Low
Guidance
Announced
California · Oct 9, 2026
EFF joins Oakland Tech Week to discuss surveillance and AI impacts
The Electronic Frontier Foundation participated in Oakland Tech Week on Sept. 30, co‑presenting an all‑day event with MediaJustice and Upturn. Attendees discussed how technology can empower or oppress communities, focusing on surveillance…
Moderate
Guidance
Published
France · Oct 9, 2026
CNIL hosts 2nd Rencontres Informatique & Libertés on connected glasses and data‑sanctions
The French data‑protection authority CNIL held its second Rencontres Informatique & Libertés on 29 September 2026, featuring panels on the privacy impact of connected glasses and the role of sanctions under the GDPR. The event gathered…
CNIL · RGPD
Moderate
Guidance
Announced
European Union · Oct 9, 2026
Commission holds special meeting of Scientific Panel on frontier AI safety and risks
The European Commission convened a special meeting of the Scientific Panel on AI, which includes 60 independent experts. The panel advises the EU AI Office and national authorities on systemic risks, model classification, evaluation…
European Commission · EU AI Act
Low
Interpretation
Published
Global · Oct 8, 2026
EFF warns age‑verification laws risk excluding people without ID
The EFF analysis highlights a global surge in mandatory age‑verification requirements for social‑media and other digital services, citing laws in Australia, India, the United Kingdom, and many U.S. states. It argues that ID‑based checks…
Online Safety Act
Moderate
Guidance
Published
Spain · Oct 8, 2026
AEPD publishes second issue of scientific journal “Privacy, Innovation and Technology”
The Spanish Data Protection Agency released the second issue of its scientific journal PIT, dedicated to the 10th anniversary of the GDPR. The monograph examines proactive responsibility, the right to explanation in automated decisions…
Agencia Española de Protección de Datos (AEPD) · Reglamento General de Protección de Datos (RGPD)
Moderate
Guidance
Published
United States (federal) · Oct 5, 2026
EPIC analysis links pixel‑tracking litigation under ECPA and CIPA to upcoming Supreme Court VPPA case
EPIC outlines how recent court decisions using the Electronic Communications Privacy Act (ECPA) and California Invasion of Privacy Act (CIPA) address non‑consensual pixel tracking and its privacy harms. The analysis cites multiple…
HHS OCR · HIPAA Privacy, Security and Breach Notification Rules
Low
Guidance
Published
European Union · Oct 2, 2026
EDPB adopts Guidelines 04/2026 on GDPR fines and corrective powers for public consultation
The European Data Protection Board adopted Guidelines 04/2026 on the application of administrative fines and other corrective powers under the EU GDPR. The guidelines were released on September 17, 2026 for public consultation.
European Data Protection Board · General Data Protection Regulation
Moderate
Guidance
Published
France · Oct 2, 2026
CNIL explains when data‑breach victims can claim compensation under the GDPR
The CNIL outlines that individuals can seek damages only if a GDPR breach caused a real material or moral injury, and they can prove a causal link. Compensation is awarded by a judge, not the CNIL, and the regulator may only impose…
CNIL · RGPD
High
Guidance
In effect
United States (federal) · Oct 2, 2026 · effective Nov 2, 2026
DOI establishes new matching program under Privacy Act of 1974
The U.S. Department of the Interior announced a new matching program that will compare records from 20 DOI programs with the Treasury's Do Not Pay Working System. The program aims to verify prepayment or pre‑award eligibility, prevent…
U.S. Department of the Interior · Privacy Act of 1974
Low
Guidance
Announced
United States (federal) · Oct 1, 2026
EFF launches Opt Out October campaign urging users to leave tech giants for privacy
The Electronic Frontier Foundation (EFF) released its annual Opt Out October campaign, encouraging individuals to regain control of their data by opting out of major platforms, apps, and operating systems. The initiative provides…
High
Guidance
Published
France · Oct 1, 2026 · effective Oct 1, 2026
CNIL and Cybermalveillance.gouv.fr release guide for individuals on personal data breach response
The French data protection authority (CNIL) and Cybermalveillance.gouv.fr have published a practical support document titled “Violation de données personnelles, que faire en 3 étapes clés ?”. The guide provides a three‑step checklist for…
CNIL
Moderate
Guidance
Published
United States (federal) · Oct 1, 2026
Federal Register limits automated access; CAPTCHA required for flagged requests
The Federal Register website warns that programmatic requests are flagged as potentially automated and must complete a CAPTCHA to proceed. Users are directed to the FederalRegister.gov and eCFR.gov API documentation for legitimate…
Low
Guidance
Announced
United States (federal) · Sep 30, 2026 · effective Sep 9, 2026
FBI announces new Cyber Strategy emphasizing public‑private collaboration and rapid threat‑intel sharing
On September 9, 2026 the FBI published its Cyber Strategy, outlining four pillars that include investigating adversaries, supporting victims, and expanding partnerships. The strategy stresses the importance of private‑sector telemetry…
Federal Bureau of Investigation
Low
Guidance
Published
United States (federal) · Sep 30, 2026
EFF discusses privacy implications of Apple Siri AI features in iOS 27
The EFF newsletter examines how Apple’s new Siri AI in iOS 27 handles user data. It contrasts on‑device processing with server‑side processing and explains the privacy risks. The piece offers guidance on limiting the data Siri can access.
Moderate
Guidance
Published
United States (federal) · Sep 30, 2026
NHTSA seeks OMB approval to renew and modify information collection for qualitative feedback on service delivery
The National Highway Traffic Safety Administration (NHTSA) announced its intention to request Office of Management and Budget (OMB) approval to renew a currently approved information collection, adding annual tracking studies for…
National Highway Traffic Safety Administration (NHTSA) · Paperwork Reduction Act of 1995
Moderate
Guidance
Announced
United States (federal) · Sep 30, 2026
Commerce Department seeks input on digitizing and modernizing the National Technical Reports Library
The National Technical Information Service (NTIS) issued a Request for Information to gather stakeholder feedback on fully digitizing the National Technical Reports Library (NTRL). The agency aims to make the technical reports more…
National Technical Information Service
Moderate
Guidance
Published
United States (federal) · Sep 30, 2026
HUD modifies system of records notice for Inventory Management System and Housing Information Portal
The Department of Housing and Urban Development (HUD) Office of Public and Indian Housing is updating its system of records notice for the Inventory Management System and Housing Information Portal. The amendment adds three new routine…
Department of Housing and Urban Development · Privacy Act of 1974
Low
Guidance
Announced
California · Sep 29, 2026
San Francisco announces new ALPR policy with limited safeguards, no warrant requirement, 30‑day data transfer deadline
San Francisco released a policy that retains Automated License Plate Reader (ALPR) surveillance but provides only limited safeguards. The policy does not require a warrant to search stored ALPR data and sets a 30‑day deadline to move data…
San Francisco Police Department
Low
Guidance
Announced
United States (federal) · Sep 29, 2026
EFF launches 'Privacy’s Defenders' podcast on digital surveillance history
The Electronic Frontier Foundation released a new podcast episode featuring Cindy Cohn and John Gilmore discussing mass surveillance, early internet activism, and ongoing privacy challenges. The episode highlights historical battles…
Moderate
Guidance
Published
United States (federal) · Sep 29, 2026
Federal Register restricts automated scraping; requires API use and CAPTCHA verification
The Federal Register warns that programmatic access to FederalRegister.gov and eCFR.gov is limited to its developer APIs due to aggressive automated scraping. Users must use the APIs or complete a CAPTCHA to verify they are human. The…
Privacy Act of 1974