REGULATORY WATCH

Privacy, AI governance and data protection developments across the US and the EU, from regulators, legislatures and courts.

⚖️ Latest developments 🌐 Jurisdictions 📚 Law library
148
Last 30 days
19
High or critical
32
Enforcement actions
72
Laws tracked
All types Enforcement Legislation Rulemaking Guidance Litigation
Any impact Critical High Moderate Any time 7 days 30 days 90 days
Topic: targeted advertising · clear
56 developments
Moderate Settlement Settled United States (federal) · Oct 2, 2026
Meta’s Muse AI Agent raises privacy, security, and child safety concerns amid past FTC consent decree
Meta launched the Muse personal AI agent in September 2026, which collects extensive personal data and can act without clear user permission. EPIC reports multiple incidents where Muse accessed messages, shared home addresses, and…
Federal Trade Commission
High Fine Decided Ireland · Sep 23, 2026 · effective Sep 21, 2026
Irish Data Protection Commission fines Google €403 million for GDPR violations over location data
The Irish Data Protection Commission issued its final decision on 21 September 2026, imposing administrative fines of €403 million on Google Ireland Limited. The DPC found infringements of GDPR principles relating to lawfulness, fairness…
Irish Data Protection Commission · General Data Protection Regulation
Low Investigation Announced Global · Aug 19, 2026
EFF report finds mobile ad libraries may leak user location data
EFF released a new report highlighting how mobile ad libraries can cause apps to unintentionally expose users' location information. The investigation notes that this leakage can reveal intimate details about individuals and be exploited…
Low Enforcement Filed Austria · Jun 9, 2026
noyb files injunction against Austrian credit agency CRIF over GDPR violations
noyb, a state‑approved qualified entity, filed an injunction against CRIF to stop its alleged unlawful collection and scoring of personal data under the GDPR. The filing also suspends the limitation period and prepares a subsequent class…
EDPB · General Data Protection Regulation
Low Investigation Filed Norway (EEA) · Jun 3, 2026
Norwegian Consumer Council and noyb file complaint against Schibsted over “Pay or Okay” tracking scheme
The Norwegian Consumer Council and privacy NGO noyb have lodged a joint complaint with the Norwegian Data Protection Authority against Schibsted for its “Pay or Okay” system that forces users to pay to refuse tracking. The complaint argues…
Norwegian Data Protection Authority · General Data Protection Regulation
Moderate Fine In effect France · Mar 13, 2026
French court upholds €40M GDPR fine against Criteo
The French Data Protection Authority (CNIL) fined Criteo €40 million for GDPR violations, including lack of valid consent, transparency, and failures to honor erasure and access rights. In March 2026, the Conseil d’État rejected Criteo’s…
CNIL · General Data Protection Regulation
Moderate Data protection authority action Decided Austria · Jan 27, 2026
Austrian DSB orders Microsoft to stop tracking school children with cookies
The Austrian Data Protection Authority ruled that Microsoft illegally installed tracking cookies on a pupil's device without consent. The authority ordered Microsoft to cease the use of those cookies within four weeks. The decision follows…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate Fine In effect France · Sep 4, 2025
CNIL fines Google €325 million for unsolicited Gmail advertising
The French data protection authority CNIL has issued a decision siding with privacy NGO noyb and fined Google €325 million for sending unsolicited advertising emails to Gmail users without consent. The authority also ordered Google to stop…
CNIL · ePrivacy Directive
Moderate Enforcement Announced European Union · Jun 16, 2025
noyb warns Meta's planned WhatsApp ads may breach GDPR and DMA
noyb alleges that Meta's intention to serve ads on WhatsApp using personal data from Instagram and Facebook violates the GDPR and the EU Digital Markets Act. The organization says the proposed "Pay or Okay" model would not provide freely…
noyb · General Data Protection Regulation
Low Enforcement Filed Germany · Feb 21, 2025
noyb files GDPR complaints against six German parties for illegal political microtargeting
In March 2023, noyb filed complaints with the Berlin and Bavarian Data Protection Authorities alleging that six German political parties used political microtargeting on Facebook during the 2021 election, violating Article 9 GDPR. The DPAs…
Berlin Data Protection Authority; Bavarian Data Protection Authority · General Data Protection Regulation
Low Enforcement Filed DE-NRW · Feb 12, 2025
noyb files complaint against WetterOnline for refusing GDPR access request
WetterOnline shares precise location data with more than 300 third‑party advertising companies and rejected a data‑subject access request, citing a "disproportionate effort". noyb filed a complaint with the North Rhine‑Westphalia data…
Data protection authority of North Rhine-Westphalia · General Data Protection Regulation
Moderate Enforcement Decided European Union · Dec 13, 2024
EDPS finds European Commission illegally used political micro‑targeting
The European Data Protection Supervisor issued a decision that the European Commission illegally targeted ads using sensitive political data. The EDPS issued only a reprimand, noting no fine was needed as the practice stopped. The decision…
