REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: data minimization · clear
123 developments
Moderate Court ruling Decided Germany · Jul 4, 2023
CJEU rules Meta must rely on consent for advertising, limiting GDPR bypass attempts
The Court of Justice of the EU held that Meta may only process personal data for core services and must obtain freely given consent for advertising and data sharing. The judgment rejects Meta's reliance on contractual necessity and…
EDPB · General Data Protection Regulation
Low Enforcement Filed European Union · Jun 1, 2023
Credit agency CRIF systematically withholds data from consumers, noyb files complaint
noyb has filed a complaint with the data protection authority alleging that CRIF violates GDPR Article 15 by providing incomplete access to personal data. The complaint cites systematic withholding of source information and limited…
EDPB · General Data Protection Regulation
Moderate Proposed regulation Proposed European Union · May 23, 2023
EU Commission proposes GDPR Procedures Regulation to address enforcement delays
Noyb calls for an EU procedural regulation to fix widespread delays and procedural tricks in GDPR enforcement across member states. The European Commission has indicated interest in such a regulation and also in the upcoming EU Collective…
European Commission · General Data Protection Regulation
Moderate Fine Announced Ireland · May 22, 2023
Irish DPC imposes €1.2 billion fine on Meta for EU‑US data transfers
The Irish Data Protection Commission, backed by the European Data Protection Board, ordered Meta to cease all transfers of European personal data to the United States and to return data already transferred to EU data centres. The decision…
Irish Data Protection Commission · Standard Contractual Clauses
Moderate Data protection authority action Decided Austria · May 10, 2023
Austrian DPA deems Clearview AI’s biometric data processing illegal, orders deletion, no fine
The Austrian Data Protection Authority ruled that Clearview AI may not process the complainant’s biometric data and must delete the data. The decision cites GDPR violations for scraping and selling personal data of Europeans. No monetary…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Data protection authority action Decided Austria · Mar 27, 2023
Austrian DPA rules CRIF's processing of Austrian citizens' personal data illegal
The Austrian Data Protection Authority found that CRIF GmbH illegally processed addresses, dates of birth, names and other personal data of millions of Austrians obtained from AZ Direkt without consent or legal basis, ordering the deletion…
Austrian Data Protection Authority · General Data Protection Regulation
Low Enforcement Filed Germany · Mar 21, 2023
noyb files GDPR complaints against German parties for political microtargeting on Facebook
noyb filed a series of complaints against several German political parties alleging unlawful political microtargeting on Facebook during the 2021 federal election. The complaints claim violations of the GDPR because the parties and…
EDPB · General Data Protection Regulation
Moderate Court ruling Decided Austria · Mar 17, 2023
Austrian Federal Administrative Court allows mobile providers to refuse access requests for location data without proof of exclusive use
The Austrian Federal Administrative Court (BVwG) ruled that A1 Telekom Austria may deny a data subject's request for traffic and location data unless the subject can prove exclusive use of the phone. The court deemed location data…
EDPB · General Data Protection Regulation
Low Enforcement Published Austria · Mar 16, 2023
Austrian DSB declares Meta tracking tools illegal under GDPR
The Austrian Data Protection Authority ruled that Meta's tracking pixel, Facebook Login and Meta Pixel violate the GDPR and the Schrems II decision on transatlantic data transfers. The decision advises EU website operators not to use any…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Enforcement Filed European Union · Feb 28, 2023
noyb files complaints against data brokers for refusing cookie‑based authentication of GDPR access requests
noyb lodged a series of complaints against websites and data brokers that denied or complicated GDPR access requests by requiring additional identification beyond cookies. The complaints argue that, under GDPR and EDPB guidance, users…
EDPB · General Data Protection Regulation
Moderate Guidance Published European Union · Jan 24, 2023
EDPB releases draft report on minimum requirements for cookie consent banners
The European Data Protection Board's task force issued a draft report outlining unlawful cookie banner practices under EU law. It sets a minimum threshold for consent banners, including the need for a visible reject option and prohibition…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate Enforcement Published Ireland · Jan 11, 2023
Irish DPC fines Meta €60m for unlawful processing and €150m for transparency breaches
The Irish Data Protection Commission (DPC) issued a final decision imposing a €150 million fine on Facebook for transparency failures and a €60 million fine on Meta for lacking a legal basis to process personal data. The decision also…
Irish Data Protection Commission · General Data Protection Regulation
Moderate Fine Decided European Union · Jul 21, 2022
6.3 million Euro fine imposed on Grindr for GDPR violations
noyb’s complaints resulted in a 6.3 million Euro fine against the gay dating app Grindr for breaching the GDPR. The fine was highlighted in noyb’s 2021 Annual Report.
EDPB · General Data Protection Regulation
High Fine In effect Greece · Jul 13, 2022
Greek DPA fines Clearview AI €20 million and bans biometric processing
The Greek Data Protection Authority imposed a €20 million fine on Clearview AI and prohibited the company from processing biometric data of individuals in Greece. Clearview must delete all existing facial‑recognition data of Greek citizens…
Greek Data Protection Authority · General Data Protection Regulation
Moderate Enforcement In effect European Union · Jul 5, 2022
EU DPAs ban use of Google Analytics over unlawful US data transfers
The Italian Data Protection Authority (GPDP) declared Google Analytics illegal because it transfers personal data to the United States. French CNIL and Austrian DPA issued similar orders, requiring websites to stop using the service. The…
Italian Data Protection Authority (GPDP) · General Data Protection Regulation
Moderate Interpretation Announced European Union · May 22, 2022
Open Letter warns EU‑US data transfer deal lacks material US law changes
The open letter published on 2022‑05‑22 criticises the announced Trans‑Atlantic Data Privacy Framework for relying on US executive orders without substantive changes to US surveillance law. It argues that the framework repeats the…
EDPB · General Data Protection Regulation
Moderate Interpretation Published Austria · May 2, 2022
Austrian DPA rejects risk‑based approach for EU‑US data transfers, deems Google IP anonymisation insufficient
The Austrian Data Protection Authority issued a decision stating that the GDPR does not permit a risk‑based approach for transfers to insecure third countries such as the United States. It also concluded that Google’s IP anonymisation does…
Austrian Data Protection Authority · General Data Protection Regulation
High Fine In effect Italy · Mar 10, 2022
Italian DPA fines Clearview AI €20 million and bans biometric processing
The Italian data protection authority imposed a €20 million fine on Clearview AI and prohibited the company from processing biometric data of individuals in Italy. Clearview must delete all existing biometric data of Italian citizens and…
Italian Data Protection Authority · General Data Protection Regulation
Low Enforcement Filed DE-HE · Feb 25, 2022
noyb files complaint against giropay for processing detailed purchase data
The German payment service giropay stores item‑by‑item purchase information from online shops, including health‑related and sexual‑preference data. noyb lodged a complaint with the Hessian State Commissioner for Data Protection, alleging…
Hessian State Commissioner for Data Protection and Freedom of Information · General Data Protection Regulation
Moderate Fine In effect Malta · Jan 20, 2022
Malta data protection commissioner fines C-Planet €65,000 for illegal voter data collection
The Malta Information & Data Protection Commissioner (IDPC) imposed a €65,000 fine on IT company C-Planet for unlawfully collecting personal data of 98% of Maltese voters, including political preferences. The IDPC found the processing…
Information & Data Protection Commissioner (IDPC) · General Data Protection Regulation
← NewerOlder →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13