AI LAW RADAR · Daily Last verified 22 Sep 2026

What changed

185 entries · newest first

Every material change to the register, dated and sourced — new instruments, deadline shifts, and the verifications behind them. Headlines below; the full note sits one click away. See the field-level revision history, or follow RSS · JSON Feed.

Mon 21 Sep 20262 entries
ME Montenegro enacts a new GDPR-aligned data protection law, replacing the 2008-era ZZPL

Updated logged 21 Sep 2026

Montenegro's Zakon o zaštiti podataka o ličnosti (Službeni list Crne Gore br. 133/2026 od 11.9.2026) was signed 8 September 2026 and entered into force 19 September 2026, becoming applicable from 19 March 2027. Its art. 23 is a GDPR art. 22-style automated-decision right that will replace the outgoing art. 15a prohibition tracked here. The jurisdiction record has been updated; a dedicated art. 23 obligation row is pending a direct read of the primary gazette text.

Primary source — me.propisi.net ↗

US Illinois SB315: frontier-AI-framework and audit obligation corrected to 2028-01-01

correction logged 21 Sep 2026

The row previously used SB315's general 2027-01-01 Act effective date. The frontier-AI-framework publication duty and annual third-party audit requirement — the specific obligations this row tracks — phase in on 2028-01-01, or 90 days after a developer first qualifies as a large frontier developer, whichever is later. Corrected after convergent law-firm client-alert corroboration; ilga.gov was unreachable (TLS error) this run.

Primary source — lw.com ↗

Sun 20 Sep 20263 entries
EU EU AI Act CSAM/nudifier prohibition: confidence restored to high with exact article citation

correction logged 20 Sep 2026

Re-verification directly against the Official Journal PDF (CELEX 32026R1744, not the truncated EUR-Lex HTML page) located the specific provision: Digital Omnibus Art. 1(7)(a) inserts new AI Act Art. 5(1) first subparagraph points (ba) and (bb) (non-consensual intimate imagery and CSAM), and Art. 1(40)(a) amends AI Act Art. 113 third paragraph point (a) to set 2 December 2026 as the application date for those points. Confidence raised from medium back to high; the 2 December 2026 date is unchanged.

Primary source — eur-lex.europa.eu ↗

BJCG Benin art. 401 and Congo-Brazzaville art. 13: confidence raised to high

correction logged 20 Sep 2026

Both rows were re-verified this run against clean, fully readable official-text mirrors (AFAPDP for Benin's Code du numerique art. 401; the Journal Officiel du Congo for Loi 29-2019 art. 13), each matching the stored wording verbatim. Confidence raised from medium to high; no change to dates or lifecycle.

Primary source — sgg.cg ↗

RW Rwanda jurisdiction page: automated-decision-making article citations corrected

correction logged 20 Sep 2026

The Rwanda deep-dive page cited art. 14 for the disclosure-of-logic duty and art. 45 for the mandatory impact assessment under Law No. 058/2021. RwandaLII's official consolidated text shows art. 14 is actually 'Source of personal data' and art. 45 is 'Communication of a personal data breach'; the correct citations are art. 42 (disclosure of logic) and art. 38 (impact assessment). Art. 21 (the core automated-decision right) was already cited correctly and is unchanged.

Primary source — rwandalii.org ↗

Sat 19 Sep 20261 entry
EU EU AI Act CSAM/nudifier prohibition: confidence lowered pending direct article citation

correction logged 19 Sep 2026

Re-verification against Regulation (EU) 2026/1744 (EUR-Lex CELEX 32026R1744) confirmed the regulation is adopted and in force and that the stored 2 December 2026 application date is consistent with the Digital Omnibus's general application-date structure. The fetched primary text did not itself isolate an explicit dated clause for the new CSAM/non-consensual-intimate-imagery prohibition specifically; that date was corroborated only via secondary legal-commentary sources. Confidence is lowered from high to medium pending a direct Art. 113/Art. 5 citation on a future check.

Primary source — eur-lex.europa.eu ↗

Thu 17 Sep 20261 entry
IN India IT Rules SGI amendment: date corrected to 10 February 2026

correction logged 17 Sep 2026

The synthetic/AI-generated-information (SGI) labelling amendment to the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 was recorded as taking effect 20 February 2026. The consolidated rules text published by MeitY dates every inserting/substituting provision to G.S.R. 120(E), dated 10.02.2026, and Rule 1(2) commences the rules on the date of Gazette publication. The date is corrected to 10 February 2026.

Primary source — meity.gov.in ↗

Tue 15 Sep 20262 entries
ME Montenegro: Assembly adopts replacement personal-data-protection laws, ZZPL art. 15a still governs pending publication

Updated logged 15 Sep 2026

The Skupština adopted both the general Predlog zakona o zaštiti podataka o ličnosti (EPA 1164 XXVIII) and the law-enforcement-sector companion bill (EPA 1165 XXVIII) at the Sixth extraordinary session of 2026, per Montenegrin legal-press reporting of the Assembly's session agenda. Official Gazette (Sluzbeni list CG) publication and an entry-into-force date have not yet been confirmed from a primary citation, so the current ZZPL art. 15a automated-decision rule remains the governing text.

Primary source — kodex.me ↗

US Idaho SB 1297: signature date corrected to 31 March 2026

correction logged 15 Sep 2026

The Idaho Conversational AI Safety Act's status note previously stated a 1 April 2026 signature date; the Idaho Legislature's own bill-status page records the Governor's signature on 31 March 2026. The 1 July 2027 operative date is unaffected.

Primary source — legislature.idaho.gov ↗

Mon 14 Sep 20262 entries
EG Egypt: two binding rules published from the Executive Regulations of the PDPL, and the «no AI-specific law in force» reading retired

Added logged 14 Sep 2026

Egypt had never been swept, because the regulator's PDFs were recorded as unreadable. The Executive Regulations of Law 151/2020, made by Ministerial Decree No. 816 of 2025 and published in الوقائع المصرية No. 244 bis (A) of 1 November 2025, have now been read in the gazette itself, all 41 pages. Two binding rules are published: art. 4 first limb item 7, which obliges a processor handling personal data for artificial-intelligence training operations and emerging and innovative technologies to follow locally, regionally and internationally recognised principles and to cause the data subject no harm; and art. 14 item 5, which bars data obtained from a child taking part in a game, competition or other activity from being used in classification, tracking or behavioural-monitoring operations. Egypt has no GDPR art. 22 analogue: the Regulations' own index carries no automated-decision or profiling heading and the regulator's own materials enumerate nine data-subject rights under PDPL art. 2, none of which is an automated-decision right. The Egypt jurisdiction record moves from Guidance only to Binding sectoral and no longer says «No AI-specific law in force».

Primary source — pdpc.gov.eg ↗

UK Crime and Policing Act 2026: the CSAM image-generator offences have not actually commenced yet

correction logged 14 Sep 2026

The row previously stated that the CSAM image-generator offences (ss.72-74) commenced on 29 June 2026 via the same commencement instrument as the intimate-image-generator offence (s.99). legislation.gov.uk marks ss.72-74 "Prospective" and confirms they were not in force at Royal Assent and have not since been commenced by UKSI 2026/689 or any later instrument. Only s.99 is in force. Confidence lowered from high to medium pending a future commencement order for ss.72-74.

Primary source — legislation.gov.uk ↗

Sun 13 Sep 20261 entry
AOCGCICV+7 Malabo Convention art. 14(5) is now recorded on all sixteen party rows, not five — and in nine of them it is a stricter rule than the national statute

Updated logged 13 Sep 2026

Article 14(5) of the African Union Convention on Cyber Security and Personal Data Protection has been in force since 8 June 2023 and binds the sixteen States that have deposited an instrument of ratification. All sixteen already carried a row on the tracker, but only five of those rows mentioned the Convention: Mozambique and Namibia, where it is the operative rule because there is no national data-protection statute, and Zambia, Mauritius and Mauritania. The other eleven were silent about it. They are silent no longer. Each now carries a Malabo overlay paragraph in its status note, giving the State's deposit date, the Convention's own entry-into-force computation under art. 36, and — the point of the exercise — how the treaty's bar differs from the national one. It differs because art. 14(5) admits no exception of any kind: no contract limb, no consent limb, no legal-authorisation limb. Nine of the eleven national statutes admit at least one. Rwanda's art. 21 and Niger's art. 52 admit all three. Senegal, Congo-Brazzaville and Togo admit a contract deeming clause under which a decision the data subject was able to comment on is treated as not solely automated at all. Angola's art. 29.º(3) and Cabo Verde's art. 23.º(3) go further and let the data-protection authority itself authorise the decision, a dispensing power the Convention never grants anyone. Ghana diverges the most: s. 41 is a right exercised by written notice rather than a standing prohibition, and s. 41(4) then excludes pre-contractual consideration, contract performance and anything authorised by an enactment — so automated hiring and credit decisions sit inside the Ghanaian carve-out and outside the treaty's. The practical consequence is recorded rather than resolved, because it is a real state of the law and not a source conflict: a controller relying on explicit consent or contract necessity in Kigali, Niamey, Accra or Praia stands on solid statutory ground and unresolved treaty ground. The national statute is carried as the operative rule in every case, since it is the instrument with a supervisory authority behind it and a penalty attached to it; the treaty runs behind it. Two of the eleven are the opposite finding and are labelled as such: Guinea's art. 27 and Côte d'Ivoire's art. 25 supply no carve-out whatever, so they already match the Convention's absolute bar, and Côte d'Ivoire is wider still, reaching any decision appraising human conduct rather than only decisions with legal effects. Their overlay says the Convention adds nothing — a checked finding, not an unexamined gap. One date carries a caveat. São Tomé e Príncipe deposited on 15 February 2024, the only deposit that post-dates the Convention's own entry into force, and art. 36 fixes only the collective date with no per-State clause, so the day from which São Tomé is bound is not derivable from the instrument; the row says so and asserts nothing more precise. No obligation was added, removed or re-dated by this change, and no national statute's facts were altered — the counts stand at 188 obligations across 78 regions and 130 countries.

Primary source — au.int ↗

Thu 10 Sep 20262 entries
ID Indonesia: the PP 33/2026 statement is flagged as reported-not-verified — no primary Indonesian corpus can confirm it yet

correction logged 10 Sep 2026

Today's earlier entry recorded Peraturan Pemerintah No. 33 Tahun 2026 as the implementing regulation for UU 27/2022 on the strength of a commercial legal database. A primary-source check could not confirm it. The JDIH of the Kementerian Sekretariat Negara holds the national collection, and its 2026 holdings ceiling at 2 July 2026 across every instrument type — the highest Peraturan Pemerintah on file is No. 31 of 2026, promulgated 2 July — so a regulation signed on 16 July falls beyond the corpus ceiling and its absence proves nothing either way. The JDIH of the Kementerian Komunikasi dan Digital, the ministry of record, still shows «Peraturan Pelaksanaan: Data belum Tersedia» against UU 27/2022. peraturan.bpk.go.id returns HTTP 403, jdihn.go.id refuses the connection and peraturan.go.id does not resolve. The status_note and max_penalty of id-uu27-adm now say so explicitly, and the 16 January 2027 commencement is held open — one secondary account gives 15 January instead. No duty, date, lifecycle or penalty figure on the row changes; the row's own primary basis remains the full text of UU 27/2022 published by the Komdigi JDIH.

Primary source — jdih.setneg.go.id ↗

ID Indonesia: PP 33/2026 finally issues the implementing regulation for UU 27/2022's automated-decision objection and impact-assessment procedures

Updated logged 10 Sep 2026

Peraturan Pemerintah No. 33 Tahun 2026 tentang Pelindungan Data Pribadi was signed by President Prabowo Subianto on 16 July 2026 and enters into force on 16 January 2027, six months after promulgation. It supplies the technical rules that UU 27/2022 left to a future Government Regulation, including the procedure for objecting to solely-automated decisions under Art. 10(2) and for personal-data-protection impact assessments under Art. 34(3), alongside DPO appointment, cross-border transfer and administrative-sanction procedures. Until it takes effect, those two procedures remain undetailed, which is reflected in the updated status_note and max_penalty text.

Primary source — hukumonline.com ↗

Wed 9 Sep 20265 entries
JM Jamaica: the 2023 Appointed Day Notice read at last — s. 12 confirmed in force from 1 December 2023, but Part VI enforcement never commenced

Updated logged 9 Sep 2026

The second Appointed Day Notice under the Data Protection Act, 2020 had been sitting unread on this tracker because the Office of the Information Commissioner publishes it only as an image scan. It has now been decoded and read. The Data Protection Act, 2020 (Additional Specified Provisions) (Appointed Day) Notice, 2023, No. 437A, Jamaica Gazette Supplement Vol. CXLVI No. 364A of 1 December 2023, appoints that date for sections 1 and 3, Part II, sections 14 to 17, 19 and 20, section 21(1), (3), (4) and (5), sections 22 to 31, Part V, sections 58, 59, 61, 63, 64, 65, 67, 68, 69, 71, 72, 73, 75 and 76, and the Second and Fourth Schedules. Section 12 is not listed by number; it comes into force inside Part II, which the Act's arrangement of sections fixes at sections 5 to 13. The 1 December 2023 date on this entry is therefore confirmed against the enumerated list rather than inferred from the section 76 transition period, and confidence rises from medium to high. Reading the list also corrected the penalty side of the entry, which had been wrong. The notice omits the whole of Part VI, sections 44 to 55, so the enforcement notice, the data protection impact assessment duty, assessment and information notices, the appeal rights, the powers of entry, and the section 52 offence carrying the one million Jamaican dollar fine are all enacted but not in operation — as are section 18, section 21(2), section 62's fixed-penalty power, section 70 and the Third Schedule. The section 68 four per cent of worldwide turnover ceiling is in force but only amplifies offences that are themselves in force, which the relevant ones are not. The live remedy for an automated-decision failure in Jamaica today is a section 12(5) order to reconsider the decision, plus section 69 damages.

Suriname added as proposed — the privacy bill's art. 11 lid 2 is a full GDPR art. 22 analogue, recovered from a PDF twice written off as unreadable

Updated logged 9 Sep 2026

Suriname joins the atlas at proposed. The Ontwerpwet Bescherming Privacy en Persoonsgegevens, live before De Nationale Assemblee under the status «In behandeling», carries at art. 11 lid 2 a right not to be subject to a decision based solely on automated processing including profiling that produces legal effects or otherwise significantly affects the data subject, with the three GDPR exits, mandatory safeguards in all three cases naming human intervention, the right to express a view and the right to contest, and — unlike the CARICOM model text in Barbados, Belize and Guyana — the GDPR art. 22(4) explicit-consent route left open for sensitive data at art. 11 lid 12. The explanation limb at art. 11 lid 3 is request-based rather than proactive: art. 10's collection-time catalogue has no logic item. Art. 47 lid 2 commences the Act on the day after promulgation in the Staatsblad — a direct offset, so no date is derivable until promulgation, which has not happened. Art. 35 lid 6 would put a breach of art. 11 in the upper fine band, SRD 10,000 or 4% of total worldwide annual turnover, whichever is higher. The finding also corrects a method error that had blocked this row twice. The Assembly's PDF is a scanner sandwich — JBIG2 page images over an invisible OCR text layer — written with cross-reference streams, so its font dictionaries sit inside a compressed object stream and a raw-byte «/Font» count returns zero. That count had been treated as proof the document had no text. pdf.js recovers 196,019 characters from the same file: all 47 articles and the full memorie van toelichting, which is the only place in the instrument where «kunstmatige intelligentie» is named. A raw-byte font count is not evidence a PDF is image-only, and any earlier «image-only, unreadable» finding on this tracker is now worth re-testing.

Primary source — dna.sr ↗

US Connecticut PA 26-15 s.1 repealed and replaced by PA 26-100 s.46

correction logged 9 Sep 2026

A companion clean-up act, Public Act No. 26-100 (HB 5222, signed 2 June 2026), repeals PA 26-15 Section 1 effective from passage (PA 26-100 s.67) and replaces the subscription-based generative-AI disclosure duty with a narrower rule at PA 26-100 s.46. The October 1, 2026 effective date and the >1,000,000-monthly-user threshold are unchanged; only the statutory citation moves from PA 26-15 s.1 to PA 26-100 s.46.

Primary source — cga.ct.gov ↗

CA Canada Bill C-36 — corrected: still at first reading, not second reading

correction logged 9 Sep 2026

The row's status_note stated Bill C-36 (Protecting Privacy and Consumer Data Act, 45th Parliament) was at second reading as of 2026-08-11. The official LEGISinfo record, re-checked today, shows C-36 completed First Reading on 15 June 2026 but Second Reading still shows no activity and Committee has not been reached. The note is corrected to reflect that C-36 remains at first-reading stage awaiting second reading. AIDA itself remains abandoned with no reintroduction.

Primary source — parl.ca ↗

BR Brazil PL 2338/2023 — tramitação date refreshed, no substantive movement

Updated logged 9 Sep 2026

The row cited the latest Câmara dos Deputados tramitação event as 2026-06-17. The live ficha de tramitação now shows a further entry on 2026-09-02, but it is only an apensação notice on an unrelated bill (PL 1542/2026). The bill remains at "Aguardando Parecer do(a) Relator(a) na Comissão Especial" with no opinion presented by rapporteur Dep. Aguinaldo Ribeiro and no plenary vote scheduled.

Primary source — camara.leg.br ↗

Tue 8 Sep 20262 entries
Nicaragua — Ley 1223, the General Telecommunications Law, read in full: no AI or automated-decision provision in 158 articles

Updated logged 8 Sep 2026

The last unread instrument on the Nicaragua row is now read and the gap is closed. Ley N.° 1223, Ley General de Telecomunicaciones Convergentes (approved 31 October 2024, La Gaceta, Diario Oficial N.° 204 of 6 November 2024), was flagged unread because TELCOR publishes it only as a 34-page image-only scan and La Gaceta's edition PDFs sit behind a subscriber login. Normaweb, the Asamblea Nacional's own statute-book database, serves a complete text-indexed rendering, and all 158 articles were read end to end. The count of «inteligencia artificial», «aprendizaje automático», «machine learning», «red neuronal», «algoritmo», «decisión automatizada», «tratamiento automatizado», «perfil», «scoring», «biométrico», «sesgo», «intervención humana» and «revisión humana» across the whole Law is zero. Its only personal-data provision is the classic confidentiality limb: art. 95(10) gives users a right to protection of communications content, associated data and metadata and personal data, art. 101(24) is the mirror-image operator duty subject to a judicial warrant, and art. 140 makes refusal an infracción muy grave — with no automated-decision, human-review, logic-disclosure or profiling limb anywhere. Two dated facts also come out of the reading. Art. 158 commences the Law twelve months after publication, a direct offset from a published date, so it entered into force on 6 November 2025, twelve days before its user-protection normativa AA 007-2025 was gazetted. And art. 156 repeals six instruments outright, including Ley N.° 200 and Decreto Ejecutivo N.° 19-96 — all six of which TELCOR's marco legal page still publishes, so that register is a mixed corpus of live and repealed law. Nicaragua stays at No AI-specific law. Method note that generalises: a regulator serving a statute only as an image-only scan is not evidence the statute is unreadable — check the national statute book, which on Domino-backed portals usually carries a text-indexed copy.

Primary source — legislacion.asamblea.gob.ni ↗

Nicaragua did briefly have an express automated-decision clause — Ley 1241 art. 6, repealed after 115 days

correction logged 8 Sep 2026

Backfilled changelog entry for a row correction that shipped on 8 September 2026 without one. Nicaragua's row has always read No AI-specific law, but it did so on the assumption that no automated-decision rule had ever existed. That assumption was wrong. Ley N.° 1241, Ley de Identificación Ciudadana (approved 27 February 2025, La Gaceta, Diario Oficial N.° 41 of 3 March 2025), provided at art. 6 that the Consejo Supremo Electoral must «preservar el origen de los datos y evitar que las nuevas tecnologías generen decisiones automatizadas que afecten los derechos de las personas» — the only express automated-decision provision ever to appear in Nicaraguan statute law. It bound one public authority in its capacity as national identity registrar, created no duty on any private actor, and vested no right in the data subject: no notification, no explanation, no logic disclosure, no human-review or contestation limb. It is also no longer in force. Ley N.° 1254 (approved 25 June 2025, La Gaceta, Diario Oficial N.° 115 of 26 June 2025) repealed Ley 1241 outright at art. 1 with no savings clause, restored Ley N.° 152, and commenced on publication. The clause therefore had a life of 115 days, from 3 March to 26 June 2025, and the restored Ley 152 consolidated text carries zero automated-decision terms. The row stays at No AI-specific law, but now on evidence rather than on assumption — and the fact that the clause was drafted at all is the strongest available signal that the concept is live for the Nicaraguan legislator. A repeal of this kind is invisible in the repealed text, which still reads as live; only Normaweb's «Observación» footer records it.

Primary source — legislacion.asamblea.gob.ni ↗

Mon 7 Sep 20262 entries
BF Burkina Faso Loi 001-2021/AN — swapped the archive.org fallback for a live official source

Updated logged 7 Sep 2026

The Assemblée nationale du Burkina Faso's own site (an.bf) now serves the full enacted text of Loi n° 001-2021/AN directly, confirming arts. 15, 19 and 31 are unchanged from the previously-cited archived CIL copy. The source_url has been updated from the Internet Archive capture to the live an.bf document; the underlying facts and medium confidence rating (promulgation-decree/Journal Officiel citation still unconfirmed) are unchanged.

Primary source — an.bf ↗

EU EU AI Act Annex I high-risk deferral — corrected the original (pre-Omnibus) application date

correction logged 7 Sep 2026

The row's summary and status_note incorrectly stated that the Digital Omnibus (Reg. (EU) 2026/1744) deferred Annex I product-embedded high-risk obligations 'from 2 Aug 2026'. Article 113 of the base Regulation (EU) 2024/1689 set the original application date for Article 6(1)/Annex I systems at 2 August 2027, not 2 August 2026 (which applied only to Annex III systems under Article 6(2)). The Omnibus moves that 2027 date to 2 August 2028. The row's final date field (2028-08-02) was already correct; only the 'from' date in the prose has been corrected.

Primary source — artificialintelligenceact.eu ↗

Fri 4 Sep 20261 entry
CN China's Anthropomorphic AI Interactive Services Measures — added the specific administrative fine range

correction logged 4 Sep 2026

The CAC's Anthropomorphic AI Interactive Services Measures (effective 15 Jul 2026) specify an administrative fine of RMB 10,000-200,000 for non-compliance, alongside rectification orders and service suspension. The row's max_penalty field previously only referenced generic CAC administrative penalties and has been updated to include this figure.

Primary source — cac.gov.cn ↗

Thu 3 Sep 20261 entry
US Delaware HB 380 signed — the DPDPA's employment-data exemption no longer covers profiling, pulling AI hiring tools into the Act from 1 January 2027

Added logged 3 Sep 2026

Governor Matt Meyer signed House Bill 380 on 2 September 2026. The amendment's employment hook is a single clause. § 12D-103(c)(14) of the Delaware Personal Data Privacy Act had exempted personal data processed «In the course of an individual applying to, employed by, or acting as an agent or independent contractor of a controller, processor, or third party, to the extent that the data is collected and used within the context of that role». The engrossed Act appends to it: «role, except for personal data processed in connection with profiling and reports under § 12D-106(f) of this title.» Employment data is still out of the DPDPA for ordinary HR processing; it is inside the Act the moment the controller profiles on it or turns it into a report. The machinery that clause switches on is new § 12D-106(f). A controller «disclosing to any third party a report for use in connection with any decision that produces legal or similarly significant effects concerning a resident» must contract with that third party for notice of «any adverse action that is based in whole or in part on any information contained in the report», «a description of the personal data relied upon in making the adverse action», a statement of the resident's right to obtain the underlying information from the controller, and a statement that the resident may request the third party «where technically feasible, perform a human review of the adverse action». On request the controller has 30 days to hand over the personal data it holds, «the source of the personal data used in profiling», «identification of all third parties who obtained a report concerning the resident within the previous 24-months», and an opportunity to correct. «Report» is defined for the first time as «any written, oral, or other communication of any personal data by a controller or processor, including recommendations, summaries, or automated decisions based on personal data or profiling», and «decisions that produce legal or similarly significant effects» expressly enumerates «employment opportunities». § 12D-106(g) exempts a score, model or algorithm that is furnished as an FCRA consumer report, so the background-check industry keeps its existing regime and the in-house screener does not. Two threshold moves widen who has to care. § 12D-103(a)(1) strikes 35,000 and inserts 10,000 consumers — the lowest applicability standard of any state privacy law — and the paragraph (a)(2) sale-revenue route drops from 10,000 to 5,000. § 12D-108(a)'s data-protection-assessment trigger falls from 100,000 to 50,000. Separately, the § 12D-104(a)(6)c opt-out strikes «solely-automated» in favour of «automated» decisions, so inserting a human reviewer no longer takes a profiling decision outside the opt-out right. Effective date is taken from the enrolled text rather than from reporting: «Section 2. This Act is effective January 1, 2027.» There are no staggered provisions. Enforcement runs through 6 Del. C. § 2513 and is reserved to the Department of Justice by § 12D-111(e), with wilful violations exposed to $10,000 each under § 2522(b); there is no private right of action, and the cure period has been discretionary since 1 January 2026. Source note: legis.delaware.gov still showed «Passed 6/16/26 / Ready for Governor for action» with an empty Effective Date field and no session-law document on 3 September 2026, so the signature rests on the Governor's own release of 2 September. Several law-firm alerts and the BillDetail synopsis quote a 15,000-consumer threshold; that is the introduced version, superseded by the engrossed text. HB 381, signed the same day, is breach notification only and adds nothing to this dataset.

Primary source — legis.delaware.gov ↗

Wed 2 Sep 20265 entries
Belize added at Proposed — the Data Protection Act 2021 carries a full GDPR art. 22 analogue that has never been brought into force

Added logged 2 Sep 2026

Belize has enacted the CARICOM model automated-decision provision and left it dormant. Section 19 of the Data Protection Act, 2021 (Act No. 45 of 2021, assented 29 November 2021) is headed «Automated individual decision-making, including profiling» and reproduces, word for word, the text already recorded for Barbados s. 18 and Guyana s. 19: «A data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or similarly significantly affects him.» The contract, statutory-authorisation and consent carve-outs sit at s. 19(2)(a)–(c), the safeguarding duty for the contract and consent cases at s. 19(3), and the stricter-than-GDPR sensitive-data rule at s. 19(4) — «Sub-section (2) shall not apply to sensitive personal data unless it is in the public interest and suitable measures to safeguard the data subject's rights and freedoms and legitimate interests are in place» — with no explicit-consent route back in. The supporting machinery is complete on paper. Sections 20(2)(f) and 21(2)(g) require proactive disclosure at collection of «the existence of automated decision-making, including profiling, referred to in section 19 and meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject». Section 63(3)(a) makes a data protection impact assessment mandatory for «a systematic and extensive evaluation of personal aspects relating to individuals which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning an individual or similarly significantly affect the individual». Section 26 requires binding corporate rules to spell the s. 19 right out. Enforcement would run Commissioner's Enforcement Notice under s. 74, then s. 81(1), a fine of BZD 5,000 on summary conviction for failing to comply with it; nothing attaches to s. 19 directly. None of it binds anyone. Section 97(1) reads «This Act comes into force on a day to be appointed by the Minister by Order published in the Gazette», and s. 97(2) permits different days for different provisions. No such Order has been found. The National Assembly's statutory-instrument registers for 2023 and 2024 were read in full and both carry Commencement Orders for other Acts — Extradition, Insurance, Fiscal Incentives, Interception of Communications, Securities Industry, Alternative Sentencing, Movable Property Security Rights — while neither names the Data Protection Act. The 2022, 2025 and 2026 registers are not published in readable form, so this is recorded as «no commencement order found», not «none exists», and the row is held at Proposed pending sight of an Order. Source caveat: on 2 September 2026 nationalassembly.gov.bz, belizelaw.org, attorneygeneral.gov.bz and belize.gov.bz were all unreachable or suspended, and digitalagenda.gov.bz answers 200 with its homepage on every path. The Act text relied on is the National Assembly's own PDF read through the Internet Archive's 14 August 2026 capture of the official URL.

Primary source — web.archive.org ↗

Bahamas added at None — the 2003 Data Protection Act predates the automated-decision right and never acquired one

Added logged 2 Sep 2026

The Data Protection (Privacy of Personal Information) Act (Act 3 of 2003, Chapter 324A of the Statute Law of The Bahamas, consolidation LRO 1/2008) was read end to end on the official Bahamas Laws On-line corpus. The words «automated», «profiling» and «logic» do not appear once in the Act. It is an Irish Data Protection Act 1988 transplant taken before Ireland acquired its own automated-decision section, so the European lineage that produced GDPR art. 22 analogues in Barbados, Belize and Guyana is absent here. The access right at s. 8(1) is where such a limb would sit, and the three things it gives are (a) confirmation «whether the data kept by him include personal data relating to the individual», (b) «a copy of the information constituting any such data», and (c) where the information «is expressed in terms that are not intelligible to the average person without explanation», «an explanation of those terms». Limb (c) is a plain-language duty about the intelligibility of the data disclosed, not a right to the logic of the processing that produced it, and it moves only on a written request that s. 8(3) permits a controller to charge for. Sections 10, 11 and 12 add rectification, a direct-marketing objection and a duty of care with no automation limb, and the Act has no profiling definition, no impact-assessment duty and no notice-at-collection obligation of the GDPR art. 13/14 kind. Unlike Trinidad and Tobago, commencement is not the issue: the Act was assented on 11 April 2003 and the printed head-note records «[Commencement 2nd April, 2007]» under S.I. 25/2007, with no proclamation carve-out — the whole Act is in force and it simply has no rule to offer. Freshness probe, 2 September 2026: the Bahamas Laws On-line point-in-time filter was set to 2026-09-02 and the letter-D acts index returned Chapter 324A as the only data-protection title; the «Tabled in House of Assembly» register was read in full and none of its 2026 bills touches data protection, privacy or artificial intelligence; the «Acts not in force» and «Under consultation» registers return no data-protection title either.

