For sale - visit GoDaddy
Contact mail@quant.rocks
The latest enforcement actions, landmark rulings, and speculative analysis on the future of EU data protection law.
Speculative analysis on the most likely changes to EU data protection law through 2028 — AI enforcement, US-EU decoupling, and LLM compliance.
With EDPB guidelines confirming web scraping for AI training requires a lawful basis, coordinated enforcement against major LLM providers is expected across EU jurisdictions.
The Trump administration's dismantling of privacy safeguards is pushing the EU from adequacy thinking toward cloud sovereignty mandates. Major institutions are already migrating from US providers.
NOYB has filed a CJEU lawsuit to annul the EU–US Data Privacy Framework. With FTC independence eliminated and PCLOB paralysed, invalidation appears increasingly inevitable.
Recent GDPR enforcement actions, policy developments, and landmark decisions. Last updated: 22 August 2026.
All AI Act provisions are now enforceable, including requirements for high-risk AI systems. Prohibited practices face fines up to €35M or 7% of global turnover. GPAI providers including LLM companies face active supervision.
New EDPB guidelines confirm web scraping for LLM training requires a lawful basis, and that AI models are not automatically anonymous. Extraction attacks and memorisation risks must be assessed.
NOYB has filed a CJEU lawsuit arguing the DPF's legal foundations have collapsed after the US Supreme Court's FTC ruling and PCLOB paralysis. "Schrems III" has formally begun.
The biggest GDPR enforcement actions since 2018, totalling over €5 billion.
Irish DPC. Unlawful data transfers to the US without adequate safeguards.
Irish DPC. Unlawful processing of personal data through the MoPub advertising network.
Irish DPC. Data transfers to China without adequate safeguards; storage of EU data on Chinese servers.