Data Protection

Regulatory frameworks governing the collection, processing, storage, and transfer of personal data, including privacy rights and institutional obligations to safeguard individual information.

Foresight tracks Data Protection developments and surfaces the alerts most likely to matter before they turn into missed deadlines, recalls, or escalation work.

Not ready for a trial? Take the 3-minute readiness assessment

Current activity

Cooling

71% below the prior 8-week baseline

3-month trend

Latest alerts below

Last updated

24 May 2026, 21:17

View alerts

Latest Data Protection developments

Source-backed regulatory and guidance signals tracked by Foresight, with the newest developments first.

German Bundestag Holds First Reading of Bill to Strengthen Medical Registers

In May 2026 the German Bundestag held the first reading of a federal bill to create a Medical Registers Act and amend social security and implant register law, establishing a unified framework and new governance for more than 350 medical registries and their health data use. If adopted, this regime will formalise qualification and interoperability requirements, expand permitted reuse and linkage of registry data, and reshape compliance strategies for medical device and pharmaceutical firms that run or rely on clinical registries and real-world evidence.

dserver.bundestag.deGermanyGermany

France Senate Proposes Law to Generalise Algorithmic Video Surveillance for Public Security

In May 2026 the French Senate registered a bill creating a permanent legal framework for AI-based analysis of CCTV images by law enforcement and key transport operators, while explicitly banning biometric identification and facial recognition. If adopted, this would move France beyond temporary retail experiments toward a nationwide, regulated regime for algorithmic video surveillance, heightening governance, data protection and oversight obligations for public authorities and technology providers.

senat.frFranceFranceEuropean UnionEuropean Union

German Government Submits Draft Medical Registers Act to Strengthen Registries and Data Use

In May 2026 the German government submitted a draft Medical Registers Act that would create a central registry framework, new quality criteria and data-sharing rules for medical registries, and align Social Code Book V and implant registry law around use of the health insurance number for pseudonymised data linkage. If enacted, medtech, pharma and health-data stakeholders running or relying on registries in Germany will face stricter qualification and governance requirements but also easier, more legally secure access to high-quality real-world data for safety, reimbursement and innovation decisions.

dserver.bundestag.deGermanyGermany

European Commission Recommends EU Age Verification Framework With Member State Roll-Out by End 2026

The European Commission has issued a non-binding Recommendation setting out a common EU framework for privacy-preserving age verification technologies and urging all Member States to deploy at least one EU age verification solution, linked to European Digital Identity Wallets, by the end of 2026. This points to a coming EU-wide expectation that online platforms and providers of age-restricted products and services will support harmonised, standards-based digital age checks aligned with the Digital Services Act, raising future compliance and IT-integration requirements even before binding rules are adopted.

data.consilium.europa.euEuropean UnionEuropean Union

European Parliament Question on Security of EU Age Verification App

In April 2026, several MEPs challenged the security and GDPR compliance of the Commission’s EU age verification app, citing alleged PIN bypasses, disabling of biometrics, and unencrypted storage of facial images on user devices. Their written question increases pressure on the Commission to strengthen security assurance and independent auditing of the app before broad deployment, which could influence future EU expectations for privacy-preserving online age verification.

europarl.europa.euEuropean UnionEuropean Union

California Assembly Passes AB 2086 On Pest Control Licensee Privacy

In April 2026 the California Assembly passed AB 2086, a bill to make pest-control licence applicants’ and licensees’ personal information confidential under the state public records law and sent it to the Senate for further consideration. If enacted, this will tighten privacy protections for pest-control operators while preserving public access to licence status and enforcement information, changing how regulators and businesses manage licensing data and disclosures.

leginfo.legislature.ca.govUnited StatesUnited States

European Parliament Resolution and Final Text on GDPR Enforcement Procedural Rules