Primary source — laws.bahamas.gov.bs ↗

Trinidad and Tobago added at None — the Data Protection Act has no automated-decision provision, and most of it is not law yet

Added logged 2 Sep 2026

Two independent reasons put Trinidad and Tobago on the tracker without an obligation row. The first is textual. The Data Protection Act, Chap. 22:04 (Act No. 13 of 2011) was read in full across 106 sections in the consolidated text served by the Ministry of the Attorney General and Legal Affairs' Digital Legislative Library, and the words «automated», «automatic», «profiling» and «logic» do not appear once. The closest analogue is the s. 2 definition of «data matching» — «the comparison, whether naturally or by means of any electronic or other device» — which is expressly automation-neutral, and the s. 50 requirement that a public body obtain the Commissioner's written authorisation before matching. That is a proportionality gate on linkage, not a rule about how a decision is reached. The twelve General Privacy Principles in s. 6 contain no human-review, explanation or automation limb. The second is commencement, and it is the same trap that nearly put Jamaica in wrong this morning. Section 1(2) leaves the Act to the President's Proclamation, and both Proclamations were read verbatim. Legal Notice No. 2 of 2012 (Legal Supplement Part B, Vol. 51, No. 1, 5 January 2012) brought into operation on 6 January 2012 only «Part I and sections 7 to 18, 22, 23, 25(1), 26 and 28 of Part II». Legal Notice No. 220 of 2021 (Legal Supplement Part B, Vol. 60, No. 125, 20 August 2021) added «section 42(a) and (b)» from 23 August 2021. Nothing else has ever been proclaimed, and the register's own act record carries the flag «This Act has only been partially proclaimed». Part III (public bodies), Part IV (the private sector, including s. 69, which is what would apply the General Privacy Principles to anyone at all) and Part V (contravention and enforcement) are not in force. The penalties at ss. 95 and 96 — up to TTD 500,000 for a body corporate, and a court fine of up to ten per cent of an enterprise's annual turnover — are unproclaimed and have nothing to attach to. On artificial intelligence there is nothing: the Parliament's publication register holds no AI bill, act or committee paper, and its only data-protection items are the Bills of 2008, 2009 and 2011 and the Act itself. Freshness probe for the negative: every Legal Notice for 2022 through 2026 was enumerated (243, 391, 254, 497 and 681 entries) and none carries a Data Protection title, so no further section has been proclaimed since August 2021.

Primary source — laws.gov.tt ↗

Guyana added at Proposed — a full GDPR art. 22 analogue is on the statute book and no commencement order has ever been made

Added logged 2 Sep 2026

Guyana's Data Protection Act 2023 (Act No. 18 of 2023, Official Gazette Legal Supplement A, 16 August 2023) contains s. 19, «Automated individual decision-making, including profiling», and it is the Barbados Data Protection Act, 2019-29 s. 18 word for word — including the departure from the European original at subsection (4), which disapplies the exception set for sensitive personal data unless the processing is in the public interest with safeguards, dropping the explicit-consent route GDPR art. 22(4) allows. The transparency limb at s. 20(2)(f) is proactive and free, owed at collection: the existence of automated decision-making referred to in s. 19 and «meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject». None of it binds anyone. Section 1 provides that the Act «shall come into operation on the day the Minister may, by order, appoint, and different days may be appointed in respect of different provisions of this Act», and no such order has been made. Every Commencement Order published in the Official E-Gazette for 2023, 2024, 2025 and 2026 was enumerated — fourteen of them — and none relates to the Data Protection Act; a separate sweep for «Data Protection» across the same four years returned ninety-four publications of which only the Bill and the Act are on point. The sharpest evidence is the sibling statute: the Digital Identity Card Act 2023 was passed on the same day and gazetted in the same supplement as Act No. 19 of 2023, and it was brought into force by Order No. 73 of 2026 on 26 March 2026 — while the data-protection Act was left uncommenced. When the order comes, the penalty position will mirror Barbados. Section 99(1) confines the Commissioner's administrative penalty of up to GYD 10,000,000 by name to ss. 53(1), 59(1) and 62-69, so s. 19 sits outside it and runs instead through a s. 78 enforcement notice with the s. 85(1) offence behind it — GYD 1,000,000 or three months on summary conviction. Freshness probe: the gazette index was current to the Official Gazette of 29 August 2026 when checked. Watch item: the commencement order must be read for its enumerated section list, not its date, because s. 1 expressly permits different days for different provisions.

Primary source — parliament.gov.gy ↗

JMBB Jamaica and Barbados added — the first two Anglophone Caribbean rows, and two different answers to the same question

addition logged 2 Sep 2026

Not one Anglophone or Dutch/French Caribbean state had a row on the tracker before today. The first two are in, and they are worth reading side by side because they were drafted from different parents. Barbados is a GDPR transplant. Section 18 of the Data Protection Act, 2019-29 reproduces art. 22 nearly verbatim — a standing right not to be subject to a decision based solely on automated processing, including profiling, with contract, statutory-authorisation and consent exceptions at s. 18(2) and a suitable-measures duty at s. 18(3). It then goes further than the European original at s. 18(4), which disapplies the whole exception set for sensitive personal data unless the processing is in the public interest with safeguards in place. GDPR art. 22(4) allows explicit consent there; Barbados does not. The logic-disclosure limb is proactive, owed at collection under ss. 19 and 20 without a request and without a fee. Jamaica is a United Kingdom Data Protection Act 1998 transplant and behaves quite differently. Section 12 of the Data Protection Act, 2020 is a notice-based right, not a prohibition: nothing bars a solely-automated significant decision until the data subject serves a s. 12(2) written notice. What Jamaica adds, and what the 1998 Act never had, is s. 12(3) — where no notice has been served, the controller must inform the individual as soon as reasonably practicable that the decision was made on a solely-automated basis, and the individual then has thirty days to require reconsideration. That is an unconditional controller-side disclosure duty on every qualifying decision. The exemptions at s. 12(7)-(8) are cumulative and, unusually, contain no consent limb at all. The separate logic right at s. 6(2)(d) is chargeable — payable «upon payment of the prescribed fee». Penalties were traced by article number rather than assumed, and in both jurisdictions the automated-decision section carries no penalty of its own. In Barbados the s. 95(1) administrative fine is confined by name to ss. 52(1), 57(1) and 60 to 67, so s. 18 is reached only through a s. 75 enforcement notice, disobedience of which is a BBD 15,000 offence under s. 83(1). In Jamaica the s. 12(5) Commissioner's order to retake the decision is the primary remedy; the enforcement-notice offence at s. 52(4) is JMD 1,000,000, and s. 68(1) puts a four-per-cent-of-worldwide-turnover ceiling over any offence committed by a body corporate. Both rows are published at medium confidence, and for the same kind of reason in each case: the substantive text is verified verbatim against the Act, and the commencement instrument is not. Jamaica's first Appointed Day Notice of 30 November 2021 was read in full and appointed only ss. 2, 4, 56, 57, 60, 66, 74, 77 and the First Schedule — section 12 was not among them, so any source dating this obligation to 2021 is reading the wrong notice. The second notice, which the regulator lists as taking effect 1 December 2023 and which matches the s. 76 two-year transition, is a JBIG2 image scan that could not be read here. Barbados's March 2021 proclamation is likewise not exposed in reachable form. Each row names the specific document that would move it to high confidence. The rest of the region — Trinidad and Tobago, Guyana, the Bahamas, Belize, Suriname, Haiti and the OECS states — remains open and is tracked as a coverage gap.

Tue 1 Sep 20264 entries
GA Gabon's Ordonnance 0011/PR/2026 re-read against the gazette text — the AI-content labelling duty is deferred to April 2027, not in force, and no penalty attaches to the deepfake prohibitions

correction logged 1 Sep 2026

The Gabon AI-content row added earlier on 1 September 2026 rested on secondary legal commentary because the official gazette host journal-officiel.ga was unreachable. A complete scan of Journal Officiel de la République Gabonaise n° 110 (8-15 avril 2026), pages 135 to 141, has now been read and the row was wrong in two ways. First, the ordonnance's Chapitre VII on AI-generated content, arts. 32 to 34, contains no labelling duty. Art. 32 prohibits four classes of AI-generated content, art. 33 creates a right of report with a 24-hour takedown, and art. 34 gives the Haute Autorité de la Communication and the Ministère Public an audit power over detection and marking systems. The labelling mandate is art. 53, in Chapitre XI, «Des dispositions transitoires, diverses et finales», and every platform editor has «un délai de douze mois à compter de la publication de la présente ordonnance» to deploy automatic AI-content detection, apply a visible, clear and permanent origin marking, verify age on new registrations and hand origin metadata to the Authority within eight days. That is a future deadline of 8 April 2027, and it is now a separate row at lifecycle dateset rather than an obligation recorded as binding since April 2026. Second, the «fines up to 50 million FCFA» the press attributed to the AI provisions belong to arts. 45, 46 and 48, which punish identity-information failures and the general duty to combat illicit content. No penal article reaches arts. 32, 33, 34 or 53. The only AI-specific penalty in the ordonnance is the closing paragraph of art. 52, which raises identity usurpation committed by means of an artificial intelligence from five years and 20 million FCFA to ten years and 50 million FCFA; enforcement of art. 32 itself runs instead through the référé numérique of arts. 39 to 44, whose measures art. 43 expires automatically if no proceedings on the merits start within one month. Structure confirmed: 55 articles, 11 chapters, signed at Libreville 26 February 2026. The gazette issue is dated as a week rather than a day, so both the publication date and the derived April 2027 deadline carry a seven-day range and both rows are held at medium confidence for that reason.

Guatemala added at status Proposed — no data-protection statute at all, no AI bill in the Congress register, and one pending bill that carries a full GDPR art. 22 analogue

Added logged 1 Sep 2026

Guatemala was untracked and is now on the map at status Proposed. It has no AI-specific law, no adopted national AI strategy and no general personal-data-protection statute, so nothing binding is tracked today. The Congress's own «Listado iniciativas a 01-09-2026» — 500 iniciativas conocidas por el Pleno, 16 November 2022 to 25 August 2026, registro numbers 5600 to 6831 — returns «inteligencia artificial» zero times and «algoritmo» zero times, so there is no artificial-intelligence bill in it. Three general data-protection bills are alive in it at once and all three texts were read from the Congress's own PDF service. Iniciativa 6464, Ley de Protección de Datos Personales y Garantía de Derechos Digitales (received by the Dirección Legislativa 29 October 2024, conocida por el Pleno 5 December 2024, Comisión de Asuntos de Seguridad Nacional, no dictamen), is the one that matters: art. 22 «Prohibición de decisiones automatizadas» is a verbatim GDPR art. 22(1) shape including profiling, art. 23 «Intervención humana» adds the right to human intervention, to express a point of view and to contest the decision, and the rights catalogue adds a «derecho a la transparencia en algoritmos» covering the logic used and the possible consequences. Its enactment would give Guatemala its first automated-decision obligation. The other two carry no such rule — Iniciativa 6572 (conocida 5 August 2025) uses «automatizado» only definitionally, and Iniciativa 6105 (conocida 18 January 2023), which is the furthest advanced with a favourable dictamen of 12 April 2023, has zero «algoritmo» and zero «perfil». Guatemala's own executive describes the same gap: writing in the official gazette, the Secretario Nacional de Ciencia y Tecnología lists «promulgar una ley de protección de datos personales» among the five urgent actions the UNESCO Readiness Assessment report identifies, alongside adopting the AI strategy and institutionalising an AI authority; the Estrategia Nacional de Inteligencia Artificial is a three-phase co-creation on the Government's participation platform whose roadmap and governance-framework phase runs to 30 October 2026. Recorded limitation: congreso.gob.gt answers ordinary HTML requests with an Incapsula challenge, and the widely reported Iniciativa 6657 (PRODIGI, deepfake criminalisation) does not appear in the register at all while its neighbours 6656 and 6658 do — it is not relied on for this status.

Primary source — congreso.gob.gt ↗

Honduras added at status None — no AI act, no AI bill, no national AI strategy and no personal-data statute at all

Added logged 1 Sep 2026

Honduras was untracked and is now on the map at status None. It has no AI-specific law, no AI bill before the Congreso Nacional, no adopted national AI strategy and no general personal-data-protection statute, so there is no automated-decision, profiling or logic-disclosure rule of any kind to track. Data protection reaches Hondurans only through the constitutional hábeas data guarantee and the confidential-data provisions of the Ley de Transparencia y Acceso a la Información Pública (Decreto 170-2006), both access-and-correction guarantees with no automation trigger and no human-review limb. The IAIP's own Anteproyecto de Ley de Protección de Datos Personales y Acción de Hábeas Data has been before the Congreso Nacional for years without being enacted and was still being socialised with deputies in 2024-2025; the IAIP portal that serves it answers HTTP 403 to this host, so no claim is made about its contents. On the El Salvador lesson — that the automated-decision duty can sit entirely outside the data-protection law — there is no candidate AI statute either: what the Executive has published is programme activity, an IDB-supported AI tool for reviewing trámites and the Talent Up Honduras scholarship programme, not norm-making. Recorded limitations, because this is a negative finding: the Congreso Nacional's expediente register became partly machine-readable this session and returns live counts for the 2026 legislature (575 expedientes activos, 66 aprobados, distributed 468 Iniciativa / 66 Aprobado / 36 EnDebate / 5 EnComisión) plus the ten most recent projects, newest dated 2 June 2026, but it exposes no title search and no per-expediente detail route and the upstream API host requires a bearer token, so the 641 project titles cannot be swept; the ENAG gazette register at consulta.enag.gob.hn does not resolve from this host; and the Poder Judicial's CEDIJ legislation library is a SharePoint single-page application with no server-rendered list.

Primary source — congresonacional.hn ↗

GA Gabon — first AI-specific instrument added: AI-content labelling and deepfake prohibitions

Added logged 1 Sep 2026

A daily coverage sweep found that Gabon's Ordonnance n° 0011/PR/2026 du 26 février 2026, on social-network and digital-platform use, published in Journal Officiel n° 110 (8-15 April 2026), predates the tracker's last Gabon check and adds a chapter on AI-generated content: a labelling duty for AI-generated content and a prohibition on deepfakes that harm human dignity, manipulate public opinion, or are used for identity usurpation. This is separate from, and does not amend, the existing data-protection automated-decision rule at Loi n° 025/2023 art. 77 (ga-loi0252023-art77). The official gazette listing confirms the ordinance's number and date; the substantive description is corroborated by independent secondary legal commentary, since the gazette PDF could not be machine-read this session — exact article numbers and the full penalty structure remain to be verified against the primary text directly.

Primary source — journal-officiel.ga ↗

August 2026115 entries
Nicaragua added at status None — no AI instrument anywhere in a 42,508-norm corpus, and a data-protection law in which «decisión» appears zero times

Added logged 31 Aug 2026

Nicaragua was untracked and is now on the map at status None. Ley N.° 787, Ley de Protección de Datos Personales, approved 21 March 2012 and published in La Gaceta, Diario Oficial N.° 61 of 29 March 2012, was read end to end in the consolidated Akoma Ntoso rendering served by the Digesto Jurídico Nicaragüense, the Asamblea Nacional's own legal corpus. Its art. 56 commences it on publication, so there is no term to reckon. The Digesto's «Normas Relacionadas» view shows exactly one affecting act in fourteen years — a Fe de Erratas of 28 August 2012 — and no amending act, so the text read is the text in force; the implementing Decreto N.° 36-2012 (La Gaceta N.° 200, 19 October 2012) was read in the gazette issue itself. The negative is the cleanest in the atlas: «perfil», «valoración», «algoritmo» and «decisión» each appear zero times in the Law and zero times in its Reglamento, and «automatizado» appears five times, every one of them in art. 1's object clause or in the art. 3 definitions of datos personales informáticos, ficheros de datos and tratamiento de datos. There is no Directive 95/46 art. 15 prohibition, no GDPR art. 22 analogue, no impugnación de valoraciones of the Spanish LOPD art. 13 kind that Uruguay, Ecuador and Panama carry, and not even the profiling-for-marketing opposition limb that El Salvador and the Dominican Republic have. Two features are worth recording anyway. Art. 10, «Derecho al olvido digital», is original 2012 text and lets a data subject require social networks, browsers and servers to delete personal data in their files, and require any provider that collected data under a contract to erase everything held once the relationship ends — a statutory digital right to be forgotten more than two years before Google Spain and four years before GDPR art. 17, and the earliest of its kind in the atlas. And there are no fines: art. 46 gives the Dirección de Protección de Datos Personales only apercibimiento, suspension of the processing operations, and temporary or definitive closure or cancellation of the files, with no monetary band anywhere. On artificial intelligence the country is empty. The Digesto's title index holds 42,508 instruments and returns zero for «inteligencia artificial»; the full-text search returns exactly one instrument in the whole corpus, Ley N.° 1243 of 26 March 2025 reforming the Código de Organización, Jurisdicción y Previsión Social Militar, whose two mentions are grants of capability to the Army — art. 4(14) on air and maritime surveillance «con el empleo de tecnología moderna e inteligencia artificial» and art. 31 on the Cuerpo de Transmisiones — not duties on anyone. The corpus was freshness-probed rather than assumed current: 490 instruments carry 2026 publication dates and the newest indexed publication is 28 August 2026, a three-day lag, so the negative is firm to the day of check.

Venezuela added at status Proposed — the AI bill passed first discussion in 2024 and is named in the 2026-2027 legislative programme, and there is no data-protection statute behind it

Added logged 31 Aug 2026

Venezuela was untracked and is now on the map at status Proposed. The Asamblea Nacional approved the Proyecto de Ley de Inteligencia Artificial in first discussion, unanimously, on 19 November 2024 — the same sitting at which the Comisión Permanente de Educación, Salud, Ciencia, Tecnología e Innovación formally received it. The bill was presented by deputy José Villarroel, runs to 57 articles in four chapters, and on the Assembly's own account classifies the risks of artificial intelligence into low, medium, high and unacceptable levels. On 12 February 2025 the commission announced a public consultation on the text. No second discussion has been taken and nothing has reached the Gaceta Oficial, so no obligation is tracked. What keeps this off a stale-bill reading is the Plan Básico Legislativo 2026-2027, approved by qualified majority on 22 January 2026 under art. 68 of the Reglamento Interior y de Debates: its published list of twenty-nine bills for the period names «la Ley de Inteligencia Artificial» explicitly, alongside the Ley de Ciberseguridad, the Ley de Derechos Digitales and the Ley de Telecomunicaciones. There is no automated-decision rule to fall back on either: Venezuela has no general personal-data statute, and the protection rests on art. 28 of the Constitution — access to one's own data in public and private registers and correction or destruction of erroneous entries — which carries no automation trigger, no human-review limb and no logic-disclosure limb. One limitation is recorded on the row rather than glossed: the Assembly's «Leyes vigentes», «Sancionadas» and «Proyectos» registers answer HTTP 403 to any request carrying a query string, so the title filter and pagination are unreachable from this host and the registers could not be enumerated end to end; the tsj.gob.ve Gaceta Oficial mirror does not resolve either. The findings rest on the Assembly's own published record of the sittings and of the legislative programme, which is primary but is not a corpus sweep.

SV El Salvador added — a comprehensive AI law in force since March 2025, and a registration deadline three days away

new logged 31 Aug 2026

El Salvador enters the tracker at «comprehensive», the second jurisdiction in the Americas after Peru to have an AI-specific statute in force. The Ley de Fomento a Inteligencia Artificial y Tecnologías (D.L. N.° 234, D.O. N.° 43, Tomo 446, 3 March 2025, in force 12 March 2025, reformed by D.L. N.° 363 of 16 July 2025) is a promotion statute whose art. 18 nonetheless carries a hard automated-decision duty: anyone using AI commercially or for access to rights or services must disclose that the decision was taken or driven by AI, explain it, and provide a route to contest it before a competent natural person. It is the only automated-decision rule on the tracker that lives entirely outside its country's data-protection law — El Salvador's Ley para la Protección de Datos Personales (D.L. N.° 144, 15 November 2024) has no such article at all. ANIA Resolución N.° 0001/2025 (D.O. 25 August 2025, in force 3 September 2025) adds the operative regime: mandatory registration, an algorithmic impact assessment and a chosen compliance route for operators whose AI is the controlling factor in consequential decisions in health, credit and insurance, public-space biometrics, government powers and benefits, employment, and education and licensing; plus an art. 24 notification duty owed by every entity, registered or not, for adverse automated decisions in seven areas. Art. 29 gave systems already running on 3 September 2025 twelve months to register — that period expires on 3 September 2026, three days from now. Nothing in the stack carries a fine: art. 28 confines ANIA to graduated guidance, notice, compliance order and referral.

Bolivia has a third pending AI bill, not two — PL N° 288/2025-2026, hidden from the register's own rendered pages

Updated logged 31 Aug 2026

A watch poll of the Chamber of Deputies' bill register found a third AI bill alive alongside the two already recorded. PL N° 288/2025-2026 «Proyecto de Ley que regula el desarrollo, la implementación y utilización de los sistemas de inteligencia artificial» was posted to the «Proyectos de Ley en Tratamiento» register on 11 March 2026 — one week before PL N° 310/2025-2026 — and serves a 27-page scan. It was missed on the first pass because the register's rendered bill page shows only the bill number: the subject line exists solely in the record store's «descripcion» field, so the string «inteligencia artificial» appears nowhere in the page HTML and no text search of the rendered register can find it. Querying the record store directly surfaces it. All three bills — PLS N° 178/2024-2025 «en Revisión», PL N° 288 and PL N° 310 «en Tratamiento» — are referred to the same committee, the Comisión de Planificación, Política Económica y Finanzas, so they are competing vehicles rather than parallel tracks. PL 288's PDF is the same PaperStream scanner output as the other two, with an image layer and no fonts, so nothing is asserted about its substance. Bolivia's status is unchanged: no AI law is promulgated, the Gaceta Oficial still returns zero norms for «inteligencia artificial», and no bill has reached «Aprobado», «Sancionado» or «Ley Promulgada». The row stays at «proposed» with no date; only the bill count and the committee finding change.

Bolivia added at «proposed» — no AI law, no data-protection statute, and two rival AI bills pending in the Chamber of Deputies

Added logged 31 Aug 2026

Bolivia was untracked. It has no AI-specific law in force and no general personal-data-protection statute, so it carries no automated-decision or profiling rule at all — the position that Belarus holds in Europe. The Gaceta Oficial's search over its published-norms corpus returns zero norms for «inteligencia artificial», «algoritmo» and «perfilamiento», and a single 1969 Decreto Supremo for «datos personales»; the Chamber of Deputies' «Leyes Promulgadas» register carries no AI law either. AGETIC's Anteproyecto de Ley de Protección de Datos Personales remains a draft. What the Deputies' own bill register shows, and what no secondary account of Bolivia reports, is that two distinct AI bills are alive there simultaneously: the Senate-origin PLS N° 178/2024-2025 «Promoción, Gestión y Uso de la Inteligencia Artificial», listed «en Revisión» for 2026, and the Deputies-origin PL N° 310/2025-2026 «Ley General de Inteligencia Artificial», listed «en Tratamiento» and scanned on 18 March 2026, which succeeds an archived PL N° 558/2024-2025 of the same title. The register shows PLS 178 both «en Revisión» (2026) and «Archivado» (2025); that is not a conflict but two records in two legislative gestiones, the archived 2025 entry carrying no PDF and the live 2026 entry carrying the scan — the same archive-and-reintroduce pattern the register shows for PL 558 → PL 310. Both bill PDFs are scanner output with no text layer, so neither bill's substance has been read against a machine-readable primary text and none of it is asserted. The row is «proposed» and carries no date.

Primary source — diputados.gob.bo ↗

PY Correction — Paraguay's Ley 7593/2025 first applies on 28 November 2027, not 27 November 2027

correction logged 31 Aug 2026

Ley N° 7593/2025 names no commencement date; art. 57 says only that it «entrará en vigor luego de transcurridos veinticuatro meses de su publicación oficial», and publication was 27 November 2025. The row was published with 27 November 2027. Art. 342 of the Código Civil (Ley N° 1183/1985) applies arts. 337 to 341 of that Code to every plazo fixed by statute unless the statute provides otherwise, art. 339 ends a plazo in months on the same-numbered day of the final month, and art. 341 makes every plazo continuous and complete and has it end at midnight of the last day. The twenty-four months therefore expire at the midnight ending 27 November 2027, and art. 57's «luego de transcurridos» puts the first day of application on 28 November 2027; a stricter dies a quo reading would put it on 29 November 2027, which the row records as an alternative. Nothing else about the entry changes.

Primary source — bacn.gov.py ↗

PY Paraguay added — Ley 7593/2025 art. 33, an LGPD-style right to request review that also catches SEMI-automated decisions, in force 27 November 2027

Added logged 31 Aug 2026

Paraguay was untracked. Ley N° 7593/2025 «De Protección de Datos Personales en la República del Paraguay» was sanctioned by the Cámara de Senadores on 5 November 2025 and promulgated and published on 27 November 2025, and art. 57 gives it a twenty-four-month vacatio legis, so it applies from 27 November 2027. The text was read in the official record of the Biblioteca y Archivo del Congreso Nacional. Art. 33 is not the GDPR art. 22 prohibition that secondary summaries report: it grants a right to SOLICITAR LA REVISIÓN of a decision taken on the basis of automated processing, on the Brazilian LGPD art. 20 pattern, together with rights to express a point of view and to contest the decision. Three features are unusual. It reaches «semiautomatizadas» decisions and carries no «únicamente» qualifier, so a human in the loop does not take a decision outside the rule as it does in Panama, Uruguay and the rest of the Directive 95/46 family. Its trigger is disjunctive — decisions that «afecten negativamente a sus intereses» or that «produzcan efectos jurídicos» — and the first limb carries no significance threshold at all, making it the lowest automated-decision trigger in the atlas; the DPIA duty at art. 14 keeps the GDPR significance test that art. 33 drops, so the right is broader than the assessment that is supposed to anticipate it. And the explanation duty's trade-secret carve-out is drafted as «secretos comerciales e industriales del titular» — the data subject's secrets, not the controller's — inverting the LGPD reservation it was copied from and, read literally, leaving the controller almost no ground to withhold the logic. Enforcement runs only through the residual catch-all at art. 44 in fine, since neither the faltas leves nor the faltas graves list names the automated-decision right, both stopping at access, rectification, erasure, restriction and portability; that makes refusal a falta leve prescribing in one year, within the art. 46 band of 20 to 2,500 jornales mínimos (5,000 for sensitive data, 10,000 for children's sensitive data). The regulator created by art. 34, the Agencia Nacional de Protección de Datos Personales inside the MITIC, does not exist yet, and art. 60 gives the Executive until the same November 2027 date to issue the reglamento.

Dominican Republic added at status Proposed — Ley 172-13 has no automated-decision rule, and the atlas's only profiling clause that permits rather than restricts

Added logged 30 Aug 2026

The Dominican Republic was untracked. It is now on the map at status Proposed, and the substantive finding is that its data-protection statute contains no automated-decision rule at all — the second Latin American statute in the atlas to omit the Directive 95/46 art. 15 shape entirely, after Costa Rica. Ley No. 172-13 (Gaceta Oficial No. 10737 of 15 December 2013) was read end to end in three independent primary renderings — the Consultoría Jurídica del Poder Ejecutivo's copy in the Executive's official corpus, the Presidencia's marco legal PDF and the Cámara de Diputados' file — all returning identical term counts. «Valoración» appears nowhere; «automatizado» appears six times and every one is scope or definitional; the rights articles, arts. 7 to 16, give consultation, access, rectification, cancellation, opposition, blocking and compensation and stop there. No right against a solely automated decision, no human review, no explanation of the logic. What makes this row distinctive is the inversion. Profiling appears exactly once in the Law and appears as a permission: art. 71 affirmatively authorises processing data «aptos para establecer perfiles determinados con fines promocionales, comerciales o publicitarios» from public sources or with consent, subject only to free access and a right to be removed. Every other profiling clause in the atlas restricts; this one licenses. And art. 6(28) gives the atlas's only statutory definition of algorithmic credit scoring — «puntaje de crédito», a methodology of probabilistic, mathematical and econometric models run through «programas informáticos especializados» to inform «la toma de decisiones crediticias» — with no constraint attached to its use. There is no general data-protection authority either: the only supervisor named is the Superintendencia de Bancos, and only over credit bureaus. Supersession and coverage were checked against the complete Consultoría Jurídica index: of 12,497 Leyes indexed from 1918 to date exactly one is titled on personal data and none names «172-13» or «inteligencia artificial», so the Law stands unamended and there is no AI statute; of 749 Reglamentos none concerns data protection, so unlike Panama — whose profiling rule lives only in its reglamento — Ley 172-13 has never been given one. The sectoral regulator was checked on the same footing and came back negative: Circular SB CSB-REG-2026000010 of 8 May 2026, the Superintendencia's Instructivo on the SIC, never mentions artificial intelligence, algorithms, profiles or scoring, reproduces the art. 6(28) definition verbatim and adds no rule on how a score may be produced. The row is Proposed rather than None because binding AI law is pending. A sweep of all 77,835 Decretos returns two instruments naming artificial intelligence, neither creating a duty: Decreto núm. 498-23 (G.O. No. 11124, 13 October 2023) approving the Estrategia Nacional de Inteligencia Artificial to 31 December 2030, and Decreto núm. 113-26 (G.O. núm. 11233, 2 March 2026) declaring digital exchange ports and AI-related submarine cables a national priority. In the Senate the «Proyecto de ley orgánica que regula los sistemas de inteligencia artificial», filed by Senator Omar Fernández, has been before the Comisión de Educación Superior, Ciencia y Tecnología since 22 April 2025 and was still under comparative review on 26 May 2026; Procompetencia issued a formal recommendations report on that file, 00495-2025-PLO-SE, on 12 March 2026. Nothing adopted, so no obligation is tracked.

