Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 24 of 214 developments
ADTP REGULATORY BRIEF
Italian DPA fines security firm €39,000 for employee data violations
The enforcement highlights the GDPR’s strict requirements for employee data access and transparent processing of location data.
ADTP REGULATORY BRIEF
CNIL hosts 2nd Rencontres Informatique & Libertés on connected glasses and data‑sanctions
The conference highlights emerging privacy challenges of wearable tech and the increasing enforcement activity of the CNIL.
ADTP REGULATORY BRIEF
Italian DPA fines IQVIA €7 million for unlawful processing of patients’ health data
The fine highlights enforcement of GDPR obligations for health data controllers and underscores the need for proper legal bases, transparency, and impact assessments.
ADTP REGULATORY BRIEF
Italian DPA fines Emirates €180,000 for health data infringements
The enforcement highlights GDPR obligations for clear information and proportionate retention of health data in the aviation sector.
ADTP REGULATORY BRIEF
Italian DPA fines BBVA €5.508 million for ignoring customer objection to direct marketing
The fine underscores the obligation of controllers to promptly respect data subject objections and implement effective technical measures.
ADTP REGULATORY BRIEF
Commission holds special meeting of Scientific Panel on frontier AI safety and risks
The meeting signals EU commitment to strengthen AI governance through scientific input on systemic risk.
ADTP REGULATORY BRIEF
CISA submits Final CIRCIA Rule to OIRA for interagency review
The rule will impose rapid cyber‑incident reporting obligations on critical‑infrastructure operators, shaping their security and compliance programs.
ADTP REGULATORY BRIEF
EFF warns age‑verification laws risk excluding people without ID
Age‑verification regimes may protect children but also threaten equal access to information and privacy for people without ID.
ADTP REGULATORY BRIEF
Future of Privacy Forum submits comments on Vermont Age-Appropriate Design Code rulemaking
The comments aim to shape Vermont’s upcoming rules on minors’ online privacy, influencing how businesses must design and operate digital services for children.
ADTP REGULATORY BRIEF
CNIL examines draft deliberation authorizing BIG DATA SANTE to process personal data for anonymized medical research (ONCOVAL)
If approved, the authorization would enable a French company to process health‑related personal data for research, shaping data‑privacy practices in the health sector.
ADTP REGULATORY BRIEF
Dutch DPA fines Uber €824.99 million for unlawful automated decision‑making
The fine demonstrates robust GDPR enforcement on automated decision‑making in the gig‑economy.
ADTP REGULATORY BRIEF
Swedish DPA fines Miljödata approx EUR 160,000 for insufficient security measures
The fine underscores the enforcement of GDPR security obligations for data processors handling large volumes of personal and sensitive data.
ADTP REGULATORY BRIEF
Hellenic DPA fines Ministry and EETAA for data breach
The enforcement action highlights the liability of both controllers and processors for inadequate security and non‑compliant processing agreements under the GDPR.
ADTP REGULATORY BRIEF
CNIL closes injunction against FRANCE TRAVAIL after compliance with data security measures
The closure shows that timely remediation of GDPR security deficiencies can halt additional penalties.
ADTP REGULATORY BRIEF
AEPD publishes second issue of scientific journal “Privacy, Innovation and Technology”
The publication provides expert analysis of GDPR challenges and AI governance, helping practitioners anticipate regulatory impacts of emerging technologies.
ADTP REGULATORY BRIEF
Treasury proposes new system of records for federal student aid data
The proposal creates a Treasury‑run record system that will collect and analyze student aid data, raising privacy considerations for the handling of personal and financial information.
ADTP REGULATORY BRIEF
DEA proposes to modify and republish its Aviation Division system of records notice
The proposal alters how the DEA handles aviation reporting records, impacting privacy protections for individuals whose data is collected.
ADTP REGULATORY BRIEF
DOJ proposes exemption for Firearms Rights Restoration Electronic Records Database from Privacy Act provisions
The proposal could limit individuals' access to their own records by creating a privacy Act exemption for a law‑enforcement database.
ADTP REGULATORY BRIEF
California Governor signs over 20 AI‑related bills into law
The new statutes impose broad AI transparency and safety obligations on providers, platforms, attorneys, and healthcare entities in California.
ADTP REGULATORY BRIEF
Commission registers European Citizens' Initiative for sovereign European AI domains
The registration signals a potential push for new EU AI governance measures driven by citizen input.
ADTP REGULATORY BRIEF
Texas AG launches investigation into children's clothing companies over toxic chemicals
The action targets possible chemical hazards in children’s apparel, highlighting consumer‑health risks and corporate accountability.
ADTP REGULATORY BRIEF
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The action highlights the need for data‑protection‑by‑design and proportionality when deploying AI‑driven video surveillance in the public sector.
ADTP REGULATORY BRIEF
NARA proposes revisions to System of Records NARA 44 for reasonable accommodation requests
The proposal expands collection of sensitive health information and introduces digital processing, impacting privacy and data‑handling obligations.
ADTP REGULATORY BRIEF
Treasury exempts new tip intake records from certain Privacy Act provisions
The exemption limits individuals' privacy rights, such as access and correction, for data in the Treasury's fraud‑tip system.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.