REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
145
Last 30 days
18
High or critical
31
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
496 developments
Moderate Proposed regulation Proposed European Union · Apr 16, 2026
EU Digital Omnibus proposal aims to limit GDPR right of access amid 83.5% non‑compliance
The European Commission’s Digital Omnibus proposal would restrict the GDPR right of access to “data protection purposes”, citing alleged abuse. NOYB’s analysis shows that 83.5% of access requests were not properly answered, with only 16.5%…
European Commission · General Data Protection Regulation
Moderate Fine In effect France · Mar 13, 2026
French court upholds €40M GDPR fine against Criteo
The French Data Protection Authority (CNIL) fined Criteo €40 million for GDPR violations, including lack of valid consent, transparency, and failures to honor erasure and access rights. In March 2026, the Conseil d’État rejected Criteo’s…
CNIL · General Data Protection Regulation
Moderate Proposed regulation Published European Union · Mar 5, 2026
EU Commission's Digital Omnibus proposal to limit GDPR Right of Access faces criticism from DPOs
The European Commission has published a Digital Omnibus proposal that would narrow the definition of personal data, restrict the Right of Access and allow broader AI training. A survey by noyb shows data protection officers consider the…
European Commission · General Data Protection Regulation
Moderate Proposed regulation Proposed European Union · Feb 24, 2026
EU Commission proposes Digital Omnibus to amend GDPR and ePrivacy Directive
The European Commission published its Digital Omnibus proposal on 19 November 2025, aiming to amend the GDPR and the ePrivacy Directive. noyb’s analysis warns that the proposed changes could conflict with the EU Charter of Fundamental…
European Commission · ePrivacy Directive
Moderate Guidance Published European Union · Feb 11, 2026
EU DPAs reject key proposals in Digital Omnibus GDPR changes
The European Data Protection Board and the European Data Protection Supervisor issued a joint opinion rejecting the Commission's proposal to narrow the definition of personal data and to restrict the right of access. They also raised…
European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) · ePrivacy Directive
Moderate Lawsuit filed Filed European Union · Jan 28, 2026
noyb debunks 5 GDPR misconceptions on Data Protection Day
The article clarifies that the GDPR does not mandate cookie banners, that DPAs rarely impose fines, and that companies must obtain explicit consent for tracking. It also explains the limited scope of the right of access and counters claims…
EDPB · General Data Protection Regulation
Low Lawsuit filed Filed Germany · Jan 28, 2026
noyb files lawsuit against Hamburg DPA over Pay or Okay case involving SPIEGEL
In 2024, privacy advocacy group noyb sued the Hamburg Data Protection Authority concerning a Pay or Okay implementation dispute with the German news magazine SPIEGEL. The case highlights concerns about DPA impartiality and enforcement…
Hamburg Data Protection Authority · General Data Protection Regulation
Moderate Data protection authority action Decided Austria · Jan 27, 2026
Austrian DSB orders Microsoft to stop tracking school children with cookies
The Austrian Data Protection Authority ruled that Microsoft illegally installed tracking cookies on a pupil's device without consent. The authority ordered Microsoft to cease the use of those cookies within four weeks. The decision follows…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low Investigation Announced Austria · Jan 20, 2026
noyb investigation reveals Austrian credit agency CRIF uses public registers for mass address data collection
noyb’s investigation of CRIF shows that most address data comes from brokers who scrape public registers, violating GDPR purpose‑limitation. The Austrian DSB has already ruled that further processing for advertising breaches the GDPR.
