Low
Guidance
Published
Global · Aug 31, 2026
EFF and The Trevor Project advise LGBTQ+ individuals to revise shared information for online safety
The Electronic Frontier Foundation and The Trevor Project provide practical steps for LGBTQ+ people to protect their personal information online. Advice includes limiting disclosure of identifying details, using avatars, disabling EXIF…
Moderate
Guidance
Published
SG · Aug 25, 2026
PDPC publishes Advisory Guidelines on Personal Data in Generative AI at Singapore Data Festival
On July 20, 2026, Singapore’s Personal Data Protection Commission released its finalized Advisory Guidelines on the Use of Personal Data in Generative AI. The guidance clarifies the Publicly Available Exception for web‑scraping and…
Personal Data Protection Commission (PDPC) · EU AI Act
Low
Guidance
Announced
United States (federal) · Aug 13, 2026
Flock Safety announces optional 7‑day ALPR data retention and other reforms
Flock Safety introduced a default optional 7‑day retention period for automated license plate reader (ALPR) data, reduced from the previous 30‑day default. Retention beyond this period requires activation of “Evidence Mode,” tied to an…
Low
Guidance
Published
United States (federal) · Aug 11, 2026
EFF states all images are human-generated, with rare AI exceptions
EFF announced that its blog and merchandise images are created by human designers, not AI image generators, except for rare cases that are explicitly credited. The organization added a credit label "Image created by EFF" to banner images…
Creative Commons Attribution (CC‑By) license
Moderate
Guidance
Announced
United States (federal) · Aug 5, 2026
Future of Privacy Forum releases updated AI risk assessment framework and best practices for hiring
Future of Privacy Forum and leading HR software firms released Updated Best Practices for AI and Workplace Assessment Technologies, addressing generative and agentic AI in employment. The guidance outlines a risk assessment framework and…
EU AI Office · EU AI Act
Moderate
Guidance
Announced
Spain · Jul 28, 2026
AEPD Privacy Lab invites entities to submit projects, research and initiatives
The AEPD's Privacy Lab has opened its Novedades space for publications, research projects, calls and activities related to privacy, data protection, AI and emerging technologies. Universities, research centres, public and private…
Agencia Española de Protección de Datos (AEPD) · Genetic Information Nondiscrimination Act
Moderate
Guidance
Announced
Spain · Jul 27, 2026
AEPD announces 2026 Data Protection Awards to recognize privacy promotion
The Spanish Data Protection Agency (AEPD) has launched the ‘Premios Protección de Datos 2026’ with nine categories covering research, vulnerable groups, communication, education, best practices, legal research, social media diffusion, DPO…
Agencia Española de Protección de Datos (AEPD) · RGPD
Moderate
Guidance
Announced
European Union · Jul 23, 2026
EDPB announces stakeholder event on upcoming data protection and competition law guidelines (15 Oct 2026)
The European Data Protection Board and the European Commission will hold a remote stakeholder event on 15 October 2026 to discuss upcoming guidelines on the interplay between competition law and data protection. The event invites…
European Data Protection Board · General Data Protection Regulation
Moderate
Guidance
Announced
Spain · Jul 23, 2026 · effective Jul 23, 2026
AEPD reopens registration for public research network on privacy and emerging technologies
The Spanish Data Protection Agency (AEPD) has reopened enrollment for its public network of research groups and projects focused on privacy and emerging technologies. The new registration phase allows groups that missed the first call and…
Agencia Española de Protección de Datos
Moderate
Guidance
Published
Spain · Jul 21, 2026
AEPD publishes technical guidance on data accuracy and minimisation in AI processing
The Spanish Data Protection Agency (AEPD) released a technical note interpreting the GDPR accuracy and data‑minimisation principles for AI‑driven personal data processing. It provides criteria for controllers, processors and DPOs to assess…
Agencia Española de Protección de Datos · RGPD
Moderate
Guidance
Announced
European Union · Jul 17, 2026