Costa Rica added as “no AI-specific law” — the first Latin American data-protection statute in the atlas with no automated-decision rule at all

Added logged 30 Aug 2026

Costa Rica was untracked. It is now on the map as a verified “no AI-specific law” row, the fourth such row after Belarus, Armenia and Turkmenistan and the first in Latin America. Ley N° 8968 «Protección de la persona frente al tratamiento de sus datos personales» (La Gaceta N° 170, 5 September 2011; rige a partir de su publicación) was read end to end twice — in the Imprenta Nacional gazette PDF and in the Procuraduría General's SINALEVI consolidated text, which stamps it «Versión de la Norma: 1 de 1», so it has never been amended in fifteen years. Its 34 articles contain no automated-decision rule: art. 7 gives access, rectification, supresión and consent to cession and stops there, and «decisión automatizada», «perfil» and «valoración» appear nowhere. That is the finding. Costa Rica is the first Latin American data-protection statute in the atlas to omit the Directive 95/46 art. 15 shape entirely — Uruguay art. 16, Ecuador art. 20 and Panama art. 19 each carry one — and it omits it while being built throughout on the phrase «tratamiento automatizado o manual»: automation-aware in scope, automation-blind in remedy. The Reglamento (Decreto Ejecutivo N° 37554-JP, current consolidated version as amended by Decreto N° 40008 of 19 July 2016) adds nothing; it defines automated processing in art. 2(y) and leaves it there, unlike Panama's reglamento, which is the only place profiling appears in that country's regime. Costa Rica has adopted no AI statute and no binding AI norm of general application: a full-text SINALEVI sweep for «inteligencia artificial» returns 86 in-force instruments with not one Ley among them, and the only three that name AI in their titles are Poder Judicial circulars binding the judiciary internally. Sweeps for «decisiones automatizadas» return three internal-governance instruments and no rights or duties. The Asamblea Legislativa's bill system was unreachable throughout this check, so no claim is made about AI bills in procedure; SINALEVI indexes adopted normativa only. Nothing to track.

PA Panama added — the only automated-decision right in the atlas that fires solely on NEGATIVE legal effects

new logged 30 Aug 2026

Art. 19 of Ley 81 de 26 de marzo de 2019 «Sobre Protección de Datos Personales» has been in force since 29 March 2021 and is now tracked. It is built on Directive 95/46 art. 15 rather than GDPR art. 22 — solely automated, plus an object requirement that the decision be one evaluating personal aspects, plus an effect — but it does two things to the effect limb that nothing else in the atlas does. It qualifies legal effects as «negativos», so a wholly automated decision in the subject's favour never engages the right; and instead of «similarly significantly affects» it requires «un detrimento a un derecho». Three exits follow — consent, contract or legal relationship, authorisation by special law — and nothing is attached to any of them: no human intervention, no right to express a view, no right to contest, no sensitive-data bar. It is the barest provision of its family here. Profiling is not in the statute at all; it arrives only in the reglamento, Decreto Ejecutivo Nº 285 de 28 de mayo de 2021, which speaks of «decisiones automatizadas, incluida la elaboración de perfiles, a que se refiere el artículo 19» and also grafts on the GDPR's «información significativa sobre la lógica aplicada» disclosure that the legislature never enacted. The penalty is the striking part: art. 36 caps ANTAI's fines at ten thousand balboas, about USD 10,000, with no turnover alternative — the lowest absolute ceiling in the atlas. Both the Law and its reglamento were read in the gazette itself, Gaceta Oficial Digital Nº 28743-A of 29 March 2019 and Nº 29296-A of 28 May 2021, whose page scans had to be pulled out of the PDFs as images. Panama has no AI statute; Proyectos 588 and 413 are before the Asamblea Nacional and neither has been enacted.

Primary source — gacetas.procuraduria-admon.gob.pa ↗

EC Ecuador's AI rulebook has been in force since 10 March 2026 — the missing gazette citation is Registro Oficial Nº 240

Updated logged 29 Aug 2026

Resolución Nº SPDP-SPD-2026-0009-R was added earlier today at lifecycle proposed with no date, because its Disposición Final ties entry into force to publication in the Registro Oficial and no gazette citation for it could be produced. The citation has now been found: Registro Oficial Año I Nº 240 of Tuesday 10 March 2026, an ordinary edition, 57 pages, where the norm runs from page 49 to page 56. The gazette text was read in full against the signed copy on the SPDP's own site and is the same instrument — ten articles, the developer/deployer/distributor/implementer taxonomy in art. 2, the same Disposición Final and signature block — so the row moves to force dated 10 March 2026 and rejoins the in-force count. What closed the gap was the gazette's own site search at registroficial.gob.ec, which had returned nothing usable earlier; neither the SPDP's publication page nor its three later 2026 resolutions, all re-checked today, carries the citation.

Primary source — esacc.corteconstitucional.gob.ec ↗

EC Ecuador joins the atlas — LOPDP art. 20, the only automated-decision right that drops «solely»

Added logged 29 Aug 2026

Art. 20 of the Ley Orgánica de Protección de Datos Personales (Quinto Suplemento del Registro Oficial Nº 459, 26 May 2021) has been binding since publication. Its title and operative sentence both read «una decisión basada única o parcialmente en valoraciones automatizadas» — wholly OR PARTLY automated — making it the only rule in the atlas without the «solely» limb that the rest of the GDPR art. 22 family turns on, and the effects threshold is widened alongside it to legal effects or infringement of fundamental rights and freedoms. Against that breadth sit four exits rather than three, the extra one being a de minimis exit for decisions with no serious impact or verifiable risk, plus a bar on advance waiver through mass adhesion contracts and a separate automated-decision article for children (art. 21). Verified against the scanned gazette, which lists five lettered entitlements a) to e) where the circulated commercial edition folds the fifth into the fourth.

Primary source — asambleanacional.gob.ec ↗

EC Ecuador's data-protection regulator has signed an AI rulebook — SPDP-SPD-2026-0009-R, tracked pending gazette publication

Added logged 29 Aug 2026

Resolución Nº SPDP-SPD-2026-0009-R, signed 12 February 2026, issues a general norm on personal data in AI systems: information, risk-management and impact-assessment, security, register-of-processing and audit duties binding on anyone who develops, trains, implements, deploys or supplies an AI system processing Ecuadorian subjects' data, regardless of where the system or supplier sits, under a four-role taxonomy of developer, deployer, distributor and implementer. There are no risk tiers, no prohibited-practices list and no conformity assessment, and breaches route to the LOPDP's existing 0.1%–1%-of-turnover tariff. It takes effect on publication in the Registro Oficial; no gazette number or date for it could be located as of 29 August 2026, so no in-force date is asserted and the row is held out of the in-force count and the deadline feeds.

Primary source — spdp.gob.ec ↗

UY Uruguay art. 16 — the «names the software» claim narrowed now that Ecuador is tracked

correction logged 29 Aug 2026

The Uruguay entry stated that no other instrument in the atlas names the software itself as the object of an explanation duty. Art. 20(c) of Ecuador's LOPDP, added today, entitles a challenger to «los criterios de valoración sobre el programa automatizado» — the valuation criteria bearing on the automated program. The claim has been narrowed to what still holds: Uruguay's art. 16 para. 3 reaches the program itself and not only the criteria about it.

Primary source — impo.com.uy ↗

UY Uruguay joins the atlas — art. 16 of Ley 18.331, an automated-decision right that a Budget Act narrowed into shape

Added logged 29 Aug 2026

Art. 16 of Ley Nº 18.331 (Diario Oficial of 18 August 2008) has been binding since 28 August 2008 and is the oldest automated-decision rule tracked in Latin America. As enacted it covered decisions based on «un tratamiento automatizado o no de datos» — automated processing or not — the same automation-blind shape Armenia still has; art. 152 of Ley Nº 18.719 of 27 December 2010 deleted «o no» and, in the same stroke, deleted a paragraph under which a data-based assessment of conduct could have evidentiary value only at the affected person's request. The surviving rule has a cumulative trigger where the GDPR's is alternative — legal effects AND significant effect — no exits of any kind, and an explanation duty that reaches «el programa utilizado en el tratamiento», the program used in the processing: the only instrument in the atlas that makes the software itself the object of the duty rather than the logic involved. Art. 35 sanctions any violation of the Law up to 500,000 UI, an inflation-indexed ceiling, without an article-number list, so art. 16 is fully covered. Both the consolidated and the originally enacted texts were read on IMPO. Uruguay has no AI-specific statute imposing obligations; arts. 74 and 75 of Ley Nº 20.212 (2023) mandate AGESIC and the URCDP to build a national AI strategy and a sandbox, and are not tracked as obligations.

XK Kosovo joins the atlas — art. 21 of Law 06/L-082, GDPR art. 22 with a broader trigger and no fine on the right itself

Added logged 29 Aug 2026

Art. 21 of Ligji Nr. 06/L-082 për Mbrojtjen e të Dhënave Personale (Gazeta Zyrtare e Republikës së Kosovës, Nr. 6, 25 February 2019) has been binding since the Law entered into force on 12 March 2019, and it completes the Western Balkans set. It is GDPR art. 22 in its exits, its safeguards and its special-categories bar, but its trigger omits both qualifiers the GDPR uses: art. 21(1) reaches a solely automated decision that produces «efekte» concerning the data subject or similarly affects them, with neither «ligjore» (legal) nor «ndjeshëm» (significantly) in the sentence, while art. 35(3.1) of the same Law and art. 8 of the repealed 2010 Law both carry the complete formula. Enforcement is asymmetric: art. 92 lists the finable breaches by article number and art. 21 is absent, so the substantive right has no dedicated penalty — the art. 12 and art. 14 transparency limbs that disclose it do, at €20,000–€40,000 — and art. 105's serious-and-large-scale catch-all, €20,000–€40,000 or 2% to 4% of annual turnover, is what reaches the decision rule. Kosovo has no Law Enforcement Directive act and no AI-specific statute.

Primary source — gzk.rks-gov.net ↗

BA Bosnia and Herzegovina joins the atlas — arts. 24 and 67 of the new ZZLP, applicable since 4 October 2025, replacing a pre-GDPR prohibition and raising the private-controller ceiling roughly eight-hundredfold

Added logged 28 Aug 2026

Bosnia and Herzegovina joins the atlas on the strength of a law that only became applicable on 4 October 2025 and that replaced a pre-GDPR prohibition of exactly the shape the atlas recorded for Montenegro yesterday. The Zakon o zaštiti ličnih podataka («Službeni glasnik BiH» broj 12/25) was adopted on 30 January 2025, published on 28 February 2025, entered into force on 8 March 2025 and applies from 4 October 2025 per the Agency's own Central Register notice. It carries the GDPR and the Law Enforcement Directive in one state-level act, split by Part. Art. 24 is GDPR art. 22 — same solely-automated trigger, same legal-effects threshold, same three exits of contract, authorising law and explicit consent, same special-categories bar routed through art. 11(2)(a) and (g), with «izrada profila» defined in GDPR terms at art. 4. Art. 67 is the LED art. 11 counterpart: a flat prohibition on the competent authority with no contract or consent exit, a special-categories bar, and an unconditional ban on profiling that discriminates on sensitive-data grounds — the twin of Serbia's art. 39(3) and Albania's art. 53(3). The drafting divergence worth recording runs through both: where the GDPR and the LED name the right to obtain human intervention on the part of the controller, arts. 24(3) and 67(1) name «prava na učešće fizičkog lica u donošenju odluke», the right to the participation of a natural person in the making of the decision — a safeguard built into the procedure rather than requested after it. Transparency is proactive and triple-anchored at arts. 15, 16 and 17, each cross-referring to art. 24(1) and (4), and art. 37 makes systematic and extensive automated evaluation a mandatory DPIA trigger. Enforcement has two features the GDPR does not: art. 113(5)(b) puts an art. 24 breach at 20,000 KM to 40,000,000 KM or 4% of worldwide turnover, whichever is higher — the KM ceilings are the euro figures doubled rather than converted at the 1.95583 currency-board peg, so about €20.45m, and the 20,000 KM floor has no GDPR counterpart at all — while art. 113(10) bars any fine on a public body or competent authority, which leaves art. 67 with no institutional penalty and only the responsible officer (5,000–70,000 KM) or employee (500–5,000 KM) exposed. Art. 119 repealed the 2006 Act («Sl. glasnik BiH» br. 49/06, 76/11, 89/11) on the day application began; its art. 29 was a Directive 95/46 art. 15 prohibition with contract-or-law exits and no consent, fineable at 5,000–50,000 KM under art. 50(1)(u), so the ceiling for a private controller rose roughly eight-hundredfold overnight. Art. 116 gives until 8 March 2027 to align other laws and existing processing operations; that date is on the watch list.

Primary source — azlp.ba ↗

ME Montenegro joins the atlas with the first pre-GDPR automated-decision rule in it — no consent exit, no human-intervention safeguard, and no fine on the prohibition

Added logged 28 Aug 2026

Art. 15a of the Zakon o zaštiti podataka o ličnosti («Službeni list Crne Gore» br. 79/08, 70/09, 44/12, 22/17, 77/24) is drafted on Directive 95/46 art. 15, not on GDPR art. 22, and every neighbour already in the atlas — Serbia, Albania, North Macedonia — is on the later model, so the contrasts are sharp. It is a prohibition on the decision-maker rather than a right the data subject invokes. There is no definition of profiling in the Act and no ‘legal effects or similarly significantly affects’ threshold; what pulls a decision in is its subject-matter — rights, obligations and interests — plus the fact that it evaluates personal characteristics and abilities, illustrated with work performance, reliability, creditworthiness and conduct. Art. 15a(2) allows two exits only, contract and authorising law: there is no explicit-consent route out of the kind GDPR art. 22(2)(c) opens, which makes the rule harder to contract around than any of its neighbours. The safeguards are not a free-standing paragraph but a condition inside the contract exit, and the only one named is the possibility for the person to express a view — no express right to human intervention, no right to contest. There is no special-categories bar. The transparency limb is reactive: art. 43(2)(7) puts the manner of the automated processing into the controller's written reply to a written access request, due within 15 days, and nothing obliges the controller to volunteer it. And the enforcement asymmetry is the finding that matters: art. 74's 21 misdemeanour items do not include art. 15a, so the prohibition itself carries no fine, while failing to answer the art. 43(1) request in time is item 18 at €500–€20,000 for a legal person. In practice the Agency's art. 71 order, whose breach is item 21, is the route to stopping a solely-automated decision. Dating the rule took three sources: the Agency's own official English translation of the 79/08+70/09 consolidation runs Article 15 straight into Article 16, so art. 15a was not in the Act as adopted; the Agency's consolidated text stamped for 79/08, 70/09 and 44/12 already carries it in today's wording; and the Official Gazette's register puts 44/12 in force on 17 August 2012. The 2017 bill as tabled changes only arts. 28, 37, 40 and adds 40a, and 77/24 is a single-article amendment, so neither touches art. 15a. Montenegro has no Law Enforcement Directive act, as North Macedonia has none — but two Government bills tabled on 7 August 2026 would change both facts at once: EPA 1164 XXVIII carries a GDPR art. 22 transposition at its član 22, and EPA 1165 XXVIII is the missing LED act. Both are still ‘u proceduri’.

Primary source — azlp.me ↗

MK North Macedonia joins the atlas: GDPR art. 22 transposed almost word for word, and a 4% fine with no euro floor under it

Added logged 28 Aug 2026

Art. 26 of the Закон за заштита на личните податоци («Службен весник на РСМ» бр. 42 of 16 February 2020, page 95) carries GDPR art. 22 with the same solely-automated trigger, the same legal-or-similarly-significant effects threshold, the same three exits of contract, authorising law and explicit consent, and the same safeguards clause naming human intervention by the controller, the right to express a personal view and the right to contest. Art. 26(4) routes the special-categories bar through art. 13(2) points 1) and 7) — explicit consent and substantial public interest — which is exactly where GDPR art. 22(4) routes through art. 9(2)(a) and (g). Unlike its two neighbours, the Act has no Law Enforcement Directive part, so there is no police-side counterpart to Serbia's art. 39 or Albania's art. 53 here. The divergence is in the penalty: art. 111(1)(15) names breach of art. 26 as a Category II offence at up to 4% of the controller's total annual income, and offers no €20 000 000 alternative of the kind GDPR art. 83(5) sets beside the percentage, so a low-revenue controller's exposure is bounded by its own income. Art. 124 puts the Act in force on the eighth day after publication, 24 February 2020, and art. 119 gave controllers 18 months to align, a window that closed on 24 August 2021. Art. 122 schedules chapter III, art. 26 among it, to cease applying on EU accession. Verified against the supervisory authority's own copy of the gazette text; art. 26 is identical there and in the consolidated text, so the 294/21 amendment did not touch it.

Primary source — azlp.mk ↗

US Colorado: the enforcement stay on the AI Act, pinned to the court record and to the rulemaking that restarts the clock

Updated logged 27 Aug 2026

The Colorado AI Act row now carries the litigation chronology from the docket rather than an approximation. xAI sued AG Weiser on 9 April 2026; the United States intervened as plaintiff-intervenor on 24 April 2026 and filed its own Complaint in Intervention alleging an Equal Protection violation, certified as of general public importance by the Acting Attorney General under 42 U.S.C. s. 2000h-2 — the first federal intervention against a state AI law. Magistrate Judge Cyrus Y. Chung entered the stipulated stay by minute order on 27 April 2026 (not 28 April, as secondary write-ups have it), and its text reaches SB 24-205 'or any legislation replacing or amending SB24-205 enacted during this legislative session', which is what carries the stay onto SB 26-189. The stay runs until 14 days after a ruling on a preliminary-injunction motion that xAI files within 28 days of final adoption of the implementing rulemaking — so the rulemaking is the clock. Those dates are now on the row: proposed rules 4 CCR 904-6 filed with the Secretary of State on 11 August 2026, comments through 26 October 2026 (4 September for the revised draft), hearing 26 October 2026. The effective date stays 1 January 2027; only enforcement is suspended. The Chatbot Safety Act row gains the same rulemaking dates and a note that it sits outside the stay, and the psychotherapy row loses the word 'injunction' — no injunction has issued in that case.

Primary source — courtlistener.com ↗

AL Albania joins the atlas: one act carrying both the GDPR and the LED automated-decision rules

Added logged 27 Aug 2026

Ligj nr. 124/2024 «Për mbrojtjen e të dhënave personale», published in Fletorja Zyrtare nr. 9 of 17 January 2025 and in force since 1 February 2025 under art. 101(1), splits the two European regimes by Part. Art. 20 in Part II is GDPR art. 22 with the same three exits and a safeguards clause naming manual intervention, the right to express a view and the right to contest, but its second effects limb reads «pasoja të ngjashme të rënda» — similar serious effects — drafting the threshold on the gravity of the effect rather than on its significance. Art. 53 in Part III is the law-enforcement counterpart, a prohibition on the authority with no consent or contract exit, and art. 53(3) bans outright any profiling that results in discrimination on sensitive-data grounds, untied to any decision or effects threshold: the near-exact twin of Serbia's art. 39(3), and still the only two provisions of their kind in the atlas. Art. 94(2)(b) puts breach of arts. 12-20 in the top band at up to 2,000,000,000 lekë or 4% of total global annual turnover, whichever is higher, but art. 94 enumerates only Part II duties, so art. 53 carries no fine tier of its own. Art. 100 repeals the whole Law on EU accession except Parts III and IV, so art. 20 falls away and art. 53 survives. The published corrigendum was downloaded and diffed: the art. 20 and art. 53 blocks are byte-identical.

Primary source — qbz.gov.al ↗

Turkmenistan added to the atlas as “no AI-specific law” — 33 articles, and not one of them mentions automation

Added logged 26 Aug 2026

Law No. 519-V of 20 March 2017 on information about private life and its protection was read end to end in the Turkmen text on turkmenistan.gov.tm and the Russian text on the Ministry of Foreign Affairs' London embassy site. «awtomat» and «profil» appear nowhere in its 33 articles, and art. 26 — the subject-rights article, read item by item — gives access, rectification, blocking, destruction, withdrawal of consent and a dissemination veto, but no right against a solely automated decision, no human review and no explanation of the logic. Art. 33(1) sets entry into force at 1 July 2017; art. 31 delegates liability without naming a figure. The amending law of 17 April 2026 that surfaces alongside it amends the accounting and financial-reporting law, not this one. On 24 January 2026 the President approved proposals to begin building a national legal framework for AI, but no draft has been published and there is no national AI strategy. Third jurisdiction recorded as “no AI-specific law”, after Belarus and Armenia.

Primary source — turkmenistan.gov.tm ↗

Tajikistan added to the atlas: an AI strategy to 2040 that says the law does not exist yet

Added logged 26 Aug 2026

The Strategy for the Development of Artificial Intelligence to 2040 is Annex 1 to Government Resolution No. 483 of 30 September 2022, in the redaction of Resolution No. 83 of 31 January 2025 — the approval line of the official text on the state portal egov.tj shows the 2022 resolution as the approving instrument, not the 2025 one that secondary write-ups name. The Strategy binds nobody: «обязан», «запрещ» and «этик» do not occur in it and «персональные данные» does not occur at all, and its own para. 47 lists the drafting of a Law «On Artificial Intelligence» as a first-priority measure, while para. 50 records that no authorised state body for AI has been designated. Separately, the Law on the Protection of Personal Data (No. 1537 of 3 August 2018), read in full on the site of the National Centre of Legislation under the President, has 27 articles, no automated-decision rule, no profiling provision and no logic item in the art. 22(4) transparency list. Status guidance-only, on the Egypt footing.

Primary source — egov.tj ↗

RS Serbia joins the atlas: one statute carrying both the GDPR and the LED automated-decision rules

Added logged 26 Aug 2026

The Zakon o zaštiti podataka o ličnosti («Sl. glasnik RS» br. 87/2018) puts both European regimes in a single act and splits them by article. Art. 38 is GDPR art. 22 with its three exits and its three minimum safeguards; art. 38(5) hands special-purpose processing to art. 39, which bans a solely automated decision by a competent authority outright, with no consent or contract exit. Art. 39(3) goes beyond both European texts with a flat ban on profiling that leads to discrimination on special-category grounds, tied to no decision and no effects threshold. Art. 95(1)(19) names breach of arts. 38 and 39 expressly at 50,000 to 2,000,000 dinara for a legal person, in fixed dinars with no turnover alternative. Applicable since 22 August 2019 under art. 102, which starts application upon the expiry of nine months from entry into force on 21 November 2018. Verified against the promulgated gazette text.

Primary source — pravno-informacioni-sistem.rs ↗

SN Senegal art. 48 — the link to the law's text died at the regulator's end, and the citation moves back to the CDP's own page

correction logged 26 Aug 2026

The direct link this row carried into the Commission de Protection des Données Personnelles' document store now answers HTTP 402 for every client: the store is a Supabase project that has been restricted for exceeding its cached-egress quota, so the signed object path and its public equivalent both fail, and the whole of cdp.sn's document content goes with it. The citation reverts to the CDP's own legislation page — the regulator's publication of the Law, live, and the page a fresh document link is generated from. Loi n° 2008-12 du 25 janvier 2008 was re-read end to end this run from the copy published by the AFAPDP, the association of francophone data-protection authorities of which the CDP is a member: art. 48 is verbatim the three-paragraph article this row describes, and the copy adds a promulgation formula dated 25 January 2008 and signed by President Wade and Prime Minister Soumaré that the CDP's copy did not carry. No Journal officiel number or date appears in either copy and no Senegalese gazette host resolves, so confidence stays medium. The supersession finding of 24 August 2026 is unchanged: art. 48 stands unrepealed and unamended.

CF Central African Republic art. 30 — ARCEP rebuilt its site and took the law with it; the citation moves to the archived official copy

correction logged 26 Aug 2026

arcep.cf now serves a single «Site en construction» placeholder at its root and 404s every document path, so the link this row carried to the regulator's own copy of Loi n° 24.001 portant protection des données à caractère personnel is dead. The citation moves to the Internet Archive's 22 June 2026 capture of that same official file, which was downloaded and re-read this run: a 5.85 MB scan of the promulgated original in which art. 30 still carries the limb this row rests on — the right to obtain the information needed to know and to contest the mechanism of an automated processing where a decision founded on it produces legal effects — and art. 6 still carries the profiling definition. Burkina Faso's Loi 001-2021 is cited the same way after cil.bf went the same way. A live official host for the Central African text is an open follow-up. Found by a dataset-wide source-link sweep run after Senegal's link died the same day.

PE Peru's AI-law Reglamento: publication, in-force date and sector-phased schedule added

Updated logged 25 Aug 2026

The row's status_note field was previously blank. DS 115-2025-PCM, approving the Reglamento of Ley 31814, was published in El Peruano on 9 September 2025 and entered into force 90 business days later, on 22 January 2026, except for four provisions (the digital AI channel and the National AI Strategy) that took effect the day after publication. The Reglamento phases sector obligations in from 10 September 2026 (health, education, justice, security, economy and finance), 10 September 2027 (transport, commerce, work) and 10 September 2028 (production, agriculture, energy, mining). The row's date and max_penalty fields were independently confirmed accurate and are unchanged.

Primary source — busquedas.elperuano.pe ↗

KZ Kazakhstan penalty citation corrected: the residual personal-data offence is KoAP art. 79, not art. 79-1

correction logged 25 Aug 2026

The row's max_penalty and notes fields cited KoAP art. 79-1 as the residual general offence for unlawful collection and processing of personal data. Art. 79-1 of Kazakhstan's Code of Administrative Offences is in fact a public-order offence (assault), unrelated to personal data. The correct residual article is art. 79. The prohibition, consent-only exit, explain-and-object duty and three-working-day response period under art. 19-1 itself are unaffected.

Primary source — adilet.zan.kz ↗

BF Burkina Faso's CIL site is back online, but the promulgation-decree date still can't be confirmed

Updated logged 25 Aug 2026

The status_note previously stated that cil.bf served a maintenance page on every path. As of today cil.bf is a normal, operating site again, so that claim is stale and has been corrected. The promulgation-decree date for Loi n° 001-2021/AN still could not be located on the site, so confidence remains medium and no other field changes.

Primary source — cil.bf ↗

MD Moldova joins the atlas: two automated-decision rules that took effect on 23 August 2026

Added logged 25 Aug 2026

Law no. 195/2024 transposes the GDPR and its art. 22 carries the automated-decision right unchanged, with fines up to 2 000 000 lei or 2 per cent of turnover under art. 88(2)(b). Law no. 160/2026 transposes the Law Enforcement Directive and its art. 11 bans solely automated decisions with an adverse legal effect by police, prosecutors, courts and prisons, with no contract or consent way out. Both entered into force on 23 August 2026, the same day Law no. 133/2011 was repealed; both phase the fine in at 10, 40 and 100 per cent over three years. Verified against the Monitorul Oficial as published.

Primary source — monitorul.gov.md ↗

GE Georgia joins the atlas: art. 19 of the 2023 data protection law, in force since 1 March 2024

Added logged 25 Aug 2026

Art. 19 of the Law of Georgia on Personal Data Protection is a GDPR art. 22 analogue with three divergences verified against the Georgian consolidated text, not the translation. Its exceptions are drafted to cover only profiling-based decisions, so a solely automated decision that is not profiling-based has no exception route. Its safeguards — human involvement, expressing a view, contesting — arise only on the data subject's request rather than as a standing duty. And matsne's official English inverts the human-review carve-out: the Georgian excludes human involvement for decisions authorised by law, the English says it is provided for by that limb. Logic disclosure exists at art. 13(1)(g) but only on request; arts. 24 and 25, the proactive notice lists, carry no automated-decision item. The DPIA trigger at art. 31(2)(a) is unconditional and adds financial consequences to the GDPR's legal-or-similarly-significant test. Fines are fixed tariffs from GEL 1 000 to GEL 5 000 under art. 72, capped in aggregate at GEL 20 000 by art. 64(2) — the lowest ceiling of any GDPR-family rule in the atlas. Enforcement sits with the State Audit Office since Law No 1289 of 17 December 2025.

Primary source — matsne.gov.ge ↗

AZ Azerbaijan joins the atlas: the automated-decision rule that never says «automated»

Added logged 25 Aug 2026

Art. 7.3 of the Law on Personal Data (No. 998-IIIQ of 11 May 2010) turns on «informasiya texnologiyaları vasitəsilə» — by means of information technologies — and the words «avtomat» and «profil» appear nowhere in the Law's nineteen articles, which is why keyword sweeps record Azerbaijan as having no rule. It has no «solely automated» qualifier, so it reaches human-in-the-loop decisions; its threshold is that the decision infringes the subject's interests, which is lower than legal effects but adverse-only; and its remedy is not human review but a duty on the owner or operator to obtain consent to process by another method or to stop without delay. The single exception is processing mandated by legislation — no consent limb, no contract limb. Art. 19 delegates the penalty; art. 375.0.2 of the Code of Administrative Offences penalises the failure to stop at a flat 300 to 500 manat regardless of whether the offender is a natural person, an official or a legal person. Verified against the consolidated texts on e-qanun.az. Confidence is medium on the commencement date only: the Law has no entry-into-force article, publication was 6 June 2010, and the e-qanun record separately shows a registration date of 1 July 2011.

