Skip to content

Regulatory Pulse

Privacy and AI governance developments, explained plainly

A human-reviewed tracker of regulatory change — each entry links back to its official source, states what changed, who should care and what to do next. No speculation, no fabricated news.

Jurisdiction

Status

Switzerland
Guidance

FDPIC orders transport operator to stop bodycam processing and delete recordings

A case-specific bodycam cessation and deletion order highlights statutory authority, recording scope and lifecycle controls.

Source: Federal Data Protection and Information Commissioner · Reviewed 4 October 2026

Ireland / European Union
Guidance

DPC orders paper-record and confidential-waste controls after children’s health data inquiry

A final DPC decision finds GDPR security failures in the physical handling of children’s paper health records and orders completed DPIAs, implemented controls and regulator consultation.

Source: Data Protection Commission · Reviewed 3 October 2026

United States
Guidance

FTC examines platform ad optimisation in impersonation scams

The FTC is seeking evidence on whether platform ad-optimisation tools amplify impersonation scams and what safeguards or future rules may be appropriate.

Source: US Federal Trade Commission (FTC) · Reviewed 26 September 2026

European Union
Guidance

ENISA Threat Landscape 2026: supplier dependencies, ransomware and AI-enabled attacks

ENISA's 2026 threat assessment highlights ransomware impact, supplier dependencies, social engineering, vulnerabilities and AI-related exposure.

Source: European Union Agency for Cybersecurity (ENISA) · Reviewed 25 September 2026

Ireland and European Union
Guidance

DPC fines Google €403 million over location data: lawfulness, transparency and retention

The DPC has announced a €403 million final decision concerning Google location-data processing, with findings on lawfulness, fairness, accountability, transparency and retention.

Source: Data Protection Commission · Reviewed 24 September 2026

Canada
Guidance

OPC investigates IDScan.net breach involving stolen identity-document scans

Canada’s privacy regulator is investigating safeguards and notification after a breach reportedly exposed digital scans of driver’s licences and other identification.

Source: Office of the Privacy Commissioner of Canada · Reviewed 24 September 2026

European Union
Guidance

EDPB finalises DSA–GDPR guidance: moderation, ads, recommenders and minors

Final EDPB Guidelines 3/2025 explain how the DSA and GDPR apply together across moderation, complaints, advertising, recommender systems, age assurance and systemic-risk controls.

Source: European Data Protection Board · Reviewed 23 September 2026

European Union
Guidance

EDPB proposes five-step test for GDPR fines and corrective measures

Draft EDPB Guidelines 04/2026 set out a five-step methodology for deciding whether a GDPR administrative fine should be imposed alone or alongside other corrective measures.

Source: European Data Protection Board · Reviewed 22 September 2026

United States
Guidance

NIST finalises token-protection guidance: securing SSO, federation and API access

Final NIST IR 8587 provides implementation guidance for protecting identity tokens, access tokens and assertions against forgery, theft and misuse across cloud, SSO, federation and API environments.

Source: National Institute of Standards and Technology (NIST), with CISA contribution · Reviewed 16 September 2026

European Union
Guidance

CRA reporting is live: ENISA launches the Single Reporting Platform

Manufacturers’ Cyber Resilience Act reporting duties began on 11 September 2026, and ENISA’s Single Reporting Platform is now operational for actively exploited vulnerabilities and severe incidents.

Source: European Union Agency for Cybersecurity (ENISA) and European Commission · Reviewed 15 September 2026

Canada
Guidance

Canada OPC issues vendor privacy assessment guidance: data flows, AI training and exit controls

New OPC guidance sets out a pre-contract vendor assessment model covering data maps, sensitive information, AI training data, subprocessors, security, transfers, retention, lock-in and ongoing monitoring.

Source: Office of the Privacy Commissioner of Canada · Reviewed 15 September 2026

United States
Guidance

FTC withdraws 2021 health-app breach policy—but the notification rule remains

The FTC has rescinded its 2021 health-app breach policy statement, but the binding Health Breach Notification Rule remains in force. Teams should update source registers without dismantling scope, incident-response or notice controls.

Source: United States Federal Trade Commission (FTC) · Reviewed 11 September 2026

France and European Union
Guidance

CNIL fines hospital €500,000 after weak access controls amplified a health-data breach

The CNIL’s final decision links missing MFA and VPN protection, over-broad patient-record access, weak monitoring and incomplete breach communications to GDPR enforcement.

Source: Commission Nationale de l’Informatique et des Libertés (CNIL) · Reviewed 10 September 2026

France and European Union
Guidance

CNIL fines EXTIA €300,000 over erasure-request failures and late responses

The final decision shows that back-end deletion does not replace the duty to respond: most 2024 erasure requests were not handled satisfactorily, and many requesters were not told the outcome.

