Skip to main content
No ads · No data selling · No tracking · Est. 2026
Your data ยท Right now Is your data already for sale?

Find Out.
Fight Back.

Check if your email appeared in a breach, score your privacy risk, and send a legal deletion request โ€” free, in 2 minutes.

14B+ accounts in breach databases
Live enforcement TikTok. Meta. Google. LinkedIn.

They were caught.
You can act.

โ‚ฌ7.1 billion in GDPR fines since 2018 โ€” and every one of those companies still holds your data. Send them a legal deletion request today.

โ‚ฌ530M TikTok fine ยท May 2025
EU AI Act ยท Aug 2026 The biggest privacy deadline in a decade

The countdown
has started.

Full EU AI Act enforcement begins August 2, 2026. Companies face fines up to โ‚ฌ35M. Know every deadline before they do.

โ‚ฌ35M max AI Act fine or 7% global turnover
Data rights GDPR gives you 8 legal rights

Most people
use zero of them.

The right to be forgotten. The right to see your data. The right to say no. They exist. They are enforceable. Here is exactly how to use them.

2,800+ GDPR enforcement actions on record
Big Tech watch Your phone knows where you sleep

See what
they know.

Meta, Google, Amazon, TikTok โ€” collecting more than you think. We break down exactly what each company takes, and how to stop them.

8 companies profiled in plain English
Corporate watchlist Under investigation right now

Who's in trouble
this week.

12 companies under active investigation by EU, UK, and US regulators. OpenAI, Microsoft Copilot, Amazon Ring, Worldcoin โ€” and the list keeps growing.

12 active investigations tracked live
01 / 06
8 quick questions

What's your personal privacy risk score?

QUESTION 1 OF 8
Latest headlines

Privacy & AI News

All news →
Regulatory deadline calendar

Privacy & AI Regulation Deadlines

Every major regulatory deadline globally โ€” filterable by region, law, and urgency. Updated continuously. Bookmark this page and never miss a compliance date.

Critical โ€” within 90 days
Upcoming โ€” within 6 months
Future โ€” 6+ months
Recently passed
โ€” deadlines Sorted by date ยท Click any row for details ยท
Date Regulation / Law Jurisdiction What happens Type Who it affects
Live enforcement intelligence

Corporate Privacy Watchlist

Companies currently under active investigation by data protection authorities. Updated as new proceedings open and close.

Sources EDPB News DPC Ireland CMS Enforcement Tracker NOYB Cases GDPRhub IAPP Privacy Tracker ยท Status current as of May 2026 ยท Investigations may close or expand at any time
What they actually do with your data

Big Tech & AI โ€” In Plain English

Most privacy policies run to 10,000 words of legal fog. We translate what the biggest platforms actually collect, how they use it, and exactly what rights you have against each one.

Sources EDPB DPC Ireland NOYB CMS Enforcement Tracker Privacy Affairs ยท Official privacy policies and DPA decisions for each company listed below each panel
No legal jargon

Major Fines, Explained for Everyone

Every big enforcement action translated into plain language โ€” what the company did wrong, what it means for you, and what you can do about it.

Sources CMS Enforcement Tracker EDPB GDPRhub Privacy Affairs ยท Official DPA decisions linked per case below
View all 2,800+ enforcement actions โ†’
Know your rights

Your Global Privacy Rights

Under GDPR, CCPA, LGPD, and dozens of other laws, you have enforceable rights over your personal data. Here's what they mean in practice.

DLA Piper Data Protection Navigator

Global Data Protection Heatmap

Regulation & enforcement intensity across 160+ jurisdictions, based on DLA Piper's Data Protection Laws of the World handbook.

Enforcement intensity: Heavy Robust Moderate Limited No data
Heavy
Robust
Moderate
Limited
Full details on DLA Piper โ†—
The legal landscape

Major Global Privacy & AI Regulations

The frameworks that give you rights over your data โ€” and the enforcement actions proving they have teeth.

Country lookup

Find regulations by country

Data Protection & Privacy Laws
๐Ÿ‡ช๐Ÿ‡บ

EU General Data Protection Regulation (GDPR)

World's most comprehensive privacy law. Fines up to 4% of global annual turnover. Applies to all EU residents' data globally.

In Force
๐Ÿ‡บ๐Ÿ‡ธ

California Privacy Rights Act (CPRA)

Expands CCPA rights. Establishes the California Privacy Protection Agency with independent enforcement powers.

In Force
๐Ÿ‡ง๐Ÿ‡ท

Brazil LGPD (Lei 13,709/2018)

Brazil's GDPR-equivalent. ANPD now issuing active enforcement fines of up to 2% of Brazil revenue.

Enforcing
๐Ÿ‡ฎ๐Ÿ‡ณ

India Digital Personal Data Protection Act (DPDP) 2023

India's first comprehensive data protection law. Implementing Rules published November 2025. Enforced by the Data Protection Board of India.

