REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: privacy · clear
161 developments
Moderate Enforcement Announced Spain · Sep 9, 2026
AEPD opens investigation into Ministry of Interior report listing journalists and political leanings
The Spanish Data Protection Agency announced it will launch a formal, ex officio investigation into a Ministry of Interior communication office report that includes journalists' names and alleged political ideologies. The probe will…
Agencia Española de Protección de Datos · Reglamento General de Protección de Datos (RGPD)
High Enforcement Decided Ireland · Sep 3, 2026 · effective Aug 28, 2026
Data Protection Commission issues €645,000 fine and compliance orders against HSE
The Irish Data Protection Commission issued a final decision on 28 August 2026 concerning the Health Service Executive's handling of paper medical records. The DPC found physical security and integrity failures at external storage…
Data Protection Commission · General Data Protection Regulation
Moderate Data protection authority action Announced Spain · Sep 2, 2026
AEPD to host data‑protection session at XX Jornadas STIC on 24 Nov 2026
The Spanish Data Protection Agency (AEPD) will hold a dedicated data‑protection space on 24 November 2026 during the XX Jornadas STIC conference in Madrid. The event, organized by the Centro Criptológico Nacional, the Centro Nacional de…
Agencia Española de Protección de Datos
Moderate Settlement Announced United States (federal) · Sep 1, 2026
Meta to implement age‑verification framework under $17 B settlement with 52 U.S. states
Meta has agreed to a $17 billion settlement with 52 state attorneys general that mandates age‑assurance technology for its platforms. The settlement requires Meta to apply age‑verification methods within one year, classify users into 18+…
state attorneys general · Children's Online Privacy Protection Act
Moderate Settlement Settled Connecticut · Aug 27, 2026
Connecticut AG settles with TaxAct over taxpayer data disclosures via tracking tech
On August 19, 2026, Connecticut Attorney General William Tong announced a $275,000 settlement with TaxAct for improperly disclosing taxpayer information to advertising partners through third‑party tracking technologies. The settlement…
Connecticut Attorney General
Moderate Settlement Settled United States (federal) · Aug 26, 2026
EFF says Meta settlement expands data collection and limits youth rights
The settlement reduces young users' access to Meta products and limits their ability to exercise free expression and community participation. It requires age assurance on every product, leading to the collection of additional personal…
Low Enforcement Announced Germany · Aug 26, 2026 · effective Aug 26, 2026
noyb sends cease‑and‑desist letter to SCHUFA over alleged ‘shadow database’ GDPR violations
In July 2026, the NGO noyb issued a cease‑and‑desist letter to German credit agency SCHUFA demanding it stop storing data beyond retention periods and provide full historical data under Article 15 GDPR. The organization warned it will seek…
EDPB · General Data Protection Regulation
Low Enforcement Announced EU-GB · Aug 21, 2026
EFF and civil groups urge Nottinghamshire Police to halt live facial recognition rollout
The Electronic Frontier Foundation and several civil‑society organisations wrote to Nottinghamshire Police in the UK demanding an immediate stop to the proposed roll‑out of live facial recognition (LFR). The letter cites concerns about…
Low Enforcement Announced United States (federal) · Aug 19, 2026
Tech firms privately resist ICE subpoenas seeking user data
ICE has sent hundreds of subpoenas to large technology companies for subscriber information. Meta and Reddit have privately pushed back, questioning statutory authority and objecting to requests tied to protected activity. In some cases…
U.S. Immigration and Customs Enforcement · 19 U.S.C. §1509
Low Investigation Announced Global · Aug 19, 2026
EFF report finds mobile ad libraries may leak user location data
EFF released a new report highlighting how mobile ad libraries can cause apps to unintentionally expose users' location information. The investigation notes that this leakage can reveal intimate details about individuals and be exploited…
Low Enforcement Filed Austria · Jun 9, 2026
noyb files injunction against Austrian credit agency CRIF over GDPR violations
noyb, a state‑approved qualified entity, filed an injunction against CRIF to stop its alleged unlawful collection and scoring of personal data under the GDPR. The filing also suspends the limitation period and prepares a subsequent class…
EDPB · General Data Protection Regulation
Low Enforcement Filed Austria · May 5, 2026
LinkedIn blocks GDPR access to profile visitor data behind paywall, noyb files complaint in Austria
LinkedIn requires users to pay to view who has visited their profile, despite the data being personal under the GDPR. noyb argues the data must be provided free of charge under Article 15 and has lodged a complaint with the Austrian Data…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate Fine In effect France · Mar 13, 2026
French court upholds €40M GDPR fine against Criteo
The French Data Protection Authority (CNIL) fined Criteo €40 million for GDPR violations, including lack of valid consent, transparency, and failures to honor erasure and access rights. In March 2026, the Conseil d’État rejected Criteo’s…
CNIL · General Data Protection Regulation
Low Investigation Announced Austria · Jan 20, 2026
noyb investigation reveals Austrian credit agency CRIF uses public registers for mass address data collection
noyb’s investigation of CRIF shows that most address data comes from brokers who scrape public registers, violating GDPR purpose‑limitation. The Austrian DSB has already ruled that further processing for advertising breaches the GDPR.
Austrian Data Protection Authority · General Data Protection Regulation
Low Enforcement Filed Austria · Dec 17, 2025
noyb files complaints against TikTok, AppsFlyer and Grindr with Austrian DSB over unlawful tracking
noyb has lodged two complaints with Austria's data protection authority alleging that TikTok tracks users across other apps and fails to provide a complete copy of personal data. The complaints also target AppsFlyer and Grindr for sharing…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Enforcement Filed Austria · Oct 28, 2025
noyb files criminal complaint against Clearview AI in Austria
noyb filed a criminal complaint with Austrian public prosecutors against Clearview AI and its managers for alleged GDPR violations. The complaint relies on Article 84 GDPR and Austria's § 63 Data Protection Act, which allow criminal…
Austrian public prosecutors · General Data Protection Regulation
Low Enforcement Filed Lithuania · Sep 29, 2025
noyb files complaint with Lithuanian DPA against Whitebridge AI for unlawful data processing
noyb has lodged a complaint with Lithuania's data protection authority alleging that Whitebridge AI unlawfully scrapes and sells AI‑generated reputation reports containing personal and sensitive data. The complaint cites violations of…
Lithuanian Data Protection Authority · General Data Protection Regulation
Low Investigation Announced Austria · Sep 25, 2025
noyb uncovers over 40,000 CRIF credit queries linking Austrian banks, telecoms and retailers
noyb obtained data requests from 2,440 individuals and analyzed more than 40,000 CRIF credit queries, finding that banks, telecoms and other firms provide personal address data to the credit agency. The analysis shows gender and geographic…
EDPB · General Data Protection Regulation
Moderate Data protection authority action Announced Ireland · Sep 18, 2025
Former Meta lobbyist Niamh Sweeney appointed Irish DPC commissioner
Niamh Sweeney, a former senior Meta lobbyist, is set to join the Irish Data Protection Commission (DPC) as a commissioner in October. The DPC is the EU lead privacy regulator for major US tech firms. The appointment raises concerns about…
Irish Data Protection Commission · General Data Protection Regulation
Low Enforcement Announced Austria · Sep 18, 2025
NGOs file EU Commission complaint over Austrian DPA budget cuts
The Austrian Data Protection Authority (DSB) announced further restrictions due to significant budget cuts. NGOs epicenter.works and noyb plan to file a complaint with the European Commission alleging violation of Article 52(4) GDPR. The…
European Commission · General Data Protection Regulation
← NewerOlder →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13