Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 24 of 213 developments
ADTP REGULATORY BRIEF
CNIL hosts 2nd Rencontres Informatique & Libertés on connected glasses and data‑sanctions
The conference highlights emerging privacy challenges of wearable tech and the increasing enforcement activity of the CNIL.
ADTP REGULATORY BRIEF
CISA submits Final CIRCIA Rule to OIRA for interagency review
The rule will impose rapid cyber‑incident reporting obligations on critical‑infrastructure operators, shaping their security and compliance programs.
ADTP REGULATORY BRIEF
EFF warns age‑verification laws risk excluding people without ID
Age‑verification regimes may protect children but also threaten equal access to information and privacy for people without ID.
ADTP REGULATORY BRIEF
Future of Privacy Forum submits comments on Vermont Age-Appropriate Design Code rulemaking
The comments aim to shape Vermont’s upcoming rules on minors’ online privacy, influencing how businesses must design and operate digital services for children.
ADTP REGULATORY BRIEF
CNIL examines draft deliberation authorizing BIG DATA SANTE to process personal data for anonymized medical research (ONCOVAL)
If approved, the authorization would enable a French company to process health‑related personal data for research, shaping data‑privacy practices in the health sector.
ADTP REGULATORY BRIEF
AEPD publishes second issue of scientific journal “Privacy, Innovation and Technology”
The publication provides expert analysis of GDPR challenges and AI governance, helping practitioners anticipate regulatory impacts of emerging technologies.
ADTP REGULATORY BRIEF
Treasury proposes new system of records for federal student aid data
The proposal creates a Treasury‑run record system that will collect and analyze student aid data, raising privacy considerations for the handling of personal and financial information.
ADTP REGULATORY BRIEF
DEA proposes to modify and republish its Aviation Division system of records notice
The proposal alters how the DEA handles aviation reporting records, impacting privacy protections for individuals whose data is collected.
ADTP REGULATORY BRIEF
DOJ proposes exemption for Firearms Rights Restoration Electronic Records Database from Privacy Act provisions
The proposal could limit individuals' access to their own records by creating a privacy Act exemption for a law‑enforcement database.
ADTP REGULATORY BRIEF
Commission registers European Citizens' Initiative for sovereign European AI domains
The registration signals a potential push for new EU AI governance measures driven by citizen input.
ADTP REGULATORY BRIEF
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
The proposal expands collection of sensitive health information and introduces digital processing, impacting privacy and data‑handling obligations.
ADTP REGULATORY BRIEF
Treasury exempts new tip intake records from certain Privacy Act provisions
The exemption limits individuals' privacy rights, such as access and correction, for data in the Treasury's fraud‑tip system.
ADTP REGULATORY BRIEF
EPIC comments on Vermont Attorney General's proposed Age-Appropriate Design Code rules
The comments influence how Vermont will enforce its children‑safety law, shaping privacy‑friendly age verification and design standards.
ADTP REGULATORY BRIEF
EPIC analysis links pixel‑tracking litigation under ECPA and CIPA to upcoming Supreme Court VPPA case
The piece provides practitioners with case‑law guidance on how pixel‑tracking claims are being evaluated under federal and state privacy statutes ahead of the Salazar v. Paramount Supreme Court review.
ADTP REGULATORY BRIEF
EDPB adopts Guidelines 04/2026 on GDPR fines and corrective powers for public consultation
The guidance clarifies how EU data protection authorities may impose fines and corrective measures, impacting GDPR enforcement.
ADTP REGULATORY BRIEF
Commission seeks feedback on proposed EU Kids Act
The consultation will shape EU‑wide rules on child online safety, privacy and age verification.
ADTP REGULATORY BRIEF
CNIL explains when data‑breach victims can claim compensation under the GDPR
Understanding the CNIL’s guidance helps data‑controllers and processors assess liability and prepare for potential court‑ordered damages.
ADTP REGULATORY BRIEF
DOI establishes new matching program under Privacy Act of 1974
The program expands federal data sharing under the Privacy Act, impacting how personal and financial records are matched and used for payment integrity.
ADTP REGULATORY BRIEF
EFF launches Opt Out October campaign urging users to leave tech giants for privacy
The campaign highlights consumer-driven privacy actions as a practical alternative to regulatory solutions.
ADTP REGULATORY BRIEF
CNIL to examine draft decree on student violence questionnaire and automated vehicle sound monitoring
The agenda signals upcoming French regulatory scrutiny of new personal data processing tools in education and transport sectors.
ADTP REGULATORY BRIEF
CNIL and Cybermalveillance.gouv.fr release guide for individuals on personal data breach response
The new CNIL guide equips citizens with clear steps to mitigate risks after a personal data breach, strengthening individual data‑privacy protection.
ADTP REGULATORY BRIEF
EU Commission proposes KIDS Act to ban social‑media access for under‑13s and set minimum account age of 15
The KIDS Act would impose age‑based restrictions and safety‑by‑design obligations on online platforms, directly affecting children’s privacy and online safety in the EU.
ADTP REGULATORY BRIEF
HUD announces intent to establish eVMS system of records under the Privacy Act
HUD’s proposed eVMS system will centralize personal and financial data for housing assistance, impacting privacy and data‑handling practices.
ADTP REGULATORY BRIEF
Federal Register limits automated access; CAPTCHA required for flagged requests
The notice implements security measures to curb automated scraping of federal documents.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.