REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
148 developments
Moderate Proposed bill Passed California · Sep 14, 2026 · effective Jan 1, 2027
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
On August 28, 2026 the California Legislature passed SB 690, a bill that would eliminate private lawsuits for website-based pen register claims under the California Invasion of Privacy Act. The bill would restrict such claims to actions…
California Attorney General · California Invasion of Privacy Act (CIPA)
Moderate Investigation Announced United States (federal) · Sep 14, 2026
Police misuse ALPR data with frivolous reasons, EFF finds
EFF analysis of Flock Safety ALPR logs shows officers across the United States entering nonsensical reasons such as "LOL", "LMAO" and "idk" to access vehicle location data. The lack of warrant requirements and weak audit controls enables…
CPPA · California Delete Act
Low New law Signed California · Sep 11, 2026
California Governor signs AB 2071 and AB 2298 to add digital literacy and cybersecurity to school curricula
Governor Newsom signed a package of 12 bills, including AB 2071 and AB 2298, that require digital wellness and cybersecurity education in California schools. The bills aim to protect children online through education rather than bans.
AB 2071
Low Guidance Published United States (federal) · Sep 11, 2026
Amazon Ring's 'Throw Away the Key Encryption' adds limited privacy but falls short of true end‑to‑end encryption
Amazon introduced the Throw Away the Key Encryption (TAKE) feature for Ring cameras, where encryption keys are held temporarily in the cloud and deleted after 24 hours. The system still allows Ring to decrypt footage for cloud‑based…
Low Enforcement Announced New Jersey · Sep 11, 2026
Cameras capture alleged vandal in Morristown SafetyStick pilot
EPIC senior counsel Jeramie D. Scott said the community should be informed before any surveillance technology is deployed. Cameras in the Morristown SafetyStick pilot captured an alleged camera vandal. Scott warned that surveillance can be…
Moderate Final regulation In effect European Union · Sep 11, 2026 · effective Sep 11, 2026
EU Cyber Resilience Act reporting obligations take effect for manufacturers
As of September 11, 2026, manufacturers of products with digital elements are subject to new incident reporting obligations under the EU Cyber Resilience Act. The obligations require manufacturers to report cybersecurity incidents related…
European Commission · Cyber Resilience Act
Moderate Guidance Announced European Union · Sep 11, 2026
ENISA launches Single Reporting Platform for Cyber Resilience Act reporting
ENISA has deployed the initial operating capability of the Single Reporting Platform (SRP) to support the Cyber Resilience Act (CRA) reporting obligations. From 11 September 2026 manufacturers and open‑source software stewards must report…
ENISA · Cyber Resilience Act
High Fine Decided France · Sep 11, 2026 · effective Jul 21, 2026
CNIL fines French IT firm EXTIA €300,000 for failing to honor data erasure requests
In 2024 EXTIA received 265 requests for erasure, many of which were not processed or not communicated to the requesters. The CNIL audit found breaches of Articles 12 and 17 GDPR regarding transparency and the right to erasure. The CNIL…
CNIL · General Data Protection Regulation
← Newer
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13