Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 16 of 214 developments
ADTP REGULATORY BRIEF
CNIL to host AIR 2026 event on political communication ethics and election manipulation on 16 Nov 2026
The event highlights how existing privacy rules (RGPD, Loi Informatique et Libertés, 2025 political‑advertising regulation) apply to election‑related data practices and the growing threat of AI‑driven manipulation.
ADTP REGULATORY BRIEF
Data Protection Commission releases AI Insights Report covering 2021‑2025 supervision
The DPC’s AI Insights Report offers regulators and controllers practical guidance on compliant AI development and deployment.
ADTP REGULATORY BRIEF
ENISA launches podcast series on Frontier AI and publishes guidance note on cybersecurity in the Frontier AI era
The launch and accompanying guidance highlight ENISA’s effort to inform stakeholders about AI‑related cybersecurity risks and recommended actions.
ADTP REGULATORY BRIEF
EU Commission releases two reports on generative AI and digital education impacts
The reports highlight privacy, bias and overreliance risks of AI in education, underscoring the need for guidance and professional development for teachers.
ADTP REGULATORY BRIEF
CNIL examines draft decree creating SI-Mandoline personal data system for protection of adults
The agenda signals upcoming regulatory actions affecting personal data processing for adult legal protection and related professional obligations in France.
ADTP REGULATORY BRIEF
Spanish Data Protection Agency issues warning to company over AI-driven resume screening
The AEPD’s warning highlights GDPR compliance requirements for AI use in recruitment, emphasizing transparency, human control, and risk assessment.
ADTP REGULATORY BRIEF
EDPB adopts guidelines on GDPR fines and DSA interaction (17 Sep 2026)
The new EDPB guidance clarifies how authorities should levy fines and align DSA obligations with GDPR rules, impacting controllers, processors and digital platforms across the EU.
ADTP REGULATORY BRIEF
EU Commission hosts fifth roundtable on Digital Services Act implementation
The event signals ongoing EU regulator engagement with stakeholders to shape DSA enforcement and address AI and child‑safety risks online.
ADTP REGULATORY BRIEF
Spanish DPA fines Securitas Direct €100,000 for charging phone line for data subject rights
The enforcement underscores that charging fees for exercising GDPR data subject rights is prohibited.
ADTP REGULATORY BRIEF
ENISA releases 2026 Threat Landscape report highlighting AI-enabled cyber threats and supply‑chain risks
The report informs EU stakeholders of evolving cyber threats, emphasizing the need for heightened vigilance and resilience across digital services.
ADTP REGULATORY BRIEF
EU Commission proposes KIDS Act to impose age‑based restrictions and safety‑by‑design for children online
The KIDS Act aims to create EU‑wide, age‑based safeguards and design obligations to protect children’s privacy and safety online.
ADTP REGULATORY BRIEF
EU proposes Article 88c/88bis to allow unrestricted AI use of personal data
If adopted, the proposal would dramatically weaken EU data‑protection rights by granting AI firms blanket access to personal data.
ADTP REGULATORY BRIEF
CNIL outlines its status, organization and sanction powers
The notice details CNIL’s enforcement authority and the maximum GDPR fines, important for data protection compliance.
ADTP REGULATORY BRIEF
CNIL plenary agenda includes draft decrees on prison camera use, Apple ATT, and data collection in real‑estate rentals
The agenda signals upcoming regulatory scrutiny of surveillance technology, app tracking, and data collection practices in France.
ADTP REGULATORY BRIEF
EU AI Board discusses AI Act implementation and publishes Action Plan on cybersecurity and AI
The meeting signals EU progress on AI governance, linking AI Act enforcement with a new cybersecurity‑AI action plan.
ADTP REGULATORY BRIEF
Kenya publishes new guidance on cross‑border data transfers
The guidance signals stricter requirements for international data flows from Kenya, affecting multinational organisations’ transfer mechanisms and compliance programs.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.