Skip to content

News

Current events, updates, and developments in data protection law

59 Posts
12 Topics
Feb 23 Latest

Hungary’s election battle mixes AI smears with Facebook ‘fight club’

Orbán-linked AI deepfakes flood social media despite EU attempts to boost transparency of Facebook ad ban

Article 13 GDPR

Contact details: typo The controller's contact details are necessary for the data subjects to get in touch with the controller and to further exercise their rights under the GDPR. The contact details must enable data subjects to easily contact the controller and should include different forms of communications.The controller's contact details are necessary for the data subjects to get in touch with the controller and to further exercise their rights under the GDPR. The contact details

European Commission’s plans will lead to worse regulations

EDRi is deeply concerned that the European Commission’s current plans to amend the Better Regulation framework will lead to worse lawmaking, not better. In its submission to the Commission, EDRi shares recommendations to ensure balanced representation, fairness, transparency, and meaningful safeguards in EU lawmaking. The post European Commission’s plans will lead to worse regulations appeared first on European Digital Rights (EDRi).

Commission opens probe of Shein after ‘child-like’ sex doll scandal

The Commission will investigate Shein over concerns about illegal products, addictive features and recommender transparency under the Digital Services Act

VDAI (Lithuania) - Nr. 3R-219 (2.13-1.E)

}}}} The DPA partially upheld a complaint and issued a reprimand against a travel company for unlawful direct marketing, excessive passport copy collection, inaccuracies in travel documents, lack of transparency, and an incomplete access response.The DPA partially upheld a complaint and issued a reprimand against a travel company for unlawful direct marketing, excessive passport copy collection, inaccuracies in travel documents, lack of transparency, and an incomplete response to an access reque

AI Omnibus: Reject the proposals to undermine transparency in the AI Act

The European Commission’s dangerous and misguided Digital Omnibus proposal includes a dangerous rollback of transparency requirements in the AI Act. 60 civil society organisations, independent public authorities and individuals, including EDRi, urge EU lawmakers to reject a change that would risk weakening enforcement, legal certainty, and the protection of fundamental rights, while offering negligible benefits for companies. The post AI Omnibus: Reject the proposals to undermine transparency in

A call to EU legislators: protect rights and reject the call to delete transparency safeguard in AI Act

We, the undersigned organisations and individuals, urge you in the strongest possible terms to reject the deletion of the Article 49(2) transparency safeguard for high-risk AI systems that is proposed in the AI Omnibus. This transparency safeguard ensures that providers of AI systems cannot circumvent the core obligations of the AI Act. The post A call to EU legislators: protect rights and reject the call to delete transparency safeguard in AI Act appeared first on Access Now.

Stakeholder event on political advertising: express your interest

Brussels, 29 January - The EDPB organises a remote event to collect stakeholders’ input on its Guidelines on the processing of personal data to target or deliver political advertisements under the regulation on the transparency and targeting of political advertising. The event will take place on 27 March 2026 (time to be confirmed). This will be an opportunity to inform and support the EDPB’s ongoing work on this topic as per its work programme 2024-2025 and it reflects the EDPB’s commitment to

TikTok makes ad transparency commitments to comply with EU DSA

The European Commission says that TikTok has agreed to provide advertising repositories in which data is stored and managed to ensure full transparency around ads on its services, as required by the Digital Services Act

USR - Referentienummer I-755/2025-8

Fixed Link: Hij beweerde later, tijdens de rechtszaak tegen de beslissing van AZOP, dat de autoriteit de feiten onjuist en onvolledig had vastgesteld, het materiële recht verkeerd had toegepast en de procedurele regels had geschonden. Hij benadrukte dat de gepubliceerde persoonlijke gegevens geen verband hadden met transparantie in de overheidsadministratie, dat hij noch een publiek figuur noch een politieke acteur was, en dat elk algemeen belang ophield zodra hij op 31 maart 2023 zijn functie had verlaten. Hij beroepte zich op zijn recht op verwijdering, zoals vastgelegd in [[Artikel...]].

