Privacy Regulation Timeline
A non-exhaustive timeline of major privacy and data-broker milestones. Every entry identifies its jurisdiction, event type, date, and official source; the timeline is a reference aid, not legal advice.
2018-05-25
European Union
Regulation
GDPR became applicable
The General Data Protection Regulation became applicable across the EU and established rights including access, erasure, and objection, subject to its scope and exceptions.
Source: EUR-Lex: Regulation (EU) 2016/679 ↗2020-01-01
California
Statute
CCPA consumer rights took effect
California’s Consumer Privacy Act rights and obligations took effect, including consumer rights to know, delete, and opt out of sale in defined circumstances.
Source: California Legislative Information: Civil Code §1798 ↗2024-01-09
United States
Enforcement
FTC order on sensitive location data
The FTC announced an order prohibiting X-Mode Social and Outlogic from selling or sharing sensitive location data and requiring specified deletion and privacy-program measures.
Source: FTC: X-Mode / Outlogic order ↗2024-02-22
United States
Enforcement
FTC order on browsing-data sales
The FTC announced an order against Avast related to selling browsing data for advertising, including monetary relief and deletion requirements described in the agency release.
Source: FTC: Avast order ↗2026-01-01
California
Statute
California Delete Act statutory provisions took effect
The California Delete Act provisions reflected in the effective statutory text established duties and implementation requirements for the state’s data-broker deletion platform.
Source: CPPA: Delete Act statutory text ↗2026-01-01
California
Public platform
California DROP opened to consumers
The CPPA describes the Delete Request and Opt-Out Platform as the state mechanism for California consumers to submit deletion requests to covered registered data brokers.
Source: CPPA: Information for data brokers / DROP ↗2026-02-26
United States
Guidance / enforcement
FTC reminded data brokers about PADFAA obligations
The FTC published a reminder describing obligations it said data brokers must follow under the Protecting Americans from Dangerous Online and Foreign Surveillance Act.
Source: FTC: PADFAA reminder ↗Download the timeline
Includes the date, event, scope, summary, and source URL for each milestone.
