REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
113 developments
Low Interpretation Published European Union · Sep 4, 2020
Max Schrems testifies at European Parliament hearing on EU‑US data transfers
Max Schrems, EU Commissioner for Justice Didier Reynders, and EDPB head Andrea Jelinek debated the EU‑US data transfer judgment that invalidated the Privacy Shield and addressed the validity of standard contractual clauses. The hearing…
European Commission · Standard Contractual Clauses
High Guidance Published European Union · Jul 24, 2020 · effective Jul 16, 2020
noyb provides step-by-step guide for EU users to stop US data transfers after Schrems II
The document outlines how data subjects can exercise GDPR rights to learn about and halt transfers of their personal data to the United States following the CJEU Schrems II judgment. It provides sample request letters for information…
European Commission · Standard Contractual Clauses
Moderate Guidance Published European Union · Jul 20, 2020
noyb releases guidance for EU companies on Schrems II data‑transfer obligations
The guidance explains steps EU controllers should take after the CJEU Schrems II judgment, including reviewing data flows, stopping transfers that rely on the invalidated Privacy Shield, and notifying DPAs when using SCCs after a negative…
EDPB · General Data Protection Regulation
Moderate Interpretation Published European Union · Jun 24, 2020
EDPB responds to noyb open letter on Facebook case procedural concerns
The European Data Protection Board acknowledged the issues raised by noyb regarding the Irish DPA's handling of the Facebook case and said it is working to improve consistency procedures and cooperation among supervisory authorities. No…
European Data Protection Board · General Data Protection Regulation
Low Guidance Published Austria · Apr 21, 2020
First European Corona contact tracing app in Austria reviewed by noyb, epicenter.works and SBA Research
The Austrian Red Cross released a contact tracing app on March 25th, which uses a hybrid central‑server and local storage model. NGOs and security researchers reviewed the app and identified privacy weaknesses, recommending a switch to a…
Moderate Guidance Published European Union · Apr 9, 2020
noyb releases ad‑hoc guidance on GDPR compliance for COVID‑19 data processing
noyb published an ad‑hoc paper outlining how the GDPR permits processing personal data to combat the coronavirus pandemic. The paper cites Articles 6(1)(d) and 9(2)(i) as legal bases and stresses the need for privacy‑by‑design, data…
EDPB · General Data Protection Regulation
Moderate Guidance Published European Union · Apr 2, 2020
Noyb reports video conferencing tools' privacy policies fall short of GDPR obligations
The report examined the privacy policies of six video‑conferencing services (Zoom, Webex Meetings, Meeting, Skype, Teams, Wire) and found they lack clear GDPR information, such as basic rights and recipient details. An update on…
EDPB · General Data Protection Regulation
Moderate Interpretation Published European Union · Feb 26, 2020 · effective Feb 26, 2020
GDPRhub launches public wiki summarizing national GDPR decisions
A new public wiki, GDPRhub, provides searchable summaries of GDPR decisions by national DPAs and courts in English. The site aims to collect over 500 decisions by the end of 2020 and includes commentaries, DPA profiles, and jurisdictional…
EDPB · General Data Protection Regulation
Low Interpretation Published European Union · Dec 19, 2019
CJEU Advocate General opinion says DPAs must halt US data transfers when fundamental rights are breached
The Advocate General stated that Data Protection Authorities must stop data transfers if fundamental rights are violated. The opinion urges the Irish DPC to order Facebook to cease transfers and clarifies that SCCs contain a “pressure…
Court of Justice of the European Union · General Data Protection Regulation
Moderate Guidance Announced European Union · Jun 5, 2019
noyb and Access Now host workshop on GDPR enforcement actions in Vienna
The workshop “One year after GDPR: Advancing rights through effective enforcement actions” was held May 8‑10, 2019 in Vienna. It gathered NGOs, public authorities and researchers to discuss practical aspects of GDPR enforcement, noting…
EDPB · General Data Protection Regulation
Low Interpretation Announced Austria · Dec 10, 2018
Austrian DSB says “pay or okay” subscription model violates GDPR consent voluntariness
The Austrian Data Protection Authority (DSB) ruled that Der Standard's subscription offering, which ties refusal of consent to a €6 monthly fee, is not a voluntary choice under the GDPR. Max Schrems and other privacy experts criticized the…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate Interpretation Published European Union · Dec 8, 2018
Noyb reports controllers limit GDPR rights to specific request formats
Noyb notes that many data controllers use automated systems that restrict how data subjects can exercise their GDPR rights, often limiting requests to specific formats that may not serve the data subject's interests. The organization…
EDPB · General Data Protection Regulation
Moderate Interpretation Published European Union · Nov 12, 2018
Max Schrems discusses GDPR on CBS 60 Minutes (Nov 11, 2018)
On 11 November 2018, noyb director Max Schrems appeared on CBS's 60 Minutes to explain the benefits and challenges of the GDPR and how the organization enforces it. The interview highlighted the law's role in allowing Europeans to reclaim…
EDPB · General Data Protection Regulation
← Newer
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13