares CRIF‑Acxiom data trading illegal under GDPR
The Bavarian data protection authority ruled that credit reference agency CRIF illegally purchased personal data from address trader Acxiom and breached GDPR purpose‑limitation and information duties. The decision follows a similar…
Bavarian Data Protection Authority · General Data Protection Regulation
Older →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13