High
Proposed regulation
Proposed
United States (federal) · Oct 13, 2026 · effective Oct 13, 2026
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
The Federal Housing Finance Agency (FHFA) announced a proposal to rescind the existing System of Records Notice (SORN) FHFA-12, which covers parking program records. The agency will consolidate those records with its transit subsidy…
Federal Housing Finance Agency · Privacy Act of 1974
Moderate
Guidance
Published
France · Oct 9, 2026
CNIL hosts 2nd Rencontres Informatique & Libertés on connected glasses and data‑sanctions
The French data‑protection authority CNIL held its second Rencontres Informatique & Libertés on 29 September 2026, featuring panels on the privacy impact of connected glasses and the role of sanctions under the GDPR. The event gathered…
CNIL · RGPD
High
Data protection authority action
Decided
Italy · Oct 9, 2026 · effective Sep 23, 2026
Italian DPA fines IQVIA €7 million for unlawful processing of patients’ health data
The Italian Data Protection Authority imposed an administrative fine of EUR 7,000,000 on IQVIA Solutions Italy S.r.l. for processing health data without a legal basis, inadequate information to patients, and missing DPIA and retention…
Italian Data Protection Authority · General Data Protection Regulation
Moderate
Guidance
Announced
European Union · Oct 9, 2026
Commission holds special meeting of Scientific Panel on frontier AI safety and risks
The European Commission convened a special meeting of the Scientific Panel on AI, which includes 60 independent experts. The panel advises the EU AI Office and national authorities on systemic risks, model classification, evaluation…
European Commission · EU AI Act
Low
Proposed regulation
Announced
United States (federal) · Oct 9, 2026
CISA submits Final CIRCIA Rule to OIRA for interagency review
On October 1, 2026, CISA submitted a draft of the Final Rule implementing the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) to OIRA. CIRCIA will require covered critical‑infrastructure entities to report…
Cybersecurity and Infrastructure Security Agency (CISA) · Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA)
Low
Interpretation
Published
Global · Oct 8, 2026
EFF warns age‑verification laws risk excluding people without ID
The EFF analysis highlights a global surge in mandatory age‑verification requirements for social‑media and other digital services, citing laws in Australia, India, the United Kingdom, and many U.S. states. It argues that ID‑based checks…
Online Safety Act
Moderate
Fine
Decided
Sweden · Oct 8, 2026
Swedish DPA fines Miljödata approx EUR 160,000 for insufficient security measures
The Swedish Data Protection Authority (IMY) imposed an administrative fine of SEK 1,800,000 (≈ EUR 160,000) on IT service provider Miljödata i Karlskrona for violating Article 32(1) GDPR. The authority found the company lacked adequate…
Swedish Data Protection Authority (IMY) · General Data Protection Regulation
High
Data protection authority action
Decided
Greece · Oct 8, 2026
Hellenic DPA fines Ministry and EETAA for data breach
The Hellenic Data Protection Authority issued a final decision on 28/07/2026 imposing administrative fines of EUR 200,000 on the Ministry of Social Cohesion and Family Affairs and EUR 150,000 on E.E.T.A.A. S.A. for security deficiencies.…
Hellenic Data Protection Authority · General Data Protection Regulation
Moderate
Enforcement
Decided
France · Oct 8, 2026
CNIL closes injunction against FRANCE TRAVAIL after compliance with data security measures
The French data protection authority (CNIL) closed the injunction issued on 22 January 2026 against FRANCE TRAVAIL, after the organization demonstrated compliance with the security measures required by Article 32 of the GDPR. The original…
CNIL · RGPD
Moderate
Guidance
Published
Spain · Oct 8, 2026
AEPD publishes second issue of scientific journal “Privacy, Innovation and Technology”
The Spanish Data Protection Agency released the second issue of its scientific journal PIT, dedicated to the 10th anniversary of the GDPR. The monograph examines proactive responsibility, the right to explanation in automated decisions…
Agencia Española de Protección de Datos (AEPD) · Reglamento General de Protección de Datos (RGPD)
Moderate
Proposed regulation
Proposed
United States (federal) · Oct 7, 2026
DOJ proposes exemption for Firearms Rights Restoration Electronic Records Database from Privacy Act provisions
The Office of the Pardon Attorney within the U.S. Department of Justice announced a notice of a new system of records called the Firearms Rights Restoration Electronic Records Database (FRRERD). The agency proposes to exempt this system…
U.S. Department of Justice · Privacy Act of 1974
High
Enforcement
Published
Spain · Oct 6, 2026 · effective Oct 6, 2026
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The Spanish Data Protection Agency (AEPD) sent preventive warnings (AI‑00170‑2026 and AI‑00171‑2026) to two local councils regarding planned video‑surveillance systems that use automated image analysis with AI. The agency stresses that the…
Agencia Española de Protección de Datos · Reglamento General de Protección de Datos
High
Final regulation
Announced
United States (federal) · Oct 6, 2026 · effective Nov 5, 2026
Treasury exempts new tip intake records from certain Privacy Act provisions
The Department of the Treasury issued a final rule exempting the system of records titled "Treasury .032--Federal Program Waste, Fraud, and Abuse Tip Intake and Referral Records" from specific provisions of the Privacy Act of 1974. The…
Department of the Treasury · Privacy Act of 1974
Low
FRAMEWORK UPDATE
Announced
Global · Oct 5, 2026
Future of Privacy Forum urges standardized privacy benchmarks for frontier AI systems
The paper argues that standardized privacy benchmarks are needed to evaluate privacy risks in frontier AI models, including data memorization, inference of sensitive attributes, and over‑collection. It describes emerging efforts such as…
Moderate
Guidance
Published
United States (federal) · Oct 5, 2026
EPIC analysis links pixel‑tracking litigation under ECPA and CIPA to upcoming Supreme Court VPPA case
EPIC outlines how recent court decisions using the Electronic Communications Privacy Act (ECPA) and California Invasion of Privacy Act (CIPA) address non‑consensual pixel tracking and its privacy harms. The analysis cites multiple…
HHS OCR · HIPAA Privacy, Security and Breach Notification Rules