Moderate
Proposed regulation
Proposed
United States (federal) · Oct 7, 2026
DEA proposes to modify and republish its Aviation Division system of records notice
The Drug Enforcement Administration (DEA) announced a proposal to update the system of records notice for its Aviation Division, changing the categories of individuals covered, record categories, purpose, routine uses, and storage…
Justice Department · Privacy Act of 1974
Moderate
Proposed regulation
Proposed
United States (federal) · Oct 7, 2026
DOJ proposes exemption for Firearms Rights Restoration Electronic Records Database from Privacy Act provisions
The Office of the Pardon Attorney within the U.S. Department of Justice announced a notice of a new system of records called the Firearms Rights Restoration Electronic Records Database (FRRERD). The agency proposes to exempt this system…
U.S. Department of Justice · Privacy Act of 1974
Moderate
New law
Signed
California · Oct 6, 2026
California Governor signs over 20 AI‑related bills into law
Governor Gavin Newsom signed more than 20 bills covering AI transparency, synthetic performer disclosures, chatbot labeling, and industry‑specific AI use restrictions. The measures amend the California AI Transparency Act, create new…
California AI Transparency Act
Moderate
Proposed regulation
Announced
European Union · Oct 6, 2026
Commission registers European Citizens' Initiative for sovereign European AI domains
The European Commission has officially registered a European Citizens' Initiative that calls for the creation of sovereign European AI domains. The initiative seeks to shape future EU policy on artificial intelligence and digital…
European Commission
Low
Enforcement
Announced
Texas · Oct 6, 2026
Texas AG launches investigation into children's clothing companies over toxic chemicals
Texas Attorney General Ken Paxton announced an investigation into major children’s clothing brands, including Hanes and Fruit of the Loom, for potential toxic chemicals in undergarments. The AG issued Civil Investigative Demands to the…
Texas Attorney General's Office
High
Enforcement
Published
Spain · Oct 6, 2026 · effective Oct 6, 2026
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The Spanish Data Protection Agency (AEPD) sent preventive warnings (AI‑00170‑2026 and AI‑00171‑2026) to two local councils regarding planned video‑surveillance systems that use automated image analysis with AI. The agency stresses that the…
Agencia Española de Protección de Datos · Reglamento General de Protección de Datos
High
Proposed regulation
Proposed
United States (federal) · Oct 6, 2026 · effective Nov 16, 2026
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
The National Archives and Records Administration (NARA) proposes to revise its System of Records NARA 44, updating the system manager and location. The revision would expand the record type to include reasonable accommodation requests…
National Archives and Records Administration · Privacy Act of 1974
High
Final regulation
Announced
United States (federal) · Oct 6, 2026 · effective Nov 5, 2026
Treasury exempts new tip intake records from certain Privacy Act provisions
The Department of the Treasury issued a final rule exempting the system of records titled "Treasury .032--Federal Program Waste, Fraud, and Abuse Tip Intake and Referral Records" from specific provisions of the Privacy Act of 1974. The…
Department of the Treasury · Privacy Act of 1974
Low
FRAMEWORK UPDATE
Announced
Global · Oct 5, 2026
Future of Privacy Forum urges standardized privacy benchmarks for frontier AI systems
The paper argues that standardized privacy benchmarks are needed to evaluate privacy risks in frontier AI models, including data memorization, inference of sensitive attributes, and over‑collection. It describes emerging efforts such as…
Low
Proposed regulation
Proposed
Vermont · Oct 5, 2026
EPIC comments on Vermont Attorney General's proposed Age-Appropriate Design Code rules
On October 2, EPIC submitted comments on two proposed rules announced by the Vermont Attorney General to implement the state's Age-Appropriate Design Code. The rules target addictive design practices for minors and outline methods for age…
