REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: data governance · clear
22 developments
Low Guidance Published European Union · Oct 2, 2026
EDPB adopts Guidelines 04/2026 on GDPR fines and corrective powers for public consultation
The European Data Protection Board adopted Guidelines 04/2026 on the application of administrative fines and other corrective powers under the EU GDPR. The guidelines were released on September 17, 2026 for public consultation.
European Data Protection Board · General Data Protection Regulation
Moderate Guidance Announced United States (federal) · Sep 30, 2026
Commerce Department seeks input on digitizing and modernizing the National Technical Reports Library
The National Technical Information Service (NTIS) issued a Request for Information to gather stakeholder feedback on fully digitizing the National Technical Reports Library (NTRL). The agency aims to make the technical reports more…
National Technical Information Service
Moderate Guidance Proposed United States (federal) · Sep 29, 2026
Agency seeks comment on proposed information collection for protection of human subjects
The agency announced a proposed collection of information related to the protection of human subjects and Institutional Review Boards and is requesting public comment. The notice also notes that programmatic access to FederalRegister.gov…
Food and Drug Administration · Paperwork Reduction Act of 1995
Moderate Guidance Published United States (federal) · Sep 28, 2026
Federal Register restricts automated scraping, requires CAPTCHA and API use
The Federal Register warns that aggressive automated scraping of its sites is limited to access via developer APIs. Human users must complete a CAPTCHA to continue, and may be asked to do so repeatedly as a security measure.
Department of Defense · Privacy Act of 1974
Moderate Guidance Published United States (federal) · Sep 25, 2026
CMS re-establishes matching program with Treasury's Do Not Pay Working System under Privacy Act
The Centers for Medicare & Medicaid Services announced the re-establishment of a data matching program with the Do Not Pay Working System, administered by the Treasury's Bureau of Fiscal Service. The notice cites subsection (e)(12) of the…
U.S. Department of Health and Human Services, Centers for Medicare & Medicaid Services · Privacy Act of 1974
High Guidance In effect United States (federal) · Sep 25, 2026 · effective Oct 26, 2026
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
The Peace Corps Office of Planning and Performance issued a public notice of a new system of records, the Peace Corps Customer Relationship Management (PC 38) system. The system will monitor, track, and analyze interactions with…
Peace Corps Office of Planning and Performance · Privacy Act of 1974
Moderate Guidance Published European Union · Sep 23, 2026
EDPB adopts guidelines on GDPR fines and DSA interaction (17 Sep 2026)
On 17 September 2026 the European Data Protection Board adopted guidelines on the use of administrative fines by data protection authorities and finalised guidance on the interaction between the Digital Services Act (DSA) and the GDPR. The…
European Data Protection Board (EDPB) · Digital Services Act
Moderate Guidance Published France · Sep 17, 2026
CNIL outlines its status, organization and sanction powers
The CNIL, created by the 1978 Loi Informatique et Libertés, is an independent administrative authority composed of a college of 18 members. Its restricted board can impose fines up to €20 million or 4 % of global annual turnover under the…
CNIL · loi Informatique et Libertés
Moderate Guidance Published KE · Sep 16, 2026
Kenya publishes new guidance on cross‑border data transfers
On 8 September 2026 Kenya’s Office of the Data Protection Commissioner released detailed Guidance Notes on cross‑border data transfers. The guidance clarifies Kenya’s transfer framework, adds operational detail, and highlights differences…
Office of the Data Protection Commissioner (ODPC) · General Data Protection Regulation
Moderate Guidance In effect France · Sep 10, 2026 · effective Sep 1, 2026
CNIL guidance on data‑protection obligations under the electronic invoicing reform effective 1 Sept 2026
The CNIL explains the data‑protection implications of the French electronic invoicing reform that entered into force on 1 Sept 2026. It details which personal data may be processed, the roles of issuers, receivers and certified platforms…
