REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: transparency · clear
13 developments
Moderate Fine In effect Italy · Oct 9, 2026 · effective Aug 6, 2026
Italian DPA fines security firm €39,000 for employee data violations
The Italian Data Protection Authority (Garante) imposed a total administrative fine of EUR 39,000 on La Patria S.p.A. for failing to respond to employee access requests and for inadequate information about GPS‑derived geolocation data. The…
Garante – Italian Data Protection Authority · General Data Protection Regulation
High Fine Decided Italy · Oct 9, 2026
Italian DPA fines Emirates €180,000 for health data infringements
The Italian Data Protection Authority imposed an administrative fine of EUR 180,000 on Emirates for violations of GDPR transparency and retention requirements concerning passengers' health data. Emirates was ordered to clarify which…
Italian Data Protection Authority · General Data Protection Regulation
High Fine In effect Italy · Oct 9, 2026 · effective Jul 3, 2026
Italian DPA fines BBVA €5.508 million for ignoring customer objection to direct marketing
The Italian Data Protection Authority issued an administrative fine of €5,508,000 against BBVA's Italian branch for failing to honor a customer's right to object to direct marketing. The violation lasted seven months, during which the…
Italian Data Protection Authority · General Data Protection Regulation
High Fine Published Netherlands · Oct 8, 2026
Dutch DPA fines Uber €824.99 million for unlawful automated decision‑making
The Autoriteit Persoonsgegevens imposed an administrative fine of €824,990,000 on Uber for violating GDPR Article 22 by automatically deactivating drivers’ accounts and for failing to provide sufficient information under Article 13. The…
Autoriteit Persoonsgegevens · General Data Protection Regulation
High Enforcement Published Spain · Oct 6, 2026 · effective Oct 6, 2026
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The Spanish Data Protection Agency (AEPD) sent preventive warnings (AI‑00170‑2026 and AI‑00171‑2026) to two local councils regarding planned video‑surveillance systems that use automated image analysis with AI. The agency stresses that the…
Agencia Española de Protección de Datos · Reglamento General de Protección de Datos
Moderate Settlement Settled United States (federal) · Oct 2, 2026
Meta’s Muse AI Agent raises privacy, security, and child safety concerns amid past FTC consent decree
Meta launched the Muse personal AI agent in September 2026, which collects extensive personal data and can act without clear user permission. EPIC reports multiple incidents where Muse accessed messages, shared home addresses, and…
Federal Trade Commission
Moderate Enforcement Announced Bulgaria · Oct 1, 2026
European Commission sends formal notice to Bulgaria for non‑compliance with the Digital Services Act
The Commission issued a formal notice (INFR(2024)2241) to Bulgaria for failing to fully comply with the DSA, specifically for not designating and empowering the required Digital Services Coordinators. Bulgaria has two months to respond…
European Commission · Digital Services Act
Low Enforcement Published New York · Sep 30, 2026
NY Attorney General releases body‑worn camera footage of minor’s death investigation
New York Attorney General Letitia James released body‑worn camera footage from an investigation into the June 27, 2026 death of a minor in Dutchess County. The footage shows officers from NY State Police, Dutchess County Sheriff’s Office…
New York Attorney General's Office · New York State Executive Law Section 70-b
Moderate Enforcement Published Spain · Sep 23, 2026
Spanish Data Protection Agency issues warning to company over AI-driven resume screening
On 23 September 2026 the AEPD sent a formal warning to a company planning to use an AI tool for analysing CVs and assigning scores. The agency stresses that data protection must be built in from the start, including DPIA for high‑risk…
Agencia Española de Protección de Datos (AEPD) · Reglamento General de Protección de Datos (RGPD)
High Fine Decided Ireland · Sep 23, 2026 · effective Sep 21, 2026
Irish Data Protection Commission fines Google €403 million for GDPR violations over location data
The Irish Data Protection Commission issued its final decision on 21 September 2026, imposing administrative fines of €403 million on Google Ireland Limited. The DPC found infringements of GDPR principles relating to lawfulness, fairness…
Irish Data Protection Commission · General Data Protection Regulation
Moderate Fine Decided Spain · Sep 22, 2026 · effective Feb 1, 2023 · deadline Feb 1, 2024
Spanish DPA fines Securitas Direct €100,000 for charging phone line for data subject rights
The Spanish Data Protection Agency (AEPD) issued a final decision on 1 February 2023 finding Securitas Direct in breach of GDPR Article 12(2) by directing data subjects to a chargeable 902 telephone number to exercise their rights. The…
Spanish Data Protection Agency (AEPD) · General Data Protection Regulation
High Enforcement Settled United States (federal) · Sep 17, 2026
FleetCor to Pay $100M to Settle FTC Administrative Action Over Unauthorized Fuel Card Fees
The Federal Trade Commission alleged that FleetCor, now operating as Corpay, charged small‑business customers hidden fees and misrepresented savings from its fuel cards. The company agreed to pay $100 million to resolve the FTC…
Federal Trade Commission · FTC Act Section 5
High Fine Decided France · Sep 11, 2026 · effective Jul 21, 2026
CNIL fines French IT firm EXTIA €300,000 for failing to honor data erasure requests
In 2024 EXTIA received 265 requests for erasure, many of which were not processed or not communicated to the requesters. The CNIL audit found breaches of Articles 12 and 17 GDPR regarding transparency and the right to erasure. The CNIL…
CNIL · General Data Protection Regulation
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13