PrivacySignal
GDPR / Intl

Notes from the IAPP Europe: GDPR anniversary, 2025 annual reports and looking ahead

IAPP · · International · GDPR & International

The IAPP's European gathering marked the anniversary of GDPR and reviewed 2025 annual reports from data protection authorities, while looking at what the near-term regulatory landscape holds for privacy professionals across the region.

Why this matters: GDPR is old enough now that the gap between what it promised and what it delivered is visible. Anniversary moments like this are useful not for celebration but for honest accounting. Enforcement has been uneven, big tech fines have moved slowly through appeals, and smaller organizations still struggle with compliance basics. What regulators say publicly at events like this shapes what companies prioritize next. If you work in privacy, the signals coming out of these meetings are worth tracking.

Who should care: Lawyers · Privacy officers · AI governance

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

GDPR / Intl
T The National Law Review · · International

HOT OFF THE PRESSES: CalPrivacy Brings First Action Against a Data Broker Under Both the CCPA and Delete Act

California's privacy regulator has filed its first enforcement action against a data broker under both the California Consumer Privacy Act and the Delete Act, marking a significant step in the state's use of its data broker oversight tools.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#state-privacy#privacy Read original →
GDPR / Intl
H Hunton Andrews Kurth LLP · · International

EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence

The European Data Protection Board has called for a review of the EU-U.S. Data Privacy Framework following a U.S. Supreme Court ruling that affects the independence of the Federal Trade Commission, a key enforcement body underpinning the transatlantic data transfer agreement.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
GDPR / Intl
Information Commissioner's Office · · UK

ICO statement on Upper Tribunal decision

I need to work carefully here — the excerpt gives almost nothing beyond the headline. I'll write only what the headline and source reasonably imply: the UK's Information Commissioner's Office issued a public statement following a ruling by the Upper Tribunal, which is an appellate body that hears ch

Who should care: Lawyers · Privacy officers · AI governance

GDPR / Intl
Inside Privacy (Covington) · · International

New York Publishes Final SAFE For Kids Act Rules

On July 28, 2026, the New York Office of the Attorney General released final rules (the “Rules”) implementing the Stop Addictive Feeds Exploitation (SAFE) for Kids Act, which goes into effect on January 25, 2027. The SAFE for Kids Act requires online “addictive social media platforms,” which are defined as websites, online services, and applications... Continue Reading…

Who should care: Lawyers · Privacy officers · Compliance

#state-privacy#regulation#security Read original →
GDPR / Intl
Inside Privacy (Covington) · · International

EDPB Publishes Draft Guidelines on Anonymisation

The European Data Protection Board has released draft guidelines updating its 2014 position on anonymisation, offering a more structured framework for determining when data can be treated as truly anonymous. The guidelines reflect the EDPB's cautious stance while attempting to give organisations clearer criteria for making that assessment.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →