REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: automated decision making · clear
37 developments
High Fine Published Netherlands · Oct 8, 2026
Dutch DPA fines Uber €824.99 million for unlawful automated decision‑making
The Autoriteit Persoonsgegevens imposed an administrative fine of €824,990,000 on Uber for violating GDPR Article 22 by automatically deactivating drivers’ accounts and for failing to provide sufficient information under Article 13. The…
Autoriteit Persoonsgegevens · General Data Protection Regulation
Moderate Settlement Settled United States (federal) · Oct 2, 2026
Meta’s Muse AI Agent raises privacy, security, and child safety concerns amid past FTC consent decree
Meta launched the Muse personal AI agent in September 2026, which collects extensive personal data and can act without clear user permission. EPIC reports multiple incidents where Muse accessed messages, shared home addresses, and…
Federal Trade Commission
Low Investigation Announced United States (federal) · Sep 24, 2026
Senate Judiciary Subcommittee holds hearing on Flock Safety AI surveillance network
The Senate Judiciary Committee’s Subcommittee on Crime and Counterterrorism conducted a hearing on Flock Safety’s nationwide AI surveillance system. Experts highlighted the extensive data collection, facial tracking, and cybersecurity…
Moderate Enforcement Published Spain · Sep 23, 2026
Spanish Data Protection Agency issues warning to company over AI-driven resume screening
On 23 September 2026 the AEPD sent a formal warning to a company planning to use an AI tool for analysing CVs and assigning scores. The agency stresses that data protection must be built in from the start, including DPIA for high‑risk…
Agencia Española de Protección de Datos (AEPD) · Reglamento General de Protección de Datos (RGPD)
Moderate Fine Announced Netherlands · Sep 10, 2026
Dutch DPA fines Uber €824,990,000 for automated decisions affecting drivers
On August 21, 2026, the Dutch Data Protection Authority announced it had fined Uber €824,990,000 for breaching the EU GDPR rules on solely automated decision‑making. The fine targets Uber's use of automated systems that affect driver…
Dutch Data Protection Authority · General Data Protection Regulation
Low Enforcement Announced Germany · Aug 26, 2026 · effective Aug 26, 2026
noyb sends cease‑and‑desist letter to SCHUFA over alleged ‘shadow database’ GDPR violations
In July 2026, the NGO noyb issued a cease‑and‑desist letter to German credit agency SCHUFA demanding it stop storing data beyond retention periods and provide full historical data under Article 15 GDPR. The organization warned it will seek…
EDPB · General Data Protection Regulation
Low Enforcement Filed Austria · Jun 9, 2026
noyb files injunction against Austrian credit agency CRIF over GDPR violations
noyb, a state‑approved qualified entity, filed an injunction against CRIF to stop its alleged unlawful collection and scoring of personal data under the GDPR. The filing also suspends the limitation period and prepares a subsequent class…
EDPB · General Data Protection Regulation
Low Investigation Announced Austria · Jan 20, 2026
noyb investigation reveals Austrian credit agency CRIF uses public registers for mass address data collection
noyb’s investigation of CRIF shows that most address data comes from brokers who scrape public registers, violating GDPR purpose‑limitation. The Austrian DSB has already ruled that further processing for advertising breaches the GDPR.
