Free Tools
Paid Assessments
Learn
Pricing
News
Compliance
Sign in
Regulatory Intelligence

EU Regulatory News

What's changed across CSRD, GDPR, EU AI Act, DMA, and EU Taxonomy, and what it means for your business.

EU e-Evidence Regulation Applies From 18 August: Direct Court Orders Now Enforceable Against Service Providers

From 18 August 2026, Regulation (EU) 2023/1543 is fully applicable across all EU Member States. Judges and prosecutors can now issue European Production Orders directly to cloud, hosting, messaging, and email providers - wherever they are headquartered - requiring disclosure of user data within 10 days. Service providers with EU users were required to have a designated contact point in place by this date.

What changed

Regulation (EU) 2023/1543 on European Production Orders for Electronic Evidence became fully applicable on 18 August 2026. The Regulation replaces the Mutual Legal Assistance Treaty process, which was the primary mechanism for cross-border law enforcement access to digital evidence and typically took 12 to 18 months per request. Under the new framework, judges and prosecutors in any EU Member State can now issue a European Production Order (EPO) or European Preservation Order (EPPO) directly to any provider of electronic communications, hosting, messaging, domain-name, or IP-address services that has users in the EU - regardless of where the company is established. EPOs require the provider to disclose specified data (subscriber data, access data, transaction data, or content data) within 10 days as a standard deadline, or within 8 hours in emergency cases. Service providers operating in the EU on or before 18 February 2026 were required to designate a contact point in an EU Member State by 18 August 2026. The designated contact point is responsible for receiving, assessing, and executing or challenging production and preservation orders. Content data orders are subject to a higher threshold: they require judicial certification in the issuing state confirming the order is necessary and proportionate. The Regulation interacts directly with the GDPR: service providers may challenge or refuse execution of an EPO where compliance would conflict with applicable EU or Member State law, including the GDPR.

The companion Directive (EU) 2023/1544, requiring Member States to designate national executing authorities and create an enforcement framework for EPOs and EPPOs, applied from 18 February 2026. Non-compliance with a valid EPO can result in financial penalties under national implementing law. The Regulation was designed to address the use of cloud and cross-border digital infrastructure in criminal investigations, but its scope is broad: any company offering email, messaging, cloud storage, web hosting, domain-name registration, VoIP, or IP-address services to users in the EU falls within scope if it receives an EPO or EPPO. The BfDI (Federal Commissioner for Data Protection and Freedom of Information, Germany) maintains a dedicated topic page on the e-Evidence Regulation, noting its interaction with data protection obligations. The ePrivacy Directive 2002/58/EC is one of the instruments the Regulation explicitly derogates from in the law enforcement access context, placing the e-Evidence framework within the broader EU privacy and digital law landscape.

What it means for your business

If your company offers electronic communications, hosting, messaging, email, VoIP, domain-name registration, or IP-address services to users in the EU: The e-Evidence Regulation now applies. If your company was operating before 18 February 2026, your EU-designated contact point should already be in place as of 18 August 2026. If you have not yet designated a contact point, do so immediately and notify the competent national authority. Establish internal procedures for receiving, logging, and responding to EPOs and EPPOs, including the standard 10-day and emergency 8-hour execution deadlines. For content data orders: Build a legal review step into your response workflow - content data EPOs require judicial certification from the issuing state, and you may challenge orders that conflict with GDPR obligations or are otherwise unlawful. For data minimisation and retention: Review your GDPR data minimisation and retention policies in light of the obligation to disclose data on receipt of a valid EPO: data you do not hold cannot be disclosed. Assess your GDPR obligations with Verdaio\'s GDPR Quick Check.

France Requires Prior Opt-In Consent for Consumer Telemarketing From 11 August 2026

On 11 August 2026, Law n° 2025-594 of 30 June 2025 and its implementing Decree n° 2026-662 of 23 July 2026 entered into force in France, replacing the Bloctel opt-out register with a prior opt-in consent requirement for all business-to-consumer telephone marketing. Under the amended Article L223-1 of the French Consumer Code, companies must obtain consumers' express prior consent before making unsolicited commercial telephone calls. Fines under Article L242-11 reach EUR 375,000 per call for companies and EUR 75,000 per call for individuals. The CNIL enforces GDPR consent quality; the DGCCRF enforces the Consumer Code.

What changed

On 11 August 2026, France's new telephone marketing consent framework entered into force following the publication and implementation of two legislative instruments. Law n° 2025-594 of 30 June 2025 (published in the Journal Officiel on 1 July 2025) amended Article L223-1 of the French Consumer Code (Code de la consommation) to replace the existing Bloctel opt-out register with a requirement for prior opt-in consent from consumers before any unsolicited commercial telephone contact. Decree n° 2026-662 of 23 July 2026 (published in the Journal Officiel on 24 July 2026) set the framework's entry-into-force date as 11 August 2026 and established the technical and procedural requirements for the consent mechanism. Under the reformed Article L223-1, a professional making unsolicited commercial telephone calls to consumers must obtain the consumer's prior express consent before making the call. The consent must be freely given, specific, informed, and unambiguous, consistent with the standard applied under GDPR Article 7. The Bloctel register, which consumers had used since 2016 to opt out of receiving unsolicited marketing calls, was abolished by the 2025 Law as the primary mechanism for consumer protection in telephone marketing. The new regime applies to B2C calls: calls to a consumer (a natural person acting outside their professional capacity) for commercial prospecting purposes require prior consent. The B2B context is not covered by Article L223-1 as amended: calls made to a professional in connection with their professional role remain subject to the legitimate interest basis under GDPR and to sector-specific rules, not to the prior consent requirement of the Consumer Code. The CNIL (Commission nationale de l'informatique et des libertés) enforces GDPR consent quality requirements when calls rely on personal data processing: the consent must meet GDPR Article 7 standards (freely given, specific, informed, unambiguous) and must be documented and withdrawable at any time. The DGCCRF (Direction générale de la concurrence, de la consommation et de la répression des fraudes) enforces the Consumer Code obligations.

The penalty provisions under Article L242-11 of the Consumer Code, as updated by the 2025 Law, provide for administrative fines of up to EUR 375,000 per unlawful call for legal persons (companies) and EUR 75,000 per call for natural persons. These fines apply per call, not per campaign or per company, making high-volume telephone prospecting without consent potentially ruinous. The new regime reverses the prior burden: under the Bloctel system, consumers bore responsibility for registering on the opt-out list, and companies bore only the obligation to screen their call lists against it. Under the new regime, companies must affirmatively obtain and document consent before calling. Consent obtained through pre-ticked boxes, bundled agreement with general terms, or other implied means does not satisfy the requirement. Companies that relied on Bloctel compliance as their primary consumer telephone marketing mechanism must now rebuild their outreach architecture around an affirmative consent database, and those that conducted prospecting calls in France in the weeks before 11 August 2026 under the old Bloctel system face a clean compliance cliff on that date. The ePrivacy Directive 2002/58/EC Article 13 already required prior consent for automated calling systems and fax marketing in EU Member States, and many Member States had extended that prior consent requirement to live telephone marketing in national implementation. France's 2025 Law brings French law in line with those stricter national implementations. The alignment with the GDPR's consent standard for data processing purposes means companies seeking French consumer consent for telephone marketing should treat it as part of their broader GDPR consent management architecture, using the same consent collection and management infrastructure that handles email marketing opt-in.

What it means for your business

If you make or commission unsolicited commercial telephone calls to consumers in France: From 11 August 2026, prior express consent is required before each call. The Bloctel opt-out register no longer provides a compliance basis for B2C telephone prospecting in France. Audit your French consumer telephone marketing lists and confirm that each contact entry is backed by documented prior opt-in consent. Calls made without consent carry fines of up to EUR 375,000 per call (companies) under Article L242-11 of the Consumer Code. Purge contacts for which you cannot demonstrate prior consent and implement a consent-at-collection flow for any new French consumer data. If you collect French consumer personal data (including telephone numbers) for marketing purposes: The new telephone marketing consent requirement reinforces the GDPR Article 7 consent standard. Review your consent collection flows to confirm they produce freely given, specific, informed and unambiguous consent that covers telephone contact, are documented in your records of processing activities (Article 30 GDPR), and can be withdrawn by the consumer at any time. Bundled or implied consent does not satisfy either the Consumer Code or GDPR requirements. If you supply CRM, marketing automation, or lead generation services to companies operating in France: Your clients' compliance with the French telephone marketing consent regime depends on the data quality and consent documentation your service provides. Ensure your platform captures and stores the consent basis for each contact, flags contacts without telephone marketing consent, and provides an easy mechanism for clients to filter French consumer contacts to those with documented prior consent. Assess your GDPR consent management posture with Verdaio's GDPR Quick Check.

Netherlands Cyberbeveiligingswet Enters Force: 8,000 Dutch Organisations Now Subject to NIS2 Obligations

On 15 August 2026, the Dutch Cyberbeveiligingswet (Cybersecurity Act) entered into force together with the Wet weerbaarheid kritieke entiteiten (Critical Entities Resilience Act), transposing the NIS2 Directive and the CER Directive into Dutch law. Approximately 8,000 organisations across essential and important sectors must now register with the NCSC, implement risk-based security measures, report significant incidents within 24 hours, and maintain board-level accountability for cybersecurity. The NCSC is designated as the national NIS2 competent authority and central point of contact.

What changed

On 15 August 2026, the Cyberbeveiligingswet (Cbw) and the Wet weerbaarheid kritieke entiteiten (Wwke) entered into force in the Netherlands, completing the Dutch transposition of the NIS2 Directive (Directive (EU) 2022/2555) and the CER Directive (Directive (EU) 2022/2557). The Netherlands was among the later EU Member States to complete NIS2 transposition; the national deadline was 17 October 2023. The Cyberbeveiligingswet designates the Nationaal Cyber Security Centrum (NCSC), which sits within the Ministry of Justice and Security, as the central NIS2 competent authority and national point of contact for cybersecurity. Sector-specific competent authorities are designated for financial services (De Nederlandsche Bank and the AFM), healthcare (Inspectie Gezondheidszorg en Jeugd), and other regulated sectors. The Cyberbeveiligingswet extends NIS2 obligations to approximately 8,000 Dutch organisations. Essential entities include organisations in energy, transport, drinking water, wastewater, banking, financial market infrastructure, healthcare, digital infrastructure, ICT service management, public administration, and space. Important entities include organisations in postal and courier services, waste management, manufacture and distribution of chemicals, food production and distribution, manufacturing of medical devices and other industrial goods, digital providers, and research. Obligations for in-scope organisations cover: registration with the NCSC within the period specified in implementing regulations; implementation of risk-based security measures addressing risk management, business continuity, supply chain security, access control, encryption, and secure communications; mandatory incident reporting to the NCSC (24-hour early warning and 72-hour full notification for significant incidents); board-level accountability under which members of the management body are personally responsible for overseeing cybersecurity risk management, with non-compliant directors potentially liable; and due diligence obligations in respect of suppliers and service providers. The Wwke transposes the CER Directive and imposes resilience obligations on critical entities, requiring entity-level resilience risk assessments and continuity measures.

The Cyberbeveiligingswet's entry into force on 15 August 2026 makes all NIS2 obligations immediately enforceable. The NCSC holds supervisory and enforcement powers including the authority to request information, conduct inspections, and impose administrative fines. For essential entities, the NIS2 maximum fine ceiling is EUR 10 million or 2% of total worldwide annual turnover (whichever is higher); for important entities, EUR 7 million or 1.4% of total worldwide annual turnover. The Dutch transposition gives the NCSC authority to order interim measures and to publicly disclose infringements in cases of serious or persistent non-compliance. The personal liability provisions for management board members are among the strongest implementations of NIS2 Article 20 adopted by any Member State: board members may be required by the NCSC to attend NIS2-mandated cybersecurity training if the organisation is found to have failed to maintain adequate oversight. The approximately 8,000 in-scope organisations that have not yet implemented NIS2-aligned risk management, incident reporting, and supply chain security procedures are in breach of the Cyberbeveiligingswet from the date of entry into force. The NCSC published guidance for in-scope entities ahead of the law's entry-into-force date, including a registration guide and a first-steps checklist. The simultaneous entry-into-force of the Wwke ensures that organisations that are both NIS2-subject and CER-designated critical entities face a coordinated Dutch regulatory framework for their cybersecurity and physical resilience obligations.

What it means for your business

If your organisation operates in the Netherlands in a sector covered by NIS2 (energy, transport, water, banking, financial market infrastructure, healthcare, digital infrastructure, public administration, postal services, waste management, chemicals, food, manufacturing, or digital providers): The Cyberbeveiligingswet entered into force on 15 August 2026. If you are an essential or important entity under NIS2, you now have immediate obligations: implement risk-based security measures covering risk management, supply chain security, access control, encryption, and incident handling; register with the NCSC within the period specified in the implementing regulations; and ensure incident reporting workflows are in place (24-hour early warning, 72-hour full notification to the NCSC for significant incidents). If you have not yet implemented NIS2-aligned procedures, you are in breach from 15 August 2026. If you are a member of the management body of a Dutch organisation in scope of the Cyberbeveiligingswet: The Dutch NIS2 transposition imposes personal responsibility on individual board members for cybersecurity governance. Ensure your organisation has board-level approval of its cybersecurity risk management measures and that cybersecurity is a standing agenda item at board level. The NCSC may require you to complete NIS2 compliance training if the organisation is found to be non-compliant. If you supply ICT products, services, or managed services to Dutch essential or important entities: Supply chain security is a core NIS2 obligation. Your Dutch customers must assess and manage supplier cybersecurity risk. Expect contractual cybersecurity requirements, supplier security questionnaires, and incident notification obligations in your agreements with Dutch NIS2-subject entities. Prepare your supplier security documentation now. Assess your NIS2 obligations with Verdaio's NIS2 Readiness Assessment.

ETSI Launches Approval Process for 17 European Standards Supporting the Cyber Resilience Act

On 14 August 2026, ETSI announced the launch of the formal approval process for 17 draft European Standards (ENs) developed to support compliance with the Cyber Resilience Act (Regulation (EU) 2024/2847). The standards cover products including password managers, anti-virus software, VPNs, home gateways, smart home assistants, connected toys, wearable health devices, IP cameras, and industrial IoT devices. Manufacturers following the adopted harmonised standards will benefit from a presumption of CRA conformity. The public enquiry phases run from mid-September through mid-November 2026.

What changed

On 14 August 2026, ETSI announced the formal launch of the approval process for 17 draft European Standards prepared by ETSI Technical Committee CYBER (TC CYBER) to support compliance with Regulation (EU) 2024/2847 (the Cyber Resilience Act, CRA). The standards were developed in response to a standardisation request from the European Commission and represent the first set of harmonised standards developed specifically for the CRA. The 17 draft ENs cover cybersecurity requirements for the following product categories: password managers; anti-virus and anti-malware software; virtual private networks (VPNs) for individual users; home gateways and routers; smart home assistants (voice-activated smart speakers and similar consumer devices); connected toys (products with digital elements designed for children that connect to the internet or to other devices); wearable health monitoring devices (including fitness trackers and smartwatches with health or biometric monitoring functions); IP cameras and video doorbells; smart meters; connected door locks; alarm systems with network connectivity; network monitoring software; industrial IoT devices; remote access software; operating systems for general-purpose use; microprocessors and microcontrollers; and hypervisors and container runtime systems. The ETSI approval process for a European Standard has two stages: a public enquiry (during which national standards bodies circulate the draft for public comment) and a formal vote by national standards bodies. For these 17 standards, the public enquiry phases are scheduled to run between mid-September and mid-November 2026. Final adoption of the standards as published ENs is expected in the first half of 2027.

Once the 17 draft ENs are adopted as published European Standards and referenced in the Official Journal under the CRA, manufacturers whose products comply with those standards will benefit from a presumption of conformity with the CRA essential cybersecurity requirements covered by the standards under CRA Article 27. The presumption of conformity reduces the evidentiary burden in enforcement dialogue with national market surveillance authorities. The CRA's full compliance date for most products with digital elements is 11 December 2027. The CRA's Article 14 incident and vulnerability reporting obligations for actively exploited vulnerabilities and CRA-related security incidents have applied from 11 September 2026. The 17 draft ENs build on EN 18031 (the harmonised standard for radio equipment cybersecurity under the Radio Equipment Directive) and extend it with requirements calibrated to specific product categories and the CRA Annex I essential cybersecurity requirements. The ETSI announcement follows the Commission's publication of non-binding CRA implementation guidance (C(2026) 5252) on 27 July 2026, which covered product scope, Article 14 reporting, support period obligations, and substantial modification. Together, the guidance and the harmonised standards form the core CRA compliance toolkit. National market surveillance authorities are expected to reference the adopted harmonised standards in their enforcement approach from 2027.

What it means for your business

If you manufacture or supply any of the 17 product categories covered by these ETSI draft ENs (password managers, anti-virus or anti-malware software, VPNs for individual users, home gateways or routers, smart home assistants, connected toys, wearable health devices, IP cameras or video doorbells, smart meters, connected door locks, alarm systems with network connectivity, network monitoring software, industrial IoT devices, remote access software, general-purpose operating systems, microprocessors or microcontrollers, or hypervisors): These draft European Standards, once adopted and OJ-referenced, will allow you to claim CRA presumption of conformity for the essential cybersecurity requirements they cover. Monitor the public enquiry process (mid-September through mid-November 2026) and consider submitting formal comments to shape the final standard for your product category. Begin evaluating whether your product security design aligns with the draft requirements now, to minimise the gap-closing work before December 2027. If you are preparing your CRA conformity assessment approach for products not covered by these 17 draft ENs: The CRA allows conformity assessment via other routes where no harmonised standard applies, including use of European cybersecurity certificates or third-party conformity assessment for Class I and II products. Track the CRA harmonised standards publication programme through ETSI and the Official Journal, as further standards covering additional product categories are expected. If you are a procurement or legal team sourcing digital products: Once harmonised standards are OJ-referenced, require suppliers to reference conformity with the relevant EN in their declarations of conformity. Until then, request that suppliers describe their intended CRA conformity assessment approach and timeline. Assess your CRA and NIS2 obligations with Verdaio's NIS2 Readiness Assessment.

Italian Garante Bans Mediaset From Deepfake Satirical Videos of Journalist Enrico Mentana Under GDPR

On 7 August 2026, Italy's data protection authority (Garante) published provvedimento n. 577 ordering R.T.I. S.p.A. (Reti Televisive Italiane, part of Mediaset) to cease using AI-generated deepfake videos of La7 news director Enrico Mentana in the satirical programme Striscia la Notizia, finding violations of GDPR Articles 5 and 25. The Garante concluded that on-screen disclaimers were insufficient: the realism of the manipulated images and the plausibility of false statements attributed to Mentana could lead viewers, including inattentive audiences and social media users, to believe the content was genuine. The decision (adopted 23 July 2026) issues a formal warning to R.T.I. and bans further processing of Mentana's data, five days after EU AI Act Article 50 transparency obligations entered force.

What changed

On 7 August 2026, the Garante per la Protezione dei Dati Personali published its decision in provvedimento n. 577 (docweb 10281135), on a complaint filed by Enrico Mentana, director of the La7 news programme TGLa7, against R.T.I. S.p.A. (Reti Televisive Italiane), the Mediaset group broadcaster that produces Striscia la Notizia. Striscia la Notizia is a long-running prime-time satirical entertainment programme broadcast on Canale 5. R.T.I. had produced and broadcast a series of segments in which Mentana's image and voice were manipulated using artificial intelligence, placing his likeness virtually in the Striscia la Notizia studio and attributing statements to him that he had never made. The segments were accompanied by on-screen disclaimers indicating that the content was AI-generated, but the Garante examined whether those disclaimers satisfied GDPR requirements. The Authority found violations of two provisions of the GDPR. Under Article 5 (the principles of lawfulness, fairness and transparency), the Garante concluded that the realism of the deepfake images, the poor perceptibility of the AI alteration, and the plausibility of the false statements attributed to Mentana could have led members of the audience, including inattentive viewers and those who encountered the videos as standalone social media clips outside the programme context, to believe the content was authentic. The on-screen disclaimers were found to be insufficiently clear, evident and comprehensible to all viewer segments. Under Article 25 (data protection by design and by default), the Authority found that R.T.I.'s production process did not embed the technical and organisational measures required to ensure that the processing of Mentana's personal data met the transparency standard and was limited to what was necessary. The Garante prohibited R.T.I. from further processing Mentana's personal data in the contested manner, while permitting retention of the relevant material for potential judicial proceedings. The decision was adopted on 23 July 2026 and published on 7 August 2026, five days after EU AI Act Article 50 transparency obligations entered force on 2 August 2026.

The Garante's decision establishes that the right to create and broadcast AI-generated satirical content depicting a real person does not override GDPR data protection principles, even where the programme has a well-established satirical character and the subject is a public figure. The Authority did not rule out the use of AI-generated deepfake content for satire in principle, but held that the production and distribution of such content must comply with GDPR transparency requirements at a standard sufficient for all segments of the intended audience. The applicable standard is higher than a technical disclaimer might suggest: the disclosure of the AI-generated character of the content must be clear, evident and comprehensible even to inattentive viewers and to viewers who encounter a clip as a standalone post on a social media platform, where they may not have the context established by the surrounding programme. No financial penalty was imposed; the Garante issued a formal warning and a prohibition on further processing. The decision's significance extends beyond the individual case because it applies GDPR Articles 5 and 25 directly to AI-generated deepfake content and to the AI production workflow itself, requiring producers to build disclosure mechanisms that meet the comprehensibility standard across all distribution channels. The decision was published five days after EU AI Act Article 50 began to require machine-readable markings and visible human-readable labels on AI-generated content depicting real people, creating a parallel compliance requirement under two separate regulatory instruments. Organisations producing or distributing AI-generated content featuring real individuals in the EU must now satisfy both GDPR transparency and AI Act Article 50 transparency, and neither instrument is satisfied by a disclaimer that is technically present but practically imperceptible to a typical viewer.

What it means for your business

If you produce, commission, or distribute AI-generated video or audio content depicting a real person's image, likeness, or voice in an EU-facing editorial, entertainment, or advertising context: The Garante's decision confirms that GDPR Articles 5 and 25 apply to the production and broadcast of AI-generated deepfake content and require disclosure to be clear, evident and comprehensible not only to attentive programme viewers but also to inattentive audiences and to viewers who encounter the content as a standalone clip on social media. Review your AI content production and distribution workflow and verify that all distribution channels carry disclosures that meet this comprehensibility standard, not only the original broadcast. If you use AI generation tools to create content depicting real identifiable people and distribute that content through digital channels: From 2 August 2026, EU AI Act Article 50 also requires machine-readable markings on AI-generated content and visible human-readable labels on deepfake video or audio depicting real people. Your compliance obligation now spans both GDPR Article 5 transparency and AI Act Article 50 disclosure. A disclaimer that is technically present in a broadcast setting but imperceptible on a social media clip does not satisfy either requirement. Review each distribution channel and ensure that compliant disclosures are embedded at the clip level, not only at the programme level. If you develop or supply AI tools that generate synthetic video or audio of real people: Article 25 of the GDPR requires data protection by design and by default. The Garante found that the absence of adequate built-in disclosure mechanisms constituted an Article 25 violation at the tool or production-process level. Assess whether your system provides controls that enable users to embed disclosure markers meeting the comprehensibility standard required by the Garante, alongside the machine-readable marking requirements of EU AI Act Article 50. Assess your data protection and AI obligations with Verdaio's GDPR Quick Check and AI Act Readiness Check.

Italian Garante Declares Police Facial Recognition Decree Incompatible with EU AI Act Article 5

On 30 July 2026, Italy's data protection authority (Garante) publicly declared that a core provision of the government's police facial recognition decree is incompatible with EU AI Act Article 5, marking one of the first open conflicts between a national data protection authority and its government over an EU AI Act prohibited practice. The contested provision would allow biometric data from surveillance cameras at stadiums and demonstrations to be stored for seven days for retrospective investigation. The Garante found the measure falls outside all three permitted exceptions under Article 5(1)(h) and called for the provision to be removed before the decree's final adoption.

What changed

On 30 July 2026, the Garante per la Protezione dei Dati Personali issued a public opinion declaring a central provision of the Italian government's draft decree on police use of facial recognition technology incompatible with EU AI Act Article 5. The decree, which covers biometric data use by law enforcement, cleared its first parliamentary reading in the Chamber of Deputies on 29 July 2026. The contested provision would permit biometric data captured by video-surveillance cameras in sensitive locations - stadiums, transportation hubs, and demonstration sites - to be stored for up to seven days to allow retrospective identification of individuals in connection with criminal investigations. The Garante examined the measure against the three categories of exception to the general prohibition on real-time remote biometric identification in public spaces under EU AI Act Article 5(1)(h). Those exceptions permit real-time remote biometric identification solely: (a) for targeted searches for specific missing or disappeared victims; (b) to prevent a specific, substantial, and imminent threat to life or a terrorist attack; and (c) for the identification of persons suspected of having committed a specific serious criminal offence listed in Annex II of the AI Act, where prosecution or execution of a criminal penalty requires identification. The Garante concluded that a seven-day biometric data retention regime directed at all individuals at defined location categories - without a specific crime under investigation or a specific suspect already identified - falls outside all three permitted exceptions. The data collection is preemptive and population-wide in character, not targeted at an identified person or a specific and imminent threat.