Vermont Attorney General · California Age-Appropriate Design Code Act
Moderate
Guidance
Published
United States (federal) · Oct 5, 2026
EPIC analysis links pixel‑tracking litigation under ECPA and CIPA to upcoming Supreme Court VPPA case
EPIC outlines how recent court decisions using the Electronic Communications Privacy Act (ECPA) and California Invasion of Privacy Act (CIPA) address non‑consensual pixel tracking and its privacy harms. The analysis cites multiple…
HHS OCR · HIPAA Privacy, Security and Breach Notification Rules
Low
Lawsuit filed
Filed
United States (federal) · Oct 2, 2026
EPIC files amicus brief challenging Spirit Airlines' bankruptcy sale of employee data to Google
EPIC and Professor Seema Patel submitted an amicus brief in a bankruptcy case to contest Spirit Airlines' proposed $10 million sale of employee data to Google for AI training. The brief argues the sale lacks adequate privacy protections…
Low
Proposed bill
Introduced
United States (federal) · Oct 2, 2026
Rep. Darrell Issa introduces the American Copyright Protection Act (H.R. 10364) targeting VPNs for site‑blocking
Rep. Darrell Issa (R‑CA) has introduced H.R. 10364, the American Copyright Protection Act, which would allow copyright owners to seek court orders blocking U.S. users from foreign piracy sites. The bill expands blocking obligations to…
American Copyright Protection Act (ACPA)
Moderate
Settlement
Settled
United States (federal) · Oct 2, 2026
Meta’s Muse AI Agent raises privacy, security, and child safety concerns amid past FTC consent decree
Meta launched the Muse personal AI agent in September 2026, which collects extensive personal data and can act without clear user permission. EPIC reports multiple incidents where Muse accessed messages, shared home addresses, and…
Federal Trade Commission
Low
Court ruling
Decided
New York · Oct 2, 2026
Federal judge rejects motion to dismiss social media surveillance lawsuit against Trump administration
A U.S. District Court in New York denied the government’s motion to dismiss a lawsuit filed by three labor unions alleging viewpoint‑based social media surveillance of noncitizens. The case, filed in October 2025, targets the Departments…
Administrative Procedure Act
Low
Enforcement
In effect
EC · Oct 2, 2026
Ecuador orders security expert Ola Bini deported and bans return for 10 years
Ecuadorian immigration authorities detained free software developer Ola Bini in Quito and ordered his immediate deportation, prohibiting his return for a decade. The decision was based on a secret report alleging threats to public…
Ecuadorian immigration authorities
Moderate
New law
Signed
California · Oct 2, 2026
California Governor signs three AI employment laws
Governor Gavin Newsom signed SB 947, SB 951, and AB 1883 to regulate AI in employment. The laws restrict automated decision systems, require technology-related layoff notices, and limit workplace surveillance tools. Each law includes civil…
California Labor Commissioner · SB 947 (No Robo Bosses Act)
Low
Guidance
Published
European Union · Oct 2, 2026
EDPB adopts Guidelines 04/2026 on GDPR fines and corrective powers for public consultation
The European Data Protection Board adopted Guidelines 04/2026 on the application of administrative fines and other corrective powers under the EU GDPR. The guidelines were released on September 17, 2026 for public consultation.
European Data Protection Board · General Data Protection Regulation
Moderate
Proposed regulation
Proposed
European Union · Oct 2, 2026
Commission seeks feedback on proposed EU Kids Act
The European Commission is gathering feedback on the proposed EU Kids Act, which aims to improve online safety for children with measures such as a social‑media delay, safety‑by‑design rules, privacy‑preserving age assurance, and…
European Commission · EU Kids Act
Moderate
Guidance
Published
France · Oct 2, 2026
CNIL explains when data‑breach victims can claim compensation under the GDPR
The CNIL outlines that individuals can seek damages only if a GDPR breach caused a real material or moral injury, and they can prove a causal link. Compensation is awarded by a judge, not the CNIL, and the regulator may only impose…
CNIL · RGPD