REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: profiling · clear
32 developments
Moderate Guidance Published United States (federal) · Sep 16, 2026
EPIC report: Data brokers sell personal data to Disney, GM, insurers and banks
EPIC highlights that data brokers collect and sell personal information to major companies such as Disney, General Motors, insurers and banks. The article notes that brokers infer additional characteristics like finance, health…
Moderate Guidance Published KE · Sep 16, 2026
Kenya publishes new guidance on cross‑border data transfers
On 8 September 2026 Kenya’s Office of the Data Protection Commissioner released detailed Guidance Notes on cross‑border data transfers. The guidance clarifies Kenya’s transfer framework, adds operational detail, and highlights differences…
Office of the Data Protection Commissioner (ODPC) · General Data Protection Regulation
Moderate Proposed bill Announced European Union · Sep 14, 2026
EU Commission to propose EU-wide minimum age for social media, linked to Digital Fairness Act
The European Commission will release a legislative proposal by the end of 2026 establishing an EU-wide minimum age for social media, building on the Special Panel's age‑tiered framework. The proposal may be incorporated into the Digital…
European Commission · Digital Services Act
Moderate Investigation Announced United States (federal) · Sep 14, 2026
Police misuse ALPR data with frivolous reasons, EFF finds
EFF analysis of Flock Safety ALPR logs shows officers across the United States entering nonsensical reasons such as "LOL", "LMAO" and "idk" to access vehicle location data. The lack of warrant requirements and weak audit controls enables…
CPPA · California Delete Act
Low Enforcement Announced Germany · Sep 10, 2026
noyb to file injunction against SCHUFA over shadow database
noyb sent a cease-and-desist letter to SCHUFA demanding the removal of its shadow database. SCHUFA's deadline to comply has expired and the agency has rejected the allegations. noyb announced it will now file an injunction and invites…
High Amendment Signed Delaware · Sep 3, 2026 · effective Jan 1, 2027
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Governor Meyer signed HB 380 on September 2, amending the Delaware Personal Data Privacy Act. The amendment expands the definition of sensitive data, lowers applicability thresholds, adds new contractual and due‑diligence requirements for…
CFPB · Fair Credit Reporting Act
Moderate Court ruling Decided Austria · Sep 1, 2026
Austrian Supreme Court rules CRIF’s use of address‑publisher data for credit scoring violates GDPR purpose limitation
The Austrian Supreme Court (OGH) held that credit reference agencies may not collect personal data from address publishers that process the data for marketing purposes, confirming a GDPR purpose‑limitation breach. The ruling supports…
EDPB · General Data Protection Regulation
Moderate Proposed bill Passed one chamber California · Aug 31, 2026
California Assembly Bill 1709 passed, bans social media recommendation features for users under 16
The California legislature passed Assembly Bill 1709, which would prohibit platforms from providing recommendation algorithms and related features to users under 16. The bill would require age‑verification methods that could involve…
AB 1709
Low Proposed regulation Proposed BR · Aug 28, 2026
EFF and allies recommend new privacy safeguards to protect Brazil's electoral integrity
The Electronic Frontier Foundation, Access Now and Data Privacy Brasil issued recommendations urging stronger personal data protection in Brazil's elections. They call for prohibiting processing of sensitive political data, requiring…
LGPD
Low Enforcement Announced Germany · Aug 26, 2026 · effective Aug 26, 2026
noyb sends cease‑and‑desist letter to SCHUFA over alleged ‘shadow database’ GDPR violations
In July 2026, the NGO noyb issued a cease‑and‑desist letter to German credit agency SCHUFA demanding it stop storing data beyond retention periods and provide full historical data under Article 15 GDPR. The organization warned it will seek…
EDPB · General Data Protection Regulation
Low Investigation Announced Global · Aug 19, 2026
EFF report finds mobile ad libraries may leak user location data
EFF released a new report highlighting how mobile ad libraries can cause apps to unintentionally expose users' location information. The investigation notes that this leakage can reveal intimate details about individuals and be exploited…
Low Enforcement Filed Austria · Jul 30, 2026
noyb files GDPR complaint against dict.cc over 1,741‑partner consent banner
noyb lodged a complaint with the Austrian Data Protection Authority alleging that dict.cc’s cookie banner forces users to consent to tracking by 1,741 partner companies with a single click, violating GDPR consent requirements. The…
Austrian Data Protection Authority · General Data Protection Regulation
← Newer
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13