Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 21 of 214 developments
ADTP REGULATORY BRIEF
Meta to implement age‑verification framework under $17 B settlement with 52 U.S. states
The settlement imposes extensive age‑verification and data‑retention obligations on Meta, affecting privacy and surveillance of all users.
ADTP REGULATORY BRIEF
Austrian Supreme Court rules CRIF’s use of address‑publisher data for credit scoring violates GDPR purpose limitation
The decision clarifies GDPR purpose‑limitation obligations for credit scoring, paving the way for a consumer class action in Austria.
ADTP REGULATORY BRIEF
EFF guide on doxxing incident response and digital footprint protection
Provides practical privacy and security measures to help victims mitigate and respond to doxxing campaigns.
ADTP REGULATORY BRIEF
Five US states enact location privacy laws banning sale of precise geolocation data
The enactment creates baseline protections for location data while highlighting enforcement gaps that could limit effectiveness.
ADTP REGULATORY BRIEF
EFF and The Trevor Project advise LGBTQ+ individuals to revise shared information for online safety
The guidance helps LGBTQ+ individuals reduce exposure to doxxing and outing risks by improving personal data control and security practices.
ADTP REGULATORY BRIEF
EFF and allies recommend new privacy safeguards to protect Brazil's electoral integrity
The recommendations aim to use privacy law enforcement to reduce manipulative political content and protect democratic processes.
ADTP REGULATORY BRIEF
EFF says Meta settlement expands data collection and limits youth rights
The settlement broadens Meta's data collection and surveillance, raising significant privacy and child‑safety concerns.
ADTP REGULATORY BRIEF
noyb sends cease‑and‑desist letter to SCHUFA over alleged ‘shadow database’ GDPR violations
The action targets a potential GDPR breach affecting up to 69 million Germans and could lead to a large‑scale class action.
ADTP REGULATORY BRIEF
PDPC publishes Advisory Guidelines on Personal Data in Generative AI at Singapore Data Festival
The new PDPC guidance updates consent and notification requirements for AI, shaping how organizations handle personal and biometric data in Singapore.
ADTP REGULATORY BRIEF
Tech firms privately resist ICE subpoenas seeking user data
Corporate resistance to ICE subpoenas highlights the role of tech firms in protecting user privacy and First Amendment rights.
ADTP REGULATORY BRIEF
Colorado governor signs SB 26-189, revising AI Act to regulate ADMT in employment
The law creates new notice, disclosure, and remediation obligations for employers using AI in hiring, promotion, and termination decisions.
ADTP REGULATORY BRIEF
Flock Safety announces optional 7‑day ALPR data retention and other reforms
The reforms aim to limit how long police can retain vehicle location data, addressing privacy concerns around mass surveillance.
ADTP REGULATORY BRIEF
New Jersey enacts Age-Appropriate Design Code (A4015) signed by Governor Sherrill
The NJAADC introduces comprehensive safety‑by‑design rules for minors online, setting a new national benchmark for age‑appropriate design.
ADTP REGULATORY BRIEF
Ninth Circuit rules Perplexity AI’s Comet browser not liable under CFAA
The ruling limits CFAA liability for AI‑driven web tools, clarifying that developers are not criminally responsible for user‑initiated access.
ADTP REGULATORY BRIEF
noyb files GDPR complaint against dict.cc over 1,741‑partner consent banner
The case highlights how mass‑consent banners can breach GDPR’s informed‑consent rule.
ADTP REGULATORY BRIEF
AEPD publishes technical guidance on data accuracy and minimisation in AI processing
The guidance clarifies how GDPR data‑quality obligations apply to AI, helping organisations balance protection with AI development.
ADTP REGULATORY BRIEF
US Supreme Court decision undermines EU‑US Data Privacy Framework
The ruling threatens the legal basis for EU‑US personal data flows, forcing a reassessment of cross‑border transfers.
ADTP REGULATORY BRIEF
noyb files injunction against Austrian credit agency CRIF over GDPR violations
The injunction could halt a large‑scale secret credit scoring system and set a precedent for collective GDPR enforcement in the EU.
ADTP REGULATORY BRIEF
LinkedIn blocks GDPR access to profile visitor data behind paywall, noyb files complaint in Austria
The case challenges LinkedIn's practice of charging for data that GDPR mandates be freely accessible, potentially setting a precedent for data access rights enforcement.
ADTP REGULATORY BRIEF
noyb files lawsuit against Hamburg DPA over inaction on PimEyes biometric data case
The suit underscores gaps in GDPR enforcement when controllers operate from third countries and process biometric data.
ADTP REGULATORY BRIEF
EU Digital Omnibus proposal aims to limit GDPR right of access amid 83.5% non‑compliance
Limiting the right of access would further erode data subject protections despite widespread non‑compliance by companies.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.