CNIL (France) - SAN-2025-015

=== Holding ====== Holding === The dispute related to the processor’s responsibility for implementing adequate security measures, under article 32 GDPR. The dispute related to the processor’s responsibility for implementing adequate security measures, under Article 32 GDPR. '''On the fairness of the procedure:''' '''On the fairness of the procedure:''' '''About responsibilities:''' '''About r

USR - Us I-755/2025-8

Fixed Link He latter further claimed during the lawsuit against AZOP's decision that the authority had incorrectly and incompletely established the facts, misapplied substantive law, and breached procedural rules. He emphasized that the published personal data was unrelated to transparency in public administration, that he was neither a public figure nor a political actor, and that any public interest ended once he left office on 31 March 2023. He invoked his right to erasure under [[Articl

#KeepItOn: Iran plunged into digital darkness, concealing human rights abuses

join the international community, including the UN’s Independent International Fact-Finding Mission, in calling on Iran to immediately restore internet and mobile communications and in demanding accountability and transparency for the grave human rights violations documented in the country The post #KeepItOn: Iran plunged into digital darkness, concealing human rights abuses appeared first on Access Now.

CNIL (France) - SAN-2025-015

Fixed link: "Regarding the fairness of the procedure:" "Regarding the fairness of the procedure:" Initially, the data protection authority (DPA) rejected this argument based on a violation of Article 6 of the European Convention on Human Rights (ECHR). The DPA pointed out that the right not to be required to prove someone's guilt does not conflict with the sharing of internal reports from the complainant, even under coercive measures. Furthermore, the publicly available reports constitute evidence upon which the DPA can base its reasoning. Initially,

USR - Reference number I-755/2025-8

Fixed Link: He later claimed, during the legal proceedings against the AZOP decision, that the authority had incorrectly and incompletely established the facts, had misapplied the relevant law, and had violated procedural rules. He emphasized that the published personal data were not related to transparency in government administration, that he was neither a public figure nor a political actor, and that any public interest ceased once he left his position on March 31, 2023. He invoked his right to erasure, as stipulated in [[Article...]].

CNIL (France) - SAN-2025-015

=== Processing ====== Processing === The dispute concerned the processor's responsibility for implementing adequate security measures, as required by Article 32 of the GDPR. The dispute concerned the processor's responsibility for implementing adequate security measures, as required by Article 32 of the GDPR. "Regarding the fairness of the procedure:" "Regarding the fairness of the procedure:" "Regarding responsibilities:" "Regarding responsibilities:"

CNIL (France) - SAN-2025-015

Fixed Link '''On the fairness of the procedure:''' '''On the fairness of the procedure:''' At first, the DPA rejected the argument based on a violation of [[article 6 ECHR]]. The DPA pointed out that the right not to incriminate oneself is not incompatible with the sharing of the complainant’s internal reports, even under coercive measures. What’s more, the disclosed reports are evidence on which the DPA can base its argument. At first,

VDAI (Lithuania) - Decision No. 3R-1700

Facts }}}} The DPA held that a gambling operator lawfully transferred data to a processor for sending invitations to sporting events, but found that the controller breached transparency obligations by not informing the data subject about the categories of data recipients.The DPA held that the operator of a gambling site lawfully transferred data to a processor for sending invitations to sporting events since the engagement of a processor does not require a separate legal basis. However, the cour

VDAI (Litouwen) - Besluit nr. 3R-1700.

Feiten: De gegevensbeschermingsautoriteit (DPA) oordeelde dat een aanbieder van kansspelen gegevens op rechtmatige wijze heeft overgedragen aan een verwerker voor het versturen van uitnodigingen voor sportevenementen, maar vond dat de verantwoordelijke partij haar transparantieplicht had geschonden doordat ze de betrokkene niet had geïnformeerd over de categorieën van ontvangers van de gegevens. De DPA oordeelde dat de exploitant van een kansspelwebsite gegevens op rechtmatige wijze heeft overgedragen aan een verwerker voor het versturen van uitnodigingen voor sportevenementen, aangezien het inschakelen van een verwerker geen aparte juridische basis vereist. Echter, het gerecht...

VDAI (Lithuania) - Decision No. 3R-1700.

Facts: The data protection authority (DPA) ruled that a gambling operator had lawfully transferred data to a processor for the purpose of sending invitations to sporting events, but found that the responsible party had violated its transparency obligations by failing to inform the data subject about the categories of recipients of the data. The DPA also ruled that the operator of a gambling website had lawfully transferred data to a processor for the purpose of sending invitations to sporting events, as the engagement of a processor does not require a separate legal basis. However, the court...

MTN Group must answer for dangerous bounty SMS campaign in the Republic of Congo

Access Now,together with several human rights organizations, are calling on MTN Group to protect mobile service subscribers and ensure transparency and accountability for data breaches perpetuated by their subsidiaries in the Republic of Congo. The post MTN Group must answer for dangerous bounty SMS campaign in the Republic of Congo appeared first on Access Now.

