REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: transparency · clear
86 developments
Low Enforcement Filed Austria · Apr 29, 2024
noyb files complaint with Austrian DPA over OpenAI's ChatGPT inaccurate personal data
noyb filed a complaint with the Austrian Data Protection Authority alleging that OpenAI cannot correct inaccurate personal data generated by ChatGPT, violating GDPR Articles 5, 15 and 16. The complaint seeks an investigation, compliance…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low Enforcement Filed Germany · Feb 16, 2024
noyb files complaint against German credit agency SCHUFA for GDPR access violations
noyb has lodged a complaint and report with the Hessian data protection authority alleging that SCHUFA blocks free access to personal data required under Article 15 GDPR. The agency allegedly uses manipulative designs to push paid products…
Hessian data protection authority · General Data Protection Regulation
Moderate Data protection authority action Published DE-BAVARIA · Feb 5, 2024
Bavarian DPA declares CRIF‑Acxiom data trading illegal under GDPR
The Bavarian data protection authority ruled that credit reference agency CRIF illegally purchased personal data from address trader Acxiom and breached GDPR purpose‑limitation and information duties. The decision follows a similar…
Bavarian Data Protection Authority · General Data Protection Regulation
Moderate Enforcement Pending European Union · Jan 28, 2024
Survey finds 74% of insiders say authorities would find GDPR violations in average EU company
A noyb survey of over 1,000 data‑protection professionals reports that 74% believe authorities would discover relevant GDPR violations during on‑site inspections. Respondents cite lack of clear DPA decisions, fines, and public enforcement…
EDPB · General Data Protection Regulation
Low Enforcement Filed Austria · Jan 4, 2024
noyb files complaint against Austrian creditors’ association KSV1870 for charging for GDPR Article 15 access
noyb lodged a complaint with the Austrian data protection authority alleging that KSV1870 charges €43 for a data‑access service that must be provided free of charge under Article 15 GDPR. The organization allegedly uses misleading website…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate Enforcement Filed European Union · Nov 16, 2023
noyb files complaint with EDPS over EU Commission’s political micro‑targeting ads on X
noyb lodged a complaint with the European Data Protection Supervisor alleging the EU Commission used unlawful micro‑targeting on X to promote its chat‑control proposal. The ads targeted users based on political views and religious beliefs…
European Data Protection Supervisor (EDPS) · General Data Protection Regulation
Moderate Fine Decided Norway (EEA) · Sep 29, 2023
Norwegian Privacy Appeals Board upholds €5.8 million fine against Grindr
The Norwegian Privacy Appeals Board confirmed the Norwegian Data Protection Authority's fine of NOK 65 million against the dating app Grindr for sharing sensitive personal data with third parties. The fine, approximately €5.8 million…
Norwegian Data Protection Authority · General Data Protection Regulation
Low Enforcement Decided DE-NI · Jul 14, 2023
German DPA declares heise.de "Pay or Okay" cookie banner illegal
The Lower Saxony Data Protection Authority (LfD) ruled that the "Pay or Okay" model used by heise.de in 2021 violates GDPR because it does not provide specific consent for each purpose. The authority issued a reprimand, noting that…
Data Protection Authority of Lower Saxony (LfD) · General Data Protection Regulation
Moderate Enforcement Filed Belgium · Jun 23, 2023
noyb files complaint against TeleSign for unlawful profiling of mobile users
noyb filed a complaint with the Belgian Data Protection Authority alleging that TeleSign receives phone data from BICS and creates reputation scores without consent, violating the GDPR. The complaint cites the use of AI-generated trust…
Belgian Data Protection Authority · General Data Protection Regulation
Moderate Fine In effect France · Jun 22, 2023
French CNIL fines Criteo €40 million for GDPR violations
The French Data Protection Authority (CNIL) fined Criteo €40 million for violating the GDPR, including lack of valid consent, transparency, and failure to respect the right to erasure and access. The enforcement followed complaints filed…
CNIL · General Data Protection Regulation
Moderate Fine In effect Sweden · Jun 13, 2023
