PrivacySignal

Search & browse the archive

The full corpus — beyond today's front page.

Reset

47 results · page 1 of 2

GDPR / Intl
O Ogletree · · International

Deployment of AI Recruitment Tools in the EU: Employer Obligations Under GDPR and EU AI Act

Employers in the EU using AI-powered recruitment tools face obligations under both GDPR and the EU AI Act, which together impose rules on how candidate data is collected, processed, and used in automated hiring decisions.

Who should care: Lawyers · Privacy officers · AI governance · Administrators · General readers · Policy

#gdpr#ai-governance#ai Read original →
Enforcement
EDPB · · EU

The Irish Data Protection Commission fines Google 403 000 000 EUR following Inquiry into Google’s processing of location data

Ireland's Data Protection Commission fined Google €403 million on September 21, 2026, following an inquiry into how the company handled location data. The decision included a compliance order and found violations of GDPR rules on lawful processing, data principles, and transparency obligations.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#regulation#privacy Read original →
Enforcement
EDPB · · EU

The Spanish DPA fined Securitas Direct 100 000 EUR for making the exercise of data subject rights more difficult by directing individuals to a chargeable telephone number

Spain's data protection authority fined Securitas Direct €100,000 after the security company directed people to a paid-rate phone number to exercise their GDPR rights. A consumer association brought the complaint, citing video surveillance notices that routed access and objection requests through a chargeable 902 number.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Cybersecurity · General readers · Policy

#enforcement#gdpr#regulation#surveillance#privacy Read original →
Enforcement
IAPP · · International

Ireland's DPC fines Google 403M euros to close 2020 location data inquiry

Ireland's Data Protection Commission has fined Google 403 million euros, closing an inquiry that began in 2020 into how the company handled users' location data. The case is one of several large enforcement actions brought against major tech companies under the EU's GDPR framework.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
BleepingComputer · · International

Google fined €403 million over location data privacy violations

Ireland's Data Protection Commission has fined Google €403 million for breaching GDPR rules around how it processed users' location data. The fine is one of the larger penalties issued under Europe's data protection framework.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#privacy Read original →
Enforcement
EDPB · · EU

EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines

The European Data Protection Board has adopted two sets of guidelines: one standardizing how national data protection authorities decide when and how to impose fines under the GDPR, and another clarifying how the Digital Services Act and the GDPR interact with each other.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#privacy Read original →
Enforcement
R Reuters · · International

Irish privacy regulator fines Google €403 million over location data processing

Ireland's Data Protection Commission has fined Google €403 million for violations related to how the company processed users' location data. The fine comes from the EU's lead privacy regulator for Google under the GDPR framework.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#regulation#privacy Read original →
Breach
noyb (None of Your Business) · · EU

AI: EU Member States plan “digital expropriation” of Europeans in the interest of AI companies

A leaked document from the Irish EU Council Presidency proposes making personal data use automatically lawful whenever it occurs 'in the context of AI,' effectively removing GDPR protections to benefit companies like OpenAI, Google, Meta, and Anthropic. Multiple EU member states are reported to informally support the measure.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · AI governance · General readers · Policy

#breach#gdpr#ai-governance#ai#privacy Read original →
Enforcement
EDPB · · EU

Failure to respect the rights of individuals: The CNIL fined EXTIA 300 000 EUR

France's data protection authority, the CNIL, fined IT and engineering firm EXTIA €300,000 following complaints from former employees about violations of transparency requirements and the right to erasure under GDPR. The July 2026 decision found the company failed to respect individuals' rights over their personal data.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#privacy Read original →
GDPR / Intl
noyb (None of Your Business) · · EU

Open Letter: Civil society coalition urges EU to kill the cookie banner!

A coalition of 19 civil society groups, businesses, and academics has published an open letter urging EU institutions to support legally binding automated privacy signals as part of the Digital Omnibus package — a mechanism that would let people set privacy preferences once instead of clicking through cookie banners repeatedly. The tracking industry is opposing the proposal.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

#gdpr#surveillance#privacy Read original →
Breach
EDPB · · EU

Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR

France's data protection authority, the CNIL, fined Hôpital Privé de la Loire €500,000 after an attacker gained unauthorized access to its centralized patient records system in summer 2025. The hospital was found in violation of GDPR rules on security of processing and breach notification to affected individuals.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · Healthcare professionals · General readers · Policy

#breach#enforcement#healthcare#privacy Read original →
GDPR / Intl
The Guardian — Privacy · · International

Online bookies accused of UK privacy breaches with use of cookie banners

A study found that 86% of licensed UK gambling websites appear to be violating GDPR by nudging users toward accepting tracking, and in many cases harvesting data before any consent is given. The research accuses the industry of widespread non-compliance and what it describes as systematic data surveillance of customers.