European Data Protection Supervisor (EDPS) · General Data Protection Regulation
Low Enforcement Filed France · Dec 12, 2024
noyb files complaint against BeReal for forced consent dark pattern in France
noyb has lodged a complaint with the French data protection authority (CNIL) alleging that BeReal uses a dark‑pattern consent banner that forces users to accept tracking for advertising. The complaint argues the consent is not freely…
CNIL · General Data Protection Regulation
Low Enforcement Pending Ireland · Nov 12, 2024
Meta proposes "less personalized" ads that use location and age without consent, sparking GDPR enforcement concerns
Meta announced a new ad option that will still use personal data such as location and date of birth without obtaining consent, which noyb says violates the GDPR. The organization has filed pending litigation against Meta for this and…
Irish Data Protection Commission · General Data Protection Regulation
Low Enforcement Filed France · Oct 22, 2024
noyb files complaint against Pinterest for unlawful tracking without consent
noyb lodged a complaint with the French data protection authority (CNIL) alleging that Pinterest tracks EU users for personalised advertising without obtaining opt‑in consent. The complaint cites a CJEU ruling that legitimate interest…
CNIL · General Data Protection Regulation
Low Enforcement Filed Austria · Sep 25, 2024
noyb files complaint against Mozilla over default ‘Privacy Preserving Attribution’ feature in Firefox
noyb lodged a complaint with the Austrian Data Protection Authority alleging that Mozilla enabled a ‘Privacy Preserving Attribution’ feature in Firefox by default without informing users or obtaining consent. The feature allows Firefox to…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
High Fine In effect European Union · Jul 29, 2024
European data protection authorities fined Meta, Spotify, Criteo and others in 2023 for GDPR violations
In 2023, the Irish DPC ordered Meta to pay €390 million and later €1.2 billion, the Swedish DPA fined Spotify €58 million SEK, and the French CNIL fined Criteo €40 million for breaches of consent and data‑subject rights under EU law.
EDPB · General Data Protection Regulation
Low Enforcement Filed Italy · Jul 9, 2024
noyb files GDPR complaint against Microsoft’s Xandr for 0% compliance with data subject rights
Xandr, a Microsoft subsidiary, collects and shares personal data of millions of Europeans for targeted advertising, including sensitive categories. noyb filed a GDPR complaint with Italy’s Garante alleging breaches of Articles 5, 12, 15…
Italian data protection authority (Garante) · General Data Protection Regulation
Moderate Fine Decided Norway (EEA) · Jul 1, 2024 · effective Jul 1, 2024
Norwegian court confirms €5.7M fine for Grindr over GDPR breach
A Norwegian court upheld a fine of NOK 65 million (€5.7 million) against Grindr for violating the GDPR by sharing user data with advertisers. The ruling follows a complaint by the Norwegian Consumer Council, supported by noyb.
EDPB · General Data Protection Regulation
Low Enforcement Filed Austria · Jun 13, 2024
noyb files complaint with Austrian DPA over Google Chrome consent pop‑up
noyb alleges that Google Chrome’s “Privacy Sandbox” pop‑up misleads users into consenting to first‑party tracking for targeted advertising. The complaint asks the Austrian data protection authority to require Google to cease processing…
Austrian Data Protection Authority · General Data Protection Regulation
Older →
Coming up
Oct 2026
13
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
United States (federal) · effective
Oct 2026
26
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
United States (federal) · effective
Oct 2026
28
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
United States (federal) · effective
Nov 2026
2
DOI establishes new matching program under Privacy Act of 1974
United States (federal) · effective
Nov 2026
5
Treasury exempts new tip intake records from certain Privacy Act provisions
United States (federal) · effective
Nov 2026
6
Treasury proposes new system of records for federal student aid data
United States (federal) · effective
Nov 2026
16
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
United States (federal) · effective
Jan 2027
1
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
Colorado · effective
Jan 2027
1
NY Attorney General urges workers to file whistleblower complaints on unsafe AI development
New York · effective
Jan 2027
1
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
Delaware · effective
Jan 2027
1
California Legislature passes SB 690 to limit pen register lawsuits under CIPA
California · effective
Jan 2027
1
Colorado AI Act (SB 26-189, replacing SB 24-205)
Colorado · law takes effect
By jurisdiction
United States (federal)66 new · 16 laws European Union18 new · 14 laws California14 new · 5 laws France12 new · 0 laws New York6 new · 2 laws Global6 new · 0 laws Italy4 new · 0 laws Spain4 new · 0 laws Texas2 new · 3 laws Vermont2 new · 2 laws Ireland2 new · 0 laws Utah1 new · 2 laws
All jurisdictions →
Topics this month
privacy · 107security · 59ai governance · 46transparency · 29data minimization · 27children · 26profiling · 24automated decision making · 22cybersecurity · 16consent · 14targeted advertising · 14data governance · 13