Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 24 of 214 developments
ADTP REGULATORY BRIEF
Italian DPA fines security firm €39,000 for employee data violations
The enforcement highlights the GDPR’s strict requirements for employee data access and transparent processing of location data.
ADTP REGULATORY BRIEF
CNIL hosts 2nd Rencontres Informatique & Libertés on connected glasses and data‑sanctions
The conference highlights emerging privacy challenges of wearable tech and the increasing enforcement activity of the CNIL.
ADTP REGULATORY BRIEF
Italian DPA fines IQVIA €7 million for unlawful processing of patients’ health data
The fine highlights enforcement of GDPR obligations for health data controllers and underscores the need for proper legal bases, transparency, and impact assessments.
ADTP REGULATORY BRIEF
Italian DPA fines Emirates €180,000 for health data infringements
The enforcement highlights GDPR obligations for clear information and proportionate retention of health data in the aviation sector.
ADTP REGULATORY BRIEF
Italian DPA fines BBVA €5.508 million for ignoring customer objection to direct marketing
The fine underscores the obligation of controllers to promptly respect data subject objections and implement effective technical measures.
ADTP REGULATORY BRIEF
EFF warns age‑verification laws risk excluding people without ID
Age‑verification regimes may protect children but also threaten equal access to information and privacy for people without ID.
ADTP REGULATORY BRIEF
CNIL examines draft deliberation authorizing BIG DATA SANTE to process personal data for anonymized medical research (ONCOVAL)
If approved, the authorization would enable a French company to process health‑related personal data for research, shaping data‑privacy practices in the health sector.
ADTP REGULATORY BRIEF
Dutch DPA fines Uber €824.99 million for unlawful automated decision‑making
The fine demonstrates robust GDPR enforcement on automated decision‑making in the gig‑economy.
ADTP REGULATORY BRIEF
Swedish DPA fines Miljödata approx EUR 160,000 for insufficient security measures
The fine underscores the enforcement of GDPR security obligations for data processors handling large volumes of personal and sensitive data.
ADTP REGULATORY BRIEF
Hellenic DPA fines Ministry and EETAA for data breach
The enforcement action highlights the liability of both controllers and processors for inadequate security and non‑compliant processing agreements under the GDPR.
ADTP REGULATORY BRIEF
CNIL closes injunction against FRANCE TRAVAIL after compliance with data security measures
The closure shows that timely remediation of GDPR security deficiencies can halt additional penalties.
ADTP REGULATORY BRIEF
AEPD publishes second issue of scientific journal “Privacy, Innovation and Technology”
The publication provides expert analysis of GDPR challenges and AI governance, helping practitioners anticipate regulatory impacts of emerging technologies.
ADTP REGULATORY BRIEF
Commission registers European Citizens' Initiative for sovereign European AI domains
The registration signals a potential push for new EU AI governance measures driven by citizen input.
ADTP REGULATORY BRIEF
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The action highlights the need for data‑protection‑by‑design and proportionality when deploying AI‑driven video surveillance in the public sector.
ADTP REGULATORY BRIEF
Future of Privacy Forum urges standardized privacy benchmarks for frontier AI systems
Standardized privacy benchmarks would give concrete, comparable metrics for AI developers and deployers, supporting better privacy protection and regulatory oversight.
ADTP REGULATORY BRIEF
EDPB adopts Guidelines 04/2026 on GDPR fines and corrective powers for public consultation
The guidance clarifies how EU data protection authorities may impose fines and corrective measures, impacting GDPR enforcement.
ADTP REGULATORY BRIEF
Commission seeks feedback on proposed EU Kids Act
The consultation will shape EU‑wide rules on child online safety, privacy and age verification.
ADTP REGULATORY BRIEF
CNIL explains when data‑breach victims can claim compensation under the GDPR
Understanding the CNIL’s guidance helps data‑controllers and processors assess liability and prepare for potential court‑ordered damages.
ADTP REGULATORY BRIEF
CNIL to examine draft decree on student violence questionnaire and automated vehicle sound monitoring
The agenda signals upcoming French regulatory scrutiny of new personal data processing tools in education and transport sectors.
ADTP REGULATORY BRIEF
CNIL and Cybermalveillance.gouv.fr release guide for individuals on personal data breach response
The new CNIL guide equips citizens with clear steps to mitigate risks after a personal data breach, strengthening individual data‑privacy protection.
ADTP REGULATORY BRIEF
European Commission sends formal notice to Bulgaria for non‑compliance with the Digital Services Act
The action highlights EU enforcement of the Digital Services Act and its impact on national enforcement frameworks and platform liability.
ADTP REGULATORY BRIEF
EU Commission proposes KIDS Act to ban social‑media access for under‑13s and set minimum account age of 15
The KIDS Act would impose age‑based restrictions and safety‑by‑design obligations on online platforms, directly affecting children’s privacy and online safety in the EU.
ADTP REGULATORY BRIEF
CNIL to host AIR 2026 event on political communication ethics and election manipulation on 16 Nov 2026
The event highlights how existing privacy rules (RGPD, Loi Informatique et Libertés, 2025 political‑advertising regulation) apply to election‑related data practices and the growing threat of AI‑driven manipulation.
ADTP REGULATORY BRIEF
Data Protection Commission releases AI Insights Report covering 2021‑2025 supervision
The DPC’s AI Insights Report offers regulators and controllers practical guidance on compliant AI development and deployment.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.