Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 23 of 214 developments
ADTP REGULATORY BRIEF
EFF and civil groups urge Nottinghamshire Police to halt live facial recognition rollout
The call highlights privacy and civil‑rights risks of deploying live facial recognition in public spaces, especially for minors.
ADTP REGULATORY BRIEF
EFF report finds mobile ad libraries may leak user location data
The findings raise privacy concerns about location tracking by ad SDKs and underscore the need for stronger safeguards.
ADTP REGULATORY BRIEF
US federal age‑verification proposals KIDS Act and KOSA face privacy criticism over ZKP use
Proposed age‑verification laws in the US and EU are criticized for privacy and security risks associated with ZKP‑based systems.
ADTP REGULATORY BRIEF
French Constitutional Council strikes down law banning under‑15s from social media
The ruling halts a major child‑protection measure, affecting age‑verification requirements and privacy protections for minors on social platforms.
ADTP REGULATORY BRIEF
EU proposes Cloud and AI Development Act (CADA) to boost AI and cloud sovereignty
CADA marks a shift toward AI‑promotion legislation in the EU, introducing positive obligations for Member States to foster AI innovation and cloud infrastructure.
ADTP REGULATORY BRIEF
EU Commission begins enforcing AI Act and new transparency rules on 2 August 2026
The enforcement introduces mandatory disclosure obligations for AI systems to curb deception and give users clearer information.
ADTP REGULATORY BRIEF
EDPB announces stakeholder event on upcoming data protection and competition law guidelines
The event signals forthcoming guidance on how GDPR and competition law intersect, affecting data controllers and processors across the EU.
ADTP REGULATORY BRIEF
noyb files GDPR complaint against dict.cc over 1,741‑partner consent banner
The case highlights how mass‑consent banners can breach GDPR’s informed‑consent rule.
ADTP REGULATORY BRIEF
AEPD Privacy Lab invites entities to submit projects, research and initiatives
The announcement expands the visibility of privacy‑related work and encourages collaboration across academia, public bodies and industry.
ADTP REGULATORY BRIEF
AEPD announces 2026 Data Protection Awards to recognize privacy promotion
The call highlights the agency’s effort to foster privacy awareness and best‑practice innovation across sectors and vulnerable populations.
ADTP REGULATORY BRIEF
EDPB announces stakeholder event on upcoming data protection and competition law guidelines (15 Oct 2026)
The event provides a forum for stakeholders to shape forthcoming guidance on how competition and data‑protection rules intersect, influencing future compliance obligations.
ADTP REGULATORY BRIEF
AEPD reopens registration for public research network on privacy and emerging technologies
The reopening expands collaboration opportunities and advances research on privacy, AI, and emerging technologies in Spain.
ADTP REGULATORY BRIEF
AEPD publishes technical guidance on data accuracy and minimisation in AI processing
The guidance clarifies how GDPR data‑quality obligations apply to AI, helping organisations balance protection with AI development.
ADTP REGULATORY BRIEF
EDPB calls for legal basis for cross‑regulatory information sharing
A legal framework for cross‑regulatory information sharing would enhance GDPR enforcement consistency and efficiency across the EU.
ADTP REGULATORY BRIEF
EDPB orders Belgian DPA to assess NOYB cookie banner complaint on merits
The ruling clarifies DPAs must assess cookie banner complaints substantively, strengthening enforcement of GDPR consent requirements.
ADTP REGULATORY BRIEF
EU Council scrapes Article 88b proposal to replace cookie banners with automated signal
The Council’s removal of Article 88b halts the EU’s effort to simplify online consent mechanisms.
ADTP REGULATORY BRIEF
noyb files injunction against Austrian credit agency CRIF over GDPR violations
The injunction could halt a large‑scale secret credit scoring system and set a precedent for collective GDPR enforcement in the EU.
ADTP REGULATORY BRIEF
Norwegian Consumer Council and noyb file complaint against Schibsted over “Pay or Okay” tracking scheme
The complaint challenges a forced‑consent model that could undermine GDPR consent standards across the Nordics.
ADTP REGULATORY BRIEF
ENISA releases NIS360 report showing improved cybersecurity maturity of EU critical sectors
The report tracks implementation of the NIS2 Directive and helps policymakers prioritize resources to boost cyber resilience across the EU.
ADTP REGULATORY BRIEF
Austrian Federal Administrative Court orders ORF to redesign cookie banner for equal consent options
The ruling clarifies that cookie consent mechanisms must offer equally prominent opt‑in and opt‑out options, impacting many online services.
ADTP REGULATORY BRIEF
LinkedIn blocks GDPR access to profile visitor data behind paywall, noyb files complaint in Austria
The case challenges LinkedIn's practice of charging for data that GDPR mandates be freely accessible, potentially setting a precedent for data access rights enforcement.
ADTP REGULATORY BRIEF
noyb files lawsuit against Hamburg DPA over inaction on PimEyes biometric data case
The suit underscores gaps in GDPR enforcement when controllers operate from third countries and process biometric data.
ADTP REGULATORY BRIEF
EU Digital Omnibus proposal aims to limit GDPR right of access amid 83.5% non‑compliance
Limiting the right of access would further erode data subject protections despite widespread non‑compliance by companies.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.