Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 10 of 214 developments
ADTP REGULATORY BRIEF
Italian DPA fines security firm €39,000 for employee data violations
The enforcement highlights the GDPR’s strict requirements for employee data access and transparent processing of location data.
ADTP REGULATORY BRIEF
Swedish DPA fines Miljödata approx EUR 160,000 for insufficient security measures
The fine underscores the enforcement of GDPR security obligations for data processors handling large volumes of personal and sensitive data.
ADTP REGULATORY BRIEF
CNIL closes injunction against FRANCE TRAVAIL after compliance with data security measures
The closure shows that timely remediation of GDPR security deficiencies can halt additional penalties.
ADTP REGULATORY BRIEF
European Commission sends formal notice to Bulgaria for non‑compliance with the Digital Services Act
The action highlights EU enforcement of the Digital Services Act and its impact on national enforcement frameworks and platform liability.
ADTP REGULATORY BRIEF
Spanish Data Protection Agency issues warning to company over AI-driven resume screening
The AEPD’s warning highlights GDPR compliance requirements for AI use in recruitment, emphasizing transparency, human control, and risk assessment.
ADTP REGULATORY BRIEF
Spanish DPA fines Securitas Direct €100,000 for charging phone line for data subject rights
The enforcement underscores that charging fees for exercising GDPR data subject rights is prohibited.
ADTP REGULATORY BRIEF
Dutch DPA fines Uber €824,990,000 for automated decisions affecting drivers
The fine underscores strict GDPR enforcement of automated decision‑making provisions.
ADTP REGULATORY BRIEF
AEPD opens investigation into Ministry of Interior report listing journalists and political leanings
The investigation could impact how government bodies handle journalists' personal and political data under GDPR.
ADTP REGULATORY BRIEF
Irish DPC welcomes court conviction of Brown Thomas for ePrivacy breaches
The enforcement action underscores the consequences of non‑compliance with ePrivacy rules for electronic marketing in Ireland.
ADTP REGULATORY BRIEF
AEPD to host data‑protection session at XX Jornadas STIC on 24 Nov 2026
The AEPD’s participation highlights the growing relevance of privacy and data‑protection in AI‑driven cybersecurity discussions.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.