The government's response came within hours. Government sources told ANSA on 30 July 2026 that Italy was not in breach of EU rules and that the decree was compatible with the EU AI Act, pointing to the law enforcement exceptions in Article 5 and the Council of Europe Convention on police use of biometric data. The dispute marks one of the first recorded conflicts between a national data protection authority and a national government over a specific legislative measure invoking EU AI Act Article 5 prohibited practice provisions. The permitted exceptions under Article 5(1)(h) are intentionally narrow. The qualifiers specific, substantial, and imminent for exception (b) require an active and clearly defined threat, not a precautionary population-level collection of biometric data. Exception (c) applies only where a specific suspect's identification is already required for prosecution of a specific past offence; it does not authorise advance collection of biometric data across crowds on the chance that a future offence might require retrospective search. The Garante called for the contested provision to be removed before the Council of Ministers adopts the decree. Parliamentary committees (the IX and X committees) must deliver their opinion by 16 August 2026 before final adoption. Whether the government proceeds without amendment or modifies the measure will be a significant early test of how EU AI Act Article 5 prohibited practice rules operate as a constraint on national government action in the law enforcement domain.

What it means for your business

If you develop, supply, or integrate biometric identification systems, facial recognition technology, or video-surveillance solutions for law enforcement, venue security, or access control in the EU: The Garante's opinion confirms that EU AI Act Article 5 imposes narrow, non-extensible exceptions for real-time remote biometric identification in public spaces. Any system that collects and retains biometric data from the general population present in a defined location - even for a short period and even for investigative purposes - is likely to fall outside the Article 5(1)(h) exceptions unless it is targeted at an identified suspect, an active specific threat, or a specific past serious offence listed in Annex II. Review the scope and purpose of your system against each permitted exception before deploying in public or quasi-public spaces in the EU. If you are a public authority, event organiser, or infrastructure operator planning to deploy facial recognition or biometric surveillance at stadiums, public spaces, or transportation hubs in the EU: The Garante's position indicates that preemptive collection and retention of biometric data from individuals present at a location - even framed as a public security measure - does not satisfy the specific, substantial, and imminent conditions of the Article 5(1)(h) exceptions. Obtain specialist legal advice before deploying any system with a population-wide data collection function, rather than a targeted identification function. Assess your EU AI Act obligations with Verdaio's AI Act Readiness Check.

Italian Garante Fines Altroconsumo Edizioni EUR 280,000 for Sending Marketing Emails to Non-Registered Users

On 29 July 2026, Italy's data protection authority (Garante) published its decision fining Altroconsumo Edizioni Srl EUR 280,000 for sending promotional emails to individuals who had begun but not completed registration on its website, treating an incomplete sign-up as a concluded contract and processing personal data for marketing without a valid GDPR legal basis. The authority also found failures in responding to erasure requests. A 50% reduced payment of EUR 140,000 is available by direct settlement within 60 days.

What changed

On 29 July 2026, the Garante per la Protezione dei Dati Personali published Newsletter No. 550, reporting its decision (Ordinanza 476, adopted 18 June 2026) to fine Altroconsumo Edizioni Srl EUR 280,000 for violations of GDPR Articles 5, 6, 12, and 17. Altroconsumo Edizioni is the publishing arm of Altroconsumo, Italy's largest consumer rights organisation. The Garante's investigation found that the company had sent promotional marketing emails to individuals who had started but not completed a registration process on its website. Altroconsumo Edizioni treated the incomplete registration - in which users had provided their email address but had not confirmed their account or accepted service terms - as a concluded service contract, asserting a contractual performance basis under GDPR Article 6(1)(b) for the marketing communications. The Garante rejected this characterisation. An incomplete online registration in which the user has not confirmed their account and accepted the service terms is not a concluded contract for the purposes of GDPR Article 6(1)(b). The contractual performance basis applies only where processing is objectively necessary for the performance of a contract to which the data subject is actually a party. Sending marketing emails to individuals who did not complete registration therefore lacked any valid GDPR legal basis, violating Article 6 and the lawfulness principle of Article 5(1)(a). The Garante also found failures in responding to data subjects' rights requests: some individuals who submitted erasure requests under GDPR Article 17 did not receive a timely or adequate response within the one-month period required by Article 12.

The Garante's analysis reinforces a well-established but frequently misapplied principle: Article 6(1)(b) is narrowly construed and cannot justify commercial communications in pre-contractual or incomplete-registration scenarios. The appropriate legal basis for email marketing in such contexts is consent under GDPR Article 6(1)(a), which requires a specific, freely given, informed, and unambiguous indication of agreement before any marketing communication is sent. The decision highlights enforcement risks for organisations that collect contact data through partially completed registration flows and use it for marketing without an independent legal basis. The EUR 280,000 fine reflects the number of individuals who received unauthorised marketing communications and the systematic character of the practice. A direct-payment settlement option is available for EUR 140,000 (50% of the assessed fine), within 60 days of receipt of the decision. The decision is published in the same Garante newsletter (No. 550) as the EUR 460,000 fine against Piaggio (story s68) and forms part of the authority's sustained enforcement focus on lawful basis and rights response obligations under GDPR Articles 5, 6, 12, and 17. Altroconsumo Edizioni may also appeal the decision before the competent court.

What it means for your business

If you send marketing or promotional emails to individuals who have started but not completed a registration process on your website or app: The Garante's decision confirms that GDPR Article 6(1)(b) (contractual performance) does not provide a valid legal basis for marketing emails to non-confirmed registrants. Sending marketing communications to partially registered users who have not finalised account creation and accepted your terms requires either consent under Article 6(1)(a) or a legitimate interests basis under Article 6(1)(f) with a documented proportionality assessment. Review your registration flow and email marketing triggers to confirm that marketing is only triggered for users with a confirmed, documented legal basis. If you use email addresses collected during incomplete or abandoned registration flows for any purpose other than account completion: Data collected before a registration is confirmed may only be used for the purpose for which it was collected at that stage. Using it for marketing or other secondary purposes requires an independent legal basis. Map your registration-to-communication data flow against GDPR Articles 5 and 6 and document the applicable legal basis at each stage. If your organisation handles data subjects' rights requests including erasure requests: The Garante found failures in responding to erasure requests within the one-month deadline of GDPR Article 12. Review your rights-handling process to ensure all incoming requests are routed to a responsible team and that response timelines are tracked and met. Assess your data protection obligations with Verdaio's GDPR Quick Check.

Germany Enacts KI-MIG: Bundesnetzagentur Designated as Central AI Act Market Surveillance Authority

On 29 July 2026, Germany's KI-Marktüberwachungsgesetz (KI-MIG) entered into force, designating the Bundesnetzagentur (Federal Network Agency) as Germany's central AI Act market surveillance authority under Article 70 of the EU AI Act, as published in the Bundesgesetzblatt on 28 July 2026. BaFin is designated as the supervisory authority for AI systems in financial services, with fines up to EUR 40 million. BfDI and Lander DPAs retain competence where AI Act obligations intersect with GDPR. The law passed the Bundestag on 11 June and the Bundesrat on 10 July 2026.

What changed

On 28 July 2026, Germany's KI-Marktüberwachungsgesetz (KI-MIG, Act on AI Market Surveillance) was published in the Bundesgesetzblatt and entered into force on 29 July 2026, meeting the EU AI Act's deadline for Member States to designate their national market surveillance authorities under Article 70 of Regulation (EU) 2024/1689 by 2 August 2026. The KI-MIG designates the Bundesnetzagentur (Federal Network Agency) as Germany's central AI Act market surveillance authority. The Bundesnetzagentur acquires supervisory competence for the broad range of AI systems covered by the EU AI Act, including general-purpose AI models, systems in the unacceptable-risk category under Article 5, and high-risk AI systems under Annex III that do not fall within a sector-specific supervisory allocation. This central authority model mirrors the approach adopted by Germany for digital market regulation more broadly, concentrating EU AI Act oversight within the Bundesnetzagentur alongside its existing mandates in telecommunications, energy, and postal markets. BaFin, the Federal Financial Supervisory Authority, is designated as the supervisory authority for AI systems in financial services, including AI systems used in credit assessment, insurance underwriting, and algorithmic trading. The KI-MIG assigns BaFin authority over Article 5 prohibitions and Annex III obligations for AI systems whose primary use case falls within the regulated financial sector. For AI systems that fall within both the AI Act's scope and GDPR's scope, the Federal Commissioner for Data Protection and Freedom of Information (BfDI) and the Lander data protection authorities (DPAs) retain their GDPR supervisory competence for processing activities, including where the AI Act's transparency and accuracy obligations for high-risk systems intersect with GDPR Articles 22 and 35 on automated decision-making and data protection impact assessments.

The KI-MIG's legislative passage was unusually swift by German federal standards. The bill was introduced by the coalition government in May 2026 and passed the Bundestag on 11 June 2026 and the Bundesrat on 10 July 2026, ahead of the federal government's initial internal target of autumn 2026. The accelerated timeline was driven by the EU AI Act's requirement that all Member States designate their Article 70 national market surveillance authorities by 2 August 2026, the date from which Article 50 transparency obligations and GPAI supervisory powers become enforceable across the EU. Germany's designation of the Bundesnetzagentur as central authority positions that agency as a significant actor in the emerging EU AI Act enforcement ecosystem alongside the AI Office and national authorities in France (CNIL), the Netherlands (ACM), Italy (Agcom, designated for AI market surveillance), and Ireland (Digital Safety Commissioner). The KI-MIG also sets out procedural rules for the exercise of supervisory powers, including the authority to request information from operators, conduct audits, order corrective measures, and impose administrative fines. Penalties for infringements of the EU AI Act's Article 5 prohibitions of up to EUR 35 million or 7 percent of worldwide annual turnover (as set by the AI Act itself) are enforceable by the Bundesnetzagentur; BaFin may impose additional penalties within the financial services sector of up to EUR 40 million for AI Act infringements by regulated financial institutions. The Bundesnetzagentur announced it expects to publish its first substantive guidance on Article 70 supervisory priorities and enforcement approach in the fourth quarter of 2026.

What it means for your business

If you place AI systems on the German market or use AI systems in business operations in Germany: The Bundesnetzagentur is now your primary EU AI Act regulatory contact in Germany. It has authority to request information, conduct audits, order corrective measures, and refer infringements for enforcement. Identify which of your AI systems fall under the EU AI Act (Article 5 prohibitions, Annex III high-risk categories, or Article 50 transparency obligations), map them to the Bundesnetzagentur's scope or the sector-specific allocations to BaFin, and ensure you have a contact designation in place for regulatory correspondence. If you operate AI systems in financial services in Germany (credit assessment, insurance underwriting, algorithmic trading, or other regulated financial use cases): BaFin is your designated AI Act supervisory authority for those systems. BaFin has authority over both the AI Act Article 5 prohibitions and Annex III high-risk obligations for financial-sector AI applications, with administrative fines up to EUR 40 million. Ensure your AI system documentation (technical file, conformity assessment, EU database registration) reflects BaFin as the relevant national competent authority. If your AI systems process personal data and fall within both the EU AI Act and GDPR: The BfDI and Lander DPAs retain GDPR supervisory competence for the data processing dimension, including data protection impact assessments under GDPR Article 35 for high-risk processing involving AI. Coordinate your GDPR and AI Act compliance documentation to avoid conflicting assessments across two supervisory regimes. Assess your EU AI Act obligations with Verdaio's AI Act Readiness Check.

Commission Confirms AI Act Enforcement Active from 2 August: Article 50 Transparency and GPAI Supervision Live

On 31 July 2026, the European Commission announced that from 2 August 2026 the EU AI Act reaches its third application tier, with Article 50 transparency obligations and the AI Office's supervision of general-purpose AI (GPAI) models becoming enforceable. Deployers of AI chatbots and conversational systems must now disclose that users are interacting with AI; deepfakes and AI-generated synthetic content must carry machine-readable labels. Providers of GPAI systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with the new marking requirements.

What changed

On 31 July 2026, the European Commission published a press release (IP/26/1714) confirming that from 2 August 2026 the EU AI Act (Regulation (EU) 2024/1689) enters its third phase of application. The first phase (2 February 2025) prohibited unacceptable-risk AI practices; the second phase (2 August 2025) applied obligations to GPAI model providers and established the AI Office. The third phase, beginning 2 August 2026, activates two new obligation sets. First, Article 50 transparency obligations now apply to AI systems that interact directly with natural persons. Deployers of AI chatbots, customer service bots, and other conversational AI systems must disclose to users that they are interacting with an AI system in a clear and timely manner, unless the context makes this obvious to a reasonably well-informed user. Providers and deployers of AI systems generating synthetic audio, video, image, or text content must ensure those outputs carry machine-readable markings identifying them as AI-generated; deepfake video and audio depicting real individuals must additionally display a visible disclosure. Second, the AI Office's supervisory powers over GPAI model providers become fully operative. Providers of GPAI models, which include large language models and multimodal foundation models, must comply with the obligations set out in Chapter V of the AI Act, including transparency documentation (Article 53), copyright compliance policies, and energy consumption reporting. GPAI model providers whose models were placed on the market before 2 August 2026 benefit from a transitional arrangement under Regulation (EU) 2026/1744 (the Digital Omnibus), which extended the grace period for compliance with the new machine-readable marking requirements to 2 December 2026.

The Commission's announcement coincides with the formal activation of the AI Office's GPAI supervisory mandate. The AI Office, established within the Commission's Directorate-General for Communications Networks, Content and Technology, is the designated supervisor for GPAI model providers across the EU. From 2 August 2026 it may open investigations, issue requests for information, and in cases of infringement recommend enforcement action to national market surveillance authorities. Systemic-risk GPAI models, being those with training compute exceeding 10^25 FLOPs or designated as systemic-risk by the Commission, face additional obligations including adversarial testing (red-teaming), incident reporting to the AI Office, and cybersecurity measures. For Article 50 transparency obligations, enforcement responsibility rests with national market surveillance authorities designated under Article 70 of the AI Act; each Member State must designate its authority by 2 August 2026. Non-compliance with Article 50 can result in administrative fines of up to EUR 15 million or 3 percent of worldwide annual turnover, whichever is higher. Non-compliance with GPAI obligations can result in fines of up to EUR 15 million or 3 percent of worldwide annual turnover for GPAI model providers, and up to EUR 30 million or 6 percent for systemic-risk GPAI model providers. The high-risk AI system obligations in Annex III categories (medical devices, critical infrastructure, education, employment, law enforcement, border control) remain subject to extended compliance timelines, with most Annex III systems having until 2 August 2027 or 2 December 2027, and Article 6(1) high-risk systems deployed by public authorities having until 2 August 2028.

What it means for your business

If you deploy AI chatbots, virtual assistants, or other AI systems that interact directly with users (customers, employees, or the public): Article 50 transparency obligations are now enforceable. Ensure that every interaction session with a conversational AI system includes a clear, timely, and intelligible disclosure that the user is communicating with an AI, not a human. A brief system prompt disclosure or persistent UI indicator is the minimum; the disclosure must be given before or at the start of the interaction, not buried in terms and conditions. If you generate, publish, or distribute audio, video, image, or text content using AI generation tools: AI-generated content must now carry machine-readable markings identifying it as AI-generated. Verify that your content pipeline includes machine-readable watermarking or metadata tagging for all synthetic outputs. For deepfake video or audio depicting real identifiable individuals, an additional visible human-readable disclosure is required. If you develop, fine-tune, or deploy GPAI models (large language models, multimodal foundation models) placed on the EU market: The AI Office's supervisory powers are now active. Ensure your Article 53 technical documentation and copyright policy are in order. If your model was on the market before 2 August 2026, the transitional period for machine-readable marking compliance runs until 2 December 2026. If your model exceeds the systemic-risk compute threshold, ensure adversarial testing results and incident reporting channels are in place. If you integrate third-party GPAI models into your products or services: Review the model provider's AI Act compliance documentation. As a deployer, your Article 50 disclosure obligations apply regardless of whether the underlying model was developed in-house or sourced externally. Assess your AI Act obligations with Verdaio's AI Act Readiness Check.

Italian Garante Fines Piaggio EUR 460,000 for Systematic Retention and Monitoring of Employee Emails

On 29 July 2026, the Italian data protection authority (Garante) published its decision fining Piaggio and C. Spa EUR 460,000 for the systematic collection and retention of corporate email data via backups, including access to 112 emails from former employees to verify alleged misconduct. The emails accessed included some sent approximately two years before the company formed a suspicion of wrongdoing. The Garante found violations of GDPR Articles 5(1)(a), 5(1)(c), and 6, prohibited Piaggio from accessing the retained data, and ordered corrective measures. Piaggio announced it would challenge the decision.

What changed

On 29 July 2026, the Italian data protection authority (Garante per la Protezione dei Dati Personali) published Newsletter No. 550, reporting its decision to fine Piaggio and C. Spa EUR 460,000 for unlawful processing of employee personal data relating to corporate email accounts. The investigation was triggered by complaints from two former employees and revealed that Piaggio had accessed their corporate email accounts during their employment, acquiring a total of 112 emails to verify alleged unlawful conduct. A significant portion of the emails accessed dated back approximately two years before the company formed its suspicion of misconduct. The systematic access to historical email communications was made possible by Piaggio's policy of retaining all employee email data via backups for the entire period of employment and for up to five years after the employment relationship ended. The Garante found that this systematic backup and the subsequent access to retained emails for investigative purposes violated GDPR Article 5(1)(a), which requires personal data to be processed lawfully, fairly, and transparently; GDPR Article 5(1)(c), which requires data to be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed (data minimisation); and GDPR Article 6, on the basis that Piaggio did not have an adequate legal basis for processing employee email communications to the extent and over the retention periods applied. The Garante prohibited Piaggio from accessing the collected and retained data on its systems relating to the practices identified in the investigation.

The Garante's decision clarifies the limits on employer access to employee emails in the context of internal investigations, even where there is a founded suspicion of unlawful conduct. First, the systematic retention of email backups covering all employee communications for the full employment period and five years post-termination, without scope limitation or controlled access mechanisms, is not a proportionate measure and violates the data minimisation principle of GDPR Article 5(1)(c) and the storage limitation principle of GDPR Article 5(1)(e). Second, retrospective access to email communications dating back two years before the suspicion arose exceeds what is necessary for any specific investigative purpose and does not satisfy the proportionality test applicable to the legitimate interests basis under GDPR Article 6(1)(f): the employer must limit the scope of the review to data necessary for the specific investigation, and access to broadly retained historical communications does not meet this standard. Third, the absence of technical controls preventing access to communications outside the scope of the investigation represents a failure of the technical and organisational measures required under GDPR Article 32. The EUR 460,000 fine reflects the Garante's assessment of the seriousness of the violations and the number of individuals affected. Piaggio announced it would contest the decision before the competent court. The decision is consistent with prior Garante enforcement on employee monitoring and internal investigations, and reinforces that employers must define in advance the precise scope of any email access, limiting it to the minimum strictly necessary for the specific investigative purpose.

What it means for your business

If you conduct or plan to conduct internal investigations that involve accessing employee email accounts, messaging systems, or other communications platforms: The Piaggio decision confirms that access to employee email is a processing activity subject to full GDPR compliance, including a valid legal basis under Article 6, data minimisation under Article 5(1)(c), and storage limitation under Article 5(1)(e). Define the scope of any email access in advance, limit the review to communications strictly necessary for the specific investigation, and document a proportionality assessment before any access is carried out. If you implement email backup or retention policies covering all employee communications for extended periods: The Garante's decision indicates that retaining email backups for the full employment period and five years post-termination, without scope limitations or controlled access mechanisms, may not be compatible with GDPR data minimisation and storage limitation principles. Review your email retention policy and ensure it is aligned with GDPR Article 5 and supported by a legitimate purpose with proportionate retention periods. If employees have previously been informed about potential access to their communications under a general acceptable use or IT policy: The Garante found that generic IT policies do not satisfy GDPR Articles 13 and 14 information obligations for investigation-specific email access. Review whether your employee privacy notices explicitly cover the circumstances under which email may be accessed as part of an internal investigation. Assess your data protection obligations with Verdaio's GDPR Quick Check.

Italian Garante Fines Data Broker Lusha EUR 2 Million and Orders Erasure of Italian Residents' Data

On 27 July 2026, the Italian data protection authority (Garante) published its decision fining Lusha Systems Inc. EUR 2 million for collecting, enriching, and reselling professional contact data of Italian residents without an adequate legal basis, in violation of GDPR Articles 5, 6, and 13. The Garante also banned Lusha from processing personal data of individuals located in Italy and ordered the erasure of that data. The authority held that the GDPR applies to Lusha under the monitoring jurisdiction of Article 3(2)(b), despite the company having no EU establishment.

What changed

On 27 July 2026, the Italian data protection authority (Garante per la Protezione dei Dati Personali) published its decision fining Lusha Systems Inc. EUR 2 million and imposing a processing ban and an erasure order covering personal data of individuals located in Italy. Lusha is a US-based B2B data intelligence company that collects and enriches contact information, including names, job titles, email addresses, telephone numbers, and professional profiles, and resells that data to sales and marketing teams. The data is obtained from multiple sources, including web scraping of social media platforms and publicly accessible professional directories, and from data purchased from other data brokers. The Garante's investigation, triggered by complaints, identified two categories of conduct giving rise to GDPR violations. First, the collection and resale of personal data of individuals located in Italy without a valid legal basis under GDPR Article 6, in breach of the lawfulness and fairness requirements of Article 5(1)(a). The Garante found that Lusha could not rely on the legitimate interests basis under Article 6(1)(f): the systematic collection, enrichment, and resale of personal data to undisclosed third parties for commercial prospecting purposes failed the proportionality and balancing test, as the commercial interests asserted were not sufficient to override the fundamental rights and interests of data subjects whose data was collected without their knowledge and resold. Second, the systematic failure to provide data subjects with the information required under GDPR Articles 13 and 14, making it practically impossible for individuals to know their data was being held and resold, and to exercise their rights including the right to object under Article 21.

A significant element of the Garante's decision is the analysis of GDPR territorial scope. Lusha has no establishment in the EU. The Garante held that GDPR nonetheless applies to Lusha's processing under Article 3(2)(b), which extends the GDPR to controllers not established in the EU where the processing relates to the monitoring of the behaviour of individuals located in the EU. The Garante found that Lusha's ongoing collection, updating, and enrichment of contact profiles, maintaining and refreshing data about professional positions, contact details, and employment status over time, constituted monitoring of the behaviour of individuals located in Italy within the meaning of Article 3(2)(b). The nature of the data broker model, in which profiles are maintained as living records updated to reflect changes in professional status, reinforced the monitoring characterisation. The EUR 2 million fine, the processing ban, and the erasure order together represent one of the more significant Garante enforcement actions against a non-EU data broker under the GDPR monitoring jurisdiction basis. The decision adds to a growing body of EU supervisory authority enforcement establishing that B2B intelligence businesses collecting and selling professional contact data of EU residents are within GDPR scope regardless of where they are established, and that the legitimate interests basis cannot justify the unrestricted commercial resale of personal data to undisclosed third parties without a genuine proportionality assessment and adequate transparency to data subjects.

What it means for your business

If you use B2B data intelligence or contact enrichment platforms that source professional contact data from third parties, data brokers, or web scraping to identify or contact EU-based professionals: The Garante's decision confirms that the controller using such a platform shares responsibility for the lawfulness of the underlying data collection. Review whether your data enrichment provider can demonstrate a valid GDPR legal basis for the data they supply, compliant information notices to data subjects, and accessible rights channels. If the provider cannot demonstrate GDPR compliance, you face controller liability for using unlawfully processed data. If you are a B2B data broker, contact enrichment provider, or marketing data reseller that processes professional contact data of EU residents without an EU establishment: The Garante's decision confirms that GDPR Article 3(2)(b) applies to your processing if you maintain, update, and enrich profiles of EU individuals over time. Appoint an EU representative under GDPR Article 27, ensure a valid legal basis for each processing purpose, and implement Article 13/14 information notices accessible to data subjects whose data you hold. If you conduct outbound marketing or sales prospecting using purchased or enriched B2B contact lists targeting EU residents: Verify that the contact data was collected with a legal basis covering the specific marketing purpose for which you are using it. The Garante's decision reinforces that legitimate interests does not provide an open-ended right to use personal data for commercial prospecting directed at EU individuals. Assess your data protection obligations with Verdaio's GDPR Quick Check.

Commission Publishes Practical Guidance on CRA Obligations Ahead of September Reporting Deadline

On 27 July 2026, the European Commission published non-binding practical guidance (C(2026) 5252) to help businesses implement the Cyber Resilience Act (Regulation (EU) 2024/2847). The guidance clarifies product scope, the Article 14 reporting requirements for actively exploited vulnerabilities and incidents (24-hour early warning, 72-hour full notification), support period obligations, and what constitutes a substantial modification. It includes 67 practical examples and a dedicated SME section. Article 14 reporting obligations apply from 11 September 2026.

What changed

On 27 July 2026, the European Commission published Commission Notice C(2026) 5252, non-binding practical guidance on the implementation of Regulation (EU) 2024/2847 (the Cyber Resilience Act, CRA). The guidance was published by DG CONNECT to support manufacturers and importers of products with digital elements in preparing for CRA compliance, with the first hard deadline - Article 14 incident and vulnerability reporting obligations - applying from 11 September 2026. The guidance addresses five principal areas of implementation uncertainty. First, product scope: the guidance provides a framework for determining whether a product falls within the CRA definition of "product with digital elements" under Article 3(1), with worked examples covering software-as-a-service products, on-premises enterprise software, open-source components, hardware with embedded software, and consumer IoT devices. Products intended purely for internal use within a single organisation and not placed on the market are outside CRA scope; the guidance also sets out the factors determining whether cloud services are in scope as products or excluded as purely cloud-based services. Second, Article 14 reporting: the guidance explains the two-stage reporting process for actively exploited vulnerabilities and incidents having an impact on the security of the product. Stage one is an early warning to ENISA within 24 hours of the manufacturer becoming aware of the event. Stage two is a full notification within 72 hours, including a severity and impact assessment and proposed mitigating actions. The guidance clarifies what "becoming aware" means and addresses reporting for multi-component products. Third, support periods: the guidance confirms that the minimum support period for security updates is five years from the date of placing the product on the market, or the expected product lifetime if shorter, and addresses how to calculate and communicate support periods in technical documentation and user-facing materials.

