Regulatory Pulse
Privacy and AI governance developments, explained plainly
A human-reviewed tracker of regulatory change — each entry links back to its official source, states what changed, who should care and what to do next. No speculation, no fabricated news.
Jurisdiction
Status
FDPIC orders transport operator to stop bodycam processing and delete recordings
A case-specific bodycam cessation and deletion order highlights statutory authority, recording scope and lifecycle controls.
Source: Federal Data Protection and Information Commissioner · Reviewed 4 October 2026
DPC orders paper-record and confidential-waste controls after children’s health data inquiry
A final DPC decision finds GDPR security failures in the physical handling of children’s paper health records and orders completed DPIAs, implemented controls and regulator consultation.
Source: Data Protection Commission · Reviewed 3 October 2026
FTC examines platform ad optimisation in impersonation scams
The FTC is seeking evidence on whether platform ad-optimisation tools amplify impersonation scams and what safeguards or future rules may be appropriate.
Source: US Federal Trade Commission (FTC) · Reviewed 26 September 2026
ENISA Threat Landscape 2026: supplier dependencies, ransomware and AI-enabled attacks
ENISA's 2026 threat assessment highlights ransomware impact, supplier dependencies, social engineering, vulnerabilities and AI-related exposure.
Source: European Union Agency for Cybersecurity (ENISA) · Reviewed 25 September 2026
DPC fines Google €403 million over location data: lawfulness, transparency and retention
The DPC has announced a €403 million final decision concerning Google location-data processing, with findings on lawfulness, fairness, accountability, transparency and retention.
Source: Data Protection Commission · Reviewed 24 September 2026
OPC investigates IDScan.net breach involving stolen identity-document scans
Canada’s privacy regulator is investigating safeguards and notification after a breach reportedly exposed digital scans of driver’s licences and other identification.
Source: Office of the Privacy Commissioner of Canada · Reviewed 24 September 2026
EDPB finalises DSA–GDPR guidance: moderation, ads, recommenders and minors
Final EDPB Guidelines 3/2025 explain how the DSA and GDPR apply together across moderation, complaints, advertising, recommender systems, age assurance and systemic-risk controls.
Source: European Data Protection Board · Reviewed 23 September 2026
EDPB proposes five-step test for GDPR fines and corrective measures
Draft EDPB Guidelines 04/2026 set out a five-step methodology for deciding whether a GDPR administrative fine should be imposed alone or alongside other corrective measures.
Source: European Data Protection Board · Reviewed 22 September 2026
NIST finalises token-protection guidance: securing SSO, federation and API access
Final NIST IR 8587 provides implementation guidance for protecting identity tokens, access tokens and assertions against forgery, theft and misuse across cloud, SSO, federation and API environments.
Source: National Institute of Standards and Technology (NIST), with CISA contribution · Reviewed 16 September 2026
CRA reporting is live: ENISA launches the Single Reporting Platform
Manufacturers’ Cyber Resilience Act reporting duties began on 11 September 2026, and ENISA’s Single Reporting Platform is now operational for actively exploited vulnerabilities and severe incidents.
Source: European Union Agency for Cybersecurity (ENISA) and European Commission · Reviewed 15 September 2026
Canada OPC issues vendor privacy assessment guidance: data flows, AI training and exit controls
New OPC guidance sets out a pre-contract vendor assessment model covering data maps, sensitive information, AI training data, subprocessors, security, transfers, retention, lock-in and ongoing monitoring.
Source: Office of the Privacy Commissioner of Canada · Reviewed 15 September 2026
FTC withdraws 2021 health-app breach policy—but the notification rule remains
The FTC has rescinded its 2021 health-app breach policy statement, but the binding Health Breach Notification Rule remains in force. Teams should update source registers without dismantling scope, incident-response or notice controls.
Source: United States Federal Trade Commission (FTC) · Reviewed 11 September 2026
CNIL fines hospital €500,000 after weak access controls amplified a health-data breach
The CNIL’s final decision links missing MFA and VPN protection, over-broad patient-record access, weak monitoring and incomplete breach communications to GDPR enforcement.
Source: Commission Nationale de l’Informatique et des Libertés (CNIL) · Reviewed 10 September 2026
CNIL fines EXTIA €300,000 over erasure-request failures and late responses
The final decision shows that back-end deletion does not replace the duty to respond: most 2024 erasure requests were not handled satisfactorily, and many requesters were not told the outcome.
