REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: consent · clear
165 developments
Moderate Fine In effect France · Nov 27, 2025
CNIL fines Conde Nast €750,000 for cookie consent violations
The French data protection authority CNIL fined Conde Nast €750,000 for placing cookies on its Vanity Fair website without obtaining valid user consent. The authority also found the publisher failed to adequately inform users about the…
CNIL
Moderate Proposed regulation Proposed European Union · Nov 11, 2025
Open letter warns EU Commission's Digital Omnibus draft could deregulate GDPR
Noyb, EDRi and the Irish Council for Civil Liberties sent an open letter to the European Commission criticizing a draft Digital Omnibus that would amend core GDPR provisions. The draft proposes redefining personal data, weakening data…
European Commission · General Data Protection Regulation
Moderate Data protection authority action Decided Austria · Oct 9, 2025
Austrian DSB rules Microsoft 365 Education illegally tracks students and orders data deletion
The Austrian Data Protection Authority found Microsoft 365 Education used tracking cookies without consent and denied a data‑access request, violating GDPR. The DSB ordered Microsoft to delete the data, provide full access, and disclose…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Data protection authority action Published Austria · Sep 26, 2025
Austrian DSB bans KSV1870 from automated credit checks without consent
The Austrian Data Protection Authority ruled that KSV1870's fully automated credit rating was unlawful and prohibited the agency from conducting such checks without the data subject's consent. The authority also ordered KSV1870 to provide…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low Investigation Announced Austria · Sep 25, 2025
noyb uncovers over 40,000 CRIF credit queries linking Austrian banks, telecoms and retailers
noyb obtained data requests from 2,440 individuals and analyzed more than 40,000 CRIF credit queries, finding that banks, telecoms and other firms provide personal address data to the credit agency. The analysis shows gender and geographic…
EDPB · General Data Protection Regulation
Moderate Data protection authority action Announced Ireland · Sep 18, 2025
Former Meta lobbyist Niamh Sweeney appointed Irish DPC commissioner
Niamh Sweeney, a former senior Meta lobbyist, is set to join the Irish Data Protection Commission (DPC) as a commissioner in October. The DPC is the EU lead privacy regulator for major US tech firms. The appointment raises concerns about…
Irish Data Protection Commission · General Data Protection Regulation
Moderate Fine In effect France · Sep 4, 2025
CNIL fines Google €325 million for unsolicited Gmail advertising
The French data protection authority CNIL has issued a decision siding with privacy NGO noyb and fined Google €325 million for sending unsolicited advertising emails to Gmail users without consent. The authority also ordered Google to stop…
CNIL · ePrivacy Directive
Moderate Court ruling Decided Austria · Aug 18, 2025
Austrian Federal Administrative Court rules DerStandard's "pay or okay" consent model illegal
The Austrian Federal Administrative Court (BVwG) confirmed the Data Protection Authority's finding that DerStandard violated the GDPR by offering a "pay or okay" choice. The court held that the newspaper did not obtain valid, granular…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low Enforcement Announced Germany · Aug 7, 2025
noyb sends cease‑and‑desist to Meta over AI training of EU users’ data
noyb commissioned a Gallup survey of 1,000 German Meta users, finding only 7% want their personal data used for AI training. Based on the results, noyb sent a cease‑and‑desist letter to Meta alleging GDPR violations and is assessing a…
EDPB · General Data Protection Regulation
Moderate Court ruling Decided European Union · Jul 31, 2025
CJEU ruling C‑446/21 limits use of personal data for online advertising and repurposing publicly available data
The European Court of Justice issued ruling C‑446/21, fully backing a lawsuit against Meta's Facebook service. The court massively limits the use of personal data for online advertising and restricts the reuse of publicly available…
EDPB · General Data Protection Regulation
Moderate Guidance Announced European Union · Jul 24, 2025
Report flags 'Pay or Okay' consent‑bypass systems as violating GDPR free‑consent requirement
The noyb report documents the spread of “Pay or Okay” systems across Europe, where users must pay to refuse tracking, resulting in near‑universal consent rates that breach the GDPR’s freely‑given consent standard. It cites a July 2023 CJEU…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate Data protection authority action Filed Austria · Jun 26, 2025
noyb files complaint against Bumble for unlawful AI Icebreakers in Austria
noyb lodged a complaint with the Austrian Data Protection Authority alleging that Bumble's AI Icebreakers process personal data without valid consent and rely on an invalid legitimate‑interest claim. The complaint cites violations of GDPR…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low Lawsuit filed Filed Germany · Jun 17, 2025
noyb sues German DPAs over inactivity on ‘Pay or OK’ GDPR complaints
noyb filed complaints in August 2021 against news sites using ‘Pay or OK’ consent mechanisms, alleging they violate the GDPR’s freely given consent requirement. After nearly four years of inaction, the North Rhine‑Westphalia and Hesse data…
EDPB · General Data Protection Regulation
Moderate Enforcement Announced European Union · Jun 16, 2025
noyb warns Meta's planned WhatsApp ads may breach GDPR and DMA
noyb alleges that Meta's intention to serve ads on WhatsApp using personal data from Instagram and Facebook violates the GDPR and the EU Digital Markets Act. The organization says the proposed "Pay or Okay" model would not provide freely…
noyb · General Data Protection Regulation
Moderate Class action Announced Austria · Jun 3, 2025
noyb seeks participants for potential GDPR class action against Austrian credit agency CRIF
noyb alleges that CRIF processes personal data of millions of Austrians to calculate credit scores based on age, gender and address, potentially violating the GDPR. The organization plans a scientific review and, if evidence supports it…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate Court ruling Decided Germany · May 23, 2025
German Higher Regional Court denies interim injunction against Meta AI training
The Higher Regional Court of Cologne refused the interim injunction sought by Verbraucherzentrale NRW, which alleged Meta's AI training violates the GDPR by using user data without consent. The court's decision is limited to the interim…
Hamburg Data Protection Authority · General Data Protection Regulation
Low Enforcement Announced Ireland · May 14, 2025
noyb sends cease and desist letter to Meta over AI training using EU personal data
noyb has issued a cease and desist letter to Meta, alleging that the company will use EU personal data from Instagram and Facebook for AI training without opt‑in consent. The letter relies on the EU Collective Redress Directive, which…
EDPB · General Data Protection Regulation
Low Enforcement Announced DE-NRW · May 6, 2025
Consumer group asks Meta to stop AI training on EU user data
The Verbraucherzentrale North Rhine-Westphalia sent Meta a cease‑and‑desist letter on 30 April 2025 demanding it halt the use of Instagram and Facebook posts for AI training, citing GDPR consent requirements. Noyb supports the request…
EDPB · General Data Protection Regulation
Low Enforcement Filed Austria · Apr 24, 2025
noyb files GDPR complaint against Ubisoft for forced online tracking of offline games
noyb lodged a complaint with the Austrian Data Protection Authority alleging that Ubisoft requires players to be online for single‑player games, collecting personal data such as start time, duration and quit time. The complaint argues the…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Court ruling Decided Ireland · Jan 29, 2025
EU General Court rules Irish DPC acted unlawfully for refusing to investigate noyb complaint
The EU General Court held that the Irish Data Protection Commission unlawfully refused to investigate a complaint filed by noyb. The court dismissed the DPC's claims against the European Data Protection Board. The case can now be appealed…
Irish Data Protection Commission · General Data Protection Regulation
← NewerOlder →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13