REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
146
Last 30 days
18
High or critical
31
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
215 developments
Low Enforcement Published Austria · Jan 13, 2022
Austrian DSB rules EU‑US transfers to Google Analytics illegal under GDPR
The Austrian Data Protection Authority (DSB) decided that the continuous use of Google Analytics violates the GDPR following the Schrems II ruling. The DSB rejected Google's claimed technical and organisational measures as ineffective…
Austrian Data Protection Authority (Datenschutzbehörde) · California Delete Act
Moderate Enforcement Published European Union · Jan 11, 2022
EDPS reprimands European Parliament for illegal EU‑US data transfers via Google and Stripe
The European Data Protection Supervisor (EDPS) issued a decision reprimanding the European Parliament for violating data protection law on its COVID‑testing website. The use of Google Analytics and Stripe was found to breach the CJEU's…
European Data Protection Supervisor (EDPS) · General Data Protection Regulation
Low Enforcement Filed Luxembourg · Dec 22, 2021
noyb files complaint with Luxembourg CNPD over Amazon's automated e-recruiting decisions
noyb lodged a complaint with the Luxembourg data protection authority (CNPD) against Amazon for using automated decision‑making in its Mechanical Turk recruitment process. The complainant was denied access without explanation, and Amazon…
Commission Nationale pour la Protection des Données (CNPD) · General Data Protection Regulation
Low Enforcement Filed DE-RP · Dec 22, 2021
noyb files GDPR complaint against Airbnb over automated review deletions
noyb filed a GDPR complaint with the Data Protection Authority of Rheinland‑Pfalz against Airbnb for automatically deleting a host's five‑star review. The complaint alleges violations of Article 22(3) GDPR, which requires the right to…
Data Protection Authority of Rheinland-Pfalz · General Data Protection Regulation
Low Enforcement Pending Ireland · Dec 19, 2021
Facebook ignores EU Court rulings on data transfers, Irish DPC enforcement pending
noyb reports that Facebook's 86‑page Transfer Impact Assessment disregards the CJEU Schrems I and II rulings that require EU‑US data transfers to stop. The Irish Data Protection Commission has not yet issued a decision despite a complaint…
Irish Data Protection Commission · General Data Protection Regulation
Moderate Fine In effect Norway (EEA) · Dec 15, 2021 · effective Dec 15, 2021
Norwegian DPA fines Grindr €6.3 M for illegal sharing of sensitive data
The Norwegian Data Protection Authority imposed a fine of 65 Mio NOK on Grindr for sharing sensitive personal data without valid consent. The authority found the consent mechanism invalid and highlighted the lack of a genuine opt‑out. The…
Norwegian Data Protection Authority · General Data Protection Regulation
Low Enforcement Announced Ireland · Dec 12, 2021
Irish DPC sends threat letters to noyb over Facebook ROPA publication
noyb published Facebook's four‑page Record of Processing Activities (ROPA) required by Article 30 GDPR. The Irish Data Protection Commission, which received the ROPA on 27.9.2018, sent angry letters to noyb demanding the removal of the…
Irish Data Protection Commission · General Data Protection Regulation
Low Enforcement Announced Germany · Dec 10, 2021
noyb and ZDF Magazin Royale seek data donors to enforce GDPR micro‑targeting ban
noyb and ZDF Magazin Royale are asking users of the "Who Targets Me" browser extension from the 2021 German federal election to donate their data. The aim is to find a case to enforce the GDPR prohibition on political micro‑targeting under…
EDPB · General Data Protection Regulation
Low Enforcement Announced Austria · Nov 28, 2021
Austrian DPA rejects Facebook's confidentiality claim in GDPR data‑transfer dispute
The Austrian Data Protection Authority (DSB) rejected Facebook's claim that certain documents were confidential, providing all documents to the Irish DPC. The DSB also reminded Facebook that official Austrian procedures must be conducted…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low Enforcement In effect Ireland · Nov 23, 2021 · effective Nov 18, 2021
Irish DPC removes noyb from GDPR procedure after demanding NDA
The Irish Data Protection Commission (DPC) demanded that privacy activist group noyb sign a non‑disclosure agreement to continue hearing its complaint against Facebook. After noyb refused, the DPC removed the organization from the GDPR…
Irish Data Protection Commission · General Data Protection Regulation