Enforcing
๐Ÿ‡จ๐Ÿ‡ณ

China Personal Information Protection Law (PIPL) 2021

Strict consent requirements and data localization. Applies globally to processing of Chinese citizens' data.

In Force
๐Ÿ‡ฌ๐Ÿ‡ง

UK GDPR / Data Protection Act 2018

Post-Brexit GDPR equivalent enforced by the ICO. Covers UK residents globally. Data (Use and Access) Bill 2025 advancing reforms.

In Force
๐Ÿ‡จ๐Ÿ‡ญ

Switzerland nFADP (revDSG) 2023

New Federal Act on Data Protection in force September 2023. Aligned with GDPR. Enforced by the FDPIC.

In Force
๐Ÿ‡ฐ๐Ÿ‡ท

South Korea PIPA (2023 amendments)

Personal Information Protection Act, significantly strengthened 2023. EU adequacy status. Enforced by PIPC.

In Force
๐Ÿ‡ธ๐Ÿ‡ฌ

Singapore PDPA 2012 (amended 2020)

Personal Data Protection Act. Mandatory breach notification, fines up to 10% of annual turnover. Enforced by PDPC.

In Force
๐Ÿ‡ฟ๐Ÿ‡ฆ

South Africa POPIA 2013

Protection of Personal Information Act, fully in force July 2021. Enforced by the Information Regulator.

In Force
Transparency & trust

Why Trust This Site

We believe credibility has to be earned โ€” not claimed. Here's who we are, what our sources are, who has reviewed our work, and how we make decisions.

๐Ÿ’ฌ

Expert Commentary

Our enforcement analysis and plain-English explanations are reviewed against official DPA decisions, EDPB guidelines, and IAPP analysis. We cite primary sources on every major claim โ€” no second-hand summaries.

"The most dangerous thing about modern data collection isn't the scale โ€” it's the invisibility. Most people never know their data has been transferred, sold, or breached until something goes wrong."

โ€” Max Schrems, NOYB founder & privacy lawyer, Vienna

"GDPR enforcement is finally catching up with the business models it was designed to constrain. The 2023โ€“2025 fine wave is not the end โ€” it's the beginning of a new enforcement normal."

โ€” Dr. Gabriela Zanfir-Fortuna, Future of Privacy Forum VP for Global Privacy
๐Ÿ”ฌ

How We Source Information

Every data point on this site traces back to a verifiable primary source. Our methodology:

  • Enforcement data โ€” CMS GDPR Enforcement Tracker (2,800+ cases), DLA Piper annual GDPR fines survey, national DPA press releases
  • Company data practices โ€” official privacy policies, DPA investigation reports, court documents, and academic research
  • Watchlist status โ€” EDPB binding decisions, DPC Ireland press releases, NOYB case database, national regulator announcements
  • Rights information โ€” Official GDPR, UK GDPR, CCPA, LGPD statutory text via EUR-Lex, CNIL, ICO, and IAPP
  • Breach data โ€” HaveIBeenPwned API (Troy Hunt), DLA Piper Data Breach Survey

Content reviewed quarterly. Enforcement data updated as DPA decisions are published.

๐Ÿ›๏ธ

Who We Are

Right to Privacy Foundation is an independent publication. We have no advertisers, no corporate sponsors, and no commercial relationships with any company we cover. We are editorially and financially independent.

Funding
Editorially independent โ€” no commercial relationships
Advertising
None โ€” ever
Data selling
Never โ€” ironic if we did
Tracking
No third-party trackers on this site
Hosting
EU-based servers, GDPR-compliant
Editorial
Fully independent โ€” no outside editorial control
โญ

Rate Your Company's Privacy Response

Have you sent a Subject Access Request or deletion request to a company? Tell the community how they responded โ€” building a unique dataset no regulator has.

Anonymous ยท No personal data collected ยท Stored locally & contributed to our community dataset

๐Ÿ“ฐ This week's editorial

Why the TikTok Fine Changes Everything About Cross-Border Data

The โ‚ฌ530M DPC decision isn't just about TikTok. It establishes that SCCs alone are insufficient when the destination country's law requires government access to data โ€” a principle that now threatens every US and Chinese tech company operating in the EU.

By the Right to Privacy Foundation editorial team ยท May 2026 ยท 4 min read
Get the weekly digest

One email per week. The most important privacy development, explained clearly. No filler.

Expert resources

Privacy References

The organisations, tools, and scholars we trust most for privacy and AI intelligence.

Suggest a resource โ†’
โš–๏ธ Regulators & Enforcement
๐Ÿ“Š Trackers & Databases
โœŠ Advocacy & NGOs
๐ŸŽ“ Professional Bodies & Education
๐Ÿ› ๏ธ Tools & Self-Help