EDPB calls for legal basis for cross‑regulatory information sharing
The European Data Protection Board urged the European Commission to create a clear legal basis for regulators to share information across competences. It highlighted the need for stronger legislation to enable confidential information…
European Data Protection Board · General Data Protection Regulation
Moderate
Interpretation
Published
Belgium · Jul 14, 2026 · effective May 28, 2026
EDPB orders Belgian DPA to assess NOYB cookie banner complaint on merits
The European Data Protection Board issued a binding decision on 28 May 2026 requiring the Belgian DPA to evaluate a NOYB complaint about VRT's cookie banners on the merits rather than dismiss it on procedural grounds. The decision found no…
European Data Protection Board · General Data Protection Regulation
Moderate
Guidance
Published
European Union · May 28, 2026
ENISA releases NIS360 report showing improved cybersecurity maturity of EU critical sectors
The ENISA NIS360 report released on 28 May 2026 indicates that cybersecurity maturity across EU critical sectors has improved, while sector criticality remains relatively stable. The report identifies a risk zone of sectors with lower…
ENISA · NIS2 Directive
Moderate
Guidance
Published
European Union · Feb 11, 2026
EU DPAs reject key proposals in Digital Omnibus GDPR changes
The European Data Protection Board and the European Data Protection Supervisor issued a joint opinion rejecting the Commission's proposal to narrow the definition of personal data and to restrict the right of access. They also raised…
European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) · ePrivacy Directive
Moderate
Guidance
Announced
European Union · Dec 10, 2025
EU‑US data transfers face imminent risk as US legal changes could undermine TAFPF and SCCs
The blog notes that most EU‑US transfers rely on the Transatlantic Data Privacy Framework (TAFPF) or Standard Contract Clauses (SCCs), which depend on fragile US laws and executive orders. It warns that upcoming US Supreme Court decisions…
EDPB · General Data Protection Regulation
Low
Guidance
Published
European Union · Dec 4, 2025
EDPB publishes first opinion on Pay or Okay, urging a three‑option consent model
In April 2024 the European Data Protection Board released its first opinion on Pay or Okay systems, recommending a third choice of "advertising, but no tracking" alongside pay and consent options. A noyb‑commissioned study shows that users…
European Data Protection Board
Moderate
Guidance
Published
European Union · Oct 1, 2025
ENISA releases cybersecurity awareness tools and skills framework for EU workplaces
ENISA, together with the European Commission, promotes cybersecurity in the EU through the European Cybersecurity Month and new guidance tools such as AR-in-a-Box and the European Cybersecurity Skills Framework. The agency highlights the…
ENISA · NIS2 Directive
Moderate
Guidance
Announced
European Union · Jul 24, 2025
Report flags 'Pay or Okay' consent‑bypass systems as violating GDPR free‑consent requirement
The noyb report documents the spread of “Pay or Okay” systems across Europe, where users must pay to refuse tracking, resulting in near‑universal consent rates that breach the GDPR’s freely‑given consent standard. It cites a July 2023 CJEU…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate
Guidance
Published
United States (federal) · Mar 31, 2025
2024 HMDA Modified LAR Data Now Available on FFIEC Platform
The Home Mortgage Disclosure Act (HMDA) Modified Loan Application Register data for 2024 have been released on the FFIEC HMDA Platform for about 4,898 filers. The loan‑level data are modified to protect consumer privacy and are now…
Consumer Financial Protection Bureau · Home Mortgage Disclosure Act
Moderate
Interpretation
In effect
European Union · Dec 2, 2024 · effective Dec 2, 2024
noyb qualified as EU 'Qualified Entity' to bring collective GDPR redress actions
noyb has been approved as a Qualified Entity under Directive (EU) 2020/1828, allowing it to bring collective injunctions and redress actions across the EU. Approvals were issued by Austria's Bundeskartellamt on 2 December 2024 and…
Bundeskartellamt; Irish Ministry for Justice · General Data Protection Regulation