REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: consent · clear
98 developments
Moderate Enforcement Published Ireland · Jan 11, 2023
Irish DPC fines Meta €60m for unlawful processing and €150m for transparency breaches
The Irish Data Protection Commission (DPC) issued a final decision imposing a €150 million fine on Facebook for transparency failures and a €60 million fine on Meta for lacking a legal basis to process personal data. The decision also…
Irish Data Protection Commission · General Data Protection Regulation
Moderate Enforcement Announced European Union · Jan 4, 2023
EU EDPB bans Meta from using personal data for personalized ads, imposes €390 million fine
The European Data Protection Board (EDPB) decided that Meta (Facebook and Instagram) may not use personal data for personalized advertising and must obtain opt‑in consent. The decision also imposes a total fine of €390 million on Meta.…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate Fine In effect Ireland · Jan 4, 2023 · effective Jan 4, 2023
EU data protection board fines Meta €390 million and bans personalized ads
The European Data Protection Board, following the Irish Data Protection Commission, ruled that Meta's use of personal data for personalized advertising violated the GDPR and imposed a €390 million fine. Meta must obtain opt‑in consent and…
European Data Protection Board · General Data Protection Regulation
Moderate Enforcement Announced European Union · Dec 6, 2022
EU Data Protection Board rules Meta's consent bypass for personalized ads illegal
The European Data Protection Board (EDPB) decided that Meta cannot force users to accept personalized ads and must obtain a yes/no consent option. The decision overturns a previous draft decision by the Irish Data Protection Commission and…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate Enforcement Filed European Union · Oct 27, 2022
noyb files 700+ GDPR complaints on cookie banners, prompting widespread addition of reject buttons
noyb scanned over 3,600 websites in March 2021 and filed more than 700 complaints across Europe for GDPR‑violating cookie banners lacking a clear reject option. Follow‑up scans in October 2022 showed that 41% of the sites added a reject…
EDPB · General Data Protection Regulation
Low Enforcement Decided Austria · Oct 20, 2022
Austrian DSB orders Profil.at to fix forced cookie banners after GDPR complaint
noyb filed a GDPR complaint against Profil.at for using a forced two‑step cookie consent mechanism. The Austrian Data Protection Authority issued a decision on 10 August 2023, confirming the violations and giving the site an eight‑week…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low Enforcement Filed France · Aug 24, 2022
noyb files complaint with CNIL over Gmail's unsolicited advertising emails
noyb.eu lodged a complaint with the French Data Protection Authority (CNIL) alleging that Google’s Gmail sends unsolicited advertising emails without user consent, contrary to the ePrivacy Directive and a CJEU ruling. The complaint cites…
CNIL · ePrivacy Directive
Moderate Enforcement Filed European Union · Aug 9, 2022
226 GDPR complaints lodged against deceptive OneTrust cookie banners
noyb filed 226 complaints with 18 data protection authorities over websites using OneTrust cookie banners that employ deceptive designs. The complaints allege violations of GDPR requirements for a fair yes/no consent choice. Some websites…
EDPB · General Data Protection Regulation
Moderate Fine Decided European Union · Jul 21, 2022
6.3 million Euro fine imposed on Grindr for GDPR violations
noyb’s complaints resulted in a 6.3 million Euro fine against the gay dating app Grindr for breaching the GDPR. The fine was highlighted in noyb’s 2021 Annual Report.
