REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: transparency · clear
29 developments
Moderate Guidance Published European Union · Sep 23, 2026
EU Commission hosts fifth roundtable on Digital Services Act implementation
On 23 September 2026 the European Commission held an online roundtable with about 60 civil society organisations and researchers to discuss the implementation of the Digital Services Act. The discussion focused on systemic risks…
European Commission · Digital Services Act
Moderate Fine Decided Spain · Sep 22, 2026 · effective Feb 1, 2023 · deadline Feb 1, 2024
Spanish DPA fines Securitas Direct €100,000 for charging phone line for data subject rights
The Spanish Data Protection Agency (AEPD) issued a final decision on 1 February 2023 finding Securitas Direct in breach of GDPR Article 12(2) by directing data subjects to a chargeable 902 telephone number to exercise their rights. The…
Spanish Data Protection Agency (AEPD) · General Data Protection Regulation
Moderate Proposed regulation Proposed European Union · Sep 21, 2026
EU Commission proposes KIDS Act to impose age‑based restrictions and safety‑by‑design for children online
On September 17, 2026 the European Commission published a proposal for a new EU KIDS Act that would ban users under 15 from creating accounts on certain social networking and video‑sharing services, with limited exceptions. The draft…
European Commission · Digital Services Act
Moderate Proposed regulation Proposed United States (federal) · Sep 18, 2026
EFF urges lawmakers to base AI cybersecurity rules on established best practices
The EFF recommends that any new AI cybersecurity legislation focus on proven security measures such as sandboxing, monitoring, and logging to mitigate risks demonstrated by recent AI lab incidents. It calls for minimum safety requirements…
Moderate Proposed regulation Announced France · Sep 17, 2026
CNIL plenary agenda includes draft decrees on prison camera use, Apple ATT, and data collection in real‑estate rentals
The CNIL plenary session of 17 September 2026 will discuss a draft decree on the use of on‑board cameras by prison surveillance staff, a draft decree amending the 2019 decree that implements the French data protection law, and a…
Commission nationale de l'informatique et des libertés (CNIL) · décret n° 2019-536 du 29 mai 2019
High Enforcement Settled United States (federal) · Sep 17, 2026
FleetCor to Pay $100M to Settle FTC Administrative Action Over Unauthorized Fuel Card Fees
The Federal Trade Commission alleged that FleetCor, now operating as Corpay, charged small‑business customers hidden fees and misrepresented savings from its fuel cards. The company agreed to pay $100 million to resolve the FTC…
Federal Trade Commission · FTC Act Section 5
Moderate FRAMEWORK UPDATE Published European Union · Sep 17, 2026 · effective Aug 2, 2026
EU AI Board discusses AI Act implementation and publishes Action Plan on cybersecurity and AI
On 17 September 2026 the EU AI Board met under the Irish Presidency to review priorities for EU AI policy and AI Act enforcement. The meeting included an update on the Commission’s Action Plan on cybersecurity and AI and on transparency…
European Commission · EU AI Act
Low Guidance Announced United States (federal) · Sep 16, 2026
EPIC report finds companies hinder personal data access under state privacy laws
The Electronic Privacy Information Center reports that many large firms make it difficult for consumers to obtain their personal data, despite state privacy statutes. EPIC notes that small fines and warning letters often have limited…
High Fine Decided France · Sep 11, 2026 · effective Jul 21, 2026
CNIL fines French IT firm EXTIA €300,000 for failing to honor data erasure requests
In 2024 EXTIA received 265 requests for erasure, many of which were not processed or not communicated to the requesters. The CNIL audit found breaches of Articles 12 and 17 GDPR regarding transparency and the right to erasure. The CNIL…
CNIL · General Data Protection Regulation
← Newer
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13