Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 9 of 214 developments
ADTP REGULATORY BRIEF
Italian DPA fines IQVIA €7 million for unlawful processing of patients’ health data
The fine highlights enforcement of GDPR obligations for health data controllers and underscores the need for proper legal bases, transparency, and impact assessments.
ADTP REGULATORY BRIEF
Italian DPA fines Emirates €180,000 for health data infringements
The enforcement highlights GDPR obligations for clear information and proportionate retention of health data in the aviation sector.
ADTP REGULATORY BRIEF
Italian DPA fines BBVA €5.508 million for ignoring customer objection to direct marketing
The fine underscores the obligation of controllers to promptly respect data subject objections and implement effective technical measures.
ADTP REGULATORY BRIEF
Dutch DPA fines Uber €824.99 million for unlawful automated decision‑making
The fine demonstrates robust GDPR enforcement on automated decision‑making in the gig‑economy.
ADTP REGULATORY BRIEF
Hellenic DPA fines Ministry and EETAA for data breach
The enforcement action highlights the liability of both controllers and processors for inadequate security and non‑compliant processing agreements under the GDPR.
ADTP REGULATORY BRIEF
Treasury proposes new system of records for federal student aid data
The proposal creates a Treasury‑run record system that will collect and analyze student aid data, raising privacy considerations for the handling of personal and financial information.
ADTP REGULATORY BRIEF
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The action highlights the need for data‑protection‑by‑design and proportionality when deploying AI‑driven video surveillance in the public sector.
ADTP REGULATORY BRIEF
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
The proposal expands collection of sensitive health information and introduces digital processing, impacting privacy and data‑handling obligations.
ADTP REGULATORY BRIEF
Treasury exempts new tip intake records from certain Privacy Act provisions
The exemption limits individuals' privacy rights, such as access and correction, for data in the Treasury's fraud‑tip system.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.