PrivacySignal
GDPR / Intl

noyb success: ORF.at must correct misleading cookie banner

noyb (None of Your Business) · · EU · GDPR & International

Austria's Federal Administrative Court has upheld a ruling requiring public broadcaster ORF to redesign its cookie consent banner so that the accept and reject buttons are visually equal. The decision, which follows a successful complaint by privacy group noyb, addresses ORF's practice of highlighting the 'Accept' button in color, which the court agreed could push users into unintended consent.

Why this matters: This is about a design trick that has been standard practice across the web for years. Making 'Accept' bright and 'Reject' dull is not a neutral choice. It is a nudge, and it works. Most people click the obvious button. A court calling that out matters because it shifts the baseline. Cookie consent has to be a real choice, not a UI pattern designed to harvest agreement. If one of Europe's public broadcasters had to change, so does everyone else still running the same playbook.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

The Attacker Did Not Need to Sleep

Spain received its first reported personal-data breach carried out by an AI agent. The techniques were familiar. The speed and autonomy were not.

· 4 min read Read →

Related stories

GDPR / Intl
W WIS News 10 · · International

SC Attorney General Alan Wilson presses Flock Safety for answers on AI use, data privacy

South Carolina Attorney General Alan Wilson has contacted Flock Safety, a license plate reader and surveillance technology company, seeking information about how the company uses AI and handles personal data collected through its systems.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#state-privacy#ai#privacy Read original →
GDPR / Intl
Information Commissioner's Office · · UK

ICO welcomes transition to new Information Commission and marks new chapter with Manchester head office opening

The UK's Information Commissioner's Office is transitioning to a newly structured Information Commission and has opened a head office in Manchester, marking an institutional shift in how the country's data protection authority is organized.

Who should care: Lawyers · Privacy officers · AI governance

GDPR / Intl
ICO · · UK

ICO head office address change

The UK's Information Commissioner's Office has announced a change to its head office address.

Who should care: Lawyers · Privacy officers · AI governance

GDPR / Intl
O Ogletree · · International

Deployment of AI Recruitment Tools in the EU: Employer Obligations Under GDPR and EU AI Act

Employers in the EU using AI-powered recruitment tools face obligations under both GDPR and the EU AI Act, which together impose rules on how candidate data is collected, processed, and used in automated hiring decisions.

Who should care: Lawyers · Privacy officers · AI governance · Administrators · General readers · Policy

#gdpr#ai-governance#ai Read original →
GDPR / Intl
T The National Law Review · · International

Amendments to Delaware’s Consumer Privacy Law Deepen the Morass of State Privacy Regulation

Delaware has amended its consumer privacy law, adding new layers to an already complex patchwork of state-level privacy rules across the United States. The changes make compliance more complicated for companies operating in multiple states.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#state-privacy#regulation#privacy Read original →