Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 24 of 214 developments
ADTP REGULATORY BRIEF
EU proposes Article 88c/88bis to allow unrestricted AI use of personal data
If adopted, the proposal would dramatically weaken EU data‑protection rights by granting AI firms blanket access to personal data.
ADTP REGULATORY BRIEF
How to limit Siri AI access in iOS 27
The article explains how iOS 27’s Siri AI expands data access and provides step‑by‑step controls for users to protect their privacy.
ADTP REGULATORY BRIEF
EFF warns that cloud TEEs undermine end‑to‑end encryption in messaging apps
The article highlights a privacy risk where AI features offload encrypted messages to cloud TEEs, weakening end‑to‑end encryption protections.
ADTP REGULATORY BRIEF
CNIL outlines its status, organization and sanction powers
The notice details CNIL’s enforcement authority and the maximum GDPR fines, important for data protection compliance.
ADTP REGULATORY BRIEF
CNIL plenary agenda includes draft decrees on prison camera use, Apple ATT, and data collection in real‑estate rentals
The agenda signals upcoming regulatory scrutiny of surveillance technology, app tracking, and data collection practices in France.
ADTP REGULATORY BRIEF
Kenya publishes new guidance on cross‑border data transfers
The guidance signals stricter requirements for international data flows from Kenya, affecting multinational organisations’ transfer mechanisms and compliance programs.
ADTP REGULATORY BRIEF
EU Cyber Resilience Act reporting obligations take effect for manufacturers
The EU Cyber Resilience Act now imposes mandatory incident reporting duties on manufacturers, raising compliance requirements for product security.
ADTP REGULATORY BRIEF
ENISA launches Single Reporting Platform for Cyber Resilience Act reporting
The SRP provides a single, EU‑wide tool for manufacturers to meet CRA reporting duties, enhancing coordinated cybersecurity risk management.
ADTP REGULATORY BRIEF
CNIL guidance on data‑protection obligations under the electronic invoicing reform effective 1 Sept 2026
Practitioners must align invoicing processes with GDPR, ISO‑27001, and eIDAS‑level authentication to avoid breaches and ensure lawful handling of personal data.
ADTP REGULATORY BRIEF
CNIL to examine draft deliberation on finance bill 2027 provisions for online platform content collection for tax purposes
The CNIL's review could shape how personal data from online platforms is collected for fiscal purposes, impacting privacy and surveillance practices.
ADTP REGULATORY BRIEF
CNIL releases Volume 2 of “L’Agence Privacy” to educate adolescents on cybercrime and data privacy
The publication provides a new pedagogical tool to improve privacy awareness among minors.
ADTP REGULATORY BRIEF
EU Commission proposes Article 88b for automated privacy signals in Digital Omnibus
The proposal could simplify consent by introducing automated privacy signals, reducing reliance on cookie banners across the EU.
ADTP REGULATORY BRIEF
EFF blog outlines digital sovereignty and its impact on privacy, data control and security
Understanding digital sovereignty is crucial for shaping privacy‑friendly policies and reducing dependence on dominant tech platforms.
ADTP REGULATORY BRIEF
EFF Announces 2026 Award Winners: Access Now, 7amleh, DeFlock, New Media Rights
The award highlights key groups advancing privacy, digital rights, and surveillance accountability worldwide.
ADTP REGULATORY BRIEF
AEPD launches “Las claves de…” series on privacy and emerging neurotechnologies
The series aims to inform stakeholders about GDPR safeguards for neurodata, highlighting emerging privacy risks of brain‑related technologies.
ADTP REGULATORY BRIEF
CNIL agenda includes review of draft decrees on automated personal data processing and authorizations for health data studies
The agenda signals upcoming CNIL scrutiny of new automated data processing initiatives affecting law‑enforcement and health research.
ADTP REGULATORY BRIEF
EFF and The Trevor Project advise LGBTQ+ individuals to revise shared information for online safety
The guidance helps LGBTQ+ individuals reduce exposure to doxxing and outing risks by improving personal data control and security practices.
ADTP REGULATORY BRIEF
EFF and allies recommend new privacy safeguards to protect Brazil's electoral integrity
The recommendations aim to use privacy law enforcement to reduce manipulative political content and protect democratic processes.
ADTP REGULATORY BRIEF
PDPC publishes Advisory Guidelines on Personal Data in Generative AI at Singapore Data Festival
The new PDPC guidance updates consent and notification requirements for AI, shaping how organizations handle personal and biometric data in Singapore.
ADTP REGULATORY BRIEF
EDPB announces stakeholder event on upcoming data protection and competition law guidelines
The event signals forthcoming guidance on how GDPR and competition law intersect, affecting data controllers and processors across the EU.
ADTP REGULATORY BRIEF
AEPD Privacy Lab invites entities to submit projects, research and initiatives
The announcement expands the visibility of privacy‑related work and encourages collaboration across academia, public bodies and industry.
ADTP REGULATORY BRIEF
AEPD announces 2026 Data Protection Awards to recognize privacy promotion
The call highlights the agency’s effort to foster privacy awareness and best‑practice innovation across sectors and vulnerable populations.
ADTP REGULATORY BRIEF
EDPB announces stakeholder event on upcoming data protection and competition law guidelines (15 Oct 2026)
The event provides a forum for stakeholders to shape forthcoming guidance on how competition and data‑protection rules intersect, influencing future compliance obligations.
ADTP REGULATORY BRIEF
AEPD reopens registration for public research network on privacy and emerging technologies
The reopening expands collaboration opportunities and advances research on privacy, AI, and emerging technologies in Spain.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.