PrivacySignal
Enforcement

Notes from the IAPP Europe: DSA and DMA enforcement, return of CSAM detection

IAPP · · International · Enforcement

At the IAPP Europe conference, discussions centered on enforcement of the Digital Services Act and Digital Markets Act, along with renewed debate over proposals to scan private messages for child sexual abuse material. The sessions reflected ongoing tension between platform accountability, market regulation, and the limits of digital privacy in Europe.

Why this matters: Three big issues in one room. DSA and DMA enforcement is moving from theory to practice, which means platforms are starting to face real consequences for how they handle content and data. That affects what you can do online and who controls the infrastructure behind it. The CSAM scanning debate is the harder one. Everyone agrees child exploitation is serious. The disagreement is whether scanning encrypted private messages is a proportionate fix or a backdoor that breaks secure communication for everyone. Europe has not resolved that, and the pressure to act has not gone away.

Who should care: Lawyers · Privacy officers · Compliance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Enforcement
The Guardian — Tech · · International

US schools and police warn about viral ‘Cat in the Hat’ trend after teens’ arrests

A social media trend using distorted or AI-generated images of the Cat in the Hat character has spread across the US, with some posts used to make threats against schools and students. Several teenagers have been arrested or charged in connection with the posts, prompting warnings from schools and law enforcement.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#enforcement#ai Read original →
Enforcement
WIRED — AI · · International

Meta Sued Over Training Data for Its AI and Face-Recognition Systems

A proposed class action lawsuit claims Meta scraped photos from Facebook and Instagram without permission to train its AI image-generation tools and develop an unreleased facial recognition feature called NameTag.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#enforcement#ai Read original →
Enforcement
The Guardian — Tech · · International

New Mexico lawyer fined for using AI-generated brief containing fabricated testimony

The New Mexico Supreme Court fined and held defense attorney Stephen Aarons in contempt after he submitted an appeal brief in a murder case that contained fabricated police testimony and invented witnesses generated by ChatGPT. Aarons said he used the AI tool to build what he described as a bulletproof summary, but did not verify the filing's accuracy before submitting it.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Administrators · General readers · Policy

#enforcement#ai-governance#ai Read original →
Enforcement
EFF — Deeplinks · · International

Cold TAKE: Amazon's New Encryption Method Still Doesn't Deliver Real Privacy

Amazon introduced a new encryption feature for Ring cameras called Throw Away the Key Encryption, which shifts some control over video access toward users. Critics argue the approach still leaves Amazon holding temporary encryption keys, stopping well short of true end-to-end privacy protection.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
Information Commissioner's Office · · UK

ICO statement on its investigation into Police Scotland

The UK's Information Commissioner's Office has issued a statement regarding an investigation it opened into Police Scotland. No further details about the investigation's findings or scope are available from this disclosure.

Who should care: Lawyers · Privacy officers · Compliance · AI governance

#enforcement#gdpr Read original →
Enforcement
EDPB · · EU

Failure to respect the rights of individuals: The CNIL fined EXTIA 300 000 EUR

France's data protection authority, the CNIL, fined IT and engineering firm EXTIA €300,000 following complaints from former employees about violations of transparency requirements and the right to erasure under GDPR. The July 2026 decision found the company failed to respect individuals' rights over their personal data.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#privacy Read original →