Primary source — e-qanun.az ↗

Armenia added to the atlas as “no AI-specific law” — art. 16 of its data-protection law occupies the automated-decision slot but drops the automation element

Added logged 25 Aug 2026

Armenia was untracked and is now on the map with status “no AI-specific law”. The Law on the Protection of Personal Data (HO-49-N of 18 May 2015) was read end to end in its current official incorporation on ARLIS, the Ministry of Justice legal information system, reflecting the most recent amendment HO-191-N of 7 May 2026 — an institutional change to art. 25(7)(2) only. The interesting part is what art. 16 does and does not say. Titled “Rights of the data subject when decisions are taken on the basis of processing personal data”, it sits in exactly the slot Armenia’s regional peers use for the automated-decision rule, and it bars decisions that do not follow from the purposes of the processing and that produce legal consequences for the data subject or otherwise affect their rights and legitimate interests, save with consent or where a law provides. But it never mentions automation. It reaches any decision grounded in processing, human or machine, and it gives no right to human review, no right to an explanation of the logic and no profiling provision — where Russia (152-FZ art. 16), Ukraine (Law 2297-VI art. 8) and Kazakhstan all confine their rule to solely automated decisions. The Law’s single reference to automation is the art. 3(1)(2) definition of processing. A full-text exact-match sweep of the ARLIS corpus returns no act whose title mentions artificial intelligence and no occurrence anywhere of the phrase “automated decision”; the 25 acts that mention artificial intelligence at all are government programmes, the economic transformation doctrine, higher-education admission decisions listing it as a degree specialty and EAEU Commission acts. The instrument that would supply the missing rule is external: by Law HO-348-N of 17 November 2021, in force 26 November 2021, Armenia ratified Protocol CETS 223 of 10 October 2018 amending Convention 108, whose new art. 9(1)(a) confers the right not to be subject to a decision significantly affecting the individual based solely on automated processing without having their views taken into consideration. Under art. 37 that Protocol binds a ratifying State only from its entry into force, a date not established from primary sources here — so Armenia carries no obligation row yet.

Primary source — arlis.am ↗

ML Mali: the 2017 amendment to Loi 2013-015 read in the gazette — it replaces five institutional articles and leaves the automated-decision rule untouched

correction logged 24 Aug 2026

Secondary sources describe Loi n° 2013-015 du 21 mai 2013 as "modifiée" by Loi n° 2017-070 du 18 décembre 2017. The amending text has now been located and read in the official gazette — Journal officiel de la République du Mali n° 53 of 2017, pp. 2115-2116 — through the Secrétariat général du Gouvernement's own gazette search. It has two articles. Art. 1 replaces arts. 21, 25, 36, 42 and 49 of the 2013 Law, all of them institutional: the composition of the Autorité de Protection des Données à Caractère Personnel as a fifteen-member deliberating organ on a seven-year non-renewable mandate, the oath sworn before the Cour suprême, the annual activity report, a five-day cap on extraordinary sessions, and the adoption of rules of procedure. Art. 2 of the amending law abrogates only prior contrary provisions. Art. 2 of the 2013 Law — the third paragraph of which is the automated-decision rule this row tracks — is not among the amended articles and stands exactly as enacted. This is also the only amendment there has ever been: the gazette index returns exactly two texts of type Loi on personal data across the whole series, the 2013 Law and this amendment, so there is no second amending law and no successor statute. The provisional flag raised earlier the same day is withdrawn; the row is confirmed unchanged.

Primary source — sgg-mali.ml ↗

GA Gabon: the official gazette site is reachable again, confirming Loi n° 025/2023 art. 77 directly rather than through an AFAPDP mirror

correction logged 24 Aug 2026

journal-officiel.ga previously returned HTTP 503 on every path and the row was sourced to a reproduction of the gazette published by AFAPDP, the Francophone data-protection authorities' association. Re-checked 24 August 2026, the official gazette site is live: https://journal-officiel.ga/20089-166-pr-/ carries Décret n° 166/PR du 12/07/2023 promulgating the Law and citing Journal Officiel n° 218 Bis du 15 Juillet 2023, and https://journal-officiel.ga/20085-025-2023-/ hosts the law text itself. Both confirm the row's existing citation and dates; nothing about the substance of art. 77 changed. The row's source_url and the Gabon entries in data/jurisdictions.json now point at the official gazette directly.

Primary source — journal-officiel.ga ↗

Belarus added to the atlas as the first “no AI-specific law” jurisdiction — its data-protection law carries no automated-decision rule at all

Added logged 24 Aug 2026

Belarus was untracked. It is now on the map with status “no AI-specific law”, on the strength of two negatives established against primary text rather than assumed. First, Law No. 99-Z of 7 May 2021 on Personal Data Protection was read end to end in its current redaction — as amended by Law No. 134-Z of 16 March 2026, in force 21 March 2026 — on ETALON-ONLINE, the official system of the National Centre of Legal Information. All 21 articles are present; none of them bars a decision taken solely on the basis of automated processing, and there is no profiling provision. The Law's only reference to automation is the art. 2 scope clause. That is the notable finding: every neighbour in the same drafting family carries the rule — Russia in art. 16 of 152-FZ, Ukraine in art. 8 of Law 2297-VI, Kazakhstan in its own personal-data law — and Belarus does not. Second, a search of the ETALON-ONLINE corpus for artificial intelligence returns no Belarusian normative act regulating it. The instruments that do come back are the CIS Interparliamentary Assembly model law on artificial-intelligence technologies (Resolution No. 58-8 of 18 April 2025) and CIS heads-of-state declarations, which bind nobody of their own force, plus academic writing and Ministry of Education material on AI in schools. Decree of the President No. 8 of 21 December 2017 lists the training of neural networks and the preparation of datasets among the activities open to High-Technology Park residents — an enabling and tax regime, not an obligation. Belarus therefore carries no obligation row: there is nothing to track yet.

Primary source — etalonline.by ↗

The jurisdiction count was three too high, and 26 rows cited a private explorer instead of the Official Journal

correction logged 23 Aug 2026

This is a housekeeping correction with no change to any obligation. Auditing every source_url that did not resolve to a government host — the sweep that had just caught the Ukraine row — turned up two separate defects. First, three countries were on the map twice. Russia, Switzerland and Türkiye each kept an old region:null stub describing a draft or a signature — «Draft horizontal AI law (in consultation)», «CoE AI Convention ratification + sectoral law», «AI bills before the Grand National Assembly» — alongside the verified binding row that had superseded it (243-ФЗ and 152-ФЗ art. 16, revFADP art. 21, KVKK art. 11(g)). The map keys by country name and the later row wins, so nobody ever saw the stale text; what the stubs did do was inflate the published jurisdiction count. It read 95. The true figure is 92, and that is what it now reads. All three stubs were also the ones sourced to a law-firm note, a policy-tracker NGO and a press release rather than to the statute. The validator now fails the build on a repeated country row, so this cannot recur silently. Second, sourcing. Twenty-six rows — the twenty-two EU member states plus four region entries — cited artificialintelligenceact.eu, a private explorer, as the authority for the AI Act. It is a good site and it was not wrong, but Primary Source First means the Official Journal or nothing; those rows now cite the EUR-Lex ELI for Regulation (EU) 2024/1689. Egypt cited an OECD dashboard and now cites the Ministry of Communications and Information Technology, which also updates the record: the National AI Council widened in January 2026 to cover quantum computing and emerging technologies, and the National AI Strategy is in its second edition (2025-2030). Still soft law, still no statute, still no penalty. Norway cited a law firm's client note and now cites Stortinget, which quotes the ministry's own 26 May 2026 statement that the high-risk rules «først vil gjelde i Norge når loven om kunstig intelligens er vedtatt av Stortinget». Norway's earlier plan to have the KI-lov in force by late summer 2026 has lapsed: the AI Act is still not in the EEA Agreement, the omnibus amendments go to a fresh consultation first, and nothing AI-specific binds a Norwegian deployer today. Three rows remain sourced to something other than an official host — Gabon (a francophone DPA association), São Tomé and Príncipe (the Ibero-American DPA network) and Burkina Faso (a web archive). Each needs its own gazette text and is being tracked separately.

DZ Algeria repealed Loi 18-07 art. 11 in July 2025 and relocated the automated-decision rule into a new law-enforcement-only title

correction logged 23 Aug 2026

Loi n° 25-11 du 24 juillet 2025 (JO n° 48 du 24 juillet 2025) repeals arts. 10 and 11 of Loi 18-07 outright (art. 7) rather than amending them in place. The automated-decision rule survives, but only inside a new Titre V bis (art. 6 of Loi 25-11, new arts. 45 bis to 45 bis 14 of Loi 18-07) headed as the title governing personal-data processing for crime prevention, detection, investigation, prosecution and sentence execution — not the general-purpose chapter that used to hold art. 11. New art. 45 bis 1 keeps the same two-limb structure (an absolute bar on judicial conduct-appraisal decisions, a general bar on other legal-effect decisions, with a contract/own-request carve-out) and Loi 25-11 also adds a first-ever statutory definition of "profilage". Whether Loi 18-07 still restricts automated decisions by controllers outside the law-enforcement context has not been confirmed from a located text and is flagged as open in the row's status_note.

Primary source — joradp.dz ↗

DZ Algeria's automated-decision rule binds only courts and law enforcement — private controllers lost it in July 2025

correction logged 23 Aug 2026

Follow-up to this morning's entry, which corrected the citation but left the row's scope fields describing the repealed art. 11. Reading Loi n° 25-11 in full from JO n° 48 closes the question it left open. The Law has exactly eight articles and enacts no general-scope replacement for art. 11 anywhere; and art. 45 bis — the opening article of the Titre V bis in which the surviving rule sits — provides that processing for the Title's purposes « ne peut être effectué que par » the judicial authority, services legally empowered to investigate offences, auxiliaires de justice and the prison administration. The Title has a closed personal scope, so the « toute autre décision » limb of art. 45 bis 1 is bounded by it. An ordinary Algerian controller has had no statutory automated-decision constraint since 24 July 2025. The row's roles are narrowed from provider/deployer/hiring to deployer and its topics from transparency/high-risk/hiring to transparency/high-risk, because the previous tagging told an employment-screening audience that a repealed provision bound them. The summary, binds and penalty fields are rewritten against the enacted text, and the Algeria region note and atlas row — untouched this morning and still describing art. 11 as the binding constraint — are corrected to match. Also corrected: the « profilage » definition is inserted by art. 2 of Loi 25-11, which rewrites art. 3 of Loi 18-07, not by art. 3 of Loi 25-11, which adds art. 27 bis on the national authority's regional poles.

Primary source — joradp.dz ↗

UA Ukraine was never voluntary-only: a no-exceptions automated-decision right has been binding since 2012, and no company can be fined for breaking it

correction logged 22 Aug 2026

Ukraine sat on this tracker as «Voluntary self-regulation; EU-aligned binding law planned», status guid, region null, sourced to an NGO roadmap page. That was wrong, and it had been wrong for as long as the row existed. Ukraine has had a binding automated-decision right since 20 December 2012. Law No. 5491-VI of 20 November 2012 added two points to part two of art. 8 of the Law «Про захист персональних даних» (No. 2297-VI of 1 June 2010), and the Rada record card puts commencement the day after publication in «Голос України» No. 241 of 19 December 2012. Both points are live in the current consolidated text, which is itself Чинний after 28 rounds of amendment. Point 13 is the widest automated-decision trigger this tracker carries and the one with the fewest defences. It gives the subject a right «на захист від автоматизованого рішення, яке має для нього правові наслідки» — protection from an automated decision that has legal consequences for them. There is no 'solely' in it. GDPR art. 22, Kazakhstan's art. 19-1, Uzbekistan's art. 24 and Russia's 152-ФЗ art. 16 all require the human to be out of the loop before they bite; Ukraine's does not, so a decision a person merely rubber-stamps is still caught. And where each of those three offers an exit — consent in Kazakhstan, consent or contract or law in Uzbekistan — art. 8(2)(13) offers none whatsoever. The compensating narrowness is on effects: legal consequences only, with no 'similarly significantly affects' limb and no Russian-style catch-all. Point 12 is the quieter find. It gives a standing right «знати механізм автоматичної обробки персональних даних» — to know the mechanism of automatic processing. That is a logic-transparency right, and it is precisely what the notes on Uzbekistan and Kazakhstan record as absent in those regimes. A 2012 Ukrainian statute grants what two 2026 Central Asian ones withhold. The catch is that Ukraine built the rights and not the machinery. Art. 8 attaches no objection procedure, no deadline to answer — Kazakhstan gives three working days, Uzbekistan ten, Russia thirty — no duty to explain the individual decision and no right to human intervention or re-decision. Supervision runs through the Verkhovna Rada Commissioner for Human Rights, not a dedicated authority. Enforcement is thinner still, and thinner than Kyrgyzstan's. The only route is KUpAP art. 188-39 part four — failure to observe the statutory protection procedure where it led to unlawful access or to violation of a subject's rights — at 100-500 НМДГ for citizens and 300-1,000 НМДГ for officials and citizen-entrepreneurs, with part five doubling that on a repeat within the year to 1,000-2,000 НМДГ. At 17 UAH per НМДГ, and the Tax Code carve-out to the tax social benefit is expressly confined to the QUALIFICATION of offences rather than to the size of the sanction, the ceiling is about 34,000 UAH, roughly 700 euro. The structural point is sharper than the arithmetic: the Code of Administrative Offences addresses natural persons only, so a company that breaches art. 8 cannot be fined for it — only its officials can be. Ukraine has no corporate administrative liability for personal-data breaches at all. One tooling note, because Ukraine had been on the sweep-gap list as 'search is JS-gated'. Half of that was right and half was hiding the statute. The search at /laws/main/find is indeed unreachable — it returns the unfiltered 294,073-document list whatever is passed in txt=. But /laws/show/<id> is also a JavaScript shell yielding about 3.5k of chrome and no statute body, which is what makes the register look empty. Appending /print to the same id returns the full consolidated text, and /laws/card/<id>/print returns the record card with the exact commencement date, the official publication list and the Чинний state. That is the fifth sweep-gap entry in a row that turned out to be a false negative rather than a block.

Primary source — zakon.rada.gov.ua ↗

UZ Uzbekistan enters the tracker: an AI statute with a duty that has no penalty (corrected same day — Kazakhstan, not Uzbekistan, is the Central Asian first)

addition logged 21 Aug 2026

Correction issued 21 August 2026: this entry originally called Uzbekistan Central Asia's first AI statute. It is not. Kazakhstan's standalone Law No. 230-VIII of 17 November 2025 entered into force on 18 January 2026, three days earlier; see the Kazakhstan entry of the same date. The rest of this entry stands. Law No. ЎРҚ-1115 of 21 January 2026 wrote artificial intelligence into Uzbekistan's 2003 Law on Informatization, and it is in force — art. 4 commences it on official publication, which the official Uzbek consolidated text records as National Database of Legislation, 21.01.2026, No. 03/26/1115/0063. New art. 7¹ carries two flat rules with no sector, size or nationality limb: AI-created information resources and AI-based information systems must not damage a person's life, health, freedom, honour, dignity or other inalienable rights, and legally significant decisions affecting rights and freedoms may not rest exclusively on their conclusions. The second is a human-in-the-loop mandate on the decision-maker, not a right the person has to invoke — and it has no consent or contract exit. Art. 7¹ carries no penalty at all: the only sanction the act created is a new part two of KoAO art. 46², 50–100 base calculation units plus confiscation, and its text couples unlawful AI processing of personal data WITH dissemination in the media, telecom networks or the Internet, so internal AI processing falls back to part one. Third row: art. 24 of the 2019 Personal Data Law (ЗРУ-547), in force 1 October 2019 by its own art. 36 and word-for-word identical in the 2019 and current 2026 redactions, bars solely automated decisions producing legal consequences unless there is written consent, a contract, or a legislative basis — it has the contract limb Russia's 152-FZ art. 16 lacks — and gives the owner/operator ten days to answer an objection, a third of Russia's thirty. Verified against the official Uzbek-language texts on lex.uz; the Russian versions there are marked unofficial translations.

Primary source — lex.uz ↗

RU Russia's first AI statute is on the books, and none of its duties starts on the commencement date being reported

Added logged 21 Aug 2026

Federal Law No. 243-FZ of 26 July 2026 on supporting the development of artificial intelligence technologies regulates only large foundational models — not fewer than 1 billion parameters, general-purpose, and serving as the basis for other software. Art. 13(1) puts the Law in force on 1 September 2026 and that is the date in general circulation, but art. 13(2) defers arts. 8, 9 and 10, together with art. 5(2) points 3-5 and art. 6 parts 2-5, to 1 March 2027; what commences in September is the subject matter, aims, definitions, principles, coordination and support powers, and a bare liability referral. The three deferred duties are recorded separately because they bind different parties: art. 8 imposes security measures, operating rules and technical documentation only on developers whose model has been granted sovereign or national status; art. 9(3) requires platforms accessed by more than 500,000 users in Russia within twenty-four hours to give users the means of placing an AI warning, which is an enablement duty rather than a labelling mandate; art. 10(1) requires anyone providing the ability to use such a model to notify users who owns the rights in the outputs and on what terms they may be accessed, used and retained. The Law states no penalty: art. 11 is a referral to general legislation and the Code of Administrative Offences carries no article on large foundational models.

Primary source — publication.pravo.gov.ru ↗

RU Russia has barred solely automated decisions since 2007, and art. 16 of 152-FZ has no contract exception

Added logged 21 Aug 2026

Art. 16 of Federal Law No. 152-FZ of 27 July 2006 forbids decisions taken on the basis of solely automated processing that produce legal consequences for a person or otherwise affect their rights and legitimate interests, and admits only two ways out: the written consent of the data subject, in the heavy art. 9(4) form that carries the identity-document particulars, or a federal law that also lays down measures protecting the person. There is no contract limb, so the automated credit refusal or tenancy screen taken in the course of contracting is not excused, and the second trigger limb carries no significance threshold at all. The operator explains the procedure of the decision and its possible legal consequences, offers the chance to object, and answers the objection within thirty days — but nothing requires the decision to be changed, and there is no logic-disclosure right anywhere in the Law. In force since 26 January 2007, 180 days after publication in Rossiyskaya Gazeta No. 165 of 29 July 2006. Enforcement runs through KoAP art. 13.11(2) for the missing written consent and art. 13.11(4) for the explanation duty; Roskomnadzor draws the protocol but a judge imposes the fine.

Primary source — pravo.gov.ru ↗

KG Kyrgyzstan has had the deepest AI regime in Central Asia since 6 February 2026, and a single 20,000-som offence behind it

addition logged 21 Aug 2026

Kyrgyzstan sat on the sweep-gap list as a 403. It is not blocked. cbd.minjust.gov.kg, the Ministry of Justice's Centralised Bank of Legal Information, is a single-page app whose JSON API answers in full once an Origin and Referer header are supplied - POST /api/v1/GetDocuments with {"searchByTextRu": "..."} full-text searches all 208,757 acts - and without them every call returns a bare "Forbidden". Behind that header check is a regime the tracker had entirely missed. Chapter 23 of the Digital Code of the Kyrgyz Republic (Code No. 178 of 31 July 2025) runs seven articles, 191 to 197, and it has been binding since 6 February 2026: commencement Law No. 179 of the same date gives the Code effect six months after its own publication in «Эркин-Тоо» No. 58 (3714) of 5 August 2025, and the ЦБД record card records 6 February 2026. That timing rewrites the Central Asian sequence this tracker published earlier today only in part - Kazakhstan's AI Law still took effect first, on 18 January 2026, and Uzbekistan's second on 21 January - but Kyrgyzstan adopted its text five months before Kazakhstan's was even published, so the notes on both neighbours now carry that caveat. On substance Kyrgyzstan is the deepest of the three. Art. 193 subjects EVERY AI system applied in the country - no risk gate - to a danger assessment run by its owner at design, before first application and on any unplanned change, and requires the result and the methodology to be published on the owner's website and as open data. Systems the assessment puts in the «повышенной опасности» tier take the full weight: the art. 194(5) owner duties, and an art. 195 gate that no EU-style notified body mediates - the owner adopts a declaration of conformity, signs it with a qualified digital signature and posts it publicly before first use. Art. 196 binds the deployer separately and gives anyone whose rights a decision touches a free right to information sufficient to understand and check how the result about them was reached. Art. 197 applies at any danger level and covers chatbot disclosure, emotion and biometric classification notice, and deepfake labelling, with a wide creativity-and-teaching carve-out from the labelling limb. The classification is comparative and self-executed rather than annex-driven, which is the same structural choice Kazakhstan made, and art. 194(3) expressly exempts systems whose role is purely auxiliary. Unlike Kazakhstan, the implementing layer is finished: Cabinet of Ministers Resolution No. 770 of 2 December 2025 approved five sets of requirements under arts. 193 and 194, and Order No. 1181-т of 31 December 2025 approved the declaration content. The finding worth carrying is the enforcement gap, and it is wider than Kazakhstan's. Law No. 180 inserted exactly one AI article into the Code of Offences, art. 228-10, and it penalises only the art. 192(2) prohibition on designing, developing or applying AI to cause targeted and knowingly unlawful harm - 200 расчетных показателей for a natural person and 650 for a legal person, and the расчетный показатель has been 100 som since 2006, so 20,000 and 65,000 som, about 230 and 745 US dollars. No fine attaches to a missing danger assessment, a missing declaration, an absent risk-management system, a refused explanation, an undisclosed chatbot or an unlabelled deepfake. Kazakhstan at least fines failure to flag misleading synthetic output; Kyrgyzstan does not. What is left is regulator-ordered suspension under arts. 194(5)(7) and 196(1)(7), termination on a court act, and civil liability - including, for digital wellbeing services, an elective statutory compensation of 100 to 400 расчетных показателей under art. 127(2) that spares the consumer proof of loss.

KR Korea: the AI Basic Act grace period has no carve-out in the MSIT release, and its end date is not fixed

correction logged 21 Aug 2026

This morning's entry recorded the MSIT administrative-fine grace period as running to ~22 Jan 2027 "except for cases involving loss of life or fundamental human-rights violations". Re-read of the cited primary release (MSIT English press release, nttSeqNo=1191) shows it contains no such exception, and no reference to loss of life or human rights at all. Two corrections: the carve-out is removed as unsourced, and the release's own words — "efforts are currently underway to gather opinions to finalize the detailed operation plan and duration of this grace period" — make ~22 Jan 2027 a floor, not a confirmed end date. What the release does confirm stands: a grace period of at least one year from the 22 Jan 2026 in-force date. kr-aibasic-highimpact also had a stale source_url pointing at the Dec 2024 passage release (nttSeqNo=1071), which says nothing about fines; it now points at nttSeqNo=1191.

Primary source — msit.go.kr ↗

KR MSIT's one-year AI Basic Act fine grace period is now confirmed in a primary release

correction logged 21 Aug 2026

Both rows previously flagged the MSIT enforcement grace period as practitioner-sourced and unconfirmed in an MSIT primary release. An MSIT English-language notice (bbsSeqNo=42, nttSeqNo=1191) now confirms MSIT will implement a grace period of at least one year from the Act's 22 January 2026 in-force date before administrative fines are imposed, with exceptions for cases involving loss of life or fundamental human-rights violations.

Primary source — msit.go.kr ↗

KZ Kazakhstan is Central Asia's real first: a standalone AI statute in force since 18 January 2026, banning seven capabilities but penalising only two failures

addition logged 21 Aug 2026

Kazakhstan was a blank on this map because every official .kz host appeared to time out. It was not a block: adilet.zan.kz serves an incomplete TLS chain, omitting its GoGetSSL G2 intermediate, and once that intermediate is supplied from the certificate's own AIA URL the host verifies and answers in about a second. Behind it sits a law the tracker had missed. Law of the Republic of Kazakhstan No. 230-VIII ЗРК of 17 November 2025 «Об искусственном интеллекте» is a standalone 31-article AI statute, published in «Егемен Қазақстан» and «Казахстанская правда» No. 222 on 18 November 2025 and in force sixty days later, on 18 January 2026 — three days before Uzbekistan's ЎРҚ-1115. The changelog entry published earlier today calling Uzbekistan the Central Asian first has been corrected accordingly. Art. 17(3) bans seven AI capabilities outright, tracking EU AI Act art. 5 closely enough to compare but framed as a prohibition on creation and operation rather than on placing on the market. Two departures from the EU model are structural: art. 17(1) leaves the minimal/medium/high risk classification to the system's own owner under the general rules on classifying informatisation objects, with no statutory annex; and art. 17(2) adds a second axis of autonomy whose highest tier — systems whose decisions a human cannot correct or reverse — is not regulated here at all but deferred to future laws. Art. 18 is the substantive duty: continuous lifecycle risk management, updated not less than once a year, with immediate suspension or termination once a prohibited-capability risk is identified. Art. 21 requires users to be told that goods, works and services are produced using AI, and permits dissemination of synthetic outputs only with machine-readable marking plus a perceptible warning — though the machine-readable standard is delegated to the authorised body under art. 22 and has not yet been issued. The enforcement side is deliberately narrow, and that is the finding worth carrying. Companion Law No. 232-VIII inserted KoAP art. 641-1, and it reaches exactly two failures: not informing users about synthetic outputs capable of misleading them, and not managing the risks of a HIGH-risk system where harm followed. Breaching the art. 17(3) prohibitions is not itself an enumerated offence; it bites only indirectly, through the art. 18(2) suspension duty, through audit under art. 20(2), through the personal-data offences, or through the criminal law. Fines run 15/20/30/100 MRP by size on a first offence and 30/50/70/200 on repetition, which is modest money — the real sanction is the suspension or prohibition of the system that accompanies a repeat, imposed by the AI authorised body itself under new KoAP art. 692-3. Finally, the automated-decision provision is art. 19-1 of the 2013 Personal Data Law, not art. 20 as previously assumed: added by Law No. 231-VIII and in force the same 18 January 2026, it bans automated processing that creates, changes or ends a person's rights or legitimate interests without consent or a statutory basis, with no contract exception and no written-consent formality, and gives three working days to answer an objection — against Uzbekistan's ten and Russia's thirty.

SA Saudi Arabia's AI-training exception is narrower than recorded: Art.30 of the Implementing Regulation adds six controls, not one

correction logged 20 Aug 2026

A primary-source read of the Implementing Regulation in Umm Al-Qura shows Art.30 subjects the Art.26(4) AI-training exception to six cumulative controls, of which only the record-keeping duty had been captured. Two of the others are material to scope: Art.30(2) withholds the exception where the work is used within a purely commercial frame, unless the use is insubstantial in relation to the work or does not affect its normal exploitation; and Art.30(5) prohibits adaptation, republication, making the work available to the public, and unnecessary inclusion of the work in the final products without the rightholder's permission. The record-keeping duty is also narrower than stated: the records are produced to a competent body examining a dispute relating to that use, not to any authority on demand. Art.60 of the Law confirmed as the commencement rule — the Regulation applies from the Law's own entry into force, so Art.30 binds from 12 Aug 2026 rather than from its 31 Jul 2026 publication, and the row's date is unchanged.

Primary source — uqn.gov.sa ↗

NE Niger: an ordonnance of the same date repeals unspecified provisions of Loi 2022-59, so art. 52 is placed under a supersession watch

correction logged 20 Aug 2026

Reading the signed original of Décret n° 2026-310/PRN/PM confirms the dissolution of the HAPDP (art. 1(9)) and the transfer of its missions to the Ministries of Justice and of the Interior (art. 2(8)), and confirms that the décret itself does not touch art. 52. But its fifth recital cites Ordonnance n° 2026-30 du 8 juin 2026, which abrogates certain laws creating regulatory authorities and certain provisions of Loi n° 2022-59 itself. That text could not be obtained from any official host, and the HAPDP's own legislation index has not been updated since the dissolution, so which provisions are repealed is unverified and the earlier statement that art. 52 is unaffected cannot be supported. The row stays live at medium confidence with the repeal risk recorded. Separately, the art. 31 prior-authorisation regime and the arts. 92 to 94 sanctions were vested in the HAPDP and now have no named holder.

Primary source — africadataprotection.org ↗

NE Niger dissolves the HAPDP, its data-protection regulator, transferring competencies to the Justice and Interior ministries

correction logged 20 Aug 2026

Décret n° 2026-310/PRN/PM of 8 June 2026, signed by President Abdourahamane Tiani, dissolved nine public entities including the Haute Autorité de Protection des Données à caractère Personnel (HAPDP), the authority that administered Loi n° 2022-59's art. 31 prior-authorisation regime and its arts. 92-94, 102, 108-110 enforcement powers. Data-protection matters now fall within the remit of the Ministries of Justice and Interior; the decree does not amend the substantive text of art. 52 itself.

Primary source — africadataprotection.org ↗

CHTR Switzerland and Türkiye join — two large non-EU European economies whose automated-decision rules forbid nothing

Added logged 19 Aug 2026

The African sweep that closed with the Malabo parties left a gap much closer to the EU row, and this pass fills it. Switzerland and Türkiye are the two largest European economies outside the EU and the EEA, neither is covered by the GDPR, and until now neither carried a row — so a reader checking whether an automated hiring sift or a credit engine was regulated in Zurich or Istanbul found nothing on the tracker, and the honest answer in both places is that it is regulated, but not by a prohibition. That is the finding the two rows share. Swiss revFADP art. 21 is titled, in the official English of the Fedlex consolidated text, «Duty to provide information in the case of an automated individual decision» — the rubric almost every secondary account silently rewrites as «automated individual decision-making». Nothing in it forbids a solely automated decision. It requires the controller to inform, and it arms two safeguards, a point of view and a review by a natural person, only on request. Its exception is the detail worth carrying: art. 21(3)(a) disapplies the article where the decision is directly connected with a contract between controller and data subject and the data subject's request is granted, which means the declined loan, the rejected policy and the failed tenancy screen are the cases the exception does not reach. Turkish KVKK art. 11(g) goes further in the same direction and is drafted as an objection right rather than as a rule about what may be done — the controller may take the decision and the data subject objects afterwards — with no exception architecture, no human-intervention right, no right to contest and no logic-disclosure limb anywhere in art. 11. Its trigger is narrower than the European one, requiring a result «against the person», so a favourable automated decision produces no right at all. Both rows also correct a date and a penalty that the secondary literature routinely gets wrong. Türkiye's article is in force from 7 October 2016, not from the 7 April 2016 publication of Law No. 6698: art. 32 puts arts. 8, 9, 11, 13, 14, 15, 16, 17 and 18 into force six months after publication, and that tranche carries the right and its entire enforcement route together. And no fine attaches to art. 11 at all — art. 18(1) penalises five things and breaching a data subject's rights is not among them, so the route runs through an art. 15(5) Board remediation order and only then to art. 18(1)(c) for non-compliance, at a statutory 25,000 to 1,000,000 lira whose printed figures are a decade out of date because art. 18 fines are uprated every calendar year under the Misdemeanour Law. The Swiss penalty is mis-stated in the opposite direction. The widely quoted CHF 250,000 is real but is aimed at a natural person, is prosecuted only on complaint, and does not cover every breach of art. 21: art. 60(1)(b)(1) reaches the art. 21(1) duty to inform and para. 2 appears nowhere in the list, so a controller who refuses a request for human review commits no offence. Where the undertaking is fined instead of the individual, art. 64(2) caps that at CHF 50,000 and allows it only as a proportionality shortcut. The FDPIC has no administrative fining power; prosecution is a cantonal matter under art. 65 with a five-year limitation under art. 66. Both entries were verified against primary text — the Fedlex consolidated English of SR 235.1 at status 1 September 2023, and the Authority's own English text of Law No. 6698 — and both are recorded as high confidence. The current-year Turkish fine figures are deliberately not published in the row: only the statutory band and the revaluation mechanism are, because the Authority's annual announcement was not retrieved for this check.

