PrivacySignal
GDPR / Intl

noyb success: ORF.at must correct misleading cookie banner

noyb (None of Your Business) · · EU · GDPR & International

Austria's Federal Administrative Court has upheld a ruling requiring public broadcaster ORF to redesign its cookie consent banner so that the accept and reject buttons are visually equal. The decision, which follows a successful complaint by privacy group noyb, addresses ORF's practice of highlighting the 'Accept' button in color, which the court agreed could push users into unintended consent.

Why this matters: This is about a design trick that has been standard practice across the web for years. Making 'Accept' bright and 'Reject' dull is not a neutral choice. It is a nudge, and it works. Most people click the obvious button. A court calling that out matters because it shifts the baseline. Cookie consent has to be a real choice, not a UI pattern designed to harvest agreement. If one of Europe's public broadcasters had to change, so does everyone else still running the same playbook.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

GDPR / Intl
C Computer Weekly · · International

ICO police facial recognition audits reveal ‘mixed’ bag

The UK's Information Commissioner's Office conducted audits of police use of facial recognition technology and found inconsistent results across the forces reviewed. The findings suggest compliance and practice vary significantly, with no uniform standard being met.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

#gdpr#surveillance#privacy Read original →
GDPR / Intl
B Biometric Update · · International

UK ICO finds police facial recognition use mostly compliant with data regulations

The UK's Information Commissioner's Office reviewed police use of facial recognition technology and found it to be largely compliant with data protection law. The assessment stops short of a full endorsement but does not identify systemic violations.

Who should care: Lawyers · Privacy officers · AI governance · Compliance · Cybersecurity · General readers · Policy

#gdpr#regulation#surveillance#privacy Read original →
GDPR / Intl
I Infosecurity Magazine · · International

ICO Urges Police to Improve Data Governance in Facial Recognition Roll

The UK's Information Commissioner's Office has called on police forces to strengthen how they manage data as facial recognition technology is deployed more widely. The ICO's intervention signals concerns about compliance and oversight during the rollout.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

#gdpr#surveillance#privacy Read original →
GDPR / Intl
K keyt.com · · International

State Privacy Regulator Issues Second Decision Penalizing Out-of-State Data Broker

A state privacy regulator has issued its second enforcement decision against an out-of-state data broker, signaling continued regulatory action beyond its own borders. The decision adds to a pattern of state-level agencies asserting jurisdiction over companies that collect and sell resident data regardless of where those companies are based.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#state-privacy#regulation#privacy Read original →
GDPR / Intl
Inside Privacy (Covington) · · International

French CNIL Publishes Note on Agentic AI and Data Protection

France's data protection authority, the CNIL, and the French AI and Digital Council released a joint exploratory note examining how existing data protection rules apply to agentic AI systems. The document is framed as an early-stage analysis rather than binding guidance.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#ai#privacy Read original →