Regulatory tracker

What organisations are now required to do about security and personal data, when each obligation starts, and what has happened to the ones that did not. Every entry is the issuing body’s own publication, linked to the original.

1
Deadlines ahead
2
Rules tracked
2
Enforcement actions
3
Guidance

What is coming

RuleUS2026-09-11Rule

Protecting Against National Security Threats to the Communications Supply Chain Through the Equipment Authorization Program

In this document, the Federal Communications Commission (Commission or FCC) takes further steps to strengthen its equipment authorization program against national security risks to the communications supply chain. The Commission closes a component-part loophole by prohibiting authorization of devices that incorporate logic-bearing hardware components produced by an entity identified on the Commission's Covered List, where the device would itself be prohibited from authorization had the Covered List entity produced the entire device. The Commission also requires that any modification or permissive change to equipment by an entity identified on the Covered List undergo full certification, clarifies that its marketing rules reach any entity (including online marketplaces) that markets unauthorized equipment, and requires online marketplaces, subject to limited exceptions, to display a device's FCC ID at the online point of sale. Finally, the Commission amends its definition of "critical infrastructure," as used on the Covered List, and corrects two administrative errors in its rules.

Federal Communications CommissionEffective 2026-10-13
EnforcementEU2026-09-03

Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE)

Background information Date of final decision: 28 August 2026 National case Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 32 (Security of processing), Article 33 (Notification of a personal data breach to the supervisory authority), Article 34 (Communication of a personal data breach to the data subject) Decision: Administrative fine, Compliance order, Communication order personal data breach Key words: GDPR enforcement, Data subjects rights, Fines, Health and research Summary of the Decision Origin of the case This Inquiry commenced on 24 May 2024 as a result of two personal data breaches notified to the Data Protection Commission (DPC) in October 2023 and November 2023. In both cases, individuals gained unauthorised access to paper records stored and retained in both St. Loman’s Hospital (Mullingar, County Westmeath) and St Conal’s Hospital (Letterkenny, County Donegal). Both locations are former disused psychiatric hospitals.Videos uploaded to social media by intruders highlighted that medical records were stored and retained in both facilities. Key Findings The Data Protection Commission (DPC) has announced its final decision

European Data Protection BoardGDPR
RuleUS2026-09-03

FTC Extends Public Comment on Proposed Policy Statement Regarding Personalized Pricing

The Federal Trade Commission extended by seven days the public comment period on the proposed enforcement policy statement regarding personalized pricing . The new deadline to submit comments is Sept. 25, 2026. On Aug. 19, 2026, the Commission invited the public to submit comments electronically until Sept. 18, 2026 on the proposed policy statement related to personalized pricing. Personalized pricing refers to the use of personal data to set prices according to the amount that a company believes an individual consumer is willing to spend.

US Federal Trade Commission
RuleUS2026-08-19

FTC Seeks Comment on Enforcement Policy Statement Regarding Personalized Pricing

This release was updated on August 31, 2026 at 2:40 PM to correct an earlier error. The Federal Trade Commission today announced it is seeking public comment on an enforcement policy statement regarding personalized pricing, which is the use of personal data to set prices according to the amount that a company believes an individual consumer is willing to spend. “When consumers see a listed price, they expect it to be same price that everyone else sees, not the retailer’s estimate of how much they are willing to pay based on their personal data,” said FTC Chairman Andrew Ferguson. “The FTC does not have the legal authority to ban personalized pricing in all circumstances, but businesses that fail to tell consumers how their personal data is being used to set a price may be in violation of the FTC Act and other laws we enforce. We are seeking public input on this draft statement, which would put businesses engaged in or considering personalized pricing on notice that the Trump-Vance FTC will not hesitate to enforce the law in this space.” This is the latest in a series of actions by the Commission, under President Donald Trump’s leadership, against businesses that mislead consumers

US Federal Trade Commission
GuidanceEU2026-07-30

Stakeholder event on guidelines on the interplay between data protection and competition law: overview of topics available

