NOYB Warns SCHUFA Over "Shadow Database" — Opens Class Action Interest List
NOYB issued a formal warning to SCHUFA, Germany's largest credit agency, over an alleged secret shadow database used for credit scoring. NOYB has opened an interest list for a potential class action challenging the practice under GDPR's automated decision-making and transparency requirements.
EU AI Act Reaches Full Application — Prohibited AI Practices Now Enforceable
All AI Act provisions are now enforceable including requirements for high-risk AI systems. Prohibited practices face fines up to €35M or 7% of global turnover. The EU AI Office is actively supervising GPAI providers including major LLM companies.
EDPB Issues Guidelines on Anonymisation and Web Scraping for Generative AI
New guidelines confirm web scraping for LLM training requires a lawful basis, and that AI models are not automatically anonymous. Extraction attacks and memorisation risks must be assessed.
EU Moves Toward Cloud Sovereignty as US-EU Digital Tensions Escalate
The Commission advanced data sovereignty proposals, with Member States pushing for EU cloud infrastructure mandates for sensitive public sector data. Several major EU institutions have already begun migrating from US cloud services.
NOYB Files Formal Lawsuit to Annul EU–US Data Privacy Framework
NOYB filed a CJEU lawsuit arguing the DPF's legal foundations have collapsed after the US Supreme Court's FTC ruling and PCLOB paralysis. Max Schrems called on the Commission to "orderly withdraw" the adequacy decision. "Schrems III" has formally begun.
NOYB Files Complaint Against dict.cc Over 1,741 Consent Requests in One Click
NOYB challenged dict.cc for bundling 1,741 ad-tech partner consent requests into a single click — arguing it violates the specificity and informed consent requirements of GDPR Articles 4(11) and 7.
EDPB Develops Guidelines on Interplay Between Data Protection and Competition Law
Draft guidelines address how GDPR and EU competition law interact — clarifying when competition authorities can share information with DPAs, and how data protection violations can constitute abuse of dominance.
EDPB Requires Belgian DPA to Handle NOYB Cookie Banner Complaint
The EDPB intervened to require the Belgian DPA to substantively address a NOYB complaint about cookie banners, reinforcing that DPAs must act on well-founded complaints in a timely manner.
EDPB and AMLA to Develop Joint Guidelines on Information Sharing
The EDPB and Anti-Money Laundering Authority announced a collaboration on joint guidelines addressing how data protection and AML frameworks interact regarding personal data exchange.
Irish DPC Publishes 2025 Annual Report and "Sharenting" Survey
The DPC released its 2025 Annual Report alongside a survey on "sharenting" — parents sharing children's personal data online. The report details the DPC's enforcement activities and strategic priorities.
US Supreme Court Ruling on FTC Threatens EU–US Data Privacy Framework
The US Supreme Court ruled the FTC may no longer operate independently, raising serious questions about the DPF. Privacy advocates flagged this as a potential trigger for "Schrems III."
EDPB Adopts Common Data Breach Notification Template
A standardised breach notification template aims to harmonise reporting across the EU/EEA, reducing administrative burden while ensuring consistent information reaches supervisory authorities.
DPC Concludes Inquiry into Hospital Ransomware Attack
Ireland's DPC issued a final decision on the Midlands Regional Hospital Tullamore ransomware attack, addressing the hospital's technical measures and breach response obligations.
NOYB Files Class Action Against CRIF for Discriminatory Credit Scoring
NOYB filed an injunction and class action against CRIF, an Austrian credit agency, over discriminatory credit scoring without proper transparency — violating automated decision-making requirements under Article 22.
EU Member States Block Cookie Banner Elimination Proposal
EU Member States opposed the Commission's proposal to eliminate cookie banners via browser-level consent signals. Cookie banners will remain a feature of European web browsing for the foreseeable future.
Schibsted "Pay or Okay" Model Challenged by NOYB
NOYB and the Norwegian Consumer Council challenged Schibsted's model forcing users to pay or consent to tracking, arguing it does not constitute freely given consent under GDPR Article 7.
ORF.at Cookie Banner Ruled Non-Compliant
NOYB secured a ruling that ORF.at's cookie banner did not meet GDPR consent requirements and must be corrected, in a case targeting Austria's public broadcaster.
Irish DPC Opens Inquiry into SHEIN Ireland
Ireland's DPC opened a formal inquiry into SHEIN Ireland under section 110, examining the fast-fashion platform's data processing practices affecting EU/EEA users.