The guidance addresses two further implementation areas. On substantial modification: CRA Article 21 requires manufacturers to reassess conformity when a product undergoes a substantial modification that may affect its CRA compliance status. The guidance provides a structured test distinguishing routine security updates and bug fixes (which do not trigger reassessment) from changes that introduce new functionality, alter the product attack surface, or affect security-by-design compliance (which may require a new or updated conformity assessment). Security patches and vulnerability fixes are explicitly not substantial modifications, even where they alter code significantly, provided they do not change the product intended functionality or security architecture. The guidance contains 67 practical examples covering all five areas, drawn from the product categories most commonly raised in consultation: consumer IoT devices, industrial control systems and operational technology, medical devices with digital connectivity, enterprise software, and mobile applications. A dedicated SME section identifies the most common compliance gaps in smaller manufacturers and provides a prioritised checklist for reaching Article 14 reporting readiness by 11 September 2026. The guidance is non-binding and does not create new legal obligations or override the CRA text or implementing acts. However, Commission notices on implementation are regularly referenced by national market surveillance authorities and ENISA when assessing compliance, and manufacturers that follow the guidance worked examples can expect a stronger position in any enforcement dialogue. The Commission indicated it will publish additional guidance on conformity assessment procedures and harmonised standards under CRA Article 27 before the December 2027 full compliance date.

What it means for your business

If you manufacture or supply products with digital elements placed or to be placed on the EU market (hardware with embedded software, connected consumer products, enterprise software, IoT devices, or industrial control systems): Article 14 reporting obligations for actively exploited vulnerabilities and CRA-related security incidents apply from 11 September 2026. Read Commission Notice C(2026) 5252 to verify your product is in scope and to understand the two-stage reporting process: 24-hour early warning to ENISA and 72-hour full notification. The guidance 67 practical examples cover the most common product categories. If you are uncertain whether your product meets the CRA scope definition or whether a planned update constitutes a substantial modification: The guidance provides a structured scope test and a substantial modification test with worked examples. Apply both before the September 2026 deadline to confirm your reporting obligations and avoid inadvertently triggering a new conformity assessment requirement. If you are an SME manufacturer with limited compliance resources: The guidance dedicated SME section provides a prioritised checklist for reaching Article 14 reporting readiness by 11 September 2026. Use it alongside the free ENISA CRA SME Maturity Assessment Model (published 13 July 2026) to identify and close your highest-priority gaps before the reporting deadline. If you are a procurement or legal team at an organisation sourcing digital products from manufacturers: CRA Article 14 reporting obligations sit with the manufacturer, not the customer. Verify that your key digital product suppliers have a documented Article 14 reporting process in place. Assess your CRA and NIS2 obligations with Verdaio's NIS2 Readiness Assessment.

Commission Confirms South Korea GDPR Adequacy in First Post-Schrems II Periodic Review

On 23 July 2026, the European Commission confirmed that South Korea's data protection framework continues to provide an adequate level of protection equivalent to EU standards, following the first completed periodic review of the 2021 adequacy decision under GDPR Article 45(3). The Commission reviewed South Korea's Personal Information Protection Act (PIPA) as amended in March 2023 and April 2025 and found ongoing equivalence. EU-to-South Korea data transfers remain lawful without supplementary measures. Future reviews will shift to a four-year cycle.

What changed

On 23 July 2026, the Commission adopted a Council document (ST-12194-2026-INIT) confirming the outcome of the first periodic review of Commission Implementing Decision (EU) 2021/1772 of 17 December 2021, which established an adequacy finding for South Korea under GDPR Article 45. The 2021 decision covered personal data transferred from the EU to data controllers and processors established in South Korea subject to the Personal Information Protection Act (PIPA). The periodic review conducted in 2026 is the first completed under GDPR Article 45(3)(b), which requires the Commission to review adequacy decisions at least every four years from their adoption. Article 45(3)(b) mandates that reviews consider all relevant developments in third countries, including legislative developments, case law, and administrative practice in the relevant third country. The Commission's review covered South Korea's two subsequent amendments to PIPA: the March 2023 amendments, which strengthened individual rights regarding automated decision-making and profiling and introduced national cross-border transfer rules, and the April 2025 amendments, which brought South Korea's AI governance framework into alignment with PIPA's general principles and extended PIPA to cover certain processing by public institutions not previously in scope. The Commission found that both sets of amendments strengthened the level of protection available to EU data subjects, and that South Korea's supervisory authority, the Personal Information Protection Commission (PIPC), had exercised enforcement powers effectively in the review period.

The periodic review represents a significant procedural milestone: it is the first adequacy decision to complete a full Article 45(3)(b) periodic review since the 2020 Schrems II judgment (Case C-311/18) invalidated the EU-US Privacy Shield adequacy decision and established a more demanding framework for evaluating third-country data protection equivalence. The Commission noted that the South Korea review sets out the methodology for periodic reviews of other existing adequacy decisions, several of which are also due for review in 2025 to 2027. The 2026 South Korea periodic review concluded positively: the Commission found no grounds to amend, suspend, or repeal the adequacy decision. The decision remains in force, and EU-to-South Korea personal data transfers under the 2021 decision remain lawful without the need for supplementary measures such as standard contractual clauses or binding corporate rules. Going forward, the Commission announced that it will shift periodic reviews of the South Korea adequacy decision from the initial three-year review cycle applicable to new adequacy decisions to the standard four-year cycle, aligning with the cycle now applicable to decisions that have passed their initial review.

What it means for your business

If you transfer personal data from the EU to recipients in South Korea (including HR data, customer data, supplier data, or intra-group transfers to Korean affiliates): The Commission's positive outcome of the first periodic review means the 2021 adequacy decision remains in force. Your transfers under the adequacy decision remain lawful without supplementary measures. No action is required. Update your data transfer records and ROPA to note that the adequacy basis was reviewed in July 2026 and confirmed. If you had implemented standard contractual clauses or binding corporate rules as a precaution alongside the adequacy decision: These supplementary measures are not required for transfers covered by the adequacy decision. You may remove or archive them from your transfer documentation for EU-to-South Korea transfers, though retaining them as a risk mitigation layer for transfers beyond the adequacy decision's scope (for example, to entities not subject to PIPA) remains best practice. If you rely on other EU adequacy decisions for international data transfers (UK, Japan, Switzerland, US Data Privacy Framework, Argentina, Israel, or New Zealand): The Commission's completion of the South Korea review signals that the Article 45(3)(b) periodic review programme is now operationally active. Other adequacy decisions are expected to enter review by 2027. Monitor Commission announcements and be prepared to demonstrate continued lawfulness of your transfer arrangements. Map your international data transfer obligations with Verdaio's GDPR Quick Check.

EFRAG Opens Consultation on Draft Sustainability Reporting Standards for Non-EU Groups

On 23 July 2026, EFRAG published for public consultation its Exposure Draft ESRS for Certain Non-EU Undertakings (ESRS-40a), implementing CSRD Article 40a for non-EU parent groups with significant EU operations. Non-EU groups with net EU turnover above EUR 150 million in each of the last two consecutive financial years and an EU subsidiary or branch with net turnover above EUR 40 million are in scope. Mandatory reporting begins for financial years starting on or after 1 January 2028, with the consultation open until 31 October 2026.

What changed

On 23 July 2026, EFRAG published its Exposure Draft ESRS for Certain Non-EU Undertakings (the Exposure Draft), the draft sustainability reporting standards developed under Article 40a of Directive 2013/34/EU (the Accounting Directive, as amended by CSRD and the CSRD Omnibus). Article 40a extends sustainability reporting obligations to non-EU groups with net turnover above EUR 150 million generated within the EU in each of the last two consecutive financial years and that have at least one EU subsidiary or EU branch with net turnover above EUR 40 million. The draft standards, designated ESRS-40a in the Exposure Draft, are proportionate to those applicable to large EU undertakings under the main CSRD regime but are adapted to the specific circumstances of non-EU parent groups: reporting is based on the consolidated level of the non-EU ultimate parent, covering the full group's sustainability impacts, risks, and opportunities. The Exposure Draft covers the full range of sustainability topics including environment (climate, pollution, water, biodiversity, and circular economy), social (own workforce, workers in the value chain, affected communities, and consumers), and governance. It follows the structure of the revised ESRS adopted by the Commission on 3 July 2026, applying the mandatory-if-material approach under which disclosure is only required where a topic is found material in the double materiality assessment. The EFRAG consultation on the Exposure Draft is open until 31 October 2026. EFRAG will consider responses before submitting a final draft to the European Commission, which must adopt the ESRS-40a standards by delegated act. The timeline for mandatory application of ESRS-40a standards is financial years starting on or after 1 January 2028, aligned with the CSRD Omnibus changes to Article 40a reporting obligations.

The Exposure Draft is the first substantive output from EFRAG's work programme on ESRS for non-EU undertakings, a workstream running in parallel with the revision of the main ESRS set. Non-EU groups that will be in scope of Article 40a have until 31 October 2026 to submit comments through EFRAG's public consultation platform. The Exposure Draft includes ESRS-40a 1 (General Disclosures), ESRS-40a E1 (Climate Change), ESRS-40a E2 (Pollution), ESRS-40a E3 (Water and Marine Resources), ESRS-40a E4 (Biodiversity and Ecosystems), ESRS-40a E5 (Resource Use and Circular Economy), ESRS-40a S1 (Own Workforce), ESRS-40a S2 (Workers in the Value Chain), ESRS-40a S3 (Affected Communities), ESRS-40a S4 (Consumers and End-users), and ESRS-40a G1 (Business Conduct). Each standard mirrors its main ESRS counterpart but is calibrated for consolidated group reporting by a non-EU parent. The Commission is expected to adopt the ESRS-40a delegated regulation by mid-2027 to allow non-EU groups sufficient preparation time before the 1 January 2028 mandatory reporting start. National competent authorities in EU member states where non-EU groups have qualifying subsidiaries or branches will be responsible for supervising compliance with the Article 40a reporting obligation once the delegated regulation enters into force.

What it means for your business

If you are the EU subsidiary or branch of a non-EU group with net EU turnover above EUR 150 million: Verify whether your non-EU parent group crosses the Article 40a threshold (EUR 150 million EU net turnover in each of the last two consecutive financial years, plus an EU subsidiary or branch with net EU turnover above EUR 40 million). If in scope, the group must prepare CSRD-equivalent sustainability reports under ESRS-40a from the financial year starting 1 January 2028. The EFRAG consultation closes 31 October 2026: engage your group's sustainability or legal team to review the Exposure Draft and consider submitting a response. If you are a non-EU group assessing your EU regulatory footprint: Article 40a does not require your EU subsidiary to report separately; the reporting obligation sits at the non-EU parent group level on a consolidated basis. Your group's double materiality assessment and ESRS-40a reports will be filed in the EU register. Begin your gap analysis against the draft ESRS-40a standards now to scope the data collection and governance changes needed before 2028. Map your CSRD obligations and run your double materiality assessment with Verdaio's CSRD Readiness Assessment.

Digital Omnibus on AI Published in Official Journal: High-Risk AI Deadlines Extended and NCII Prohibition Added

On 24 July 2026, Regulation (EU) 2026/1744 (the Digital Omnibus on AI) was published in the Official Journal and enters into force on 27 July 2026, amending the EU AI Act. High-risk AI system deadlines for standalone Annex III applications are extended from 2 August 2026 to 2 December 2027; Annex I embedded systems gain a further year to 2 August 2028. A new prohibition is added covering AI-generated non-consensual intimate imagery and child sexual abuse material. Article 50 transparency and GPAI obligations are unchanged and apply from 2 August 2026.

What changed

On 24 July 2026, Regulation (EU) 2026/1744 was published in Official Journal Series L, amending Regulation (EU) 2024/1689 (the EU AI Act). The regulation enters into force on 27 July 2026, three days after publication, and makes four principal changes to the AI Act enforcement timeline and prohibited practices. First, the compliance deadline for high-risk AI systems listed in Annex III that operate as standalone applications, meaning AI systems not embedded in a regulated product already subject to safety legislation listed in Annex I, is extended from 2 August 2026 to 2 December 2027. This category covers the broadest range of commercial AI applications flagged as high-risk, including biometric categorisation systems, AI used in critical infrastructure management, AI in educational or vocational training access decisions, AI used in employment and worker management, AI used in access to essential private and public services, AI used in law enforcement, migration and asylum management, and AI used in the administration of justice. Second, the compliance deadline for high-risk AI systems embedded in products covered by Annex I sector-specific safety legislation (such as medical devices, machinery, and aviation) is extended from 2 August 2027 to 2 August 2028. Third, a new prohibition is inserted into Article 5 of the AI Act: it is prohibited to place on the market, put into service, or use AI systems that generate non-consensual intimate imagery (NCII) or child sexual abuse material (CSAM). This prohibition applies from 27 July 2026, the regulation's entry-into-force date. Fourth, the transitional arrangements for the Article 50 transparency obligations are clarified: providers and deployers of AI systems already lawfully in service before 2 August 2026 must comply with the Article 50(2) machine-readable marking and Article 50(4) deepfake labelling requirements by 2 December 2026, consistent with the grace period announced ahead of the OJ publication.

The publication of Regulation (EU) 2026/1744 in the Official Journal resolves a period of uncertainty following the Council's political agreement of 29 June 2026: the AI Act's high-risk AI system obligations for standalone Annex III applications, which had been due to apply from 2 August 2026, will not now be enforceable until 2 December 2027. Operators who had been preparing for the 2 August 2026 date retain the benefit of their compliance work, but regulators cannot enforce high-risk AI system obligations under Chapter III of the AI Act against standalone Annex III systems for another 16 months. The Article 5 prohibitions, including the new NCII and CSAM prohibition, and the Article 50 transparency obligations applying from 2 August 2026, are unaffected. The conformity assessment regime for high-risk AI systems remains unchanged in substance: operators of standalone Annex III systems must still complete their risk management documentation, technical documentation, and conformity assessments under Articles 9, 11, 12, 13, 14, 15, and 16, prepare their EU declaration of conformity, and register in the EU database under Article 71 before 2 December 2027. The obligations for providers of GPAI models, including the Code of Practice compliance pathway and the systemic risk obligations for the most powerful models, are not affected by Regulation (EU) 2026/1744: these apply from 2 August 2026. The new NCII and CSAM prohibition under the revised Article 5 applies immediately from 27 July 2026 and is not subject to a phased timeline. National market surveillance authorities designating competent authorities to oversee Article 5 compliance may issue guidance on the scope and enforcement approach for the new prohibition in the coming months.

What it means for your business

If you develop or deploy standalone high-risk AI systems in Annex III categories (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, or justice): The compliance deadline for your system has been extended from 2 August 2026 to 2 December 2027 by Regulation (EU) 2026/1744. You are no longer required to be fully compliant by 2 August 2026, but your conformity assessment work, risk management documentation, technical file, and EU database registration must be completed before 2 December 2027. Do not stop your compliance preparations: use the extended timeline to close gaps rather than delay. If you develop or deploy AI-based products subject to Annex I sector legislation (medical devices, machinery, aviation, vehicles): Your compliance deadline has moved from 2 August 2027 to 2 August 2028. Review your current compliance roadmap and adjust your milestones against the new deadline. If you provide or deploy any AI system with Article 50 transparency obligations (interaction disclosure, synthetic content marking, deepfake labelling): Regulation (EU) 2026/1744 does not change the 2 August 2026 application date for Article 50 obligations. These apply on schedule. Review the Commission's guidelines on Article 50 published 20 July 2026 and ensure your implementation is live by 2 August 2026. If you develop AI systems that could generate intimate imagery or any content involving minors: The new prohibition under the revised Article 5 applies from 27 July 2026. Ensure your system includes controls that prevent generation of NCII or CSAM. Assess your EU AI Act obligations with Verdaio's AI Act Quick Check.

ENISA Publishes Healthcare Cybersecurity Procurement Guidelines Under EU Health Action Plan

On 22 July 2026, ENISA published updated cybersecurity procurement guidelines for hospitals and healthcare providers as the first deliverable under the EU Action Plan for the Cybersecurity of Hospitals and Healthcare Providers. Developed with the NIS Cooperation Group and EU Health ISAC, the guidelines cover procurement practices across all lifecycle phases and set cybersecurity requirements for suppliers. Healthcare providers are NIS2 Annex I essential entities, making the guidelines directly relevant to their compliance obligations under Commission Implementing Regulation (EU) 2024/2690.

What changed

On 22 July 2026, ENISA published updated cybersecurity procurement guidelines for hospitals and healthcare providers, marking the first concrete deliverable under the EU Action Plan for the Cybersecurity of Hospitals and Healthcare Providers (the EU Health Action Plan), adopted by the Commission in January 2023. The guidelines were developed jointly with the NIS Cooperation Group, the Network and Information Security Cooperation Group of EU member state competent authorities, and the EU Health Information Sharing and Analysis Centre (EU Health ISAC). The guidelines cover cybersecurity requirements across all lifecycle phases of ICT procurement: planning, tendering, contract negotiation, deployment, operation, and decommissioning. They establish baseline cybersecurity requirements that healthcare organisations should incorporate into supplier contracts and procurement specifications, addressing categories including network security, access control, software supply chain, incident response capability, and secure disposal. The guidelines are designed to help healthcare organisations implement the NIS2 security measures under Article 21 of Directive (EU) 2022/2555 and the specific sector requirements under Commission Implementing Regulation (EU) 2024/2690, which sets sector-specific technical and methodological requirements for NIS2 essential entities in the health sector.

Healthcare providers are classified as essential entities under Annex I of NIS2 (Directive (EU) 2022/2555), meaning they are subject to the full NIS2 security obligation regime, including the Article 21 measures on supply chain security, access control, and incident handling, and the sector-specific requirements under Commission Implementing Regulation (EU) 2024/2690 applicable from 18 January 2027. The procurement guidelines directly support compliance with NIS2 Article 21(2)(d), which requires supply chain security measures addressing the relationship between each entity and its direct suppliers and service providers. ENISA notes that many healthcare data breaches originate from third-party supplier vulnerabilities, making procurement-phase cybersecurity controls a material risk reduction lever. Member state supervisory authorities are expected to reference the guidelines as good practice when assessing healthcare organisations' NIS2 compliance, particularly for supply chain security measures. Organisations that adopt the guidelines' procurement requirements can reference them in their NIS2 compliance documentation as evidence of measures addressing Article 21(2)(d).

What it means for your business

If you are a hospital, clinic, or healthcare provider subject to NIS2 as an essential entity: Review the ENISA procurement guidelines against your current supplier contract templates and ICT procurement specifications. The guidelines provide a structured checklist for NIS2 Article 21(2)(d) supply chain security obligations, and adopting them strengthens your compliance documentation ahead of the sector-specific requirements under Commission Implementing Regulation (EU) 2024/2690 that apply from 18 January 2027. If you are an ICT supplier to the healthcare sector: Expect procurement teams at hospital and clinic customers to introduce NIS2-aligned cybersecurity requirements into tender documents and contract terms based on the ENISA guidelines. Review your security documentation, incident response procedures, and software supply chain controls against the guidelines' supplier requirements. If you handle patient data or operate medical devices connected to hospital networks: Supply chain security controls under NIS2 apply to your contractual relationship with the healthcare operator. Assess your NIS2 obligations with Verdaio's NIS2 Quick Check.

Commission Publishes Final Guidelines on Article 50 AI Act Transparency Obligations

On 20 July 2026, the European Commission published final guidelines on transparency obligations under Article 50 of the EU AI Act, clarifying what providers and deployers of certain AI systems must disclose to users starting 2 August 2026. The guidelines cover AI interaction disclosure, machine-readable marking of synthetic content, deepfake labelling, and emotion recognition notices. Maximum penalties reach EUR 15 million or 3% of global annual turnover. The deadline to register as a Code of Practice signatory was 22 July 2026 at 18:00 CET.

What changed

On 20 July 2026, the European Commission published its final Guidelines on the transparency obligations for providers and deployers of certain AI systems under Article 50 of the EU AI Act (Regulation (EU) 2024/1689). Article 50 obligations apply from 2 August 2026, thirteen days after the guidelines were issued. The guidelines address four categories of transparency obligation. Under Article 50(1), providers of AI systems that interact directly with humans must inform users that they are interacting with an AI system, unless this is obvious from context or the system is used for authorised law enforcement purposes; the guidelines clarify what "obvious from context" means and what minimum disclosure language satisfies the obligation. Under Article 50(2), providers of AI systems that generate synthetic audio, image, video, or text content must mark those outputs as artificially generated in a machine-readable format where technically feasible; the guidelines specify which marking formats and metadata standards are accepted and how the technical feasibility assessment should be documented. Under Article 50(4), providers and deployers of AI systems that generate or manipulate image, audio, or video content depicting real or realistic-looking persons must label such content as artificially generated or manipulated; the guidelines address deepfake and synthetic media labelling requirements, including display requirements for consumer-facing output. Under Article 50(3), providers of emotion recognition and biometric categorisation systems must notify users of the system's operation. The guidelines also address Article 50(5), which requires GPAI model providers to equip downstream providers with the information needed to fulfil their own Article 50 obligations.

The Commission's guidelines were issued thirteen days before the Article 50 application date of 2 August 2026, leaving a short implementation window for providers and deployers not yet compliant. Two transitional provisions are relevant. First, AI systems already lawfully placed on the market or put into service before 2 August 2026 must comply with Article 50 marking and labelling obligations (Articles 50(2) and (4)) by 2 December 2026 under the AI Omnibus agreement adopted by Council on 29 June 2026 and awaiting Official Journal publication; Article 50(1) and (3) interaction disclosure and emotion recognition notice obligations still apply from 2 August 2026 regardless of when the system was first deployed. Second, the signatory deadline for the EU AI Office's Code of Practice on Transparency of AI-Generated Content, whose adequacy was confirmed by Commission Opinion and AI Board Assessment on 8 and 9 July 2026 respectively, closed on 22 July 2026 at 18:00 CET. Organisations that signed by that deadline benefit from a presumption of conformity with Articles 50(2), (4), and (5) from 2 August 2026. The guidelines confirm that the presumption of conformity shifts the evidentiary burden in enforcement proceedings. Maximum penalties for Article 50 violations are set by member states at up to EUR 15 million or 3% of global annual turnover.

What it means for your business

If you provide or deploy any AI system that generates synthetic content, interacts with users, recognises emotions, or categorises users biometrically: Article 50 transparency obligations apply from 2 August 2026. Review the Commission's guidelines against each Article 50 category relevant to your system: interaction disclosure (Article 50(1)), machine-readable synthetic content marking (Article 50(2)), deepfake and manipulated media labelling (Article 50(4)), and emotion recognition or biometric categorisation notice (Article 50(3)). If you signed the Code of Practice on Transparency of AI-Generated Content by 22 July 2026, you benefit from a presumption of conformity with Articles 50(2), (4), and (5); demonstrate independent Article 50 compliance through technical documentation if you did not sign. If you provide a GPAI model whose outputs are used by downstream providers or deployers: Article 50(5) requires you to equip downstream operators with the information needed to comply with their own transparency obligations; review your API documentation and model cards against the guidelines' Article 50(5) requirements. If your AI system was already on the market before 2 August 2026: The legacy system grace period to 2 December 2026 applies for Articles 50(2) and (4) marking and labelling obligations under the AI Omnibus agreement; Article 50(1) and (3) obligations still apply from 2 August 2026. Assess your EU AI Act obligations with Verdaio's AI Act Quick Check.

Italian Garante Fines WINDTRE EUR 1.7 Million for Security Failures Behind Two GDPR Data Breaches

On 16 July 2026, the Italian data protection authority (Garante) published its decision fining WINDTRE EUR 1,715,600 for two data breaches notified in February 2025. Hackers posed as IT support technicians to trick store employees into granting system access, exfiltrating data on over 365,000 customers; 41,359 also had payment data stolen. The Garante found WINDTRE violated GDPR Articles 5(1)(f) and 32 and ordered security improvements including strengthened credential management.

What changed

On 16 July 2026, the Italian data protection authority (Garante per la Protezione dei Dati Personali) published Newsletter No. 549, reporting its decision (adopted 14 May 2026, docweb 10263796; published docweb 10272004) to fine WINDTRE S.p.A. EUR 1,715,600 for violations of the General Data Protection Regulation arising from two data breaches notified to the Garante in February 2025. The two breaches shared a common root cause: attackers used social engineering to pose as IT support technicians and persuaded store employees to grant them access to WINDTRE's internal systems under the pretext of resolving technical issues. Once access was granted, the attackers exfiltrated personal data belonging to over 365,000 WINDTRE customers, including names, contact details, and account information. In a subset of 41,359 affected customers, the data stolen also included payment data: postal money order details, IBAN numbers, and partially obscured credit card numbers. The Garante found that WINDTRE had violated Article 5(1)(f) of the GDPR, which requires processing of personal data to be carried out in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage (the integrity and confidentiality principle). The Garante also found a violation of Article 32 GDPR, which requires controllers to implement appropriate technical and organisational security measures taking into account the state of the art, implementation costs, and the nature, scope, context, and purposes of processing, as well as the risk to the rights and freedoms of natural persons.

In its assessment, the Garante found that WINDTRE's internal security audits had failed to identify the vulnerabilities that enabled the social engineering attacks: specifically, inadequate employee training on social engineering vectors, insufficient verification procedures for IT support access requests, and a credential management framework that permitted external actors to leverage employee cooperation to bypass technical security controls. The authority ordered WINDTRE to take corrective action: to strengthen its credential and certificate management procedures to prevent similar social engineering attacks; to implement secure password management tooling; and to reinforce employee security awareness training targeting social engineering and IT impersonation scenarios. The EUR 1,715,600 fine reflects the Garante's assessment of the severity of the breach, the number of affected data subjects, and the categories of data compromised, including payment data. WINDTRE's cooperation with the investigation and remedial steps taken following the breach notification were treated as mitigating factors. The decision reinforces the Garante's focus on social engineering as a recognised and foreseeable threat vector that operators must address in their security frameworks under GDPR Article 32, and adds to a series of enforcement actions in the telecommunications sector targeting inadequate security measures.

