Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
34 articles found · #edpb
French Supreme Court (Mar 18, 2026) — Geolocation and working time
The French Supreme Court allows geolocation to measure working time if no other objective, reliable and accessible means exists and employees lack freedom to organize their time. Luxembourg focus: legal basis, necessity, DPIA.
Web scraping to train AI: ICO opens, EDPB tightens
The ICO considers legitimate interests a practicable basis for AI training via web scraping, subject to strict tests and transparency. The EDPB narrows this, stressing Article 14 notice and the constraints of Article 9.
Workplace video surveillance: Garante fine and lessons for Luxembourg
Italy’s Garante fined a shop €2,000 for video surveillance without notice or labor authorization. In Luxembourg, L.261‑1, two‑layer notice and short retention are mandatory.
Art. 28 GDPR: Garante fines Velletri over sub-processing chain
On 12 Feb 2026, the Italian Garante fined Velletri Servizi for non‑compliant sub‑processing contracts under Art. 28(4) GDPR and insufficient oversight. Key takeaway: document and audit the entire sub‑processing chain.
Data transfers outside the EU: EDPB vs ICO — essential equivalence or risk test?
On 15 Jan 2026, the ICO introduced a simplified three‑step test and TRA, diverging from the EDPB/CNPD’s ‘essential equivalence’ plus supplementary measures approach. Bottom line: distinct compliance tracks for EU vs UK transfers.
UL: €98,000 for late notification — what Article 33 really requires
Ireland’s DPC fined the University of Limerick for three late GDPR notifications. Here is how to meet Article 33 and notify the CNPD within 72 hours, with documented timing and solid content.
C‑97/23 P — Binding decisions of the EDPB are challengeable
The CJEU allows direct actions against an EDPB binding decision (WhatsApp v EDPB, 10/02/2026). Bottom line: intra‑group data sharing must be documented and defensible before the EU courts.
Right of access to call recordings: the Vodafone (GR) case, 2026
On 11 February 2026, the Hellenic DPA fined Vodafone-Panafon for obstructing access rights and breaching GDPR Articles 12, 15 and 18. Key takeaway: deliver a usable copy of recordings within one month.
Cookies: EDPB orders Belgian DPA to decide the merits in the VRT case
On 14 July 2026, the EDPB ordered the Belgian DPA to rule on the merits of NOYB’s complaint against VRT’s cookie banner, rejecting the abuse-of-rights argument. A signal for CNPD oversight and consent practices in Luxembourg.
EU–US DPF: CNPD/EDPB cautious, ICO ‘data bridge’ more flexible
The DPF offers a secure lane to certified US recipients in the EU, while the UK ‘data bridge’ further streamlines UK-to-US flows. Outside the DPF, SCC/BCR + TIA remain required per CNPD/EDPB guidance.
EDPB: Guidelines on Anonymisation and AI Web Scraping
On 8 July 2026, the EDPB adopted draft guidelines on anonymisation and on web scraping in the context of generative AI for public consultation. Consultation open until 30 October 2026.
AML/CFT information sharing: EDPB and AMLA to issue joint guidelines
The EDPB and AMLA announced joint guidelines on information‑sharing partnerships under AMLR Article 75, applicable from 10 July 2027. Goal: a GDPR‑compatible data‑sharing framework for AML/CFT.