PrivacySignal
Enforcement

1,741 “informed” consents with one click?! GDPR complaint against dict.cc filed

noyb (None of Your Business) · · EU · Enforcement

Privacy advocacy group noyb has filed a GDPR complaint against the online dictionary dict.cc, alleging that the site uses a single-click consent button to grant data access to 1,741 advertising and tracking partners. The complaint argues that bundling that many recipients into one click makes it impossible for users to give the informed, specific consent the GDPR requires.

Why this matters: One click, 1,741 companies you have never heard of, all getting access to your data. That is not consent in any meaningful sense. It is a legal fiction dressed up as a button. Dict.cc is an extreme case, but the underlying trick is everywhere. Most cookie banners are designed to get you to say yes as fast as possible, not to help you understand what you are agreeing to. The GDPR was supposed to stop exactly this. When it does not, complaints like this one are the only real check on the gap between what the law says and what companies actually do.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Cybersecurity · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Enforcement
The Guardian — Tech · · International

US schools and police warn about viral ‘Cat in the Hat’ trend after teens’ arrests

A social media trend using distorted or AI-generated images of the Cat in the Hat character has spread across the US, with some posts used to make threats against schools and students. Several teenagers have been arrested or charged in connection with the posts, prompting warnings from schools and law enforcement.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#enforcement#ai Read original →
Enforcement
WIRED — AI · · International

Meta Sued Over Training Data for Its AI and Face-Recognition Systems

A proposed class action lawsuit claims Meta scraped photos from Facebook and Instagram without permission to train its AI image-generation tools and develop an unreleased facial recognition feature called NameTag.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#enforcement#ai Read original →
Enforcement
The Guardian — Tech · · International

New Mexico lawyer fined for using AI-generated brief containing fabricated testimony

The New Mexico Supreme Court fined and held defense attorney Stephen Aarons in contempt after he submitted an appeal brief in a murder case that contained fabricated police testimony and invented witnesses generated by ChatGPT. Aarons said he used the AI tool to build what he described as a bulletproof summary, but did not verify the filing's accuracy before submitting it.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Administrators · General readers · Policy

#enforcement#ai-governance#ai Read original →
Enforcement
EFF — Deeplinks · · International

Cold TAKE: Amazon's New Encryption Method Still Doesn't Deliver Real Privacy

Amazon introduced a new encryption feature for Ring cameras called Throw Away the Key Encryption, which shifts some control over video access toward users. Critics argue the approach still leaves Amazon holding temporary encryption keys, stopping well short of true end-to-end privacy protection.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
Information Commissioner's Office · · UK

ICO statement on its investigation into Police Scotland

The UK's Information Commissioner's Office has issued a statement regarding an investigation it opened into Police Scotland. No further details about the investigation's findings or scope are available from this disclosure.

Who should care: Lawyers · Privacy officers · Compliance · AI governance

#enforcement#gdpr Read original →
Enforcement
EDPB · · EU

Failure to respect the rights of individuals: The CNIL fined EXTIA 300 000 EUR

France's data protection authority, the CNIL, fined IT and engineering firm EXTIA €300,000 following complaints from former employees about violations of transparency requirements and the right to erasure under GDPR. The July 2026 decision found the company failed to respect individuals' rights over their personal data.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#privacy Read original →