REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: privacy · clear
161 developments
Moderate Enforcement Filed Austria · Nov 28, 2023
noyb files GDPR complaint against Meta over “Pay or Okay” tracking fee
noyb lodged a complaint with the Austrian Data Protection Authority alleging that Meta’s practice of charging users up to €251.88 a year to avoid personalized advertising violates GDPR consent requirements. The complaint references the…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate Enforcement Filed European Union · Nov 16, 2023
noyb files complaint with EDPS over EU Commission’s political micro‑targeting ads on X
noyb lodged a complaint with the European Data Protection Supervisor alleging the EU Commission used unlawful micro‑targeting on X to promote its chat‑control proposal. The ads targeted users based on political views and religious beliefs…
European Data Protection Supervisor (EDPS) · General Data Protection Regulation
Moderate Fine Decided Norway (EEA) · Sep 29, 2023
Norwegian Privacy Appeals Board upholds €5.8 million fine against Grindr
The Norwegian Privacy Appeals Board confirmed the Norwegian Data Protection Authority's fine of NOK 65 million against the dating app Grindr for sharing sensitive personal data with third parties. The fine, approximately €5.8 million…
Norwegian Data Protection Authority · General Data Protection Regulation
Moderate Enforcement Filed European Union · Aug 31, 2023
noyb files complaints against Fitbit in Austria, Netherlands, Italy over forced consent for data transfers
noyb lodged three complaints with the Austrian, Dutch and Italian data protection authorities alleging that Fitbit forces new EU users to consent to transfers of personal and health data to the United States and other countries. The…
Austrian Data Protection Authority, Dutch Data Protection Authority, Italian Data Protection Authority · General Data Protection Regulation
High Penalty Published European Union · Aug 23, 2023
EU data protection board draft decision imposes €390 million fine on Meta for forced consent
In December 2022, the European Data Protection Board (EDPB) published a draft decision in the “forced consent” case against Meta, finding the company's practices violated the GDPR. The decision resulted in a €390 million fine. The case…
European Data Protection Board · General Data Protection Regulation
Moderate Enforcement Pending European Union · Aug 14, 2023
noyb reports 23 years of illegal EU‑US data transfers and limited enforcement actions
The EU Court of Justice invalidated the Safe Harbor and Privacy Shield deals in 2015 and 2020, making all EU‑US data transfers since 2000 illegal. Despite this, most DPAs have not acted on 101 complaints filed by noyb, with only Sweden…
European Commission · EU-U.S. Data Privacy Framework
Moderate Enforcement Announced European Union · Aug 1, 2023
Meta to switch to consent for behavioral ads after EU litigation
Meta announced it will seek user consent before showing behavioral ads in the EU and Switzerland, changing its legal basis from legitimate interest to consent. The move follows litigation by noyb, decisions by the EDPB and the CJEU, and a…
Irish Data Protection Commission · General Data Protection Regulation
High Data protection authority action Filed Spain · Jul 27, 2023
noyb files complaint with Spanish DPA over Ryanair’s facial‑recognition verification for travel‑agent bookings
noyb lodged a complaint with Spain's Data Protection Authority (AEPD) alleging that Ryanair forces customers who book via online travel agents to undergo a facial‑recognition verification process. The complaint argues that Ryanair lacks a…
Spanish Data Protection Authority (AEPD) · General Data Protection Regulation
Moderate Enforcement Settled Belgium · Jul 19, 2023
Belgian DPA settles with news outlets, allowing them to avoid GDPR compliance
Fifteen Belgian news sites paid €10,000 each in a settlement with the Belgian Data Protection Authority, which closed the cases without ordering changes to unlawful cookie banners. noyb filed complaints to force the DPA to reopen…
Belgian Data Protection Authority · General Data Protection Regulation
Moderate Enforcement In effect Norway (EEA) · Jul 17, 2023 · effective Aug 4, 2023
Norwegian DPA temporarily bans Meta’s behavioral advertising on Facebook and Instagram
The Norwegian Data Protection Authority (Datatilsynet) issued a temporary ban on Meta's use of behavioral advertising on Facebook and Instagram, effective from August 4 for at least three months. The ban remains until Meta can demonstrate…
