REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: security · clear
123 developments
Low Investigation Filed DE-HE · Mar 2, 2020
noyb files GDPR complaint against Amazon for lacking TLS email encryption
The privacy NGO noyb submitted a complaint to the Hessian Data Protection Authority alleging Amazon violates GDPR Article 32 by not using TLS encryption for emails. The complaint may also be handled by Luxembourg's DPA, which could impose…
Hessian Data Protection Authority · General Data Protection Regulation
Low Court ruling Decided Ireland · May 31, 2019
Irish Supreme Court dismisses Facebook’s application to halt EU‑US data‑transfer reference
The Irish Supreme Court dismissed Facebook’s application, finding it had jurisdiction to intervene but the company failed to substantiate its request. The court therefore did not take the actions sought by Facebook, allowing the case to…
Irish Data Protection Commission · Safe Harbor
Moderate Interpretation Published European Union · Nov 12, 2018
Max Schrems discusses GDPR on CBS 60 Minutes (Nov 11, 2018)
On 11 November 2018, noyb director Max Schrems appeared on CBS's 60 Minutes to explain the benefits and challenges of the GDPR and how the organization enforces it. The interview highlighted the law's role in allowing Europeans to reclaim…
EDPB · General Data Protection Regulation
← Newer
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13