Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 24 of 214 developments
ADTP REGULATORY BRIEF
Commission holds special meeting of Scientific Panel on frontier AI safety and risks
The meeting signals EU commitment to strengthen AI governance through scientific input on systemic risk.
ADTP REGULATORY BRIEF
CNIL examines draft deliberation authorizing BIG DATA SANTE to process personal data for anonymized medical research (ONCOVAL)
If approved, the authorization would enable a French company to process health‑related personal data for research, shaping data‑privacy practices in the health sector.
ADTP REGULATORY BRIEF
Dutch DPA fines Uber €824.99 million for unlawful automated decision‑making
The fine demonstrates robust GDPR enforcement on automated decision‑making in the gig‑economy.
ADTP REGULATORY BRIEF
AEPD publishes second issue of scientific journal “Privacy, Innovation and Technology”
The publication provides expert analysis of GDPR challenges and AI governance, helping practitioners anticipate regulatory impacts of emerging technologies.
ADTP REGULATORY BRIEF
Commission registers European Citizens' Initiative for sovereign European AI domains
The registration signals a potential push for new EU AI governance measures driven by citizen input.
ADTP REGULATORY BRIEF
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The action highlights the need for data‑protection‑by‑design and proportionality when deploying AI‑driven video surveillance in the public sector.
ADTP REGULATORY BRIEF
Future of Privacy Forum urges standardized privacy benchmarks for frontier AI systems
Standardized privacy benchmarks would give concrete, comparable metrics for AI developers and deployers, supporting better privacy protection and regulatory oversight.
ADTP REGULATORY BRIEF
CNIL to examine draft decree on student violence questionnaire and automated vehicle sound monitoring
The agenda signals upcoming French regulatory scrutiny of new personal data processing tools in education and transport sectors.
ADTP REGULATORY BRIEF
EU Commission proposes KIDS Act to ban social‑media access for under‑13s and set minimum account age of 15
The KIDS Act would impose age‑based restrictions and safety‑by‑design obligations on online platforms, directly affecting children’s privacy and online safety in the EU.
ADTP REGULATORY BRIEF
CNIL to host AIR 2026 event on political communication ethics and election manipulation on 16 Nov 2026
The event highlights how existing privacy rules (RGPD, Loi Informatique et Libertés, 2025 political‑advertising regulation) apply to election‑related data practices and the growing threat of AI‑driven manipulation.
ADTP REGULATORY BRIEF
Data Protection Commission releases AI Insights Report covering 2021‑2025 supervision
The DPC’s AI Insights Report offers regulators and controllers practical guidance on compliant AI development and deployment.
ADTP REGULATORY BRIEF
ENISA launches podcast series on Frontier AI and publishes guidance note on cybersecurity in the Frontier AI era
The launch and accompanying guidance highlight ENISA’s effort to inform stakeholders about AI‑related cybersecurity risks and recommended actions.
ADTP REGULATORY BRIEF
EU Commission releases two reports on generative AI and digital education impacts
The reports highlight privacy, bias and overreliance risks of AI in education, underscoring the need for guidance and professional development for teachers.
ADTP REGULATORY BRIEF
Commission designates ChatGPT, Reddit, Roblox as VLOPs/VLOSE under the Digital Services Act
The designations trigger new DSA compliance duties for major online services, affecting their risk‑management and user‑protection obligations.
ADTP REGULATORY BRIEF
Spanish Data Protection Agency issues warning to company over AI-driven resume screening
The AEPD’s warning highlights GDPR compliance requirements for AI use in recruitment, emphasizing transparency, human control, and risk assessment.
ADTP REGULATORY BRIEF
EU Commission hosts fifth roundtable on Digital Services Act implementation
The event signals ongoing EU regulator engagement with stakeholders to shape DSA enforcement and address AI and child‑safety risks online.
ADTP REGULATORY BRIEF
Future of Privacy Forum opens nominations for 17th Annual Privacy Papers for Policymakers Awards
The call encourages privacy‑focused scholarship that can directly inform policy development.
ADTP REGULATORY BRIEF
ENISA releases 2026 Threat Landscape report highlighting AI-enabled cyber threats and supply‑chain risks
The report informs EU stakeholders of evolving cyber threats, emphasizing the need for heightened vigilance and resilience across digital services.
ADTP REGULATORY BRIEF
EU Commission proposes KIDS Act to impose age‑based restrictions and safety‑by‑design for children online
The KIDS Act aims to create EU‑wide, age‑based safeguards and design obligations to protect children’s privacy and safety online.
ADTP REGULATORY BRIEF
EU proposes Article 88c/88bis to allow unrestricted AI use of personal data
If adopted, the proposal would dramatically weaken EU data‑protection rights by granting AI firms blanket access to personal data.
ADTP REGULATORY BRIEF
How to limit Siri AI access in iOS 27
The article explains how iOS 27’s Siri AI expands data access and provides step‑by‑step controls for users to protect their privacy.
ADTP REGULATORY BRIEF
EFF warns that cloud TEEs undermine end‑to‑end encryption in messaging apps
The article highlights a privacy risk where AI features offload encrypted messages to cloud TEEs, weakening end‑to‑end encryption protections.
ADTP REGULATORY BRIEF
EU AI Board discusses AI Act implementation and publishes Action Plan on cybersecurity and AI
The meeting signals EU progress on AI governance, linking AI Act enforcement with a new cybersecurity‑AI action plan.
ADTP REGULATORY BRIEF
Dutch DPA fines Uber €824,990,000 for automated decisions affecting drivers
The fine underscores strict GDPR enforcement of automated decision‑making provisions.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.