REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
146
Last 30 days
18
High or critical
31
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: privacy · clear
389 developments
Low Enforcement Filed Austria · Jun 9, 2026
noyb files injunction against Austrian credit agency CRIF over GDPR violations
noyb, a state‑approved qualified entity, filed an injunction against CRIF to stop its alleged unlawful collection and scoring of personal data under the GDPR. The filing also suspends the limitation period and prepares a subsequent class…
EDPB · General Data Protection Regulation
Low Enforcement Filed Austria · May 5, 2026
LinkedIn blocks GDPR access to profile visitor data behind paywall, noyb files complaint in Austria
LinkedIn requires users to pay to view who has visited their profile, despite the data being personal under the GDPR. noyb argues the data must be provided free of charge under Article 15 and has lodged a complaint with the Austrian Data…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate Lawsuit filed Filed Germany · Apr 30, 2026
noyb files lawsuit against Hamburg DPA over inaction on PimEyes biometric data case
noyb has filed a lawsuit against the Hamburg Data Protection Authority, alleging that the authority has failed to act on illegal biometric data processing by PimEyes. The DPA considers PimEyes' facial recognition practices illegal but…
Hamburg Data Protection Authority · General Data Protection Regulation
Moderate Proposed regulation Proposed European Union · Apr 16, 2026
EU Digital Omnibus proposal aims to limit GDPR right of access amid 83.5% non‑compliance
The European Commission’s Digital Omnibus proposal would restrict the GDPR right of access to “data protection purposes”, citing alleged abuse. NOYB’s analysis shows that 83.5% of access requests were not properly answered, with only 16.5%…
European Commission · General Data Protection Regulation
Moderate Fine In effect France · Mar 13, 2026
French court upholds €40M GDPR fine against Criteo
The French Data Protection Authority (CNIL) fined Criteo €40 million for GDPR violations, including lack of valid consent, transparency, and failures to honor erasure and access rights. In March 2026, the Conseil d’État rejected Criteo’s…
CNIL · General Data Protection Regulation
Moderate Proposed regulation Published European Union · Mar 5, 2026
EU Commission's Digital Omnibus proposal to limit GDPR Right of Access faces criticism from DPOs
The European Commission has published a Digital Omnibus proposal that would narrow the definition of personal data, restrict the Right of Access and allow broader AI training. A survey by noyb shows data protection officers consider the…
European Commission · General Data Protection Regulation
Moderate Guidance Published European Union · Feb 11, 2026
EU DPAs reject key proposals in Digital Omnibus GDPR changes
The European Data Protection Board and the European Data Protection Supervisor issued a joint opinion rejecting the Commission's proposal to narrow the definition of personal data and to restrict the right of access. They also raised…
European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) · ePrivacy Directive
Low Lawsuit filed Filed Germany · Jan 28, 2026
noyb files lawsuit against Hamburg DPA over Pay or Okay case involving SPIEGEL
In 2024, privacy advocacy group noyb sued the Hamburg Data Protection Authority concerning a Pay or Okay implementation dispute with the German news magazine SPIEGEL. The case highlights concerns about DPA impartiality and enforcement…
Hamburg Data Protection Authority · General Data Protection Regulation
Low Investigation Announced Austria · Jan 20, 2026
noyb investigation reveals Austrian credit agency CRIF uses public registers for mass address data collection
noyb’s investigation of CRIF shows that most address data comes from brokers who scrape public registers, violating GDPR purpose‑limitation. The Austrian DSB has already ruled that further processing for advertising breaches the GDPR.