What it means for your business

If you operate in a sector where employees have access to customer data management systems (telecommunications, financial services, retail, healthcare, utilities): The Garante's WINDTRE decision identifies social engineering and IT support impersonation as a GDPR Article 32 risk that operators are expected to mitigate. Audit whether your employee security awareness training covers social engineering scenarios and whether your procedures for granting system access in response to support requests include verification steps that cannot be bypassed by social engineering. If you hold payment data or financial information belonging to customers: The presence of payment data (IBAN, partial card data) among the exfiltrated records was an aggravating factor in the Garante's fine calculation. Segment and restrict access to payment data more tightly than general customer data; apply a need-to-know principle and minimise which employees or systems can access IBAN and card data stores. If you are a DPO, security lead, or compliance officer preparing a GDPR security assessment under Article 32: The Garante held that an operator's internal security audits must be capable of identifying social engineering vulnerabilities. Document your threat modelling process to show that social engineering is treated as a foreseeable attack vector, and record the controls implemented in response. Map your GDPR security obligations with Verdaio's GDPR Quick Check.

EDPB Calls for EU Legal Basis for Cross-Regulatory Enforcement Information Sharing

On 17 July 2026, the European Data Protection Board published a statement calling on EU co-legislators to introduce a specific and clearly delimited legal basis enabling competent authorities under sectoral EU regulations to share personal data with data protection supervisory authorities for enforcement coordination purposes. The EDPB identified the absence of such a basis as a structural gap that impedes effective cross-regulatory enforcement across the AI Act, Digital Markets Act, DORA, and other frameworks.

What changed

On 17 July 2026, the European Data Protection Board adopted and published a statement calling for EU co-legislators to introduce a specific legal basis in EU law for cross-regulatory information sharing between data protection supervisory authorities and competent authorities under other EU regulatory frameworks. The statement addresses a structural gap identified by the EDPB: where enforcement of sector-specific EU regulations (including the EU AI Act, the Digital Markets Act, DORA, NIS2, and the AML Regulation) requires coordination with data protection authorities, the absence of a clear GDPR-compatible legal basis for sharing personal data obtained during enforcement investigations prevents effective coordination. Under the current legal framework, enforcement authorities investigating violations that span multiple regulatory domains cannot freely share information and evidence without risking a GDPR violation, as there is no specific legal basis authorising such transfers of personal data between regulators. The EDPB called on EU co-legislators to legislate a narrowly defined, purpose-limited legal basis for information sharing in enforcement cooperation contexts, accompanied by appropriate safeguards including proportionality requirements, purpose limitation, data minimisation, and security obligations. The statement reflects the EDPB's role as an institution with cross-cutting relevance to all regulatory frameworks that involve personal data processing, and its engagement in the broader debate on how EU regulatory bodies can coordinate enforcement without creating GDPR risk.

The EDPB statement follows calls from multiple EU bodies, including the AI Board and national data protection authorities, for closer enforcement cooperation at the intersections of data protection, AI governance, financial stability, and digital markets regulation. EU enforcement of the AI Act, the Digital Markets Act, DORA, and NIS2 routinely involves personal data that is also subject to GDPR, and investigations under any of these frameworks can uncover facts relevant to another authority's enforcement mandate. The practical effect of the current gap is that enforcement coordination between a national market surveillance authority under the AI Act and a supervisory authority under GDPR, or between the European Banking Authority under DORA and a national data protection authority, is legally uncertain. Once a legal basis is introduced, these information flows will be permissible within defined limits, enabling more systematic joint enforcement. The EDPB statement does not create new compliance obligations for businesses. However, it signals the direction of travel in EU regulatory enforcement: coordination between sectoral regulators and data protection authorities is expected to intensify as EU co-legislators respond to the Board's call. Businesses operating across multiple EU regulatory frameworks should treat compliance with each framework as interconnected rather than siloed.

What it means for your business

If you are subject to supervisory investigations, audits, or information requests under the AI Act, DMA, DORA, NIS2, or AML Regulation, and also process personal data subject to GDPR: The EDPB statement signals that once a legal basis for cross-regulatory information sharing is in place, findings from one regulatory investigation may be shared with data protection supervisory authorities, and vice versa. Maintain consistent, accurate, and complete records across all regulatory filings, as inconsistencies between regulatory submissions and GDPR records will become more visible under coordinated enforcement. If you are an AI system provider or deployer subject to both the EU AI Act and GDPR: AI Act enforcement by national market surveillance authorities and GDPR enforcement by supervisory authorities are already substantively linked, as high-risk AI systems typically involve personal data processing. Expect these enforcement streams to become formally coordinated once cross-regulatory information sharing is authorised in EU law. If you are a financial entity subject to DORA and also process personal data under GDPR: DORA incident reporting and digital resilience testing obligations generate operational data that may intersect with GDPR. Align your DORA and GDPR compliance frameworks now to avoid exposure when cross-regulatory sharing is formalised. Map your GDPR obligations with Verdaio's GDPR Quick Check.

Commission Issues Two Binding DMA Specification Orders Targeting Google Android AI and Search Data Access

On 16 July 2026, the European Commission adopted two binding specification measures under the Digital Markets Act against Google, requiring it to open 11 Android AI features to competing providers on equal terms to its Gemini assistant, and to share anonymised search data with rival search engines and AI chatbots on FRAND terms. Google disputed both decisions, citing privacy and security concerns.

What changed

On 16 July 2026, the European Commission adopted two sets of binding specification measures under Article 8 of the Digital Markets Act (Regulation (EU) 2022/1925) against Google, which has been designated as a gatekeeper for Android OS, Google Search, Google Play, and related core platform services. The first specification targets Android AI interoperability: Google must grant competing AI service providers access to 11 defined Android system features on equal and non-discriminatory terms to those available to Google's own Gemini AI assistant. The specified features include voice activation and wake-word commands, cross-app action execution capabilities, access to on-device contextual data (including the content of the active screen and push notifications), integration with Android accessibility services, and system-level app management functions. The Commission set a primary deadline aligned with the next major Android release (Android 18, expected in the second half of 2026 or early 2027), with a hard deadline of 1 August 2027 for all 11 features. The DMA's non-discrimination obligation requires gatekeepers to grant third-party business users access to core platform services on terms no less favourable than those the gatekeeper grants to its own services. The specification translates this obligation into concrete technical requirements for the Android AI ecosystem.

The second specification targets Google Search data access: Google must provide anonymised query, click, and ranking data from its Search index to rival search engines and AI applications operating in the EU that seek to compete with Google Search. The Commission required provision on fair, reasonable, and non-discriminatory (FRAND) terms, with implementation starting from January 2027. The anonymisation methodology was developed with privacy and data protection experts and is stated to be aligned with guidelines issued jointly by the DMA enforcement team and relevant data protection regulators on data interoperability. Google publicly disputed both decisions. On Android AI interoperability, Google raised privacy and security objections, arguing that the specified features involve sensitive on-device data that could be misused by third-party AI providers. On search data sharing, Google cited the risk of sharing proprietary search data with entities outside EU jurisdiction and argued the specification exceeded the DMA's mandate. The Commission published both decisions in the Digital Markets Act portal and set formal compliance timelines. Non-compliance with a binding specification measure under the DMA can result in fines of up to 10 percent of global annual turnover.

What it means for your business

If you develop AI services or virtual assistants for Android: From the Android 18 release deadline (no later than 1 August 2027), Google must provide your product access to 11 Android system features on the same terms available to Gemini. Review the Commission's specification decision to identify which Android integration capabilities are now mandated, and plan your technical integration roadmap to leverage these openings. If you operate a search engine or AI chatbot that competes with Google Search in the EU: From January 2027, you may formally request access to anonymised Google Search data under FRAND terms. Begin assessing the technical and commercial requirements of a data access request and evaluate whether the Commission's anonymisation framework satisfies your data quality needs. If you are a large platform or gatekeeper under the DMA: This specification sets a precedent for how the Commission will enforce non-discrimination and interoperability obligations through binding technical measures. Audit your existing interoperability commitments under your DMA designation against this standard before the Commission issues similar specifications to you. Assess your digital platform obligations with Verdaio's GDPR Quick Check.

CJEU Rules Google Cannot Invoke Hosting Liability Exemption for YouTube Revenue-Sharing Partner Channels

On 16 July 2026, the Court of Justice ruled in Case C-421/24 (AGCOM v. Google Ireland) that Google cannot rely on the e-Commerce Directive's hosting liability exemption for YouTube channels whose content it reviewed before entering a commercial revenue-sharing partnership. A platform that exercises prior editorial review for commercial purposes loses its passive intermediary status and cannot claim immunity from liability for infringing content on those channels.

What changed

On 16 July 2026, the Court of Justice of the European Union issued its judgment in Case C-421/24 (AGCOM v. Google Ireland Ltd and Others), addressing a dispute that arose from Italy's communications regulator AGCOM fining Google Ireland EUR 750,000 in July 2022 for failing to remove YouTube videos posted by a revenue-sharing partner channel that promoted online gambling in breach of Italian law prohibiting gambling advertising. Google Ireland contested the fine, arguing it was entitled to the hosting liability exemption under Article 14 of Directive 2000/31/EC (the e-Commerce Directive) as an online platform that stores third-party content at the user's request. The referring Italian court asked the CJEU to clarify: (1) whether online gambling advertising fell within the scope of the Directive even where gambling services themselves are excluded from its scope; and (2) whether Google could invoke the hosting exemption for content on a channel with which it had entered a commercial revenue-sharing partnership after reviewing the channel's content theme, most-viewed videos, and metadata. The Court answered both questions against Google. On scope, the Court held that online advertising for gambling falls within the e-Commerce Directive's scope as an information society service, even though gambling services themselves are excluded. On liability, the Court held that a platform that has reviewed a channel's content before entering a commercial partnership that generates joint revenue cannot claim to be a passive, neutral host in respect of content on that channel.

The CJEU's finding on platform liability status has significant implications beyond gambling content, and directly informs how the Digital Services Act (DSA) is interpreted. The judgment establishes that where a platform exercises prior editorial review of a creator's content profile for commercial purposes - for example, by screening channels, videos, or posts before accepting them into a revenue or partnership programme - the platform may lose its status as a passive host entitled to the intermediary liability exemption for content on those accounts. The DSA, which replaced the e-Commerce Directive's liability framework for online platforms from February 2024, incorporates the same underlying passive/active host distinction in its approach to illegal content liability. While the judgment interprets the e-Commerce Directive rather than the DSA directly, EU courts and regulators will apply the CJEU's reasoning when determining whether a platform's conduct triggers active host status under DSA Article 6. Platform operators should note that commercial screening practices - including creator programme admissions, partner channel reviews, or monetisation eligibility checks - are now at heightened risk of being characterised as prior editorial review that eliminates the hosting liability safe harbour for content on those accounts.

What it means for your business

If you operate a video, content, or social platform that runs a revenue-sharing, partner, or creator programme: This judgment indicates that screening or reviewing creator channel content, themes, or past videos as part of a commercial partnership admission process may eliminate your hosting liability exemption for content posted on those channels. Review your partner programme admission criteria and procedures, and assess whether your screening practices constitute prior editorial review under the CJEU's standard. If you are a brand, advertiser, or network that uses influencer or partner channels on video platforms to reach audiences: The judgment creates new pressure on platforms to regulate partner channel content more closely. Monitor whether platforms update their partner programme terms and content policies in response to this ruling, as those changes will affect creator contracts and content permissions. If you provide legal or compliance counsel to platform operators: The CJEU's passive/active host distinction under the e-Commerce Directive now applies with additional clarity to commercial screening practices. Map each of your client's commercial programme admission procedures against the CJEU's test and advise on whether liability exemptions are preserved. Assess your platform compliance obligations with Verdaio's GDPR Quick Check.

EU AI Office Expert Panel Flags Training Data Legal Uncertainty as Top Frontier AI Barrier

On 15 July 2026, the EU AI Office published findings from a panel of over 100 experts on frontier AI, identifying computing infrastructure and energy access as the most urgent two-year priorities for European competitiveness, and calling for greater legal certainty on copyright and data protection for AI training data. The report warns that the next one to two years may be decisive for Europe's position in frontier AI.

What changed

On 15 July 2026, the European Commission's AI Office published a consolidated report of findings from a structured consultation involving over 100 experts on frontier AI, including representatives from research institutions, AI developers, technology companies, and policy specialists. The report was commissioned as part of the EU's AI Continent Action Plan and is intended to inform both policy responses to frontier AI and the AI Office's approach to general-purpose AI model oversight under the EU AI Act. Key findings from the expert panel: frontier AI capabilities have advanced significantly in a compressed timeframe, with systems moving from limited task performance to approaching saturation on standard benchmarks within approximately three years; Europe's overall position in frontier AI development remains modest relative to its economic weight and research base; experts identified two-year priorities as computing infrastructure access and energy capacity, citing that European AI developers consistently face insufficient access to large-scale GPU compute clusters and adequate power supply as the primary practical barriers to frontier AI training runs; and the report characterises these as the most urgent constraints on European frontier AI competitiveness and calls for coordinated EU-level action on compute access and energy permitting. The report also places the training data legal framework among the top structural concerns identified by experts, alongside compute and energy.

The AI Office report identified legal uncertainty around training data as a structural concern for frontier AI development in the EU. Experts flagged that the intersection of EU copyright law (including the text and data mining exceptions under Directive (EU) 2019/790) and GDPR data minimisation and purpose limitation obligations creates ambiguity for AI developers seeking to assemble large-scale training datasets from EU-based sources. The uncertainty affects both EU-established AI developers and non-EU companies seeking to use EU-based data for training. Experts called for regulatory clarification - either through guidance from the AI Office and relevant supervisory authorities, or through targeted legislative action - to provide a predictable legal framework for AI training data collection and use in the EU. The report characterises the next one to two years as potentially decisive for Europe's position in frontier AI: the window for establishing competitive frontier AI capabilities is narrowing, and policy decisions taken in this period on compute access, energy, training data, and talent retention will determine whether European organisations can maintain a meaningful role in frontier AI development. The findings directly inform the AI Office's work on the general-purpose AI model Code of Practice and upcoming AI Act enforcement posture, and are expected to feed into Commission legislative proposals expected in the second half of 2026.

What it means for your business

If you are an AI developer or researcher building or planning to build large AI models in the EU: The report's call for legal certainty on training data is directly relevant to your planning. The AI Office has signalled it is aware of the GDPR-copyright intersection problem for AI training and intends to address it through guidance or legislation. Monitor AI Office and EDPB outputs on training data guidance, and document your current training data provenance and legal basis now to be in a strong position when guidance or legislative clarification arrives. If you are a general-purpose AI model developer potentially in scope of the EU AI Act's GPAI provisions: The AI Office's frontier AI expert findings will shape the final Code of Practice for GPAI models, which is the primary compliance mechanism for GPAI providers under the AI Act. The emphasis on transparency obligations and training data documentation signals that these will be heavily weighted in the Code. If you are a business deploying or integrating AI models for EU-facing applications: The report indicates that EU frontier AI policy is entering a high-priority phase. Regulatory posture toward GPAI models and high-capability AI systems is expected to tighten as the AI Act's GPAI provisions come into full effect. Map your AI system obligations with Verdaio's AI Act Quick Check.

Commission Accepts X's Binding DSA Corrective Action Plan Following EUR 120 Million Fine for Three Platform Violations

On 15 July 2026, the European Commission announced it had accepted X's (formerly Twitter) binding corrective action plan under the Digital Services Act, following a EUR 120 million fine imposed in 2025 for three violations: deceptive "blue checkmark" design, inadequate ad repository transparency, and failure to provide researcher data access. X must implement the plan within six months and undergo independent compliance audits.

What changed

On 15 July 2026, the European Commission announced that it had accepted X's (formerly Twitter) binding corrective action plan submitted under the Digital Services Act (Regulation (EU) 2022/2065), formally terminating the Commission's enforcement proceedings related to three DSA violations for which X was fined EUR 120 million in 2025. The three violations concerned: first, X's "blue checkmark" verification system, which the Commission found operated as a deceptive interface design by presenting a paid verification symbol - "X Premium" subscribers' blue check - as equivalent to the prior identity-verified blue checkmark, misleading users about the authenticity and identity of accounts; second, X's ad transparency repository, which the Commission found did not provide sufficient searchability, display quality, or completeness of required advertising metadata under DSA Article 39; and third, X's researcher data access programme, which the Commission found applied screening criteria for researcher applications that were insufficiently transparent, resulted in processing delays inconsistent with DSA Article 40, and excluded researchers from data access on grounds not provided for in the DSA. The accepted action plan requires X to address all three violation areas through binding commitments with defined timelines and mandatory independent audit requirements.

Under X's accepted corrective action plan, X must: revise the display and labelling of its paid verification product to clearly distinguish it from identity-based verification; improve the ad repository's search filters, data completeness, and response times to meet DSA Article 39 requirements; revise its researcher application screening criteria to be transparent and objectively justified; process researcher data access applications within timelines consistent with the DSA; provide eligible researchers with access to at least the public data access package free of charge; and update its platform terms to not prohibit scraping of publicly available data for eligible research purposes. X must implement the plan within six months of acceptance and is subject to mandatory independent compliance audits. The Board for Digital Services - an advisory body composed of national Digital Services Coordinators - had previously found X's proposed action plan inadequate. The Commission proceeded to acceptance after requiring X to clarify and strengthen several commitments. The acceptance terminates the enforcement proceedings on the three violations but does not preclude new proceedings if X fails to implement the plan or commits new violations.

What it means for your business

If you operate a very large online platform or search engine designated under the DSA: The Commission's acceptance of X's corrective action plan signals how it will evaluate platform remediation proposals. Deceptive interface design (dark patterns under DSA Article 25), incomplete ad repository compliance (Article 39), and researcher access failures (Article 40) are active enforcement targets. Review your platform's interface design, ad repository completeness, and researcher data access programme against these requirements before an investigation is opened against you. If you are a researcher seeking data access from very large online platforms under DSA Article 40: X's accepted action plan includes commitments to provide a free public data access tier and transparent application criteria. This sets a benchmark that researchers can cite when requesting data access from other DSA-designated platforms. If you are a brand, agency, or compliance team assessing ad transparency obligations: The Commission's enforcement of the ad repository requirement under DSA Article 39 confirms it is actively monitored. Verify that all platforms on which you place advertising maintain a DSA-compliant ad repository and keep records of your own ad placements and targeting parameters. Assess your digital platform compliance with Verdaio's GDPR Quick Check.

CJEU Rules Anti-Doping Athlete Name Publication Requires Individual GDPR Proportionality Assessment Before Each Disclosure

On 14 July 2026, the Court of Justice ruled in Case C-474/24 (NADA Austria) that EU Member States may legislate to permit publication of anti-doping rule violators' names and sanction details online, but only if the responsible organisation individually weighs competing interests before each publication. Blanket automatic disclosure without individual assessment violates GDPR, and continued online publication after the sanction period expires is disproportionate.

What changed

On 14 July 2026, the Court of Justice of the European Union issued its judgment in Case C-474/24 (National Anti-Doping Agency (NADA) Austria v. others), addressing the compatibility with GDPR of Austrian national legislation permitting the publication of athletes' names, sanction durations, and grounds for anti-doping rule violations on publicly accessible internet platforms. The referring Austrian court asked the CJEU whether EU law, including GDPR, precluded national anti-doping legislation that required the automatic publication of such information for all anti-doping rule violations without requiring the responsible organisation to conduct an individual assessment of competing interests in each case. The Court held that EU Member States may, in principle, legislate to permit sports anti-doping organisations to publish athletes' names, sanction periods, and violation grounds on publicly accessible internet platforms. Such processing is capable of falling within the legitimate interests exception under GDPR Article 6(1)(f) when pursued for anti-doping integrity and deterrence purposes, or within a specifically enacted legal basis under Article 6(1)(c) or (e). However, the Court attached two conditions to permissible publication. First, the responsible organisation must carry out an individual balancing of competing interests before each publication. The automatic and undifferentiated publication of all violators' details without case-by-case assessment of factors such as the severity of the violation, the nature of the sanction, and the athlete's circumstances is not compatible with the GDPR's proportionality requirements under Article 5(1)(c) (data minimisation) and Article 17 (right to erasure).

The Court's second condition is that the continued publication of an athlete's name and violation details on a publicly accessible internet platform after the sanction period has expired is disproportionate under GDPR and must be discontinued. Once the sanction has run, the public interest in disclosure no longer outweighs the data subject's rights, and organisations must remove or anonymise the published information. The judgment has direct implications for national sports anti-doping organisations, sports federations, and sports governing bodies across the EU that operate online sanction registries or publish disciplinary records. These bodies must establish individual assessment procedures before each disclosure and implement automated or manual removal processes on sanction expiry. More broadly, the judgment contributes to the CJEU's developing jurisprudence on the limits of public transparency interests when balanced against GDPR data subject rights. Organisations that publish personal data in enforcement or disciplinary contexts citing public interest or transparency grounds should review whether their disclosure practices include individual proportionality assessments and expiry-triggered removal procedures.

What it means for your business

If you operate a sports anti-doping organisation, sports federation, or national governing body that publishes sanction information involving athletes' names: This judgment requires you to implement an individual proportionality assessment before each publication of an athlete's name and violation details. Blanket automatic publication policies are not compatible with GDPR as interpreted by the CJEU. Review your sanctions publication procedures and introduce documented individual assessments. Also implement a sunset mechanism: remove or anonymise published entries when the sanction period expires. If you operate any public register, disciplinary registry, or transparency publication that discloses personal data on the basis of public interest or legitimate interests: The CJEU's proportionality analysis applies beyond the anti-doping context. Any blanket disclosure policy that does not include an individual interests-balancing step is at risk of GDPR challenge. Review your disclosure framework against the CJEU's two-condition standard: individual assessment before publication, and removal on expiry of the relevant period. If you are a data protection officer at a public body, regulator, or membership organisation that publishes enforcement or disciplinary outcomes: This ruling adds to the body of CJEU authority on when public transparency interests can override individual data protection rights. Audit your existing publications and introduce case-by-case review where it is currently absent. Map your GDPR obligations with Verdaio's GDPR Quick Check.

ENISA Publishes Free CRA Maturity Assessment Tool for SME Manufacturers

On 13 July 2026, ENISA published a free Cyber Resilience Act SME Maturity Assessment Model, providing small and medium-sized enterprises with a structured self-assessment framework to evaluate their cybersecurity practices against CRA requirements. The tool covers CRA obligations for security-by-design, vulnerability management, and incident reporting, produces a maturity score across four pillars, and provides prioritised remediation guidance. The CRA incident and vulnerability reporting deadline is 11 September 2026; full CRA obligations apply from 11 December 2027.

What changed

On 13 July 2026, the European Union Agency for Cybersecurity (ENISA) published the Cyber Resilience Act SME Maturity Assessment Model, a free structured self-assessment tool designed to help small and medium-sized enterprises evaluate their cybersecurity practices against the requirements of Regulation (EU) 2024/2847 (the Cyber Resilience Act, CRA). The CRA imposes mandatory security requirements on manufacturers and suppliers of products with digital elements placed on the EU market. Core obligations include security-by-design and default requirements under Article 13 (covering security policies, access controls, vulnerability handling, and encryption); coordinated vulnerability disclosure and reporting under Article 14, including early warning notification to ENISA within 24 hours of a manufacturer becoming aware of an actively exploited vulnerability or a CRA-related incident; and a minimum five-year security support period for product updates. The ENISA SME Maturity Assessment Model structures the self-assessment across four pillars: security requirements for product design and development; vulnerability management and disclosure; incident detection and response; and documentation and conformity assessment. For each pillar, the tool provides a structured questionnaire, defines five maturity levels (initial, developing, defined, managed, optimised), and produces a scored output with prioritised remediation steps. ENISA published the tool free of charge to support SME manufacturers that may lack internal cybersecurity expertise ahead of the first CRA compliance date of 11 September 2026, when Article 14 incident and vulnerability reporting obligations begin to apply.

The CRA has a staggered implementation timeline. Article 14 obligations for incident and vulnerability reporting to ENISA apply from 11 September 2026. Full CRA obligations, including security-by-design, vulnerability management, and documentation requirements, apply from 11 December 2027. Manufacturers of products with digital elements placed or to be placed on the EU market are within scope; the CRA defines "product with digital elements" broadly to cover hardware and software products whose intended use includes direct or indirect logical or physical data connection to a network or another device. The ENISA maturity assessment tool is designed specifically for SMEs, which are disproportionately represented among CRA-in-scope manufacturers but least likely to have dedicated compliance resources. The tool complements ENISA's broader CRA guidance and work on harmonised standards under CRA Article 27, which will provide a presumption of conformity when fulfilled. ENISA has indicated the tool will be updated as implementing acts and harmonised standards under the CRA are finalised; manufacturers should monitor the ENISA CRA publications page for updates before the September 2026 and December 2027 deadlines.

