Moderate
Guidance
Announced
United States (federal) · Aug 5, 2026
Future of Privacy Forum releases updated AI risk assessment framework and best practices for hiring
Future of Privacy Forum and leading HR software firms released Updated Best Practices for AI and Workplace Assessment Technologies, addressing generative and agentic AI in employment. The guidance outlines a risk assessment framework and…
EU AI Office · EU AI Act
Moderate
Proposed bill
In committee
United States (federal) · Aug 5, 2026
Senate Commerce Committee to vote on four privacy‑invasive bills (KOSA, SCREEN Act, Youth AI Privacy Act, CHATBOT Act)
The Senate Commerce Committee will vote this week on four bills: KOSA, the SCREEN Act, the Youth AI Privacy Act, and the CHATBOT Act. The bills are presented as child‑protection measures but are criticized for creating new privacy and…
U.S. Senate Commerce Committee · KOSA
Moderate
Guidance
Announced
European Union · Dec 10, 2025
EU‑US data transfers face imminent risk as US legal changes could undermine TAFPF and SCCs
The blog notes that most EU‑US transfers rely on the Transatlantic Data Privacy Framework (TAFPF) or Standard Contract Clauses (SCCs), which depend on fragile US laws and executive orders. It warns that upcoming US Supreme Court decisions…
EDPB · General Data Protection Regulation
Moderate
Proposed regulation
Proposed
European Union · Nov 22, 2025
EU Commission proposes Digital Omnibus package with new personal data definition and research exemption
The European Commission has released the Digital Omnibus proposal, introducing a narrower definition of personal data (Art. 4(1)), a broader research exemption (Arts. 4(38), 5(1)(b), 13, 89), and new AI‑related rules (Arts. 9(2)(k), 9(5)…
European Commission · General Data Protection Regulation
Moderate
Proposed regulation
Proposed
European Union · Nov 11, 2025
Open letter warns EU Commission's Digital Omnibus draft could deregulate GDPR
Noyb, EDRi and the Irish Council for Civil Liberties sent an open letter to the European Commission criticizing a draft Digital Omnibus that would amend core GDPR provisions. The draft proposes redefining personal data, weakening data…
European Commission · General Data Protection Regulation
Moderate
Data protection authority action
Decided
Ireland · Jul 16, 2025
DPC issues final decision reprimanding Children’s Health Ireland for GDPR security breaches
The Irish Data Protection Commission concluded that Children’s Health Ireland (CHI) at Tallaght University Hospital breached GDPR security and confidentiality obligations. CHI was reprimanded and ordered to bring its processing into…
Data Protection Commission (Ireland) · General Data Protection Regulation
Low
Enforcement
Filed
DE-NRW · Feb 12, 2025
noyb files complaint against WetterOnline for refusing GDPR access request
WetterOnline shares precise location data with more than 300 third‑party advertising companies and rejected a data‑subject access request, citing a "disproportionate effort". noyb filed a complaint with the North Rhine‑Westphalia data…
Data protection authority of North Rhine-Westphalia · General Data Protection Regulation
Moderate
Executive order
Signed
United States (federal) · Jan 23, 2025
Trump signs executive order that could dismantle EU-US Transatlantic Data Privacy Framework
The US President signed an executive order stating that all Biden-era national security decisions, including those underpinning the EU‑US data transfer framework, will be reviewed and possibly revoked within 45 days. The Transatlantic Data…
European Commission · EU-U.S. Data Privacy Framework
Moderate
Enforcement
Filed
European Union · Jan 16, 2025
noyb files GDPR complaints against TikTok, AliExpress, SHEIN, Temu, WeChat and Xiaomi over transfers to China
noyb has lodged six GDPR complaints in five EU countries alleging unlawful transfers of Europeans' personal data to China by TikTok, AliExpress, SHEIN, Temu, WeChat and Xiaomi. The complaints request that DPAs suspend the transfers under…
European Commission · Standard Contractual Clauses
Moderate
Enforcement
Filed
European Union · Aug 22, 2024
noyb files two complaints with EDPS over EU Parliament recruitment platform data breach
In early May 2024 the European Parliament disclosed a massive breach of its PEOPLE recruitment platform affecting over 8,000 staff. noyb filed two complaints with the European Data Protection Supervisor alleging violations of the EU GDPR…
