Activity Tracker

The DPA Activity Tracker provides our latest information on developments in legislatures, judiciaries and the executive branches of G20, EU member states and Switzerland.

355 events advancing 309 policy or regulatory changes:

Most active jurisdictions Number of policy changes

Graph

Table

Most active policy areas Number of policy changes
Targeted economic activity Number of policy changes
Reset filters
355 events advancing 309 policy or regulatory changes:
revoked

Regulation extending derogation from the ePrivacy Directive to support the detection of child sexual abuse

Latest event Date: 2026-04-03 law implementation

Terminated Regulation on Extension of Derogation from the ePrivacy Directive to support the detection of child sexual abuse

On 3 April 2026, the Regulation on the Extension of Derogation from the ePrivacy Directive for the purpose of identifying Child Sexual Abuse Material (CSAM) online expires. The extension concerns an exemption from data protection regulations, which …

Implementer
European Union
Policy area Data governance
Policy or regulatory element Data protection regulation
Economic activity cross-cutting
revoked

Derogation of ePrivacy Directive to fight child sexual abuse

Latest event Date: 2026-04-03 law termination

Applicability of the Derogation from ePrivacy Directive to support the detection of child sexual abuse ends

On 3 April 2026, the applicability of the Derogation from the ePrivacy Directive supporting the detection of child sexual abuse ends. The derogation was extended by Regulation (EU) 2024/1307. The extension allows providers of number-independent inte…

Implementer
European Union
Policy area Data governance
Policy or regulatory element Data protection regulation
Economic activity cross-cutting
adopted

Data Protection Commission's assessment of compliance with compliance audit returns under Data Protection Act

Latest event Date: 2026-04-01 order adoption

Data Protection Commission extended deadline for compliance audit returns under Data Protection Act

On 1 April 2026, the Nigeria Data Protection Commission (NDPC) extended the filing deadline for the data protection compliance audit by 60 days. The extension applies to all data controllers and processors of major importance who are required to sub…

Implementer
Nigeria
Policy area Data governance
Policy or regulatory element Data protection regulation
Economic activity cross-cutting
in force

Consumer Financial Protection Bureau Personal Financial Data Rights Rule

Latest event Date: 2026-04-01 order implementation

Implemented obligations for depository institutions with at least USD 250 billion in total assets outlined in Rule on Personal Financial Data Rights

On 1 April 2026, the final rule on personal financial data rights came into force for depository institutions with at least USD 250 billion in total assets and non-depository institutions with at least USD 10 billion in revenue. The rule mandates fi…

Implementer
United States of America
Policy area Data governance
Policy or regulatory element Data protection regulation
Economic activity digital payment provider (incl. cryptocurrencies), other service provider
adopted

Guidance on use of cookies and similar online tracking technologies

Latest event Date: 2026-03-31 outline adoption

Federal Data Protection and Information Commissioner published guidance on use of cookies and similar online tracking technologies

On 31 March 2026, the Federal Data Protection and Information Commissioner (FDPIC) published guidance on the use of cookies and similar online tracking technologies. The guidance applies to website operators and data controllers deploying such techn…

Implementer
Switzerland
Policy area Data governance
Policy or regulatory element Data protection regulation
Economic activity cross-cutting
in consultation

Guidance on automated decision-making including profiling

Latest event Date: 2026-03-31 outline consultation opened

Information Commissioner's Office opened consultation on guidance on automated decision-making including profiling

On 31 March 2026, the Information Commissioner's Office (ICO) opened a consultation on guidance on automated decision-making, including profiling, until 29 May 2026. The guidance applies to all organisations carrying out automated decision-making, i…

Implementer
United Kingdom
Policy area Data governance
Policy or regulatory element Data protection regulation
Economic activity cross-cutting
adopted

Guidelines on Roles Expected of Cyber Infrastructure Providers under Basic Act on Cybersecurity

Latest event Date: 2026-03-31 outline adoption

Ministry of Economy, Trade and Industry and National Cybersecurity Office released guidelines on roles expected of cyber infrastructure providers

On 31 March 2026, the Ministry of Economy, Trade and Industry (METI) and the National Cybersecurity Office (NCO) released guidelines on the roles expected of cyber infrastructure providers. The guidelines were developed by the Study Group on the Rol…

Implementer
Japan
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity infrastructure provider: internet and telecom services, infrastructure provider: cloud computing, storage and databases, infrastructure provider: network hardware and equipment, infrastructure provider: other
under deliberation

Guidance on automated decision-making in recruitment

Latest event Date: 2026-03-31 outline drafting

Information Commissioner's Office published report and draft guidance on automated decision making in recruitment

On 31 March 2026, the Information Commissioner's Office (ICO) published a report and draft guidance on the use of automated decision-making (ADM) in recruitment. The guidance would apply to employers that use automated tools to process job applicati…

Implementer
United Kingdom
Policy area Data governance
Policy or regulatory element Data protection regulation
Economic activity other service provider, software provider: other software
processing consultation

Guidance on application of Regulation (EU) 2024/2847 (Cyber Resilience Act)

Latest event Date: 2026-03-31 outline consultation closed

European Commission closes consultation on draft Commission guidance on the application of Regulation (EU) 2024/2847 (Cyber Resilience Act)

On 31 March 2026, the European Commission closes the consultation on draft guidance concerning the application of Regulation (EU) 2024/2847 (Cyber Resilience Act). The draft guidance clarifies how the Regulation should be interpreted and implemented…

Implementer
European Union
Policy area Data governance
Policy or regulatory element Cybersecurity regulation
Economic activity cross-cutting
in consultation

Data protection regulation in Privacy (Children's Online Privacy) Code

Latest event Date: 2026-03-31 order consultation opened

Office of the Australian Information Commissioner opened consultation on Privacy (Children's Online Privacy) Code 2026 including data protection regulation

On 31 March 2026, the Office of the Australian Information Commissioner (OAIC) opened a consultation on the exposure draft of the Privacy (Children's Online Privacy) Code 2026 (the Code) until 5 June 2026. The Code would apply to providers of social…

Implementer
Australia
Policy area Data governance
Policy or regulatory element Data protection regulation
Economic activity platform intermediary: user-generated content, software provider: other software, messaging service provider
Page
1
2
...
31