PrivacySignal

Search & browse the archive

The full corpus — beyond today's front page.

Reset

31 results · page 1 of 2

GDPR / Intl
IAPP · · International

The EDPB's draft anonymization guidelines: What they mean for your data strategy

The European Data Protection Board has released draft guidelines on anonymization, offering new technical and legal benchmarks for when data can be considered truly anonymous and therefore outside the scope of GDPR obligations. The guidelines are aimed at clarifying a standard that organizations have long applied inconsistently.

Who should care: Lawyers · Privacy officers · AI governance

AI Governance
E Euronews.com · · International

Brussels Effect: How the EU AI Act reaches firms beyond the bloc

The EU AI Act is shaping how companies outside Europe build and deploy AI systems, as firms seeking access to the EU market must comply with its requirements regardless of where they are headquartered. This regulatory reach mirrors the pattern seen with GDPR, where European rules effectively became a global baseline.

Who should care: AI governance · Lawyers · Administrators · General readers · Policy

#ai-governance#ai Read original →
Enforcement
noyb (None of Your Business) · · EU

1,741 “informed” consents with one click?! GDPR complaint against dict.cc filed

Privacy advocacy group noyb has filed a GDPR complaint against the online dictionary dict.cc, alleging that the site uses a single-click consent button to grant data access to 1,741 advertising and tracking partners. The complaint argues that bundling that many recipients into one click makes it impossible for users to give the informed, specific consent the GDPR requires.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Cybersecurity · General readers · Policy

#enforcement#gdpr#surveillance#privacy Read original →
GDPR / Intl
EDPB · · EU

EDPB calls for legal basis for cross-regulatory information sharing

At a July 2026 meeting in Dublin, the European Data Protection Board called for an explicit legal foundation governing how data protection authorities share information with regulators outside their jurisdiction. The EDPB also discussed deepening cooperation among DPAs to strengthen consistent GDPR enforcement across the EU.

Who should care: Lawyers · Privacy officers · AI governance · Compliance · General readers · Policy

#gdpr#regulation#privacy Read original →
Enforcement
EDPB · · EU

EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint

The European Data Protection Board has issued a binding decision requiring the Belgian Data Protection Authority to rule on the substance of a cookie banner complaint filed by NOYB against Flemish public broadcaster VRT. The dispute arose after the Belgian DPA, acting as lead supervisory authority, submitted a draft decision that did not address the merits of the case.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#privacy Read original →
GDPR / Intl
IAPP · · International

Thought for the week: Web scraping for generative AI is subject to the GDPR

A commentary from the IAPP argues that web scraping used to build generative AI training datasets falls within the scope of GDPR, meaning the collection and processing of personal data found online is not exempt simply because it occurs at scale or at the infrastructure level.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

GDPR / Intl
- - Center for Democracy and Technology · · International

Potential Avenues for Redress for AI-related Harms under the GDPR: A Visual Explanation

The Center for Democracy and Technology has published a visual guide mapping out how individuals can seek redress for harms caused by AI systems under the GDPR. The resource appears aimed at helping people and advocates understand which legal pathways are available when AI causes harm covered by European data protection law.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

GDPR / Intl
EDPB · · EU

One-Stop-Shop case digest on right to object and right to erasure updated

The European Data Protection Board has released an updated case digest compiling significant One-Stop-Shop decisions related to individuals' rights to object and to erasure under GDPR, drawn from its public register and developed through its inter-DPA cooperation program.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
Enforcement
iapp.org · · International

GDPR EU representative enforcement continues

EU data protection authorities are continuing to enforce GDPR requirements around the designation of local representatives for non-EU companies doing business in Europe. The trend signals that regulators are treating this structural compliance obligation as a live enforcement priority, not a paper formality.

Who should care: Lawyers · Privacy officers · Compliance · AI governance

#enforcement#gdpr Read original →
Enforcement
EDPB · · EU

Supporting GDPR consistency: EDPB launches dedicated form

The European Data Protection Board has introduced a dedicated online form allowing stakeholders to flag discrepancies in how GDPR is interpreted or enforced across EU member states, including gaps between national supervisory authorities and EDPB positions. The initiative stems from commitments made in the EDPB's Helsinki Statement on clarity and engagement.

Who should care: Lawyers · Privacy officers · Compliance · AI governance

#enforcement#gdpr Read original →
GDPR / Intl
noyb (None of Your Business) · · EU

EU Member States (and Google) suddenly want to keep cookie banners!