Source: Commission Nationale de l’Informatique et des Libertés (CNIL) · Reviewed 10 September 2026
CISA, NSA and FBI warn of industrial-scale AI model distillation campaigns
A joint 8 September 2026 advisory describes coordinated extraction of frontier-model capabilities through APIs, cloud platforms, aggregators, proxy networks and account pools, and recommends detection, access, telemetry and intelligence-sharing controls.
Source: CISA, NSA and FBI · Reviewed 9 September 2026
CRA FAQ clarifies open-source steward reporting starts in December 2027
The 4 September 2026 FAQ update distinguishes stewards’ 11 December 2027 reporting start from manufacturers’ 11 September 2026 duties. This clarifies existing law; it does not extend manufacturers’ deadlines.
Source: European Commission (DG CONNECT) · Reviewed 8 September 2026
Indonesia issues PDP Law implementing regulation: operational duties from January 2027
Government Regulation No. 33 of 2026 adds operational rules for Indonesia’s PDP Law and is scheduled to take effect on 16 January 2027.
Source: Government of Indonesia · Reviewed 5 September 2026
CalPrivacy warns data brokers: incorrect registration data can trigger daily fines
CalPrivacy’s 3 September 2026 advisory says annual data-broker registrations must be true and correct, with daily fines possible while errors remain.
Source: California Privacy Protection Agency Enforcement Division · Reviewed 4 September 2026
Irish DPC fines HSE €645,000 over paper-record security, retention and breach response
The DPC’s €645,000 HSE decision links paper-record security, excessive retention, physical storage and breach response to concrete GDPR enforcement.
Source: Data Protection Commission, Ireland · Reviewed 4 September 2026
Commission designates ChatGPT, Reddit and Roblox under the DSA
The Commission’s 31 August 2026 DSA designations trigger additional systemic-risk, audit, compliance and transparency duties within four months.
Source: European Commission · Reviewed 3 September 2026
PCPD publishes agentic AI privacy guidance: permissions, memory and human oversight
New PCPD guidance connects agentic AI access, memory and action controls to existing privacy duties. Includes a practical implementation checklist and evidence register.
Source: Office of the Privacy Commissioner for Personal Data, Hong Kong · Reviewed 31 August 2026
Canada privacy regulator seeks Federal Court order on search-result de-listing
The OPC has asked the Federal Court to enforce recommendations that Google de-list specified results from name searches in a limited, harm-based case. No court order has yet been made.
Source: Office of the Privacy Commissioner of Canada · Reviewed 29 August 2026
FTC finalises ‘Active Listening’ AI marketing orders: claims, consent and vendor evidence
The FTC’s final orders turn alleged false claims about AI-powered listening, consent and local targeting into a practical test for claim substantiation and vendor evidence.
Source: Federal Trade Commission · Reviewed 28 August 2026
Canada privacy regulator urges stronger safeguards in proposed consumer-driven banking rules
The OPC supports the proposed open-banking framework but recommends clearer data scope, stronger accreditation evidence, narrower public-data reuse and sensitivity-based security.
Source: Office of the Privacy Commissioner of Canada · Reviewed 27 August 2026
OAIC expands AML/CTF privacy guidance: ID-document lifecycle tools and minimisation
Draft revision: OAIC’s 28 August update adds lifecycle tools and sharper guidance on necessity, less intrusive verification and time-limited retention of identity-document copies.
Source: Office of the Australian Information Commissioner · Reviewed 28 August 2026
FTC proposes personalized-pricing enforcement policy: disclosures, consent and data use
The FTC proposes treating undisclosed or inadequately disclosed use of personal data for personalized pricing as potentially unfair or deceptive under Section 5. The proposal is not final and does not ban personalized pricing.
Source: United States Federal Trade Commission · Reviewed 4 September 2026
UK ICO extends Children’s Code strategy: priorities for platforms, games and age assurance
The ICO extended its Children’s Code strategy for six months and highlighted compliance gaps across platforms, games, age assurance and edtech.
Source: UK Information Commissioner’s Office · Reviewed 24 August 2026
California DROP deletion processing is live: 45-day duties for data brokers
California data brokers must now retrieve and process DROP deletion requests at least every 45 days, with matching, suppression, vendor and status-reporting controls.
Source: California Privacy Protection Agency (CalPrivacy) · Reviewed 24 August 2026
EU Cyber Resilience Act guidance: what product and software teams should do now
The European Commission has published new guidance to support timely implementation of the Cyber Resilience Act (Regulation (EU) 2024/2847). It does not change the law, but it clarifies scope questions ahead of the reporting obligations that apply from 11 September 2026.
Source: European Commission (DG CONNECT) · Reviewed 24 August 2026