Source: Commission Nationale de l’Informatique et des Libertés (CNIL) · Reviewed 10 September 2026

United States / global AI ecosystem
Guidance

CISA, NSA and FBI warn of industrial-scale AI model distillation campaigns

A joint 8 September 2026 advisory describes coordinated extraction of frontier-model capabilities through APIs, cloud platforms, aggregators, proxy networks and account pools, and recommends detection, access, telemetry and intelligence-sharing controls.

Source: CISA, NSA and FBI · Reviewed 9 September 2026

European Union
Guidance

CRA FAQ clarifies open-source steward reporting starts in December 2027

The 4 September 2026 FAQ update distinguishes stewards’ 11 December 2027 reporting start from manufacturers’ 11 September 2026 duties. This clarifies existing law; it does not extend manufacturers’ deadlines.

Source: European Commission (DG CONNECT) · Reviewed 8 September 2026

Indonesia
Guidance

Indonesia issues PDP Law implementing regulation: operational duties from January 2027

Government Regulation No. 33 of 2026 adds operational rules for Indonesia’s PDP Law and is scheduled to take effect on 16 January 2027.

Source: Government of Indonesia · Reviewed 5 September 2026

California, United States
Guidance

CalPrivacy warns data brokers: incorrect registration data can trigger daily fines

CalPrivacy’s 3 September 2026 advisory says annual data-broker registrations must be true and correct, with daily fines possible while errors remain.

Source: California Privacy Protection Agency Enforcement Division · Reviewed 4 September 2026

Ireland and European Union
Guidance

Irish DPC fines HSE €645,000 over paper-record security, retention and breach response

The DPC’s €645,000 HSE decision links paper-record security, excessive retention, physical storage and breach response to concrete GDPR enforcement.

Source: Data Protection Commission, Ireland · Reviewed 4 September 2026

European Union
Guidance

Commission designates ChatGPT, Reddit and Roblox under the DSA

The Commission’s 31 August 2026 DSA designations trigger additional systemic-risk, audit, compliance and transparency duties within four months.

Source: European Commission · Reviewed 3 September 2026

Hong Kong
Guidance

PCPD publishes agentic AI privacy guidance: permissions, memory and human oversight

New PCPD guidance connects agentic AI access, memory and action controls to existing privacy duties. Includes a practical implementation checklist and evidence register.

Source: Office of the Privacy Commissioner for Personal Data, Hong Kong · Reviewed 31 August 2026

Canada
Guidance

Canada privacy regulator seeks Federal Court order on search-result de-listing

The OPC has asked the Federal Court to enforce recommendations that Google de-list specified results from name searches in a limited, harm-based case. No court order has yet been made.

Source: Office of the Privacy Commissioner of Canada · Reviewed 29 August 2026

United States
Guidance

FTC finalises ‘Active Listening’ AI marketing orders: claims, consent and vendor evidence

The FTC’s final orders turn alleged false claims about AI-powered listening, consent and local targeting into a practical test for claim substantiation and vendor evidence.

Source: Federal Trade Commission · Reviewed 28 August 2026

Canada
Guidance

Canada privacy regulator urges stronger safeguards in proposed consumer-driven banking rules

The OPC supports the proposed open-banking framework but recommends clearer data scope, stronger accreditation evidence, narrower public-data reuse and sensitivity-based security.

Source: Office of the Privacy Commissioner of Canada · Reviewed 27 August 2026

Australia
Guidance

OAIC expands AML/CTF privacy guidance: ID-document lifecycle tools and minimisation

Draft revision: OAIC’s 28 August update adds lifecycle tools and sharper guidance on necessity, less intrusive verification and time-limited retention of identity-document copies.

Source: Office of the Australian Information Commissioner · Reviewed 28 August 2026

United States
Guidance

FTC proposes personalized-pricing enforcement policy: disclosures, consent and data use

The FTC proposes treating undisclosed or inadequately disclosed use of personal data for personalized pricing as potentially unfair or deceptive under Section 5. The proposal is not final and does not ban personalized pricing.

Source: United States Federal Trade Commission · Reviewed 4 September 2026

United Kingdom
Guidance

UK ICO extends Children’s Code strategy: priorities for platforms, games and age assurance

The ICO extended its Children’s Code strategy for six months and highlighted compliance gaps across platforms, games, age assurance and edtech.

Source: UK Information Commissioner’s Office · Reviewed 24 August 2026

United States — California
Guidance

California DROP deletion processing is live: 45-day duties for data brokers

California data brokers must now retrieve and process DROP deletion requests at least every 45 days, with matching, suppression, vendor and status-reporting controls.

Source: California Privacy Protection Agency (CalPrivacy) · Reviewed 24 August 2026

European Union
Guidance

EU Cyber Resilience Act guidance: what product and software teams should do now

The European Commission has published new guidance to support timely implementation of the Cyber Resilience Act (Regulation (EU) 2024/2847). It does not change the law, but it clarifies scope questions ahead of the reporting obligations that apply from 11 September 2026.

Source: European Commission (DG CONNECT) · Reviewed 24 August 2026