The European Parliament’s first-reading legislative resolution on additional procedural rules for enforcing the GDPR has now been published in the Official Journal, confirming that this position text corresponds to final Regulation (EU) 2025/2518. This consolidates the EU-level framework for GDPR enforcement procedures, signalling that organisations should monitor the separate publication and application of the new regulation and prepare for more structured handling of investigations and complaints.

eur-lex.europa.euEuropean UnionEuropean Union

New UK Regulations Require ICO to Produce AI and Automated Decision Making Code Under the Data Protection Act

The UK has adopted regulations, effective May 2026, requiring the Information Commissioner to develop a statutory code of practice on artificial intelligence and automated decision-making under the UK GDPR and Data Protection Act 2018. While the instrument itself does not yet change controller or processor duties directly, it signals that UK regulators will formalise expectations for AI-driven processing, so organisations should anticipate a more codified compliance framework and align future governance and risk assessments with the forthcoming code.

legislation.gov.ukUnited KingdomUnited Kingdom

CJEU Judgment C‑769/22: Hungary’s Child‑Protection Content Law Breaches EU Law and Fundamental Rights

In April 2026, the EU Court of Justice ruled that Hungary’s 2021 “child-protection” law restricting minors’ access to LGBTQ+-related content and broadening access to sex-offender registers breaches multiple EU directives, the GDPR, the EU Charter of Fundamental Rights and Article 2 of the Treaty on European Union. This judgment significantly tightens EU-wide limits on national content and data rules, signalling that future restrictions on online services, media, advertising, education and criminal-records access must avoid discrimination and respect fundamental rights, reshaping compliance and litigation risk for operations and campaigns in Hungary and potentially other Member States.

eur-lex.europa.euEuropean UnionEuropean UnionHungaryHungary

Swedish Medical Products Agency Updates AI Guidance for Healthcare

Sweden’s Medical Products Agency has issued an updated AI guidance for healthcare in early April 2026, aligning clinical use of AI systems – including generative models – with the EU AI Act, MDR/IVDR and data protection rules. Healthcare providers deploying AI in Sweden now face clearer expectations to treat AI tools as regulated medical and high-risk AI systems, with more rigorous demands on risk analysis, governance, data protection, lifecycle management, and in-house development.

lakemedelsverket.seSwedenSweden

Netherlands Sets Multi-Year Labour and Social Security Enforcement Strategy 2026–2029

The Netherlands has established a 2026–2029 enforcement strategy that indexes fines for health, safety, and labour violations to ensure penalties outweigh the financial gains of non-compliance. Businesses face heightened financial risk and must ensure labour providers are authorized under new mandatory requirements taking full effect by 2028.

open.overheid.nlNetherlandsNetherlands

Netherlands Parliament Motion Seeks Research Into Statutory Aftercare Duty for Large-Scale Personal Data Breaches Under NIS2 Implementation

The Dutch Parliament has commissioned research into a statutory aftercare duty for large-scale data breaches with findings expected by the third quarter of 2026. This initiative signals a potential shift toward expanded corporate liability and mandatory victim support frameworks that exceed current European cybersecurity and data protection standards.

zoek.officielebekendmakingen.nlNetherlandsNetherlandsEuropean UnionEuropean Union

France National Assembly Tables Bill No. 2600 On Screening Of Foreign Investments In Strategic Sectors

France introduced Bill No. 2600 in March 2026 to significantly broaden the screening of foreign investments in strategic sectors including energy, health, and critical raw materials. This proposal signals a shift toward stricter oversight of cross-border M&A with potential mandates for R&D localization and patent protection to safeguard national economic sovereignty.

assemblee-nationale.frFranceFrance

Netherlands Adopts Law Introducing Reporting and Verification Duties for Workplace Accidents for Lending Employers

The Netherlands has enacted legislation requiring host and lending employers to share workplace accident data and verify safety measures for temporary workers. Businesses utilizing or providing temporary labor must formalize cross-entity safety reporting protocols and documentation standards to ensure compliance and manage liability risks.