Austrian Data Protection Authority · General Data Protection Regulation
Moderate Enforcement Filed Austria · Oct 28, 2025
noyb files criminal complaint against Clearview AI in Austria
noyb filed a criminal complaint with Austrian public prosecutors against Clearview AI and its managers for alleged GDPR violations. The complaint relies on Article 84 GDPR and Austria's § 63 Data Protection Act, which allow criminal…
Austrian public prosecutors · General Data Protection Regulation
Low Enforcement Filed Lithuania · Sep 29, 2025
noyb files complaint with Lithuanian DPA against Whitebridge AI for unlawful data processing
noyb has lodged a complaint with Lithuania's data protection authority alleging that Whitebridge AI unlawfully scrapes and sells AI‑generated reputation reports containing personal and sensitive data. The complaint cites violations of…
Lithuanian Data Protection Authority · General Data Protection Regulation
Moderate Data protection authority action Published Austria · Sep 26, 2025
Austrian DSB bans KSV1870 from automated credit checks without consent
The Austrian Data Protection Authority ruled that KSV1870's fully automated credit rating was unlawful and prohibited the agency from conducting such checks without the data subject's consent. The authority also ordered KSV1870 to provide…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low Investigation Announced Austria · Sep 25, 2025
noyb uncovers over 40,000 CRIF credit queries linking Austrian banks, telecoms and retailers
noyb obtained data requests from 2,440 individuals and analyzed more than 40,000 CRIF credit queries, finding that banks, telecoms and other firms provide personal address data to the credit agency. The analysis shows gender and geographic…
EDPB · General Data Protection Regulation
Low Enforcement Announced Germany · Aug 7, 2025
noyb sends cease‑and‑desist to Meta over AI training of EU users’ data
noyb commissioned a Gallup survey of 1,000 German Meta users, finding only 7% want their personal data used for AI training. Based on the results, noyb sent a cease‑and‑desist letter to Meta alleging GDPR violations and is assessing a…
EDPB · General Data Protection Regulation
Low Enforcement Announced Ireland · May 14, 2025
noyb sends cease and desist letter to Meta over AI training using EU personal data
noyb has issued a cease and desist letter to Meta, alleging that the company will use EU personal data from Instagram and Facebook for AI training without opt‑in consent. The letter relies on the EU Collective Redress Directive, which…
EDPB · General Data Protection Regulation
Moderate Enforcement Filed Norway (EEA) · Mar 20, 2025
noyb files second GDPR complaint against OpenAI over defamatory AI hallucinations in Norway
noyb filed a second complaint with the Norwegian Data Protection Authority alleging that OpenAI's ChatGPT generated false, defamatory personal data about a Norwegian user. The complaint cites violations of GDPR Article 5(1)(d) on data…
Norwegian Datatilsynet · General Data Protection Regulation
Low Enforcement Filed Sweden · Feb 27, 2025
Swedbank denies data subject access to mortgage rate logic, noyb files complaint with Swedish DPA
Swedbank rejected a Swedish citizen's request for information on how its automated mortgage interest rate is calculated, citing a trade‑secret claim. The refusal appears to breach Article 15(1)(h) of the GDPR, which requires meaningful…
Swedish Data Protection Authority (IMY) · General Data Protection Regulation
Moderate Data protection authority action Filed Austria · Aug 29, 2024
noyb files complaint with Austrian DPA over automated credit checks by KSV1870 and Unsere Wasserkraft
noyb lodged a complaint with the Austrian Data Protection Authority against credit reference agency KSV1870 and energy supplier Unsere Wasserkraft. The complaint alleges that customers are subjected to fully automated credit checks that…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Enforcement Filed European Union · Aug 12, 2024
noyb files nine GDPR complaints against X over AI training of 60 million EU users
noyb has lodged GDPR complaints in Austria, Belgium, France, Greece, Ireland, Italy, the Netherlands, Spain and Poland alleging that X used personal data of over 60 million EU/EEA users to train its AI system without consent. The Irish…
Irish Data Protection Commission · General Data Protection Regulation
Low Enforcement Announced Ireland · Jun 14, 2024 · effective Jun 14, 2024
Meta pauses AI training on EU/EEA user data after DPC intervention
The Irish Data Protection Commission announced that Meta has committed to stop processing EU/EEA user data for undefined AI techniques following 11 noyb complaints. Meta had previously relied on a "legitimate interest" argument. The…
Data Protection Commission (DPC) · General Data Protection Regulation
Moderate Data protection authority action Published DE-BAVARIA · Feb 5, 2024
Bavarian DPA declares CRIF‑Acxiom data trading illegal under GDPR
The Bavarian data protection authority ruled that credit reference agency CRIF illegally purchased personal data from address trader Acxiom and breached GDPR purpose‑limitation and information duties. The decision follows a similar…
Bavarian Data Protection Authority · General Data Protection Regulation
Older →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13