Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 24 of 214 developments
ADTP REGULATORY BRIEF
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
The notice establishes a new Privacy Act system of records for handling personal data of Peace Corps applicants and volunteers.
ADTP REGULATORY BRIEF
State bills propose exemption for biometric data converted to irreversible mathematical representations
The trend could reshape biometric privacy safeguards by carving out a carve‑out for transformed biometric data.
ADTP REGULATORY BRIEF
NY AG secures $2.3M settlement and reforms from Labcorp after data breach
The settlement forces Labcorp to adopt stronger data‑security and vendor‑risk controls, aiming to protect millions of consumers’ sensitive health information.
ADTP REGULATORY BRIEF
Supreme Court hears digital‑privacy case involving Paramount and targeted advertising
The outcome may define whether online video platforms must use privacy‑preserving methods instead of targeted advertising.
ADTP REGULATORY BRIEF
Spanish Data Protection Agency issues warning to company over AI-driven resume screening
The AEPD’s warning highlights GDPR compliance requirements for AI use in recruitment, emphasizing transparency, human control, and risk assessment.
ADTP REGULATORY BRIEF
EPIC files amicus brief urging Third Circuit to uphold Pennsylvania’s Internet Sharing Ban on voter data
The filing highlights the importance of state voter‑data privacy protections in the context of ongoing appellate litigation.
ADTP REGULATORY BRIEF
Irish Data Protection Commission fines Google €403 million for GDPR violations over location data
The fine underscores strict enforcement of GDPR obligations for large tech firms handling location data.
ADTP REGULATORY BRIEF
Spanish DPA fines Securitas Direct €100,000 for charging phone line for data subject rights
The enforcement underscores that charging fees for exercising GDPR data subject rights is prohibited.
ADTP REGULATORY BRIEF
EU proposes Article 88c/88bis to allow unrestricted AI use of personal data
If adopted, the proposal would dramatically weaken EU data‑protection rights by granting AI firms blanket access to personal data.
ADTP REGULATORY BRIEF
How to limit Siri AI access in iOS 27
The article explains how iOS 27’s Siri AI expands data access and provides step‑by‑step controls for users to protect their privacy.
ADTP REGULATORY BRIEF
EPIC report finds companies hinder personal data access under state privacy laws
The report highlights enforcement challenges in state privacy regimes as companies resist data‑access requests.
ADTP REGULATORY BRIEF
Kenya publishes new guidance on cross‑border data transfers
The guidance signals stricter requirements for international data flows from Kenya, affecting multinational organisations’ transfer mechanisms and compliance programs.
ADTP REGULATORY BRIEF
Supreme Court hears challenge to DHS/SSA upgrades to SAVE database
The case could limit DHS’s use of the SAVE system for citizenship verification, reinforcing federal privacy protections.
ADTP REGULATORY BRIEF
EPIC warns sale of Google’s Spirit Air AI worker data lacks private right of action
The lack of a private right of action could hinder enforcement against the sale of employee data for AI training.
ADTP REGULATORY BRIEF
California AB 1709, a ban on social media for under‑16, signed into law
The law restricts minors' access to social media and raises privacy and free‑speech concerns.
ADTP REGULATORY BRIEF
CNIL guidance on data‑protection obligations under the electronic invoicing reform effective 1 Sept 2026
Practitioners must align invoicing processes with GDPR, ISO‑27001, and eIDAS‑level authentication to avoid breaches and ensure lawful handling of personal data.
ADTP REGULATORY BRIEF
CNIL releases Volume 2 of “L’Agence Privacy” to educate adolescents on cybercrime and data privacy
The publication provides a new pedagogical tool to improve privacy awareness among minors.
ADTP REGULATORY BRIEF
noyb to file injunction against SCHUFA over shadow database
The planned injunction highlights enforcement of EU data‑protection rights against a major credit reference agency.
ADTP REGULATORY BRIEF
EFF blog outlines digital sovereignty and its impact on privacy, data control and security
Understanding digital sovereignty is crucial for shaping privacy‑friendly policies and reducing dependence on dominant tech platforms.
ADTP REGULATORY BRIEF
AEPD opens investigation into Ministry of Interior report listing journalists and political leanings
The investigation could impact how government bodies handle journalists' personal and political data under GDPR.
ADTP REGULATORY BRIEF
Irish DPC welcomes court conviction of Brown Thomas for ePrivacy breaches
The enforcement action underscores the consequences of non‑compliance with ePrivacy rules for electronic marketing in Ireland.
ADTP REGULATORY BRIEF
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
The amendment significantly strengthens privacy protections and expands data‑controller obligations in Delaware.
ADTP REGULATORY BRIEF
Data Protection Commission issues €645,000 fine and compliance orders against HSE
The enforcement action underscores GDPR accountability for health data custodians in Ireland.
ADTP REGULATORY BRIEF
CNIL agenda includes review of draft decrees on automated personal data processing and authorizations for health data studies
The agenda signals upcoming CNIL scrutiny of new automated data processing initiatives affecting law‑enforcement and health research.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.