Migrant smuggling laws: European Commission found in breach of transparency rules

The European Ombudsman has found that the Commission disregarded important transparency rules while preparing the Europol Regulation, which is a part of the legislation to "counter migrant smuggling". The inquiry concluded that the Commission didn't provide enough evidence to justify the claims of "urgency" to bypass their own 'Better Regulation' rules, and skipping public consultations, thorough impact assessments and evidence gathering. The post Migrant smuggling laws: European Commission foun

Wetten inzake het smokkelen van migranten: De Europese Commissie heeft regels inzake transparantie overtreden.

De Europese Ombudsman heeft vastgesteld dat de Europese Commissie belangrijke transparantiewetten negeerde bij de voorbereiding van de Europol-verordening, die deel uitmaakt van de wetgeving om "menselijke smokkel van migranten" tegen te gaan. Het onderzoek concludeerde dat de Commissie niet voldoende bewijs leverde om de beweringen van "urgentie" te rechtvaardigen, waarmee ze hun eigen regels voor "betere regelgeving" omzeilden, evenals openbare consultaties, grondige impactanalyses en het verzamelen van bewijs. Artikel: Wetgeving tegen menselijke smokkel van migranten: De Europese Commissie...

Laws regarding the smuggling of migrants: The European Commission has violated rules regarding transparency.

The European Ombudsman has found that the European Commission disregarded important transparency laws during the preparation of the Europol regulation, which is part of the legislation aimed at combating "human smuggling of migrants." The investigation concluded that the Commission did not provide sufficient evidence to justify its claims of "urgency," thereby circumventing its own rules for "better regulation," as well as public consultations, thorough impact assessments, and the gathering of evidence. Article: Legislation against human smuggling of migrants: The European Commission...

Gecoördineerd handhavingskader: Het EDPB selecteert een onderwerp voor 2026.

Brussel, 14 oktober - Tijdens de plenaire vergadering van oktober heeft het Europees Comité voor de bescherming van de persoonlijke levenssfeer (EDPB) het onderwerp gekozen voor zijn vijfde gecoördineerde handhavingsactie. Deze actie zal betrekking hebben op de naleving van de verplichtingen met betrekking tot transparantie en informatieverstrek onder de Algemene Verordening Gegevensbescherming (AVG). De AVG zorgt ervoor dat individuen worden geïnformeerd wanneer hun gegevens worden verwerkt (zoals vastgelegd in artikel 12, 13 en 14). Dit recht op informatie is een essentieel onderdeel van transparantie en zorgt ervoor dat individuen meer...

Coordinated Enforcement Framework: EDPB selects topic for 2026

Brussels, 14 October - During its October plenary, the European Data Protection Board (EDPB) picked the topic for its fifth coordinated enforcement action, which will concern compliance with the obligations of transparency and information under the General Data Protection Regulation (GDPR). The GDPR ensures that individuals are informed when their data is being processed (under Art. 12, 13 and 14). This right to be informed is a core element of transparency and ensures that individuals have more

Coordinated enforcement framework: The European Data Protection Board will select a topic for enforcement action in 2026.

Brussels, October 14th - During its plenary meeting in October, the European Data Protection Board (EDPB) selected the topic for its fifth coordinated enforcement action. This action will focus on compliance with the obligations regarding transparency and information provision under the General Data Protection Regulation (GDPR). The GDPR ensures that individuals are informed when their data is being processed (as stipulated in Articles 12, 13, and 14). This right to information is a crucial element of transparency and ensures that individuals have more...

report

Government.

The purpose of this study was to assess the transparency of personal data in thirteen specific public registers in relation to European data protection law, and to identify privacy-enhancing measures that could bring these registers into compliance with the regulations or prepare them for future developments...

Wet op de politieke partijen

Legislation

Kamerstukken II, 36742, nr. 3. Regels betreffende de financiering van politieke partijen en transparantieregels met betrekking tot hun interne organisatie en financiën, evenals regels met betrekking tot het toezicht en het verbieden van politieke partijen (Wet op de politieke partijen). Zie uitge...

Law on Political Parties.

Legislation.

Chamber Documents II, 36742, No. 3. Rules concerning the financing of political parties and transparency regulations regarding their internal organization and finances, as well as rules concerning the supervision and prohibition of political parties (Political Parties Act). See details in...

In short:

Government.

"In terms of information management (including digital accessibility, document transparency, and GDPR compliance), the staffing levels are a major bottleneck, and have not kept pace with the rest of the organization. The CvTE (presumably an organization) must comply with all laws and regulations applicable to government bodies, and there is a risk that it will not be able to do so..."