Austrian Data Protection Authority · General Data Protection Regulation
Moderate Court ruling Decided Austria · Dec 18, 2025 · deadline Dec 31, 2025
Austrian Supreme Court orders Meta to give users full data access within 14 days
The Austrian Supreme Court ruled that Meta must provide a complete copy of all personal data to any user request within 14 days, including source, recipient and purpose information. The court also required Meta to obtain explicit opt‑in…
EDPB · General Data Protection Regulation
Low Enforcement Filed Austria · Dec 17, 2025
noyb files complaints against TikTok, AppsFlyer and Grindr with Austrian DSB over unlawful tracking
noyb has lodged two complaints with Austria's data protection authority alleging that TikTok tracks users across other apps and fails to provide a complete copy of personal data. The complaints also target AppsFlyer and Grindr for sharing…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Guidance Announced European Union · Dec 10, 2025
EU‑US data transfers face imminent risk as US legal changes could undermine TAFPF and SCCs
The blog notes that most EU‑US transfers rely on the Transatlantic Data Privacy Framework (TAFPF) or Standard Contract Clauses (SCCs), which depend on fragile US laws and executive orders. It warns that upcoming US Supreme Court decisions…
EDPB · General Data Protection Regulation
Low Guidance Published European Union · Dec 4, 2025
EDPB publishes first opinion on Pay or Okay, urging a three‑option consent model
In April 2024 the European Data Protection Board released its first opinion on Pay or Okay systems, recommending a third choice of "advertising, but no tracking" alongside pay and consent options. A noyb‑commissioned study shows that users…
European Data Protection Board
Moderate Proposed regulation Proposed European Union · Nov 22, 2025
EU Commission proposes Digital Omnibus package with new personal data definition and research exemption
The European Commission has released the Digital Omnibus proposal, introducing a narrower definition of personal data (Art. 4(1)), a broader research exemption (Arts. 4(38), 5(1)(b), 13, 89), and new AI‑related rules (Arts. 9(2)(k), 9(5)…
European Commission · General Data Protection Regulation
Moderate Proposed regulation Proposed European Union · Nov 11, 2025
Open letter warns EU Commission's Digital Omnibus draft could deregulate GDPR
Noyb, EDRi and the Irish Council for Civil Liberties sent an open letter to the European Commission criticizing a draft Digital Omnibus that would amend core GDPR provisions. The draft proposes redefining personal data, weakening data…
European Commission · General Data Protection Regulation
Moderate Enforcement Filed Austria · Oct 28, 2025
noyb files criminal complaint against Clearview AI in Austria
noyb filed a criminal complaint with Austrian public prosecutors against Clearview AI and its managers for alleged GDPR violations. The complaint relies on Article 84 GDPR and Austria's § 63 Data Protection Act, which allow criminal…
Austrian public prosecutors · General Data Protection Regulation
Low Enforcement Filed Lithuania · Sep 29, 2025
noyb files complaint with Lithuanian DPA against Whitebridge AI for unlawful data processing
noyb has lodged a complaint with Lithuania's data protection authority alleging that Whitebridge AI unlawfully scrapes and sells AI‑generated reputation reports containing personal and sensitive data. The complaint cites violations of…
Lithuanian Data Protection Authority · General Data Protection Regulation
Low Investigation Announced Austria · Sep 25, 2025
noyb uncovers over 40,000 CRIF credit queries linking Austrian banks, telecoms and retailers
noyb obtained data requests from 2,440 individuals and analyzed more than 40,000 CRIF credit queries, finding that banks, telecoms and other firms provide personal address data to the credit agency. The analysis shows gender and geographic…
EDPB · General Data Protection Regulation
Moderate Data protection authority action Announced Ireland · Sep 18, 2025
Former Meta lobbyist Niamh Sweeney appointed Irish DPC commissioner
Niamh Sweeney, a former senior Meta lobbyist, is set to join the Irish Data Protection Commission (DPC) as a commissioner in October. The DPC is the EU lead privacy regulator for major US tech firms. The appointment raises concerns about…
Irish Data Protection Commission · General Data Protection Regulation
Low Enforcement Announced Austria · Sep 18, 2025
NGOs file EU Commission complaint over Austrian DPA budget cuts
The Austrian Data Protection Authority (DSB) announced further restrictions due to significant budget cuts. NGOs epicenter.works and noyb plan to file a complaint with the European Commission alleging violation of Article 52(4) GDPR. The…
European Commission · General Data Protection Regulation
← NewerOlder →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union17 new · 14 laws California14 new · 5 laws France11 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 106security · 57ai governance · 46transparency · 28data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 15consent · 14targeted advertising · 14data governance · 13