Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 24 of 214 developments
ADTP REGULATORY BRIEF
CNIL guidance on data‑protection obligations under the electronic invoicing reform effective 1 Sept 2026
Practitioners must align invoicing processes with GDPR, ISO‑27001, and eIDAS‑level authentication to avoid breaches and ensure lawful handling of personal data.
ADTP REGULATORY BRIEF
CNIL to examine draft deliberation on finance bill 2027 provisions for online platform content collection for tax purposes
The CNIL's review could shape how personal data from online platforms is collected for fiscal purposes, impacting privacy and surveillance practices.
ADTP REGULATORY BRIEF
CNIL releases Volume 2 of “L’Agence Privacy” to educate adolescents on cybercrime and data privacy
The publication provides a new pedagogical tool to improve privacy awareness among minors.
ADTP REGULATORY BRIEF
noyb to file injunction against SCHUFA over shadow database
The planned injunction highlights enforcement of EU data‑protection rights against a major credit reference agency.
ADTP REGULATORY BRIEF
EU Commission proposes Article 88b for automated privacy signals in Digital Omnibus
The proposal could simplify consent by introducing automated privacy signals, reducing reliance on cookie banners across the EU.
ADTP REGULATORY BRIEF
2015 court ruling requires warrant for police use of stingray devices
The ruling establishes that police need a warrant to deploy stingray technology, protecting privacy rights against warrantless surveillance.
ADTP REGULATORY BRIEF
EFF blog outlines digital sovereignty and its impact on privacy, data control and security
Understanding digital sovereignty is crucial for shaping privacy‑friendly policies and reducing dependence on dominant tech platforms.
ADTP REGULATORY BRIEF
EFF Announces 2026 Award Winners: Access Now, 7amleh, DeFlock, New Media Rights
The award highlights key groups advancing privacy, digital rights, and surveillance accountability worldwide.
ADTP REGULATORY BRIEF
AEPD opens investigation into Ministry of Interior report listing journalists and political leanings
The investigation could impact how government bodies handle journalists' personal and political data under GDPR.
ADTP REGULATORY BRIEF
FTC rescinds 2021 Policy Statement on Breaches by Health Apps and Connected Devices
The FTC's withdrawal of this guidance removes a previously stated compliance expectation for health app and IoT device developers.
ADTP REGULATORY BRIEF
EFF files FOIA lawsuit against CMS over AI-driven Medicare WISeR program
The case raises critical AI‑governance and health‑care transparency issues for Medicare beneficiaries.
ADTP REGULATORY BRIEF
AEPD launches “Las claves de…” series on privacy and emerging neurotechnologies
The series aims to inform stakeholders about GDPR safeguards for neurodata, highlighting emerging privacy risks of brain‑related technologies.
ADTP REGULATORY BRIEF
Irish DPC welcomes court conviction of Brown Thomas for ePrivacy breaches
The enforcement action underscores the consequences of non‑compliance with ePrivacy rules for electronic marketing in Ireland.
ADTP REGULATORY BRIEF
EU Commission designates ChatGPT as VLOSE and Reddit, Roblox as VLOPs under DSA
The designations subject the three platforms to heightened DSA compliance requirements, impacting their data handling and AI governance practices.
ADTP REGULATORY BRIEF
SEC Investor Advisory Committee to Host Sept. 10 Meeting on AI Technologies and NMS Rules
The SEC is convening a meeting to examine AI’s impact on market integrity, signaling potential future regulatory focus.
ADTP REGULATORY BRIEF
Delaware Governor signs HB 380, amending the DPDPA effective Jan 1 2027
The amendment significantly strengthens privacy protections and expands data‑controller obligations in Delaware.
ADTP REGULATORY BRIEF
Data Protection Commission issues €645,000 fine and compliance orders against HSE
The enforcement action underscores GDPR accountability for health data custodians in Ireland.
ADTP REGULATORY BRIEF
CNIL agenda includes review of draft decrees on automated personal data processing and authorizations for health data studies
The agenda signals upcoming CNIL scrutiny of new automated data processing initiatives affecting law‑enforcement and health research.
ADTP REGULATORY BRIEF
Texas bans state funding for ALPRs; Florida orders removal of highway ALPRs
These executive actions curb state‑funded automated license plate reader surveillance, limiting location data collection on drivers.
ADTP REGULATORY BRIEF
AEPD to host data‑protection session at XX Jornadas STIC on 24 Nov 2026
The AEPD’s participation highlights the growing relevance of privacy and data‑protection in AI‑driven cybersecurity discussions.
ADTP REGULATORY BRIEF
Federal judge finds DoD retaliation against Anthropic unlawful under First Amendment
The ruling underscores the legal limits on government retaliation against AI companies that refuse to support mass surveillance, impacting privacy and AI governance.
ADTP REGULATORY BRIEF
Meta to implement age‑verification framework under $17 B settlement with 52 U.S. states
The settlement imposes extensive age‑verification and data‑retention obligations on Meta, affecting privacy and surveillance of all users.
ADTP REGULATORY BRIEF
Austrian Supreme Court rules CRIF’s use of address‑publisher data for credit scoring violates GDPR purpose limitation
The decision clarifies GDPR purpose‑limitation obligations for credit scoring, paving the way for a consumer class action in Austria.
ADTP REGULATORY BRIEF
California Assembly Bill 1709 passed, bans social media recommendation features for users under 16
The bill could force platforms to collect more personal data from minors while restricting their access to online speech.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.