REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: data minimization · clear
44 developments
Moderate Executive order Signed United States (federal) · Oct 9, 2026
President Trump issues executive order creating federal voter eligibility list
In March 2026, President Trump issued an executive order directing DHS to compile a list of U.S. citizens 18 years or older and directing DOJ to prosecute officials who provide ballots to ineligible voters. The order has been challenged by…
Privacy Act of 1974
High Fine Decided Italy · Oct 9, 2026
Italian DPA fines Emirates €180,000 for health data infringements
The Italian Data Protection Authority imposed an administrative fine of EUR 180,000 on Emirates for violations of GDPR transparency and retention requirements concerning passengers' health data. Emirates was ordered to clarify which…
Italian Data Protection Authority · General Data Protection Regulation
Moderate Proposed regulation Proposed Vermont · Oct 8, 2026
Future of Privacy Forum submits comments on Vermont Age-Appropriate Design Code rulemaking
On October 2, 2026 the Future of Privacy Forum filed comments to the Vermont Attorney General’s rulemaking for the Age-Appropriate Design Code. The act, enacted in June 2025, sets duties for businesses serving minors and will become…
Vermont Office of the Attorney General · California Age-Appropriate Design Code Act
Moderate Proposed regulation Proposed France · Oct 8, 2026
CNIL examines draft deliberation authorizing BIG DATA SANTE to process personal data for anonymized medical research (ONCOVAL)
During its plenary session on 8 October 2026, the CNIL will consider a draft deliberation that would permit BIG DATA SANTE (Octopize Mimethik Data) to carry out automated processing of personal data to create anonymised datasets for…
Commission nationale de l'informatique et des libertés (CNIL) · Law of 6 January 1978
Moderate Enforcement Decided France · Oct 8, 2026
CNIL closes injunction against FRANCE TRAVAIL after compliance with data security measures
The French data protection authority (CNIL) closed the injunction issued on 22 January 2026 against FRANCE TRAVAIL, after the organization demonstrated compliance with the security measures required by Article 32 of the GDPR. The original…
CNIL · RGPD
Moderate Guidance Published Spain · Oct 8, 2026
AEPD publishes second issue of scientific journal “Privacy, Innovation and Technology”
The Spanish Data Protection Agency released the second issue of its scientific journal PIT, dedicated to the 10th anniversary of the GDPR. The monograph examines proactive responsibility, the right to explanation in automated decisions…
Agencia Española de Protección de Datos (AEPD) · Reglamento General de Protección de Datos (RGPD)
Moderate Proposed regulation Proposed United States (federal) · Oct 7, 2026
DEA proposes to modify and republish its Aviation Division system of records notice
The Drug Enforcement Administration (DEA) announced a proposal to update the system of records notice for its Aviation Division, changing the categories of individuals covered, record categories, purpose, routine uses, and storage…
Justice Department · Privacy Act of 1974
High Enforcement Published Spain · Oct 6, 2026 · effective Oct 6, 2026
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The Spanish Data Protection Agency (AEPD) sent preventive warnings (AI‑00170‑2026 and AI‑00171‑2026) to two local councils regarding planned video‑surveillance systems that use automated image analysis with AI. The agency stresses that the…
Agencia Española de Protección de Datos · Reglamento General de Protección de Datos
Low FRAMEWORK UPDATE Announced Global · Oct 5, 2026
Future of Privacy Forum urges standardized privacy benchmarks for frontier AI systems
The paper argues that standardized privacy benchmarks are needed to evaluate privacy risks in frontier AI models, including data memorization, inference of sensitive attributes, and over‑collection. It describes emerging efforts such as…
Low Lawsuit filed Filed United States (federal) · Oct 2, 2026
EPIC files amicus brief challenging Spirit Airlines' bankruptcy sale of employee data to Google
EPIC and Professor Seema Patel submitted an amicus brief in a bankruptcy case to contest Spirit Airlines' proposed $10 million sale of employee data to Google for AI training. The brief argues the sale lacks adequate privacy protections…
Moderate Settlement Settled United States (federal) · Oct 2, 2026
Meta’s Muse AI Agent raises privacy, security, and child safety concerns amid past FTC consent decree
Meta launched the Muse personal AI agent in September 2026, which collects extensive personal data and can act without clear user permission. EPIC reports multiple incidents where Muse accessed messages, shared home addresses, and…
Federal Trade Commission
Low Court ruling In effect Utah · Oct 1, 2026
Federal judge blocks Utah's anti-VPN age‑verification law (SB 73) with preliminary injunction
A U.S. federal judge issued a preliminary injunction halting enforcement of Utah's SB 73, which required adult websites to block VPN users or determine their physical location for age verification. The court found the statute imposes a…
Utah SB 73
Low Guidance Announced United States (federal) · Oct 1, 2026
EFF launches Opt Out October campaign urging users to leave tech giants for privacy
The Electronic Frontier Foundation (EFF) released its annual Opt Out October campaign, encouraging individuals to regain control of their data by opting out of major platforms, apps, and operating systems. The initiative provides…
High Guidance Published France · Oct 1, 2026 · effective Oct 1, 2026
CNIL and Cybermalveillance.gouv.fr release guide for individuals on personal data breach response
The French data protection authority (CNIL) and Cybermalveillance.gouv.fr have published a practical support document titled “Violation de données personnelles, que faire en 3 étapes clés ?”. The guide provides a three‑step checklist for…
CNIL
Low Guidance Published United States (federal) · Sep 30, 2026
EFF discusses privacy implications of Apple Siri AI features in iOS 27
The EFF newsletter examines how Apple’s new Siri AI in iOS 27 handles user data. It contrasts on‑device processing with server‑side processing and explains the privacy risks. The piece offers guidance on limiting the data Siri can access.
Moderate Guidance Published United States (federal) · Sep 30, 2026
HUD modifies system of records notice for Inventory Management System and Housing Information Portal
The Department of Housing and Urban Development (HUD) Office of Public and Indian Housing is updating its system of records notice for the Inventory Management System and Housing Information Portal. The amendment adds three new routine…
Department of Housing and Urban Development · Privacy Act of 1974
Moderate Guidance Announced France · Sep 28, 2026
CNIL to host AIR 2026 event on political communication ethics and election manipulation on 16 Nov 2026
The French data‑protection authority CNIL will hold a public debate on 16 November 2026 about the ethical challenges of digital political communication and foreign interference. The programme will examine voter consent, data‑minimisation…
CNIL · RGPD
Moderate Guidance Published Ireland · Sep 28, 2026
Data Protection Commission releases AI Insights Report covering 2021‑2025 supervision
The Irish Data Protection Commission published a report on its supervision of AI products and services from 2021 to 2025, noting a rise in AI engagements and improvements in lawful basis, transparency and data‑minimisation. The report…
Data Protection Commission
High Guidance In effect United States (federal) · Sep 25, 2026 · effective Oct 26, 2026
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
The Peace Corps Office of Planning and Performance issued a public notice of a new system of records, the Peace Corps Customer Relationship Management (PC 38) system. The system will monitor, track, and analyze interactions with…
Peace Corps Office of Planning and Performance · Privacy Act of 1974
Moderate Proposed bill Proposed United States (federal) · Sep 24, 2026
State bills propose exemption for biometric data converted to irreversible mathematical representations
Several U.S. state privacy bills are introducing a new exception that excludes biometric data once it is transformed into an irreversible mathematical representation that cannot be used to recreate the original measurement. The proposed…
Illinois Biometric Information Privacy Act
Older →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13