REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: privacy · clear
88 developments
Moderate Guidance Published United States (federal) · Mar 31, 2025
2024 HMDA Modified LAR Data Now Available on FFIEC Platform
The Home Mortgage Disclosure Act (HMDA) Modified Loan Application Register data for 2024 have been released on the FFIEC HMDA Platform for about 4,898 filers. The loan‑level data are modified to protect consumer privacy and are now…
Consumer Financial Protection Bureau · Home Mortgage Disclosure Act
Moderate Interpretation In effect European Union · Dec 2, 2024 · effective Dec 2, 2024
noyb qualified as EU 'Qualified Entity' to bring collective GDPR redress actions
noyb has been approved as a Qualified Entity under Directive (EU) 2020/1828, allowing it to bring collective injunctions and redress actions across the EU. Approvals were issued by Austria's Bundeskartellamt on 2 December 2024 and…
Bundeskartellamt; Irish Ministry for Justice · General Data Protection Regulation
Low Guidance Published European Union · Jul 11, 2024
noyb releases Consent Banner Report comparing EDPB taskforce findings with national DPA positions
noyb published a report that compares the European Data Protection Board's Cookie Banner Taskforce recommendations with guidance and decisions from national DPAs across Europe. The report highlights the minimum thresholds set by the EDPB…
Moderate Guidance Announced European Union · Feb 16, 2024
28 NGOs urge EU Data Protection Board to reject Meta's 'Pay or Okay' consent model
A coalition of 28 NGOs, including Wikimedia Europe, Bits of Freedom and the Norwegian Consumer Council, sent a joint letter to the European Data Protection Board requesting a binding opinion on Meta's "Pay or Okay" system, which forces…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate Interpretation Announced European Union · Oct 3, 2023
Meta proposes 'Pay for your Rights' model charging EU users €160/year for non‑consent
Meta plans to charge EU users €160 per year if they do not consent to the processing of their personal data on Facebook and Instagram. The proposal references an obiter dictum from the CJEU case C‑252/21 that an alternative to ads may be…
Irish Data Protection Commission · General Data Protection Regulation
Low Interpretation Published Austria · Apr 11, 2023
Austrian DPA says "Pay or Okay" cookie paywalls must allow specific consent
The Austrian Data Protection Authority partially reversed its earlier stance on the "Pay or Okay" model used by Der Standard, confirming its general permissibility but requiring that users be able to say "yes" or "no" to each specific data…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Guidance Announced European Union · Apr 4, 2023
noyb launches free tool for broad Facebook opt‑out under GDPR
The privacy NGO noyb released an online tool that lets users submit a broad objection to Meta’s processing of personal data for targeted advertising, which Meta bases on “legitimate interest”. The tool simplifies the GDPR right to object…
EDPB · General Data Protection Regulation
Moderate Interpretation Announced European Union · May 22, 2022
Open Letter warns EU‑US data transfer deal lacks material US law changes
The open letter published on 2022‑05‑22 criticises the announced Trans‑Atlantic Data Privacy Framework for relying on US executive orders without substantive changes to US surveillance law. It argues that the framework repeats the…
EDPB · General Data Protection Regulation
Moderate Interpretation Published Austria · May 2, 2022
Austrian DPA rejects risk‑based approach for EU‑US data transfers, deems Google IP anonymisation insufficient
The Austrian Data Protection Authority issued a decision stating that the GDPR does not permit a risk‑based approach for transfers to insecure third countries such as the United States. It also concluded that Google’s IP anonymisation does…
Austrian Data Protection Authority · General Data Protection Regulation
Low Guidance Published European Union · Sep 2, 2021
noyb hires GDPR lawyers and full stack developers
noyb announced job openings for GDPR lawyers and full stack developers. The announcement invites referrals and directs interested candidates to the job page. It seeks to expand the team to handle its workload.
EDPB · General Data Protection Regulation
Low Interpretation Announced Ireland · Apr 27, 2021
Irish DPC admits it does not decide GDPR complaints, handling 99.93% without decision
The Irish Data Protection Commissioner publicly stated that it does not issue decisions on GDPR complaints, with 99.93% of cases remaining without a decision. The DPC argued there is no obligation under the 2018 Act to produce a decision…
Irish Data Protection Commissioner (DPC) · General Data Protection Regulation
Moderate Guidance Published European Union · Jan 27, 2021
noyb urges stronger GDPR enforcement on European Data Protection Day
noyb highlights that despite the GDPR's strong provisions, compliance remains low and enforcement insufficient. The organization calls on data protection authorities and companies to move from paper rights to real protection, citing the…
EDPB · General Data Protection Regulation
Low Interpretation Announced United States (federal) · Dec 9, 2020
US Senate Commerce Committee holds hearing on EU‑US data transfers after Schrems II
The Committee on Commerce, Science and Transportation of the United States Senate scheduled a hearing on EU‑US data transfers following the CJEU Schrems II decision. Witnesses include representatives from the FTC, the Department of…
EU‑US Privacy Shield
Low Guidance Published Belgium · Oct 29, 2020
Belgian Ministerial Decree approves noyb as qualified entity to file class actions
In September, the Belgian Official Journal published a Ministerial Decree approving noyb as a qualified entity under the collective action scheme of the Belgian Code of Economic Law. This authorisation enables noyb to file representative…
EDPB · General Data Protection Regulation
Moderate Interpretation Published European Union · Oct 29, 2020
noyb reaches 3,000 subscribers for GDPRtoday newsletter
The organization noyb announced that its GDPRtoday newsletter has surpassed 3,000 subscribers within ten months. The newsletter provides English summaries of GDPR decisions from across Europe and has translated and summarized over 500…
EDPB · General Data Protection Regulation
Low Guidance Announced European Union · Sep 8, 2020
noyb publishes 2018-2019 annual report
The report outlines noyb's funding, membership growth, and operational costs as a European non‑profit focused on strategic litigation to uphold the GDPR. It details the organization’s budget aims and the proportion of recurring support…
EDPB · General Data Protection Regulation
Low Interpretation Published European Union · Sep 4, 2020
Max Schrems testifies at European Parliament hearing on EU‑US data transfers
Max Schrems, EU Commissioner for Justice Didier Reynders, and EDPB head Andrea Jelinek debated the EU‑US data transfer judgment that invalidated the Privacy Shield and addressed the validity of standard contractual clauses. The hearing…
European Commission · Standard Contractual Clauses
High Guidance Published European Union · Jul 24, 2020 · effective Jul 16, 2020
noyb provides step-by-step guide for EU users to stop US data transfers after Schrems II
The document outlines how data subjects can exercise GDPR rights to learn about and halt transfers of their personal data to the United States following the CJEU Schrems II judgment. It provides sample request letters for information…
European Commission · Standard Contractual Clauses
Moderate Guidance Published European Union · Jul 20, 2020
noyb releases guidance for EU companies on Schrems II data‑transfer obligations
The guidance explains steps EU controllers should take after the CJEU Schrems II judgment, including reviewing data flows, stopping transfers that rely on the invalidated Privacy Shield, and notifying DPAs when using SCCs after a negative…
EDPB · General Data Protection Regulation
Moderate Interpretation Published European Union · Jun 24, 2020
EDPB responds to noyb open letter on Facebook case procedural concerns
The European Data Protection Board acknowledged the issues raised by noyb regarding the Irish DPA's handling of the Facebook case and said it is working to improve consistency procedures and cooperation among supervisory authorities. No…
European Data Protection Board · General Data Protection Regulation
← NewerOlder →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13