REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: privacy · clear
88 developments
Low Guidance Announced California · Oct 9, 2026
EFF joins Oakland Tech Week to discuss surveillance and AI impacts
The Electronic Frontier Foundation participated in Oakland Tech Week on Sept. 30, co‑presenting an all‑day event with MediaJustice and Upturn. Attendees discussed how technology can empower or oppress communities, focusing on surveillance…
Moderate Guidance Published France · Oct 9, 2026
CNIL hosts 2nd Rencontres Informatique & Libertés on connected glasses and data‑sanctions
The French data‑protection authority CNIL held its second Rencontres Informatique & Libertés on 29 September 2026, featuring panels on the privacy impact of connected glasses and the role of sanctions under the GDPR. The event gathered…
CNIL · RGPD
Low Interpretation Published Global · Oct 8, 2026
EFF warns age‑verification laws risk excluding people without ID
The EFF analysis highlights a global surge in mandatory age‑verification requirements for social‑media and other digital services, citing laws in Australia, India, the United Kingdom, and many U.S. states. It argues that ID‑based checks…
Online Safety Act
Moderate Guidance Published Spain · Oct 8, 2026
AEPD publishes second issue of scientific journal “Privacy, Innovation and Technology”
The Spanish Data Protection Agency released the second issue of its scientific journal PIT, dedicated to the 10th anniversary of the GDPR. The monograph examines proactive responsibility, the right to explanation in automated decisions…
Agencia Española de Protección de Datos (AEPD) · Reglamento General de Protección de Datos (RGPD)
Moderate Guidance Published United States (federal) · Oct 5, 2026
EPIC analysis links pixel‑tracking litigation under ECPA and CIPA to upcoming Supreme Court VPPA case
EPIC outlines how recent court decisions using the Electronic Communications Privacy Act (ECPA) and California Invasion of Privacy Act (CIPA) address non‑consensual pixel tracking and its privacy harms. The analysis cites multiple…
HHS OCR · HIPAA Privacy, Security and Breach Notification Rules
Low Guidance Published European Union · Oct 2, 2026
EDPB adopts Guidelines 04/2026 on GDPR fines and corrective powers for public consultation
The European Data Protection Board adopted Guidelines 04/2026 on the application of administrative fines and other corrective powers under the EU GDPR. The guidelines were released on September 17, 2026 for public consultation.
European Data Protection Board · General Data Protection Regulation
Moderate Guidance Published France · Oct 2, 2026
CNIL explains when data‑breach victims can claim compensation under the GDPR
The CNIL outlines that individuals can seek damages only if a GDPR breach caused a real material or moral injury, and they can prove a causal link. Compensation is awarded by a judge, not the CNIL, and the regulator may only impose…
CNIL · RGPD
High Guidance In effect United States (federal) · Oct 2, 2026 · effective Nov 2, 2026
DOI establishes new matching program under Privacy Act of 1974
The U.S. Department of the Interior announced a new matching program that will compare records from 20 DOI programs with the Treasury's Do Not Pay Working System. The program aims to verify prepayment or pre‑award eligibility, prevent…
U.S. Department of the Interior · Privacy Act of 1974
Low Guidance Announced United States (federal) · Oct 1, 2026
EFF launches Opt Out October campaign urging users to leave tech giants for privacy
The Electronic Frontier Foundation (EFF) released its annual Opt Out October campaign, encouraging individuals to regain control of their data by opting out of major platforms, apps, and operating systems. The initiative provides…
High Guidance Published France · Oct 1, 2026 · effective Oct 1, 2026
CNIL and Cybermalveillance.gouv.fr release guide for individuals on personal data breach response
The French data protection authority (CNIL) and Cybermalveillance.gouv.fr have published a practical support document titled “Violation de données personnelles, que faire en 3 étapes clés ?”. The guide provides a three‑step checklist for…
CNIL
Low Guidance Published United States (federal) · Sep 30, 2026
EFF discusses privacy implications of Apple Siri AI features in iOS 27
The EFF newsletter examines how Apple’s new Siri AI in iOS 27 handles user data. It contrasts on‑device processing with server‑side processing and explains the privacy risks. The piece offers guidance on limiting the data Siri can access.
Moderate Guidance Published United States (federal) · Sep 30, 2026
NHTSA seeks OMB approval to renew and modify information collection for qualitative feedback on service delivery
The National Highway Traffic Safety Administration (NHTSA) announced its intention to request Office of Management and Budget (OMB) approval to renew a currently approved information collection, adding annual tracking studies for…
National Highway Traffic Safety Administration (NHTSA) · Paperwork Reduction Act of 1995
Moderate Guidance Published United States (federal) · Sep 30, 2026
HUD modifies system of records notice for Inventory Management System and Housing Information Portal
The Department of Housing and Urban Development (HUD) Office of Public and Indian Housing is updating its system of records notice for the Inventory Management System and Housing Information Portal. The amendment adds three new routine…
Department of Housing and Urban Development · Privacy Act of 1974
Low Guidance Announced California · Sep 29, 2026
San Francisco announces new ALPR policy with limited safeguards, no warrant requirement, 30‑day data transfer deadline
San Francisco released a policy that retains Automated License Plate Reader (ALPR) surveillance but provides only limited safeguards. The policy does not require a warrant to search stored ALPR data and sets a 30‑day deadline to move data…
San Francisco Police Department
Low Guidance Announced United States (federal) · Sep 29, 2026
EFF launches 'Privacy’s Defenders' podcast on digital surveillance history
The Electronic Frontier Foundation released a new podcast episode featuring Cindy Cohn and John Gilmore discussing mass surveillance, early internet activism, and ongoing privacy challenges. The episode highlights historical battles…
Moderate Guidance Announced United States (federal) · Sep 29, 2026
FCC and USAC launch new computer matching program to verify Lifeline eligibility
The Federal Communications Commission and the Universal Service Administrative Company will conduct a computer matching program with the Connecticut Department of Social Services. The program is intended to verify the eligibility of…
Federal Communications Commission · Privacy Act of 1974
Moderate Guidance Proposed United States (federal) · Sep 29, 2026
Agency seeks comment on proposed information collection for protection of human subjects
The agency announced a proposed collection of information related to the protection of human subjects and Institutional Review Boards and is requesting public comment. The notice also notes that programmatic access to FederalRegister.gov…
Food and Drug Administration · Paperwork Reduction Act of 1995
High Interpretation Published European Union · Sep 28, 2026
Commission designates ChatGPT, Reddit, Roblox as VLOPs/VLOSE under the Digital Services Act
The European Commission has designated ChatGPT as a Very Large Online Search Engine and Reddit and Roblox as Very Large Online Platforms under the DSA, citing each service’s reach of at least 45 million EU monthly users. The designated…
European Commission · Digital Services Act
Moderate Guidance Published United States (federal) · Sep 28, 2026
Federal Register restricts automated scraping, requires CAPTCHA and API use
The Federal Register warns that aggressive automated scraping of its sites is limited to access via developer APIs. Human users must complete a CAPTCHA to continue, and may be asked to do so repeatedly as a security measure.
Department of Defense · Privacy Act of 1974
Moderate Guidance Published United States (federal) · Sep 25, 2026
DoD updates SORN for DON Child and Youth Program to align with cybersecurity policies
The Department of Defense is modifying and reissuing the system of records titled "DON Child and Youth Program" (NM01754-3) under the Privacy Act of 1974. The updates incorporate DoD standard routine uses A through J, expand the collection…
Department of Defense · Privacy Act of 1974
Older →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13