Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 13 of 220 developments
ADTP REGULATORY BRIEF
California Privacy Protection Agency adopts multiple regulations including Conflict of Interest Code Amendments and Data Broker Registration Fee
Adopted CPPA regulations expand enforcement tools for the CCPA and Delete Act, affecting data brokers and other entities.
ADTP REGULATORY BRIEF
Data Protection Commission releases AI Insights Report covering 2021‑2025 supervision
The DPC’s AI Insights Report offers regulators and controllers practical guidance on compliant AI development and deployment.
ADTP REGULATORY BRIEF
State bills propose exemption for biometric data converted to irreversible mathematical representations
The trend could reshape biometric privacy safeguards by carving out a carve‑out for transformed biometric data.
ADTP REGULATORY BRIEF
Supreme Court hears digital‑privacy case involving Paramount and targeted advertising
The outcome may define whether online video platforms must use privacy‑preserving methods instead of targeted advertising.
ADTP REGULATORY BRIEF
Spanish Data Protection Agency issues warning to company over AI-driven resume screening
The AEPD’s warning highlights GDPR compliance requirements for AI use in recruitment, emphasizing transparency, human control, and risk assessment.
ADTP REGULATORY BRIEF
Spanish DPA fines Securitas Direct €100,000 for charging phone line for data subject rights
The enforcement underscores that charging fees for exercising GDPR data subject rights is prohibited.
ADTP REGULATORY BRIEF
EU proposes Article 88c/88bis to allow unrestricted AI use of personal data
If adopted, the proposal would dramatically weaken EU data‑protection rights by granting AI firms blanket access to personal data.
ADTP REGULATORY BRIEF
Kenya publishes new guidance on cross‑border data transfers
The guidance signals stricter requirements for international data flows from Kenya, affecting multinational organisations’ transfer mechanisms and compliance programs.
ADTP REGULATORY BRIEF
California AB 1709, a ban on social media for under‑16, signed into law
The law restricts minors' access to social media and raises privacy and free‑speech concerns.
ADTP REGULATORY BRIEF
CNIL guidance on data‑protection obligations under the electronic invoicing reform effective 1 Sept 2026
Practitioners must align invoicing processes with GDPR, ISO‑27001, and eIDAS‑level authentication to avoid breaches and ensure lawful handling of personal data.
ADTP REGULATORY BRIEF
CNIL releases Volume 2 of “L’Agence Privacy” to educate adolescents on cybercrime and data privacy
The publication provides a new pedagogical tool to improve privacy awareness among minors.
ADTP REGULATORY BRIEF
AEPD opens investigation into Ministry of Interior report listing journalists and political leanings
The investigation could impact how government bodies handle journalists' personal and political data under GDPR.
ADTP REGULATORY BRIEF
EFF releases 1,000 pages of CMS records on AI-driven Medicare WISeR prior‑authorization program
The disclosure highlights how an AI‑driven Medicare prior‑authorization system may compromise patient access and raise privacy and bias concerns.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.