EDPB · General Data Protection Regulation
Moderate Enforcement Announced European Union · May 24, 2022
noyb warns of widespread GDPR non‑compliance and lack of enforcement after four years
The NGO noyb states that despite the GDPR becoming applicable on 25 May 2018, many companies continue to ignore users' rights and enforcement remains weak. It notes that about 50 cross‑country cases it filed have not yet received a final…
EDPB · General Data Protection Regulation
Moderate Settlement Settled Ireland · Apr 28, 2022 · effective Apr 28, 2022
Irish DPC to pay tens of thousands in costs to noyb over 47‑month delay in WhatsApp and Instagram GDPR cases
The Irish Data Protection Commission settled with privacy group noyb, agreeing to cover tens of thousands of euros in legal costs after a 47‑month delay in drafting decisions on WhatsApp and Instagram cases. The delay contravenes GDPR…
Irish Data Protection Commission (DPC) · General Data Protection Regulation
Moderate Enforcement Announced European Union · Mar 4, 2022
noyb launches second wave of GDPR complaints against deceptive cookie banners
noyb sent 270 draft complaints to website operators whose cookie banners violate the GDPR, offering a 60‑day grace period before filing formal complaints. If companies do not fully comply, noyb will file complaints with DPAs, which may…
Data Protection Authorities · General Data Protection Regulation
Low Enforcement Filed DE-HE · Feb 25, 2022
noyb files complaint against giropay for processing detailed purchase data
The German payment service giropay stores item‑by‑item purchase information from online shops, including health‑related and sexual‑preference data. noyb lodged a complaint with the Hessian State Commissioner for Data Protection, alleging…
Hessian State Commissioner for Data Protection and Freedom of Information · General Data Protection Regulation
Moderate Enforcement Announced European Union · Jan 23, 2022
noyb reports low GDPR enforcement rates on Data Protection Day
noyb disclosed that only 15% of its 51 GDPR complaints were decided within a year and no pan‑European case has been resolved under the one‑stop‑shop mechanism. The organization highlights delays across DPAs, including a three‑year‑plus…
EDPB · General Data Protection Regulation
Moderate Enforcement Published European Union · Jan 11, 2022
EDPS reprimands European Parliament for illegal EU‑US data transfers via Google and Stripe
The European Data Protection Supervisor (EDPS) issued a decision reprimanding the European Parliament for violating data protection law on its COVID‑testing website. The use of Google Analytics and Stripe was found to breach the CJEU's…
European Data Protection Supervisor (EDPS) · General Data Protection Regulation
Moderate Fine In effect Norway (EEA) · Dec 15, 2021 · effective Dec 15, 2021
Norwegian DPA fines Grindr €6.3 M for illegal sharing of sensitive data
The Norwegian Data Protection Authority imposed a fine of 65 Mio NOK on Grindr for sharing sensitive personal data without valid consent. The authority found the consent mechanism invalid and highlighted the lack of a genuine opt‑out. The…
Norwegian Data Protection Authority · General Data Protection Regulation
Low Enforcement In effect Ireland · Nov 23, 2021 · effective Nov 18, 2021
Irish DPC removes noyb from GDPR procedure after demanding NDA
The Irish Data Protection Commission (DPC) demanded that privacy activist group noyb sign a non‑disclosure agreement to continue hearing its complaint against Facebook. After noyb refused, the DPC removed the organization from the GDPR…
Irish Data Protection Commission · General Data Protection Regulation
Low Enforcement Filed Germany · Oct 18, 2021
noyb files GDPR complaint against Acxiom and CRIF Bürgel over illegal credit scores
noyb lodged a complaint in Germany alleging that address trader Acxiom and credit reference agency CRIF Bürgel illegally use personal data to calculate credit scores without consent, violating the GDPR and the German Federal Data…
EDPB · General Data Protection Regulation
Moderate Enforcement Announced Ireland · Oct 15, 2021
Irish DPC orders noyb to remove draft decision from website
The Irish Data Protection Commission sent a take‑down request to privacy activist group noyb on 14 Oct 2021, ordering removal of a draft decision that allegedly strips Facebook users of GDPR rights. noyb refused, citing Austrian law and…
Irish Data Protection Commission · General Data Protection Regulation
Moderate Enforcement Filed European Union · Aug 13, 2021
noyb files complaints against cookie paywalls of seven German and Austrian news sites over unlawful consent
noyb filed complaints against the cookie paywalls of SPIEGEL.de, Zeit.de, heise.de, FAZ.net, derStandard.at, krone.at and t-online.de, arguing that the "pay or okay" model violates the GDPR's requirement for freely given consent. The…
EDPB · General Data Protection Regulation
← NewerOlder →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13