Activity Tracker

The DPA Activity Tracker provides our latest information on developments in legislatures, judiciaries and the executive branches of G20, EU member states and Switzerland.

81 events advancing 80 policy or regulatory changes:

Most active jurisdictions Number of policy changes

Graph

Table

Most active policy areas Number of policy changes
Targeted economic activity Number of policy changes
Reset filters
81 events advancing 80 policy or regulatory changes:
in force

Personal Information Protection Commission investigation into 2K Games' compliance with Personal Information Protection Act's security obligations

Latest event Date: 2025-12-11 investigation ruling

Personal Information Protection Commission fined 2K Games KRW 217.1 million for noncompliance with security obligations

On 11 December 2025, the Personal Information Protection Commission (PIPC) fined 2K Games KRW 217.1 million for a personal information breach affecting approximately 12,906 domestic users. The breach, discovered around 28 September 2022, occurred af…

Implementer
Republic of Korea
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity software provider: other software
in consultation

Implementing regulation on establishment and operation of the European Health Data Space Board

Latest event Date: 2025-12-09 order consultation opened

European Commission opened consultation on draft implementing regulation on establishment and operation of the European Health Data Space Board

On 9 December 2025, the European Commission opened a consultation on a draft implementing regulation for the establishment and operation of the European Health Data Space Board (EHDS Board) until 6 January 2026. The draft regulation outlines the nec…

Implementer
European Union
Policy area Data governance
Policy or regulatory element Data protection authority governance
Economic activity cross-cutting
in consultation

Federal Trade Commission investigation into Illuminate Education over failure to secure students' personal data

Latest event Date: 2025-12-04 investigation consultation opened

Federal Trade Commission opened consultation on proposed consent order for Illuminate Education over failure to secure students' personal data

On 4 December 2025, the Federal Trade Commission (FTC) opened a consultation on its proposed consent order against educational technology provider Illuminate Education until 5 January 2026. The FTC alleged that Illuminate Education failed to take ap…

Implementer
United States of America
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity other service provider
adopted

TC260 Standard Data Security Technology - Security Requirements for Data Transaction Services (GB/T 37932-2025)

Latest event Date: 2025-12-02 order adoption

National Information Security Standardisation Technical Committee adopted standard on security requirements for data transaction services

On 2 December 2025, the National Information Security Standardisation Technical Committee (TC260) adopted the Standard Data Security Technology-Security Requirements for Data Transaction Services (GB/T 37932-2025). The standard sets out security req…

Implementer
China
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity cross-cutting
adopted

TC260 Standard Information Technology Security Technology - Cybersecurity Part 7: Network Virtualization Security (GB/T 25068.7-2025)

Latest event Date: 2025-12-02 order adoption

National Information Security Standardisation Technical Committee adopted standard cybersecurity part 7: network virtualization security

On 2 December 2025, the National Information Security Standardisation Technical Committee (TC260) adopted the Standard Information Technology Security Technology - Cybersecurity Part 7: Network Virtualization Security (GB/T 25068.7-2025). The standa…

Implementer
China
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity cross-cutting
adopted

TC260 Standard Information Technology Security Technology - Network Security Part 6: Wireless Network Access Security (GB/T 25068.6-2025)

Latest event Date: 2025-12-02 order adoption

National Information Security Standardisation Technical Committee adopted standard on network security part 6: wireless network access security

On 2 December 2025, the National Information Security Standardisation Technical Committee (TC260) adopted the Standard Information Technology Security Technology - Network Security Part 6: Wireless Network Access Security (GB/T 25068.6-2025). The st…

Implementer
China
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity cross-cutting
adopted

TC260 Standard Network Security Technology - Network Security Test Platform Architecture (GB/T 46820-2025)

Latest event Date: 2025-12-02 order adoption

National Information Security Standardisation Technical Committee adopted standard on network security test platform architecture

On 2 December 2025, the National Information Security Standardisation Technical Committee (TC260) adopted the Standard Network Security Technology - Network Security Test Platform Architecture (GB/T 46820-2025). The standard sets out the system arch…

Implementer
China
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity cross-cutting
adopted

TC260 standard data interface security risk monitoring methods (GB/T 46796-2025)

Latest event Date: 2025-12-02 order adoption

National Information Security Standardisation Technical Committee adopted standard data interface security risk monitoring methods

On 2 December 2025, the National Information Security Standardisation Technical Committee (TC260) adopted the standard data interface security risk monitoring methods (GB/T 46796-2025). The standard sets out security risk monitoring methods in relat…

Implementer
China
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity cross-cutting
adopted

TC260 standard cybersecurity product interconnectivity -part 3: alarm information format (GB/T 44886.3-2025)

Latest event Date: 2025-12-02 order adoption

National Information Security Standardisation Technical Committee adopted standard cybersecurity product interconnectivity -part 3: alarm information format

On 2 December 2025, the National Information Security Standardisation Technical Committee (TC260) adopted the standard cybersecurity product interconnectivity-part 3: alarm information format (GB/T 44886.3-2025). The standard applies to interconnect…

Implementer
China
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity software provider: other software
in grace period

Cybersecurity regulation in Protection of Critical Infrastructures (Computer Systems) Ordinance (Ordinance No. 4 of 2025)

Latest event Date: 2025-03-28 law in force with grace period

Legislative Council's Protection of Critical Infrastructures (Computer Systems) Ordinance including cybersecurity regulation entered into force with grace period

On 28 March 2025, the Legislative Council's Protection of Critical Infrastructures (Computer Systems) Ordinance (Ordinance No. 4 of 2025) including cybersecurity regulation entered into force with a grace period. With its publication in the gazette,…

Implementer
Hong Kong
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity infrastructure provider: internet and telecom services, infrastructure provider: cloud computing, storage and databases, infrastructure provider: network hardware and equipment, infrastructure provider: other
Page
1
2
...
8