Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 17 of 214 developments
ADTP REGULATORY BRIEF
CNIL releases Volume 2 of “L’Agence Privacy” to educate adolescents on cybercrime and data privacy
The publication provides a new pedagogical tool to improve privacy awareness among minors.
ADTP REGULATORY BRIEF
CNIL agenda includes review of draft decrees on automated personal data processing and authorizations for health data studies
The agenda signals upcoming CNIL scrutiny of new automated data processing initiatives affecting law‑enforcement and health research.
ADTP REGULATORY BRIEF
AEPD to host data‑protection session at XX Jornadas STIC on 24 Nov 2026
The AEPD’s participation highlights the growing relevance of privacy and data‑protection in AI‑driven cybersecurity discussions.
ADTP REGULATORY BRIEF
Austrian Supreme Court rules CRIF’s use of address‑publisher data for credit scoring violates GDPR purpose limitation
The decision clarifies GDPR purpose‑limitation obligations for credit scoring, paving the way for a consumer class action in Austria.
ADTP REGULATORY BRIEF
EFF and allies recommend new privacy safeguards to protect Brazil's electoral integrity
The recommendations aim to use privacy law enforcement to reduce manipulative political content and protect democratic processes.
ADTP REGULATORY BRIEF
noyb sends cease‑and‑desist letter to SCHUFA over alleged ‘shadow database’ GDPR violations
The action targets a potential GDPR breach affecting up to 69 million Germans and could lead to a large‑scale class action.
ADTP REGULATORY BRIEF
PDPC publishes Advisory Guidelines on Personal Data in Generative AI at Singapore Data Festival
The new PDPC guidance updates consent and notification requirements for AI, shaping how organizations handle personal and biometric data in Singapore.
ADTP REGULATORY BRIEF
EU proposes Cloud and AI Development Act (CADA) to boost AI and cloud sovereignty
CADA marks a shift toward AI‑promotion legislation in the EU, introducing positive obligations for Member States to foster AI innovation and cloud infrastructure.
ADTP REGULATORY BRIEF
EU Commission begins enforcing AI Act and new transparency rules on 2 August 2026
The enforcement introduces mandatory disclosure obligations for AI systems to curb deception and give users clearer information.
ADTP REGULATORY BRIEF
AEPD Privacy Lab invites entities to submit projects, research and initiatives
The announcement expands the visibility of privacy‑related work and encourages collaboration across academia, public bodies and industry.
ADTP REGULATORY BRIEF
AEPD announces 2026 Data Protection Awards to recognize privacy promotion
The call highlights the agency’s effort to foster privacy awareness and best‑practice innovation across sectors and vulnerable populations.
ADTP REGULATORY BRIEF
AEPD reopens registration for public research network on privacy and emerging technologies
The reopening expands collaboration opportunities and advances research on privacy, AI, and emerging technologies in Spain.
ADTP REGULATORY BRIEF
AEPD publishes technical guidance on data accuracy and minimisation in AI processing
The guidance clarifies how GDPR data‑quality obligations apply to AI, helping organisations balance protection with AI development.
ADTP REGULATORY BRIEF
EDPB calls for legal basis for cross‑regulatory information sharing
A legal framework for cross‑regulatory information sharing would enhance GDPR enforcement consistency and efficiency across the EU.
ADTP REGULATORY BRIEF
EU Council scrapes Article 88b proposal to replace cookie banners with automated signal
The Council’s removal of Article 88b halts the EU’s effort to simplify online consent mechanisms.
ADTP REGULATORY BRIEF
noyb files injunction against Austrian credit agency CRIF over GDPR violations
The injunction could halt a large‑scale secret credit scoring system and set a precedent for collective GDPR enforcement in the EU.
ADTP REGULATORY BRIEF
noyb files lawsuit against Hamburg DPA over inaction on PimEyes biometric data case
The suit underscores gaps in GDPR enforcement when controllers operate from third countries and process biometric data.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.