MZ Mozambique joins on a treaty, not a statute — the Malabo Convention's automated-decision bar, in force since 2023

Added logged 19 Aug 2026

Mozambique joins the tracker with mz-malabo-art14-5, and it is the first row whose obligation arrives by treaty rather than by legislation. Mozambique has no national data-protection statute — a Proposta de Lei establishing a Regime Jurídico de Proteção de Dados Pessoais and creating an Autoridade Nacional de Proteção de Dados was approved by the Council of Ministers on 3 March 2026 and is still before the Assembleia da República — but it ratified the African Union Convention on Cyber Security and Personal Data Protection (Malabo, 27 June 2014) on 2 December 2019 by Resolução n.º 5/2019 of the Assembleia da República and deposited its instrument with the Chairperson of the African Union Commission on 21 January 2020. Art. 18 of the Constitution of the Republic of Mozambique puts validly approved and ratified treaties into the domestic legal order on official publication, with the rank of ordinary legislation. Art. 14(5) of the Convention provides that a person shall not be subject to a decision which produces legal effects concerning them or significantly affects them to a substantial degree and which is based solely on automated processing of data intended to evaluate certain personal aspects relating to them. The date is computed from the instrument. Art. 36 makes the Convention enter into force thirty days after the depositary receives the fifteenth instrument of ratification, with no separate per-State clause. On the African Union's own status list the fifteenth deposit is Mauritania's, on 9 May 2023, which puts entry into force at 8 June 2023 — the date carried here. Mozambique's signature, ratification and deposit all precede it, so the treaty's own date governs rather than the deposit. Two things make this row unusual in opposite directions. Art. 14(5) is the most absolute automated-decision bar on the tracker: it has no contract limb, no consent limb and no legal-authorisation limb, where art. 15(2) of Directive 95/46/EC — its ancestor — and every Lusophone and Francophone row derived from it carry at least two. But the Convention never requires an explanation. The art. 16 information duty runs (a) to (h) and the art. 17 access right runs (a) to (d), and neither carries an automated-decision or logic item; art. 18 gives objection on legitimate grounds and art. 19 rectification, blocking and erasure. There is no right to human intervention and no right to contest. Mozambique is the Angola shape reached by a different road: the machine decision is forbidden and never has to be explained. The row is carried at medium confidence, and the reason is domestication rather than dating. Art. 8(1) frames the Convention's personal-data chapter as a commitment by each State Party «to establishing a legal framework», and art. 14(1) is drafted the same programmatic way — «State Parties shall undertake to prohibit». Art. 14(5) is not: it states a rule about what may be done to a person, and reads as self-executing where its own paragraph 1 does not. No Mozambican court has been shown to apply it, no domestic instrument repeats it, no supervisory authority has been established, and no penalty attaches — art. 12(2)(h) leaves sanction amounts to national law, and Mozambique has set none. No monetary range is recorded rather than one imported from a peer jurisdiction. What Mozambique does have was checked and ruled out. The personal-data chapter of Lei n.º 3/2017, de 9 de Janeiro (Lei de Transacções Electrónicas) at arts. 63-65 covers accuracy and purpose limitation, notice on indirect collection, security, access, reasoned refusal and objection, a bar on cross-institution sharing and a designated responsible individual — and nothing about automated decisions or profiling. The words «perfil» and «perfis» do not occur in the Law, and every occurrence of «automatizado» is UNCITRAL automated-message-system vocabulary about contract formation, input errors and automated calling systems. INTIC, the national ICT institute, publishes the same enumeration of the country's current framework — Constitution art. 71, Lei 3/2017 arts. 63-65, Decreto n.º 67/2017 on e-government interoperability, and the regulation on intermediate electronic service providers — and none of it regulates automated decision-making. Guinea-Bissau was swept in the same pass and is a closed negative: it signed the Convention on 31 January 2015 but has never ratified it, has no data-protection law and no data-protection authority, and the legislation index of ARN, its national regulator, carries only the 2013 telecommunications decrees. Four further Convention parties — Mauritius, Namibia, Zambia and Mauritania — are bound by art. 14(5) and are not yet tracked; they are recorded as a follow-up coverage gap, Namibia most sharply, since it has no national data-protection statute and should be the same shape as this row.

MRMUNAZM The four remaining Malabo Convention parties join — three on their own statutes, Namibia on the treaty alone

Added logged 19 Aug 2026

Four African Union Convention parties join the tracker in one pass, and the pass answered a structural question that opened it. When Mozambique was added on art. 14(5) of the Malabo Convention, four further parties were recorded as bound and untracked — Namibia, Zambia, Mauritius and Mauritania — with the worry that four more per-country treaty rows would be a pattern rather than a one-off, and that the Convention might belong on the tracker as a single African Union regional row instead. Reading the four national statutes dissolved the worry. Three of the four have their own automated-decision bar in national law, so they are ordinary national rows on the same footing as the eleven Convention parties already tracked, and the treaty runs behind them as background rather than as the operative rule. Only Namibia is the Mozambique shape. The pattern is two treaty rows, not five. Zambia joins with zm-dpa2021-s62. Section 62(1) of the Data Protection Act, 2021 (Act No. 3 of 2021) bars any decision based solely on automated processing, including profiling, producing legal effects concerning the data subject or similarly affecting them, with three exceptions at s. 62(2) — contract necessity, authorisation by any written law, explicit consent — and, where one is relied on, a s. 62(3) safeguard duty carrying the full triad the Convention omits: human intervention on the part of the controller, the right to express a point of view, and the right to contest the decision. Section 62(4) adds a separate bar on automated processing of sensitive personal data absent express consent, public interest or statutory permission with safeguards. The explanation limb is reactive only — s. 58(2)(d) gives access to information about the basic logic involved in any automatic processing in case of automated decision making, while the s. 64 duty to inform at direct collection runs (a) to (f) and carries no automated-decision item — so a Zambian controller must explain when asked and need not volunteer that a machine decided. Section 57 is the sleeper: notification to the Commissioner of any third-party agreement allowing that third party to trade on a data subject's profile. The Zambian date and the Zambian penalty both had to be traced rather than assumed. Section 1 is a bare enabling clause and the 24 March 2021 assent date on the face of the Act is not the operative date; the appointing instrument is Statutory Instrument No. 22 of 2021, the Data Protection Act (Commencement) Order, 2021, made by the Minister of Transport and Communication on 31 March 2021, whose para. 2 brings the Act into operation on the date of publication of the Order — published 1 April 2021, which is the date carried. On penalty, the Act penalises by Part: s. 18(1) covers Part IV at up to one hundred million penalty units or 2% of turnover, and s. 55(1) covers Part VIII at 2% of turnover or two million penalty units. Section 62 sits in Part IX, and Part IX has no equivalent clause. Section 77, the general penalty, reaches only a person who commits an offence for which no specified penalty is provided, so it presupposes an offence rather than creating one. No offence attaches to s. 62. The commonly repeated figure of a fine plus three years' imprisonment for automated-decision breaches in Zambia is s. 77 misapplied; the real remedies are a s. 68 complaint to the Commissioner, a s. 69 appeal to the High Court and s. 72 compensation. Mauritius joins with mu-dpa2017-s38, and it is the fullest automated-decision regime of any Convention party. Section 38(1) of the Data Protection Act 2017 (Act 20/2017) carries the GDPR right in GDPR order, with the three exceptions at s. 38(2) and the controller's own safeguard duty at s. 38(5) confined to the contract and explicit-consent limbs — the legal-authorisation route being policed instead by the safeguards the authorising law must itself lay down. Section 38(3) goes further than GDPR art. 22(4): automated processing intended to evaluate certain personal aspects shall not be based on special categories of personal data at all, with no consent or substantial-public-interest escape. The explanation duty runs three times over: proactively at s. 23(1)(g) with the logic involved and the significance and envisaged consequences, reactively at s. 37(2)(h) inside the right of access, and again at s. 38(4), which requires the s. 23 information to state the existence of processing for such a decision and its envisaged effects whenever an exception is used. Section 34(2)(a) makes an impact assessment mandatory beforehand. And unlike Zambia, the penalty reaches it: s. 43(1) catches «any person who commits an offence under this Act for which no specific penalty is provided or who otherwise contravenes this Act» — a fine not exceeding 200,000 rupees and imprisonment not exceeding 5 years, drafted with «and» rather than «or» between them, which on a literal reading makes both cumulative. The Act binds the State under s. 3(1) and treats each Ministry as separate from every other under s. 3(2). In force since 15 January 2018 by Proclamation No. 3 of 2018, not the 8 December 2017 passage, the 22 December 2017 assent or the 23 December 2017 gazetting. Mauritania joins with mr-loi2017020-art19, and its first paragraph has no counterpart anywhere else on the tracker. Article 19 of Loi n° 2017-020 du 22 juillet 2017 opens by barring any judicial decision involving an assessment of a person's conduct from being founded on automated processing intended to evaluate certain aspects of their personality — a rule addressed to courts, cutting off algorithmic input into sentencing, bail and every other judicial appraisal of behaviour. Its second paragraph is the general bar, and it is art. 2 of France's Loi n° 78-17 in its pre-2018 wording carried across whole: no exception limb of any kind — no contract, no consent, no legal authorisation — no profiling definition, and an «effets juridiques» threshold with no «significantly affects» limb, so a purely commercial automated refusal falls outside it where it would be caught in Zambia, Mauritius or under the Convention. There is no logic item anywhere: the art. 53 right of access runs to five items and the information duty at collection to nine, and neither carries one, and there is no right to human intervention and none to contest. Mauritania is the Angola shape at a different latitude — the machine decision is forbidden and never has to be explained. Scope under art. 3 is the means-in-territory test rather than the GDPR's targeting test. The penal articles, arts. 84 to 98, were read one by one and none of them names art. 19 or cross-refers to it, so no criminal penalty attaches; what reaches it is art. 80, letting the Autorité de Protection des Données à caractère personnel impose pecuniary sanctions proportionate to gravity, up to ten million ouguiyas on a first breach and fifty million or 5% of pre-tax turnover on a repeat within five years. Those figures predate the 1 January 2018 redenomination at ten old ouguiya to one new, so in present-day currency they are MRU 1,000,000 and MRU 5,000,000. The row is carried at medium confidence for two reasons that are not about the text of art. 19: the transitional regime at arts. 99 and 100 runs from a compound trigger, entry into force and the effective establishment of the Authority, and the Authority was stood up years late; and every figure in the Law is denominated in the old currency. Namibia joins with na-malabo-art14-5, and it is the Mozambique shape exactly — the obligation arrives by treaty because there is no statute for it to arrive by. Namibia never signed the Convention; it acceded on 25 January 2019 and deposited on 1 February 2019, and its signature column on the African Union's status list is empty. Reception is more direct than in Mozambique: art. 144 of the Constitution provides that unless otherwise provided by the Constitution or an Act of Parliament, the general rules of public international law and international agreements binding upon Namibia under the Constitution shall form part of the law of Namibia — automatic incorporation with no publication precondition, where Mozambique's art. 18 conditions entry into the domestic order on official publication. Two qualifications cut the other way and keep the row at medium confidence alongside the same self-executing question art. 14 raises inside itself: the phrase «under this Constitution» routes incorporation through art. 63(2)(e), the National Assembly's power to agree to ratification of or accession to international agreements, and the opening words make art. 144 expressly subject to displacement by an Act of Parliament — an Act of Parliament on precisely this subject being pending. The Data Protection Bill, drafted in successive versions since 2013 and most recently circulated as the Data Protection Bill 2023, carries its own solely-automated-decision provision with consent and contract exceptions and a human-intervention safeguard; the Ministry of Information and Communication Technology said in August 2025 it was in its final stages and would be tabled between September and October 2025. It has not been enacted, and until it is the Convention is the only automated-decision rule in force in Namibia. When it passes, this row is superseded rather than duplicated. Article 13 of the Constitution was checked and ruled out: it gives a privacy right against interference with homes, correspondence and communications, and no data-processing regime. The dating of all four is anchored the same way, and it is worth restating because it is counter-intuitive. Art. 36 of the Convention brings it into force thirty days after the depositary receives the fifteenth instrument of ratification, and there is no separate per-State entry-into-force clause — so a party that deposited earlier is bound from the collective date, not from its own deposit. The fifteenth deposit is Mauritania's, on 9 May 2023, which puts the Convention in force on 8 June 2023 for all sixteen parties, Mauritius (deposited 2018), Namibia (2019) and Zambia (2021) included. Mauritania is therefore both bound by art. 14(5) and the reason art. 14(5) binds anyone. Where a national statute and the Convention both apply and diverge, the national statute is carried as the operative rule and the treaty is recorded behind it. The divergence is real and it is not academic: art. 14(5) admits no contract, consent or legal-authorisation exception, while s. 62(2) in Zambia and s. 38(2) in Mauritius admit all three. A controller relying on explicit consent in Lusaka or Port Louis is on solid statutory ground and unresolved treaty ground. That tension is recorded rather than resolved. With these four, all sixteen States that have deposited an instrument of ratification of the Convention now carry a row — Angola, Cabo Verde, Congo, Côte d'Ivoire, Ghana, Guinea, Mauritania, Mauritius, Mozambique, Namibia, Niger, Rwanda, São Tomé and Príncipe, Senegal, Togo and Zambia. The coverage gap opened by the Mozambique row is closed. What remains open is a structure question rather than a data one: whether the Convention should additionally exist as a single African Union regional row alongside the fourteen national-statute rows and the two treaty-only rows, or whether per-country rows remain the right shape now that the treaty-only cases have turned out to be two rather than five. 142 -> 146 obligations / 51 -> 55 regions / 85 -> 89 countries.

AOCVST Cabo Verde joins as the Lusophone prohibition rewritten to the GDPR's shape — and Angola loses its uniqueness claim

Added logged 19 Aug 2026

Cabo Verde joins the tracker with cv-lei133-art23, from art. 23.º of Lei n.º 133/V/2001, de 22 de janeiro, in the consolidated text republished by Lei n.º 121/IX/2021, de 17 de março, in force in this wording since 16 April 2021 (art. 6 of the amending Law: thirty days after publication in Boletim Oficial I Série n.º 28 of 17 March 2021). It is the third Lusophone row after Angola and São Tomé e Príncipe and the only one of the three rewritten since the GDPR. The 2021 amendment replaced nos. 1 and 2 of the article and cut the Lei 67/98 evaluative limb — processing «destinado a avaliar determinados aspectos da sua personalidade, designadamente a sua capacidade profissional, o seu crédito, a confiança de que é merecedora ou o seu comportamento» — putting «incluindo a definição de perfis» in its place, with profiling defined at art. 5(1)(j) in GDPR art. 4(4) terms. The bar therefore no longer asks what the processing was for: any solely automated decision producing effects in a person's legal sphere or significantly affecting them is caught, which is wider than either Lusophone sibling. Scope was rewritten with it, from the means-in-territory test Angola and São Tomé still use to a GDPR art. 3 shape reaching controllers with no presence in Cabo Verde that offer goods or services to, or monitor the behaviour of, people who are there. Art. 14(1)(c) gives a right to know the logic underlying the automated processing as regards automated decisions including profiling, cross-referring art. 23(1) by name — more than São Tomé's «razões» and more than Angola, which gives nothing — but the art. 13 information duty carries no automated-decision item, so the right is reactive, and there is no right to human intervention and no right to contest. Art. 50(1)(b) names art. 23 in the enumerated list of administrative infractions: coima 100,000$00 to 1,000,000$00, negligence always punishable, with accessory prohibition of the processing under art. 69 and qualified disobedience under art. 62 for defying a CNPD order to stop. This row also corrects a claim published on 18 August. The Angola entry said art. 29(3) — the limb letting the Agência de Protecção de Dados licence an otherwise-prohibited automated decision and write the safeguards itself — had no analogue in any other tracked statute. Cabo Verde's art. 23(3) is the same clause, naming the Comissão Nacional de Proteção de Dados, and both descend from art. 13(3) of Portugal's Lei 67/98. The regulator-licence route is a shared Lusophone inheritance, not an Angolan invention; São Tomé e Príncipe is the member of the group that dropped it. The Angola and São Tomé entries and both sets of jurisdiction notes have been amended accordingly.

ST São Tomé e Príncipe: the same Lusophone prohibition as Angola, without the regulator's escape hatch

Added logged 18 Aug 2026

São Tomé e Príncipe joins the tracker with st-lei32016-art13, the second Lusophone row and the closest textual sibling to Angola's. Art. 13.º of Lei n.º 3/2016 reproduces the Portuguese Lei 67/98 prohibition almost word for word — no decision producing effects in a person's legal sphere or significantly affecting them may be taken exclusively on automated processing intended to evaluate aspects of their personality, namely professional capacity, credit, trustworthiness or conduct. The comparison is what makes the row worth having. São Tomé keeps only the parent law's two exceptions, contract and authorising statute, and gives its Agência Nacional de Protecção de Dados Pessoais no power to licence a prohibited decision — the art. 29(3) limb that still leaves Angola alone on the tracker. It is also the more transparent of the two: art. 11(1)(c) lets the data subject obtain knowledge of the reasons underlying the automated processing of their data, where Angola's Law carries no logic or reasons limb anywhere. And where Angola's art. 29 sits outside both contravention lists, São Tomé's art. 32(1) names art. 13 explicitly, so breach is an administrative infraction of 25,000,000 to 50,000,000 dobras as written in the 2016 text, applied by the Agência, with accessory prohibition of the processing and a qualified-disobedience crime for defying an order to stop. Approved 15 February 2016, promulgated 18 March, published in the Diário da República n.º 39 of 10 May 2016; art. 47 sends entry into force to the general rule rather than fixing a date, and that residual is stated on the entry rather than smoothed over.

CGGAMG Madagascar, Congo-Brazzaville and Gabon — and the correction of a claim that Guinea's judicial limb stood alone

Added logged 18 Aug 2026

Madagascar, the Republic of the Congo and Gabon are the eighteenth, nineteenth and twentieth African jurisdictions on the tracker and the fortieth, forty-first and forty-second in the atlas region set. All three were read article by article in an official text, and all three carry an operative automated-decision bar. Madagascar's Loi n° 2014-038 states it as a founding principle at art. 3, in the general-provisions chapter, with the wide trigger — any administrative and private decision involving an appraisal of human conduct — and no carve-out of any kind. Congo's Loi n° 29-2019 states it at art. 13 on the narrow Directive 95/46/EC trigger confined to decisions producing legal effects, with the familiar deeming clause for contract decisions and for decisions satisfying the person's own requests. Gabon's Loi n° 025/2023 states it at art. 77 on the same narrow trigger, appended, as its 2011 predecessor was, to the article on offence and conviction data. Two findings are worth separating out. The first is Gabon's: the recast defines Intelligence Artificielle in its definitions article, along with raw and input data in the field of artificial intelligence and the artificial neuron, and pairs the bar with the full GDPR transparency package at art. 43 — the existence of automated decision-making including profiling, meaningful information about the underlying logic, and the significance and envisaged consequences — plus a distinct right to know the reasoning underlying the processing where its results are applied. No other data-protection statute in the Francophone African block defines artificial intelligence at all. The second is a correction. The Guinea entry published on 17 August said that art. 27's omission of the word "seul" from its judicial limb was unique on the tracker. It is not. Madagascar's art. 3, Congo's art. 13, Gabon's art. 77 and Algeria's art. 11 all drop the qualifier from the judicial limb while keeping it in the limb that follows, which makes the asymmetry a shared inheritance of the Francophone family rather than a Guinean innovation. The Guinea row and its jurisdiction notes have been amended; what remains true of Guinea, and is now stated on that narrower basis, is that it alone combines the strict judicial limb with a wide second limb, no exception of any kind, and a general penalty article reaching 7 per cent of turnover. A third observation follows from Madagascar and is recorded here because it bears on how the remaining Francophone jurisdictions should be read: Madagascar is not an ECOWAS member and never has been, yet it takes the wide "appréciation sur un comportement humain" trigger that Côte d'Ivoire, Burkina Faso, Niger, Mali and Guinea take. The ECOWAS Supplementary Act can therefore no longer be treated as the hinge that decides which drafting a Francophone state adopts.

GQ Equatorial Guinea — the widest evaluation-challenge trigger on the tracker, and Chad closed negative across all 98 articles

Added logged 18 Aug 2026

Equatorial Guinea joins the tracker with gq-ley1-2016-art13b, and it breaks the Central African pattern. Every other row in the block — Cameroon, Chad, the Central African Republic, Gabon, Congo-Brazzaville — is Francophone and drawn from Directive 95/46/EC or from the GDPR. Ley núm. 1/2016, de 22 de julio, de Protección de Datos Personales is Hispanophone and drawn from the Spanish LOPD, and it shows in the shape of the rule. Art. 13(b), Impugnación de valoraciones, does two things no other tracked provision does at once: it makes the controller disclose el programa utilizado, the program used in the processing, not merely the logic involved; and it lets the data subject challenge todo acto administrativo o decisión involving an evaluation of their conduct or behaviour and a definition of their characteristics or personality, with no requirement that the decision be solely automated and no legal-effects threshold. On trigger width it is the broadest evaluation-challenge right on the tracker. On depth it is among the thinnest: there is no prohibition on automated decisions anywhere in the Law, no human-intervention right, and no duty to tell anyone up front that a machine is scoring them, so the right is purely reactive — the same structural weakness recorded for the Central African Republic a heartbeat earlier, reached from a completely different legal ancestry. Enforcement is administrative and sits with the Ministro de Telecomunicaciones y Nuevas Tecnologías; the Órgano Rector de Protección de Datos Personales that art. 15 designates as guardian of the rights still awaits its creating Decree. Refusing an art. 13(b) request is an infracción grave: 500,001 to 5,000,000 FCFA, suspension of the processing, and sealing of the premises for up to fifteen working days. The date recorded is 22 July 2016, the date the Law carries on its face; the Disposición Final gives a twenty-day vacatio from publication in the Boletín Oficial del Estado, whose issue date is not stated in the official copy and is not published online, so the in-force day is a range in August or September 2016 rather than a verified date — hence medium confidence. Read in the official scanned copy published by the Ministerio de la Función Pública y la Reforma Administrativa, a 45-page image-only scan read as page images. The same heartbeat closed Chad negative: Loi n° 007/PR/2015 was read across all 98 articles and its implementing Décret n° 075/PR/2019 across all 16, and neither carries an automated-decision or profiling rule of any kind — not even the art. 12(a) access limb that the Central African Republic has.

CD The DRC completes the pair: Angola forbids the automated decision, Kinshasa makes you explain it

Added logged 18 Aug 2026

The Democratic Republic of the Congo joins the tracker with cd-codenum-art209, drawn from Ordonnance-loi n° 23/010 du 13 mars 2023 portant Code du numérique. Read next to the Angolan row added the same day, it splits the GDPR's automated-decision package cleanly in two. Angola's Lei 22/11 art. 29 forbids the solely automated evaluative decision and never once requires anyone to explain the logic. The DRC never forbids it and requires the logic three times over: art. 209 on request, art. 220 up front at collection, art. 235 where the data were collected elsewhere — each time «des informations utiles concernant la logique sous-jacente, ainsi que l'importance et les conséquences prévues de ce traitement pour la personne concernée». Art. 245 adds the DPIA trigger for systematic automated evaluation including profiling. What is missing is any art. 22 analogue: the rights section runs from art. 209 to the general opposition right in art. 213 without ever reaching a prohibition, there is no human-intervention or contest right, and art. 187's prior-authorisation list does not cover profiling. Scope under art. 184 is the widest on the African rows — the State, provinces, decentralised entities, legal and natural persons, and processing carried out on the national territory or abroad. Enforcement is two-step: a warning and a mise en demeure of at most eight days under art. 256, then 8,000,000 to 200,000,000 Congolese francs under art. 257, with a 5% of turnover limb reserved for violations that led to death or attempted murder and a cease-processing injunction for those endangering national security. In force since 13 March 2023 under art. 390, the date of promulgation. Read in the certified copy issued by the Cabinet of the President of the Republic, cross-checked against a born-digital rendering covering arts. 186-390.

CF Central African Republic — a data-protection statute that lets you contest an automated decision but never forbids one, and defines profiling without regulating it

Added logged 18 Aug 2026

The Central African Republic is the twenty-second African jurisdiction on the tracker and the forty-fourth in the atlas region set, and it is the first that had to be added for what its statute does not say. Loi 24.001 du 25 janvier 2024 portant protection des données à caractère personnel is a full modern data-protection law — fifty-eight articles, an independent administrative authority, a data protection officer, turnover-based administrative fines, a nine-article penal chapter — and it contains no rule against automated decisions at all. The word automatisé occurs three times in the whole text. Twice it is in the art. 6 definitions. The third and only operative occurrence is the third indent of the art. 30 access right, which gives the data subject the information allowing them to know and to contest the mechanism of the automated processing where a decision is taken on its foundation and produces legal effects in respect of them. That indent is Directive 95/46/EC art. 12(a) verbatim; what is missing is Directive art. 15, the prohibition that every other Francophone African statute on the tracker carries in some form — Senegal, Côte d'Ivoire, Benin, Burkina Faso, Mali, Niger, Togo, Guinea, Madagascar, Congo-Brazzaville, Gabon, Morocco and Algeria all state that a decision producing legal effects may not be taken on the sole foundation of an automated processing. The Central African Republic took the access half of the template and left the bar behind. The result is the only jurisdiction on the tracker where automated decision-making is lawful without qualification and the data subject's sole remedy is to ask, after the fact, how it was done. Two details sharpen the finding. The first is that the omission is not obviously deliberate drafting economy, because art. 6 imports the GDPR art. 4(4) definition of Profilage in full, including the prediction of work performance, economic situation, health, preferences, interests, reliability, behaviour, location and movements — and then never uses the defined term anywhere in the operative text. A GDPR-lineage definition sits orphaned inside a Directive-lineage rights chapter, which makes the Central African Republic the first entry on the tracker to define profiling without regulating it. The second is that the art. 35 information duty owed at collection, which in the Directive-derived statutes is where the logic of an automated decision usually has to be disclosed proactively, lists only identity, purpose, whether the data are obligatory or optional, categories, recipients and the rights of objection, access and rectification. Nothing about automated logic. So the art. 30 right can only be triggered by a person who already suspects a machine decided, and art. 31 then removes it entirely for public-security and offence-detection processing. On dates: art. 58 is unusually clean for the region, providing in terms that the Law takes effect from the date of its promulgation, so unlike Morocco, Congo-Brazzaville, Gabon and Cameroon there is no publication-to-force assumption to make. The residual uncertainty is the opposite one — the promulgation date does not survive in the scanned regulator copy, whose signature page over President Touadéra's signature is stamped and handwritten, so 25 January 2024 is taken from ARCEP's own regulation index citing the file it hosts. Confidence is medium on that ground alone. Two structural notes for the region file: art. 57 gave the Ministry twelve months from promulgation to stand up the supervisory agency, a deadline that expired on 25 January 2025 with the Ministry discharging its missions in the meantime, and arts. 24 to 27 are the first transfer regime on the tracker to draw the free-flow perimeter around CEMAC and CEEAC rather than around a national adequacy list, which matters for anyone modelling Central African data flows as a bloc rather than a set of countries.

CM Cameroon — the first GDPR-shaped automated-decision right in Francophone Africa, and the only African statute that criminalises profiling

Added logged 18 Aug 2026

Cameroon is the twenty-first African jurisdiction on the tracker and the forty-third in the atlas region set, and it changes the shape of the African block in three ways. The first is lineage. Every Francophone African row added so far — Senegal, Côte d'Ivoire, Benin, Burkina Faso, Mali, Niger, Togo, Guinea, Madagascar, Congo-Brazzaville, Gabon, Morocco and Algeria — states its automated-decision rule in the Directive 95/46/EC form: a judicial limb, a second limb about decisions taken on the sole foundation of an automated processing, and a deeming clause for contract decisions. Loi n° 2024/017 du 23 décembre 2024 does none of that. Art. 44 is a GDPR art. 22 right of objection, held by the data subject rather than a prohibition addressed to decision-makers, and art. 44(3) carries all three limbs of the art. 22(3) safeguard — human intervention, the right to express a point of view, the right to contest the decision. The Francophone-equals-Directive assumption that has held for thirteen consecutive rows does not survive Cameroon; the dividing line is the date of the statute, not the legal family. The second is scope. Art. 44 states no threshold at all: no requirement that the decision produce legal effects, as in Congo, Gabon, Togo, Senegal, Morocco and Algeria, and no significant-effect limb either, which makes the Cameroonian trigger wider than the GDPR's own. Its exception list is correspondingly narrower — informed prior explicit consent, or authorisation by a law carrying appropriate safeguards, and nothing else. There is no contract carve-out anywhere in art. 44, which is the single most commonly used escape hatch in the Directive-derived statutes. The third is enforcement, and it is the finding worth reading twice. Art. 65 punishes the controller or processor who carries out or causes to be carried out a processing of personal data for profiling purposes with three to ten years' imprisonment and a fine of one million to twenty million francs CFA. That is an offence attaching to profiling itself, not to any breach of the art. 44 right, and read with the definition of profilage in the Law's definitions article — automated processing used to evaluate personal aspects relating to a natural person, notably health, preferences, location and economic situation — it reaches ordinary commercial scoring and segmentation. Nothing comparable exists anywhere else in the African block, where the automated-decision article is typically reached, if at all, only by an administrative catch-all: in Ghana, Uganda, Madagascar, Congo-Brazzaville, Gabon, Morocco and Algeria no penal article touches it. Legal persons face up to one billion francs CFA under art. 71. On dates: the Law was promulgated on 23 December 2024 and carries no commencement article, art. 75 providing only for registration, publication under the urgency procedure and insertion in the Journal Officiel in French and English. Art. 73 gave controllers eighteen months from promulgation to conform, so the conformance window closed on 23 June 2026 and the duty is now fully operative. The row is dated from promulgation, consistent with how the Rwandan and Indonesian transitional windows were treated, with the June 2026 date recorded in the entry's status note. The text was read page by page in the certified true copy published by the Presidency of the Republic.

