Regulatory Watch

New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.

9Last 24 hours
34Last 7 days
21High or critical

Showing 24 of 214 developments

Regulatory Guidance ADTP BRIEF 🧭

ADTP REGULATORY BRIEF

CNIL hosts 2nd Rencontres Informatique & Libertés on connected glasses and data‑sanctions

published EU-FR

The conference highlights emerging privacy challenges of wearable tech and the increasing enforcement activity of the CNIL.

Cybersecurity Privacy
Moderate 42 · Oct 9, 2026 · CNIL (France)
Read the full brief →
Dpa Action ADTP BRIEF ⚖️

ADTP REGULATORY BRIEF

Italian DPA fines IQVIA €7 million for unlawful processing of patients’ health data

decided EU-IT

The fine highlights enforcement of GDPR obligations for health data controllers and underscores the need for proper legal bases, transparency, and impact assessments.

Cybersecurity Data governance GDPR
High 72 · Oct 9, 2026 · European Data Protection Board news
Read the full brief →
Regulatory Guidance ADTP BRIEF 🧭

ADTP REGULATORY BRIEF

Commission holds special meeting of Scientific Panel on frontier AI safety and risks

announced EU

The meeting signals EU commitment to strengthen AI governance through scientific input on systemic risk.

AI governance Cybersecurity EU AI Act
Moderate 54 · Oct 9, 2026 · European Commission digital strategy news
Read the full brief →
Regulatory Interpretation ADTP BRIEF 🔎

ADTP REGULATORY BRIEF

EFF warns age‑verification laws risk excluding people without ID

published WORLD

Age‑verification regimes may protect children but also threaten equal access to information and privacy for people without ID.

Children Cybersecurity
Low 30 · Oct 8, 2026 · EFF updates
Read the full brief →
Fine ADTP BRIEF 💰

ADTP REGULATORY BRIEF

Swedish DPA fines Miljödata approx EUR 160,000 for insufficient security measures

decided EU-SE

The fine underscores the enforcement of GDPR security obligations for data processors handling large volumes of personal and sensitive data.

Cybersecurity Enforcement GDPR
Moderate 57 · Oct 8, 2026 · European Data Protection Board news
Read the full brief →
Dpa Action ADTP BRIEF ⚖️

ADTP REGULATORY BRIEF

Hellenic DPA fines Ministry and EETAA for data breach

decided EU-GR

The enforcement action highlights the liability of both controllers and processors for inadequate security and non‑compliant processing agreements under the GDPR.

Cybersecurity Enforcement GDPR
High 62 · Oct 8, 2026 · European Data Protection Board news
Read the full brief →
Enforcement Action ADTP BRIEF ⚖️

ADTP REGULATORY BRIEF

CNIL closes injunction against FRANCE TRAVAIL after compliance with data security measures

decided EU-FR

The closure shows that timely remediation of GDPR security deficiencies can halt additional penalties.

Cybersecurity Data governance
Moderate 42 · Oct 8, 2026 · CNIL (France)
Read the full brief →
Regulatory Guidance ADTP BRIEF 🧭

ADTP REGULATORY BRIEF

AEPD publishes second issue of scientific journal “Privacy, Innovation and Technology”

published EU-ES

The publication provides expert analysis of GDPR challenges and AI governance, helping practitioners anticipate regulatory impacts of emerging technologies.

AI governance Children
Moderate 53 · Oct 8, 2026 · AEPD (Spain) press releases
Read the full brief →
Enforcement Action ADTP BRIEF ⚖️

ADTP REGULATORY BRIEF

AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects

published EU-ES

The action highlights the need for data‑protection‑by‑design and proportionality when deploying AI‑driven video surveillance in the public sector.

AI governance Biometric
High 66 · Oct 6, 2026 · AEPD (Spain) press releases
Read the full brief →
Framework Update ADTP BRIEF 🧩

ADTP REGULATORY BRIEF

Future of Privacy Forum urges standardized privacy benchmarks for frontier AI systems

announced WORLD

Standardized privacy benchmarks would give concrete, comparable metrics for AI developers and deployers, supporting better privacy protection and regulatory oversight.

AI governance Cybersecurity
Low 39 · Oct 5, 2026 · Future of Privacy Forum
Read the full brief →
Enforcement Action ADTP BRIEF ⚖️

ADTP REGULATORY BRIEF

Ecuador orders security expert Ola Bini deported and bans return for 10 years

in effect EC

The case highlights the vulnerability of security researchers to arbitrary state actions, raising concerns for digital rights and cybersecurity practitioners.

Cybersecurity Enforcement
Low 26 · Oct 2, 2026 · EFF updates
Read the full brief →
Regulatory Guidance ADTP BRIEF 🧭

ADTP REGULATORY BRIEF

CNIL explains when data‑breach victims can claim compensation under the GDPR

published EU-FR

Understanding the CNIL’s guidance helps data‑controllers and processors assess liability and prepare for potential court‑ordered damages.

