What each government has actually done to private communication and identity, with the legal status stated precisely and the primary source attached.
11Measures
6In force
2Under challenge
3Not yet binding
Every row was read against its primary source on . A measure that is proposed, in negotiation, or passed but not yet applying imposes nothing on you today, and this page says so rather than collapsing all of it into “the law”.
Status words
PROPOSED
Introduced, tabled, or published as a draft. No legal force. Includes amendments that were moved but not carried.
IN NEGOTIATION
Formally under interinstitutional or inter-chamber negotiation. Text is not settled and no obligation exists yet.
PASSED, NOT YET APPLYING
Adopted or enacted, but the operative duty has not started applying yet.
IN FORCE
Adopted and the operative duty applies now.
UNDER CHALLENGE
In force or partly in force, and being litigated. The duty can change on a court timetable.
LAPSED
Was in force and has expired, been repealed, or been withdrawn.
DEFEATED
Rejected, voted down, or abandoned without adoption.
Official source monitor
Direct captures from official legislation, rulemaking and regulator sources. Each run records the exact source route, retrieval time and SHA-256 hash of the raw response. A failed or changed source is marked here and contributes no incomplete rows. Last capture: .
Voluntary CSAM scanning derogation from ePrivacy (Regulation (EU) 2026/1881)
IN FORCE
Topic
Encryption
Status as of
Expires
Last verified
The 2021 derogation that let providers voluntarily scan for child sexual abuse material expired on 3 April 2026 because the co-legislators did not agree an extension in time. A replacement regulation was adopted on 24 July 2026 and published on 28 July 2026; it applies until 3 April 2028.
What you face todayVoluntary scanning by messaging providers is again lawful in the EU until April 2028. It is permissive, not mandatory, and it does not require any provider to weaken end-to-end encryption.
Crypto-asset transaction reporting by service providers (DAC8, Council Directive (EU) 2023/2226)
IN FORCE
Topic
Data protection
Status as of
Last verified
DAC8 amends the administrative cooperation directive to make reporting crypto-asset service providers collect and report customer and transaction data to tax authorities, which then exchange it between member states. EUR-Lex records the directive as in force, with member states required to adopt the rules by 31 December 2025 and apply them from 1 January 2026. Services that are not themselves crypto-asset service providers can still expose users through partners that are: Bitrefill states that its own gift-card and top-up purchases fall outside DAC8, while the partners issuing its EU card do fall in scope, so crypto top-ups of that card are expected to be reported in Estonia.
What you face todayBuying or exchanging crypto through an EU-facing reporting provider now creates a tax-authority record tying your identity to your transactions, and that record is exchanged across member states. It does not add an identity check at the point of sale, so a service can keep a light or unchanged sign-up flow while its reporting exposure grows. The obligation follows the provider, not the customer, which is why the reporting partner behind a product matters as much as the brand on it.
The Commission's May 2022 proposal for a permanent child sexual abuse regulation, which would allow detection orders, is still in interinstitutional negotiation. Regulation (EU) 2026/1881 records in its own recitals that those negotiations remain ongoing, which is why a further temporary derogation was needed.
What you face todayThe proposed detection-order system is not an adopted EU-wide requirement. Separate temporary rules allow providers to carry out voluntary detection. These are different measures.
App Store Accountability Act (SB 142), app-store age verification and parental consent
IN FORCE
Topic
Age verification
Status as of
Last verified
Utah's SB 142 phased its sections in from 2025, with the core app-store verification and parental-consent duties in sections 13-75-201 and 13-75-202 effective 6 May 2026. Two challenges filed in the District of Utah in February 2026 were both dismissed by stipulation on 21 April 2026, so the law is in force and not currently under active challenge.
What you face todayApp stores serving Utah users must verify an age category and obtain parental consent for minor accounts. The enforcement section, 13-75-401, takes effect 31 December 2026.
Digital Personal Data Protection Rules, 2025 under the DPDP Act, 2023
IN FORCE
Topic
Data protection
Status as of
Last verified
The DPDP Act, 2023 was enacted on 11 August 2023 and the DPDP Rules were notified on 13 November 2025, with a corrigendum on 11 December 2025. The rules phase obligations in rather than starting them all at once.
What you face todayThis is a consent and data-protection regime, not an encryption mandate. It does not require providers to weaken encryption or retain message content.
Online Safety Act age assurance duties for pornography and harmful content
IN FORCE
Topic
Age verification
Status as of
Last verified
The children's safety duties requiring highly effective age assurance became enforceable in July 2025, with the sixth commencement regulations bringing the remaining provisions into force on 25 July 2025.
What you face todaySites in scope must run age checks before serving adult content to UK users. VPNs remain legal for adults and no measure restricts adult VPN use; the government's own explainer directs its VPN concern at platforms, not at users.
Investigatory Powers Act s.253 technical capability notice served on Apple
UNDER CHALLENGE
Topic
Encryption
Status as of
Last verified
A technical capability notice reported in February 2025 led Apple to withdraw Advanced Data Protection for new UK users. Privacy International records that the first notice was withdrawn and a second one, targeting British users, was issued in October 2025; Apple's original challenge was then dismissed for a change in circumstances. Apple confirmed a fresh Investigatory Powers Tribunal complaint in August 2026.
What you face todayAdvanced Data Protection still cannot be switched on by new UK users, so iCloud backups, Drive, and Photos are held under keys Apple can access. The tribunal timetable is a case management hearing in September 2026, with the Privacy International claim listed for December 2026.
Children's Wellbeing and Schools Act 2026 s.70, power to extend age checks to internet services
PASSED, NOT YET APPLYING
Topic
Age verification
Status as of
Last verified
The House of Lords amendment on age assurance for VPN-style services did not stay a bare amendment. It became section 70 of the Children's Wellbeing and Schools Act 2026, enacted 29 April 2026, which is a regulation-making power rather than a duty that binds providers directly.
What you face todaySection 70 does not itself require VPN age checks. In its published consultation response, the government says it will not ban or age-gate VPNs, while keeping circumvention under review.
App Store Accountability Act (SB 2420), app-store age verification and parental consent
UNDER CHALLENGE
Topic
Age verification
Status as of
Last verified
Texas SB 2420 set a 1 January 2026 start date. The district court blocked enforcement, but the Fifth Circuit lifted the injunctions in June. CCIA's 3 August update confirms that the Supreme Court declined to intervene and that the appeal was set for argument on 4 August.
What you face todayThe latest cited case update permits enforcement while the appeal continues. The law requires app-store age checks and parental consent for minors. No later ruling is recorded here; the court docket was unavailable during this review.
AB 1043, operating-system age signals to applications
PASSED, NOT YET APPLYING
Topic
Age verification
Status as of
Applies from
Last verified
AB 1043 was approved on 13 October 2025 as Chapter 675 and becomes operative on 1 January 2027. Operating-system providers must offer an account-setup interface for a user's birth date, age, or both, and pass an age bracket to applications.
What you face todayThe duty starts in January 2027. Apps receive an age bracket rather than the underlying birth date. Existing devices must be offered the age-entry interface before 1 July 2027.
Statuses on this page change on legislative and court timetables, not on a publishing schedule. Each row carries its own verification date so a stale row is visible rather than silently wrong.
Evidence basis: Claims on this page are linked to published sources for comparison, not certification, audit, endorsement, or recommendation; read the methodology and coverage map before relying on an entry.