Low Enforcement Filed Austria · Nov 11, 2021
noyb files GDPR complaint against Grindr over selfie ID requirement
noyb lodged a GDPR complaint with the Austrian Data Protection Authority alleging that Grindr's policy of requiring a selfie with a passport and email paper violates data minimisation and the right of access. The complainant was denied…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low Enforcement Filed Luxembourg · Oct 21, 2021
noyb files GDPR complaint against Amazon Europe over opaque automated payment decisions
noyb lodged a complaint with Luxembourg's data protection authority alleging that Amazon Europe's automated "Monthly Invoice" payment rejections violate GDPR transparency and access requirements. The complaint cites the lack of explanation…
Luxembourg National Data Protection Commission · General Data Protection Regulation
Low Enforcement Filed Germany · Oct 18, 2021
noyb files GDPR complaint against Acxiom and CRIF Bürgel over illegal credit scores
noyb lodged a complaint in Germany alleging that address trader Acxiom and credit reference agency CRIF Bürgel illegally use personal data to calculate credit scores without consent, violating the GDPR and the German Federal Data…
EDPB · General Data Protection Regulation
Moderate Enforcement Announced Ireland · Oct 15, 2021
Irish DPC orders noyb to remove draft decision from website
The Irish Data Protection Commission sent a take‑down request to privacy activist group noyb on 14 Oct 2021, ordering removal of a draft decision that allegedly strips Facebook users of GDPR rights. noyb refused, citing Austrian law and…
Irish Data Protection Commission · General Data Protection Regulation
Moderate Fine Announced Ireland · Sep 2, 2021
Irish DPC issues €225 million fine against WhatsApp
The Irish Data Protection Commission imposed a €225 million fine on WhatsApp (owned by Facebook) under the GDPR. The fine was increased from an initial €50 million after pressure from other EU data protection authorities. Max Schrems of…
Irish Data Protection Commission · General Data Protection Regulation
Moderate Enforcement Filed European Union · Aug 13, 2021
noyb files complaints against cookie paywalls of seven German and Austrian news sites over unlawful consent
noyb filed complaints against the cookie paywalls of SPIEGEL.de, Zeit.de, heise.de, FAZ.net, derStandard.at, krone.at and t-online.de, arguing that the "pay or okay" model violates the GDPR's requirement for freely given consent. The…
EDPB · General Data Protection Regulation
Moderate Enforcement Filed European Union · Aug 10, 2021
noyb files 422 GDPR complaints over deceptive cookie banners
noyb filed 422 formal GDPR complaints with data protection authorities in ten EU countries concerning dark‑pattern cookie banners. After a warning phase, 42% of identified violations were remedied, but 82% of the 516 sites still breach the…
Data Protection Authorities · General Data Protection Regulation
Low Enforcement Decided Austria · Aug 4, 2021
Austrian DPA orders credit agency CRIF to disclose scoring logic after GDPR complaint
The Austrian Data Protection Authority ruled that CRIF's credit assessment constitutes profiling under the GDPR and must disclose that the creditworthiness score was calculated only from address, gender, name and date of birth. CRIF must…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate Enforcement Pending European Union · Jul 19, 2021
noyb reports 2.5‑year delay in GDPR access‑request complaints against streaming services
In January 2019 noyb filed complaints against eight streaming services for failing to comply with the GDPR right of access. After two and a half years only one complaint was resolved after noyb took the responsible authority to court. The…
EDPB · General Data Protection Regulation
Moderate Settlement Settled European Union · Jul 16, 2021
Max Schrems notes settlement with Irish DPC in Jan 2021 amid Schrems II fallout
The statement highlights that of the 101 model complaints filed by noyb after the Schrems II ruling, none have been decided yet. It notes that the original Facebook complaint led to a settlement with the Irish Data Protection Commission in…
Irish Data Protection Commission · Standard Contractual Clauses
← NewerOlder →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union17 new · 14 laws California14 new · 5 laws France11 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 106security · 57ai governance · 46transparency · 28data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 15consent · 14targeted advertising · 14data governance · 13