Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 24 of 214 developments
ADTP REGULATORY BRIEF
EU Commission releases two reports on generative AI and digital education impacts
The reports highlight privacy, bias and overreliance risks of AI in education, underscoring the need for guidance and professional development for teachers.
ADTP REGULATORY BRIEF
Commission designates ChatGPT, Reddit, Roblox as VLOPs/VLOSE under the Digital Services Act
The designations trigger new DSA compliance duties for major online services, affecting their risk‑management and user‑protection obligations.
ADTP REGULATORY BRIEF
CNIL examines draft decree creating SI-Mandoline personal data system for protection of adults
The agenda signals upcoming regulatory actions affecting personal data processing for adult legal protection and related professional obligations in France.
ADTP REGULATORY BRIEF
CNIL closes injunction against SOLOCAL MARKETING SERVICES
The decision underscores CNIL's enforcement of GDPR consent requirements for commercial prospecting and the accountability of controllers for partner‑collected data.
ADTP REGULATORY BRIEF
Spanish Data Protection Agency issues warning to company over AI-driven resume screening
The AEPD’s warning highlights GDPR compliance requirements for AI use in recruitment, emphasizing transparency, human control, and risk assessment.
ADTP REGULATORY BRIEF
European Commission proposes EU KIDS Act to strengthen online child protections
The proposal could reshape how online platforms handle children's personal data across the EU.
ADTP REGULATORY BRIEF
Irish Data Protection Commission fines Google €403 million for GDPR violations over location data
The fine underscores strict enforcement of GDPR obligations for large tech firms handling location data.
ADTP REGULATORY BRIEF
EDPB adopts guidelines on GDPR fines and DSA interaction (17 Sep 2026)
The new EDPB guidance clarifies how authorities should levy fines and align DSA obligations with GDPR rules, impacting controllers, processors and digital platforms across the EU.
ADTP REGULATORY BRIEF
EU Commission hosts fifth roundtable on Digital Services Act implementation
The event signals ongoing EU regulator engagement with stakeholders to shape DSA enforcement and address AI and child‑safety risks online.
ADTP REGULATORY BRIEF
London faces privacy pushback against smart glasses, EPIC warns
Highlights emerging privacy concerns about smart glasses in London, relevant for privacy practitioners.
ADTP REGULATORY BRIEF
Future of Privacy Forum opens nominations for 17th Annual Privacy Papers for Policymakers Awards
The call encourages privacy‑focused scholarship that can directly inform policy development.
ADTP REGULATORY BRIEF
Spanish DPA fines Securitas Direct €100,000 for charging phone line for data subject rights
The enforcement underscores that charging fees for exercising GDPR data subject rights is prohibited.
ADTP REGULATORY BRIEF
ENISA releases 2026 Threat Landscape report highlighting AI-enabled cyber threats and supply‑chain risks
The report informs EU stakeholders of evolving cyber threats, emphasizing the need for heightened vigilance and resilience across digital services.
ADTP REGULATORY BRIEF
EU Commission proposes KIDS Act to impose age‑based restrictions and safety‑by‑design for children online
The KIDS Act aims to create EU‑wide, age‑based safeguards and design obligations to protect children’s privacy and safety online.
ADTP REGULATORY BRIEF
EU proposes Article 88c/88bis to allow unrestricted AI use of personal data
If adopted, the proposal would dramatically weaken EU data‑protection rights by granting AI firms blanket access to personal data.
ADTP REGULATORY BRIEF
How to limit Siri AI access in iOS 27
The article explains how iOS 27’s Siri AI expands data access and provides step‑by‑step controls for users to protect their privacy.
ADTP REGULATORY BRIEF
EFF warns that cloud TEEs undermine end‑to‑end encryption in messaging apps
The article highlights a privacy risk where AI features offload encrypted messages to cloud TEEs, weakening end‑to‑end encryption protections.
ADTP REGULATORY BRIEF
CNIL outlines its status, organization and sanction powers
The notice details CNIL’s enforcement authority and the maximum GDPR fines, important for data protection compliance.
ADTP REGULATORY BRIEF
CNIL plenary agenda includes draft decrees on prison camera use, Apple ATT, and data collection in real‑estate rentals
The agenda signals upcoming regulatory scrutiny of surveillance technology, app tracking, and data collection practices in France.
ADTP REGULATORY BRIEF
EU AI Board discusses AI Act implementation and publishes Action Plan on cybersecurity and AI
The meeting signals EU progress on AI governance, linking AI Act enforcement with a new cybersecurity‑AI action plan.
ADTP REGULATORY BRIEF
Kenya publishes new guidance on cross‑border data transfers
The guidance signals stricter requirements for international data flows from Kenya, affecting multinational organisations’ transfer mechanisms and compliance programs.
ADTP REGULATORY BRIEF
EU Commission to propose EU-wide minimum age for social media, linked to Digital Fairness Act
The upcoming proposal could set EU‑wide age limits for minors on social platforms, reshaping platform design and advertising practices.
ADTP REGULATORY BRIEF
EU Cyber Resilience Act reporting obligations take effect for manufacturers
The EU Cyber Resilience Act now imposes mandatory incident reporting duties on manufacturers, raising compliance requirements for product security.
ADTP REGULATORY BRIEF
Dutch DPA fines Uber €824,990,000 for automated decisions affecting drivers
The fine underscores strict GDPR enforcement of automated decision‑making provisions.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.