PrivacySignal
Enforcement

GDPR EU representative enforcement continues

iapp.org · · International · Enforcement

EU data protection authorities are continuing to enforce GDPR requirements around the designation of local representatives for non-EU companies doing business in Europe. The trend signals that regulators are treating this structural compliance obligation as a live enforcement priority, not a paper formality.

Why this matters: If your company is based outside the EU but handles data from European residents, you are legally required to appoint someone inside the EU who can be reached by regulators and individuals. That person or entity is not a technicality. They are the contact point when something goes wrong. Companies that treat this as a checkbox are learning it can become a real liability. Regulators are not waiting for a bigger violation to act. This is the kind of procedural gap that turns into a fine before the underlying data practices ever get examined.

Who should care: Lawyers · Privacy officers · Compliance · AI governance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Enforcement
The Guardian — Tech · · International

US schools and police warn about viral ‘Cat in the Hat’ trend after teens’ arrests

A social media trend using distorted or AI-generated images of the Cat in the Hat character has spread across the US, with some posts used to make threats against schools and students. Several teenagers have been arrested or charged in connection with the posts, prompting warnings from schools and law enforcement.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#enforcement#ai Read original →
Enforcement
WIRED — AI · · International

Meta Sued Over Training Data for Its AI and Face-Recognition Systems

A proposed class action lawsuit claims Meta scraped photos from Facebook and Instagram without permission to train its AI image-generation tools and develop an unreleased facial recognition feature called NameTag.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#enforcement#ai Read original →
Enforcement
The Guardian — Tech · · International

New Mexico lawyer fined for using AI-generated brief containing fabricated testimony

The New Mexico Supreme Court fined and held defense attorney Stephen Aarons in contempt after he submitted an appeal brief in a murder case that contained fabricated police testimony and invented witnesses generated by ChatGPT. Aarons said he used the AI tool to build what he described as a bulletproof summary, but did not verify the filing's accuracy before submitting it.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Administrators · General readers · Policy

#enforcement#ai-governance#ai Read original →
Enforcement
EFF — Deeplinks · · International

Cold TAKE: Amazon's New Encryption Method Still Doesn't Deliver Real Privacy

Amazon introduced a new encryption feature for Ring cameras called Throw Away the Key Encryption, which shifts some control over video access toward users. Critics argue the approach still leaves Amazon holding temporary encryption keys, stopping well short of true end-to-end privacy protection.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
Information Commissioner's Office · · UK

ICO statement on its investigation into Police Scotland

The UK's Information Commissioner's Office has issued a statement regarding an investigation it opened into Police Scotland. No further details about the investigation's findings or scope are available from this disclosure.

Who should care: Lawyers · Privacy officers · Compliance · AI governance

#enforcement#gdpr Read original →
Enforcement
EDPB · · EU

Failure to respect the rights of individuals: The CNIL fined EXTIA 300 000 EUR

France's data protection authority, the CNIL, fined IT and engineering firm EXTIA €300,000 following complaints from former employees about violations of transparency requirements and the right to erasure under GDPR. The July 2026 decision found the company failed to respect individuals' rights over their personal data.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#privacy Read original →