Skip to main content
Research asset · Source-linked timeline

Privacy Regulation Timeline

A non-exhaustive timeline of major privacy and data-broker milestones. Every entry identifies its jurisdiction, event type, date, and official source; the timeline is a reference aid, not legal advice.

Rahul Kandoriya
Written byRahul Kandoriya·Founder, OfflistMe·Last updated August 25, 2026
How to use it: Dates describe the milestone shown in the linked source. Laws, guidance, and enforcement posture can change, so verify the current statute or regulator page before relying on a deadline or legal conclusion.

2018-05-25

European Union
Regulation

GDPR became applicable

The General Data Protection Regulation became applicable across the EU and established rights including access, erasure, and objection, subject to its scope and exceptions.

Source: EUR-Lex: Regulation (EU) 2016/679

2024-01-09

United States
Enforcement

FTC order on sensitive location data

The FTC announced an order prohibiting X-Mode Social and Outlogic from selling or sharing sensitive location data and requiring specified deletion and privacy-program measures.

Source: FTC: X-Mode / Outlogic order

2024-02-22

United States
Enforcement

FTC order on browsing-data sales

The FTC announced an order against Avast related to selling browsing data for advertising, including monetary relief and deletion requirements described in the agency release.

Source: FTC: Avast order

2026-01-01

California
Statute

California Delete Act statutory provisions took effect

The California Delete Act provisions reflected in the effective statutory text established duties and implementation requirements for the state’s data-broker deletion platform.

Source: CPPA: Delete Act statutory text

2026-01-01

California
Public platform

California DROP opened to consumers

CalPrivacy describes the Delete Request and Opt-Out Platform as the state mechanism for California residents to submit a deletion request to active data brokers within the current mechanism scope.

Source: CalPrivacy: Consumer DROP guidance

2026-02-26

United States
Guidance / enforcement

FTC reminded data brokers about PADFAA obligations

The FTC published a reminder describing obligations it said data brokers must follow under the Protecting Americans from Dangerous Online and Foreign Surveillance Act.

Source: FTC: PADFAA reminder

Download the timeline

Includes the date, event, scope, summary, and source URL for each milestone.