REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
72 developments
Moderate Guidance Announced United States (federal) · Sep 29, 2026
FCC and USAC launch new computer matching program to verify Lifeline eligibility
The Federal Communications Commission and the Universal Service Administrative Company will conduct a computer matching program with the Connecticut Department of Social Services. The program is intended to verify the eligibility of…
Federal Communications Commission · Privacy Act of 1974
Moderate Guidance Proposed United States (federal) · Sep 29, 2026
Agency seeks comment on proposed information collection for protection of human subjects
The agency announced a proposed collection of information related to the protection of human subjects and Institutional Review Boards and is requesting public comment. The notice also notes that programmatic access to FederalRegister.gov…
Food and Drug Administration · Paperwork Reduction Act of 1995
Moderate Guidance Announced France · Sep 28, 2026
CNIL to host AIR 2026 event on political communication ethics and election manipulation on 16 Nov 2026
The French data‑protection authority CNIL will hold a public debate on 16 November 2026 about the ethical challenges of digital political communication and foreign interference. The programme will examine voter consent, data‑minimisation…
CNIL · RGPD
Moderate Guidance Published Ireland · Sep 28, 2026
Data Protection Commission releases AI Insights Report covering 2021‑2025 supervision
The Irish Data Protection Commission published a report on its supervision of AI products and services from 2021 to 2025, noting a rise in AI engagements and improvements in lawful basis, transparency and data‑minimisation. The report…
Data Protection Commission
Moderate Guidance Published European Union · Sep 28, 2026
ENISA launches podcast series on Frontier AI and publishes guidance note on cybersecurity in the Frontier AI era
ENISA announced a new podcast series to discuss the latest cybersecurity developments, with the first episode focusing on Frontier AI. In July 2026 the agency also published a note providing recommendations for national authorities and EU…
ENISA
High Interpretation Published European Union · Sep 28, 2026
Commission designates ChatGPT, Reddit, Roblox as VLOPs/VLOSE under the Digital Services Act
The European Commission has designated ChatGPT as a Very Large Online Search Engine and Reddit and Roblox as Very Large Online Platforms under the DSA, citing each service’s reach of at least 45 million EU monthly users. The designated…
European Commission · Digital Services Act
Moderate Guidance Published United States (federal) · Sep 28, 2026
Federal Register restricts automated scraping, requires CAPTCHA and API use
The Federal Register warns that aggressive automated scraping of its sites is limited to access via developer APIs. Human users must complete a CAPTCHA to continue, and may be asked to do so repeatedly as a security measure.
Department of Defense · Privacy Act of 1974
Moderate Guidance Published United States (federal) · Sep 25, 2026
DoD updates SORN for DON Child and Youth Program to align with cybersecurity policies
The Department of Defense is modifying and reissuing the system of records titled "DON Child and Youth Program" (NM01754-3) under the Privacy Act of 1974. The updates incorporate DoD standard routine uses A through J, expand the collection…
Department of Defense · Privacy Act of 1974
Moderate Guidance Published United States (federal) · Sep 25, 2026
CMS re-establishes matching program with Treasury's Do Not Pay Working System under Privacy Act
The Centers for Medicare & Medicaid Services announced the re-establishment of a data matching program with the Do Not Pay Working System, administered by the Treasury's Bureau of Fiscal Service. The notice cites subsection (e)(12) of the…
U.S. Department of Health and Human Services, Centers for Medicare & Medicaid Services · Privacy Act of 1974
High Guidance In effect United States (federal) · Sep 25, 2026 · effective Oct 26, 2026
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
The Peace Corps Office of Planning and Performance issued a public notice of a new system of records, the Peace Corps Customer Relationship Management (PC 38) system. The system will monitor, track, and analyze interactions with…
Peace Corps Office of Planning and Performance · Privacy Act of 1974
Moderate Guidance Announced United States (federal) · Sep 24, 2026
DraftKings uses AI to target losing gamblers with online behavioral advertising
DraftKings employs AI and machine learning on customers' betting records to identify likely losing gamblers and serve them targeted promotions. The practice exemplifies online behavioral advertising that leverages first‑party data to…
Moderate Guidance Published United States (federal) · Sep 24, 2026
SBA seeks comments on modified matching program under Privacy Act
The U.S. Small Business Administration issued a Federal Register notice requesting public comment on a Privacy Act notice for a revised computer‑matching program. The program will compare SBA benefits records with the Treasury Department’s…
U.S. Small Business Administration · Privacy Act of 1974
Moderate Guidance Published European Union · Sep 23, 2026
EDPB adopts guidelines on GDPR fines and DSA interaction (17 Sep 2026)
On 17 September 2026 the European Data Protection Board adopted guidelines on the use of administrative fines by data protection authorities and finalised guidance on the interaction between the Digital Services Act (DSA) and the GDPR. The…
European Data Protection Board (EDPB) · Digital Services Act
Moderate Guidance Published European Union · Sep 23, 2026
EU Commission hosts fifth roundtable on Digital Services Act implementation
On 23 September 2026 the European Commission held an online roundtable with about 60 civil society organisations and researchers to discuss the implementation of the Digital Services Act. The discussion focused on systemic risks…
European Commission · Digital Services Act
Moderate Guidance Announced United States (federal) · Sep 22, 2026
WBUR reports driver’s license data appearing on dark web, raising AI‑enabled fraud risks
WBUR discussed a breach where images of driver’s licenses have been posted on the dark web. The episode highlighted risks of new account fraud, especially when combined with AI tools that can synthesize voice, images, or video. It also…
Low Interpretation Published EU-GB · Sep 22, 2026
London faces privacy pushback against smart glasses, EPIC warns
The article reports growing public concern in London over smart glasses that can record video. EPIC's AI and Human Rights director Calli Shroeder says solving privacy problems will be difficult and warns of fear of being left behind in the…
Low Interpretation Published United States (federal) · Sep 22, 2026
EPIC and Consumer Federation issue pamphlet defining surveillance pricing
The Electronic Privacy Information Center and the Consumer Federation of America released an 11‑page pamphlet that provides clearly defined terms for surveillance pricing, a practice the groups condemn. The release follows the FTC’s recent…
Federal Trade Commission
Low Guidance Announced Global · Sep 22, 2026
Future of Privacy Forum opens nominations for 17th Annual Privacy Papers for Policymakers Awards
The Future of Privacy Forum (FPF) announced that submissions for the 17th Privacy Papers for Policymakers Award are open until October 16, 2026. The award seeks privacy, AI‑governance, and youth‑online research that emphasizes data…
Moderate Guidance Published European Union · Sep 22, 2026 · effective Sep 22, 2026
ENISA releases 2026 Threat Landscape report highlighting AI-enabled cyber threats and supply‑chain risks
ENISA's 2026 Threat Landscape report analyses incidents from 1 January to 31 December 2025, noting a rise in ransomware, AI‑driven malicious activity, and supply‑chain attacks. The report finds public administration to be the most targeted…
ENISA · NIS2 Directive
Low Guidance Published Global · Sep 18, 2026
How to limit Siri AI access in iOS 27
Apple’s iOS 27 introduces a more powerful Siri AI that can access data from native and third‑party apps and may send information to Apple’s Private Cloud Compute. Users can mitigate privacy risks by disabling Siri, turning off app content…
← NewerOlder →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13