Low
Guidance
Announced
Global · Sep 18, 2026
EFF warns that cloud TEEs undermine end‑to‑end encryption in messaging apps
The EFF explains that while trusted execution environments (TEEs) can protect data on cloud servers, they do not provide the same mathematical guarantees as end‑to‑end encryption. Sending message content to a TEE for AI processing creates…
Moderate
Guidance
Published
France · Sep 17, 2026
CNIL outlines its status, organization and sanction powers
The CNIL, created by the 1978 Loi Informatique et Libertés, is an independent administrative authority composed of a college of 18 members. Its restricted board can impose fines up to €20 million or 4 % of global annual turnover under the…
CNIL · loi Informatique et Libertés
Low
Guidance
Published
United States (federal) · Sep 11, 2026
Amazon Ring's 'Throw Away the Key Encryption' adds limited privacy but falls short of true end‑to‑end encryption
Amazon introduced the Throw Away the Key Encryption (TAKE) feature for Ring cameras, where encryption keys are held temporarily in the cloud and deleted after 24 hours. The system still allows Ring to decrypt footage for cloud‑based…
Moderate
Guidance
Announced
European Union · Sep 11, 2026
ENISA launches Single Reporting Platform for Cyber Resilience Act reporting
ENISA has deployed the initial operating capability of the Single Reporting Platform (SRP) to support the Cyber Resilience Act (CRA) reporting obligations. From 11 September 2026 manufacturers and open‑source software stewards must report…
ENISA · Cyber Resilience Act
Moderate
Guidance
In effect
France · Sep 10, 2026 · effective Sep 1, 2026
CNIL guidance on data‑protection obligations under the electronic invoicing reform effective 1 Sept 2026
The CNIL explains the data‑protection implications of the French electronic invoicing reform that entered into force on 1 Sept 2026. It details which personal data may be processed, the roles of issuers, receivers and certified platforms…
CNIL · réforme relative à la facturation électronique
Low
Guidance
Announced
Global · Sep 9, 2026
EFF blog outlines digital sovereignty and its impact on privacy, data control and security
The post explains that digital sovereignty refers to the ability of individuals, nations and organizations to control their digital destiny, including data, technology and infrastructure. It highlights policy discussions in Europe and…
Low
Guidance
Announced
Global · Sep 9, 2026
EFF Announces 2026 Award Winners: Access Now, 7amleh, DeFlock, New Media Rights
The Electronic Frontier Foundation announced that Access Now, 7amleh – The Arab Center for the Advancement of Social Media, DeFlock, and New Media Rights received the 2026 EFF Awards. The award recognizes their work defending digital…
Moderate
Guidance
Repealed
United States (federal) · Sep 9, 2026 · effective Sep 9, 2026
FTC rescinds 2021 Policy Statement on Breaches by Health Apps and Connected Devices
The Federal Trade Commission announced it is rescinding the 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. The guidance is deemed obsolete and is being withdrawn. The rescission was published on 2026-09-09.
Federal Trade Commission
Moderate
Guidance
Published
United States (federal) · Aug 31, 2026
EFF guide on doxxing incident response and digital footprint protection
The Electronic Frontier Foundation published a guide outlining steps for individuals and groups to respond to doxxing attacks. It covers incident logging, team role assignment, monitoring hate forums, setting up alerts, hardening accounts…
California Delete Act
Low
Guidance
Published
Global · Aug 31, 2026
EFF and The Trevor Project advise LGBTQ+ individuals to revise shared information for online safety
The Electronic Frontier Foundation and The Trevor Project provide practical steps for LGBTQ+ people to protect their personal information online. Advice includes limiting disclosure of identifying details, using avatars, disabling EXIF…
Moderate
Guidance
Published
SG · Aug 25, 2026
PDPC publishes Advisory Guidelines on Personal Data in Generative AI at Singapore Data Festival
On July 20, 2026, Singapore’s Personal Data Protection Commission released its finalized Advisory Guidelines on the Use of Personal Data in Generative AI. The guidance clarifies the Publicly Available Exception for web‑scraping and…
Personal Data Protection Commission (PDPC) · EU AI Act
Low
Guidance
Announced
United States (federal) · Aug 13, 2026
Flock Safety announces optional 7‑day ALPR data retention and other reforms
Flock Safety introduced a default optional 7‑day retention period for automated license plate reader (ALPR) data, reduced from the previous 30‑day default. Retention beyond this period requires activation of “Evidence Mode,” tied to an…
Moderate
Guidance
Announced
United States (federal) · Aug 5, 2026
Future of Privacy Forum releases updated AI risk assessment framework and best practices for hiring
Future of Privacy Forum and leading HR software firms released Updated Best Practices for AI and Workplace Assessment Technologies, addressing generative and agentic AI in employment. The guidance outlines a risk assessment framework and…
EU AI Office · EU AI Act
Moderate
Guidance
Announced
European Union · Dec 10, 2025
EU‑US data transfers face imminent risk as US legal changes could undermine TAFPF and SCCs
The blog notes that most EU‑US transfers rely on the Transatlantic Data Privacy Framework (TAFPF) or Standard Contract Clauses (SCCs), which depend on fragile US laws and executive orders. It warns that upcoming US Supreme Court decisions…
EDPB · General Data Protection Regulation
Moderate
Interpretation
Announced
European Union · May 22, 2022
Open Letter warns EU‑US data transfer deal lacks material US law changes
The open letter published on 2022‑05‑22 criticises the announced Trans‑Atlantic Data Privacy Framework for relying on US executive orders without substantive changes to US surveillance law. It argues that the framework repeats the…
EDPB · General Data Protection Regulation
Moderate
Interpretation
Published
Austria · May 2, 2022
Austrian DPA rejects risk‑based approach for EU‑US data transfers, deems Google IP anonymisation insufficient
The Austrian Data Protection Authority issued a decision stating that the GDPR does not permit a risk‑based approach for transfers to insecure third countries such as the United States. It also concluded that Google’s IP anonymisation does…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate
Guidance
Published
European Union · Jan 27, 2021
noyb urges stronger GDPR enforcement on European Data Protection Day
noyb highlights that despite the GDPR's strong provisions, compliance remains low and enforcement insufficient. The organization calls on data protection authorities and companies to move from paper rights to real protection, citing the…
EDPB · General Data Protection Regulation
High
Guidance
Published
European Union · Jul 24, 2020 · effective Jul 16, 2020
noyb provides step-by-step guide for EU users to stop US data transfers after Schrems II
The document outlines how data subjects can exercise GDPR rights to learn about and halt transfers of their personal data to the United States following the CJEU Schrems II judgment. It provides sample request letters for information…
European Commission · Standard Contractual Clauses
Moderate
Guidance
Published
European Union · Jul 20, 2020
noyb releases guidance for EU companies on Schrems II data‑transfer obligations
The guidance explains steps EU controllers should take after the CJEU Schrems II judgment, including reviewing data flows, stopping transfers that rely on the invalidated Privacy Shield, and notifying DPAs when using SCCs after a negative…
EDPB · General Data Protection Regulation
Low
Guidance
Published
Austria · Apr 21, 2020
First European Corona contact tracing app in Austria reviewed by noyb, epicenter.works and SBA Research
The Austrian Red Cross released a contact tracing app on March 25th, which uses a hybrid central‑server and local storage model. NGOs and security researchers reviewed the app and identified privacy weaknesses, recommending a switch to a…