Statement from the listed authors of Stochastic Parrots on the “AI pause” letter

> The harms from so-called AI are real and present and follow from the acts of people and corporations deploying automated systems. Regulatory efforts should focus on transparency, accountability and preventing exploitative labor practices. By Angelina McMillan-Major, Emily M. Bender, Margaret Mitchell and Timnit Gebru for DAIR on March 31, 2023

Verklaring van de auteurs van het artikel "Stochastic Parrots" over de brief waarin een "pauze in de ontwikkeling van AI" wordt bepleit.

De schadelijke gevolgen van zogenaamde kunstmatige intelligentie zijn reëel en actueel, en zijn het gevolg van de handelingen van mensen en bedrijven die geautomatiseerde systemen inzetten. Regulatoire inspanningen moeten zich richten op transparantie, verantwoordelijkheid en het voorkomen van uitbuitende arbeidspraktijken. Geschreven door Angelina McMillan-Major, Emily M. Bender, Margaret Mitchell en Timnit Gebru voor DAIR op 31 maart 2023.

Artificial intelligence: the action plan of the CNIL

The main thing is: The CNIL has been undertaking work for several years to anticipate and respond to the issues raised by AI. In 2023, it will extend its action on augmented cameras and wishes to expand its work to generative AIs, large language models and derived applications (especially chatbots). Its action plan is structured around four strands: to understand the functioning of AI systems and their impact on people; enabling and guiding the development of privacy-friendly AI; federate and

Uber-chauffeurs vragen toegang tot persoonlijke gegevens en transparantie over geautomatiseerde besluitvorming: een balans tussen privacy en passagiersveiligheid.

Verzoek van Uber-chauffeurs aan Uber voor toegang tot bepaalde persoonsgegevens die betrekking hebben op hen (waaronder "beoordelingen" gegeven door passagiers), zoals bedoeld in artikel 15 lid 1 AVG, en voor informatie zoals bedoeld in artikel 15 lid 1 onder h AVG (informatie over het bestaan van geautomatiseerde besluitvorming in de zin van artikel 22 AVG). Bescherming van de persoonsgegevens van passagiers. Is adapti...

Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems?

> The growth of generative artificial intelligence systems has led EU lawmakers to focus on General Purpose AI in drafting the AI Act, which will set the framework governing artificial intelligence in the European Union. As previously reported, the EU Parliament has already broadened the definition of artificial intelligence for the purposes of the AI Act… The post Is the AI Act caging ChatGPT and other General Purpose Artificial Intelligence systems? appeared first on GamingTechLaw.

Unprecedented appearance by European Commissioner for Home Affairs, innovating on quicksand, and the cabinet vs. online confidentiality

> Read through the most interesting developments at the intersection of human rights and technology from the Netherlands. This is the second update in this series.

Court rules on Experian appeal of ICO enforcement notice

> The First-Tier Tribunal overturned portions of a 2020 enforcement notice by the U.K. Information Commissioner's Office against Experian, confirming the company's reliance on legitimate interests as a legal basis for processing credit reference agency information for direct marketing purposes. Deputy Commissioner Stephen Bonner, CIPP/E, CIPM, said marketing processes "must happen in line with the law and in an open and honest way" and the ICO noted it will consider an app

De rechtbank heeft uitspraak gedaan in het beroep van Experian tegen de handhavingsmaatregel van de ICO (Information Commissioner's Office).

Het eerste beroepstribunaal heeft delen van een handhavingsbesluit uit 2020 van het Britse Information Commissioner's Office (ICO) tegen Experian vernietigd. Hierin werd bevestigd dat het bedrijf zich terecht baseert op legitieme belangen als juridische basis voor het verwerken van informatie van kredietreferentiebureaus voor direct marketingdoeleinden. Waarnemend commissaris Stephen Bonner, CIPP/E, CIPM, zei dat marketingprocessen "in overeenstemming met de wet en op een open en eerlijke manier moeten plaatsvinden", en het ICO heeft aangegeven dat het een app zal overwegen.

Fairness perceptions of algorithmic decision-making: A systematic review of the empirical literature

> Algorithmic decision-making increasingly shapes people's daily lives. Given that such autonomous systems can cause severe harm to individuals and social groups, fairness concerns have arisen. A human-centric approach demanded by scholars and policymakers requires considering people's fairness perceptions when designing and implementing algorithmic decision-making. We provide a comprehensive, systematic literature review synthesizing the existing empirical insights on perceptions of algorithmic

Overview of EU Strategy for Data: Digital Services Act

> The Digital Services Act was published in the Official Journal of the European Union Oct. 27. The DSA, which harmonizes conditions for the provision of intermediary services and increases transparency requirements for online intermediaries, will enter into force Nov. 16. In the latest installment of a multipart series, the IAPP Research and Insights team provides privacy professionals with an overview of the DSA, including the law's objectives, key requirements and enforcement.

