Activity Tracker

The DPA Activity Tracker provides our latest information on developments in legislatures, judiciaries and the executive branches of G20, EU member states and Switzerland.

197 events advancing 172 policy or regulatory changes:

Most active jurisdictions Number of policy changes

Graph

Table

Most active policy areas Number of policy changes
Targeted economic activity Number of policy changes
Reset filters
197 events advancing 172 policy or regulatory changes:
in force

SEC investigation into technological companies over alleged misleading cybersecurity disclosures

Latest event Date: 2024-10-22 investigation ruling

Issued ruling in SEC investigation into technological companies over alleged misleading cybersecurity disclosures

On 22 October 2024, the United States Securities and Exchange Commission (SEC) charged four companies, Unisys Corp., Avaya Holdings Corp., Check Point Software Technologies Ltd, and Mimecast Limited, with providing materially misleading information …

Implementer
United States of America
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity software provider: other software
concluded

European Affairs Committee inquiry on UK-EU Data Adequacy

Latest event Date: 2024-10-22 inquiry closure

Issued findings following inquiry into UK-EU Data Adequacy

On 22 October 2024, the House of Lords European Affairs Committee wrote to the Secretary of State outlining conclusions and recommendations from their inquiry into UK-EU data adequacy. The inquiry, launched in March 2024, was driven by the June 2025…

Implementer
United Kingdom
Policy area Data governance
Policy or regulatory element Cross-border data transfer regulation
Economic activity cross-cutting
adopted

CFPB Personal Financial Data Rights Rule

Latest event Date: 2024-10-22 order adoption

Adopted Final Rule on Personal Financial Data Rights by Consumer Financial Protection Bureau

On 22 October 2024, the Consumer Financial Protection Bureau (CFPB) adopted the final rule on personal financial data rights. The rule mandates financial institutions to provide consumers with their data in a secure and usable format upon request. T…

Implementer
United States of America
Policy area Data governance
Policy or regulatory element Data protection regulation
Economic activity digital payment provider (incl. cryptocurrencies), other service provider
under deliberation

FCC's Privacy and Data Protection Task Force partnerships with ten state Attorneys General

Latest event Date: 2024-10-21 outline announcement

Announced FCC’s Privacy and Data Protection Task Force partnerships with ten state Attorneys General

On 21 October 2024, the Federal Communications Commission's (FCC) Privacy and Data Protection Task Force announced partnerships with ten state Attorneys General, expanding efforts to protect consumer privacy, data, and cybersecurity. These partnersh…

Implementer
United States of America
Policy area Data governance
Policy or regulatory element Data protection authority governance
Economic activity cross-cutting
under deliberation

CISA security requirements for restricted transactions pursuant to Executive Order 14117

Latest event Date: 2024-10-21 order announcement

Announced CISA security requirements for restricted transactions pursuant to Executive Order 14117

On 21 October 2024, the Cybersecurity and Infrastructure Security Agency (CISA) published the draft security requirements for restricted transactions pursuant to Executive Order 14117. The security requirements are aimed at protecting US sensitive p…

Implementer
United States of America
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity cross-cutting
adopted

TC260 cybersecurity standards practice guidelines

Latest event Date: 2024-10-21 outline adoption

Adopted TC260 cybersecurity standards practice guidelines

On 21 October 2024, the National Information Security Standardisation Technical Committee (TC260) adopted cybersecurity standards practice guidelines. The guidelines' purpose is to regulate the drafting and management of the TC260 guidelines, which …

Implementer
China
Policy area Data governance
Policy or regulatory element Data protection authority governance
Economic activity cross-cutting, software provider: other software
adopted

OAIC guidance on privacy and the use of commercially available AI products

Latest event Date: 2024-10-21 outline adoption

Published OAIC guidance on privacy and the use of commercially available AI products

On 21 October 2024, the Office of the Australian Information Commissioner (OAIC) published guidance on privacy and the use of commercially available AI products. The guidance emphasises that organisations and government agencies must comply with pri…

Implementer
Australia
Policy area Data governance
Policy or regulatory element Data protection regulation
Economic activity ML and AI development
adopted

OAIC Guidance on Privacy and Developing and Training Generative AI Models

Latest event Date: 2024-10-21 outline adoption

Adopted Guidance on Privacy and Developing and Training Generative AI Models

On 21 October 2024, the Office of the Australian Information Commissioner issued guidance on privacy considerations for developing and training generative artificial intelligence (AI) models. The guidance outlines measures to address privacy concern…

Implementer
Australia
Policy area Data governance
Policy or regulatory element Data protection regulation
Economic activity ML and AI development
processing consultation

PIPC Guideline on Notification on the Method of Transmitting Personal Information and Designation of Personal Information Management Organizations

Latest event Date: 2024-10-21 order consultation closed

Closed consultation on PIPC Guideline on Notification on the Method of Transmitting Personal Information and Designation of Personal Information Management Organisations

On 21 October 2024, the Personal Information Protection Committee (PIPC) of Korea closed its consultation on the guidelines for the methods of transmitting personal information and the designation of specialized institutions for managing such inform…

Implementer
Republic of Korea
Policy area Data governance
Policy or regulatory element Data protection regulation
Economic activity cross-cutting
under deliberation

Justice Department Rule on Access to Americans' Bulk Sensitive Personal Data and Government-Related Data by Countries of Concern implementing EO 14117

Latest event Date: 2024-10-21 order announcement

Announced DOJ NPRM on Access to Americans’ Bulk Sensitive Personal Data and Government-Related Data by Countries of Concern

On 21 October 2024, the United States Department of Justice (DOJ) issued a Notice of Proposed Rulemaking (NPRM) concerning the Rule on Access to Americans’ Bulk Sensitive Personal Data and Government-Related Data by Countries of Concern, implementin…

Implementer
United States of America
Policy area Data governance
Policy or regulatory element Cross-border data transfer regulation
Economic activity cross-cutting
Page
1
2
...
18