CNIL · réforme relative à la facturation électronique
Moderate Guidance Announced Spain · Jul 28, 2026
AEPD Privacy Lab invites entities to submit projects, research and initiatives
The AEPD's Privacy Lab has opened its Novedades space for publications, research projects, calls and activities related to privacy, data protection, AI and emerging technologies. Universities, research centres, public and private…
Agencia Española de Protección de Datos (AEPD) · Genetic Information Nondiscrimination Act
Moderate Guidance Announced European Union · Jul 23, 2026
EDPB announces stakeholder event on upcoming data protection and competition law guidelines (15 Oct 2026)
The European Data Protection Board and the European Commission will hold a remote stakeholder event on 15 October 2026 to discuss upcoming guidelines on the interplay between competition law and data protection. The event invites…
European Data Protection Board · General Data Protection Regulation
Moderate Guidance Announced Spain · Jul 23, 2026 · effective Jul 23, 2026
AEPD reopens registration for public research network on privacy and emerging technologies
The Spanish Data Protection Agency (AEPD) has reopened enrollment for its public network of research groups and projects focused on privacy and emerging technologies. The new registration phase allows groups that missed the first call and…
Agencia Española de Protección de Datos
Moderate Guidance Published Spain · Jul 21, 2026
AEPD publishes technical guidance on data accuracy and minimisation in AI processing
The Spanish Data Protection Agency (AEPD) released a technical note interpreting the GDPR accuracy and data‑minimisation principles for AI‑driven personal data processing. It provides criteria for controllers, processors and DPOs to assess…
Agencia Española de Protección de Datos · RGPD
Moderate Guidance Announced European Union · Jul 17, 2026
EDPB calls for legal basis for cross‑regulatory information sharing
The European Data Protection Board urged the European Commission to create a clear legal basis for regulators to share information across competences. It highlighted the need for stronger legislation to enable confidential information…
European Data Protection Board · General Data Protection Regulation
Moderate Guidance Announced European Union · Dec 10, 2025
EU‑US data transfers face imminent risk as US legal changes could undermine TAFPF and SCCs
The blog notes that most EU‑US transfers rely on the Transatlantic Data Privacy Framework (TAFPF) or Standard Contract Clauses (SCCs), which depend on fragile US laws and executive orders. It warns that upcoming US Supreme Court decisions…
EDPB · General Data Protection Regulation
Moderate Guidance Published United States (federal) · Mar 31, 2025
2024 HMDA Modified LAR Data Now Available on FFIEC Platform
The Home Mortgage Disclosure Act (HMDA) Modified Loan Application Register data for 2024 have been released on the FFIEC HMDA Platform for about 4,898 filers. The loan‑level data are modified to protect consumer privacy and are now…
Consumer Financial Protection Bureau · Home Mortgage Disclosure Act
Low Interpretation Announced Ireland · Apr 27, 2021
Irish DPC admits it does not decide GDPR complaints, handling 99.93% without decision
The Irish Data Protection Commissioner publicly stated that it does not issue decisions on GDPR complaints, with 99.93% of cases remaining without a decision. The DPC argued there is no obligation under the 2018 Act to produce a decision…
Irish Data Protection Commissioner (DPC) · General Data Protection Regulation
Moderate Interpretation Published European Union · Jun 24, 2020
EDPB responds to noyb open letter on Facebook case procedural concerns
The European Data Protection Board acknowledged the issues raised by noyb regarding the Irish DPA's handling of the Facebook case and said it is working to improve consistency procedures and cooperation among supervisory authorities. No…
European Data Protection Board · General Data Protection Regulation
Low Guidance Published Austria · Apr 21, 2020
First European Corona contact tracing app in Austria reviewed by noyb, epicenter.works and SBA Research
The Austrian Red Cross released a contact tracing app on March 25th, which uses a hybrid central‑server and local storage model. NGOs and security researchers reviewed the app and identified privacy weaknesses, recommending a switch to a…
Older →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13