European Data Protection Supervisor · General Data Protection Regulation
High
Fine
In effect
Ireland · May 24, 2024 · effective Aug 25, 2026
Irish Data Protection Commission fines HSE €645,000 for GDPR breaches over paper record storage
The Data Protection Commission (DPC) issued a final decision on 25 August 2026, fining the Health Service Executive (HSE) €645,000 for multiple GDPR infringements related to the storage and security of paper medical records. The DPC also…
Data Protection Commission (Ireland) · General Data Protection Regulation
Moderate
Enforcement
Pending
European Union · Jan 28, 2024
Survey finds 74% of insiders say authorities would find GDPR violations in average EU company
A noyb survey of over 1,000 data‑protection professionals reports that 74% believe authorities would discover relevant GDPR violations during on‑site inspections. Respondents cite lack of clear DPA decisions, fines, and public enforcement…
EDPB · General Data Protection Regulation
Moderate
Enforcement
Filed
European Union · Nov 16, 2023
noyb files complaint with EDPS over EU Commission’s political micro‑targeting ads on X
noyb lodged a complaint with the European Data Protection Supervisor alleging the EU Commission used unlawful micro‑targeting on X to promote its chat‑control proposal. The ads targeted users based on political views and religious beliefs…
European Data Protection Supervisor (EDPS) · General Data Protection Regulation
Moderate
Proposed regulation
Announced
European Union · Jul 10, 2023
EU Commission adopts third Trans-Atlantic Data Privacy Framework, likely to face CJEU challenge
The European Commission has introduced a new Trans-Atlantic Data Privacy Framework as its third attempt to secure an EU‑US data transfer adequacy decision. Privacy‑rights group noyb says it will challenge the decision before the Court of…
European Commission · EU-U.S. Data Privacy Framework
Moderate
Fine
In effect
Sweden · Jul 3, 2023
Swedish DPA fines Tele2 €1M and CDON €0.3M for illegal use of Google Analytics
The Swedish Data Protection Authority (IMY) issued decisions against four companies for unlawful EU‑US data transfers via Google Analytics. It imposed a fine of 12 mio SEK (≈€1 M) on Tele2 and 300 000 SEK on CDON. The authority also…
Swedish Data Protection Authority (IMY) · General Data Protection Regulation
Moderate
Fine
Announced
Ireland · May 22, 2023
Irish DPC imposes €1.2 billion fine on Meta for EU‑US data transfers
The Irish Data Protection Commission, backed by the European Data Protection Board, ordered Meta to cease all transfers of European personal data to the United States and to return data already transferred to EU data centres. The decision…
Irish Data Protection Commission · Standard Contractual Clauses
Low
Enforcement
Published
Austria · Mar 16, 2023
Austrian DSB declares Meta tracking tools illegal under GDPR
The Austrian Data Protection Authority ruled that Meta's tracking pixel, Facebook Login and Meta Pixel violate the GDPR and the Schrems II decision on transatlantic data transfers. The decision advises EU website operators not to use any…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate
Executive order
Signed
United States (federal) · Oct 7, 2022
US President Biden signs Executive Order on surveillance, unlikely to satisfy EU law
President Joe Biden signed a new Executive Order intended to address EU concerns over US surveillance practices. The order retains bulk surveillance and creates a non‑judicial “Data Protection Review Court,” which the source says does not…
EDPB · General Data Protection Regulation
Moderate
Enforcement
Announced
European Union · May 24, 2022
noyb warns of widespread GDPR non‑compliance and lack of enforcement after four years
The NGO noyb states that despite the GDPR becoming applicable on 25 May 2018, many companies continue to ignore users' rights and enforcement remains weak. It notes that about 50 cross‑country cases it filed have not yet received a final…
EDPB · General Data Protection Regulation
Moderate
Interpretation
Announced
European Union · May 22, 2022
Open Letter warns EU‑US data transfer deal lacks material US law changes
The open letter published on 2022‑05‑22 criticises the announced Trans‑Atlantic Data Privacy Framework for relying on US executive orders without substantive changes to US surveillance law. It argues that the framework repeats the…
EDPB · General Data Protection Regulation