Brussels, 30 July – The EDPB and the European Commission organise a remote stakeholder event in the context of their joint work on upcoming guidelines on the interplay between competition and data protection . The event will take place on 15 October 2026 and is an opportunity for stakeholders to inform and support the ongoing work on this topic. The event reflects the EDPB’s commitment to stakeholder engagement and cross-regulatory cooperation, as outlined in the Helsinki statement and in the EDPB Strategy 2024-2027 . Who can participate? The EDPB and the European Commission welcome participation from individuals and organisations with relevant expertise in the topic of the event. How to take part? The call is now closed. Overview of key topics Please find here the overview of topics and questions for the EDPB–EC Stakeholder Event on GDPR & Competition Law . Further background reading Position paper on Interplay between data protection and competition law OECD - The intersection between competition and data privacy (this document has not been produced by the EDPB)

European Data Protection BoardGDPR
RuleUS2026-07-16Proposed Rule

Request for Information; Clinical Laboratory Improvement Amendments of 1988 (CLIA) Regulations

Clinical laboratory testing technology has advanced significantly since the Clinical Laboratory Improvement Amendments of 1988 (CLIA) regulations were implemented in 1992. This request for information (RFI) seeks input from the public regarding various topics related to the CLIA regulations, including: breath testing; laboratory processes and procedures; emergency preparedness, biosafety and biosecurity, and cybersecurity; and specialty testing areas. Responses to this RFI may be used to help inform CMS and the CDC as to what types of action, if any, should be taken to update the existing CLIA regulations through future notice and comment rulemaking.

Health and Human Services DepartmentComments close 2026-09-14
RuleEU2026-07-08

EDPB sheds light on anonymisation and web scraping for generative AI and adopts final version of guidelines on blockchain

Brussels, 8 July– During its latest plenary, the EDPB has adopted guidelines on anonymisation and guidelines on web scraping in the context of generative AI. In addition, the Board has adopted the final version of its guidelines on the processing of personal data through blockchain technologies. Understanding anonymous data The new EDPB guidelines bring clarity to the notion of anonymous data , taking also into account the ruling of the Court of Justice of the EU in the case C-413/23 P EDPS v SRB of 4 September 2025 and other CJEU jurisprudence. The guidelines mark a significant milestone in clarifying the notion of anonymous data, establishing clear standards that facilitate the use of data while protecting individuals' fundamental rights. In developing these guidelines, we incorporated valuable input from our stakeholder event, showing, once more, our strong commitment to collaborative dialogue as outlined in the EDPB Helsinki statement. EDPB Chair, Anu Talus Data is anonymous if it does not relate to an identified or identifiable natural person. Whether this is the case may vary from one entity to another. Information can relate to an individual because of its content, purpose,

European Data Protection Board
RuleUS2026-07-06Rule

Counter-UAS Authority for State, Local, Tribal, and Territorial Law Enforcement and Correctional Agencies

In this interim final rule ("IFR"), the Department of Justice ("DOJ") and the Department of Homeland Security ("DHS") (collectively, "the Departments") codify the framework for implementing the SAFER SKIES Act, which authorizes State, local, Tribal, and territorial law enforcement or correctional ("SLTT") agencies to conduct counter-unmanned aircraft system ("C-UAS") operations. This framework governs training and certification (including a two-tiered structure for detection and warning operations and for mitigation operations), authorized technologies, spectrum coordination, airspace approval, real-time air traffic control notification, mitigation reporting, privacy protections, and compliance requirements for SLTT agencies in relation to the exercise of C-UAS authority.

