REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
142
Last 30 days
18
High or critical
30
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
496 developments
Low Enforcement Published Austria · Feb 6, 2023
Austrian DSB rules credit bureau KSV 1870 may not collect data via access requests and civil registries
The Austrian Data Protection Authority found KSV 1870's practice of storing information obtained through GDPR access requests and civil‑registry comparisons illegal, violating purpose‑limitation under Article 5(1)(b) GDPR. The DSB ordered…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Fine Announced Ireland · Jan 27, 2023
Irish DPC announces €390 million fine on Meta for GDPR consent breach
The Irish Data Protection Commission announced a €390 million fine against Meta, ordering it to obtain valid consent for personalized advertising after the European Data Protection Board issued a binding decision. The fine illustrates…
Irish Data Protection Commission · General Data Protection Regulation
Low Court ruling Decided Spain · Jan 25, 2023
Spanish Audiencia Nacional rules location data is personal data, overturning AEPD decision
The Audiencia Nacional annulled the Spanish DPA's earlier ruling that denied a customer access to his location data held by Virgin telco. The court held that location data qualifies as personal data under the GDPR, obliging the provider to…
Agencia Española de Protección de Datos (AEPD) · General Data Protection Regulation
Moderate Guidance Published European Union · Jan 24, 2023
EDPB releases draft report on minimum requirements for cookie consent banners
The European Data Protection Board's task force issued a draft report outlining unlawful cookie banner practices under EU law. It sets a minimum threshold for consent banners, including the need for a visible reject option and prohibition…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate Enforcement Published Ireland · Jan 11, 2023
Irish DPC fines Meta €60m for unlawful processing and €150m for transparency breaches
The Irish Data Protection Commission (DPC) issued a final decision imposing a €150 million fine on Facebook for transparency failures and a €60 million fine on Meta for lacking a legal basis to process personal data. The decision also…
Irish Data Protection Commission · General Data Protection Regulation
Moderate Enforcement Announced European Union · Jan 4, 2023
EU EDPB bans Meta from using personal data for personalized ads, imposes €390 million fine
The European Data Protection Board (EDPB) decided that Meta (Facebook and Instagram) may not use personal data for personalized advertising and must obtain opt‑in consent. The decision also imposes a total fine of €390 million on Meta.…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate Fine In effect Ireland · Jan 4, 2023 · effective Jan 4, 2023
EU data protection board fines Meta €390 million and bans personalized ads
The European Data Protection Board, following the Irish Data Protection Commission, ruled that Meta's use of personal data for personalized advertising violated the GDPR and imposed a €390 million fine. Meta must obtain opt‑in consent and…
European Data Protection Board · General Data Protection Regulation
Low Proposed regulation Announced European Union · Dec 13, 2022
EU Commission issues draft adequacy decision for US data transfers, criticized by noyb
The European Commission announced a new adequacy decision for US data transfers, replacing the invalidated Privacy Shield. The draft decision is under review by the European Data Protection Board and Member States, and may be challenged in…
European Commission · Executive Order 14086
Moderate Enforcement Announced European Union · Dec 6, 2022
EU Data Protection Board rules Meta's consent bypass for personalized ads illegal
The European Data Protection Board (EDPB) decided that Meta cannot force users to accept personalized ads and must obtain a yes/no consent option. The decision overturns a previous draft decision by the Irish Data Protection Commission and…
European Data Protection Board (EDPB) · General Data Protection Regulation
Low Court ruling Decided Sweden · Nov 9, 2022
Swedish court rules IMY must investigate GDPR complaints and grant complainants party status
The Stockholm administrative court held that a complainant under Article 77 GDPR can request a decision from the Swedish Data Protection Authority (IMY) after six months and that Swedish law does not deny party status. The court ordered…
Swedish Data Protection Authority (IMY) · General Data Protection Regulation