BI Burundi writes the strongest automated-decision rule on the tracker — and the first that says «intelligence artificielle» out loud

Added logged 18 Aug 2026

Burundi joins the tracker with bi-loi103-art19-20, from Loi n°1/03 du 10 mars 2026 portant protection des données à caractère personnel, promulgated at Gitega and in force the same day. Three things make it the strongest automated-decision regime tracked so far. First, art. 20 is a permission rule: decisions with legal or important effects are authorised only under a legislative or regulatory act with appropriate safeguards, with consent, or where strictly necessary to conclude or perform a contract. Second, where such a decision is permitted the data subject may have it reformulated — they file written observations and «une nouvelle décision motivée est prise par un être humain, qui remplace entièrement la première». That is a right to have the machine's decision vacated and retaken, which goes past the GDPR's right to obtain human intervention. Third, art. 19 requires the underlying logic to be explained «en termes clairs et simples» and, where the system only assists a human, requires the controller to describe what the human decider actually contributed and on what methods and criteria — a rubber-stamp rule with no analogue elsewhere on the tracker. Art. 17(7) also makes processing «à l'aide de l'intelligence artificielle pour la prise de décision automatisée» a mandatory disclosure at collection, the first time a tracked data-protection statute names AI in an operative duty, though art. 4 does not define the term. Enforcement is indirect — the penal chapter names no article, so arts. 19-20 run through art. 48's unfair, unlawful or non-transparent processing offence, up to five years and 10,000,000 Burundian francs for a natural person and 20,000,000 for a private legal person, doubled for a responsable majeur de traitement. Two forward deadlines come from art. 53: existing processing has until 10 September 2026 in the private sector and 10 March 2027 in the public sector. Read in the signed and sealed original, 32 bilingual French-Kirundi pages, published by the regulator ARCT on gov.bi.

AO Angola opens Lusophone Africa — and brings the first automated-decision prohibition a regulator can licence

Added logged 18 Aug 2026

Angola joins the tracker with ao-lei2211-art29, the first Lusophone African row and the first row of any lineage where the supervisory authority can itself permit an automated decision the statute otherwise forbids. Lei n.º 22/11, de 17 de Junho, da Protecção de Dados Pessoais descends from Portugal's Lei 67/98 rather than from the Directive 95/46/EC transpositions that shape the Francophone rows or the GDPR that shapes Cameroon's. Art. 29(1) is the classical prohibition — no decision producing effects in a person's legal sphere or significantly affecting them may be taken exclusively on automated processing intended to evaluate aspects of their personality, namely professional capacity, credit, trustworthiness or conduct — and its legal-effects-or-significant-effect threshold makes it narrower than Equatorial Guinea's art. 13(b) or Cameroon's art. 44, both of which bite without one. Art. 29(2) is the familiar contract exception. Art. 29(3) is not familiar at all: the decision may also be permitted quando a Agência de Protecção de Dados o autorize, definindo medidas de garantia da defesa dos interesses legítimos do titular dos dados — where the Agência authorises it and writes the safeguards itself. Every other prohibition on the tracker admits only exceptions fixed in the statute; Angola hands the regulator a case-by-case licensing power over automated decision-making, and whatever protection the data subject gets in that case is whatever the authorisation says. What Angola does not give is disclosure. The art. 25 information duty and the art. 26 access right both run without any automated-decision or logic item, so an Angolan data subject has no route to learn that a machine decided at all — the mirror image of Equatorial Guinea, where the disclosure limb reaches el programa utilizado but nothing forbids the machine. Enforcement of art. 29 is indirect and worth stating plainly: art. 51 lists the finable contraventions by article number (arts. 14-17, 20, 30-32 at USD 75,000-150,000; arts. 6-11, 18, 19, 21-24 at USD 65,000-130,000, trebled for legal persons) and art. 29 is in neither list. A person's remedies are the art. 47 complaint to the Agência, art. 48 judicial reparation for moral or material harm, and the art. 58 crime of qualified disobedience — up to 3 years' imprisonment for failing to interrupt, cease or block a processing after being notified to do so. Art. 55(1)(a) additionally criminalises omitting a request for authorisation to the Agência, which on its face reaches a controller relying on the art. 29(3) route without ever having asked. The date recorded is 17 June 2011: art. 67 puts the Law in force on the date of publication, and it was published in the Diário da República, I Série, n.º 114, of that day, having been approved on 24 May 2011 and promulgated on 8 June 2011. Read in full in the official gazette scan published by the Agência de Protecção de Dados itself — 18 pages, image-only, no text layer, read as page images. A revision of Lei 22/11 went to public consultation on the Government's consultapublica.gov.ao portal from 17 March to 17 April 2025 and is closed; nothing has been gazetted, so the 2011 text is the operative rule and the draft is a watch item rather than a dated entry.

UG Uganda joins the tracker: s. 27 of the Data Protection and Privacy Act, 2019, and Ghana loses its monopoly on hard African deadlines

Added logged 17 Aug 2026

Uganda is the eighth African jurisdiction on the tracker and the twenty-ninth in the atlas region set. Section 27 of the Data Protection and Privacy Act, 2019 (Act 9 of 2019) has been in force since 3 May 2019 — the Act sets no commencement date of its own, so s. 14(1) of the Acts of Parliament Act (Cap. 2) supplies the date of publication in the Gazette, and the Act was published in Uganda Gazette no. 21 of that day. The provision belongs to the UK Data Protection Act 1998 s. 12 lineage that already gave us Ghana's s. 41 and Tanzania's s. 36: a data subject may by written notice require that no decision significantly affecting them be taken solely by automatic means, and, whether or not such a notice has been served, a controller that has taken such a decision must notify the data subject as soon as reasonably practicable and must answer a reconsideration demand. Until today Ghana was the only African row with hard deadlines. Uganda now matches both of Ghana's twenty-one-day clocks — twenty-one days for the data subject to demand reconsideration after being notified, twenty-one days for the controller to report the steps it has taken — and adds a third that no other African row has: under s. 27(5) a data subject who is not satisfied with the controller's answer shall complain in writing to the Authority within fourteen days. That is the tightest end-to-end sequence on the continent. The trade-off is the same one Ghana makes: s. 27(4) excludes pre-contractual consideration, contract formation and contract performance outright, without requiring the safeguards that the GDPR-shaped exceptions in Kenya, Nigeria and Rwanda demand, so the rule simply does not reach the automated credit, insurance and hiring-shortlist decisions that sit inside a contractual frame. Nothing in s. 27 is backed by a fine: Part VIII creates only three offences, none of which touches automated decision-taking, and the sanction route is the Authority's power under s. 32 to direct a remedy. Text verified in the enacted copy published by the Ministry of ICT and National Guidance, including the Clerk to Parliament's certification and the President's assent page of 25 February 2019.

GNTG Togo and Guinea: two art. 27s that split the ECOWAS family, and Guinea's catch-all penalty at 7% of turnover

Added logged 17 Aug 2026

Togo and Guinea are the sixteenth and seventeenth African jurisdictions on the tracker and the thirty-eighth and thirty-ninth in the atlas region set. Both automated-decision rules happen to sit at art. 27 of their statutes, and the coincidence is where the resemblance ends. Togo's Loi n° 2019-014 du 29 octobre 2019 did not take the wider ECOWAS Supplementary Act drafting that Côte d'Ivoire, Burkina Faso, Niger and Mali use. Its second limb is confined to decisions producing legal effects — the Directive 95/46/EC art. 15 trigger — and it carries the Moroccan and Algerian carve-out deeming contract decisions with an opportunity to present observations, and decisions satisfying the data subject's own requests, outside the bar. Togo is a founding ECOWAS member and its Law postdates the Supplementary Act by nine years, which is precisely why every statute in this block is read article by article rather than inferred from membership. Guinea's Loi n° L/2016/037/AN du 28 juillet 2016 goes the other way and is now the strictest formulation tracked. It takes the wider ECOWAS trigger in its second limb, states no exception of any kind, and — alone among every provision on the tracker — omits the word "sole" from its judicial limb: no judicial decision appraising the conduct of a natural person may have as its foundation an automated processing intended to evaluate aspects of that person's personality, full stop. The qualifier appears in the second limb of the same article, so its absence from the first is a drafting choice on the face of the enacted text. Enforcement diverges just as sharply. Togo's art. 27 is administratively enforced only: its fifteen offences in arts. 79 to 93 each name their own conduct and none reaches an automated decision, leaving the Instance de protection's art. 71 fine of up to 100,000,000 francs CFA and art. 72 astreinte of up to 5,000,000 francs CFA per day. Guinea's art. 56, by contrast, is a general catch-all — any controller or processor who does not respect the provisions of the Law is fined 50,000,000 to 150,000,000 Guinean francs, rising on recidivism within five years to 1,500,000,000 Guinean francs or 7% of pre-tax turnover for an undertaking. It is the only penalty in the Francophone block that reaches the automated-decision article directly, and the highest turnover ceiling in it against 5% in Côte d'Ivoire, Niger and Burkina Faso. Guinea also carries the only express commencement rule in the block: art. 65 attaches force to the date of promulgation, which the signature block stamps as 28 July 2016, resolving against the widely repeated "26 juillet 2016" citation. Both entries are medium confidence for stated reasons. Togo's enacted text is signed "Fait à Lomé, le 30 octobre 2019" in a gazette issue dated 29 October 2019, a one-day discrepancy on the face of the gazette itself; Guinea's promulgation date is a rubber stamp on a scanned signature page and the Journal Officiel citation could not be established. Neither jurisdiction's statute names a predecessor in its abrogation clause, so nothing on the tracker is superseded. The Directive family now splits seven ways with the ECOWAS Supplementary Act as the hinge: narrow legal-effects trigger with a contract carve-out in Morocco, Algeria and Togo; wide administrative-or-private trigger with no carve-out at all in Côte d'Ivoire, Mali, Burkina Faso and Guinea; and the wide trigger with consent, contract and legal-authorisation exceptions in Niger.

SN Senegal joins the tracker: art. 48 of Loi 2008-12, the closest African sibling of Morocco's and Algeria's art. 11

Added logged 17 Aug 2026

Senegal is the twelfth African jurisdiction on the tracker and the thirty-fourth in the atlas region set. Article 48 of Loi n° 2008-12 du 25 janvier 2008 portant sur la protection des données à caractère personnel is recorded from the date the Law itself bears: the copy published by the Commission de Protection des Données Personnelles runs from the exposé des motifs to art. 78 and contains neither a commencement article nor a publication clause. Its three paragraphs are the Directive 95/46/EC art. 15 shape in its purest African form — an absolute bar on a court founding an appraisal of a person's conduct on an automated processing intended to evaluate aspects of their personality; a bar on any decision producing legal effects being taken on the sole basis of an automated processing intended to define the person's profile or evaluate aspects of their personality; and a deeming clause under which contract-formation and contract-performance decisions where the person could present observations, and decisions satisfying the person's own requests, are not treated as taken on that sole basis. That makes Senegal, Morocco and Algeria the closest trio on the tracker, and it splits the Francophone family in two: those three keep the Directive's own drafting, while Côte d'Ivoire's art. 25 and Niger's art. 52 take the wider ECOWAS Supplementary Act A/SA.1/01/10 art. 42 drafting in which the legal-effects threshold disappears and any administrative or private decision appraising human conduct is caught. Senegal predates that Supplementary Act by two years. There is no right to know the logic of an automated processing — the art. 58 information list does not reach it — and no human-review right. Senegal is also the only jurisdiction on the tracker whose data-protection statute creates no offences at all: art. 75 is the entire penal chapter and simply refers infringements to the Penal Code and to the cybercrime law, Loi n° 2008-11 adopted the same day, so no penalty figure can be attributed to art. 48 from the statute itself. What is left is the CDP: warning and mise en demeure under art. 29; on non-compliance, provisional withdrawal of the authorisation for three months becoming definitive on expiry, and a fine of 1,000,000 to 100,000,000 francs CFA under art. 30; in urgency, interruption or blocking for up to three months and temporary or definitive prohibition under art. 31; appeal to the Conseil d'Etat under art. 32. Confidence is medium and one step weaker than Morocco's: no Senegalese official-gazette host resolved, so the date of the Journal officiel carrying the Law could not be established, and entry into force can only be 25 January 2008 or later.

NE Niger joins the tracker: art. 52 of Loi 2022-59, the only rule anywhere on the tracker that names artificial intelligence inside a data-protection automated-decision article

Added logged 17 Aug 2026

Niger is the eleventh African jurisdiction on the tracker and the thirty-third in the atlas region set. Article 52 of Loi n° 2022-59 du 16 décembre 2022 relative à la protection des données à caractère personnel is recorded from the date of promulgation printed on the enacted text, "Fait à Niamey, le 16 décembre 2022": art. 112 combines abrogation and publication in a single bare clause and defers nothing. That article also settles a supersession question the sweep was opened on — Loi n° 2022-59 abrogates Loi n° 2017-28 du 3 mai 2017 as modified by Loi n° 2019-71 du 24 décembre 2019, so the 2017 statute is no longer operative and is not tracked. The provision opens with the same two limbs as Côte d'Ivoire's art. 25, word for word: no judicial decision appraising a person's conduct may be founded on an automated processing intended to evaluate aspects of their personality, and no administrative or private decision appraising human conduct may rest on the sole foundation of an automated processing giving a definition of the person's profile or personality. It then goes further than any other African row in two directions. It confers a right to know and to contest the information and the reasoning used in any processing, automated or not, whose results are relied on against the person. And it adds a sentence that exists nowhere else on the tracker: where that processing falls within artificial intelligence, the criteria and the nature of the personal data founding it must be indicated to the person from the point of collection — a disclosure duty that bites at collection rather than at the decision. In exchange Niger admits what Côte d'Ivoire does not: an automated individual decision is permitted on explicit consent, on contract necessity, or where authorised by a legislative or regulatory provision, which is the GDPR art. 22(2) exception set grafted onto a Directive-era bar. Profiling is a defined term in art. 1 and art. 31 puts any profiling or behavioural-analysis processing under prior HAPDP authorisation. Niger is also the first Directive-family row where a criminal penalty reaches part of the automated-decision article: art. 102 punishes obstructing the exercise of a right conferred by the Law with three months to two years' imprisonment and a fine of 1,000,000 to 20,000,000 francs CFA, which catches a refusal of the right to know and contest, though not the two bars themselves. Those run through arts. 92 to 94 — warning, mise en demeure, interruption, blocking, temporary or definitive prohibition, withdrawal of authorisation, and a pecuniary sanction capped at 100,000,000 francs CFA, rising on repetition within two years to 200,000,000 francs CFA or 5% of pre-tax turnover within a limit of 500,000,000. Confidence is medium because no Nigerien official-gazette host resolved: the date of the Journal officiel carrying the Law could not be established, so the promulgation date is used and the true entry into force can only be that date or later. The text was read article by article in the enacted signed copy published by the HAPDP and cross-read against the HAPDP's April 2026 consolidated version, which shows that none of Loi n° 2023-31, Ordonnance n° 2024-16 or Ordonnance n° 2024-29 has touched art. 52.

ML Mali joins the tracker: art. 2 of Loi 2013-015, the only automated-decision bar on the tracker stated as a founding principle rather than a right

Added logged 17 Aug 2026

Mali is the fourteenth African jurisdiction on the tracker and the thirty-sixth in the atlas region set, and it is the structural outlier of the whole corpus. Its automated-decision rule is not in a rights chapter or an obligations chapter: it is the third paragraph of art. 2 of Loi n° 2013-015 du 21 mai 2013, in Chapitre I, the chapter headed "De l'objet". Article 2 declares that informatics must be at the service of every person and must respect human identity, human rights, private life and public and individual freedoms, states that everyone has a right to the protection of their personal data, and then provides that no decision inducing legal effects with regard to a person may be taken on the sole basis of a computerised processing intended to define the profile of the person concerned or to evaluate certain aspects of their personality. It is the leanest formulation in the Francophone family in three ways: one limb only, with no separate bar addressed to the courts, which Senegal, Morocco, Algeria, Côte d'Ivoire, Niger and Benin all carry; no exception of any kind, which it shares only with Côte d'Ivoire; and the older formula "traitement informatique" rather than "traitement automatisé". The companion right is art. 12, which entitles any person to obtain from a controller the communication in intelligible form of all the data concerning them and any available information as to their origin, and the information and the reasoning used in computerised processing whose results are relied on against them — free of charge, on the spot or remotely, answered without delay, with a copy conforming to the content of the processing delivered on request. That reasoning right is the same one Niger states inside its art. 52, which makes Mali and Niger the only Francophone rows carrying it. The date is the date of the Journal officiel de la République du Mali that carries the Law, numéro 26 of 28 June 2013 at pp. 1002 to 1011, read directly; the Law was adopted by the Assemblée nationale on 9 May 2013 and promulgated at Bamako on 21 May 2013, and it contains no commencement article — Chapitre X consists of art. 69 alone, which only empowers the Autorité to supply practical implementation matters by deliberation. Enforcement is the weakest of any row on the tracker. No offence reaches art. 2: art. 58 refers the classification of offences to the Penal Code and other laws, and the Law's own fines in arts. 65 and 66 name other conduct — unauthorised communication or access, purpose diversion, unfair collection, health-research processing, offence data, security failures and unconsented sensitive data. And the administrative list in art. 61 is exhaustive and carries no fine at all: a warning against a good-faith controller, a mise en demeure, an injunction to cease processing, and withdrawal of agrément. The Autorité may execute its decision of its own motion under art. 62 and may transact on any pecuniary sanction under art. 67, and its President may denounce infringers to the Procureur under art. 56. Confidence is medium: the Malian general publication-to-force rule was not read against a primary source, so it could not be confirmed whether force attaches on the day of publication or after a delay.

GH Ghana joins the Africa set: Act 843 s. 41 forces a twenty-one-day reconsideration answer on solely-automated decisions

Added logged 17 Aug 2026

Section 41 of Ghana's Data Protection Act, 2012 (Act 843) is the country's operative automated-decision rule and is now tracked. Its shape is older than its regional peers' — it descends from the UK Data Protection Act 1998 rather than from GDPR Art. 22 — so the headline right is exercised by written notice: an individual may at any time require in writing that no decision significantly affecting them be based solely on processing by automatic means. The part that bites hardest does not depend on that notice. Section 41(2) applies despite its absence: where a controller has taken a solely-automated decision that significantly affects an individual, it must as soon as reasonably practicable tell the individual the decision was taken on that basis, and the individual may then demand reconsideration by written notice within twenty-one days of that notification. Section 41(3) gives the controller twenty-one days from that demand to state in writing what steps it will take. Those are the only hard clocks in any of the four African provisions the tracker now carries: Kenya's s. 35 says only 'a reasonable period', and South Africa's s. 71 and Nigeria's s. 37 set no deadline at all. Cutting the other way, the s. 41(4) carve-out is the widest of the four, excluding decisions made in considering whether to enter a contract, with a view to entering one, or in performance of one, with no requirement of compensating safeguards. Enforcement is indirect: the Commission may order compliance on a data subject's complaint under s. 41(5) or serve an enforcement notice under s. 75, and only failure to comply with that notice is an offence, carrying up to 150 penalty units or one year's imprisonment under s. 80(1). Commencement needed care. The Act does not commence itself — s. 99 leaves the date to the Minister by Gazette publication, and the '18 May 2012' printed on the Act is its gazette notification, not its commencement. The ministerial instrument is not published online anywhere official, so the date recorded here, 16 October 2012, is the one stated by the Data Protection Commission itself, the authority the Act creates. Ghana is the tracker's fourth African jurisdiction and its 61st country.

DE Germany KI-MIG row corrected: EU AI Act Annex I high-risk deadline is 2 August 2028, not 2027

correction logged 17 Aug 2026

The status_note previously said the Annex I product-embedded high-risk obligations apply from 'Aug 2, 2027'. Under the Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026), the Annex I deadline was deferred from 2 August 2026 to 2 August 2028, not 2027 — 2027-08-02 is not the Annex I date. Corrected to 'Aug 2, 2028' to match the eu-aia-highrisk-annex1 row.

Primary source — eur-lex.europa.eu ↗

CI Côte d'Ivoire joins the tracker: art. 25 of Loi 2013-450, the widest automated-decision bar in Africa and the only one with no exception at all

Added logged 17 Aug 2026

Côte d'Ivoire is the tenth African jurisdiction on the tracker and the thirty-second in the atlas region set. Article 25 of Loi n° 2013-450 du 19 juin 2013 relative à la protection des données à caractère personnel has been in force since publication in the Journal officiel de la République de Côte d'Ivoire of 8 August 2013 at pp. 474 to 482 — the Law sets no commencement date and its final article, art. 54, is a bare publication clause. The provision belongs to the Directive 95/46/EC art. 15 lineage, which reaches West Africa through art. 42 of the ECOWAS Supplementary Act A/SA.1/01/10, and it joins Morocco's and Algeria's art. 11 to make that the third three-member family on the continent. It is also the outlier of the family in both directions. It is the widest rule tracked in Africa, because its second limb is not confined to decisions producing legal effects and carries no significant-effect threshold either: no administrative or private decision involving an appraisal of human conduct may have as its sole foundation an automated processing giving a definition of the profile or the personality of the person concerned. Its first limb forbids a court to found an appraisal of a person's conduct on an automated processing intended to evaluate aspects of their personality. And it is the barest rule tracked anywhere on the tracker, because the Law states no exception whatever — where Morocco and Algeria both deem contract-formation and contract-performance decisions with an opportunity to present observations outside the bar, Côte d'Ivoire supplies no contract carve-out, no consent exception and no observations proviso. There is no right to know the logic underlying an automated processing, which Morocco has in art. 7(c), and no human-review right. No penal article reaches art. 25: the Law's three offences are confined to sensitive-data processing (arts. 21), unconsented direct marketing (art. 22) and obstruction of the regulator (art. 45). What is left is the administrative route in arts. 49 to 51 — warning, mise en demeure, interruption or blocking of the processing, temporary or definitive prohibition, provisional or definitive withdrawal of the authorisation, and a pecuniary sanction capped at 10,000,000 francs CFA, rising on a repeated failure within five years to 100,000,000 francs CFA or, for an undertaking, 5% of pre-tax turnover for the last closed financial year within a limit of 500,000,000 francs CFA. Art. 46 confers the functions of the Autorité de protection on ARTCI, the telecommunications and ICT regulator. Confidence is medium on the same narrow ground as Morocco and Algeria: the Ivorian general publication-to-force rule could not be read in a primary source, so the entry uses the date of the Journal officiel that carries the Law.

CL Chile Ley 21.719 (Art. 8° bis automated-decision right) — 1 December 2026 date still stands, but a government postponement is now under active evaluation

correction logged 17 Aug 2026

The 1 December 2026 entry-into-force date remains the legally operative one on the face of Ley 21.719 — no decree or amending law has changed it. But on 4 August 2026 co-Minister of Economy Daniel Mas publicly confirmed the government is evaluating a postponement, because the new Agencia de Protección de Datos Personales still has no seated Consejo Directivo: the Senate rejected the President's first slate of three nominees in May 2026 for lack of the required two-thirds quorum, and the June 2026 statutory deadline to appoint the board has lapsed. No amending bill has yet been introduced.

Primary source — emol.com ↗

BFNE Burkina Faso closes the Francophone West Africa sweep: art. 15 of Loi 001-2021/AN, and art. 31's prior authorisation for predictive AI

Added logged 17 Aug 2026

Burkina Faso is the fifteenth African jurisdiction on the tracker and the thirty-seventh in the atlas region set, and it completes the six-jurisdiction Francophone West Africa block. Loi n° 001-2021/AN du 30 mars 2021 abrogates Loi n° 010-2004/AN of 20 April 2004, the statute this sweep originally targeted. Its art. 15 takes the wider ECOWAS Supplementary Act drafting shared with Côte d'Ivoire and Niger — no judicial decision appraising human conduct may be founded on an automated processing giving a definition of a person's profile or personality and intended to evaluate aspects of that personality, and no administrative or private decision appraising human conduct may rest on the sole foundation of such a processing — and, like Côte d'Ivoire and Mali, it states no exception whatever. What sets Burkina Faso apart sits in the two provisions around it. Art. 19 gives every person the right to know and to contest the information and the reasoning used in processing, automated or not, whose results are relied on against them, and requires that where the processing falls within artificial intelligence the criteria and the nature of the personal data founding it be indicated from the point of collection. And art. 31 subjects to prior authorisation by the Commission de l'informatique et des libertés any processing that assists administrative or private decision-making and involves an appraisal of human conduct, defines a person's profile or personality, or rests on artificial-intelligence techniques for predictive purposes — an ex ante licensing gate on predictive AI, and the only one in any data-protection statute on the tracker. This entry also corrects the Niger row published earlier today. Niger's art. 52 was described as the only provision anywhere on the tracker naming artificial intelligence; Burkina Faso's art. 19 carries the same clause in materially identical words and predates Niger's Law by twenty months, so Burkina Faso is the source of that drafting and Niger the follower. The Niger entry has been amended accordingly. Enforcement in Burkina Faso is wholly administrative in substance: art. 79 creates no offence and simply refers breaches to the Penal Code's provisions on computing and ICT offences, while arts. 63 to 77 give the CIL a warning, a mise en demeure, an injunction to cease, blocking, a flat-rate fine and withdrawal of the authorisation. That flat-rate fine is measured in turnover rather than currency — one per cent of pre-tax turnover for the last closed financial year on a first failure and five per cent on recidivism — which no other Francophone row does. The specific fines in arts. 67 to 75 run up to 100,000,000 francs CFA, and the 5,000,000 to 20,000,000 francs CFA fine for processing without the prior formalities is what reaches a missing art. 31 authorisation. Confidence is medium: laws in Burkina Faso are promulgated by presidential decree and neither the promulgation decree for Loi n° 001-2021/AN nor the Journal officiel date could be established, because cil.bf serves a maintenance page on every path and legiburkina.bf, jo.gov.bf and sgg.gov.bf do not resolve. The enacted text was read in the copy published by the CIL itself, retrieved from the Internet Archive capture of 10 July 2025 of the CIL's own document store.

BJ Benin joins the tracker: art. 401 of the Code du numérique, the bridge between Africa's Directive and GDPR automated-decision lineages

Added logged 17 Aug 2026

Benin is the thirteenth African jurisdiction on the tracker and the thirty-fifth in the atlas region set. Article 401 of Loi n° 2017-20 du 20 avril 2018 portant code du numérique sits in Livre cinquième, the book devoted to the protection of personal data, and is recorded from the date the Law bears: the Code has no commencement article, abrogates Loi n° 2009-09 du 24 mai 2009, and ends with a bare execution clause. Its shape is the Directive 95/46/EC shape — a judicial limb barring a court from founding an appraisal of a person's conduct on an automated processing intended to evaluate aspects of their personality, a general limb barring decisions from resting on the sole basis of such a processing, and an exception — but three things are imported from the GDPR and they change its character. The general limb reaches decisions producing legal effects with regard to a person or significantly affecting them, so the legal-effects ceiling that caps Senegal, Morocco and Algeria is gone. Profiling is a defined term and is named inside the judicial limb itself. And Benin is the only Francophone row on the tracker with a full logic-disclosure right: arts. 415 and 416 and the access right each require the controller to disclose the existence of automated decision-making including profiling within the meaning of art. 401 and, at least in such cases, useful information about the underlying logic and about the significance and the envisaged consequences of the processing, with a copy due within sixty days of an access request. Art. 401 processing is also a named data protection impact assessment trigger. The exception is the strongest-conditioned of the Francophone family: contract-based and law-based decisions escape the bar only if the contract or the enabling provision itself contains appropriate measures safeguarding the legitimate interests of the person concerned, and the person must at least be permitted to put their point of view usefully — where Senegal, Morocco and Algeria simply deem contract decisions outside the bar and Niger admits consent, contract and legal authorisation outright. No offence reaches art. 401 itself: the fifteen offences in art. 460 do not name it, though two of them — failing to respect the Livre's provisions on informing data subjects, and failing to respect its provisions on access rights — catch a controller that withholds the art. 401 disclosures, and art. 461 punishes those with six months to ten years' imprisonment and a fine of 10,000,000 to 50,000,000 francs CFA. The bar itself runs through the APDP: warning and an eight-day mise en demeure under art. 452, then a pecuniary sanction, cessation injunction, withdrawal of authorisation or blocking under art. 454, capped by art. 455 at 50,000,000 francs CFA on a first failure and at 100,000,000 francs CFA or 5% of pre-tax turnover, within a limit of 100,000,000, on repetition within five years, with appeal to the administrative court and discretionary publication. Confidence is medium: the Beninese general publication-to-force rule was not read against a primary source and the Journal officiel date could not be established, so entry into force can only be 20 April 2018 or later. Text read in the edition printed by the APDP itself. One drafting slip is recorded: art. 461 opens by referring to "les infractions visées à l'article 445" where the offence list is art. 460, which the same article then cites correctly twice.