Homeland Security DepartmentEffective 2026-07-01
GuidanceEU2026-07-01

EDPB and AMLA to develop Joint Guidelines on partnerships for information sharing

Brussels/Frankfurt, 1 July – The EDPB and the Anti-Money Laundering Authority (AMLA) are working together to bring greater clarity to a question of growing importance for industry and authorities alike: how to share information to fight financial crime while protecting personal data. Why information sharing matters The fight against financial crime depends on cooperation, and information sharing can help detect and prevent money laundering and terrorist financing. Art. 75 of the AML Regulation makes this possible, allowing companies and professionals covered by anti-money laundering rules to share information with each other and with public authorities, within clear limits. The new information sharing possibility will apply from 10 July 2027. To provide clarity on this possibility, the EDPB and AMLA will work together on the development of Joint Guidelines. Clearer rules for industry and authorities Sharing information of this kind means processing personal data, which is why data protection safeguards are essential. The Joint Guidelines, developed by the EDPB and AMLA, will set out in practical terms how partnerships can be built so that effective information sharing and th

European Data Protection Board
EnforcementUS2026-06-30$2.25m

FTC Requires Amazon to Pay $2.25 Million to Resolve Charges It Knowingly Violated the Fair Credit Reporting Act

Amazon will pay $2.25 million in civil penalties to settle Federal Trade Commission allegations that the online retail giant knowingly violated the Fair Credit Reporting Act (FCRA) by refusing to provide transaction records to consumers whose personal information was used by identity thieves to commit fraud. The complaint , filed by the Department of Justice upon notification and referral from the FTC, alleged that in numerous instances, Amazon.com Inc. failed to comply with Section 609(e) of the FCRA, which requires companies to, within 30 days of a consumer’s request, provide victims of identity theft with application and business transaction records about fraudulent transactions made in their names. According to the complaint, Amazon had no written policy to respond to Section 609(e) requests until early 2025, after it learned of the FTC’s investigation, despite prior outreach from FTC staff advising the company to review its compliance with Section 609(e). “Amazon often put identity theft victims through a Kafkaesque ordeal by demanding they identify the thief who stole their information before Amazon would release the records the law entitles them to—records that could help vi

US Federal Trade Commission
RuleUS2026-04-23Proposed Rule

Improving Customer Service and Protecting Consumers Through Onshoring

In this document, the Federal Communications Commission (Commission) proposes actions that would encourage and facilitate the onshoring of foreign call centers. Specifically, the Commission proposes rules and otherwise explore ways to improve customer service communications and better protect consumers' sensitive personal information by limiting use of foreign call centers and by improving standards applicable to a company's remaining foreign call center operations. It also seeks comment on extending these protections to modes of customer service communications other than calls, such as emails, texts, and on-line chats, and on ideas to deter scam and other unlawful calls made to the United States from foreign countries. Finally, it explore steps we can take to financially deter unlawful foreign-originated calls, such as bond requirements. The Commission proposes to apply these requirements to providers of telecommunications services, CMRS, interconnected VoIP service, cable television service, and DBS services, or affiliates of such providers. It also proposes to apply these requirements to the use of foreign call centers for consumer communications relating to internet access service offered by any of the foregoing providers or their affiliates and seeks comment on whether it should extend some or all of the proposed rules to providers of other types of services.

Federal Communications CommissionComments close 2026-05-26
RuleUS2026-04-20Proposed Rule

Concept Release on Consolidated Audit Trail and Other Audit Trails and Data Sources

The Securities and Exchange Commission (the "Commission") is publishing this concept release to solicit comments in support of a comprehensive review of the Consolidated Audit Trail and other audit trails and related data sources currently used in the regulation of U.S. securities markets, including comments regarding the funding mechanisms for these audit trails and/or related data sources. There have been several developments since the Commission last evaluated the scope and sufficiency of these audit trails and related data sources. These developments have prompted the Commission to consider whether changes should be made to the rules and regulations governing existing audit trails and related data sources to better respond to and reflect current market conditions; demonstrated regulatory needs; civil liberty, privacy, and confidentiality concerns; cost-efficient technology solutions; and cybersecurity considerations.

Securities and Exchange CommissionComments close 2026-06-22

Sources: the US Federal Register, the Securities and Exchange Commission, the Federal Trade Commission, the European Data Protection Board and the UK National Cyber Security Centre. Dates are as published and are shown in UTC. This is a tracker, not legal advice, and an obligation that applies to you is a question for your own counsel.