Austrian Data Protection Authority · General Data Protection Regulation
Moderate Court ruling Decided Austria · Dec 18, 2025 · deadline Dec 31, 2025
Austrian Supreme Court orders Meta to give users full data access within 14 days
The Austrian Supreme Court ruled that Meta must provide a complete copy of all personal data to any user request within 14 days, including source, recipient and purpose information. The court also required Meta to obtain explicit opt‑in…
EDPB · General Data Protection Regulation
Low Enforcement Filed Austria · Dec 17, 2025
noyb files complaints against TikTok, AppsFlyer and Grindr with Austrian DSB over unlawful tracking
noyb has lodged two complaints with Austria's data protection authority alleging that TikTok tracks users across other apps and fails to provide a complete copy of personal data. The complaints also target AppsFlyer and Grindr for sharing…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Guidance Announced European Union · Dec 10, 2025
EU‑US data transfers face imminent risk as US legal changes could undermine TAFPF and SCCs
The blog notes that most EU‑US transfers rely on the Transatlantic Data Privacy Framework (TAFPF) or Standard Contract Clauses (SCCs), which depend on fragile US laws and executive orders. It warns that upcoming US Supreme Court decisions…
EDPB · General Data Protection Regulation
Low Guidance Published European Union · Dec 4, 2025
EDPB publishes first opinion on Pay or Okay, urging a three‑option consent model
In April 2024 the European Data Protection Board released its first opinion on Pay or Okay systems, recommending a third choice of "advertising, but no tracking" alongside pay and consent options. A noyb‑commissioned study shows that users…
European Data Protection Board
Moderate Fine In effect France · Nov 27, 2025
CNIL fines Conde Nast €750,000 for cookie consent violations
The French data protection authority CNIL fined Conde Nast €750,000 for placing cookies on its Vanity Fair website without obtaining valid user consent. The authority also found the publisher failed to adequately inform users about the…
CNIL
Moderate Proposed regulation Proposed European Union · Nov 22, 2025
EU Commission proposes Digital Omnibus package with new personal data definition and research exemption
The European Commission has released the Digital Omnibus proposal, introducing a narrower definition of personal data (Art. 4(1)), a broader research exemption (Arts. 4(38), 5(1)(b), 13, 89), and new AI‑related rules (Arts. 9(2)(k), 9(5)…
European Commission · General Data Protection Regulation
Moderate Proposed regulation Proposed European Union · Nov 11, 2025
Open letter warns EU Commission's Digital Omnibus draft could deregulate GDPR
Noyb, EDRi and the Irish Council for Civil Liberties sent an open letter to the European Commission criticizing a draft Digital Omnibus that would amend core GDPR provisions. The draft proposes redefining personal data, weakening data…
European Commission · General Data Protection Regulation
Moderate Enforcement Filed Austria · Oct 28, 2025
noyb files criminal complaint against Clearview AI in Austria
noyb filed a criminal complaint with Austrian public prosecutors against Clearview AI and its managers for alleged GDPR violations. The complaint relies on Article 84 GDPR and Austria's § 63 Data Protection Act, which allow criminal…
Austrian public prosecutors · General Data Protection Regulation
Moderate Data protection authority action Decided Austria · Oct 9, 2025
Austrian DSB rules Microsoft 365 Education illegally tracks students and orders data deletion
The Austrian Data Protection Authority found Microsoft 365 Education used tracking cookies without consent and denied a data‑access request, violating GDPR. The DSB ordered Microsoft to delete the data, provide full access, and disclose…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Guidance Published European Union · Oct 1, 2025
ENISA releases cybersecurity awareness tools and skills framework for EU workplaces
ENISA, together with the European Commission, promotes cybersecurity in the EU through the European Cybersecurity Month and new guidance tools such as AR-in-a-Box and the European Cybersecurity Skills Framework. The agency highlights the…
ENISA · NIS2 Directive
Low Enforcement Filed Lithuania · Sep 29, 2025
noyb files complaint with Lithuanian DPA against Whitebridge AI for unlawful data processing
noyb has lodged a complaint with Lithuania's data protection authority alleging that Whitebridge AI unlawfully scrapes and sells AI‑generated reputation reports containing personal and sensitive data. The complaint cites violations of…
Lithuanian Data Protection Authority · General Data Protection Regulation
← NewerOlder →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union16 new · 14 laws California14 new · 5 laws France11 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 106security · 56ai governance · 46transparency · 28data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 14consent · 14targeted advertising · 14data governance · 13