Who should care: Lawyers · Privacy officers · AI governance · Compliance · Cybersecurity · General readers · Policy

#gdpr#regulation#surveillance#privacy Read original →
GDPR / Intl
noyb (None of Your Business) · · EU

Supreme Court: CRIF illegally collected data of millions in Austria. Way clear for class action!

Austria's Supreme Court has ruled that credit reference agency CRIF violated GDPR's purpose limitation principle by collecting personal data from address publishers without a lawful basis. The decision, secured before a full hearing, strengthens a parallel class action brought by privacy group noyb on behalf of millions of affected Austrians.

Who should care: Lawyers · Privacy officers · AI governance

GDPR / Intl
noyb (None of Your Business) · · EU

‘Shadow database’ scandal: noyb sends SCHUFA cease-and-desist letter; interest list for class action opened

German privacy group noyb has sent a cease-and-desist letter to credit agency SCHUFA after investigations revealed it retained millions of records that should have been deleted, and used them for customer testing. Noyb has opened an interest list for a class action, with up to 69 million people potentially affected.

Who should care: Lawyers · Privacy officers · AI governance

Breach
DataBreaches.net · · International

UK: ICO reprimands ACRO Criminal Records Office after data breach

The UK Information Commissioner's Office has formally reprimanded ACRO Criminal Records Office for violating UK GDPR security requirements following a data breach. ACRO is a national police unit that handles sensitive records including criminal history, Police Certificates, and International Child Protection Certificates.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · AI governance

#breach#gdpr Read original →
GDPR / Intl
IAPP · · International

The EDPB's draft anonymization guidelines: What they mean for your data strategy

The European Data Protection Board has released draft guidelines on anonymization, offering new technical and legal benchmarks for when data can be considered truly anonymous and therefore outside the scope of GDPR obligations. The guidelines are aimed at clarifying a standard that organizations have long applied inconsistently.

Who should care: Lawyers · Privacy officers · AI governance

AI Governance
E Euronews.com · · International

Brussels Effect: How the EU AI Act reaches firms beyond the bloc

The EU AI Act is shaping how companies outside Europe build and deploy AI systems, as firms seeking access to the EU market must comply with its requirements regardless of where they are headquartered. This regulatory reach mirrors the pattern seen with GDPR, where European rules effectively became a global baseline.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
Enforcement
noyb (None of Your Business) · · EU

1,741 “informed” consents with one click?! GDPR complaint against dict.cc filed

Privacy advocacy group noyb has filed a GDPR complaint against the online dictionary dict.cc, alleging that the site uses a single-click consent button to grant data access to 1,741 advertising and tracking partners. The complaint argues that bundling that many recipients into one click makes it impossible for users to give the informed, specific consent the GDPR requires.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Cybersecurity · General readers · Policy

#enforcement#gdpr#surveillance#privacy Read original →
GDPR / Intl
EDPB · · EU

EDPB calls for legal basis for cross-regulatory information sharing

At a July 2026 meeting in Dublin, the European Data Protection Board called for an explicit legal foundation governing how data protection authorities share information with regulators outside their jurisdiction. The EDPB also discussed deepening cooperation among DPAs to strengthen consistent GDPR enforcement across the EU.

Who should care: Lawyers · Privacy officers · AI governance · Compliance · General readers · Policy

#gdpr#regulation#privacy Read original →
Enforcement
EDPB · · EU

EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint

The European Data Protection Board has issued a binding decision requiring the Belgian Data Protection Authority to rule on the substance of a cookie banner complaint filed by NOYB against Flemish public broadcaster VRT. The dispute arose after the Belgian DPA, acting as lead supervisory authority, submitted a draft decision that did not address the merits of the case.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#privacy Read original →
GDPR / Intl
IAPP · · International

Thought for the week: Web scraping for generative AI is subject to the GDPR

A commentary from the IAPP argues that web scraping used to build generative AI training datasets falls within the scope of GDPR, meaning the collection and processing of personal data found online is not exempt simply because it occurs at scale or at the infrastructure level.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

GDPR / Intl
- - Center for Democracy and Technology · · International

Potential Avenues for Redress for AI-related Harms under the GDPR: A Visual Explanation

The Center for Democracy and Technology has published a visual guide mapping out how individuals can seek redress for harms caused by AI systems under the GDPR. The resource appears aimed at helping people and advocates understand which legal pathways are available when AI causes harm covered by European data protection law.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

Page 1 of 2 Next →