PrivacySignal
GDPR / Intl

Digital Omnibus reality check: 83.5% of access requests not properly answered

noyb (None of Your Business) · · EU · GDPR & International

A new analysis by privacy advocacy group noyb found that over eight years of sending GDPR data access requests to companies, only 16.5% received a satisfactory response. More than half of replies were incomplete, and nearly 30% of companies did not respond at all.

Why this matters: The right to access your own data is not a bonus feature. It is the foundation. You cannot fix wrong information, challenge illegal processing, or understand what a company knows about you if they simply ignore the request. This data shows most companies do, in fact, ignore it. That is not a compliance gap. It is a deliberate pattern. And the timing matters: noyb published this as industry lobbying pushes Brussels to weaken these very rights. The people asking for less enforcement are the same ones failing to comply with the rules that already exist.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

GDPR / Intl
C Computer Weekly · · International

ICO police facial recognition audits reveal ‘mixed’ bag

The UK's Information Commissioner's Office conducted audits of police use of facial recognition technology and found inconsistent results across the forces reviewed. The findings suggest compliance and practice vary significantly, with no uniform standard being met.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

#gdpr#surveillance#privacy Read original →
GDPR / Intl
B Biometric Update · · International

UK ICO finds police facial recognition use mostly compliant with data regulations

The UK's Information Commissioner's Office reviewed police use of facial recognition technology and found it to be largely compliant with data protection law. The assessment stops short of a full endorsement but does not identify systemic violations.

Who should care: Lawyers · Privacy officers · AI governance · Compliance · Cybersecurity · General readers · Policy

#gdpr#regulation#surveillance#privacy Read original →
GDPR / Intl
I Infosecurity Magazine · · International

ICO Urges Police to Improve Data Governance in Facial Recognition Roll

The UK's Information Commissioner's Office has called on police forces to strengthen how they manage data as facial recognition technology is deployed more widely. The ICO's intervention signals concerns about compliance and oversight during the rollout.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

#gdpr#surveillance#privacy Read original →
GDPR / Intl
K keyt.com · · International

State Privacy Regulator Issues Second Decision Penalizing Out-of-State Data Broker

A state privacy regulator has issued its second enforcement decision against an out-of-state data broker, signaling continued regulatory action beyond its own borders. The decision adds to a pattern of state-level agencies asserting jurisdiction over companies that collect and sell resident data regardless of where those companies are based.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#state-privacy#regulation#privacy Read original →
GDPR / Intl
Inside Privacy (Covington) · · International

French CNIL Publishes Note on Agentic AI and Data Protection

France's data protection authority, the CNIL, and the French AI and Digital Council released a joint exploratory note examining how existing data protection rules apply to agentic AI systems. The document is framed as an early-stage analysis rather than binding guidance.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#ai#privacy Read original →