Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 14 of 214 developments
ADTP REGULATORY BRIEF
Irish DPC welcomes court conviction of Brown Thomas for ePrivacy breaches
The enforcement action underscores the consequences of non‑compliance with ePrivacy rules for electronic marketing in Ireland.
ADTP REGULATORY BRIEF
Data Protection Commission issues €645,000 fine and compliance orders against HSE
The enforcement action underscores GDPR accountability for health data custodians in Ireland.
ADTP REGULATORY BRIEF
CNIL agenda includes review of draft decrees on automated personal data processing and authorizations for health data studies
The agenda signals upcoming CNIL scrutiny of new automated data processing initiatives affecting law‑enforcement and health research.
ADTP REGULATORY BRIEF
Austrian Supreme Court rules CRIF’s use of address‑publisher data for credit scoring violates GDPR purpose limitation
The decision clarifies GDPR purpose‑limitation obligations for credit scoring, paving the way for a consumer class action in Austria.
ADTP REGULATORY BRIEF
EFF and The Trevor Project advise LGBTQ+ individuals to revise shared information for online safety
The guidance helps LGBTQ+ individuals reduce exposure to doxxing and outing risks by improving personal data control and security practices.
ADTP REGULATORY BRIEF
EFF and allies recommend new privacy safeguards to protect Brazil's electoral integrity
The recommendations aim to use privacy law enforcement to reduce manipulative political content and protect democratic processes.
ADTP REGULATORY BRIEF
noyb sends cease‑and‑desist letter to SCHUFA over alleged ‘shadow database’ GDPR violations
The action targets a potential GDPR breach affecting up to 69 million Germans and could lead to a large‑scale class action.
ADTP REGULATORY BRIEF
PDPC publishes Advisory Guidelines on Personal Data in Generative AI at Singapore Data Festival
The new PDPC guidance updates consent and notification requirements for AI, shaping how organizations handle personal and biometric data in Singapore.
ADTP REGULATORY BRIEF
noyb files GDPR complaint against dict.cc over 1,741‑partner consent banner
The case highlights how mass‑consent banners can breach GDPR’s informed‑consent rule.
ADTP REGULATORY BRIEF
AEPD publishes technical guidance on data accuracy and minimisation in AI processing
The guidance clarifies how GDPR data‑quality obligations apply to AI, helping organisations balance protection with AI development.
ADTP REGULATORY BRIEF
noyb files injunction against Austrian credit agency CRIF over GDPR violations
The injunction could halt a large‑scale secret credit scoring system and set a precedent for collective GDPR enforcement in the EU.
ADTP REGULATORY BRIEF
LinkedIn blocks GDPR access to profile visitor data behind paywall, noyb files complaint in Austria
The case challenges LinkedIn's practice of charging for data that GDPR mandates be freely accessible, potentially setting a precedent for data access rights enforcement.
ADTP REGULATORY BRIEF
noyb files lawsuit against Hamburg DPA over inaction on PimEyes biometric data case
The suit underscores gaps in GDPR enforcement when controllers operate from third countries and process biometric data.
ADTP REGULATORY BRIEF
EU Digital Omnibus proposal aims to limit GDPR right of access amid 83.5% non‑compliance
Limiting the right of access would further erode data subject protections despite widespread non‑compliance by companies.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.