What it means for your business

If you manufacture or supply products with digital elements placed or to be placed on the EU market (including software, IoT devices, connected consumer goods, or industrial control systems): CRA Article 14 reporting obligations for actively exploited vulnerabilities and CRA-related incidents apply from 11 September 2026. Use the free ENISA SME Maturity Assessment Model to benchmark your current practices against CRA requirements and identify gaps before that date. The tool provides a structured questionnaire, five maturity levels per pillar, and prioritised remediation guidance. If you are an SME with limited internal cybersecurity expertise: The ENISA tool is designed for your context. Complete the self-assessment across all four pillars (security design, vulnerability management, incident response, and documentation) before the September 2026 reporting deadline to identify your highest-priority gaps. If you are a larger enterprise sourcing hardware or software components from SME manufacturers: CRA Article 13 supply chain security obligations require you to assess and manage the security practices of your digital product suppliers. Share the ENISA tool with SME suppliers as a common reference framework for assessing their CRA readiness before the December 2027 full compliance date. Assess your CRA and NIS2 obligations with Verdaio's NIS2 Readiness Assessment.

EDPB Requires Belgian DPA to Examine NOYB Cookie Banner Complaint Against VRT on Merits

On 14 July 2026, the European Data Protection Board published Binding Decision 1/2026 (adopted 28 May 2026), ordering the Belgian data protection authority to handle on the merits noyb's GDPR complaint against Belgian public broadcaster VRT. The Belgian DPA had dismissed the complaint as an "abuse of rights." The EDPB, acting by two-thirds majority under GDPR Article 60(3), found the dismissal impermissible and directed the Belgian DPA to proceed with a substantive examination of whether VRT's cookie banner complies with GDPR.

What changed

On 14 July 2026, the European Data Protection Board published Binding Decision 1/2026, adopted on 28 May 2026 pursuant to GDPR Article 60(3). The decision resolves a dispute between the Austrian privacy organisation noyb (None Of Your Business) and the Belgian data protection authority (Autoriteit Persoonsgegevens/Gegevensbeschermingsautoriteit, APD/GBA). Noyb had filed a GDPR complaint against VRT (Vlaamse Radio- en Televisieomroeporganisatie), the publicly funded Belgian broadcaster, alleging that VRT's cookie consent banner did not comply with the requirements of GDPR Articles 5(1)(a) (lawfulness, fairness, transparency), 6(1) (lawfulness of processing), and 7 (conditions for consent). The Belgian DPA dismissed noyb's complaint as an "abuse of rights" under national procedural law, without examining whether VRT's cookie banner processing was substantively compliant with the GDPR. Noyb objected to this dismissal and referred the objection to the EDPB under the consistency mechanism of Article 60 GDPR. The EDPB found that the Belgian DPA's decision to dismiss a GDPR complaint as an "abuse of rights" without conducting a substantive examination was impermissible under GDPR Article 60(3). The Board held that supervisory authorities cannot dismiss a complaint by relying on a national procedural rule in a way that undermines the substance of the data subject's right to lodge a complaint under GDPR Article 77, and that the data subject's right to an effective remedy under Article 79 requires a supervisory authority to examine the complaint on the merits. The EDPB, acting by a two-thirds majority vote as required under Article 60(3), issued a binding decision directing the Belgian DPA to handle noyb's complaint on the merits and conduct a substantive examination of VRT's cookie banner practices under GDPR.

EDPB Binding Decision 1/2026 has two principal implications. First, it constrains supervisory authority discretion to dismiss GDPR complaints on procedural grounds. The decision confirms that national procedural rules such as "abuse of rights" provisions cannot be applied to block a substantive examination of whether a data controller complies with the GDPR; the data subject's right to lodge a complaint under Article 77 and the right to an effective remedy under Article 79 require supervisory authorities to examine complaints substantively. This reinforces the principle that GDPR supervisory enforcement is not purely discretionary: a complaint that raises plausible grounds of GDPR non-compliance must receive a reasoned decision on the merits. Second, the decision advances enforcement against cookie banner practices across the EU. VRT's cookie banner will now be examined by the Belgian DPA on substantive GDPR grounds, including whether consent obtained through its banner architecture meets the conditions of Article 7 (freely given, specific, informed, unambiguous) and whether the banner presents lawful processing options under Article 6(1). The outcome of the Belgian DPA's examination will be a substantive enforcement decision, with potential corrective measures and administrative fines under GDPR Article 83 if violations are found. Cookie banner enforcement has accelerated across the EU: the French CNIL, Spanish AEPD, and Irish DPC have all issued decisions and guidance on banner design in recent years. EDPB Binding Decision 1/2026 signals that supervisory authorities cannot use procedural dismissals to avoid substantive examination, reinforcing the enforcement pathway for cookie consent complaints across the EU.

What it means for your business

If you operate a website or digital service with a cookie consent banner targeting EU visitors: EDPB Binding Decision 1/2026 signals active enforcement against cookie banner practices across the EU. The decision requires the Belgian DPA to examine VRT's banner substantively for GDPR compliance, including whether consent is freely given, specific, informed, and unambiguous under Article 7, and whether processing relies on a valid legal basis under Article 6(1). Audit your cookie banner against these standards: reject-all options must be presented with the same prominence as accept-all; pre-ticked boxes and consent by scrolling are invalid; and consent must be as easy to withdraw as to give (Article 7(3) GDPR). If you use consent management platforms (CMPs) for cookie consent: Verify that your CMP configuration results in valid consent under GDPR Article 7. The EDPB's Cookie Guidelines (Guidelines 05/2020) and national DPA guidance from CNIL, AEPD, and others set the baseline; ensure your banner does not use dark patterns, false equivalence, or misleading UI that undermines the validity of consent. If you have received a GDPR complaint that a supervisory authority dismissed without substantive examination: Binding Decision 1/2026 establishes that such dismissals are subject to EDPB review under Article 60(3). If you are a complainant, the decision confirms you can object to procedural dismissals; if you are a controller, a previously dismissed complaint may be re-examined on the merits. Map your GDPR cookie consent obligations with Verdaio's GDPR Quick Check.

Commission Refers Ireland, Spain, France, and Netherlands to CJEU for NIS2 Transposition Failures

On 9 July 2026, the European Commission referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the EU for failing to transpose the NIS2 Directive (Directive (EU) 2022/2555) into national law by the 17 October 2024 deadline. The Commission had issued letters of formal notice on 28 November 2024 and reasoned opinions on 7 May 2025 with no sufficient response. The Commission asked the Court to impose financial sanctions, including a lump sum and daily penalty payments, until each member state notifies complete transposition.

What changed

On 9 July 2026, the European Commission announced it had referred Ireland, Spain, France, and the Netherlands to the Court of Justice of the European Union (CJEU) for failing to transpose Directive (EU) 2022/2555 (NIS2 Directive) into national law (Press Release IP/26/1499). The NIS2 Directive, which repeals and replaces the original Network and Information Security Directive (Directive (EU) 2016/1148), required member states to adopt and publish the national measures necessary to comply with its provisions by 17 October 2024 and to apply those measures from the same date (Article 41 NIS2). As of the referral date, all four member states had failed to achieve this. The Commission had previously issued letters of formal notice to the four states on 28 November 2024, the first formal step in infringement proceedings under Article 258 TFEU, notifying them of the breach of their transposition obligation. No sufficient response having been received, the Commission issued reasoned opinions on 7 May 2025, specifying the breach in detail and calling on each member state to complete transposition within a fixed period. With the four states still having failed to notify complete transposition, the Commission proceeded to the referral stage and is now asking the CJEU to impose financial sanctions under Article 260(3) TFEU: a lump sum calculated by reference to the duration and gravity of the infringement, and daily penalty payments to accrue from the date of the CJEU judgment until each member state notifies complete transposition of the NIS2 Directive.

The NIS2 Directive significantly expands the scope of mandatory cybersecurity obligations compared to its predecessor. Under NIS2, entities in 18 sectors designated as essential or important (including energy, transport, water, healthcare, digital infrastructure, banking, financial market infrastructure, public administration, and space) must implement cybersecurity risk management measures (Article 21 NIS2), including technical and organisational measures covering security policies, supply chain security, access controls, encryption, and incident detection and response, and must report significant incidents to national competent authorities within 24 hours (early warning) and 72 hours (incident notification) under Article 23 NIS2. The four member states subject to the referral have not fully incorporated these provisions into their national legal systems; businesses and other entities operating in those states in sectors covered by NIS2 cannot rely on a finalised national NIS2 legal framework. In practice, operators in Ireland, Spain, France, and the Netherlands have been operating in a gap period since October 2024, during which the NIS2 obligations are legally required but not yet transposed into national implementing legislation. The CJEU referral does not create new direct obligations for individual operators; however, member states facing daily financial penalties have a strong incentive to accelerate transposition. Ireland, Spain, France, and the Netherlands are expected to complete or substantially advance their national transposition processes in the months following the CJEU referral.

What it means for your business

If you operate in Ireland, Spain, France, or the Netherlands in a sector covered by NIS2 (energy, transport, water, healthcare, digital infrastructure, banking, financial market infrastructure, public administration, or space): The CJEU referral signals that national NIS2 transposition legislation is imminent in all four states. Monitor your national competent authority for the publication of implementing regulations; once transposed, you will be subject to the Article 21 security measures and Article 23 incident reporting obligations with minimal notice. Begin gap analysis against the NIS2 requirements now so you are ready to comply as soon as national law is in place. If you operate in other EU member states that have completed NIS2 transposition: The referral does not affect existing national obligations. However, if you have supply chain relationships with entities in the four referred states, note that those entities may not yet be subject to equivalent national NIS2 cybersecurity requirements, which may affect your own supply chain risk assessments under Article 21(2)(d) NIS2. If you provide digital infrastructure services, managed security services, or cloud services to entities in Ireland, Spain, France, or the Netherlands: Anticipate incoming NIS2 contractual requirements from customers in those states as national transposition advances and entities begin conforming their supplier contracts to NIS2 requirements. Map your NIS2 obligations with Verdaio's NIS2 Readiness Assessment.

Commission and AI Board Issue Adequacy Assessment of AI-Generated Content Transparency Code

On 8 July 2026, the European Commission issued a formal Opinion concluding that the Code of Practice on Transparency of AI-generated content, finalised by the EU AI Office on 10 June 2026, adequately covers the obligations under AI Act Article 50(2), (4), and (5). On 9 July 2026, the AI Board adopted its own Adequacy Assessment. Together, these assessments activate a presumption of conformity for signatories: organisations that adhere to the Code are presumed compliant with Article 50's transparency obligations. The signatory registration deadline is 22 July 2026 at 18:00 CET; Article 50 obligations apply from 2 August 2026.

What changed

On 8 July 2026, the European Commission published a formal Opinion on the assessment of the Code of Practice on Transparency of AI-generated content (the "Transparency Code"), which was finalised and adopted by the EU AI Office on 10 June 2026. The Commission's Opinion concludes that the Transparency Code adequately covers the obligations set out in Article 50(2), (4), and (5) of the EU AI Act (Regulation (EU) 2024/1689). On 9 July 2026, the AI Board adopted its own Adequacy Assessment reaching the same conclusion. Article 50 of the AI Act requires: providers of AI systems that interact with humans to disclose that the user is interacting with an AI, unless this is obvious from context (Article 50(1)); providers of AI systems that generate synthetic audio, image, video, or text content to mark the output as artificially generated in machine-readable formats where technically feasible (Article 50(2)); providers of emotion recognition or biometric categorisation systems to notify users (Article 50(3)); providers and deployers of AI systems that generate or manipulate image, audio, or video content resembling real persons to mark such content as artificially generated or manipulated (Article 50(4)); and providers of GPAI models to make available information necessary for compliance by downstream providers (Article 50(5)). The Transparency Code specifically addresses Articles 50(2), (4), and (5). Under AI Act Article 60(4), compliance with a Code of Practice whose adequacy has been formally confirmed creates a "presumption of conformity" with the corresponding obligations. The Commission's 8 July Opinion and the AI Board's 9 July 2026 Adequacy Assessment together activate this presumption for the Transparency Code. To be included on the initial signatory list and benefit from the presumption from 2 August 2026, organisations must register their sign-up with the EU AI Office by 22 July 2026 at 18:00 CET.

Article 50 transparency obligations enter into application on 2 August 2026, the same date as the general AI Act obligations for providers and deployers of prohibited-use and high-risk AI systems. Unlike high-risk obligations under Annex III, which the Digital Omnibus deal extends to December 2027 (pending publication in the Official Journal), Article 50 is not covered by that extension: transparency obligations for synthetic content and deepfake marking apply from 2 August 2026 without modification. Any provider or deployer of GPAI models or AI systems that generate or manipulate synthetic content within the scope of Article 50(2), (4), or (5) must be compliant by 2 August 2026. Signing the Code creates a presumption of conformity that shifts the evidentiary burden in enforcement proceedings; it does not replace compliance with Article 50 directly. Organisations that are within Article 50(2) and (4) scope but do not sign the Code must demonstrate compliance through their own technical documentation and disclosures. The EU AI Office indicated it may issue additional information requests to non-signatories within scope after 2 August 2026. Penalties for Article 50 violations are set by member states, with maximum levels required to be effective, proportionate, and dissuasive; the Code's signing deadline of 22 July 2026 and the Article 50 application date of 2 August 2026 leave a narrow window for organisations still assessing their signing position.

What it means for your business

If you provide or deploy AI systems that generate or manipulate synthetic audio, image, video, or text content (chatbots, image or video generation tools, voice synthesis, AI writing assistants): Article 50 transparency obligations under the EU AI Act apply from 2 August 2026. This deadline is not extended by the Digital Omnibus deal; the extension to December 2027 applies only to Annex III high-risk obligations. If your system falls within Article 50(2), (4), or (5) scope, you must implement machine-readable marking or disclosure by 2 August 2026. Assess whether to sign the Transparency Code before 22 July 2026 at 18:00 CET: signing creates a presumption of conformity and reduces enforcement risk. If you are a provider of a GPAI model (including models integrated into third-party products or services): Article 50(5) applies to your model's generated output. Assess whether the Code covers your output types and whether signing before the 22 July 2026 deadline is feasible. If you are within Article 50 scope but do not sign the Code: You must independently demonstrate Article 50 compliance through technical documentation and disclosure practices; the AI Office has indicated non-signatories within scope may receive information requests after 2 August 2026. Assess your AI Act obligations with Verdaio's EU AI Act Assessment.

CJEU Rules Criminal Conviction Databases Cannot Claim GDPR Journalism Exemption

On 9 July 2026, the Court of Justice of the EU ruled in Case C-199/24 (Legal Newsdesk Sweden AB) that operating a paid online database enabling searches on persons subject to criminal proceedings and allowing consultation of conviction decisions does not, in principle, constitute processing personal data for journalistic purposes under GDPR Article 85(2). The ruling means individuals retain their right to erasure against operators of commercial criminal-record databases that invoke the Article 85 journalism exemption to block deletion requests (CJEU, Press Release No. 100/26, 9 Jul 2026).

What changed

On 9 July 2026, the Court of Justice of the European Union delivered judgment in Case C-199/24 (Legal Newsdesk Sweden AB v Integritetsskyddsmyndigheten) (CJEU Press Release No. 100/26). The case arose from a Swedish company, Legal Newsdesk Sweden AB, operating a paid subscription database providing online access to Swedish court decisions, including criminal conviction records, enabling users to search for individuals by name and retrieve details of their criminal proceedings. The Swedish data protection authority (Integritetsskyddsmyndigheten, IMY) ordered the company to comply with an individual's request for erasure of a 2011 conviction from its database. Legal Newsdesk refused, invoking the journalism exemption under Chapter IX of the GDPR and the corresponding national exemption under Swedish law implementing GDPR Article 85(2), which permits member states to derogate from the GDPR's data subject rights (including the right to erasure under Article 17) for processing carried out for journalistic purposes, or for academic, artistic, or literary expression. The CJEU held that the journalism exemption cannot, in principle, apply to the operation of a paid database that makes historical criminal conviction records searchable by the identity of the data subject. The Court found that the essential purpose of the processing was commercial (providing a subscription service), not journalistic, and that the processing was not strictly necessary to achieve a journalistic objective. The exemption under Article 85(2) requires that the derogation from data subject rights is necessary to reconcile the right to data protection with freedom of expression and information; the CJEU determined that a paid commercial criminal record database does not meet this necessity test.

The judgment is significant for operators of databases containing personal data of identifiable individuals, in particular databases drawing on court records, public registers, or similar authoritative sources that may include criminal proceedings, sanctions, or enforcement actions. The ruling confirms that commercial access to historical criminal data does not benefit from the Article 85 journalism exemption even if the underlying source documents were public, and even if the database includes editorial annotations or commentary. Controllers that process personal data from court or administrative records as part of a commercial database must ground their processing in a valid legal basis under GDPR Article 6, satisfy the data minimisation and storage limitation principles under Article 5, and cannot block erasure requests by invoking the journalism exemption. For providers of compliance databases, business intelligence platforms, legal information services, or similar services that systematically collect and provide access to data about individuals derived from public proceedings, the judgment draws a clear boundary: commercial provision of searchable personal data from public sources is not journalism for GDPR purposes, and data subjects' Article 17 right to erasure must be respected unless another specific exemption applies. National data protection authorities across the EU and EEA are likely to reference C-199/24 in enforcement actions against commercial data aggregators that have previously relied on the journalism exemption to resist erasure and access requests.

What it means for your business

If you operate a database, information service, or business intelligence platform that provides searchable access to personal data derived from court records, criminal proceedings, administrative decisions, or public registers: The CJEU's judgment in C-199/24 rules out the GDPR Article 85(2) journalism exemption for commercial database operators. Audit whether your legal basis for processing personal data from public sources is adequate under GDPR Article 6 independent of any journalism exemption claim, and ensure your processes for handling Article 17 erasure requests are operational and compliant with the ruling. If you process personal data derived from criminal proceedings, sanctions, or enforcement decisions as part of a commercial product or service: Article 10 of the GDPR (processing relating to criminal convictions and offences) imposes additional restrictions. Criminal conviction data can only be processed under the control of official authority or when authorised by member state law; the commercial database model in C-199/24 is likely to face additional Article 10 scrutiny following this judgment. If you rely on the Article 85 journalism exemption to resist data subject rights requests in any processing context: The CJEU in C-199/24 confirms the exemption applies only where processing is strictly necessary to reconcile data protection with freedom of expression and information, and the primary purpose is genuinely journalistic, academic, artistic, or literary. Review whether your claimed exemption meets this strict necessity standard. Map your GDPR obligations with Verdaio's GDPR Quick Check.

Italian Garante Fines Character.AI €158,000 for Failing to Protect Minors Under GDPR

On 9 July 2026, the Italian data protection authority (Garante) fined Character.AI €158,000 for five GDPR violations relating to the protection of minors: inadequate age verification, no cooling-off period after banning a minor user, minor profiles not set to private by default, a late Data Protection Impact Assessment, and failure to appoint an EU representative under Article 27. The Garante ordered remedial action within 120 days.

What changed

On 9 July 2026 (decision dated 3 July 2026, document reference 10269571), the Garante per la Protezione dei Dati Personali (Italian data protection authority) issued a decision fining Character.AI €158,000 for violations of the GDPR in connection with the processing of personal data of minor users of its conversational AI platform. The Garante found five distinct violations: first, inadequate age verification mechanisms, which allowed minors to access the platform without effective controls commensurate with the risk that the platform's content and interaction model poses to minors; second, the absence of a mandatory cooling-off period following the ban of a minor user, enabling immediate re-registration and circumventing protective account restrictions; third, failure to set minor user profiles to private by default, contrary to the data protection by design and by default obligations under GDPR Article 25; fourth, failure to conduct a Data Protection Impact Assessment (DPIA) under GDPR Article 35 within the required timeframe, with the assessment completed late; and fifth, failure to appoint an EU representative under GDPR Article 27, which is mandatory for non-EU controllers that process personal data of EU data subjects on a systematic basis. The Garante issued remedial orders alongside the fine, requiring Character.AI to implement effective age verification, introduce a cooling-off period for minor re-registration, set minor profiles to private by default, and bring its EU representation into compliance, all within 120 days of the decision.

The Character.AI fine follows a period of heightened Garante scrutiny of AI conversational platforms; the authority restricted ChatGPT in 2023 and has since investigated multiple generative AI services for compliance with GDPR transparency, data minimisation, and age verification obligations. The five violations reflect a comprehensive theory of GDPR liability for consumer-facing AI platforms: the Garante applied not only the data protection by design and by default requirement of Article 25, but also the Article 27 EU representative requirement, which has historically been under-enforced for smaller non-EU technology companies but is receiving increasing attention from EU supervisory authorities as consumer-facing AI applications scale across the EU. The requirement to maintain a cooling-off period for banned minor users addresses circumvention risk specific to the AI chatbot context; the decision provides useful precedent for how GDPR Article 25 obligations translate into specific technical requirements for age-gated conversational AI services. Controllers offering similar conversational AI services to users in EU member states, in particular services accessible to or used by minors, should treat this decision as a benchmark for the minimum technical and organisational measures the GDPR requires.

What it means for your business

If you operate a consumer-facing AI platform, chatbot, or similar digital service accessible to minors across EU member states: The Garante's Character.AI decision establishes a GDPR compliance benchmark for age-gated AI services. As a minimum, implement effective age verification proportionate to the risk to minors, set minor profiles to private by default (Article 25), introduce a cooling-off period preventing banned minor users from immediately re-registering, and complete a DPIA under GDPR Article 35. If you are a non-EU controller processing personal data of EU data subjects on a systematic basis: The Article 27 EU representative requirement was among the five violations in this decision. Appoint an EU representative in writing, designate them as the point of contact for supervisory authorities, and inform data subjects of the representative's identity in your privacy notice. If you process personal data of minors under GDPR: Article 8 (age of consent for information society services) and Article 25 (data protection by design and by default) are increasingly enforced jointly. Review your age verification approach, default settings for minor users, and DPIA documentation against this decision. Use Verdaio's GDPR Quick Check to map your GDPR obligations.

EDPB Adopts Guidelines on Anonymisation, AI Web Scraping, and Blockchain at July Plenary

At its 122nd plenary on 8 July 2026, the European Data Protection Board (EDPB) adopted two draft sets of guidelines and one final text under GDPR. The drafts cover the legal concept of anonymous data, updated in light of CJEU judgment C-413/23 P, and the GDPR compliance of web scraping for generative AI; both are open for public consultation until 30 October 2026. The Board also adopted the final version of its guidelines on processing personal data through blockchain technologies (EDPB, press release, 8 Jul 2026).

What changed

On 8 July 2026, the European Data Protection Board (EDPB) concluded its 122nd plenary session by adopting three sets of guidelines under the GDPR. First, the Board adopted draft Guidelines on Anonymisation, updating the EDPB's position on the legal concept of anonymous data in light of CJEU judgment C-413/23 P (EDPS v SRB, 4 September 2025) and other relevant case law. The draft guidelines clarify the threshold for data to fall outside GDPR scope as truly anonymous, address risk-based and absolute approaches to anonymisation, and cover common techniques including aggregation, generalisation, and noise addition. Second, the Board adopted draft Guidelines on Web Scraping in the Context of Generative AI, clarifying the GDPR compliance requirements for large-scale automated data extraction from publicly available online sources for AI training purposes. The guidelines set out which legal bases under GDPR Article 6 are available for web scraping operations, address the conditions for processing special categories of personal data under Article 9 where scraping inadvertently collects health, biometric, or similar data, and outline transparency and data subject rights obligations for controllers. Third, the Board adopted the final version of its Guidelines on Processing of Personal Data through Blockchain Technologies, replacing the earlier draft and providing definitive guidance on how GDPR requirements apply to both permissioned and permissionless blockchain architectures. The Board emphasises the importance of conducting Data Protection Impact Assessments before processing personal data through blockchain systems and highlights the particular challenges posed by the immutable nature of ledger entries for GDPR rights including erasure and rectification.

The anonymisation guidelines are expected to raise the practical bar for claims that processed data falls outside the GDPR, with material implications for AI model developers who rely on anonymisation of training datasets. The web scraping guidelines signal that the EDPB does not regard general legitimate interest balancing tests as automatically sufficient legal basis for large-scale scraping for AI training; controllers must document a specific, context-appropriate legal basis for each category of data collected and address data subject notification obligations. The blockchain guidelines, now finalised, are the authoritative EDPB reference for GDPR compliance in decentralised ledger environments; organisations operating blockchain-based systems that process personal data of EU residents should treat the guidelines as directly applicable. The public consultation on the anonymisation and web scraping guidelines closes 30 October 2026, providing an opportunity for industry, researchers, and civil society to comment on the practical thresholds and conditions set out by the Board. The EDPB is also cooperating with the EU AI Office on guidelines addressing the interplay between the AI Act and EU data protection law, the draft of which is expected in the second half of 2026.

What it means for your business

If you train AI models or use web scraping to collect personal data at scale: The EDPB draft guidelines require a documented legal basis under GDPR Article 6 for each web scraping operation. Legitimate interest under Article 6(1)(f) is not automatically available and requires a documented balancing test; special category data under Article 9 requires explicit consent or another qualifying ground. Review your training data sourcing practices against the draft guidelines and consider submitting a consultation response by 30 October 2026. If you rely on anonymisation to take your processing outside GDPR scope: The draft guidelines update the anonymisation threshold in light of CJEU C-413/23 P. Review your anonymisation methodology against the updated standards before the consultation closes on 30 October 2026. If you use blockchain to record or share personal data of EU data subjects: The final blockchain guidelines are now the authoritative EDPB reference. Conduct a DPIA if one is not in place, and implement technical measures, such as off-chain storage, cryptographic deletion, or zero-knowledge proofs, to address the rights to erasure and rectification. Use Verdaio's GDPR Quick Check to map your GDPR obligations.

Commission Launches EU Cybersecurity and AI Action Plan: Four Pillars Under AI Act and NIS2

On 7 July 2026, the European Commission published the EU Action Plan on Cybersecurity and Artificial Intelligence (IP/26/1544), setting out four concrete measures to address the risks and opportunities of advanced AI for cybersecurity. The plan complements the existing legal framework under the AI Act, Cyber Resilience Act, NIS2, DORA, and the Cyber Solidarity Act, and does not introduce new legislation.