DZ Algeria joins the tracker: art. 11 of Loi 18-07, the only African rule that binds the courts themselves

Added logged 17 Aug 2026

Algeria is the ninth African jurisdiction on the tracker and the thirty-first in the atlas region set. Article 11 of Loi n° 18-07 of 10 June 2018 has been in force since publication in Journal officiel n° 34 of that day — the Law sets no commencement date and its final article, art. 76, is a bare publication clause. The provision belongs to the Directive 95/46/EC art. 15 lineage that so far only Morocco represented, and it is the stronger of the pair: its first limb forbids a court to found an appraisal of a person's conduct on an automated processing intended to evaluate aspects of their personality, with no exception at all, and its second limb bars any other decision producing legal effects from resting on the sole basis of an automated processing intended to profile the person or evaluate aspects of their personality. The only relief is a deeming clause: contract-formation and contract-performance decisions for which the person could present observations, and decisions satisfying the person's own requests, are not treated as taken on that sole basis. Like Morocco's art. 11, and unlike Rwanda's art. 21, no penal article reaches it — the enumerated offences in arts. 56 to 74 name every other operative article and omit this one, and art. 47's fixed 500,000 DA fine is confined to the data-subject rights and the notification duties. What is left is art. 46: warning, mise en demeure, provisional or definitive withdrawal of the declaration receipt or authorisation, and a fine of unstated amount, imposed by the Autorité nationale and appealable to the Conseil d'Etat. Confidence is medium on the same narrow ground as Morocco: the Algerian general publication-to-force rule in art. 4 of the Code civil could not be read in a primary source, because the 1975 Journal officiel volumes are image scans, and Loi n° 05-10 of 2005 amends the Code civil without touching art. 4.

MARWTZ Rwanda, Tanzania and Morocco join the Africa set — and the three lineages of African automated-decision law are now all represented

Added logged 17 Aug 2026

Three more African automated-decision provisions are now tracked, taking the continent from four rows to seven and the atlas from 61 countries to 63. Rwanda's Law No. 058/2021 art. 21, in force since its publication in the Official Gazette of 15 October 2021, is a standing prohibition in the GDPR art. 22 shape: no decision based solely on automated processing, including profiling, that may produce legal or significant consequences, unless it rests on explicit consent, on a contract, or on a law laying down safeguards. What makes it unusual is the paragraph that survives those exceptions — evaluative automated processing may not be grounded in sensitive personal data unless an art. 10 ground is met, a limit none of the other African rows carries. What it lacks is any remedy: where Nigeria grants human intervention and the right to contest, and Kenya grants written notification plus a fresh non-automated decision, Rwanda states the right and stops. Tanzania's Personal Data Protection Act, 2022 s. 36 came into operation on 1 May 2023, appointed by Government Notice No. 326 of 2023 and printed on the face of the Chapter 44 republication. It belongs to the same UK Data Protection Act 1998 lineage as Ghana's Act 843 s. 41 and is the closest pair on the tracker: a request-based right in subsection (1), and in subsection (2) an automatic duty to notify the data subject that a solely-automated decision was taken and to entertain a demand that it be reconsidered. The difference is the clock. Ghana fixes twenty-one days in each direction; Tanzania says only that notification must come as soon as practicable and sets no period at all for the controller's answer. Ghana therefore remains the only African row with hard deadlines. The Act also reaches Zanzibar, but only for union matters. Morocco's Loi 09-08 art. 11 is the oldest drafting on the tracker in this family and the only one descended from Directive 95/46/EC. Its first paragraph binds courts directly — no judicial decision appraising a person's conduct may be founded on automated processing intended to evaluate aspects of their personality — which nothing else on the tracker does. Its second paragraph extends the bar to any other decision producing legal effects, and its carve-out for contract formation and performance is conditioned on the person having been able to make observations, the same safeguard South Africa uses in POPIA s. 71(3). It is narrower than every peer in one respect: it reaches only decisions producing legal effects, with no significant-effect limb. The date recorded is the Bulletin Officiel publication of 5 March 2009; the Law has no commencement clause, and confidence is medium for that reason rather than because the text is in doubt. Uganda and Egypt remain unswept and are carried forward.

NG Nigeria completes the Africa sweep: NDPA 2023 s. 37 gives a right to human intervention against solely-automated decisions

Added logged 16 Aug 2026

Nigeria was examined in this morning's Africa sweep alongside South Africa and Kenya but held back because no official host would serve the Act text. That gap is now closed. Section 37 of the Nigeria Data Protection Act, 2023 gives a data subject the right not to be subject to a decision based solely on automated processing of personal data, including profiling, which produces legal or similar significant effects. The right yields where the decision is necessary for entering into or performing a contract with the data subject, is authorised by a written law that establishes suitable safeguards, or is authorised by the data subject's consent — but s. 37(3) then requires the controller to implement suitable measures including the rights to obtain human intervention on the part of the data controller, to express the data subject's point of view, and to contest the decision. That makes it the strongest of the tracker's three African provisions on remedy: South Africa's POPIA s. 71 offers only representations plus disclosure of the underlying logic, and Kenya's Data Protection Act s. 35, while it alone requires written notification and allows a demand for a fresh non-automated decision, is otherwise the same shape. Section 65 defines automated decision-making as a decision based solely on automated processing by automated means, without any human involvement. Commencement is printed on the face of the enacted Act — [12th Day of June, 2023] — so the section has been in force since that date; the Act was published as Act No. 37 in the Federal Republic of Nigeria Official Gazette No. 119, Vol. 110 of 1 July 2023, at pages A719 to A758. The Commission's sanction under s. 48 is the greater of ₦10,000,000 and 2% of preceding-year annual gross revenue for a data controller or processor of major importance, or the greater of ₦2,000,000 and 2% for one that is not; failure to comply with a compliance order is a separate offence under s. 49 carrying the same fine ceiling or up to one year's imprisonment. The text was read in the Federal Government Printer's gazette PDF published by the Nigeria Data Protection Commission, the supervisory authority established by s. 4 of the Act; ndpc.gov.ng itself returns HTTP 403 to non-browser clients, so the citation resolves through the Internet Archive's byte-for-byte capture of that NDPC-hosted file. No secondary or NGO copy was used. The NDPC General Application and Implementation Directive 2025 may add implementation detail on automated decision-making but every archived capture replays 503, so it is not reflected here.

ID Indonesia joins the tracker: an objection right against solely-automated decisions and a mandatory impact assessment, both already in force

Added logged 16 Aug 2026

Extends the automated-decision coverage-symmetry cluster — Brazil LGPD Art. 20, China PIPL Art. 24, Korea PIPA Art. 37-2, Argentina Ley 25.326 Art. 20 and Chile's forthcoming Ley 19.628 Art. 8° bis — to the largest ASEAN jurisdiction, which the tracker had carried only as guidance-only on the strength of the non-binding Komdigi AI-ethics circular. Undang-Undang Nomor 27 Tahun 2022 tentang Pelindungan Data Pribadi entered into force on the day it was promulgated, 17 October 2022 (Art. 76; Lembaran Negara 2022 No. 196, Tambahan Lembaran Negara No. 6820), and the two-year alignment window that Art. 74 allowed controllers and processors closed on 17 October 2024, so the duties are fully exigible today. Art. 10(1) lets a data subject object to a decision taken solely on automated processing, including profiling, where it produces legal effects or has a significant impact; Art. 34(1) requires a personal-data-protection impact assessment for high-risk processing, and Art. 34(2)(a) puts automated decision-making with legal or significant effect at the head of that list. The two articles are not enforced alike: Art. 57(1) enumerates the sanctioned provisions and includes Art. 34(1) but not Art. 10, so the administrative fine of up to 2 per cent of annual revenue attaches to the impact-assessment duty, while the objection right runs through the supervisory body and the dispute-resolution route of Chapter XIII. No Government Regulation implementing the Act has been issued, which leaves the Art. 10(2) objection procedure, the Art. 34(3) assessment procedure and the Art. 57(5) fine procedure without detailed rules — verified against the Sekretariat Negara legal database, which returns no such regulation, and the Komdigi record for the Act, whose implementing-regulation section is empty. The statutory text was read in the full-text record published by the JDIH of the Kementerian Komunikasi dan Digital, the ministry of record; the Sekretariat Negara salinan is a scanned image without a text layer and peraturan.bpk.go.id refused every request.

PHTH Philippines and Thailand join the tracker: a consent bar on solely-automated decisions, and algorithmic ranking disclosure for platforms

Added logged 16 Aug 2026

Closes the ASEAN half of the coverage-symmetry sweep that added Indonesia yesterday. The Philippines enters through the Implementing Rules and Regulations of the Data Privacy Act of 2012, in force since 9 September 2016 (IRR Sec. 72, fifteen days after Official Gazette publication on 25 August 2016). IRR Sec. 48 is the sharpest provision: a controller must notify the National Privacy Commission once automated processing becomes the sole basis for a decision that would significantly affect a data subject, filing the methods and logic used and the decisions to be made — and no decision with legal effects may be taken solely on the basis of automated processing without the data subject's consent. IRR Sec. 34 adds a right to be informed of the existence of automated decision-making and profiling, meaningful information about the logic involved and its significance and envisaged consequences, and a right to object to automated processing or profiling. Fines follow NPC Circular No. 2022-01: 0.5 to 3 per cent of annual gross income for an infraction of Sec. 16 rights affecting more than 1,000 subjects, capped at PHP 5,000,000. Thailand enters on a different axis. The Royal Decree on the Operation of Digital Platform Service Businesses That Are Subject to Prior Notification, B.E. 2565, has been in force since 21 August 2023 — 240 days after publication in the Government Gazette on 23 December 2022 (Sec. 2) — and its Sec. 17 obliges intermediary platforms and online search engines to publish the main parameters of the algorithms or criteria they use to rank or recommend goods and services, to present advertisements, and to collect, moderate and publish user reviews. Enforcement is structural rather than monetary: Sec. 33 empowers the competent official to prohibit the service until compliance, and to strike the operator from the notification registry after ninety days of non-compliance. Thailand's PDPA has no GDPR Art. 22 analogue, so no solely-automated-decision right is tracked there. Malaysia was reviewed in the same pass and is not yet publishable: the Personal Data Protection Department has issued a final Automated Decision-Making and Profiling Guideline, but its operative date could not be extracted from the published text and is being verified separately.

KEZA Africa joins the tracker: South Africa's bar on solely-automated profiling decisions and Kenya's right to a re-decision

Added logged 16 Aug 2026

Until today none of the tracker's 113 obligations covered an African jurisdiction. Two go live, both already in force. South Africa enters through s. 71 of the Protection of Personal Information Act 4 of 2013, which bars a decision producing legal consequences or a substantial effect where it is based solely on automated processing intended to profile the person — the statute names performance at work, creditworthiness, reliability, location, health, personal preferences and conduct — unless the contract or law exception applies and appropriate measures give the data subject an opportunity to make representations plus sufficient information about the underlying logic of the processing. Commencement is not on the face of the Act: s. 115 leaves it to the President, and Proclamation No. R. 21 of 2020 (Government Gazette No. 43461, 22 June 2020) set 1 July 2020 for ss. 55 to 109, which contains s. 71, with the s. 114(1) transitional year closing on 1 July 2021. Breach runs through an enforcement notice, then an administrative fine of up to R10 million under s. 109 or, on non-compliance with the notice, an offence carrying up to ten years. Kenya enters through s. 35 of the Data Protection Act No. 24 of 2019, in force on its stated commencement date of 25 November 2019. It is the closer GDPR Art. 22 analogue of the two: the controller must notify the data subject in writing once a solely-automated decision with legal or significant effect has been taken, and the data subject can then require the decision to be reconsidered or a new decision taken that is not based solely on automated processing. The Data Commissioner's penalty is capped at KES 5 million or one per cent of an undertaking's preceding-year annual turnover, whichever is lower. Both texts were read at official sources — the gazetted Act on gov.za and the commencement proclamation published by the Information Regulator for South Africa, and the Office of the Data Protection Commissioner's copy of the Act for Kenya. Nigeria's Data Protection Act 2023 was examined in the same sweep but no copy is reachable on an official host, so it stays unpublished pending verification.

VN Vietnam: Decision 33/2026/QD-TTg — the 46 high-risk AI systems list is now in force

Updated logged 15 Aug 2026

Scheduled lifecycle flip: vn-highrisk-dec33 moves from 'dateset' to 'force' on its stated commencement date of 15 August 2026. Re-verified on the day against the Government legal-document portal record for the Decision, which states Ngay ban hanh (issued) 30-06-2026 and Ngay co hieu luc (effective) 15-08-2026. From today, new deployments of any of the 46 designated high-risk AI systems require a pre-deployment conformity assessment under Law 134/2025/QH15 and Decree 142/2026/ND-CP. Systems already in operation get a transition period: 1 March 2027 for most sectors, 1 September 2027 for healthcare, education and finance. No change to the date, source, penalty or scope fields.

US NY RAISE Act: superseded by March 2026 chapter amendment moving oversight to a new DFS office

correction logged 15 Aug 2026

Daily verification found the row's source_url still pointed to the original 19 December 2025 signing (Ch. 699) and status_note was blank. A chapter amendment, S8828 (Ch. 96), was introduced 6 January 2026, passed both chambers, and was signed by Governor Hochul on 27 March 2026, superseding the original text. The amendment moves rulemaking and critical-incident-report oversight from the Division of Homeland Security and Emergency Services to a new office within the NY Department of Financial Services (DFS); the 1 January 2027 effective date is unchanged.

Primary source — nysenate.gov ↗

ARMX LATAM sweep: Mexico's platform algorithmic-management duties and Argentina's ban on solely-automated profiling decisions

Added logged 15 Aug 2026

Coverage-symmetry follow-up to the CAC Algorithmic Recommendation Provisions (cn-algo-recommendation), sweeping Mexico, Colombia, Chile and Argentina for in-force peers of the recommendation off-switch (CAC Art. 17), algorithmic work dispatch (Art. 20) and algorithmic price discrimination (Art. 21). Two entries added. Mexico: Capítulo IX Bis of the Ley Federal del Trabajo, added by the DOF decree of 24 December 2024 and in force since 22 June 2025 under Transitorio Primero, requires digital-platform employers to publish an algorithmic work-management policy covering how tasks are assigned, how ratings and incentives bite, and which categories affect allocation (Art. 291-J), and to route deactivation reviews through staff with autonomy and review power rather than algorithms (Art. 291-P), with fines of 1,000–25,000 and 500–25,000 UMA respectively under Art. 997-B. Argentina: Art. 20 of Ley 25.326 voids judicial decisions and administrative acts founded solely on automated profiling of the data subject, in force since November 2000 and the country's only in-force constraint on automated decision-making; Argentina now appears as its own jurisdiction. Colombia and Chile returned no publishable in-force peer this pass — Arts. 29 and 30 of Ley 2466 de 2025 (automated-supervision transparency and a right to human review for delivery-platform workers) are enacted but deferred by Art. 67 to twelve months after a reglamentación that has not yet been issued, so no date is publishable, and Chile's Ley 21.431 could not be verified because the Biblioteca del Congreso Nacional text service was rate-limited throughout; both are tracked for a later pass.

CN China: PIPL Art. 24 automated-decision-making duties — in force since 1 November 2021

Added logged 15 Aug 2026

Continues the coverage-symmetry sweep of automated-decision duties that sit inside data-protection statutes rather than AI-specific acts (peers already tracked: br-lgpd-art20, kr-pipa-art37-2-adm, uk-duaa-adm, ca-quebec-law25, au-adm-privacy-app). China's five existing rows were all CAC AI instruments, so the general ADM duty was uncovered. PIPL Art. 24 requires transparency and fair results in automated decision-making, bans unreasonable differential treatment in transaction prices and other transaction conditions, requires a non-personalised option or a convenient refusal route for automated push delivery and commercial marketing, and gives individuals a right to an explanation of, and a right to refuse, decisions made solely by automated means where those decisions have a major effect on their rights and interests. Art. 55(2) requires a personal information protection impact assessment before automated decision-making, retained with the processing record for at least three years (Art. 56). Verified against the official NPC text on npc.gov.cn and against the Cyberspace Administration of China republication (identical wording), which is the cited link because npc.gov.cn does not serve https: Art. 24, Art. 55, the Art. 73(2) definition of automated decision-making, the Art. 66 penalty tiers, and Art. 74, which puts the commencement date of 1 November 2021 on the face of the statute. Coverage gap logged for follow-up: the CAC Provisions on the Administration of Algorithmic Recommendation in Internet Information Services (in force 1 March 2022) are still untracked.

Primary source — cac.gov.cn ↗

CN China: CAC Algorithmic Recommendation Provisions — in force since 1 March 2022

Added logged 15 Aug 2026

Closes the coverage gap logged alongside cn-pipl-art24. The Provisions on the Administration of Algorithmic Recommendation in Internet Information Services (Order No. 9 of the CAC, MIIT, Ministry of Public Security and SAMR, signed 31 December 2021, published 4 January 2022, effective 1 March 2022 per Art. 35) are China's operative algorithm-governance regime and were untracked. They bind any provider using generative/synthetic, personalised-push, ranking, retrieval-filtering or scheduling-decision algorithms to supply internet information services in the PRC: conspicuous disclosure that recommendation is in use plus publication of the basic principles, purpose and main mechanisms (Art. 16); a non-personalised option or convenient off-switch and user control over personal-characteristic tags (Art. 17); periodic review of mechanisms, models, data and outputs and a ban on addiction- or overspending-inducing models (Art. 8); labelling of unlabelled algorithmically generated or synthesised information before onward transmission (Art. 9). Providers with public-opinion attributes or social-mobilisation capacity must also file in the CAC algorithm filing system within 10 working days of launch with an algorithm self-assessment report (Art. 24), display the filing number (Art. 26) and run a security assessment (Art. 27). Art. 21 bans algorithmic price discrimination against consumers; Arts. 18-20 add duties towards minors, the elderly and gig workers under algorithmic dispatch. Art. 31 penalty: warning, circulated criticism, rectification order, and on refusal or serious circumstances suspension of information updates plus RMB 10,000-100,000; Art. 32 routes the remaining breaches to the underlying laws (PIPL Art. 66 reaches RMB 50,000,000 or 5% of turnover). Verified against the full Chinese text at the CAC publication (https://www.cac.gov.cn/2022-01/04/c_1642894606364259.htm). Impact tier: all entities.

CL Chile joins the tracker: platform-algorithm duties in the Labour Code, and an automated-decision right from 1 December 2026

Added logged 15 Aug 2026

Completes the LATAM coverage-symmetry sweep begun on 15 August 2026, which had left Chile unresolved because the Biblioteca del Congreso Nacional text service returned HTTP 429 on every attempt. The same LeyChile service answers without the quota error on the backend host the LeyChile front end itself calls, so both candidate laws could be read in full. Two entries added. Chapter X of the Código del Trabajo, inserted by Ley 21.431 (published 11 March 2022) and in force since 1 September 2022 under its first transitional article, bans discrimination through automated decision-making in work allocation, bonuses and pay, treats apparently neutral conduct with disproportionate effect as discrimination, requires workers to be told the compliance mechanisms adopted, gives workers access to and portability of their ratings data within fifteen working days, and requires platforms to open the programming of the algorithm, its decision logic and its training data to the Dirección del Trabajo on request; the Dirección del Trabajo enforces it with the Art. 506 fines, doubled on repeat offence. Ley 21.719 (published 13 December 2024) inserts Art. 8° bis into Ley 19.628, a GDPR-style right to object to and not be subject to solely-automated decisions and profiling with legal or significant effects, backed by rights to an explanation, human intervention and review even where an exception applies; its first transitional article defers commencement to the first day of the twenty-fourth month after publication, i.e. 1 December 2026, so it is tracked as a scheduled date with fines of up to 20,000 UTM or 2–4% of turnover once the Agencia de Protección de Datos Personales takes up enforcement. Chile now appears as its own jurisdiction and moves from 'proposed' to 'binding sectoral' on the atlas.

VN Data fix: Vietnam Decision 33/2026 entry used jurisdiction_label 'VN', splitting Vietnam into two jurisdictions

Corrected logged 14 Aug 2026

vn-highrisk-dec33 carried jurisdiction_label 'VN' while vn-ai-law-risk and vn-ai-law-labelling carried 'Vietnam', so the same country appeared twice in jurisdiction facets and counts. Normalised to 'Vietnam'. No substantive change to the obligation.

US Coverage sweep (AIL-204): Washington, Oregon and California added to the DE HB 191 nonhuman-entity title-protection class

Added logged 14 Aug 2026

Following the Delaware HB 191 addition, swept US states for enacted statutes barring AI/nonhuman entities from professional licensure or protected-title use. Confirmed and added three: Oregon HB 2748 (2025 c.378 §2, codified ORS 678.027, in force 2026-01-01 — first state to enact this class, bars nonhuman entities from nursing titles/abbreviations, Class C misdemeanor under ORS 678.990); Washington HB 2155 (amending RCW 18.79.030, in force 2026-06-11 — bars nonhuman entities from RN/APRN/LPN titles, enforced as unlicensed practice under RCW 18.130.190, gross misdemeanor/felony); California AB 489 (Bus. & Prof. Code §§ 4999.8-4999.9, in force 2026-01-01 — structurally distinct: extends existing health-profession title-protection crimes to AI/GenAI developers and deployers across all licensed healing-arts professions, not a standalone nonhuman-entity bar, but included under Coverage Symmetry as the title-protection analogue). All three verified against official legislature/state-code primary sources with bill text fetched and quoted directly. Ruled out: New York SB 7263 (unauthorized-practice liability bill) — not yet enacted as of 2026-08-14, still on Senate third reading as of 2026-03-04; excluded pending passage.

US Delaware added: HB 191 bars AI agents from medical/nursing licensure and protected titles

Added logged 14 Aug 2026

Delaware had no entries in the tracker. A full sweep of all 1,961 records of the 153rd General Assembly surfaced HB 191, signed and approved 23 April 2026 as 85 Del. Laws ch. 250. The Act amends 24 Del. C. §§ 1920, 1720 and 1773 to provide that a nonhuman entity, "including an agent powered by artificial intelligence", may not be licensed or certified to practice professional, advanced practice or practical nursing, medicine, or as a physician assistant, and may not use the associated protected titles (Nurse, RN, LPN, APRN, CRNA, CNS, CNP, CNM, Doctor/Dr., Physician, Surgeon, MD, DO, Physician Assistant/PA). There is no delayed-effective-date clause, so the entry is published in force from 23 April 2026. Penalties come from the existing enforcement provisions: unlawful practice of medicine is a class F felony carrying a $1,000–$5,000 fine and up to 3 years (24 Del. C. § 1766(a)), other Chapter 17 violations are a class B misdemeanor (§ 1766(c)), and nursing practice or title misuse carries up to $1,000 and up to 1 year (§ 1925). Verified against the Laws of Delaware session-law text and delcode.delaware.gov; not sourced from any secondary summary.

UK UK: SI 2026/425 adds a statutory duty on the ICO to produce an AI and automated-decision-making code of practice

Added logged 14 Aug 2026

Found via a legislation.gov.uk 2026 title search while checking whether the UK AI (Regulation) Bill had been enacted (it has not). The Data Protection Act 2018 (Code of Practice on Artificial Intelligence and Automated Decision-Making) Regulations 2026 (SI 2026/425) were made 16 April 2026, laid 21 April and came into force 12 May 2026. They require the Information Commissioner to prepare a statutory code of practice covering the development and use of AI and automated decision-making under the UK GDPR and DPA 2018, expressly including guidance on children's personal data. The code has not yet been issued, so its own start date is TBD; the instrument's in-force date is what is tracked here. Regulation 3 carves national security out of the s.124B review panel's remit.

KR South Korea: PIPA Art. 37-2 gives data subjects the right to object to, and demand an explanation of, fully automated AI decisions

Added logged 14 Aug 2026

Coverage-symmetry sweep off uk-si-2026-425-ico-ai-code: automated-decision-making duties that sit inside data-protection statutes rather than AI-specific acts. Korea's Personal Information Protection Act Art. 37-2, inserted by Act No. 19234 (promulgated 14 March 2023), took effect 15 March 2024 under Addenda Art. 1(1) — one year after promulgation, six months later than the bulk of that amendment. It expressly covers decisions made by 'a completely automated system (including a system to which artificial intelligence technologies are applied)' that significantly affect a data subject's rights or duties: the data subject may object and request an explanation, and the controller must then either not apply the decision absent compelling reason or take measures such as human re-processing. Controllers must also disclose the criteria and procedures for automated decisions. Verified against the official English text of PIPA published by the Personal Information Protection Commission (PIPA2023.pdf, Enforcement Date 15 Sep 2023 edition, which carries both Art. 37-2 and the Addenda commencement rule) and cited to law.go.kr. Penalty confirmed at PIPA Art. 75(2) 24: administrative fine up to KRW 30 million for breach of Art. 37-2(3). This is separate from Korea's AI Basic Act entries — the trigger is personal-data processing, not AI-operator status.

BR Brazil: LGPD Art. 20 gives a right to review of solely-automated decisions — in force since 18 September 2020

Added logged 14 Aug 2026

Closes AIL-207, found in the AIL-206 coverage-symmetry sweep of automated-decision duties sitting inside data-protection statutes (peers: kr-pipa-art37-2-adm, uk-duaa-adm, ca-quebec-law25, au-adm-privacy-app). Brazil previously had only br-pl2338 (proposed), so the tracker showed zero in-force Brazilian coverage. LGPD Art. 20, as amended by Lei 13.853/2019, lets a data subject request review of decisions taken solely on the basis of automated processing that affect their interests, including profiling for personal, professional, consumer or credit purposes, and requires the controller to disclose the criteria and procedures used, subject to trade secrecy; where secrecy is invoked the ANPD may audit for discriminatory effects. Note the amendment deleted the original "por pessoa natural" requirement, so this is not a guaranteed human-review right. The in-force date was traced through the Art. 65 amendment chain on Planalto rather than taken from secondary sources: Lei 13.853/2019 set 24 months after publication (LGPD published DOU 15.8.2018); MP 959/2020 art. 4 moved that to 3 May 2021 and was in force from 29.4.2020; the conversion law Lei 14.058/2020, published DOU 18.9.2020 and effective on publication, carries no amendment to Lei 13.709, so the postponement lapsed and the general articles took effect 18 September 2020. Sanctions under Arts. 52-54 commenced 1 August 2021 per Art. 65 I-A (Lei 14.010/2020), and the penalty field reflects that. Coverage-symmetry check of ANPD normative acts found no AI- or ADM-specific resolução as of 2026-08-14.

BR Brazil's ECA Digital carries algorithmic duties that have been in force since March, and its first transparency report is due 17 September 2026

new logged 14 Aug 2026

Lei 15.211/2025, the ECA Digital, was sanctioned on 17 September 2025 and has been in force since 17 March 2026 - Art. 41-A originally said six months after publication, and Lei 15.352/2026 replaced that with the express date. We had no entry for it because it reads at first as a child-online-safety statute, but the consolidated text on Planalto imposes duties squarely on algorithmic systems, so it belongs here. Art. 17 s.4 requires the default parental-supervision settings of services directed at or likely accessed by minors to include control over personalised recommendation systems with an option to switch them off (item V) and regular review of the artificial-intelligence tools in the service, with specialists and competent bodies participating, against technical criteria that ensure safety and suitability for minors, with non-essential functionalities capable of being disabled (item VIII). Art. 22 bans profiling for advertising directed at minors and the use of emotional analysis or augmented, extended and virtual reality for that purpose; Art. 26 bans building behavioural profiles of minors from personal, group or collective data, including data collected during age verification; and Art. 30 II requires a provider removing content to tell the user whether the content was identified by human or automated analysis. Decreto 12.622/2025 designates the ANPD as the autonomous enforcement authority under Art. 34 and Decreto 12.880/2026 is the implementing regulation. Penalties under Art. 35 run to 10% of the economic group's Brazilian turnover or, absent turnover, R$10 to R$1,000 per registered user, capped at R$50,000,000 per infraction, with suspension and prohibition of activities reserved to the courts. The Art. 31 semi-annual transparency report is tracked separately because it carries its own near-term date. It binds internet application providers with more than 1,000,000 registered child and adolescent users connecting from Brazil, and must be published in Portuguese on the provider's own site covering complaint channels and volumes, moderation counts by type, the measures used to identify child accounts under Art. 24 s.3 and illicit acts under Art. 27, technical improvements for data protection and parental consent, and the methods and results of impact and risk assessments. The statute sets no publication date, so Despacho Decisorio CD/ANPD 122/2026, published in the Diario Oficial da Uniao on 11 August 2026, supplies the calendar until specific regulation supervenes: the first report covers 1 January to 30 June 2026, or 17 March to 30 June for providers without earlier data, and must be published by 17 September 2026; from the second report the periods follow the civil semesters, due 1 August and 1 February. This is Brazil's second and third in-scope entry after br-lgpd-art20, alongside the still-proposed AI bill br-pl2338.

Primary source — planalto.gov.br ↗

US Colorado AI Act entry now records the FTC's proposed Section 5 policy statement as a live federal-preemption pressure

Updated logged 13 Aug 2026

The Colorado AI Act (SB 26-189) entry already carried the consent-based enforcement stay in xAI v. Weiser. A second, independent source of pressure on the same statute is now recorded: the FTC's proposed 'Policy Statement Concerning the Suppression of Accuracy in Artificial Intelligence Systems', published in the Federal Register on 7 July 2026 under docket FTC-2026-0859. The notice names Colorado's revised Artificial Intelligence Act by name and treats output steering undertaken in attempted compliance with such a State law as potentially deceptive under Section 5 of the FTC Act — an implicit preemption threat. The comment period closed 31 July 2026 and drew opposing filings, including a multistate attorney-general coalition comment. Nothing about the Colorado statute changes: the entry keeps its 1 January 2027 date, its scope and its lifecycle, because the FTC has neither finalised the statement nor obtained a ruling, and the Federal Register notice creates no obligation of its own. It is carried as status context so readers tracking the 2027 date can see that a federal challenge to that regime is live. Verified against the Federal Register notice; the regulations.gov comment docket and ftc.gov comment index both refuse automated retrieval from the pipeline host, so the coalition filing itself is described without a date or a headcount.

