Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 24 of 214 developments
ADTP REGULATORY BRIEF
Italian DPA fines security firm €39,000 for employee data violations
The enforcement highlights the GDPR’s strict requirements for employee data access and transparent processing of location data.
ADTP REGULATORY BRIEF
Italian DPA fines IQVIA €7 million for unlawful processing of patients’ health data
The fine highlights enforcement of GDPR obligations for health data controllers and underscores the need for proper legal bases, transparency, and impact assessments.
ADTP REGULATORY BRIEF
Italian DPA fines Emirates €180,000 for health data infringements
The enforcement highlights GDPR obligations for clear information and proportionate retention of health data in the aviation sector.
ADTP REGULATORY BRIEF
Italian DPA fines BBVA €5.508 million for ignoring customer objection to direct marketing
The fine underscores the obligation of controllers to promptly respect data subject objections and implement effective technical measures.
ADTP REGULATORY BRIEF
Dutch DPA fines Uber €824.99 million for unlawful automated decision‑making
The fine demonstrates robust GDPR enforcement on automated decision‑making in the gig‑economy.
ADTP REGULATORY BRIEF
Swedish DPA fines Miljödata approx EUR 160,000 for insufficient security measures
The fine underscores the enforcement of GDPR security obligations for data processors handling large volumes of personal and sensitive data.
ADTP REGULATORY BRIEF
Hellenic DPA fines Ministry and EETAA for data breach
The enforcement action highlights the liability of both controllers and processors for inadequate security and non‑compliant processing agreements under the GDPR.
ADTP REGULATORY BRIEF
CNIL closes injunction against FRANCE TRAVAIL after compliance with data security measures
The closure shows that timely remediation of GDPR security deficiencies can halt additional penalties.
ADTP REGULATORY BRIEF
Texas AG launches investigation into children's clothing companies over toxic chemicals
The action targets possible chemical hazards in children’s apparel, highlighting consumer‑health risks and corporate accountability.
ADTP REGULATORY BRIEF
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The action highlights the need for data‑protection‑by‑design and proportionality when deploying AI‑driven video surveillance in the public sector.
ADTP REGULATORY BRIEF
Meta’s Muse AI Agent raises privacy, security, and child safety concerns amid past FTC consent decree
The report highlights significant privacy and safety risks of Meta’s new AI agent, underscoring ongoing concerns about the company’s data practices.
ADTP REGULATORY BRIEF
Ecuador orders security expert Ola Bini deported and bans return for 10 years
The case highlights the vulnerability of security researchers to arbitrary state actions, raising concerns for digital rights and cybersecurity practitioners.
ADTP REGULATORY BRIEF
EFF and ACLU demand records from Marin County Sheriff over illegal ALPR data sharing
The action highlights ongoing non‑compliance with California privacy statutes governing ALPR data and pressures the agency to audit and halt unlawful data sharing.
ADTP REGULATORY BRIEF
European Commission sends formal notice to Bulgaria for non‑compliance with the Digital Services Act
The action highlights EU enforcement of the Digital Services Act and its impact on national enforcement frameworks and platform liability.
ADTP REGULATORY BRIEF
NY Attorney General releases body‑worn camera footage of minor’s death investigation
The AG’s release of police body‑camera video aims to improve transparency and public confidence in law‑enforcement investigations.
ADTP REGULATORY BRIEF
Texas AG Paxton launches investigation into AI data center development on land originally conveyed for park use
The investigation could halt a private AI data center project that may violate a longstanding public‑park trust, highlighting enforcement of land‑use restrictions in emerging AI infrastructure.
ADTP REGULATORY BRIEF
Senate Judiciary Subcommittee holds hearing on Flock Safety AI surveillance network
The hearing spotlights growing privacy and security risks of AI‑driven license‑plate and facial‑recognition surveillance used by police.
ADTP REGULATORY BRIEF
CNIL closes injunction against SOLOCAL MARKETING SERVICES
The decision underscores CNIL's enforcement of GDPR consent requirements for commercial prospecting and the accountability of controllers for partner‑collected data.
ADTP REGULATORY BRIEF
NY AG secures $2.3M settlement and reforms from Labcorp after data breach
The settlement forces Labcorp to adopt stronger data‑security and vendor‑risk controls, aiming to protect millions of consumers’ sensitive health information.
ADTP REGULATORY BRIEF
Spanish Data Protection Agency issues warning to company over AI-driven resume screening
The AEPD’s warning highlights GDPR compliance requirements for AI use in recruitment, emphasizing transparency, human control, and risk assessment.
ADTP REGULATORY BRIEF
Irish Data Protection Commission fines Google €403 million for GDPR violations over location data
The fine underscores strict enforcement of GDPR obligations for large tech firms handling location data.
ADTP REGULATORY BRIEF
Spanish DPA fines Securitas Direct €100,000 for charging phone line for data subject rights
The enforcement underscores that charging fees for exercising GDPR data subject rights is prohibited.
ADTP REGULATORY BRIEF
FTC Announces Additional Payments to Consumers Under Amazon Prime Settlement
The expanded refund amount increases consumer restitution in the Amazon Prime case.
ADTP REGULATORY BRIEF
FleetCor to Pay $100M to Settle FTC Administrative Action Over Unauthorized Fuel Card Fees
The settlement enforces FTC rules against deceptive fee practices that affect small businesses.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.