PrivacySignal
Enforcement

EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint

EDPB · · EU · Enforcement

The European Data Protection Board has issued a binding decision requiring the Belgian Data Protection Authority to rule on the substance of a cookie banner complaint filed by NOYB against Flemish public broadcaster VRT. The dispute arose after the Belgian DPA, acting as lead supervisory authority, submitted a draft decision that did not address the merits of the case.

Why this matters: Cookie banners are the most visible privacy mechanism most people ever encounter, and they are routinely designed to wear you down until you click accept. NOYB has spent years pushing regulators to actually enforce the rules against this. The problem here is not just VRT. It is a supervisory authority trying to close a complaint without deciding whether the law was broken. The EDPB is now forcing that decision. If regulators can dodge the merits, enforcement becomes theater. This ruling says they cannot.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Enforcement
Lawfare · · US Federal

U.K. Supreme Court Opens Door for Spyware Victims to Sue Foreign States

The U.K. Supreme Court has issued a ruling that allows victims of state-deployed spyware to bring civil claims against foreign governments in British courts. The decision marks a significant shift in how sovereign immunity protections apply when states are accused of covert digital surveillance against individuals.

Who should care: Lawyers · Privacy officers · Compliance · Cybersecurity

#enforcement#surveillance Read original →
Enforcement
HIPAA Journal · · US Federal

Azul Vision Settles HIPAA Right of Access Case for $50,000

The HHS Office for Civil Rights has reached a $50,000 settlement with Azul Vision over a HIPAA right of access violation, marking the agency's ninth financial penalty in this enforcement area.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals

#enforcement#healthcare Read original →
Enforcement
The Guardian — Tech · · International

What could Meta’s US settlement mean around the world – and what now for other claims against firm?

Meta's settlement with U.S. authorities over privacy violations is prompting scrutiny of what similar concessions could be extracted in other jurisdictions, while separate legal actions against the company are pending in multiple countries including Kenya and the Netherlands. One of those cases involves allegations that Facebook's algorithm actively amplified posts calling for a man's murder during Ethiopia's civil war.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Administrators · General readers · Policy

#enforcement#ai-governance#ai#privacy Read original →
Enforcement
Ars Technica — Policy · · International

Elon Musk’s xAI used child porn to train Grok models, lawsuit says

A lawsuit alleges that Elon Musk's xAI used real and AI-generated child sexual abuse material to train its Grok AI models. The company has not publicly responded to the specific claims in the suit.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#enforcement#ai Read original →
Enforcement
WIRED — AI · · International

A Georgia Cop Used Flock to Track 2 Other Cops: His Ex and Her Friend

A Georgia police officer used Flock Safety's license plate reader network to surveil a fellow officer who was his ex-partner in an affair, as well as a man whose vehicle appeared near hers, according to internal investigation records.

Who should care: Lawyers · Privacy officers · Compliance

#enforcement Read original →