What changed

On 7 July 2026, the European Commission published the EU Action Plan on Cybersecurity and Artificial Intelligence (Commission press release IP/26/1544), a non-legislative policy document establishing four pillars for coordinated EU action at the intersection of AI and cybersecurity. The plan operationalises and complements the existing legislative framework, which includes the EU AI Act (Regulation (EU) 2024/1689), the Cyber Resilience Act (Regulation (EU) 2024/2847), the NIS2 Directive (Directive (EU) 2022/2555), the Digital Operational Resilience Act (DORA, Regulation (EU) 2022/2554), and the Cyber Solidarity Act (Regulation (EU) 2024/1252). The four pillars of the action plan are: first, establishing an EU AI model evaluation capacity to strengthen third-party assessment of advanced AI models before EU market placement, supporting the EU AI Office in its enforcement role under the AI Act; second, developing a European blueprint for structured and secure access to advanced AI capabilities for cybersecurity purposes, to be produced jointly by the Commission and ENISA; third, creating a secure testing and simulation platform for AI in cybersecurity, operated jointly by ENISA and the Commission's Joint Research Centre (JRC), with priority access for operators in critical sectors including energy, transport, health, finance, and public administration; and fourth, launching an EU Grand Challenge on AI for Cybersecurity, a competitive initiative to foster innovation in AI-powered cybersecurity solutions by bringing together companies, researchers, and other stakeholders.

The Commission framed the action plan as an implementation measure for existing obligations rather than a source of new legal requirements. Organisations already subject to the AI Act, NIS2, DORA, or the CRA do not face new compliance deadlines from the plan itself. However, the plan has operational significance: the AI model evaluation capacity will inform how the AI Office assesses GPAI model obligations under Chapter V of the AI Act from 2 August 2026; the secure testing platform will be available to critical-sector operators required under NIS2 Article 21 to implement appropriate technical and organisational security measures, which increasingly include measures addressing AI-driven threats; and the EU Grand Challenge may produce reference architectures and practices that national competent authorities incorporate into supervisory expectations under NIS2 and DORA. The plan also signals Commission priority attention on AI-specific cybersecurity risks, including adversarial attacks on AI models, AI-enabled social engineering and phishing at scale, and the use of AI to automate vulnerability discovery and exploitation against critical infrastructure. The European Parliament had included AI and cybersecurity intersection work as a priority in its June 2026 agenda in the days immediately preceding the plan's publication.

What it means for your business

If you develop, provide or deploy AI systems or use AI tools in your operations and are subject to NIS2 or DORA: The Commission action plan confirms that national supervisory authorities and the AI Office will increasingly assess AI-specific cybersecurity risks as part of both AI Act and NIS2/DORA compliance reviews. Under NIS2 Article 21, your risk management measures must address all relevant threats, including AI-enabled attacks. The plan's secure testing platform (ENISA plus JRC) will be available to critical-sector operators; monitor ENISA for access details as the platform is developed. If you are a provider of GPAI models subject to Chapter V of the AI Act: The EU AI model evaluation capacity pillar signals that third-party evaluation practices will evolve rapidly from 2 August 2026 when AI Office enforcement activates. Align your technical documentation and safety evaluations with the GPAI Code of Practice before that date. If you manufacture connected products subject to the CRA: The plan signals increased Commission and ENISA attention to AI-driven vulnerability discovery and exploitation; ensure your vulnerability management and Article 14 incident reporting processes are operational before the 11 September 2026 CRA reporting deadline. Map your AI Act and NIS2 obligations with Verdaio's EU AI Act Assessment and NIS2 Readiness Assessment.

Commission Adopts Revised ESRS, Cutting Total Datapoints by Over 70% Under CSRD Omnibus

On 3 July 2026, the European Commission formally adopted revised European Sustainability Reporting Standards (ESRS) under the CSRD Omnibus package, reducing the total number of mandatory datapoints by more than 70% compared to the 2023 delegated act. The revised ESRS introduce a voluntary-first approach for most sustainability topics, with mandatory disclosure limited to a core set of material matters, and introduce a simplified ESRS set for SMEs subject to CSRD.

What changed

The Commission adopted the revised ESRS on 3 July 2026 as a delegated regulation under Article 29b of Directive 2013/34/EU (the Accounting Directive, as amended by CSRD). The revision follows the CSRD Omnibus proposal published in February 2026 and subsequent technical work by EFRAG. The 2023 ESRS delegated act (Commission Delegated Regulation (EU) 2023/2772) contained 1,144 mandatory and semi-mandatory datapoints across twelve thematic standards (ESRS E1 to E5, ESRS S1 to S4, ESRS G1) and two cross-cutting standards (ESRS 1 and ESRS 2). The revised ESRS reduce the total disclosure burden by more than 70%, restructuring the standards so that the vast majority of datapoints become voluntary or conditional on a materiality assessment finding them to be material. Under the revised framework, ESRS 2 (General Disclosures) retains a mandatory core of entity-level information required regardless of materiality assessment outcome; all thematic standards (environment, social, governance) shift to a mandatory-if-material basis, meaning disclosure is only required where the topic is determined material through the double materiality assessment. The Commission simultaneously adopted a simplified ESRS set for small and medium-sized enterprises in scope of CSRD (listed SMEs and large non-listed entities below the CSRD thresholds that are nonetheless captured by the directive's phased scope). The simplified ESRS set applies from the 2026 financial year for third-wave in-scope companies.

The revised ESRS take effect immediately as a delegated regulation and will govern sustainability reporting for all entities in scope of CSRD from the applicable reporting year. Companies in wave one (large public-interest entities with more than 500 employees) that began reporting under the 2023 ESRS from the 2024 financial year will need to transition to the revised ESRS for their 2025 financial year report, published in 2026. EFRAG is expected to provide transition guidance and mapping documentation between the 2023 and revised ESRS. The CSRD Omnibus also made legislative amendments to Directive 2022/2464/EU (CSRD) itself, including revisions to the in-scope thresholds: from 2028, mandatory CSRD reporting will apply only to companies with more than 1,000 employees and either more than €50 million net turnover or more than €25 million balance sheet total. Companies between 250 and 1,000 employees are no longer automatically in-scope under the revised CSRD thresholds, though listed SMEs remain subject to CSRD with the simplified ESRS set.

What it means for your business

If you are currently in scope of CSRD (a large public-interest entity, large undertaking, or listed SME under Directive 2013/34/EU as amended by CSRD): The revised ESRS reduce your mandatory disclosure burden by more than 70%. Review whether topics you previously assessed as material remain material under the revised framework, and update your double materiality assessment and reporting templates accordingly. For your first report under the revised ESRS, transition guidance from EFRAG is expected in late 2026. If you are a listed SME or a company that will be in scope under the revised CSRD thresholds: The simplified ESRS set adopted simultaneously provides a proportionate reporting framework; begin your gap analysis against the simplified ESRS requirements now. If you are a large company between 250 and 1,000 employees that expected to enter CSRD scope: Review the revised in-scope thresholds (1,000 employees + turnover/balance sheet criteria) to confirm whether you remain subject to CSRD mandatory reporting from 2028. Map your CSRD obligations and run your double materiality assessment with Verdaio's CSRD Readiness Assessment.

Italian Garante 2025 Report: Sanctions Surge 54% to EUR 37.7 Million, AI Takes Centre Stage

The Italian data protection authority (Garante) presented its 2025 Annual Report to the Italian Parliament on 2 July 2026, recording 807 collegial measures, EUR 37.7 million in sanctions (a 54.5% increase year-on-year), and 2,415 data breach notifications. Enforcement actions targeting generative AI were dominant in 2025: the Garante issued a decision limiting DeepSeek's processing of Italian user data, warnings against deepfake platforms including Grok, ChatGPT, and Clothoff, and suspended facial recognition at Milan Linate airport. The authority also sent 65 criminal referrals to judicial bodies in 2025, four times the 16 made in 2024.

What changed

The Garante per la Protezione dei Dati Personali (Italian data protection authority) presented its 2025 annual activity report to the Camera dei Deputati (Italian Chamber of Deputies) on 2 July 2026. The report records 807 collegial measures adopted in 2025, of which 506 were enforcement actions comprising 229 sanctions or corrective measure decisions and 91 formal warnings. Sanctions collected reached EUR 37.7 million, a 54.5% year-on-year increase on the EUR 24.4 million collected in 2024. Data breach notifications received by the Garante totalled 2,415, a 10% annual increase, with 78.7% originating from private-sector entities and 21.3% from public-sector entities. The Garante sent 65 criminal referrals to judicial authorities in 2025, compared to 16 in 2024, covering unauthorised access to computer systems, extortion, and in 54 cases the non-consensual distribution of sexually explicit images (NCII). Presenting the report, Garante President Pasquale Stanzione described artificial intelligence as "the new infrastructure of power," noting the volume and pace of AI-driven data processing as the authority's defining enforcement challenge for 2025 and 2026.

Generative AI and deepfakes were the dominant enforcement themes of 2025. In January 2025, the Garante issued a decision limiting the processing of personal data of Italian users by the Chinese companies operating the DeepSeek conversational AI system, citing non-compliance with GDPR transparency and data subject information obligations and unresolved concerns about transfers to third countries. Investigation activities against the illicit generation of synthetic intimate images resulted in warnings addressed to operators of platforms including Grok, ChatGPT, and Clothoff, calling on service providers to adopt technical and organisational measures consistent with the prohibition on non-consensual intimate image generation. The Garante also suspended the FaceBoarding biometric identification system at Milan Linate airport after finding that biometric data of more than 24,500 passengers had been stored in a centralised database without adequate control mechanisms. For 2026, the Garante's inspection plan targets data processing in public administration databases and the use of new technologies and AI-based systems in both public and private sectors, signalling continued scrutiny of AI deployments, large-scale data collection, and biometric processing across Italy.

What it means for your business

If you process personal data of Italian data subjects, operate an establishment in Italy, or offer goods or services to individuals in Italy: The 2025 Annual Report confirms the Garante is in a phase of significantly expanded enforcement, with sanctions up 54.5% year-on-year and criminal referrals quadrupled. The Garante's 2026 inspection plan targets public-sector databases and new-technology deployments including AI systems; private-sector entities processing personal data with generative AI tools, biometric identification systems, or large-scale data warehouses face elevated inspection risk. If you develop, provide or deploy AI systems that process personal data of Italian users, generate synthetic content, or use biometric data: Review compliance with GDPR Articles 9 (special category data), 5(1)(a)(c)(e) (lawfulness, data minimisation, storage limitation), 13-14 (transparency), and 25 (data protection by design). The Garante's parallel application of GDPR and the EU AI Act prohibition on workplace emotion-inference AI in prior decisions signals that cross-regulatory enforcement is accelerating. Map your GDPR obligations with Verdaio's GDPR Quick Check.

EDPB and AMLA Partner to Develop Joint Guidelines on AML Information Sharing

On 1 July 2026, the European Data Protection Board (EDPB) and the Anti-Money Laundering Authority (AMLA) announced they will develop joint guidelines on how financial entities can share personal data for anti-money laundering purposes while complying with GDPR. The initiative targets Article 75 of the EU AML Regulation, which creates a new information-sharing permission for obligated entities entering into force on 10 July 2027. A public consultation on the draft guidelines is planned for the first half of 2027.

What changed

On 1 July 2026, the EDPB and AMLA published a joint announcement confirming their cooperation to develop guidelines clarifying how the information-sharing provisions of the EU AML Regulation interact with GDPR obligations. Article 75 of the AML Regulation creates a new legal basis for obligated entities (banks, payment institutions, e-money institutions, asset managers, and other AML-obligated financial actors) to share personal data and transaction information with each other and with competent authorities, including financial intelligence units (FIUs), for the purpose of preventing, detecting, and investigating money laundering and terrorist financing. This information-sharing capability enters into application on 10 July 2027. The joint EDPB-AMLA guidelines will address the practical conditions under which such sharing can take place in a manner consistent with GDPR, covering the legal basis for processing, transparency obligations toward data subjects, data subject rights, and technical and organisational safeguards. The EDPB and AMLA announced they will hold a stakeholder event later in 2026 to gather early views on what the guidelines should address, with a public consultation on the draft guidelines planned for the first half of 2027.

The EDPB's involvement in developing these joint guidelines signals that Article 75 AML information sharing will be assessed against all applicable GDPR principles, including purpose limitation, data minimisation, and storage limitation under Article 5 GDPR. Data protection impact assessments (DPIAs) under GDPR Article 35 are likely to be required for large-scale Article 75 information-sharing arrangements, as they involve systematic processing of personal data with heightened risk (financial transaction data and identity data). For entities subject to both GDPR and DORA, cross-entity information sharing for AML purposes also creates ICT third-party risk obligations under DORA Articles 28-44, including classification of information-sharing counterparties in the Register of Information submitted to competent authorities. The AMLA, established as the central EU AML supervisor, will take over direct supervision of certain high-risk obligated entities from national supervisors from July 2027, meaning the joint guidelines will also define the standard expected in AMLA supervisory reviews.

What it means for your business

If you are a financial entity subject to EU AML obligations (banks, credit institutions, payment institutions, e-money institutions, asset managers, virtual asset service providers, or other obligated entities under the AML Regulation): Article 75 information sharing becomes available from 10 July 2027. Monitor the EDPB-AMLA guidelines development: a draft is expected for public consultation in the first half of 2027. Begin reviewing your data governance architecture for AML information-sharing use cases now, and identify whether existing DPIAs need updating when the draft guidelines are published. If you are subject to both GDPR and DORA: Cross-entity AML information sharing creates additional ICT third-party risk obligations under DORA Articles 28-44; identify information-sharing counterparties in your DORA Register of Information. Map your GDPR obligations with Verdaio's GDPR Quick Check.

Council of the EU Formally Adopts Digital Omnibus on AI, Completing the Co-Legislative Process

On 29 June 2026, the Council of the European Union formally adopted the Digital Omnibus on AI legislative package, completing the co-legislative process and clearing the last step before publication in the Official Journal of the EU. The Council's adoption follows the European Parliament's approval on 16 June 2026. Once published, the amendments to the EU AI Act extend the compliance deadline for providers and deployers of high-risk AI systems under Annex III from August 2026 to December 2027, giving affected organisations an additional 16 months.

What changed

The Digital Omnibus on AI amends the EU AI Act (Regulation (EU) 2024/1689) and follows the standard EU co-legislative process: a provisional agreement was reached between the European Parliament and the Council on 7 May 2026, the European Parliament approved the package at plenary on 16 June 2026, and on 29 June 2026 the Council of the EU voted to formally adopt the text. The Council's adoption is the final legislative step; the regulation will be signed by the Presidents of the European Parliament and the Council, published in the Official Journal of the European Union, and enter into force twenty days after publication. The core amendment extends the deadline for Annex III and Annex IV obligations under the EU AI Act from 2 August 2026 to 2 December 2027, giving providers and deployers of high-risk AI systems in the Annex III categories (critical infrastructure, education, employment, essential services, law enforcement, migration management, and the administration of justice) an additional 16 months. The package also permanently bans AI-based nudifier applications that generate synthetic intimate images of identifiable real persons without consent under Article 5 of the AI Act prohibited practices, and introduces a three-month technical implementation grace period for the Article 50 transparency and watermarking obligations.

For organisations that have been planning their EU AI Act compliance on the original August 2026 timeline, the formal Council adoption confirms that the December 2027 extension is now legally certain, pending only signature and Official Journal publication (which typically takes weeks, not months). Providers of general-purpose AI (GPAI) models are not affected by the Annex III extension: the GPAI obligations under Chapter V of the AI Act, including copyright disclosure, technical documentation, and the GPAI Code of Practice process, applied from 2 August 2025 and are unchanged. The Article 50 transparency obligations (disclosure requirements for AI systems interacting with persons) still apply from 2 August 2026; only the technical implementation of compliant watermarking and metadata solutions receives the three-month grace period until 2 December 2026. The prohibited practices ban under Article 5 has been in effect since 2 February 2025 and is unaffected by the Digital Omnibus, except for the new permanent prohibition on nudifier applications. The publication of the Digital Omnibus on AI in the Official Journal will trigger the 20-day countdown to its entry into force and confirm the extended Annex III deadline at 2 December 2027.

What it means for your business

If you develop, provide or deploy AI systems classified as high-risk under Annex III of the EU AI Act (AI systems in critical infrastructure management, education and vocational training, employment and workforce management, access to essential private and public services, law enforcement, migration and border management, or administration of justice): The Annex III compliance deadline is legally confirmed as 2 December 2027 following the Council's formal adoption on 29 June 2026. Use the extension to complete conformity assessments, prepare technical documentation, align with harmonised standards as they are published, and register in the EU database. Do not wait for Official Journal publication to begin: the date is confirmed. If you build or deploy generative AI systems subject to Article 50 transparency obligations: Those obligations apply from 2 August 2026; the technical grace period for compliant watermarking extends to 2 December 2026. If you provide general-purpose AI models: Your Chapter V obligations from August 2025 are unchanged by the Digital Omnibus on AI. Map your EU AI Act obligations with Verdaio's EU AI Act Assessment.

EDPB Launches Contact Form to Report GDPR Interpretation Inconsistencies Across the EU

On 24 June 2026, the European Data Protection Board launched a dedicated contact form allowing any stakeholder to report alleged divergences in how the GDPR is interpreted by national supervisory authorities, either between national positions or between a national position and the EDPB's own published guidance. The form is a Helsinki Statement deliverable designed to help the Board identify where GDPR application is most fragmented across the EU. Submissions are compiled for Board discussion; the EDPB will not respond to individual reports.

What changed

The EDPB contact form was published on 24 June 2026 as part of the Board's implementation of the Helsinki Statement on enhanced clarity, support, and engagement, adopted to address feedback that fragmented national GDPR interpretations create uneven compliance conditions across the EU and EEA. The form allows any stakeholder, including businesses, legal practitioners, civil society organisations, researchers, and individuals, to report specific cases of perceived inconsistency: either a divergence between the positions of two or more national supervisory authorities on a GDPR question, or a divergence between a national supervisory authority's position and published EDPB opinions, guidelines, or decisions. The mechanism covers all areas of GDPR interpretation where national approaches differ, including legal bases for processing (such as legitimate interest under Article 6(1)(f)), consent requirements, data retention limits, breach notification practices, and data transfer mechanisms. The form is not a complaint tool and does not trigger any individual investigation or remedy by the EDPB; the Board has confirmed it will not respond to individual submissions received through the mechanism.

Submissions received via the form will be compiled by the EDPB Secretariat and presented periodically to the Board for review. The Board will then consider whether any of the identified inconsistency areas warrant additional consistency measures, which may include new EDPB guidelines under Article 70(1)(e) of the GDPR, a formal opinion under Article 64 (which the Board can issue at the request of a supervisory authority or on its own initiative), or a binding decision under Article 65 (used to resolve disputes in cross-border cases). The form complements the EDPB's existing consistency toolkit and its broader Helsinki Statement commitments, which also include the common data breach notification template adopted at the Board's June 2026 plenary (open for public consultation until 5 August 2026), the DPIA template published earlier in 2026, and ongoing work on anonymisation guidelines. The EDPB's focus on consistency comes at a time of accelerating GDPR enforcement: cumulative documented fines have passed €7.4 billion, with more than €600 million issued in the first half of 2026. Organisations operating across multiple EU or EEA member states currently face different national approaches to core GDPR concepts, which the EDPB consistency mechanism seeks to reduce over time.

What it means for your business

If you operate across multiple EU or EEA member states and face conflicting GDPR guidance from different national supervisory authorities (for example, divergent positions on legitimate interest assessments, cookie consent requirements, or data retention periods): The EDPB consistency form gives you a direct channel to bring those divergences to the Board's attention. Submissions that document systemic inconsistencies may lead the EDPB to issue clarifying guidelines that benefit your compliance programme across all affected jurisdictions. The form does not produce individual rulings, but flagging a well-documented divergence is a practical step when cross-border inconsistency creates real compliance cost. If you submit a report: include specific regulatory references, the national authority positions involved, and the practical impact, to give the EDPB the structured information it needs to assess whether a consistency action is warranted. Map your GDPR obligations with Verdaio's GDPR Quick Check.

European Parliament Approves Digital Omnibus on AI: High-Risk Deadline Moved to December 2027

On 16 June 2026, the European Parliament voted to approve the Digital Omnibus on AI legislative package, formally adopting amendments to the EU AI Act (Regulation (EU) 2024/1689) that extend the deadline for high-risk AI system obligations under Annexes III and IV. The vote extends the compliance deadline for providers and deployers of high-risk AI systems from August 2026 to December 2027, giving affected organisations an additional 16 months. The package also introduces a permanent ban on AI-based nudifier applications under Article 5 prohibited practices.

What changed

The Digital Omnibus on AI is a legislative amendment package that modifies key transition provisions of the EU AI Act (Regulation (EU) 2024/1689). The AI Act entered into force on 1 August 2024, with prohibited practices applying from 2 February 2025 and obligations for providers of general-purpose AI models applying from 2 August 2025. The original AI Act established 2 August 2026 as the compliance deadline for obligations applying to providers and deployers of high-risk AI systems listed in Annex III (covering AI systems in critical infrastructure, education, employment, essential private and public services, law enforcement, migration management, and the administration of justice) and Annex IV (documentation requirements for high-risk AI systems). The provisional agreement on the Digital Omnibus on AI was reached between the European Parliament and the Council of the EU on 7 May 2026. On 16 June 2026, the European Parliament voted to formally approve the package at plenary. The Council is expected to adopt the text formally in the coming weeks. Once published in the Official Journal of the European Union, the amendments enter into force. The core change in the Digital Omnibus on AI is the extension of the Annex III and Annex IV obligations deadline to 2 December 2027, giving providers and deployers of high-risk AI systems in those categories an additional 16 months beyond the original August 2026 date. The package also permanently bans AI systems that generate synthetic intimate images of identifiable real persons without their consent (nudifier applications) under Article 5 of the AI Act's prohibited practices list.

The Digital Omnibus on AI also includes a three-month grace period for providers and deployers to adopt compliant technical measures for the Article 50 transparency and watermarking obligations, resulting in a transitional deadline of 2 December 2026 for those implementation steps (the underlying Article 50 obligations themselves still apply from 2 August 2026). For providers of general-purpose AI (GPAI) models, the Digital Omnibus on AI does not change the 2 August 2025 application date or the obligations under Chapter V of the AI Act, including the requirements for systematic copyright disclosure, the preparation of technical documentation, and compliance with the GPAI Code of Practice process. The extension of the Annex III high-risk deadline does not alter the prohibited practices ban (Article 5, applied since 2 February 2025), the transparency obligations for AI systems interacting with persons (Article 50, applied from 2 August 2026), or the GPAI obligations (Article 51 onward, applied from 2 August 2025). National market surveillance authorities and the EU AI Office continue to coordinate on the transition, including the publication of standardised conformity assessment templates and technical standards by the European standards bodies (CEN, CENELEC, ETSI) under the AI Act mandate.

What it means for your business

If you develop, provide or deploy AI systems classified as high-risk under Annex III of the EU AI Act (AI systems in critical infrastructure management, education and vocational training, employment and workforce management, access to essential private and public services, law enforcement, migration and border management, or administration of justice): Your compliance deadline for the core Annex III obligations (conformity assessment, technical documentation, registration in the EU AI Act database, transparency requirements for deployers, and post-market monitoring) has been extended to 2 December 2027. Use the additional time to complete a structured readiness assessment, align with the published harmonised standards once available, and prepare your technical documentation and conformity assessment process. If you build or deploy generative AI systems or systems covered by Article 50 transparency obligations: The Article 50 obligations still apply from 2 August 2026; the three-month technical grace period extends implementation of compliant watermarking and metadata solutions to 2 December 2026. If you develop or deploy nudifier applications that generate synthetic intimate images of real persons: These are now permanently prohibited under Article 5 of the AI Act. Map your EU AI Act obligations with Verdaio's EU AI Act Assessment.

EU Cyber Resilience Act Chapter IV Enters Into Force, Reporting Obligations Due 11 September 2026

On 11 June 2026, Chapter IV of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) entered into application, requiring EU Member States to have designated notifying authorities for the assessment and notification of conformity assessment bodies for products with digital elements. This milestone marks the start of the CRA's phased rollout: the next deadline is 11 September 2026, when Article 14 mandatory vulnerability and incident reporting obligations apply, requiring manufacturers to submit a 24-hour early warning to ENISA and the relevant national CSIRT for any actively exploited vulnerability. With fewer than 90 days to the Article 14 deadline, manufacturers of connected products sold in the EU must complete preparation for the ENISA Single Reporting Platform.

What changed

The Cyber Resilience Act (CRA, Regulation (EU) 2024/2847) entered into force on 10 December 2024 and sets mandatory cybersecurity requirements for products with digital elements placed on the EU market, covering hardware and software with network connectivity or data-processing functions. The CRA follows a phased application schedule tied to 18, 21 and 36 months after entry into force. Chapter IV, which governs the notification of conformity assessment bodies, applies from 11 June 2026 (the 18-month milestone). Under Chapter IV, EU Member States are required to have designated notifying authorities responsible for establishing and carrying out procedures for the assessment, designation, monitoring and notification of conformity assessment bodies. Conformity assessment bodies are the accredited third-party organisations that certify CRA compliance for manufacturers of Class II products (Annex III items including firewalls, VPNs, operating systems, microprocessors and industrial control systems) and for Class I products where manufacturers cannot demonstrate conformity through internal checks alone.