NOYB Files Complaint Over LinkedIn Locking GDPR Rights Behind Paywall
NOYB filed a complaint alleging LinkedIn locks GDPR data access rights behind a premium paywall, targeting the Microsoft subsidiary via the Austrian DPA.
DPC Publishes Decision on Permanent TSB Data Breaches
The DPC concluded its inquiry into personal data breaches at Permanent TSB, addressing the bank's handling of breach notifications and technical measures.
NOYB Sues Hamburg DPA for Inaction Against PimEyes
NOYB sued the Hamburg DPA for failing to act against facial recognition service PimEyes, whose practices the DPA itself considered illegal but had not enforced against.
NOYB Study: 83.5% of Access Requests Not Properly Answered
NOYB published research showing the vast majority of GDPR access requests go unanswered or are improperly handled, raising concerns about the proposed Digital Omnibus regulation's effectiveness.
Criteo €40M Fine Upheld by France's Highest Administrative Court
France's Conseil d'État upheld CNIL's €40 million fine against Criteo, Europe's largest ad-tech tracker. The case was brought by NOYB and Privacy International over tracking without valid consent.
EDPB Launches CEF 2026 on Transparency Obligations
Coordinated Enforcement Framework 2026 focuses on transparency and information obligations — national authorities will run aligned checks on how clearly organisations explain data processing.
NOYB Critique: GDPR Omnibus Simplification "Far From Real Business Needs"
NOYB published analysis arguing the EU's proposed GDPR simplification is disconnected from real business needs, with survey results contradicting the Commission's approach.
DPC Publishes Decision on University of Limerick Data Breaches
The DPC published its final decision following an own-volition inquiry into UL concerning a series of personal data breaches that occurred between November 2018 and January 2020.
Irish DPC Opens Inquiry into X over Grok AI Images
Ireland's DPC opened a section 110 inquiry into X over Grok AI's alleged generation of non-consensual intimate and sexualised images of real people, including children.
Google Fined €325 Million by CNIL for Gmail Spam
France's CNIL fined Google €325 million for sending unsolicited promotional emails to Gmail users without valid consent. The case was brought by NOYB.
TikTok Fined €530 Million for Data Transfers to China
Ireland's DPC fined TikTok €530M for transferring EU users' data to China without adequate safeguards. TikTok was found to have stored some EU data on Chinese servers contrary to earlier representations.
LinkedIn Fined €310 Million by Irish DPC
Ireland's DPC fined LinkedIn €310M for unlawfully processing personal data for targeted advertising using invalid legal bases including legitimate interests and consent.
X (Twitter) Fined €550 Million by Irish DPC
Ireland's DPC fined X Corp €550M for unlawful processing of personal data for advertising through the MoPub ad network, including inferred political opinions and sexual orientation.
Uber Fined €290 Million by Dutch DPA for US Data Transfers
The Dutch AP fined Uber €290M for transferring European drivers' personal data to the US without adequate safeguards, reinforcing robust supplementary measures requirements post-Schrems II.
EU AI Act Enters Into Force
The world's first comprehensive AI regulation entered into force, creating obligations that interact directly with GDPR for AI systems processing personal data. Full application began August 2026.
Meta Fined €1.2 Billion — Record GDPR Penalty
The Irish DPC issued the largest GDPR fine in history against Meta for transferring personal data to the US without adequate safeguards following Schrems II.
EU–US Data Privacy Framework Adopted
The Commission's adequacy decision provided a legal basis for transatlantic data flows to certified US companies, introducing a Data Protection Review Court as a redress mechanism.
EDPB Establishes ChatGPT Task Force
After Italy's Garante temporarily banned ChatGPT, the EDPB established a task force to coordinate a consistent EU-wide approach to large language models and GDPR compliance.
Meta (Instagram) Fined €405M for Children's Data
Ireland's DPC fined Meta €405M for Instagram's failure to protect children's data — including defaulting minor accounts to public visibility and displaying contact details publicly.
Meta (Facebook) Fined €265M for Data Scraping
The Irish DPC fined Meta €265M after 533 million user records scraped via the contact import feature appeared on hacking forums, due to inadequate anti-scraping measures.
New Standard Contractual Clauses Published
Modernised SCCs for international data transfers replaced outdated versions with a modular structure covering multiple transfer scenarios and incorporating Transfer Impact Assessment requirements.