Primary source — federalregister.gov ↗

US Connecticut's online safety act split into its four statutory tranches

Updated logged 12 Aug 2026

Connecticut Substitute Senate Bill 5 became Public Act No. 26-15, an act concerning online safety, signed by the Governor on 27 May 2026. We were carrying it as a single row dated 1 October 2026 with its three later start dates mentioned only in a note, so those deadlines did not appear anywhere in the tracker. Reading the enacted public act, each section carries its own effective-date parenthetical, and the private-sector duties fall into four tranches. From 1 October 2026: s 1 subscription-based provider disclosures, s 2 frontier developer duties, s 15 provenance data and detectability of synthetic digital content for a generative provider with more than 1,000,000 monthly users that is publicly accessible for personal use, and s 38 controls on state agency use and procurement of AI. From 1 January 2027, ss 4 to 6 govern artificial intelligence companions, with heightened duties where the user is under eighteen, including a clear and conspicuous statement at the start of each interaction that the companion is not a licensed mental health professional, and bars on romantic or erotic interaction, on discouraging a minor from seeking mental health services or adult help, and on manipulative techniques that extend engagement. From 1 October 2027, the automated employment-related decision technology duties in ss 8 to 10 attach; those sections are themselves effective 1 October 2026, but each duty is written to apply only to technology deployed in the state on or after 1 October 2027, which is the date that matters to developers and deployers. From 1 January 2028, s 39 restricts personalised recommendation feeds for covered users under eighteen unless the operator uses commercially reasonable and technically feasible age determination or obtains verifiable parental consent. Enforcement across the act runs through the unfair or deceptive trade practice route in Conn. Gen. Stat. s 42-110b(a), reserved to the Attorney General for ss 1, 5, 6, 15 and 8 to 11. The entry title has also been corrected: the act is Public Act 26-15, an act concerning online safety, not an AI Responsibility and Transparency Act, and the source now cites the enacted public act rather than the bill status page.

Primary source — cga.ct.gov ↗

US California AB 853 split into its three statutory tranches, and a 2028 capture-device deadline surfaced

Updated logged 12 Aug 2026

California's AB 853 (approved 13 October 2025) layers three separate start dates onto the California AI Transparency Act, and we were carrying them as a single in-force row dated 2 August 2026, which hid both future deadlines from the tracker. The enacted text on leginfo sets them out expressly. The covered-provider duties in Bus. & Prof. Code s 22757.3 - a free AI-detection tool and latent disclosures for a GenAI system with over 1,000,000 monthly visitors or users that is publicly accessible in California - became operative on 2 August 2026 under s 22757.6 and stay tracked as us-ca-sb942. From 1 January 2027, s 22757.3.1 requires a large online platform to detect provenance data, expose it through a user interface, let users inspect or download it, and stop knowingly stripping provenance data or digital signatures, while s 22757.3.2 bars a GenAI hosting platform from knowingly making available a model that omits those disclosures; us-ca-ab853 now carries that 2027 date. From 1 January 2028, s 22757.3.3 requires capture device manufacturers to offer a latent disclosure and embed it by default in devices first produced for sale in the state on or after that day; that tranche is new as us-ca-ab853-capture-device and had no entry before today. Two scope corrections came out of the same reading: the large online platform test is 2,000,000 unique monthly users over the preceding 12 months under s 22757.1(h)(1), not the 1,000,000 figure that applies to covered providers, and capture device manufacturers face no size threshold at all. Penalties across the chapter are $5,000 per violation with each day a discrete violation, enforced by the Attorney General, a city attorney or a county counsel under s 22757.4.

Primary source — leginfo.legislature.ca.gov ↗

VN Vietnam Decision 33 — MoST explainer guidance located (published 3 Jul 2026); earlier "none published" note corrected

correction logged 11 Aug 2026

The status note previously stated that no supplementary MoST guidance had been published as of 9 August 2026. That was incorrect when written, not overtaken by events: MoST's own portal (mst.gov.vn) published explainer content on 3 July 2026 covering all 6 sectors designated under Decision 33/2026/QD-TTg and both transition deadlines (1 March 2027 / 1 September 2027), with a further notice on 8 July 2026 — five weeks before the check that reported none existed. The material is contextual guidance, not a new binding regulation, so the obligation's substance (46 systems, effective 15 August 2026) is unchanged; the negative claim has been replaced with the dated MoST citation.

Primary source — vanban.chinhphu.vn ↗

CA Canada — new federal privacy bill C-36 carries AI-transparency provisions

Updated logged 11 Aug 2026

AIDA (Bill C-27) remains dead on prorogation and was not itself reintroduced. However, a separate federal bill, C-36 (Protecting Privacy and Consumer Data Act, 45th Parliament), had first reading 15 June 2026 and is at second reading in the House as of 11 August 2026; it amends PIPEDA and includes AI-related transparency provisions (e.g. disclosure for automated/algorithmic decision tools). It is a privacy-law vehicle rather than an AIDA-style comprehensive AI act, and is not yet enacted, so Canada's status is unchanged for now, but the entry's status note is updated to reflect this development.

Primary source — parl.ca ↗

SG Singapore MAS agentic-AI entry corrected — SAFR is voluntary, not the binding instrument

correction logged 10 Aug 2026

The entry previously described SAFR (Safeguards for Agentic Finance at Runtime) as MAS's binding supervisory framework for agentic AI. Re-checked against MAS's own parliamentary reply of 5 August 2026 and its 13 November 2025 AI Risk Management Guidelines consultation paper: SAFR, published 3 July 2026, is an industry-led voluntary information paper, not a binding instrument. The binding track is MAS's proposed AI Risk Management Guidelines, still in consultation, which propose a 12-month compliance transition once issued but carry no MAS-confirmed finalization date — 'Q4 2026' was market/analyst expectation, not a MAS commitment. The parliamentary reply itself states MAS will continue to review and update existing supervisory expectations for AI agents, rather than declaring a new codified binding rule already in force. Title, summary, status note and law_short updated to separate the voluntary SAFR paper from the still-pending binding Guidelines; confidence remains medium pending the Guidelines' finalization. The Singapore jurisdiction record was brought in line with the same correction.

Primary source — mas.gov.sg ↗

EUJPSG Three more AI-training copyright exceptions on the Radar — Japan Art.30-4, Singapore s.244, EU DSM Art. 4

Added logged 9 Aug 2026

The copyright and training-data themes launched with only the Saudi exemption and the EU AI Act's general-purpose AI model duties. The three other statutory regimes that actually govern whether protected works can be mined for model training are now carried as entries, each read against its own primary text. Japan's Copyright Act Art.30-4 (in force 1 January 2019) is the broadest: exploitation for information analysis with no rightholder opt-out and no non-commercial limit, bounded only by the proviso for unreasonable prejudice to the copyright owner. Singapore's Copyright Act 2021 s.244 (in force 21 November 2021) permits copying for computational data analysis — s.243 names training a program as an example — gated on lawful access to a non-infringing source copy, with contracting-out void under s.187. The EU's DSM Directive Art. 4 (transposition deadline 7 June 2021) permits commercial mining of lawfully accessible works but only where the rightholder has not reserved the use by machine-readable means; that reservation is precisely what AI Act Art. 53(1)(c) requires model providers to respect, so the two EU entries cross-reference rather than duplicate. The United Kingdom was checked and produced no entry: the Data (Use and Access) Act 2025 ss.135-137 place reporting duties on the Secretary of State rather than on AI developers, and CDPA s.29A remains confined to non-commercial research.

Primary source — eur-lex.europa.eu ↗

EU New EU deadline 2 Dec 2026 — Art. 50(2) marking retrofit for synthetic-content systems already on the market

Added logged 9 Aug 2026

The Digital Omnibus on AI (Regulation (EU) 2026/1744, Article 1(39)(b)) adds a new Article 111(4) to the EU AI Act giving providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text and were placed on the market before 2 August 2026 until 2 December 2026 to implement the Article 50(2) marking obligation. Recital (38) frames it as a four-month transitional period. Verified against the OJ PDF (OJ L, 24.7.2026). Breaches sit in the Article 99(4) tier (up to 3% of turnover or EUR 15M), not the 7% Article 5 tier that applies to the new CSAM/NCII prohibitions sharing the same date.

Primary source — eur-lex.europa.eu ↗

EU New EU deadline 2 Aug 2030 — legacy high-risk AI intended for public authorities must be brought into compliance

Added logged 9 Aug 2026

The Digital Omnibus on AI (Regulation (EU) 2026/1744, Article 1(39)(a)) replaces Article 111(2) of the EU AI Act. Alongside the general grace period for high-risk systems placed on the market before the Chapter III application dates, the replaced text sets a hard backstop: providers and deployers of high-risk AI systems intended to be used by public authorities have until 2 August 2030 to meet the AI Act's requirements and obligations. Recital (39) confirms the grace period runs at type-and-model level, with a significant change in design ending it. Verified against the OJ PDF (OJ L, 24.7.2026). This is now the furthest-out dated duty tracked for the EU; breaches sit in the Article 99(4) tier (up to 3% of turnover or EUR 15M).

Primary source — eur-lex.europa.eu ↗

US Illinois SB 343 signed into law as Public Act 104-0805 — no AI provisions

Updated logged 8 Aug 2026

Governor Pritzker signed the bill on 2026-08-07 as Public Act 104-0805. As previously tracked, the enacted text contains no AI or algorithmic-pricing provisions, so no AI obligation exists under this bill number.

Primary source — ilga.gov ↗

US AI Kill Switch Act assigned bill number H.R. 9917

Updated logged 8 Aug 2026

The bill introduced by Reps. Lieu and Moran on 2026-07-23 has been indexed as H.R. 9917 and referred to the House Committee on Homeland Security. No change to lifecycle or substantive obligations.

Primary source — govinfo.gov ↗

UK UK DUAA s.138 commencement — SI citation corrected

correction logged 8 Aug 2026

The row cited SI 2026/82 as the commencement instrument for section 138 (non-consensual deepfake creation/request offences). The correct instrument is SI 2026/31 (Commencement No. 5 Regulations 2026); SI 2026/82 (Commencement No. 6) instead commences the separate automated decision-making reform tracked under uk-duaa-adm. The in-force date of 2026-02-06 is unchanged.

Primary source — legislation.gov.uk ↗

US Illinois SB 343 — AI rental-pricing language removed from the bill before transmittal to the Governor

correction logged 7 Aug 2026

Senate Floor Amendment No. 1 (adopted 2026-05-21) had added the algorithmic rental-price-coordination ban this row tracks, but House Committee Amendment No. 1 (adopted 2026-05-29) replaced that content entirely with unrelated Cook County / Calumet City eminent-domain provisions. The bill sent to Gov. Pritzker on 2026-06-30 contains no AI provisions. Confidence raised to high now that the current bill text is confirmed; status_note updated to explain the amendment history. No AI obligation currently exists under this bill number.

Primary source — ilga.gov ↗

US Rhode Island H 7349 — effective date confirmed as signing date

correction logged 2 Aug 2026

The row's status_note previously flagged the effective date as unconfirmed pending Rhode Island Legislature source review. Secondary reporting on the enacted law confirms the act took effect upon passage on June 22, 2026, matching the date already tracked. Status note updated to remove the TBD language; no change to the tracked date or lifecycle.

Primary source — transparencycoalition.ai ↗

US California AI Transparency Act (SB 942) enters into force

Updated logged 2 Aug 2026

SB 942 (as amended by AB 853) took effect August 2, 2026, requiring GenAI providers with >1M monthly users to offer an AI-detection tool and content provenance disclosures.

Primary source — leginfo.legislature.ca.gov ↗

US Added California AB 853 — AI Transparency Act Phase 2 (Aug 2, 2026)

Added logged 2 Aug 2026

Added new entry for AB 853, which extends the California AI Transparency Act duties to large online platforms and device manufacturers. Phase 1 (AI detection tools, manifest disclosures) is in force from August 2, 2026; Phase 2 (additional large-platform obligations) activates January 1, 2027.

Primary source — leginfo.legislature.ca.gov ↗

US Rhode Island S 2195 — source citation corrected to enacted Substitute A text

correction logged 1 Aug 2026

The row cited the as-introduced bill text (LC003227), which lacks the AG-reporting and penalty language reflected in the row's status_note. The enacted version is Substitute A. Source updated to the Substitute A PDF; no change to the tracked date, lifecycle, or facts, which already matched the enacted text.

Primary source — webserver.rilegislature.gov ↗

July 202625 entries
CN China AI Agents Opinions — upgraded to the CAC's own primary text

correction logged 30 Jul 2026

The row previously cited an English-language gov.cn news writeup. The Cyberspace Administration of China has published the authoritative Chinese-language full text of the AI Agent Standardized Application and Innovative Development Implementation Opinions on its own domain. Source updated to the CAC original and confidence raised from medium to high; no change to the tracked date or substance.

Primary source — cac.gov.cn ↗

UK UK AI (Regulation) Bill [HL] confidence upgraded to high

correction logged 29 Jul 2026

UK Parliament's Bills API confirms the Bill remains at first reading in the House of Lords with no progress since introduction. DSIT's published Blueprint for AI Regulation favours an AI Growth Lab / sector-sandbox approach over government-sponsored AI legislation, corroborating the existing assessment that the Bill is unlikely to advance as drafted. Confidence raised from medium to high; no change to the tracked facts or dates.

Primary source — bills-api.parliament.uk ↗

US Illinois SB 343 added: algorithmic rental price-coordination ban (awaiting signature)

Added logged 28 Jul 2026

Illinois SB 343 amends the Illinois Antitrust Act to ban algorithmic coordination of rental prices. It passed the 104th General Assembly and is on Governor Pritzker's desk with a 29 August 2026 action deadline, so it is tracked as proposed with no effective date. Four of the five companion AI bills have been signed; SB 343 had not been as of 28 July 2026.

Primary source — ilga.gov ↗

CNUK Add UK DUAA ADM reform, UK DUAA s.138 deepfake offences, China AI Agents Opinions

Added logged 28 Jul 2026

Three obligations identified as coverage gaps and added to the register. UK: the Data (Use and Access) Act 2025 automated decision-making reform (ss.22A-22D of the UK GDPR, in force 5 February 2026 by SI 2026/82), which replaces the Art. 22 default prohibition with notification, representation, human-review and contest duties. UK: DUAA 2025 s.138, in force 6 February 2026, which inserts ss.66E-66H into the Sexual Offences Act 2003 and criminalises creating or requesting a non-consensual intimate deepfake even where it is never shared — distinct from the Crime and Policing Act 2026 offences, which target tool suppliers. China: the CAC/NDRC/MIIT AI Agents Implementation Opinions of 8 May 2026.

Primary source — legislation.gov.uk ↗

UKUS Algorithmic price-coordination bans reclassified; UK deepfake offence scope widened to everyone

correction logged 28 Jul 2026

Three rows carried topic tags that no theme page defines and were therefore untagged and unreachable from any topic: the NJ FAIR Act, Maryland's Protection From Predatory Pricing Act and Illinois SB 343. All three ban a use of an algorithm outright, so they now sit under Prohibited AI practices, and that page covers the price-coordination family. Separately, UK DUAA 2025 s.138 was scoped to deployers, though the offence binds any person in the UK who creates or requests a non-consensual intimate deepfake; it is now scoped to everyone. No dates, sources or facts changed.

Primary source — legislation.gov.uk ↗

US Rhode Island H 7538 effective-date uncertainty resolved

Updated logged 27 Jul 2026

The row previously carried a placeholder status note pending confirmation of the effective date. Law-firm trackers citing the enacted text (R.I. Gen. Laws ch. 23-106) confirm it was signed 22 June 2026 and is effective upon passage. Status note updated and confidence raised from medium to high.

Primary source — webserver.rilegislature.gov ↗

US RAISE Act bill citation corrected to S6953-B/A6453-B

correction logged 27 Jul 2026

The row previously cited the RAISE Act as S1169-A. The bill actually signed into law by Governor Hochul on 19 December 2025 is S6953-B/A6453-B. The tracked effective date (1 January 2027) is unaffected.

Primary source — governor.ny.gov ↗

US Georgia SB 540 effective date confirmed via official Senate press release

Updated logged 27 Jul 2026

An official Georgia Senate press release confirms SB 540's 1 July 2027 effective date. Confidence raised from medium to high; no other fields changed.

Primary source — senatepress.net ↗

KR South Korea high-impact AI grace period confirmed via official government briefing

Updated logged 27 Jul 2026

An official Korea Policy Briefing (korea.kr) release directly quotes MSIT confirming an at-least-one-year fines grace period running from the AI Basic Act's 22 January 2026 effective date. Confidence raised from medium to high; no other fields changed.

Primary source — korea.kr ↗

AU Australia ADM transparency citation corrected to APP 1.7-1.9

correction logged 27 Jul 2026

The row previously cited the automated decision-making transparency duty as APP 1.3. The Privacy and Other Legislation Amendment Act 2024 (Cth), Schedule 1, cl.88 actually inserts the new duty as APP 1.7-1.9, per the Federal Register of Legislation text and the ATO Legal Database. The 10 December 2026 commencement date is unaffected.

Primary source — legislation.gov.au ↗

US Washington HB 1170 penalty and enforcement mechanism confirmed

correction logged 26 Jul 2026

The row previously flagged the penalty amount and enforcement mechanism as unverified. Washington legislative bill reports confirm the law (Chapter 167, Laws of 2026) is enforced exclusively by the state Attorney General under the Consumer Protection Act (ch. 19.86 RCW), with civil penalties up to $100,000 per covered provider.

Primary source — lawfilesext.leg.wa.gov ↗

US Tennessee SB 1700 corrected: enacted as a study mandate, not a chatbot-safety law

correction logged 26 Jul 2026

Primary-source review found that Senate amendments adopted 14 April 2026 stripped SB 1700's original companion-chatbot safety restrictions before passage. As signed (Public Chapter 1082), the law only directs TACIR to study potential AI/chatbot regulation, with no report deadline and no compliance obligation on AI operators. The row is corrected to reflect this; it no longer carries a 2027-01-01 compliance date.

Primary source — wapp.capitol.tn.gov ↗

US Rhode Island S 2195 effective date corrected to 1 January 2027

correction logged 26 Jul 2026

The row previously used the 22 June 2026 signing date as a placeholder pending confirmation. Primary and corroborating legislative-tracking sources confirm the Act's general effective date is 1 January 2027, with the separate annual AG reporting duty beginning 1 July 2027. Date and lifecycle updated accordingly.

Primary source — webserver.rilegislature.gov ↗

EU EU Digital Omnibus published in the Official Journal as Regulation (EU) 2026/1744

Updated logged 24 Jul 2026

The Digital Omnibus amending the AI Act was published in the Official Journal as Regulation (EU) 2026/1744, ending the period in which the original Article 113 dates stood pending publication. Three tracked entries move off 'proposed' to fixed future application dates: the Annex III high-risk obligations are deferred to 2 December 2027, the Annex I product-embedded high-risk obligations to 2 August 2028, and the new Article 5 prohibition covering AI-generated CSAM and intimate imagery applies from 2 December 2026.

Primary source — eur-lex.europa.eu ↗

US Six US state synthetic-media and digital-likeness laws added

Added logged 22 Jul 2026

Coverage expands across the deepfake and digital-replica cluster: Washington's Forged Digital Likeness Protection Act (SB 5886) and AI Content Disclosure Act (HB 1170), Hawaii's Deepfake Protection and Synthetic Performer Disclosure law (HB 2137 / Act 247), New York's Synthetic Performer Disclosure Law (S.8420-A) and Deceased Performer Digital Replica Consent Law (S.8391), and Maryland's Deepfake Identity Fraud law (SB 8 / Ch. 445). Each row links to its enacted text.

Primary source — data.capitol.hawaii.gov ↗

US Five further US state AI laws added across housing, education and pricing

Added logged 21 Jul 2026

Illinois' Artificial Intelligence Safety Measures Act (SB 315), New Jersey's FAIR Act banning algorithmic rent-setting (A3497/S451), California's AB 2148 requiring K-12 school employees and contractors to be natural persons, Illinois' SB 2909 restricting AI in teacher evaluation, and Maryland's HB 895 on surveillance and predatory pricing. Algorithmic pricing is now tracked across two jurisdictions but does not yet have its own theme page.

Primary source — pub.njleg.gov ↗

US Ten US laws on AI in prior authorization, utilization review and health claims added

Added logged 21 Jul 2026

A near-uniform rule runs through this group: an algorithm may inform a coverage decision but may not be its sole basis, with licensed human review before an adverse determination. Washington SB 5395, Iowa HF 2635, Alabama SB 63, Georgia SB 444 and Colorado HB 26-1139 carry the human-review requirement; Maryland HB 820 adds quarterly regulator audits; Utah SB 319 and Indiana HB 1271 add disclosure of AI use; Illinois SB 3114 extends the logic to claim downcoding; and Rhode Island H 7538 covers AI transcription in the clinic. A new Healthcare theme page groups them.

Primary source — app.leg.wa.gov ↗

US Fifteen US companion-AI, chatbot and mental-health AI laws added

Added logged 21 Jul 2026

The 2026 US state session produced a dense cluster of conversational-AI statutes, now tracked in full. The common core is disclosure that the system is not human, a protocol when a conversation turns to self-harm, and additional safeguards for minors — in Hawaii (Act 248), Iowa (SF 2417), Washington (HB 2225), Oregon (SB 1546), Georgia (SB 540), Colorado (HB 26-1263), Idaho (SB 1297), Rhode Island (S 2195), Nebraska (LB 525), Connecticut (SB 5) and Tennessee (SB 1700). A second line addresses AI in mental-health care: Tennessee SB 1580, Rhode Island H 7349, Colorado HB 26-1195. Three new theme pages cover this material.

Primary source — olis.oregonlegislature.gov ↗

AUEUVN Vietnam, Australia and two EU instruments added

Added logged 21 Jul 2026

Vietnam's Decision 33 publishes a list of 46 high-risk AI systems, applicable 15 August 2026. Australia's automated decision-making transparency requirement under the Privacy Act reforms is tracked as a separate row. On the EU side, the Annex I product-embedded high-risk obligations are now a distinct entry from Annex III, and Implementing Regulation (EU) 2026/1755 sets out the GPAI enforcement and investigation procedures, applicable from 10 August 2026.

Primary source — eur-lex.europa.eu ↗

CN China Anthropomorphic AI Measures now in force (15 Jul 2026)

Updated logged 21 Jul 2026

The Interim Measures for the Administration of Anthropomorphic Artificial Intelligence Interaction Services entered into force on 15 July 2026, confirmed from the Digital Policy Alert primary-source record. Lifecycle updated from 'dateset' to 'force'; status note updated to reflect in-force date.

Primary source — digitalpolicyalert.org ↗

AE DIFC Regulation 10/11 public consultation closed 18 Jul 2026

Updated logged 21 Jul 2026

The 30-day public consultation on proposed amendments to DIFC Data Protection Regulation 10 (strengthening AI/autonomous-system certification and the Autonomous Systems Officer role) and the new Regulation 11 (Commissioner accreditation powers), launched 18 June 2026 under Consultation Paper No. 3 of 2026, closed on 18 July 2026. The final amended regulations are pending adoption. Status note updated to reflect the closed consultation.

Primary source — difc.com ↗

BR Brazil PL 2338: still in Special Commission awaiting rapporteur's opinion; plenary vote not before late 2026

Updated logged 11 Jul 2026

As of July 2026, PL 2338/2023 remains in the Chamber of Deputies' Special Commission on Artificial Intelligence (rapporteur: Deputy Aguinaldo Ribeiro, PP-PB) awaiting the rapporteur's formal opinion; the bill has not been voted on. The Camara's official tracking page shows status 'Aguardando Parecer do Relator(a)' with no scheduled plenary date. Status note updated to reflect the current committee stage and expected timeline.

Primary source — camara.leg.br ↗

US NY RAISE Act: incident reporting corrected to NYDFS (not AG/DHSES) after chapter amendment

correction logged 10 Jul 2026

The chapter amendment to the RAISE Act (signed 27 March 2026) restructured incident reporting: Critical Safety Incident reports now go to a new office within NYDFS (not the AG or DHSES), and NYDFS has discretion to share them with the AG and other governmental entities. The summary previously stated 'NY AG/DHSES'; corrected to reflect that NYDFS is the primary recipient of 72h reports, with the AG retaining civil-penalty enforcement authority.

Primary source — dwt.com ↗

VN Vietnam AI Law: confidence upgraded to high; grace periods clarified from primary law text

correction logged 1 Jul 2026

Primary law text (Art. 35, Law 134/2025/QH15) confirms a 12-month grace period for all sectors (compliance to 1 March 2027) and an 18-month grace period specifically for health, education and finance sectors (compliance to 1 September 2027). Implementing Decree 142/2026/ND-CP, effective 1 May 2026, provides procedural details. With the Law and its implementing decree both in force and confirmed from the official English law translation, confidence for both obligations is upgraded from medium to high. The vn-ai-law-risk status note is updated to specify the September 2027 endpoint for health/education/finance sectors.

Primary source — english.luatvietnam.vn ↗

EU EU Digital Omnibus: Council formally adopted 29 Jun 2026; OJ publication pending

Updated logged 1 Jul 2026

The Council of the EU formally adopted the Digital Omnibus AI simplification package on 29 June 2026 (Parliament adopted 16 June 2026). The regulation will be published in the Official Journal in July 2026 and enters into force 3 days after publication. Upon entry into force: the deferral of Annex III (standalone) high-risk AI obligations to 2 December 2027 takes legal effect; the new Art. 5 prohibition on AI-generated CSAM and non-consensual intimate imagery applies from 2 December 2026; and the Art. 50(2) marking deferral for pre-August 2026 systems to 2 December 2026 is confirmed. Status notes updated to reflect completed inter-institutional adoption; confidence raised from low to medium as OJ publication is the sole remaining step.

Primary source — consilium.europa.eu ↗

June 20268 entries
CN China: Anthropomorphic AI Interactive Services Measures — new obligation, effective 15 Jul 2026

Added logged 30 Jun 2026

The CAC and four co-regulators (NDRC, MIIT, MPS, SAMR) jointly issued the Interim Measures for the Management of Anthropomorphic Interactive Services of Artificial Intelligence on 10 April 2026, effective 15 July 2026. The Measures require providers to disclose AI identity to users, prohibit virtual intimate relationships for minors under 14, mandate addiction-monitoring and emotion-management systems, and impose usage-time warnings after two consecutive hours. This is China's first dedicated regulation targeting AI companion and emotionally interactive services.

Primary source — cac.gov.cn ↗

IN India IT Rules updated: Feb 2026 amendment introduces 3-hour takedown and SGI definition

Updated logged 28 Jun 2026

MeitY notified the IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 (G.S.R. 120(E)) on 10 February 2026; the rules came into force on 20 February 2026. The amendment introduces a statutory 'synthetically generated information' (SGI) definition, mandates provenance-metadata labels on AI-generated content, and tightens the government-ordered takedown window from 36 hours to 3 hours (2 hours for CSAM and non-consensual intimate imagery). The obligation date has been updated from 2025-11-15 to 2026-02-20 to reflect the current operative version, and the source URL updated to the 2026 MeitY notification.

Primary source — meity.gov.in ↗

AE DIFC opens public consultation on amended Data Protection Regulations (closes 18 Jul 2026)

Updated logged 27 Jun 2026

On 18 Jun 2026 the DIFC Commissioner announced a 30-day consultation on proposed amendments to the Data Protection Regulations. The proposed changes strengthen Regulation 10 (certification obligations for autonomous/AI systems and the Autonomous Systems Officer role) and introduce a new Regulation 11 empowering the Commissioner to recognise external accreditation schemes. Regulation 10 itself remains in force; general certification guidance is still pending. Status note updated to reflect the open consultation.

Primary source — gulfnews.com ↗

EU EU GPAI obligations — confidence upgraded to high after CoP finalisation

correction logged 26 Jun 2026

The AI Office published the final General-Purpose AI Code of Practice on 10 July 2025; the European Commission and AI Board confirmed it as an adequate compliance tool under Art. 53. With the final CoP in place and GPAI enforcement via Art. 101 beginning 2 August 2026, the residual uncertainty that drove the 'medium' rating is resolved. Confidence updated to high.

Primary source — digital-strategy.ec.europa.eu ↗

US RAISE Act chapter amendment confirmed; confidence upgraded to high

correction logged 25 Jun 2026

The chapter amendment to the RAISE Act (S1169-A) was signed 27 March 2026, finalising the law's text after the original signing on 19 December 2025. With both the original signing and the chapter amendment confirmed, the 1 January 2027 effective date is legally settled and federal preemption has not materialised. Confidence updated from medium to high.

Primary source — governor.ny.gov ↗

KR Corrected South Korea AI Basic Act grace period: runs to ~22 Jan 2027

correction logged 25 Jun 2026

MSIT indicated a one-year enforcement grace period beginning on the Act's effective date of 22 January 2026. Both obligation rows previously stated the grace period ran 'through ~2026', which understates the window; the correct expiry is approximately 22 January 2027. Status notes updated accordingly.

Primary source — cooley.com ↗

Global data pass — every map jurisdiction verified to primary sources

Updated logged 24 Jun 2026

Verified the AI-regulation status of all 30+ shaded jurisdictions and upgraded every non-EU/US obligation to primary-source standard, with checked dates and confidence flags.

Primary source — artificialintelligenceact.eu ↗

May 20261 entry
MX Mexico enacts performer-AI protections

Added logged 14 May 2026

A reform to the Federal Labour Law and Copyright Law requiring consent and remuneration to clone a performer’s voice or image via AI was published in the DOF.

Primary source — diputados.gob.mx ↗

March 20261 entry
January 20261 entry

Want these in your inbox? Get an email when an obligation in your profile changes — or follow the feed.