Regulatory Watch
New laws, rules, guidance, enforcement actions and court decisions in privacy, AI and cybersecurity. Every item links to its primary source.
Showing 14 of 220 developments
ADTP REGULATORY BRIEF
FHFA proposes to rescind SORN FHFA-12 and consolidate records under SORN FHFA-11
The proposal changes how FHFA manages personal data in its parking program, potentially affecting record-keeping and privacy compliance.
ADTP REGULATORY BRIEF
President Trump issues executive order creating federal voter eligibility list
The order expands federal data consolidation for voter eligibility, raising significant privacy and constitutional concerns.
ADTP REGULATORY BRIEF
Italian DPA fines security firm €39,000 for employee data violations
The enforcement highlights the GDPR’s strict requirements for employee data access and transparent processing of location data.
ADTP REGULATORY BRIEF
Italian DPA fines IQVIA €7 million for unlawful processing of patients’ health data
The fine highlights enforcement of GDPR obligations for health data controllers and underscores the need for proper legal bases, transparency, and impact assessments.
ADTP REGULATORY BRIEF
Italian DPA fines Emirates €180,000 for health data infringements
The enforcement highlights GDPR obligations for clear information and proportionate retention of health data in the aviation sector.
ADTP REGULATORY BRIEF
Italian DPA fines BBVA €5.508 million for ignoring customer objection to direct marketing
The fine underscores the obligation of controllers to promptly respect data subject objections and implement effective technical measures.
ADTP REGULATORY BRIEF
Future of Privacy Forum submits comments on Vermont Age-Appropriate Design Code rulemaking
The comments aim to shape Vermont’s upcoming rules on minors’ online privacy, influencing how businesses must design and operate digital services for children.
ADTP REGULATORY BRIEF
CNIL examines draft deliberation authorizing BIG DATA SANTE to process personal data for anonymized medical research (ONCOVAL)
If approved, the authorization would enable a French company to process health‑related personal data for research, shaping data‑privacy practices in the health sector.
ADTP REGULATORY BRIEF
CNIL closes injunction against FRANCE TRAVAIL after compliance with data security measures
The closure shows that timely remediation of GDPR security deficiencies can halt additional penalties.
ADTP REGULATORY BRIEF
AEPD publishes second issue of scientific journal “Privacy, Innovation and Technology”
The publication provides expert analysis of GDPR challenges and AI governance, helping practitioners anticipate regulatory impacts of emerging technologies.
ADTP REGULATORY BRIEF
DEA proposes to modify and republish its Aviation Division system of records notice
The proposal alters how the DEA handles aviation reporting records, impacting privacy protections for individuals whose data is collected.
ADTP REGULATORY BRIEF
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The action highlights the need for data‑protection‑by‑design and proportionality when deploying AI‑driven video surveillance in the public sector.
ADTP REGULATORY BRIEF
Treasury exempts new tip intake records from certain Privacy Act provisions
The exemption limits individuals' privacy rights, such as access and correction, for data in the Treasury's fraud‑tip system.
ADTP REGULATORY BRIEF
Future of Privacy Forum urges standardized privacy benchmarks for frontier AI systems
Standardized privacy benchmarks would give concrete, comparable metrics for AI developers and deployers, supporting better privacy protection and regulatory oversight.
Source: LiveThreat Regulatory Intelligence, analysed by ADTP. Briefs summarize the linked source and are not legal advice; the linked source is the authority. Dates appear only when the source states them.