Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 24 of 214 developments
ADTP REGULATORY BRIEF
Federal Register limits automated access; CAPTCHA required for flagged requests
The notice implements security measures to curb automated scraping of federal documents.
ADTP REGULATORY BRIEF
Federal Register proposes limiting automated scraping, requiring API use and CAPTCHAs
The proposal impacts developers by mandating API‑only programmatic access and adding CAPTCHA verification to protect site security.
ADTP REGULATORY BRIEF
FBI announces new Cyber Strategy emphasizing public‑private collaboration and rapid threat‑intel sharing
The strategy signals increased FBI engagement with private sector to improve cyber threat detection and response.
ADTP REGULATORY BRIEF
EFF discusses privacy implications of Apple Siri AI features in iOS 27
Understanding Siri’s data handling helps users protect privacy as AI features expand on mobile devices.
ADTP REGULATORY BRIEF
NHTSA seeks OMB approval to renew and modify information collection for qualitative feedback on service delivery
The notice expands federal data collection on enforcement activities, raising privacy considerations for respondents.
ADTP REGULATORY BRIEF
Commerce Department seeks input on digitizing and modernizing the National Technical Reports Library
The RFI could shape how U.S. government technical data become available for AI training and research, impacting data‑governance and AI‑governance considerations.
ADTP REGULATORY BRIEF
HUD modifies system of records notice for Inventory Management System and Housing Information Portal
The update revises HUD's data handling rules, affecting how housing assistance information is collected, shared, and protected.
ADTP REGULATORY BRIEF
San Francisco announces new ALPR policy with limited safeguards, no warrant requirement, 30‑day data transfer deadline
The policy's weak safeguards raise significant privacy concerns over citywide location tracking.
ADTP REGULATORY BRIEF
EFF launches 'Privacy’s Defenders' podcast on digital surveillance history
The podcast provides advocacy insight and historical context for privacy practitioners tracking privacy and surveillance issues.
ADTP REGULATORY BRIEF
Federal Register restricts automated scraping; requires API use and CAPTCHA verification
Increased security measures on federal sites affect developers and researchers who rely on automated data collection.
ADTP REGULATORY BRIEF
Agency seeks comment on proposed information collection for protection of human subjects
The request for comment could shape future data‑privacy and security requirements for institutions handling human‑subjects data and API access.
ADTP REGULATORY BRIEF
FCC and USAC launch new computer matching program to verify Lifeline eligibility
The program aims to improve verification of Lifeline benefits by sharing personal data between agencies.
ADTP REGULATORY BRIEF
San Francisco Police Department proposes expanded drone surveillance policy, drawing criticism from EFF
The proposed SFPD drone policy could enable widespread surveillance without adequate privacy protections, raising civil liberties concerns.
ADTP REGULATORY BRIEF
EPIC and consumer groups urge FTC to ban surveillance pricing, calling disclosure insufficient
The filing pushes the FTC to consider banning personalized pricing, potentially expanding consumer protection against data-driven price discrimination.
ADTP REGULATORY BRIEF
CNIL to host AIR 2026 event on political communication ethics and election manipulation on 16 Nov 2026
The event highlights how existing privacy rules (RGPD, Loi Informatique et Libertés, 2025 political‑advertising regulation) apply to election‑related data practices and the growing threat of AI‑driven manipulation.
ADTP REGULATORY BRIEF
California Privacy Protection Agency adopts multiple regulations including Conflict of Interest Code Amendments and Data Broker Registration Fee
Adopted CPPA regulations expand enforcement tools for the CCPA and Delete Act, affecting data brokers and other entities.
ADTP REGULATORY BRIEF
Data Protection Commission releases AI Insights Report covering 2021‑2025 supervision
The DPC’s AI Insights Report offers regulators and controllers practical guidance on compliant AI development and deployment.
ADTP REGULATORY BRIEF
ENISA launches podcast series on Frontier AI and publishes guidance note on cybersecurity in the Frontier AI era
The launch and accompanying guidance highlight ENISA’s effort to inform stakeholders about AI‑related cybersecurity risks and recommended actions.
ADTP REGULATORY BRIEF
Commission designates ChatGPT, Reddit, Roblox as VLOPs/VLOSE under the Digital Services Act
The designations trigger new DSA compliance duties for major online services, affecting their risk‑management and user‑protection obligations.
ADTP REGULATORY BRIEF
Federal Register restricts automated scraping, requires CAPTCHA and API use
The notice informs users of new access controls that impact automated data collection from federal publications.
ADTP REGULATORY BRIEF
HHS modifies ORR Unaccompanied Children system of records, effective Oct 28, 2026
The update alters how child protection data is shared, impacting privacy and information handling for vulnerable minors.
ADTP REGULATORY BRIEF
DoD updates SORN for DON Child and Youth Program to align with cybersecurity policies
The notice updates how children's health and personal data are handled, adding cybersecurity safeguards and expanded uses.
ADTP REGULATORY BRIEF
Peace Corps announces new CRM system of records (PC 38) effective Oct 26, 2026
The notice establishes a new Privacy Act system of records for handling personal data of Peace Corps applicants and volunteers.
ADTP REGULATORY BRIEF
CMS re-establishes matching program with Treasury's Do Not Pay Working System under Privacy Act
The program expands data sharing for fraud prevention, raising privacy and security considerations for covered entities.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.