Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 24 of 214 developments
ADTP REGULATORY BRIEF
Italian DPA fines security firm €39,000 for employee data violations
The enforcement highlights the GDPR’s strict requirements for employee data access and transparent processing of location data.
ADTP REGULATORY BRIEF
Italian DPA fines IQVIA €7 million for unlawful processing of patients’ health data
The fine highlights enforcement of GDPR obligations for health data controllers and underscores the need for proper legal bases, transparency, and impact assessments.
ADTP REGULATORY BRIEF
Italian DPA fines Emirates €180,000 for health data infringements
The enforcement highlights GDPR obligations for clear information and proportionate retention of health data in the aviation sector.
ADTP REGULATORY BRIEF
Italian DPA fines BBVA €5.508 million for ignoring customer objection to direct marketing
The fine underscores the obligation of controllers to promptly respect data subject objections and implement effective technical measures.
ADTP REGULATORY BRIEF
Dutch DPA fines Uber €824.99 million for unlawful automated decision‑making
The fine demonstrates robust GDPR enforcement on automated decision‑making in the gig‑economy.
ADTP REGULATORY BRIEF
Swedish DPA fines Miljödata approx EUR 160,000 for insufficient security measures
The fine underscores the enforcement of GDPR security obligations for data processors handling large volumes of personal and sensitive data.
ADTP REGULATORY BRIEF
Hellenic DPA fines Ministry and EETAA for data breach
The enforcement action highlights the liability of both controllers and processors for inadequate security and non‑compliant processing agreements under the GDPR.
ADTP REGULATORY BRIEF
CNIL closes injunction against FRANCE TRAVAIL after compliance with data security measures
The closure shows that timely remediation of GDPR security deficiencies can halt additional penalties.
ADTP REGULATORY BRIEF
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The action highlights the need for data‑protection‑by‑design and proportionality when deploying AI‑driven video surveillance in the public sector.
ADTP REGULATORY BRIEF
Ecuador orders security expert Ola Bini deported and bans return for 10 years
The case highlights the vulnerability of security researchers to arbitrary state actions, raising concerns for digital rights and cybersecurity practitioners.
ADTP REGULATORY BRIEF
European Commission sends formal notice to Bulgaria for non‑compliance with the Digital Services Act
The action highlights EU enforcement of the Digital Services Act and its impact on national enforcement frameworks and platform liability.
ADTP REGULATORY BRIEF
CNIL closes injunction against SOLOCAL MARKETING SERVICES
The decision underscores CNIL's enforcement of GDPR consent requirements for commercial prospecting and the accountability of controllers for partner‑collected data.
ADTP REGULATORY BRIEF
Spanish Data Protection Agency issues warning to company over AI-driven resume screening
The AEPD’s warning highlights GDPR compliance requirements for AI use in recruitment, emphasizing transparency, human control, and risk assessment.
ADTP REGULATORY BRIEF
Irish Data Protection Commission fines Google €403 million for GDPR violations over location data
The fine underscores strict enforcement of GDPR obligations for large tech firms handling location data.
ADTP REGULATORY BRIEF
Spanish DPA fines Securitas Direct €100,000 for charging phone line for data subject rights
The enforcement underscores that charging fees for exercising GDPR data subject rights is prohibited.
ADTP REGULATORY BRIEF
Dutch DPA fines Uber €824,990,000 for automated decisions affecting drivers
The fine underscores strict GDPR enforcement of automated decision‑making provisions.
ADTP REGULATORY BRIEF
noyb to file injunction against SCHUFA over shadow database
The planned injunction highlights enforcement of EU data‑protection rights against a major credit reference agency.
ADTP REGULATORY BRIEF
AEPD opens investigation into Ministry of Interior report listing journalists and political leanings
The investigation could impact how government bodies handle journalists' personal and political data under GDPR.
ADTP REGULATORY BRIEF
Irish DPC welcomes court conviction of Brown Thomas for ePrivacy breaches
The enforcement action underscores the consequences of non‑compliance with ePrivacy rules for electronic marketing in Ireland.
ADTP REGULATORY BRIEF
EU Commission designates ChatGPT as VLOSE and Reddit, Roblox as VLOPs under DSA
The designations subject the three platforms to heightened DSA compliance requirements, impacting their data handling and AI governance practices.
ADTP REGULATORY BRIEF
Data Protection Commission issues €645,000 fine and compliance orders against HSE
The enforcement action underscores GDPR accountability for health data custodians in Ireland.
ADTP REGULATORY BRIEF
AEPD to host data‑protection session at XX Jornadas STIC on 24 Nov 2026
The AEPD’s participation highlights the growing relevance of privacy and data‑protection in AI‑driven cybersecurity discussions.
ADTP REGULATORY BRIEF
noyb sends cease‑and‑desist letter to SCHUFA over alleged ‘shadow database’ GDPR violations
The action targets a potential GDPR breach affecting up to 69 million Germans and could lead to a large‑scale class action.
ADTP REGULATORY BRIEF
EFF and civil groups urge Nottinghamshire Police to halt live facial recognition rollout
The call highlights privacy and civil‑rights risks of deploying live facial recognition in public spaces, especially for minors.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.