PrivacySignal
GDPR / Intl

EDPS Annual Report 2025: protecting people in a changing digital world

EDPS · · EU · GDPR & International

The European Data Protection Supervisor has published its Annual Report for 2025, covering a year the agency describes as focused on expanding its operational mandate across monitoring, enforcement, and advisory roles. The report is accompanied by an executive summary, a supervisory speech, and a press conference.

Why this matters: The EDPS is the watchdog for EU institutions — it oversees how bodies like the European Commission, Europol, and eu-LISA handle personal data. What it does, or does not do, shapes privacy standards across the bloc. Annual reports like this one are a paper trail. They show which institutions got scrutinized, which new powers the agency took on, and where it chose to act or hold back. If you want to know whether European data protection is getting stronger or softer in practice, this is one of the documents worth reading past the press release.

Who should care: Lawyers · Privacy officers · AI governance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

GDPR / Intl
H Hunton Andrews Kurth LLP · · International

EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence

The European Data Protection Board has called for a review of the EU-U.S. Data Privacy Framework following a U.S. Supreme Court ruling that affects the independence of the Federal Trade Commission, a key enforcement body underpinning the transatlantic data transfer agreement.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
GDPR / Intl
Information Commissioner's Office · · UK

ICO statement on Upper Tribunal decision

I need to work carefully here — the excerpt gives almost nothing beyond the headline. I'll write only what the headline and source reasonably imply: the UK's Information Commissioner's Office issued a public statement following a ruling by the Upper Tribunal, which is an appellate body that hears ch

Who should care: Lawyers · Privacy officers · AI governance

GDPR / Intl
Inside Privacy (Covington) · · International

New York Publishes Final SAFE For Kids Act Rules

On July 28, 2026, the New York Office of the Attorney General released final rules (the “Rules”) implementing the Stop Addictive Feeds Exploitation (SAFE) for Kids Act, which goes into effect on January 25, 2027. The SAFE for Kids Act requires online “addictive social media platforms,” which are defined as websites, online services, and applications... Continue Reading…

Who should care: Lawyers · Privacy officers · Compliance

#state-privacy#regulation#security Read original →
GDPR / Intl
Inside Privacy (Covington) · · International

EDPB Publishes Draft Guidelines on Anonymisation

The European Data Protection Board has released draft guidelines updating its 2014 position on anonymisation, offering a more structured framework for determining when data can be treated as truly anonymous. The guidelines reflect the EDPB's cautious stance while attempting to give organisations clearer criteria for making that assessment.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
GDPR / Intl
IAPP · · International

EDPB requests review of EU-US Data Privacy Framework following Trump v. Slaughter

The European Data Protection Board has called for a review of the EU-US Data Privacy Framework following the Trump v. Slaughter case, which relates to the dismissal of Federal Trade Commission members and raises concerns about the independence of the US enforcement body underpinning the transatlantic data transfer agreement.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
GDPR / Intl
DataBreaches.net · · International

Cyberattack hits Liechtenstein, with 31,000 records stolen

Liechtenstein's government has confirmed a cyberattack that resulted in the theft of approximately 31,000 personal records. Given the country's population of around 41,000, the breach potentially affects the majority of its residents.

Who should care: Lawyers · Privacy officers · AI governance