Moderate Enforcement Filed European Union · Oct 27, 2022
noyb files 700+ GDPR complaints on cookie banners, prompting widespread addition of reject buttons
noyb scanned over 3,600 websites in March 2021 and filed more than 700 complaints across Europe for GDPR‑violating cookie banners lacking a clear reject option. Follow‑up scans in October 2022 showed that 41% of the sites added a reject…
EDPB · General Data Protection Regulation
Low Enforcement Decided Austria · Oct 20, 2022
Austrian DSB orders Profil.at to fix forced cookie banners after GDPR complaint
noyb filed a GDPR complaint against Profil.at for using a forced two‑step cookie consent mechanism. The Austrian Data Protection Authority issued a decision on 10 August 2023, confirming the violations and giving the site an eight‑week…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Court ruling Published European Union · Oct 13, 2022
CJEU Advocate General opinion may limit GDPR non‑material damages compensation
The Advocate General of the Court of Justice of the EU issued an opinion that could restrict the right to claim non‑material damages under the GDPR. The opinion questions whether Article 82 allows damages without material loss and suggests…
EDPB · General Data Protection Regulation
Moderate Executive order Signed United States (federal) · Oct 7, 2022
US President Biden signs Executive Order on surveillance, unlikely to satisfy EU law
President Joe Biden signed a new Executive Order intended to address EU concerns over US surveillance practices. The order retains bulk surveillance and creates a non‑judicial “Data Protection Review Court,” which the source says does not…
EDPB · General Data Protection Regulation
Low Proposed regulation Announced European Union · Sep 25, 2022
EU-US data transfer agreement in principle remains unimplemented six months later
On 25 March 2022 US President Joe Biden and European Commission President Ursula von der Leyen announced an "agreement in principle" on EU‑US data transfers, but six months later no concrete framework has been published. The CJEU has…
European Commission · General Data Protection Regulation
Low Enforcement Filed France · Aug 24, 2022
noyb files complaint with CNIL over Gmail's unsolicited advertising emails
noyb.eu lodged a complaint with the French Data Protection Authority (CNIL) alleging that Google’s Gmail sends unsolicited advertising emails without user consent, contrary to the ePrivacy Directive and a CJEU ruling. The complaint cites…
CNIL · ePrivacy Directive
Moderate Enforcement Filed European Union · Aug 9, 2022
226 GDPR complaints lodged against deceptive OneTrust cookie banners
noyb filed 226 complaints with 18 data protection authorities over websites using OneTrust cookie banners that employ deceptive designs. The complaints allege violations of GDPR requirements for a fair yes/no consent choice. Some websites…
EDPB · General Data Protection Regulation
Moderate Fine Decided European Union · Jul 21, 2022
6.3 million Euro fine imposed on Grindr for GDPR violations
noyb’s complaints resulted in a 6.3 million Euro fine against the gay dating app Grindr for breaching the GDPR. The fine was highlighted in noyb’s 2021 Annual Report.
EDPB · General Data Protection Regulation
High Fine In effect Greece · Jul 13, 2022
Greek DPA fines Clearview AI €20 million and bans biometric processing
The Greek Data Protection Authority imposed a €20 million fine on Clearview AI and prohibited the company from processing biometric data of individuals in Greece. Clearview must delete all existing facial‑recognition data of Greek citizens…
Greek Data Protection Authority · General Data Protection Regulation
Moderate Data protection authority action Published Ireland · Jul 7, 2022
Irish DPC issues Draft Decision on Facebook EU-US data transfers, starts one-month comment period
The Irish Data Protection Commission issued a Draft Decision under Article 60 GDPR concerning Meta's Facebook EU‑US data transfers. The draft triggers a one‑month comment period for other European DPAs and does not immediately halt the…
Irish Data Protection Commission · General Data Protection Regulation
← NewerOlder →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)65 new · 16 laws European Union16 new · 14 laws California13 new · 5 laws France11 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 103security · 54ai governance · 45transparency · 28data minimization · 27children · 26profiling · 24automated decision making · 22consent · 14targeted advertising · 14data governance · 13cybersecurity · 13