Swedish Data Protection Authority fines Spotify €5 million for GDPR access violations
The Swedish Data Protection Authority (IMY) imposed a fine of 58 million Swedish crowns (≈ €5 million) on Spotify for not fully complying with users' right of access under the GDPR. The authority ordered Spotify to provide the complete set…
Swedish Data Protection Authority (IMY) · General Data Protection Regulation
Low Enforcement Filed European Union · Jun 1, 2023
Credit agency CRIF systematically withholds data from consumers, noyb files complaint
noyb has filed a complaint with the data protection authority alleging that CRIF violates GDPR Article 15 by providing incomplete access to personal data. The complaint cites systematic withholding of source information and limited…
EDPB · General Data Protection Regulation
Moderate Data protection authority action Announced Malta · May 17, 2023
Maltese DPA orders C-PLANET to disclose data source within 20 days or face fine
The Maltese Data Protection Authority (IDPC) ordered IT company C-PLANET to provide details on the source of personal data collected on voters within 20 days. Failure to comply will result in a proportionate and dissuasive fine under the…
Maltese Data Protection Authority (IDPC) · General Data Protection Regulation
Moderate Enforcement Published Ireland · Jan 11, 2023
Irish DPC fines Meta €60m for unlawful processing and €150m for transparency breaches
The Irish Data Protection Commission (DPC) issued a final decision imposing a €150 million fine on Facebook for transparency failures and a €60 million fine on Meta for lacking a legal basis to process personal data. The decision also…
Irish Data Protection Commission · General Data Protection Regulation
Moderate Enforcement Announced European Union · Jan 4, 2023
EU EDPB bans Meta from using personal data for personalized ads, imposes €390 million fine
The European Data Protection Board (EDPB) decided that Meta (Facebook and Instagram) may not use personal data for personalized advertising and must obtain opt‑in consent. The decision also imposes a total fine of €390 million on Meta.…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate Fine In effect Ireland · Jan 4, 2023 · effective Jan 4, 2023
EU data protection board fines Meta €390 million and bans personalized ads
The European Data Protection Board, following the Irish Data Protection Commission, ruled that Meta's use of personal data for personalized advertising violated the GDPR and imposed a €390 million fine. Meta must obtain opt‑in consent and…
European Data Protection Board · General Data Protection Regulation
Moderate Enforcement Filed European Union · Oct 27, 2022
noyb files 700+ GDPR complaints on cookie banners, prompting widespread addition of reject buttons
noyb scanned over 3,600 websites in March 2021 and filed more than 700 complaints across Europe for GDPR‑violating cookie banners lacking a clear reject option. Follow‑up scans in October 2022 showed that 41% of the sites added a reject…
EDPB · General Data Protection Regulation
Moderate Enforcement Filed European Union · Aug 9, 2022
226 GDPR complaints lodged against deceptive OneTrust cookie banners
noyb filed 226 complaints with 18 data protection authorities over websites using OneTrust cookie banners that employ deceptive designs. The complaints allege violations of GDPR requirements for a fair yes/no consent choice. Some websites…
EDPB · General Data Protection Regulation
Low Enforcement Filed Malta · Apr 29, 2022
noyb files second complaint against C‑Planet for refusing data‑subject access to source of political data
noyb filed a second complaint with Malta's Information & Data Protection Commissioner (IDPC) demanding C‑Planet disclose the original source of illegally processed voter data. The company previously received a €65,000 fine for illegal…
Information & Data Protection Commissioner (IDPC) · General Data Protection Regulation
Moderate Settlement Settled Ireland · Apr 28, 2022 · effective Apr 28, 2022
Irish DPC to pay tens of thousands in costs to noyb over 47‑month delay in WhatsApp and Instagram GDPR cases
The Irish Data Protection Commission settled with privacy group noyb, agreeing to cover tens of thousands of euros in legal costs after a 47‑month delay in drafting decisions on WhatsApp and Instagram cases. The delay contravenes GDPR…
Irish Data Protection Commission (DPC) · General Data Protection Regulation
← NewerOlder →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13