The most operationally urgent CRA deadline is 11 September 2026, when Article 14 enters into application. Article 14 requires manufacturers of products with digital elements to report actively exploited vulnerabilities and incidents affecting product security to both ENISA and the national CSIRT of the Member State where the manufacturer has its main establishment, via ENISA's Single Reporting Platform (SRP). The reporting process has three stages: an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident; a detailed notification within 72 hours covering the nature and severity of the vulnerability, affected product versions and initial mitigation measures; and a final report within 14 days of a patch or corrective action being available. As of June 2026, ENISA is providing registration instructions, training materials and dry-run support for the SRP, which is expected to be fully operational by 11 September 2026. Non-compliance with Article 14 carries fines of up to €15 million or 2.5% of global annual turnover, whichever is higher. Manufacturers are also required under Article 13 to identify and document vulnerabilities in their products and to apply security updates without undue delay throughout the product's expected service lifetime.

What it means for your business

If you manufacture, develop or place on the EU market hardware or software products with digital elements (IoT devices, routers, firewalls, network equipment, operating systems, security software, industrial control systems, or connected consumer products): The 11 September 2026 Article 14 deadline is now fewer than 90 days away. Complete your ENISA Single Reporting Platform registration during June 2026 while training and dry-run support is available, map your internal vulnerability management and incident response procedures to the 24-hour, 72-hour and 14-day reporting windows, and confirm your main establishment in the EU for CSIRT notification routing. If your product falls within Class II under Annex III of the CRA (firewalls, VPNs, hardware security modules, operating systems, microprocessors, industrial automation systems): Third-party conformity assessment is mandatory. Engage a designated conformity assessment body notified by a Member State under Chapter IV. Check your CRA product classification and prepare your technical documentation with Verdaio's CRA Product Compliance Checker.

ENISA Runs Cyber Europe 2026 Exercise Testing EU Collective Response to Attacks on Rail and Maritime Infrastructure

On 10 June 2026, ENISA launched Cyber Europe 2026, the eighth pan-European cybersecurity exercise, bringing together more than 5,000 experts from EU and EEA Member States to simulate coordinated cyberattacks targeting rail and maritime critical infrastructure. The exercise tested the revised EU Cybersecurity Blueprint for large-scale incident coordination and marked the first activation of the EU Cybersecurity Reserve in a full-scale scenario.

What changed

Cyber Europe 2026 took place on 10 and 11 June 2026 under the organisation of ENISA and brought together more than 5,000 cybersecurity professionals from EU Member States, EEA countries, EU institutions, and private sector operators. The exercise simulated a large-scale coordinated cyberattack scenario targeting two critical infrastructure sectors listed as essential sectors under the NIS2 Directive (Directive (EU) 2022/2555): rail transport (railway networks and operational technology systems) and maritime transport (port logistics, navigation systems, and vessel traffic services). Cyber Europe is the EU's flagship cyber crisis simulation, designed to test the technical and operational crisis management procedures developed under the EU Cybersecurity Blueprint, the overarching framework for the EU's coordinated response to large-scale cybersecurity incidents and crises, revised in June 2025 to align with the evolving threat landscape and NIS2 obligations. The 2026 edition marked the first activation of the EU Cybersecurity Reserve in a full-scale exercise scenario. The EU Cybersecurity Reserve, established under the EU Cyber Solidarity Act (Regulation (EU) 2024/1252), consists of pre-committed incident response services provided by trusted managed security service providers, available to Member States facing significant or large-scale cybersecurity incidents that exceed their national capacities.

The exercise findings, including identified capability gaps, coordination bottlenecks, and response metrics, will be published in an after-action report by ENISA in the second half of 2026. Cyber Europe 2026 focused on the cross-border and cross-sector coordination dimension of the NIS2 Directive, which requires Member States to designate national cybersecurity crisis management authorities and participate in the EU CyCLONe network (Cyber Crisis Liaison Organisation Network) for large-scale incident coordination. For transport-sector operators, the exercise confirmed that port authorities, railway infrastructure managers, vessel traffic service providers, and freight logistics platforms are priority threat targets in national and EU-level incident response planning. The exercise also validated the interaction between the NIS2 single point of contact structure (Articles 8 and 40 of NIS2) and the EU Cybersecurity Blueprint notification chains, confirming that mandatory incident reporting under NIS2 Article 23, the 24-hour early warning obligation, and ongoing threat information sharing via the CSIRTs Network are integral parts of the collective response framework.

What it means for your business

If you operate critical infrastructure in the rail or maritime transport sector (port operators, railway infrastructure managers, vessel traffic services, freight logistics platforms, or passenger rail networks) as an essential entity under NIS2: Cyber Europe 2026 confirms that your sector is a priority target in EU-level threat scenario planning. Review your NIS2 Article 21 security measures, confirm your incident reporting readiness under Article 23 (24-hour early warning to your national CSIRT), and verify that your contacts in the national cybersecurity crisis management authority are current. If you provide services to transport-sector critical infrastructure operators as an important entity under NIS2, or supply operational technology (OT), industrial control systems (ICS) or vessel traffic management software to the transport sector: Supply chain security and OT/IT convergence are central to the NIS2 Article 21 risk management requirements. Check your NIS2 obligations and security controls with Verdaio's NIS2 Compliance Assessment.

EU AI Office Publishes Final Code of Practice on Marking and Labelling of AI-Generated Content

On 10 June 2026, the European Commission's AI Office published the final Code of Practice on the transparency of AI-generated content, developed under Article 50 of the EU AI Act through a multi-stakeholder process with more than 187 participants. The voluntary code sets out practical commitments for providers of generative AI systems to mark synthetic audio, image, video and text outputs in machine-readable formats, and for deployers to label deepfakes and AI-generated text published to inform the public on matters of public interest. The underlying Article 50 transparency obligations apply from 2 August 2026, with a three-month grace period for technical implementation measures until 2 December 2026.

What changed

On 10 June 2026, the European AI Office published the final Code of Practice on the Transparency of AI-Generated Content, completing a multi-stakeholder drafting process launched in September 2025. Six independent experts appointed by the AI Office led three rounds of stakeholder consultations with more than 187 participants from industry, academia, civil society, rightsholders, and EU Member States. The code is structured in two sections addressing distinct obligations under Article 50 of the EU AI Act (Regulation (EU) 2024/1689). Section 1 covers the obligations of providers of generative AI systems under Article 50(2): providers must ensure that audio, image, video and text outputs generated or substantially manipulated by their systems are marked in a machine-readable format allowing detection as artificially generated. The code recommends two primary technical mechanisms: digitally-signed metadata and imperceptible watermarking, implemented in a way that is effective, interoperable, robust, and reliable as far as technically feasible. Section 2 covers the obligations of deployers under Article 50(4): deployers must clearly label deepfakes (AI-generated or manipulated audio, video or images depicting real persons or real places in a way that a person would mistakenly believe to be authentic) and AI-generated or manipulated text published for the purpose of informing the public on matters of public interest, with practical guidance on label design, placement, and presentation including icons and disclaimers.

The Code of Practice is voluntary: it does not create obligations beyond those already contained in Article 50 of the AI Act and does not introduce new requirements or additional administrative burdens. Providers and deployers that sign the code commit to the practical measures it describes as a way to demonstrate compliance with the underlying AI Act obligations. Signatories will be publicly listed in July 2026, ahead of the 2 August 2026 date on which Article 50 transparency obligations apply. The Digital Omnibus on AI provisional agreement of 7 May 2026 included a three-month grace period for providers and deployers to adopt compliant technical solutions (such as watermarking infrastructure), with a transitional deadline of 2 December 2026 for those implementation steps. Separately, the Commission opened a targeted public consultation on draft Article 50 transparency guidelines in May 2026, closed on 3 June 2026; the final guidelines are expected later in 2026 and will clarify the legal scope of Article 50 duties. From 2 August 2026, providers of AI systems designed to interact directly with persons must also ensure users are informed they are communicating with an AI system unless that is obvious from context (Article 50(1)).

What it means for your business

If you build or deploy generative AI systems (text-to-image, voice synthesis, video generation, chatbots, or deepfake tools) that produce or manipulate audio, image, video or text for EU users: Your Article 50(2) marking obligation applies from 2 August 2026. Implement machine-readable metadata or watermarking in your output pipeline before that date; the Code of Practice sets the technical benchmark against which the EU AI Office and national market surveillance authorities will assess compliance. If you have not yet adopted a compliant technical mechanism, the 2 December 2026 transitional deadline applies to those implementation steps. If you operate a platform that publishes AI-generated or AI-manipulated content on matters of public interest (news, political advertising, public information campaigns): The Article 50(4) deepfake and public-interest text labelling obligation applies from 2 August 2026. Review your editorial workflows and label placement against the Code's Section 2 guidance. If you deploy chatbots or virtual assistants that interact directly with users: The Article 50(1) AI disclosure obligation also applies from 2 August 2026. Map your AI Act transparency obligations with Verdaio's EU AI Act Assessment.

EDPB Adopts Common EU Data Breach Notification Template, Opens Consultation Until 5 August 2026

On 10 June 2026, during its June plenary, the European Data Protection Board adopted a common template for data breach notifications to supervisory authorities, designed to harmonise compliance with the 72-hour notification duty under Article 33 of the GDPR. The template provides predefined fields and structured guidance that reduce the administrative burden of breach reporting, particularly for smaller organisations without dedicated data protection officers. The template is open for public consultation until 5 August 2026; following the consultation, the EDPB will determine the timeline for all EU and EEA supervisory authorities to adopt it as their standard notification form.

What changed

On 10 June 2026, the European Data Protection Board (EDPB) held its June plenary, at which it adopted a draft common template for personal data breach notifications to supervisory authorities under Article 33 of the GDPR. Article 33 requires data controllers to notify their competent supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of a personal data breach that is likely to result in a risk to the rights and freedoms of natural persons. Until now, each national data protection authority in the EU and EEA has operated its own notification form with different fields, formats, and submission channels, requiring organisations with cross-border operations to manage separate national procedures. The EDPB common template introduces a single, harmonised format with predefined fields and guidance covering the information required under Article 33(3) GDPR: the nature of the breach, the categories and approximate number of data subjects and records involved, the likely consequences, and the measures taken or proposed to address the breach.

The adoption follows the EDPB Helsinki Commitments to simplify GDPR compliance and reduce administrative burden, in particular for small and medium-sized enterprises and controllers without dedicated data protection officers. After the public consultation closes on 5 August 2026, the EDPB will decide on the timeline for all EU and EEA supervisory authorities to adopt the template as their standard or reference form, with the aim that organisations eventually face a single notification format regardless of which national authority receives the report. The June 10 plenary also saw the EDPB meet with Commissioner Michael McGrath (Commissioner for Democracy, Justice, the Rule of Law and Consumer Protection), where discussions included the Digital Omnibus proposals and their implications for the GDPR. The template is separate from the existing EDPB Guidelines 09/2022 on personal data breach notification, which remain in force and continue to provide substantive guidance on when notification is required and what constitutes a risk to rights and freedoms.

What it means for your business

If you act as a data controller operating in one or more EU or EEA Member States: The EDPB common breach notification template will, once finalised and adopted by national supervisory authorities, replace each DPA's current notification form with a single harmonised format. Review your incident response playbook now: your internal notification procedures, SIEM runbooks, and outsourced incident response arrangements should be structured around the Article 33(3) mandatory information elements so they can map cleanly onto the new fields when the template enters into force. If you operate across borders and currently maintain separate notification procedures for different national DPA forms: the common template will simplify cross-border breach response materially once it enters into force. Participate in the public consultation (open until 5 August 2026) if your organisation has practical experience with current breach notification forms. Map your GDPR controls and breach response readiness with Verdaio's GDPR Quick Check.

EU Commission Opens Infringement Against Spain Over Excessive Traveller Data Collection

On 4 June 2026, the European Commission sent a letter of formal notice to Spain, opening an infringement procedure (case INFR(2026)4005) over Real Decreto 933/2021, which requires hotels, travel agencies, and car rental companies to collect payment details, GPS coordinates, and other personal data from travellers and transmit them to the national police. The Commission considers the data collection disproportionate and inconsistent with the Law Enforcement Directive (Directive 2016/680, LED), which limits police access to personal data to what is strictly necessary for law-enforcement purposes. Spain has two months to reply before the Commission may escalate to a reasoned opinion and, ultimately, a referral to the Court of Justice of the EU.

What changed

On 4 June 2026, the European Commission announced infringement proceedings against Spain as part of its June 2026 infringement package. The case targets Real Decreto 933/2021, a Spanish royal decree that entered into force in January 2023 and imposes extensive data-collection obligations on accommodation providers (hotels, hostels, holiday rentals), travel agencies, and vehicle rental companies. Under the decree, those businesses must collect a wide range of personal data from travellers — including full payment-card details, national identity or passport number, address, and GPS location data — and transmit it in real time to a national police database. The data is retained for three years and accessible to the Guardia Civil and National Police for public security and crime-prevention purposes.

The Commission's letter of formal notice argues that the data categories mandated by Real Decreto 933/2021 — particularly payment details, GPS coordinates, and the blanket three-year retention period — exceed what is strictly necessary for the law-enforcement objectives the decree purports to serve, in breach of the proportionality and data-minimisation requirements of the Law Enforcement Directive (Directive (EU) 2016/680). The LED governs processing of personal data by competent authorities for criminal law-enforcement and public-security purposes and applies a stricter necessity test than the general GDPR framework. The Commission's action follows years of complaints from the hospitality and travel sector and concerns raised by privacy advocates that the decree's requirements had been designed largely to build a comprehensive state surveillance database of domestic and foreign travellers. Spain has two months from the formal notice to submit observations before the Commission may issue a reasoned opinion, which would be a prerequisite for referral to the Court of Justice of the EU.

What it means for your business

If you operate accommodation, travel, or vehicle rental services that collect guest or traveller data on behalf of police or regulatory mandates in any EU Member State: This infringement case signals that the Commission treats blanket traveller-data mandates as disproportionate under the LED, regardless of national security justifications. Audit the categories and retention periods of traveller data you are required by national law to collect and transmit, and document the LED legal basis and necessity analysis in your ROPA. If you operate in Spain under Real Decreto 933/2021: Monitor developments closely; if the Commission escalates to a reasoned opinion or Court referral, Spain may be required to amend or repeal the decree, which would alter your compliance obligations. Review your data mapping and subject-rights procedures with Verdaio's GDPR Quick Check.

EU Commission Proposes Tech Sovereignty Package: Chips Act 2.0 and Cloud and AI Development Act

On 3 June 2026, the European Commission unveiled the European Technological Sovereignty Package, a set of four linked measures to strengthen EU independence in semiconductors, cloud, and artificial intelligence. The package includes two legislative proposals: the Chips Act 2.0, which aims to accelerate EU semiconductor capacity, and the Cloud and AI Development Act (CADA), which introduces a four-level EU sovereignty framework for cloud and AI services used in sensitive public-sector workloads. The Open Source Strategy and a Strategic Roadmap for Digitalisation and AI in Energy complete the package; all legislative elements must still clear the European Parliament and Council before taking effect.

What changed

On 3 June 2026, the European Commission presented the European Technological Sovereignty Package in a formal communication, accompanied by two legislative proposals. The Chips Act 2.0 proposes measures to accelerate EU semiconductor production capacity, streamline permitting, deepen partnerships with allied nations, and introduce an EU excellence label for semiconductor regions. The Cloud and AI Development Act (CADA) is designed to reduce EU dependence on non-EU hyperscalers, which currently represent approximately 70% of Europe's cloud market. CADA aims to triple EU data centre capacity over five to seven years through streamlined permitting, public investment incentives, and coordination across Member States. The package also includes a non-legislative EU Open Source Strategy and a Strategic Roadmap for Digitalisation and AI in Energy grids.

The CADA introduces a four-level EU sovereignty framework for cloud and AI services used by public bodies. Level 2 requires providers to demonstrate independence from third-country jurisdictions and transparency over their software supply chain; Level 3 requires EU ownership and control, including additional criteria such as personnel citizenship, with the Commission able to recognise qualifying third-country providers by exception; Level 4 requires full software supply-chain transparency and no interference from any third country. Public bodies procuring cloud and AI services for sensitive workloads in healthcare, banking, energy, and justice must conduct sovereignty risk assessments and apply the appropriate CADA level. The Computer and Communications Industry Association raised concerns that the territorial approach risks market fragmentation and disadvantages non-EU providers with established European operations. Both Chips Act 2.0 and CADA are legislative proposals requiring co-decision by the European Parliament and Council before they enter into force.

What it means for your business

If you sell cloud services, SaaS, or AI tools to EU public-sector bodies (central government, health, banking, energy, or justice): CADA introduces formal sovereignty risk assessments into public procurement. Prepare to answer questions about parent-company jurisdiction, third-country data access rights, software supply-chain transparency, and data escrow arrangements. Non-EU-owned providers face structural barriers to Levels 3 and 4 procurement tiers. If you build or deploy AI systems hosted on cloud infrastructure: The CADA sovereignty framework may affect your cloud provider options for regulated public-sector workloads once the act enters into force. Map your infrastructure against the four CADA levels and assess whether current provider arrangements would require renegotiation. Both proposals are early-stage and must pass the full EU legislative process. Map your AI Act obligations with Verdaio's EU AI Act Assessment and your CRA exposure with the CRA Product Compliance Checker.

EU Commission Appoints AI Act Scientific Panel and Advisory Forum to Drive Enforcement

On 2 June 2026, the European Commission appointed two independent bodies to support enforcement of the EU AI Act: a Scientific Panel of 60 independent experts focused on general-purpose AI (GPAI) model risks, and an Advisory Forum of 174 members drawn from academia, civil society, and industry. The Scientific Panel, established under Article 68 of the AI Act, will alert the EU AI Office to systemic risks in GPAI models, advise on model classification and evaluation methodologies, and support cross-border market surveillance. Both bodies serve 2-year renewable mandates, ahead of the Commission's full enforcement powers for GPAI obligations entering into application on 2 August 2026.

What changed

On 2 June 2026, the European Commission published an announcement confirming the appointment of the Scientific Panel and Advisory Forum established under the EU AI Act (Regulation (EU) 2024/1689). The Scientific Panel, governed by Article 68 of the AI Act, brings together 60 world-class independent experts with experience in frontier AI research, engineering, technical auditing, industry, and societal impact. Experts are appointed in a personal capacity for 24-month renewable terms. The panel's mandate covers three areas: alerting the EU AI Office to systemic risks linked to general-purpose AI (GPAI) models and systems, advising on GPAI model classification and evaluation methodologies, and supporting cross-border market surveillance activities for GPAI model providers.

The Advisory Forum, established under Article 67 of the AI Act, brings together 174 members selected from more than 700 applications, drawn from civil society, academia, and industry including small and medium-sized enterprises and startups. The EU Agency for Fundamental Rights (FRA) and the EU Agency for Cybersecurity (ENISA) hold permanent seats on the Advisory Forum, alongside standardisation bodies. The Forum provides technical expertise and stakeholder input to the Commission and the AI Board on AI Act implementation, standardisation, and compliance challenges. Both bodies are operational ahead of the August 2, 2026 milestone, when the Commission's enforcement powers for GPAI model obligations under Chapter V of the AI Act enter into full application. From that date, the AI Office may impose fines of up to 3% of total worldwide annual turnover or €15 million (whichever is higher) on non-compliant GPAI model providers.

What it means for your business

If you provide, deploy, or integrate general-purpose AI models (including large language models, multimodal foundation models, or AI models made available via API) in your products or services: The Scientific Panel now gives the EU AI Office dedicated independent expertise to identify systemic risks in GPAI models, advise on classification, and coordinate cross-border enforcement from 2 August 2026. Review your GPAI model obligations under Articles 53-55 of the AI Act: technical documentation, transparency measures including copyright summaries, cooperation with the AI Office, and systemic risk assessments for high-impact capability models. If your GPAI model was on the market before 2 August 2025, you have until 2 August 2027 to achieve full compliance. If you build or deploy AI systems that use GPAI models as components: your obligations as a deployer depend on whether the downstream use creates a high-risk AI system. Classify your AI system and map your obligations with Verdaio's EU AI Act Assessment.

Italian Garante Warns AI Startup Over Workplace Stress-Detection Plug-in, Citing GDPR and EU AI Act

On 28 May 2026, the Italian data protection authority (the Garante) published a formal warning to Myndoor S.r.l., a Milan-area startup that markets an AI plug-in for Slack and Microsoft Teams that infers employees' psychological stress levels from workplace chat messages. The Garante's decision (Provvedimento n. 342 of 14 May 2026) found that aggregate stress reports of this kind would likely breach the GDPR ban on processing special category data, the Italian employment law limits on employer data collection, and the EU AI Act prohibition on workplace emotion-inference AI systems under Article 5(1)(f). The warning was issued under Article 58(2)(a) of the GDPR and did not impose a financial penalty.

What changed

On 28 May 2026, Italy's Garante per la Protezione dei Dati Personali published a press release detailing a formal warning against Myndoor S.r.l., a Milan-area artificial intelligence startup. The underlying decision (Provvedimento n. 342 of 14 May 2026, document reference 10255494) targets a Myndoor plug-in for Slack and Microsoft Teams that analyses the language and emotional content of workplace chat messages to infer employees' psychological stress levels, and which Myndoor markets to employers in the form of aggregate stress reports. The Garante opened the file after the startup's own product communications drew regulatory attention and assessed the plug-in under both the GDPR and the EU AI Act.

The Garante concluded that even when presented in aggregate form, inferred stress data falls within categories of personal data that employers are forbidden to collect under Italian employment law and within the special category of health-related data under Article 9 of the GDPR. The authority issued a formal warning under Article 58(2)(a) GDPR that placing the plug-in on the market in the way described would likely breach the principles of lawfulness, data minimisation and privacy by design under Articles 5, 6 and 25 of the GDPR. It also identified the practice as falling within the EU AI Act prohibition on workplace emotion-inference AI systems under Article 5(1)(f) of Regulation (EU) 2024/1689. The decision is one of the first European enforcement actions to invoke both the GDPR and the EU AI Act in parallel against a single workplace AI product, and did not impose a financial penalty.

What it means for your business

If you build, deploy or procure AI tools that score employee sentiment, mood, stress or wellbeing from communications data: Review the legal basis for any such product against both Article 9 GDPR (special category data) and the EU AI Act Article 5(1)(f) prohibition on workplace emotion-inference AI. Aggregation, anonymisation labels and "wellbeing" framings will not save a product that infers psychological states from chat or voice data. If you run collaboration suites such as Slack or Microsoft Teams across your workforce: Audit any third-party plug-ins or integrations that perform sentiment, emotion or stress analytics, document the lawful basis and DPIA, and tighten supplier terms before procurement. Map your AI Act exposure with Verdaio's EU AI Act Assessment and your GDPR controls with the GDPR Quick Check.

French CNIL Fines IQVIA €5 Million Over Health Data Warehouse Transparency and Anonymisation Failures

On 26 May 2026, France's data protection authority (the CNIL) imposed a €5 million fine on IQVIA OPERATIONS FRANCE for failures in the operation of two health data warehouses: the LRX warehouse, supplied by data from around 14,000 pharmacies, and the EMR warehouse, supplied by data from several thousand doctors. The CNIL rejected IQVIA's argument that the data was anonymous, finding that the data was only pseudonymous because re-identification was possible by reasonable means, and held that patients had not been properly informed under Articles 14 and 25 of the GDPR. The CNIL also ordered IQVIA to remedy the remaining breaches within six months, subject to a penalty of €10,000 per day of delay.

What changed

On 26 May 2026, the CNIL's restricted committee published a decision against IQVIA OPERATIONS FRANCE, a health data company that operates two large data warehouses: the LRX warehouse (authorised by the CNIL in 2018, supplied with data extracted from around 14,000 pharmacies) and the EMR warehouse (authorised in 2021, supplied with data from several thousand doctors). The CNIL opened the investigation after receiving complaints from individuals and associations following a Cash Investigation report on the use of patient data by IQVIA. Inspections at four Paris pharmacies on the LRX panel in autumn 2021 found that none of them was handing out the patient notice or displaying the general information poster required by the original CNIL authorisation.

The CNIL's restricted committee rejected IQVIA's argument that the data processed in the warehouses was anonymous, concluding that the data was only pseudonymous because re-identification of the data subjects was possible by reasonable means, and that the data therefore remained personal data subject to the GDPR. The committee found that pharmacy management software transmitted customer data to IQVIA even when patients refused, contrary to data-protection-by-design requirements under Article 25, and that patients had not received the information required by Article 14 GDPR because the patient information sheet contained inaccuracies and there was no effective procedure for individuals to exercise their right to object. The committee also found security failings, including the absence of regular analysis of connection logs in both warehouses and the lack of multi-factor authentication for the EMR warehouse, although it noted that IQVIA had remediated several of those issues since the inspections. In addition to the €5 million fine, the CNIL ordered IQVIA to bring the warehouses into compliance within six months, subject to a penalty of €10,000 per day of delay.

What it means for your business

If you operate a data warehouse, research platform or other large-scale processing that you have characterised as anonymous: The CNIL's decision confirms that the GDPR anonymisation threshold is high and the test is whether re-identification remains reasonably possible. Re-assess your anonymisation methodology against the singling-out, linkability and inference criteria of the Article 29 Working Party opinion (WP216), and avoid relying on labels alone. If you collect personal data through pharmacies, doctors, brokers or other intermediaries: Article 14 GDPR transparency duties stay with the controller. You cannot rely on a third party to hand out a notice; you must verify the information actually reaches data subjects and that an effective right to object is available. Tighten your information notices, logging and access controls with Verdaio's GDPR Quick Check.

