REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
212 developments
Moderate Proposed bill Passed California · Sep 14, 2026 · effective Jan 1, 2027
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
On August 28, 2026 the California Legislature passed SB 690, a bill that would eliminate private lawsuits for website-based pen register claims under the California Invasion of Privacy Act. The bill would restrict such claims to actions…
California Attorney General · California Invasion of Privacy Act (CIPA)
Moderate Investigation Announced United States (federal) · Sep 14, 2026
Police misuse ALPR data with frivolous reasons, EFF finds
EFF analysis of Flock Safety ALPR logs shows officers across the United States entering nonsensical reasons such as "LOL", "LMAO" and "idk" to access vehicle location data. The lack of warrant requirements and weak audit controls enables…
CPPA · California Delete Act
Low New law Signed California · Sep 11, 2026
California Governor signs AB 2071 and AB 2298 to add digital literacy and cybersecurity to school curricula
Governor Newsom signed a package of 12 bills, including AB 2071 and AB 2298, that require digital wellness and cybersecurity education in California schools. The bills aim to protect children online through education rather than bans.
AB 2071
Low Guidance Published United States (federal) · Sep 11, 2026
Amazon Ring's 'Throw Away the Key Encryption' adds limited privacy but falls short of true end‑to‑end encryption
Amazon introduced the Throw Away the Key Encryption (TAKE) feature for Ring cameras, where encryption keys are held temporarily in the cloud and deleted after 24 hours. The system still allows Ring to decrypt footage for cloud‑based…
Low Enforcement Announced New Jersey · Sep 11, 2026
Cameras capture alleged vandal in Morristown SafetyStick pilot
EPIC senior counsel Jeramie D. Scott said the community should be informed before any surveillance technology is deployed. Cameras in the Morristown SafetyStick pilot captured an alleged camera vandal. Scott warned that surveillance can be…
Moderate Final regulation In effect European Union · Sep 11, 2026 · effective Sep 11, 2026
EU Cyber Resilience Act reporting obligations take effect for manufacturers
As of September 11, 2026, manufacturers of products with digital elements are subject to new incident reporting obligations under the EU Cyber Resilience Act. The obligations require manufacturers to report cybersecurity incidents related…
European Commission · Cyber Resilience Act
Moderate Guidance Announced European Union · Sep 11, 2026
ENISA launches Single Reporting Platform for Cyber Resilience Act reporting
ENISA has deployed the initial operating capability of the Single Reporting Platform (SRP) to support the Cyber Resilience Act (CRA) reporting obligations. From 11 September 2026 manufacturers and open‑source software stewards must report…
ENISA · Cyber Resilience Act
High Fine Decided France · Sep 11, 2026 · effective Jul 21, 2026
CNIL fines French IT firm EXTIA €300,000 for failing to honor data erasure requests
In 2024 EXTIA received 265 requests for erasure, many of which were not processed or not communicated to the requesters. The CNIL audit found breaches of Articles 12 and 17 GDPR regarding transparency and the right to erasure. The CNIL…
CNIL · General Data Protection Regulation
Moderate New law Signed California · Sep 10, 2026
California AB 1709, a ban on social media for under‑16, signed into law
AB 1709 was signed into law by Governor Gavin Newsom. The law imposes a functional ban on social media use for people under the age of 16 and requires age‑verification. Critics say the ban will increase data collection and limit free…
AB 1709
Moderate Fine Announced Netherlands · Sep 10, 2026
Dutch DPA fines Uber €824,990,000 for automated decisions affecting drivers
On August 21, 2026, the Dutch Data Protection Authority announced it had fined Uber €824,990,000 for breaching the EU GDPR rules on solely automated decision‑making. The fine targets Uber's use of automated systems that affect driver…
Dutch Data Protection Authority · General Data Protection Regulation
Moderate Proposed regulation Proposed France · Sep 10, 2026
CNIL to examine draft deliberation on finance bill 2027 provisions for online platform content collection for tax purposes
The CNIL plenary session on 10 September 2026 will examine a draft deliberation giving an opinion on provisions of the 2027 finance bill that would perpetuate the collection and exploitation of content from online platforms for tax…
Commission nationale de l'informatique et des libertés (CNIL) · projet de loi de finances pour 2027
Moderate Guidance In effect France · Sep 10, 2026 · effective Sep 1, 2026
CNIL guidance on data‑protection obligations under the electronic invoicing reform effective 1 Sept 2026
The CNIL explains the data‑protection implications of the French electronic invoicing reform that entered into force on 1 Sept 2026. It details which personal data may be processed, the roles of issuers, receivers and certified platforms…
CNIL · réforme relative à la facturation électronique
Moderate Guidance Published France · Sep 10, 2026
CNIL releases Volume 2 of “L’Agence Privacy” to educate adolescents on cybercrime and data privacy
On 10 September 2026 the French data‑protection authority CNIL published the second volume of its educational comic series “L’Agence Privacy”. The free online and paper resource targets teenagers and parents, covering risks such as…
CNIL
Low Enforcement Announced Germany · Sep 10, 2026
noyb to file injunction against SCHUFA over shadow database
noyb sent a cease-and-desist letter to SCHUFA demanding the removal of its shadow database. SCHUFA's deadline to comply has expired and the agency has rejected the allegations. noyb announced it will now file an injunction and invites…
Moderate Proposed regulation Proposed European Union · Sep 10, 2026
EU Commission proposes Article 88b for automated privacy signals in Digital Omnibus
The European Commission, as part of the Digital Omnibus package, proposed legally binding automated privacy signals under Article 88b of the GDPR to replace cookie banners. The proposal would let users set their privacy preferences once…
European Commission · California Delete Act
Low Court ruling Decided United States (federal) · Sep 9, 2026
2015 court ruling requires warrant for police use of stingray devices
A Baltimore judge concluded that law enforcement hid its use of a Stingray device by using a pen register order, violating disclosure obligations. The decision resulted in a landmark 2015 privacy ruling that police must obtain a warrant to…
Low Guidance Announced Global · Sep 9, 2026
EFF blog outlines digital sovereignty and its impact on privacy, data control and security
The post explains that digital sovereignty refers to the ability of individuals, nations and organizations to control their digital destiny, including data, technology and infrastructure. It highlights policy discussions in Europe and…
Low Guidance Announced Global · Sep 9, 2026
EFF Announces 2026 Award Winners: Access Now, 7amleh, DeFlock, New Media Rights
The Electronic Frontier Foundation announced that Access Now, 7amleh – The Arab Center for the Advancement of Social Media, DeFlock, and New Media Rights received the 2026 EFF Awards. The award recognizes their work defending digital…
Moderate Enforcement Announced Spain · Sep 9, 2026
AEPD opens investigation into Ministry of Interior report listing journalists and political leanings
The Spanish Data Protection Agency announced it will launch a formal, ex officio investigation into a Ministry of Interior communication office report that includes journalists' names and alleged political ideologies. The probe will…
Agencia Española de Protección de Datos · Reglamento General de Protección de Datos (RGPD)
Moderate Guidance Repealed United States (federal) · Sep 9, 2026 · effective Sep 9, 2026
FTC rescinds 2021 Policy Statement on Breaches by Health Apps and Connected Devices
The Federal Trade Commission announced it is rescinding the 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. The guidance is deemed obsolete and is being withdrawn. The rescission was published on 2026-09-09.
Federal Trade Commission
← NewerOlder →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13