Overzicht van de EU-strategie voor data: de Digital Services Act.

De Digital Services Act is op 27 oktober gepubliceerd in het Publicatieblad van de Europese Unie. De DSA, die de voorwaarden voor de aanbieding van intermediaire diensten harmoniseert en de transparantie-eisen voor online intermediairs verhoogt, treedt op 16 november in werking. In het nieuwste deel van een reeks artikelen biedt het onderzoeksteam van de IAPP professionals op het gebied van privacy een overzicht van de DSA, inclusief de doelstellingen, de belangrijkste vereisten en de handhaving van de wet.

Aanbevelingssystemen waarop u kunt vertrouwen: Een juridisch en empirisch perspectief op de transparantie en controle die individuen nodig hebben om nieuwsverpersoonlijking te vertrouwen.

De wet kan een belangrijke rol spelen bij het waarborgen van het vertrouwen in organisaties die gebruikmaken van nieuwsverpersoonlijking. Maatregelen voor controle en transparantie zijn cruciaal om ervoor te zorgen dat individuen deze organisaties kunnen vertrouwen. De huidige focus van de wet, die gericht is op het informeren van individuen en hen in staat stellen om de verpersoonlijking te stoppen, houdt geen rekening met het belang van het mogelijk maken voor individuen om controle te hebben over hoe het nieuws wordt gepersonaliseerd.

Recommenders you can rely on: A legal and empirical perspective on the transparency and control individuals require to trust news personalisation

Law can play an important role in safeguarding trust in organisations that use news personalisation. Control and transparency measures are crucial to enabling individuals to trust these organisations. The law’s current focus on informing individuals about and empowering them to stop personalisation does not account for the importance of enabling individuals to control how news is personalised.

Garante onderzoekt het gebruik van "cookie walls".

De Garante (de Italiaanse Autoriteit voor de bescherming van persoonsgegevens) merkt op dat de Europese wetgeving inzake de bescherming van persoonsgegevens in principe niet verhindert dat de eigenaar van een website de toegang tot content voor gebruikers afhankelijk maakt van hun toestemming voor het verzamelen van gegevens voor profilering (via cookies of andere trackingtools), of, als alternatief, van het betalen van een bedrag. Dit verwijst naar de initiatieven die de afgelopen dagen zijn genomen door verschillende online kranten, websites en bedrijven die actief zijn op internet.

De Griekse toezichthouder heeft Clearview AI een boete van 20 miljoen euro opgelegd.

Een overzicht van de boete die aan IAPP is opgelegd: https://iapp.org/news/a/a-rundown-of-the-greek-dpas-clearview-ai-fine-findings

Greek SA fines Clearview AI for EUR 20M

A rundown of the fine on IAPP: https://iapp.org/news/a/a-rundown-of-the-greek-dpas-clearview-ai-fine-findings

De ICO publiceert een conceptrichtlijn over het monitoren van werknemers ter beoordeling.

Op 14 oktober 2022 heeft de Federal Trade Commission aangekondigd dat de deadline voor het indienen van commentaren op haar voorlopige voorstel voor regelgeving over commerciële surveillance en inadequate databeveiligingspraktijken met een maand wordt verlengd.

TikTok faces potential 27M GBP fine from ICO

> The U.K. Information Commissioner's Office announced a notice of intent to fine TikTok 27 million GBP for alleged U.K. data protection violations. The ICO's investigation found potential violations concerning nonconsensual processing of minors' data, unlawful processing of special category data and insufficient transparency.

TikTok staat mogelijk een boete van 27 miljoen Britse pond te wachten van de ICO (Information Commissioner's Office).

Het Britse Information Commissioner's Office heeft aangekondigd dat TikTok een boete van 27 miljoen pond zal krijgen vanwege vermeende schendingen van de Britse wetgeving inzake gegevensbescherming. Het onderzoek van de ICO heeft mogelijke overtredingen blootgelegd met betrekking tot de verwerking van gegevens van minderjarigen zonder toestemming, de onrechtmatige verwerking van speciale categorieën van gegevens en een ontoereikend niveau van transparantie.