Cybersecurity Data governance
Moderate 44 · Oct 2, 2026 · CNIL (France)
Read the full brief →
Proposed Regulation ADTP BRIEF 📋

ADTP REGULATORY BRIEF

CNIL to examine draft decree on student violence questionnaire and automated vehicle sound monitoring

announced EU-FR

The agenda signals upcoming French regulatory scrutiny of new personal data processing tools in education and transport sectors.

AI governance Children
Moderate 44 · Oct 1, 2026 · CNIL (France)
Read the full brief →
Regulatory Guidance ADTP BRIEF 🧭

ADTP REGULATORY BRIEF

CNIL and Cybermalveillance.gouv.fr release guide for individuals on personal data breach response

published EU-FR

The new CNIL guide equips citizens with clear steps to mitigate risks after a personal data breach, strengthening individual data‑privacy protection.

Cybersecurity Data governance
High 63 · Oct 1, 2026 · CNIL (France)
Read the full brief →
Regulatory Guidance ADTP BRIEF 🧭

ADTP REGULATORY BRIEF

ENISA launches podcast series on Frontier AI and publishes guidance note on cybersecurity in the Frontier AI era

published EU

The launch and accompanying guidance highlight ENISA’s effort to inform stakeholders about AI‑related cybersecurity risks and recommended actions.

AI governance Cybersecurity
Moderate 43 · Sep 28, 2026 · ENISA news
Read the full brief →
Regulatory Interpretation ADTP BRIEF 🔎

ADTP REGULATORY BRIEF

Commission designates ChatGPT, Reddit, Roblox as VLOPs/VLOSE under the Digital Services Act

published EU

The designations trigger new DSA compliance duties for major online services, affecting their risk‑management and user‑protection obligations.

AI governance Children DSA
High 61 · Sep 28, 2026 · European Commission digital strategy news
Read the full brief →
Regulatory Guidance ADTP BRIEF 🧭

ADTP REGULATORY BRIEF

ENISA releases 2026 Threat Landscape report highlighting AI-enabled cyber threats and supply‑chain risks

published EU

The report informs EU stakeholders of evolving cyber threats, emphasizing the need for heightened vigilance and resilience across digital services.

AI governance Cybersecurity NIS2
Moderate 52 · Sep 22, 2026 · ENISA news
Read the full brief →
Proposed Regulation ADTP BRIEF 📋

ADTP REGULATORY BRIEF

EU Commission proposes KIDS Act to impose age‑based restrictions and safety‑by‑design for children online

proposed EU

The KIDS Act aims to create EU‑wide, age‑based safeguards and design obligations to protect children’s privacy and safety online.

AI governance Children DSA
Moderate 55 · Sep 21, 2026 · Covington Inside Privacy
Read the full brief →
Regulatory Guidance ADTP BRIEF 🧭

ADTP REGULATORY BRIEF

How to limit Siri AI access in iOS 27

published WORLD

The article explains how iOS 27’s Siri AI expands data access and provides step‑by‑step controls for users to protect their privacy.

AI governance Cybersecurity
Low 32 · Sep 18, 2026 · EFF updates
Read the full brief →
Regulatory Guidance ADTP BRIEF 🧭

ADTP REGULATORY BRIEF

EFF warns that cloud TEEs undermine end‑to‑end encryption in messaging apps

announced WORLD

The article highlights a privacy risk where AI features offload encrypted messages to cloud TEEs, weakening end‑to‑end encryption protections.

AI governance Cybersecurity
Low 32 · Sep 18, 2026 · EFF updates
Read the full brief →
Regulatory Guidance ADTP BRIEF 🧭

ADTP REGULATORY BRIEF

CNIL outlines its status, organization and sanction powers

published EU-FR

The notice details CNIL’s enforcement authority and the maximum GDPR fines, important for data protection compliance.

Cybersecurity Privacy
Moderate 48 · Sep 17, 2026 · CNIL (France)
Read the full brief →
Framework Update ADTP BRIEF 🧩

ADTP REGULATORY BRIEF

EU AI Board discusses AI Act implementation and publishes Action Plan on cybersecurity and AI

published EU

The meeting signals EU progress on AI governance, linking AI Act enforcement with a new cybersecurity‑AI action plan.

AI governance Cybersecurity EU AI Act
Moderate 50 · Sep 17, 2026 · European Commission digital strategy news
Read the full brief →
Final Regulation ADTP BRIEF 📜

ADTP REGULATORY BRIEF

EU Cyber Resilience Act reporting obligations take effect for manufacturers

in effect EU

The EU Cyber Resilience Act now imposes mandatory incident reporting duties on manufacturers, raising compliance requirements for product security.

Cybersecurity Privacy CRA
Moderate 49 · Sep 11, 2026 · Hunton Privacy & Cybersecurity Law Blog
Read the full brief →
Regulatory Guidance ADTP BRIEF 🧭

ADTP REGULATORY BRIEF

ENISA launches Single Reporting Platform for Cyber Resilience Act reporting

announced EU

The SRP provides a single, EU‑wide tool for manufacturers to meet CRA reporting duties, enhancing coordinated cybersecurity risk management.

Cybersecurity Rules and guidance CRA
Moderate 50 · Sep 11, 2026 · ENISA news
Read the full brief →
Page 1 of 2 Next →

Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.