officielebekendmakingen.nlNetherlandsNetherlands

EU Parliament Adopts Position Proposing Delayed Artificial Intelligence Act Application and Ban on Nudifier Apps

The European Parliament has adopted its position on the Digital Omnibus on AI, proposing staggered compliance deadlines through 2028 and a ban on non-consensual AI image generation. Manufacturers of AI-integrated products must prepare for phased enforcement that aligns AI Act obligations with existing sectoral safety frameworks for medical devices, toys, and radio equipment.

europarl.europa.euEuropean UnionEuropean Union

Lower Saxony Publishes Eckpunkte Guidance On Video Surveillance In Slaughterhouses

Lower Saxony has published technical guidance for video surveillance in slaughterhouses to enhance animal welfare transparency ahead of expected federal mandates. Operators should align voluntary monitoring systems with these benchmarks to ensure readiness for future statutory obligations and standardized state inspections.

ml.niedersachsen.deGermanyGermany

MedTech Europe Response To EU Digital Omnibus Consultation On AI And Data Rules

MedTech Europe is advocating for the alignment of the EU Digital Omnibus with existing medical device regulations to ensure a coherent framework for AI and health data. Industry is pushing for a single conformity assessment pathway and enhanced trade secret protections to avoid duplicative compliance burdens and market access delays for digital health technologies.

eur-lex.europa.euEuropean UnionEuropean Union

European Parliament Amendments 103–107 To Digital Omnibus On AI

Proposed EU Parliament amendments to the Digital Omnibus on AI aim to accelerate high-risk compliance timelines and remove simplified testing pathways for embedded systems. These changes would force a hard 2027 application date and require all legacy AI systems to meet full regulatory standards by the end of 2030.

europarl.europa.euEuropean UnionEuropean Union

Minnesota Legislature Proposes Age-Appropriate Design Code Act (HF 4511)

Minnesota introduced legislation in early 2026 to mandate safety-by-design and strict data privacy standards for online products likely to be accessed by minors. Impacted firms must prioritize child well-being over commercial interests and prepare for mandatory impact assessments to mitigate substantial per-child civil penalties.

revisor.mn.govUnited StatesUnited States

New York Assembly Proposes Consumer Camera Privacy Act for Networked Camera Devices (Bill A10687)

New York has introduced legislation to strictly regulate networked camera devices, mandating explicit opt-ins for surveillance features and imposing tight data retention limits. Manufacturers must prepare for significant product design and data governance shifts, including mandatory point-of-sale disclosures and increased litigation risk from a private right of action.

assembly.state.ny.usUnited StatesUnited States

Not a newsletter. Not a feed. Structured intelligence mapped to your business.

These are just a few of the most recent Data Protection alerts. Foresight tracks every jurisdiction, every day — and surfaces only what affects your portfolio, with full citations and evidence.

Start free trial

Topic context

How to read Data Protection regulatory activity

Definition

What is Data Protection?

Regulatory frameworks governing the collection, processing, storage, and transfer of personal data, including privacy rights and institutional obligations to safeguard individual information.

Industry relevance

Why it matters

Data Protection developments can change product scope, supplier expectations, market access, reporting duties, and risk ownership. Foresight tracks the signals early so teams can respond before obligations become urgent.

Foresight tracking

How Foresight monitors it

Foresight monitors official sources, extracts structured regulatory intelligence, and maps alerts to a customer's products, substances, markets, and priorities so teams see the relevant signal with source evidence for review.

Frequently asked questions

Everything you need to know about Foresight's regulatory intelligence platform

Still have questions? Get in touch with our team

Join 3,500+ professionals staying ahead

Subscribe to Foresight Weekly for expert-picked regulatory developments across chemicals, sustainability, product safety, ESG, and HSE.

Free forever. Unsubscribe anytime.

Read by professionals at

Boeing
AstraZeneca
Siemens
PepsiCo
SpaceX