Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 15 of 214 developments
ADTP REGULATORY BRIEF
EU Commission to propose EU-wide minimum age for social media, linked to Digital Fairness Act
The upcoming proposal could set EU‑wide age limits for minors on social platforms, reshaping platform design and advertising practices.
ADTP REGULATORY BRIEF
EU Cyber Resilience Act reporting obligations take effect for manufacturers
The EU Cyber Resilience Act now imposes mandatory incident reporting duties on manufacturers, raising compliance requirements for product security.
ADTP REGULATORY BRIEF
ENISA launches Single Reporting Platform for Cyber Resilience Act reporting
The SRP provides a single, EU‑wide tool for manufacturers to meet CRA reporting duties, enhancing coordinated cybersecurity risk management.
ADTP REGULATORY BRIEF
Dutch DPA fines Uber €824,990,000 for automated decisions affecting drivers
The fine underscores strict GDPR enforcement of automated decision‑making provisions.
ADTP REGULATORY BRIEF
CNIL guidance on data‑protection obligations under the electronic invoicing reform effective 1 Sept 2026
Practitioners must align invoicing processes with GDPR, ISO‑27001, and eIDAS‑level authentication to avoid breaches and ensure lawful handling of personal data.
ADTP REGULATORY BRIEF
CNIL to examine draft deliberation on finance bill 2027 provisions for online platform content collection for tax purposes
The CNIL's review could shape how personal data from online platforms is collected for fiscal purposes, impacting privacy and surveillance practices.
ADTP REGULATORY BRIEF
CNIL releases Volume 2 of “L’Agence Privacy” to educate adolescents on cybercrime and data privacy
The publication provides a new pedagogical tool to improve privacy awareness among minors.
ADTP REGULATORY BRIEF
EU Commission proposes Article 88b for automated privacy signals in Digital Omnibus
The proposal could simplify consent by introducing automated privacy signals, reducing reliance on cookie banners across the EU.
ADTP REGULATORY BRIEF
AEPD opens investigation into Ministry of Interior report listing journalists and political leanings
The investigation could impact how government bodies handle journalists' personal and political data under GDPR.
ADTP REGULATORY BRIEF
Irish DPC welcomes court conviction of Brown Thomas for ePrivacy breaches
The enforcement action underscores the consequences of non‑compliance with ePrivacy rules for electronic marketing in Ireland.
ADTP REGULATORY BRIEF
CNIL agenda includes review of draft decrees on automated personal data processing and authorizations for health data studies
The agenda signals upcoming CNIL scrutiny of new automated data processing initiatives affecting law‑enforcement and health research.
ADTP REGULATORY BRIEF
AEPD to host data‑protection session at XX Jornadas STIC on 24 Nov 2026
The AEPD’s participation highlights the growing relevance of privacy and data‑protection in AI‑driven cybersecurity discussions.
ADTP REGULATORY BRIEF
Austrian Supreme Court rules CRIF’s use of address‑publisher data for credit scoring violates GDPR purpose limitation
The decision clarifies GDPR purpose‑limitation obligations for credit scoring, paving the way for a consumer class action in Austria.
ADTP REGULATORY BRIEF
French Constitutional Council strikes down law banning social media for under‑15s
The ruling blocks a privacy‑invasive age‑verification regime and sets a precedent for similar restrictions in Europe.
ADTP REGULATORY BRIEF
PDPC publishes Advisory Guidelines on Personal Data in Generative AI at Singapore Data Festival
The new PDPC guidance updates consent and notification requirements for AI, shaping how organizations handle personal and biometric data in Singapore.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.