Moderate
Proposed bill
Passed
California · Sep 14, 2026 · effective Jan 1, 2027
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
On August 28, 2026 the California Legislature passed SB 690, a bill that would eliminate private lawsuits for website-based pen register claims under the California Invasion of Privacy Act. The bill would restrict such claims to actions…
California Attorney General · California Invasion of Privacy Act (CIPA)
Moderate
Investigation
Announced
United States (federal) · Sep 14, 2026
Police misuse ALPR data with frivolous reasons, EFF finds
EFF analysis of Flock Safety ALPR logs shows officers across the United States entering nonsensical reasons such as "LOL", "LMAO" and "idk" to access vehicle location data. The lack of warrant requirements and weak audit controls enables…
CPPA · California Delete Act
Low
New law
Signed
California · Sep 11, 2026
California Governor signs AB 2071 and AB 2298 to add digital literacy and cybersecurity to school curricula
Governor Newsom signed a package of 12 bills, including AB 2071 and AB 2298, that require digital wellness and cybersecurity education in California schools. The bills aim to protect children online through education rather than bans.
AB 2071
Low
Guidance
Published
United States (federal) · Sep 11, 2026
Amazon Ring's 'Throw Away the Key Encryption' adds limited privacy but falls short of true end‑to‑end encryption
Amazon introduced the Throw Away the Key Encryption (TAKE) feature for Ring cameras, where encryption keys are held temporarily in the cloud and deleted after 24 hours. The system still allows Ring to decrypt footage for cloud‑based…
Low
Enforcement
Announced
New Jersey · Sep 11, 2026
Cameras capture alleged vandal in Morristown SafetyStick pilot
EPIC senior counsel Jeramie D. Scott said the community should be informed before any surveillance technology is deployed. Cameras in the Morristown SafetyStick pilot captured an alleged camera vandal. Scott warned that surveillance can be…
Moderate
Final regulation
In effect
European Union · Sep 11, 2026 · effective Sep 11, 2026
EU Cyber Resilience Act reporting obligations take effect for manufacturers
As of September 11, 2026, manufacturers of products with digital elements are subject to new incident reporting obligations under the EU Cyber Resilience Act. The obligations require manufacturers to report cybersecurity incidents related…
European Commission · Cyber Resilience Act
Moderate
Guidance
Announced
European Union · Sep 11, 2026
ENISA launches Single Reporting Platform for Cyber Resilience Act reporting
ENISA has deployed the initial operating capability of the Single Reporting Platform (SRP) to support the Cyber Resilience Act (CRA) reporting obligations. From 11 September 2026 manufacturers and open‑source software stewards must report…
ENISA · Cyber Resilience Act
High
Fine
Decided
France · Sep 11, 2026 · effective Jul 21, 2026
CNIL fines French IT firm EXTIA €300,000 for failing to honor data erasure requests
In 2024 EXTIA received 265 requests for erasure, many of which were not processed or not communicated to the requesters. The CNIL audit found breaches of Articles 12 and 17 GDPR regarding transparency and the right to erasure. The CNIL…
CNIL · General Data Protection Regulation