REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: profiling · clear
138 developments
Low Enforcement Filed Austria · Mar 18, 2021
noyb files GDPR complaint against CRIF and AZ Direct over illegal data exchange
noyb lodged a GDPR complaint on 18 March 2021 against credit scoring firm CRIF GmbH and address publisher AZ Direct for exchanging personal data without a legal basis. The complaint alleges violations of the GDPR purpose‑limitation…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate Court ruling Pending Austria · Mar 14, 2021
Austrian Supreme Court to consider referral of Facebook GDPR consent bypass case
The Austrian Supreme Court (OGH) has been asked to refer a case concerning Facebook's alleged bypass of GDPR consent rules to the CJEU. The dispute centers on Facebook's claim that a contractual duty to provide personalized advertising…
EDPB · General Data Protection Regulation
Low Enforcement Filed Austria · Feb 8, 2021
noyb files GDPR complaint against Austrian credit data broker KSV 1870
On 08.02.2021, the privacy NGO noyb lodged a GDPR complaint with the Austrian data protection authority alleging that KSV 1870 stores identification data from access requests in its commercial database, violating purpose‑limitation. The…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate Enforcement Announced Germany · Jan 28, 2021 · deadline Feb 12, 2021
Hamburg DPA preliminarily deems Clearview AI’s biometric profiling of EU residents illegal and orders partial deletion
The Hamburg Data Protection Authority preliminarily found that Clearview AI’s collection of biometric profiles of Europeans violates the GDPR and ordered the deletion of the mathematical hash values of the complainant’s biometric profile.…
Hamburg Data Protection Authority · General Data Protection Regulation
Moderate Fine In effect Norway (EEA) · Jan 26, 2021
Norwegian DPA fines Grindr €9.63 million for illegal sharing of sensitive data
The Norwegian Data Protection Authority imposed a fine of 100 Mio NOK on Grindr for sharing personal and sensitive data without valid consent. The authority found Grindr's consent mechanism invalid and highlighted the company's lack of…
Norwegian Data Protection Authority · General Data Protection Regulation
Low Enforcement Filed Germany · Nov 16, 2020
noyb files complaints against Apple's IDFA tracking code
The privacy NGO noyb filed two complaints with the German and Spanish data protection authorities alleging that Apple's Identifier for Advertisers (IDFA) tracks users without consent, violating the EU e‑Privacy Directive. The complaints…
EDPB · General Data Protection Regulation
Moderate Enforcement Filed Malta · Nov 12, 2020
noyb files complaint with Maltese DPA over C-Planet voter data breach
noyb filed a complaint with the Maltese Data Protection Authority against C-Planet IT Solutions for leaking personal data of 337,384 voters, including phone numbers, dates of birth and political opinions. NGOs Daphne Foundation and…
Maltese Data Protection Authority · General Data Protection Regulation
Moderate Enforcement Filed Austria · Aug 4, 2020
noyb files GDPR complaint against CRIF over arbitrary credit score
noyb.eu lodged a GDPR complaint with the Austrian Data Protection Authority against credit rating agency CRIF for assigning a credit score of 446 despite claiming no personal data was stored. The score caused an electricity supplier to…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate Fine In effect France · Jun 19, 2020
French court upholds €50 million CNIL fine against Google
The French Data Protection Authority (CNIL) imposed a €50 million fine on Google for insufficient information and lack of valid consent for personalized ads. The Conseil d’État confirmed the CNIL's decision and affirmed its jurisdiction…
CNIL · General Data Protection Regulation
Low Enforcement Pending Ireland · May 24, 2020
noyb files GDPR complaints against Facebook Group, warns of potential €2.5bn fine
Within hours of the GDPR becoming applicable on 25 May 2018, the non‑profit noyb filed three complaints against Facebook, Instagram and WhatsApp. The Irish DPC has kept the investigation confidential but may issue a fine of up to…
Irish Data Protection Commission · General Data Protection Regulation
Low Enforcement Announced Austria · Mar 31, 2020
Streaming services fail GDPR transparency requirements, report finds
A joint investigation by the Austrian Chamber of Labour and noyb evaluated eight streaming platforms against GDPR transparency obligations. The study found that most services provide insufficient information on data handling, retention…
EDPB · General Data Protection Regulation
Moderate Court ruling Pending Austria · Feb 26, 2020
Vienna Regional Court closes oral hearing in GDPR case against Facebook, judgment pending
The Vienna Regional Court for Civil Matters (LGfZRS) ended a nine‑hour oral hearing in a data‑protection lawsuit against Facebook. The court will issue a written judgment in the coming months and the case is expected to be appealed to…
EDPB · General Data Protection Regulation
Low Enforcement Filed Norway (EEA) · Jan 14, 2020
Norwegian DPA receives GDPR complaints against Grindr and ad‑tech firms
The Norwegian Consumer Council, together with noyb, filed three formal GDPR complaints against Grindr and five ad‑tech companies (Twitter’s MoPub, AT&T’s AppNexus, OpenX, AdColony, Smaato) with the Norwegian Data Protection Authority. The…
Norwegian Data Protection Authority · General Data Protection Regulation
Low Enforcement Filed France · Dec 10, 2019
noyb files three GDPR complaints with CNIL over fake consent cookie banners on French sites
The privacy NGO noyb filed three formal complaints with the French Data Protection Authority (CNIL) alleging that CDiscount, Allocine.fr and Vanity Fair turn user rejections of cookies into "fake consent". The sites use the IAB…
CNIL · General Data Protection Regulation
Low Lawsuit filed Pending Austria · Nov 12, 2019
Austrian court hears case accusing Facebook of processing data without consent under GDPR
In proceedings before the Vienna Regional Court, Facebook admitted to collecting and processing user data without consent since the GDPR took effect on May 25, 2018. The plaintiff argues that Facebook cannot rely on an alleged advertising…
EDPB · General Data Protection Regulation
Low Enforcement Published Austria · Dec 10, 2018
Austrian DSB decision on DerStandard.at ‘pay or okay’ subscription model
The Austrian Data Protection Authority (DSB) ruled that DerStandard.at’s subscription option requiring users to pay €6 per month for privacy instead of giving free consent is not voluntary under the GDPR. The decision sparked criticism…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low Interpretation Announced Austria · Dec 10, 2018
Austrian DSB says “pay or okay” subscription model violates GDPR consent voluntariness
The Austrian Data Protection Authority (DSB) ruled that Der Standard's subscription offering, which ties refusal of consent to a €6 monthly fee, is not a voluntary choice under the GDPR. Max Schrems and other privacy experts criticized the…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate Interpretation Published European Union · Nov 12, 2018
Max Schrems discusses GDPR on CBS 60 Minutes (Nov 11, 2018)
On 11 November 2018, noyb director Max Schrems appeared on CBS's 60 Minutes to explain the benefits and challenges of the GDPR and how the organization enforces it. The interview highlighted the law's role in allowing Europeans to reclaim…
EDPB · General Data Protection Regulation
← Newer
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13