Datatilsynet · General Data Protection Regulation
Low Enforcement Decided DE-NI · Jul 14, 2023
German DPA declares heise.de "Pay or Okay" cookie banner illegal
The Lower Saxony Data Protection Authority (LfD) ruled that the "Pay or Okay" model used by heise.de in 2021 violates GDPR because it does not provide specific consent for each purpose. The authority issued a reprimand, noting that…
Data Protection Authority of Lower Saxony (LfD) · General Data Protection Regulation
Moderate Fine In effect Sweden · Jul 3, 2023
Swedish DPA fines Tele2 €1M and CDON €0.3M for illegal use of Google Analytics
The Swedish Data Protection Authority (IMY) issued decisions against four companies for unlawful EU‑US data transfers via Google Analytics. It imposed a fine of 12 mio SEK (≈€1 M) on Tele2 and 300 000 SEK on CDON. The authority also…
Swedish Data Protection Authority (IMY) · General Data Protection Regulation
Moderate Fine Announced Ireland · May 22, 2023
Irish DPC imposes €1.2 billion fine on Meta for EU‑US data transfers
The Irish Data Protection Commission, backed by the European Data Protection Board, ordered Meta to cease all transfers of European personal data to the United States and to return data already transferred to EU data centres. The decision…
Irish Data Protection Commission · Standard Contractual Clauses
Moderate Data protection authority action Announced Malta · May 17, 2023
Maltese DPA orders C-PLANET to disclose data source within 20 days or face fine
The Maltese Data Protection Authority (IDPC) ordered IT company C-PLANET to provide details on the source of personal data collected on voters within 20 days. Failure to comply will result in a proportionate and dissuasive fine under the…
Maltese Data Protection Authority (IDPC) · General Data Protection Regulation
Moderate Data protection authority action Decided Austria · May 10, 2023
Austrian DPA deems Clearview AI’s biometric data processing illegal, orders deletion, no fine
The Austrian Data Protection Authority ruled that Clearview AI may not process the complainant’s biometric data and must delete the data. The decision cites GDPR violations for scraping and selling personal data of Europeans. No monetary…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low Enforcement Filed Germany · Mar 21, 2023
noyb files GDPR complaints against German parties for political microtargeting on Facebook
noyb filed a series of complaints against several German political parties alleging unlawful political microtargeting on Facebook during the 2021 federal election. The complaints claim violations of the GDPR because the parties and…
EDPB · General Data Protection Regulation
Low Enforcement Published Austria · Mar 16, 2023
Austrian DSB declares Meta tracking tools illegal under GDPR
The Austrian Data Protection Authority ruled that Meta's tracking pixel, Facebook Login and Meta Pixel violate the GDPR and the Schrems II decision on transatlantic data transfers. The decision advises EU website operators not to use any…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Enforcement Filed European Union · Feb 28, 2023
noyb files complaints against data brokers for refusing cookie‑based authentication of GDPR access requests
noyb lodged a series of complaints against websites and data brokers that denied or complicated GDPR access requests by requiring additional identification beyond cookies. The complaints argue that, under GDPR and EDPB guidance, users…
EDPB · General Data Protection Regulation
Low Enforcement Published Austria · Feb 6, 2023
Austrian DSB rules credit bureau KSV 1870 may not collect data via access requests and civil registries
The Austrian Data Protection Authority found KSV 1870's practice of storing information obtained through GDPR access requests and civil‑registry comparisons illegal, violating purpose‑limitation under Article 5(1)(b) GDPR. The DSB ordered…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Fine Announced Ireland · Jan 27, 2023
Irish DPC announces €390 million fine on Meta for GDPR consent breach
The Irish Data Protection Commission announced a €390 million fine against Meta, ordering it to obtain valid consent for personalized advertising after the European Data Protection Board issued a binding decision. The fine illustrates…
Irish Data Protection Commission · General Data Protection Regulation
← NewerOlder →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13