The European Commission proposed replacing cookie consent banners with automated browser-based signals as part of its Digital Omnibus simplification package. However, Google and several EU member states, including Germany and France, have pushed back against the change, apparently preferring the current banner system.

Who should care: Lawyers · Privacy officers · AI governance · Compliance · General readers · Policy

#gdpr#regulation#privacy Read original →
GDPR / Intl
EDPB · · EU

EDPB gets a new look: discover the new website and brand identity

The European Data Protection Board has launched a redesigned website and updated brand identity, marking a communications refresh for the EU body responsible for consistent GDPR enforcement and guidance across member states since 2018.

Who should care: Lawyers · Privacy officers · AI governance · Compliance · General readers · Policy

#gdpr#regulation#privacy Read original →
News
IAPP · · International

Are businesses ready for the UK's new data protection complaints regime?

The UK is introducing a revised data protection complaints regime that will change how individuals can raise grievances and how businesses must respond. The shift puts new procedural and compliance pressure on organisations handling personal data under UK GDPR.

Who should care: General readers · Privacy officers · Policy

Enforcement
Inside Privacy (Covington) · · International

Amadeus IT Group Receives GDPR Fine

Spain's data protection authority fined Amadeus IT Group €18 million for GDPR violations tied to its Global Distribution System, which powers booking and travel data infrastructure used across the global travel industry. Amadeus voluntarily paid the fine, receiving a 20% reduction for doing so.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#privacy Read original →
GDPR / Intl
E EPIC – Electronic Privacy Information Center · · International

Council of the EU Must Prevent GDPR Changes From Eroding Privacy Rights, EPIC, Coalition Urge

EPIC and a coalition of privacy advocates have urged the Council of the European Union to block proposed changes to GDPR that they say would weaken existing privacy protections. The groups are pushing EU member states to resist modifications they believe would roll back rights the regulation was designed to guarantee.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
Enforcement
EDPB · · EU

Italian SA fines a company for post-sick leave questionnaires

Italy's data protection authority fined Magna PT S.p.A. and issued a definitive ban on data processing after the company used questionnaires to collect information from employees returning from sick leave. The regulator found violations covering lawfulness of processing, transparency obligations, and the handling of special category health data under the GDPR.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
EDPB · · EU

The Italian Supervisory Authority fined a company 120 000 EUR for tracking five employees who drove company cars

Italy's data protection authority fined Pioneer Hi-Bred Italia Sementi s.r.l. €120,000 for unlawfully tracking five employees via GPS systems in company vehicles, finding violations of GDPR principles on lawful processing, transparency, and data subject information obligations.

Who should care: Lawyers · Privacy officers · Compliance · Cybersecurity · General readers · Policy

#enforcement#regulation#surveillance#privacy Read original →
Enforcement
EDPB · · EU

Imposition of fine on a telecommunications company for violations of data subject’s rights

Greece's data protection authority fined Vodafone-Panafon in February 2026 for failing to properly handle a customer's data rights requests. The violations covered multiple GDPR obligations, including timely responses, the right of access, and the right to restrict processing.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Breach
EDPB · · EU

The Italian SA fined Poste Vita for data breach

Italy's data protection authority issued an administrative fine against insurance firm Poste Vita S.p.A. following a customer complaint alleging unauthorized disclosure of personal data. The regulator found violations of GDPR principles governing data processing and breach-notification obligations.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

#breach#enforcement#privacy Read original →
Enforcement
EDPB · · EU

The Italian SA imposed a 40 000 EUR fine on a company for violating the confidentiality of a employee's email account after the end of his employment

Italy's data protection authority fined LTL S.p.A. €40,000 for accessing a former employee's work email account after his employment ended, breaching GDPR principles on lawful processing, transparency, and the individual's right to access his own data.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#regulation#privacy Read original →
GDPR / Intl
IAPP · · International

GDPR certification goes global, simplifying data transfers and compliance

A GDPR certification mechanism is expanding to cover international data transfers, offering organizations a recognized compliance path across borders. The move is intended to reduce the friction companies face when moving personal data between jurisdictions under Europe's data protection framework.

Who should care: Lawyers · Privacy officers · AI governance · Compliance

#gdpr#regulation Read original →
Page 1 of 2 Next →