Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 24 of 213 developments
ADTP REGULATORY BRIEF
CNIL hosts 2nd Rencontres Informatique & Libertés on connected glasses and data‑sanctions
The conference highlights emerging privacy challenges of wearable tech and the increasing enforcement activity of the CNIL.
ADTP REGULATORY BRIEF
Italian DPA fines IQVIA €7 million for unlawful processing of patients’ health data
The fine highlights enforcement of GDPR obligations for health data controllers and underscores the need for proper legal bases, transparency, and impact assessments.
ADTP REGULATORY BRIEF
CISA submits Final CIRCIA Rule to OIRA for interagency review
The rule will impose rapid cyber‑incident reporting obligations on critical‑infrastructure operators, shaping their security and compliance programs.
ADTP REGULATORY BRIEF
EFF warns age‑verification laws risk excluding people without ID
Age‑verification regimes may protect children but also threaten equal access to information and privacy for people without ID.
ADTP REGULATORY BRIEF
Swedish DPA fines Miljödata approx EUR 160,000 for insufficient security measures
The fine underscores the enforcement of GDPR security obligations for data processors handling large volumes of personal and sensitive data.
ADTP REGULATORY BRIEF
Hellenic DPA fines Ministry and EETAA for data breach
The enforcement action highlights the liability of both controllers and processors for inadequate security and non‑compliant processing agreements under the GDPR.
ADTP REGULATORY BRIEF
CNIL closes injunction against FRANCE TRAVAIL after compliance with data security measures
The closure shows that timely remediation of GDPR security deficiencies can halt additional penalties.
ADTP REGULATORY BRIEF
AEPD publishes second issue of scientific journal “Privacy, Innovation and Technology”
The publication provides expert analysis of GDPR challenges and AI governance, helping practitioners anticipate regulatory impacts of emerging technologies.
ADTP REGULATORY BRIEF
DOJ proposes exemption for Firearms Rights Restoration Electronic Records Database from Privacy Act provisions
The proposal could limit individuals' access to their own records by creating a privacy Act exemption for a law‑enforcement database.
ADTP REGULATORY BRIEF
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The action highlights the need for data‑protection‑by‑design and proportionality when deploying AI‑driven video surveillance in the public sector.
ADTP REGULATORY BRIEF
Treasury exempts new tip intake records from certain Privacy Act provisions
The exemption limits individuals' privacy rights, such as access and correction, for data in the Treasury's fraud‑tip system.
ADTP REGULATORY BRIEF
Future of Privacy Forum urges standardized privacy benchmarks for frontier AI systems
Standardized privacy benchmarks would give concrete, comparable metrics for AI developers and deployers, supporting better privacy protection and regulatory oversight.
ADTP REGULATORY BRIEF
EPIC analysis links pixel‑tracking litigation under ECPA and CIPA to upcoming Supreme Court VPPA case
The piece provides practitioners with case‑law guidance on how pixel‑tracking claims are being evaluated under federal and state privacy statutes ahead of the Salazar v. Paramount Supreme Court review.
ADTP REGULATORY BRIEF
Rep. Darrell Issa introduces the American Copyright Protection Act (H.R. 10364) targeting VPNs for site‑blocking
The bill would extend site‑blocking orders to VPN services, raising significant privacy and security concerns.
ADTP REGULATORY BRIEF
Meta’s Muse AI Agent raises privacy, security, and child safety concerns amid past FTC consent decree
The report highlights significant privacy and safety risks of Meta’s new AI agent, underscoring ongoing concerns about the company’s data practices.
ADTP REGULATORY BRIEF
Federal judge rejects motion to dismiss social media surveillance lawsuit against Trump administration
The ruling lets unions challenge a government AI‑driven social media surveillance program that threatens free speech and privacy of noncitizens.
ADTP REGULATORY BRIEF
Ecuador orders security expert Ola Bini deported and bans return for 10 years
The case highlights the vulnerability of security researchers to arbitrary state actions, raising concerns for digital rights and cybersecurity practitioners.
ADTP REGULATORY BRIEF
CNIL explains when data‑breach victims can claim compensation under the GDPR
Understanding the CNIL’s guidance helps data‑controllers and processors assess liability and prepare for potential court‑ordered damages.
ADTP REGULATORY BRIEF
DOI establishes new matching program under Privacy Act of 1974
The program expands federal data sharing under the Privacy Act, impacting how personal and financial records are matched and used for payment integrity.
ADTP REGULATORY BRIEF
Court order forces Google to allow third‑party app stores on Play Store
The ruling opens Google Play to competing app stores, creating new privacy and security options for Android users.
ADTP REGULATORY BRIEF
Federal judge blocks Utah's anti-VPN age‑verification law (SB 73) with preliminary injunction
The ruling stops Utah's attempt to force worldwide VPN blocking for age‑verification, preserving user privacy and highlighting technical limits of such legislation.
ADTP REGULATORY BRIEF
CNIL to examine draft decree on student violence questionnaire and automated vehicle sound monitoring
The agenda signals upcoming French regulatory scrutiny of new personal data processing tools in education and transport sectors.
ADTP REGULATORY BRIEF
CNIL and Cybermalveillance.gouv.fr release guide for individuals on personal data breach response
The new CNIL guide equips citizens with clear steps to mitigate risks after a personal data breach, strengthening individual data‑privacy protection.
ADTP REGULATORY BRIEF
HUD announces intent to establish eVMS system of records under the Privacy Act
HUD’s proposed eVMS system will centralize personal and financial data for housing assistance, impacting privacy and data‑handling practices.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.