ENISA Publishes Third NIS360 Report: Six EU Critical Sectors Stay in Cybersecurity Risk Zone

On 28 May 2026, the EU Agency for Cybersecurity (ENISA) published the third edition of its NIS360 report, an annual assessment of cybersecurity maturity and criticality across the high-criticality sectors listed in Annex I of the NIS2 Directive. ENISA finds that electricity, telecoms and banking remain the most mature sectors, supported by strong regulatory oversight, consistent investment and well-established public-private partnerships. Six sectors fall within the risk zone, where cybersecurity maturity lags behind criticality, with progress across the NIS2 perimeter described as improving but uneven.

What changed

On 28 May 2026, ENISA released the third edition of its annual NIS360 report, which assesses the cybersecurity maturity and criticality of all sectors of high criticality identified under Annex I of the NIS2 Directive. NIS360 is designed as a tool for national authorities, policymakers and other stakeholders to compare sectors and prioritise NIS2 investment, supervisory attention and capacity building. ENISA scores sectoral maturity on four pillars: legislation and its effectiveness, companies and their preparedness, authorities and their institutional capacity, and sectoral ecosystem structures and their effectiveness.

ENISA identifies electricity, telecoms and banking as the most mature sectors, citing strong regulatory oversight, consistent investment and well-established public-private partnerships. Six sectors fall within the NIS360 risk zone, meaning their cybersecurity maturity is comparatively lower while their criticality score is higher than their maturity score. Across the broader NIS2 perimeter, ENISA notes that maturity is steadily improving but that progress remains uneven both across and within sectors, reflecting skill shortages, sector-specific characteristics and organisational size.

What it means for your business

If your organisation is registered as an essential or important entity under NIS2: The 2026 NIS360 is the most authoritative public benchmark of where each high-criticality sector stands on cyber maturity, and a signal of where supervisory attention is likely to land first. Compare your governance, risk management, incident response and supply-chain controls against ENISA's four pillars (legislation, company preparedness, authority capacity and ecosystem) and prioritise the gaps that pull your sector's profile down. If you operate in a sector flagged as falling within the risk zone: expect closer scrutiny from your national competent authority during the next supervision cycle and budget for accelerated remediation. Map your NIS2 obligations and identify gaps with Verdaio's NIS2 Readiness Assessment.

NIS2 Cooperation Group Adopts Common EU Templates for Cyber Incident Reporting

On 26 May 2026, during the 39th Plenary meeting in Cyprus, the NIS Cooperation Group (composed of EU Member States, the European Commission and the EU Agency for Cybersecurity, ENISA) adopted common templates for incident reporting under the NIS2 Directive. The templates provide a single, uniform format for reporting cyber incidents across Member States and are positioned as a simplification measure aimed at reducing the administrative burden on essential and important entities. The Commission has signalled that it will adopt the templates through an implementing act so they become mandatory across the Union.

What changed

On 26 May 2026, the NIS Cooperation Group, made up of EU Member States, the European Commission and the EU Agency for Cybersecurity (ENISA), agreed on common templates for incident reporting at its 39th Plenary meeting held in Cyprus. NIS2 (Directive 2022/2555) requires essential and important entities to notify their competent authorities or CSIRTs of significant incidents through an early warning within 24 hours, an incident notification within 72 hours and a final report within one month under Article 23. Until now, Member States have been free to design their own reporting forms and fields, and multinational entities had to navigate a patchwork of national templates.

The newly adopted templates set out a clear, harmonised format and common reporting fields for the early warning, the incident notification and the final report stages. The European Commission has indicated that it will adopt the templates through an implementing act, making them mandatory for all Member States, and has framed the work as part of a broader simplification agenda that also feeds into the proposed single entry point for cyber incident reporting under the upcoming Digital Omnibus. The change is intended to lighten the administrative load on companies, while giving authorities a more consistent EU-wide picture of cyber incidents.

What it means for your business

If you are an essential or important entity under NIS2 with operations in more than one Member State: Common templates will materially reduce the cost of complying with the Article 23 reporting clock by replacing parallel national forms with a single EU-wide format. Track the implementing act expected from the Commission, then update your internal incident playbooks, SIEM runbooks and outsourcing contracts so your 24-hour, 72-hour and one-month reports map cleanly onto the new fields. If you are a managed service provider or supplier to NIS2 entities: Expect customers to push the harmonised template requirements down through contractual clauses on incident notification and cooperation. Map your NIS2 obligations and tighten your incident response process with Verdaio's NIS2 Readiness Assessment.

Irish High Court Rejects Meta's Challenge, Clearing Path for DPC €360-€430M GDPR Access Right Fine

On 21 May 2026, the Irish High Court rejected Meta's judicial review challenge to a Data Protection Commission (DPC) draft decision that proposes a fine of €360 to €430 million for failures to give a Facebook user access to all personal data Meta held about him. Justice Siobhan Phelan dismissed Meta's argument that the DPC had unlawfully expanded a 2018 individual complaint into a systemic, EEA-wide inquiry, ruling there had been no impermissible extension and no breach of fair procedures. The DPC's draft signalled infringements of Articles 12, 15 and 20 of the GDPR over Meta's handling of access requests to data held in its internal data warehouse known as Hive.

What changed

On 21 May 2026, Ms Justice Siobhan Phelan of the Irish High Court delivered a 98-page judgment rejecting all grounds of Meta Platforms Ireland's challenge to the Irish Data Protection Commission. The case followed an October 2025 DPC draft decision finding Meta in breach of Articles 12, 15 and 20 of the GDPR over how it handled a 2018 access request from a Facebook user. The user had asked for the personal data Meta held about him beyond what was returned via Meta's standard self-service download tools, and complained that he had not been given access to information stored in an internal data warehouse referred to as Hive. The DPC's draft signalled a reprimand, a compliance order affecting Meta's general data-access practices, and proposed fines of €360 million to €430 million.

Meta argued that the DPC had unlawfully turned a single user complaint into an own-volition inquiry covering systemic, EEA-wide practices, exceeding its powers under the GDPR and the Data Protection Act 2018. Justice Phelan found that contention was not legally sound, ruling that there had been "no impermissible extension of the process from an individual-complaint process to an own-volition process and no breach of rights of fair procedures". With the judicial review dismissed, the DPC can now move to finalise its decision and proposed fine, subject to the cross-border cooperation and consistency procedures with other EEA supervisory authorities under Articles 60 to 65 of the GDPR. Meta has previously indicated it intends to challenge any final decision.

What it means for your business

If you operate any consumer service that handles personal data and receives data subject access requests under GDPR Article 15: The High Court ruling reinforces that regulators can pursue systemic access-right failures and propose substantial fines, even when an inquiry starts from a single complaint. Audit your end-to-end access-request workflow, ensure all categories of personal data (including data held in internal analytics warehouses, logs, and backend tools) are returned in a complete and intelligible form within the one-month deadline of Article 12, and document any restrictions you rely on under Article 15(4). If you are considering challenging a DPC or other EEA preliminary finding: Procedural arguments about the scope of an inquiry are unlikely to defeat findings on the merits where the regulator has identified systemic issues affecting many users. Map your data subject rights process with Verdaio's GDPR Quick Check.

French CNIL 2025 Annual Report: Record €486.8 Million in Fines, AI Act Powers to Expand in 2026

On 19 May 2026, France's data protection authority (the CNIL) published its 2025 annual report. The CNIL recorded 20,150 complaints (a 10% rise on 2024), 6,167 data breach notifications (up 9.5%), 323 investigations and 259 corrective decisions including 83 sanctions totalling €486,839,500. For 2026, the CNIL will dedicate half of its controls and enforcement actions to data security, and confirmed it is already the designated authority for prohibited AI practices under the EU AI Act and is set to be named market surveillance authority for several categories of high-risk AI systems.

What changed

On 19 May 2026, France's Commission nationale de l'informatique et des libertés (CNIL) presented its 2025 annual report, marking another record year for enforcement and complaints. The CNIL received 20,150 complaints in 2025, a 10% increase on 2024, and 6,167 notifications of personal data breaches, up 9.5%. It carried out 323 investigations, issued 259 corrective decisions, and adopted 83 sanctions for a total of €486,839,500, the highest annual fine total in the authority's history. Two sanctions issued on 1 September 2025, both relating to cookies and other trackers, accounted for €475 million of that total.

The CNIL also set out its 2026 priorities. Half of all controls and enforcement actions this year will focus on data security, in response to the continued rise in breach notifications. On artificial intelligence, the CNIL confirmed that it is already the designated national authority to monitor prohibited AI practices under Article 5 of the EU AI Act, and is expected shortly to be designated as the market surveillance authority for several categories of high-risk AI systems, including biometrics, migration, law enforcement, employment and education. The report also covers the CNIL's continued work on its AI regulatory sandbox, where six projects relating to the silver economy were supported during the year.

What it means for your business

If you handle personal data of users in France or sell into the French market: The CNIL's 2025 figures show enforcement intensity is rising on cookies, employee monitoring and data security, the three areas it identifies as driving the bulk of last year's fines. Review your cookie banners, monitor your data-breach response times against the Article 33 72-hour deadline, and audit your security controls against the storage-limitation and security principles of GDPR Articles 5 and 32. If you build, deploy or distribute AI systems used in France: The CNIL is positioning itself as one of the most active EU AI Act regulators and is on track to supervise several Annex III high-risk categories (biometrics, migration, law enforcement, employment, education) once formally designated. Map your AI systems against the prohibited practices in Article 5 and the high-risk categories in Annex III. Run a privacy review with Verdaio's GDPR Quick Check and an AI Act classification check with Verdaio's EU AI Act Assessment.

Italian Garante Fines Ambrosetti €85,000 for Plain-Text Passwords and Late Breach Notification

On 21 May 2026, Italy's data protection authority (the Garante) announced an €85,000 fine against the consultancy The European House - Ambrosetti for security and notification failures exposed by a data breach affecting 61,670 people. The Garante found roughly 36,000 account passwords stored in plain text and around 98,000 hashed with the outdated MD5 algorithm, alongside excessive retention of credentials for systems no longer in use. Although Ambrosetti notified the regulator within the 72-hour deadline, it informed the affected individuals only about two months later, and only after the authority intervened.

What changed

On 21 May 2026, the Italian Garante per la protezione dei dati personali published an enforcement decision fining The European House - Ambrosetti €85,000 following a data breach that exposed the names, email addresses, usernames and passwords of 61,670 people, including staff of client companies and internal users of Ambrosetti's online services. The Garante found that the company had stored about 36,000 passwords in plain text and roughly 98,000 using the MD5 hashing algorithm, not always with a salt, a configuration the authority considered inadequate against the security and integrity requirements of GDPR Articles 5(1)(f) and 32. The authority also found that the company retained credentials for systems that were no longer in use, in breach of the storage-limitation principle of Article 5(1)(e).

The Garante separately examined how Ambrosetti handled communication of the breach. The company notified the authority within the 72-hour window required by Article 33, but it informed the affected individuals only around two months after discovering the incident, and only after the Garante intervened. Ambrosetti argued that disclosure had been complicated by reputational concerns and by the organisation of the Cernobbio Forum, but the authority held that those reasons could not justify the delay or override the rights of the people whose data had been exposed. The Garante concluded that the breach posed a high risk to the rights and freedoms of data subjects, which under Article 34 of the GDPR triggers an obligation to communicate the breach to those individuals without undue delay.

What it means for your business

If you store user credentials or run any service that holds account passwords: Plain-text password storage and weak hashing remain among the clearest security failures a regulator can find. Hash passwords with a modern, salted algorithm, never keep them in readable form, and delete credentials for systems and accounts you no longer use, in line with the storage-limitation principle. If you handle personal data breaches: Notifying the supervisory authority within 72 hours under Article 33 is only half of the obligation. Where a breach poses a high risk to individuals, Article 34 requires you to inform those individuals without undue delay, and commercial or reputational concerns do not pause that clock. Map your breach-response plan and security controls with Verdaio's GDPR Quick Check.

EU Commission Opens Consultation on Draft Guidelines for Classifying High-Risk AI Systems

On 19 May 2026, the European Commission published draft guidelines on the classification of high-risk AI systems under Article 6 of the EU AI Act and opened a targeted public consultation that closes on 23 June 2026. The guidelines explain both routes to high-risk status, the Annex I product-safety route and the Annex III route across eight areas (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and border control, and justice), and include practical examples of AI systems that should or should not be classified as high-risk.

What changed

On 19 May 2026, the European Commission published its draft guidelines on the classification of high-risk AI systems and opened a targeted consultation on the AI Act Single Information Platform. The guidelines set out the Commission's interpretation of the concepts relevant to Article 6 of the EU AI Act, which defines two routes to high-risk classification. Under Article 6(1), an AI system is high-risk where it is itself a product, or a safety component of a product, covered by the Union harmonisation legislation listed in Annex I (for example medical devices, machinery, toys and lifts). Under Article 6(2), an AI system is high-risk where it falls within one of the eight areas listed in Annex III: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and the administration of justice and democratic processes.

In line with Article 6(5) of the EU AI Act, the guidelines are accompanied by a set of practical examples of AI systems that should or should not be classified as high-risk, giving providers and deployers concrete reference points for borderline cases. The targeted consultation runs until 23 June 2026 (22:00 CET) and is open to AI providers and developers, organisations using AI systems, public authorities, supervisory bodies, researchers, civil society and members of the public. The guidelines are designed to support uniform application and effective enforcement of Article 6 by providers, deployers and market surveillance authorities. They arrive ahead of the high-risk obligations themselves, whose application date for stand-alone Annex III systems was provisionally postponed to 2 December 2027 under the Digital Omnibus on AI agreement.

What it means for your business

If you build, deploy or distribute AI systems and are unsure whether they count as high-risk: These draft guidelines are the most detailed official steer yet on where the high-risk line sits. Map your AI systems against the Annex I product-safety route and the eight Annex III areas, and use the practical examples to test borderline cases such as HR, credit-scoring and biometric tools. If a specific use case is unclear, submit feedback to the consultation before 23 June 2026. Classification is the first step in every AI Act compliance programme: a system classified as high-risk triggers risk management, data governance, logging, transparency and human-oversight obligations. Run a classification check with Verdaio's EU AI Act Assessment.

EU Member States Confirm Digital Omnibus on AI Compromise, Lock 2 December 2027 Annex III Deadline

On 13 May 2026, the Council's Permanent Representatives Committee (Coreper) formally confirmed the 7 May 2026 provisional agreement on the Digital Omnibus on AI. The text fixes the high-risk Annex III application date at 2 December 2027 and the Annex I date at 2 August 2028, shortens the grace period for AI-content transparency solutions to three months (new deadline 2 December 2026), and postpones the deadline for national AI regulatory sandboxes to 2 August 2027.

What changed

On 13 May 2026, Member State ambassadors meeting in the Permanent Representatives Committee (Coreper) confirmed the compromise text on the Digital Omnibus on AI agreed with the European Parliament on 7 May 2026. The Council Presidency was authorised to send a letter to the European Parliament stating that, if Parliament adopts the text at first reading, the Council will approve Parliament's position. The compromise locks the new application dates for high-risk AI systems: 2 December 2027 for stand-alone Annex III systems (employment, education, credit scoring, biometrics, critical infrastructure, law enforcement, migration, justice) and 2 August 2028 for high-risk AI embedded in regulated Annex I products (medical devices, machinery, toys, lifts, watercraft).

The Coreper text also clarifies several technical points beyond the headline deadlines. The grace period for providers to implement watermarking and other transparency solutions for AI-generated content under Article 50(2) is cut from six months to three months, with the new deadline set on 2 December 2026. The deadline for competent national authorities to establish AI regulatory sandboxes under Article 57 is postponed to 2 August 2027. The text also adds a new Article 5 prohibition on AI systems generating non-consensual sexual content ("nudification" tools) and AI-generated child sexual abuse material, extends SME regulatory exemptions to small mid-cap enterprises (up to 500 employees) and broadens the lawful basis for processing sensitive personal data for bias detection and mitigation. Formal adoption by Parliament at first reading is expected before 2 August 2026.

What it means for your business

If you build, deploy or distribute high-risk AI systems or general-purpose AI: The new deadlines (2 December 2027 for Annex III, 2 August 2028 for Annex I) are now locked in by Coreper but are not yet law until Parliament adopts at first reading. Until that adoption, the original 2 August 2026 deadline applies. If you build generative AI consumer products: The reduced three-month grace period means watermarking and content-provenance solutions must be in place by 2 December 2026, three months earlier than the originally proposed six-month grace. Audit your tooling against the new "nudification" and CSAM prohibitions before adoption. Run a classification check with Verdaio's EU AI Act Assessment.

EU Council Adopts Conclusions on Human-Centred AI in Education, Reinforces Teacher AI Literacy

On 11 May 2026, the EU Education, Youth, Culture and Sport Council adopted conclusions calling for an ethical, safe and human-centred approach to artificial intelligence in education. The conclusions ask Member States to strengthen teachers' AI literacy, embrace AI's potential while mitigating bias, misinformation and data-protection risks, and ensure teachers participate in the design and evaluation of AI tools used in classrooms.

What changed

On 11 May 2026, EU education ministers meeting as the Council adopted conclusions on the role of teachers in the era of AI, calling for an ethical, safe and human-centred approach to AI in education. The conclusions ask Member States to boost teachers' AI literacy, promote education-specific AI tools, address digital divides, and safeguard teachers' working conditions and well-being. The Council also argues that teachers should have an opportunity to contribute to the design and evaluation of AI tools, in line with an approach based on "digital humanism" that ensures technology supports human agency and democratic values.

The conclusions explicitly raise concerns about reduced autonomy, over-reliance on technology, and risks relating to bias, misinformation and data protection. The Council notes that AI in education could exacerbate inequalities and digital divides, affect learners' concentration and skill acquisition, and have broader societal and environmental implications. The conclusions reinforce Article 4 of the EU AI Act (the AI literacy obligation), which requires providers and deployers of AI systems to ensure their staff and persons dealing with the operation and use of those systems have a sufficient level of AI literacy. They also align with the classification of AI used in education and vocational training as a "high-risk" use case under Annex III of the EU AI Act.

What it means for your business

If you provide AI systems to schools, universities or vocational training providers, or if you deploy AI in an education or training context: Education ministers are now formally aligned on a human-centred deployment model. Expect Member States to push procurement requirements that include teacher AI-literacy training, transparent evaluation criteria, and bias and misinformation safeguards. The conclusions also reinforce that the Article 4 AI literacy obligation applies to all AI deployers, not just those in high-risk sectors. If you sell AI tools for HR, recruitment, assessment or scoring in an education or training context: Classification as high-risk under Annex III is now coupled with these political conclusions, raising the bar for transparency, human oversight and evaluation. Run a classification check with Verdaio's EU AI Act Assessment and review your training programme with Verdaio's AI Literacy guide.

EU Commission Opens Public Consultation on AI Act Article 50 Transparency Guidelines

On 8 May 2026, the European Commission published draft guidelines on the implementation of the transparency obligations under Article 50 of the EU AI Act and opened a targeted consultation that closes on 3 June 2026. From 2 August 2026, providers must inform users when they interact with an AI system and add machine-readable marks to AI-generated or manipulated audio, image, video and text, while deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest.

What changed

The draft guidelines clarify the scope of Article 50 transparency duties for both providers and deployers of AI systems. Providers of AI systems intended to interact directly with people must design them so users are informed they are interacting with an AI system, unless that fact is obvious. Providers of generative AI systems must mark synthetic audio, image, video and text outputs in a machine-readable format that allows detection as artificially generated. Deployers must disclose AI-generated deepfakes and AI-generated text published to inform the public on matters of public interest, and must inform people exposed to emotion recognition or biometric categorisation systems.

The Commission has run the guidelines work in parallel with the Code of Practice on marking and labelling of AI-generated content: the guidelines clarify legal scope and the Code addresses technical implementation. The targeted consultation runs until 3 June 2026 and is open to providers, deployers, businesses, public authorities, academics and citizens. Article 50 obligations apply from 2 August 2026 and were not affected by the 7 May 2026 Digital Omnibus on AI deal, which postponed the high-risk Annex III deadline to 2 December 2027 but left the transparency timeline intact.

What it means for your business

If you build or deploy generative AI, chatbots, deepfake tools, emotion recognition or biometric categorisation systems: The 2 August 2026 transparency deadline still stands. Plan now for chatbot disclosure, machine-readable watermarking of synthetic outputs, and clear deepfake labelling, and submit feedback before 3 June 2026 if your use case needs clarification. Run a classification check with Verdaio's EU AI Act Assessment.

Irish DPC Fines PTSB €277,500 for Voice-Phishing Account Takeover Failures

On 8 May 2026, Ireland's Data Protection Commission concluded its inquiry into Permanent TSB (PTSB) and imposed total fines of €277,500: €250,000 for security and integrity failings under GDPR Articles 5 and 32, plus €27,500 for failing to notify the DPC of personal data breaches within 72 hours under Article 33. The breaches stemmed from voice-phishing attacks against PTSB's "Open24" contact centre in 2022, where attackers posed as customers and changed account details on three occasions, exposing the holders to fraud and financial loss.

What changed

The DPC found that PTSB's call-centre identification controls were not consistently followed in three separate incidents in 2022. Attackers, already in possession of certain customer information, contacted PTSB's "Open24" contact centre and impersonated the legitimate account holders to amend account details and obtain further account information. PTSB had reimbursed the affected customers for the funds taken by external fraudsters, but the DPC concluded that the bank infringed the security and integrity requirements of GDPR Articles 5(1)(f) and 32(1).

The DPC also found a separate breach of Article 33: PTSB failed to notify the regulator without undue delay and within 72 hours of becoming aware of the incidents. The total enforcement is €277,500 (€250,000 for the Article 5 and 32 infringements and €27,500 for the Article 33 infringement) and is accompanied by a formal reprimand. PTSB has acknowledged the outcome and stated that it has improved its processes to reduce the risk of similar incidents.

What it means for your business

If you operate a contact centre or any voice-channel customer service handling personal or financial data: Voice-channel social engineering remains a top regulatory concern. Map your caller-authentication procedures against Articles 5(1)(f) and 32(1), train staff on knowledge-based authentication weaknesses and impersonation indicators, and ensure your incident-response process can detect and notify the supervisory authority within the 72-hour window of Article 33. Run a structured posture check with Verdaio's GDPR Quick Check.

EU AI Act Omnibus Deal Reached: High-Risk Annex III Deadline Postponed to 2 December 2027

On 7 May 2026, the European Parliament and Council reached a provisional political agreement on the Digital Omnibus on AI, postponing the high-risk AI Act obligations originally due on 2 August 2026. Stand-alone Annex III systems now apply from 2 December 2027 and AI embedded in regulated Annex I products from 2 August 2028. The deal also adds a new prohibited practice covering AI "nudification" tools and AI-generated child sexual abuse material.

What changed

After the 28 April 2026 trilogue collapsed without agreement, negotiators returned on 7 May 2026 and closed a provisional deal under the Cypriot Council Presidency. Annex III stand-alone high-risk obligations (employment, education, credit scoring, biometrics, critical infrastructure, law enforcement, migration, justice) are postponed by 16 months, from 2 August 2026 to 2 December 2027. Annex I obligations covering AI embedded in regulated products (medical devices, machinery, toys, lifts, watercraft) are postponed by 24 months, to 2 August 2028. Both deadlines are now fixed dates rather than conditional on harmonised standards being in place.

The deal introduces a new prohibited AI practice under Article 5: AI systems used to generate non-consensual sexually explicit content (so-called "nudification" tools) and child sexual abuse material. Targeted simplifications extend SME regulatory exemptions to small mid-cap companies (SMCs, up to 500 employees), narrow certain technical documentation requirements, and broaden the lawful basis for processing sensitive personal data for bias detection and mitigation. The provisional agreement still requires formal adoption by both co-legislators before 2 August 2026 to take effect; until that adoption, the original 2 August 2026 deadline remains the legal baseline.

What it means for your business

If you build, deploy or distribute high-risk AI systems (HR, education, credit scoring, biometrics, AI in regulated products) or general-purpose AI: Plan for a 2 December 2027 (Annex III) or 2 August 2028 (Annex I) deadline, but do not stop compliance work. Formal adoption is still pending and the original 2 August 2026 deadline applies until both co-legislators sign off. The extra time is best used to mature risk management, data governance and human-oversight controls, not to delay them. If you build generative AI consumer products: Audit your tooling against the new "nudification" and CSAM prohibitions before the deal is adopted. Run a classification check with Verdaio's EU AI Act Assessment.

EU Commission Opens Public Consultation on Revised ESRS, Closes 3 June 2026

On 6 May 2026, the European Commission opened a one-month "Have Your Say" public consultation on the draft revised European Sustainability Reporting Standards (ESRS) and on a separate voluntary standard for smaller companies. The consultations close on 3 June 2026, with adoption planned for Q2 2026.

What changed

The draft revised ESRS reduce mandatory datapoints by over 60% and total datapoints by over 70%, are shorter and clearer, introduce new flexibilities, and simplify the materiality assessment used to determine what must be reported. The Commission estimates these changes will reduce reporting costs per company by more than 30%. The revised standards build largely on technical advice provided by EFRAG in December 2025.

Undertakings within the scope of the Corporate Sustainability Reporting Directive (CSRD) must use the revised ESRS for financial years beginning on or after 1 January 2027. However, undertakings subject to the CSRD for financial year 2026 may choose to apply the revised ESRS for that financial year instead of the existing ESRS. The voluntary standard introduces a "value chain cap": CSRD in-scope companies cannot require value-chain partners with 1,000 employees or fewer to provide information beyond the voluntary standard, unless those partners choose to provide it.

What it means for your business

If you are an undertaking in scope of the CSRD (1,000+ employees, €450M+ turnover): Review the draft revised ESRS now, especially the materiality assessment changes and reduced datapoint set, and decide whether to apply the revised standards early for FY 2026 or wait for FY 2027. Submit feedback before 3 June 2026 if you have specific concerns. If you are a smaller company in a CSRD value chain: The voluntary standard plus the value chain cap limits what your large clients can require from you on sustainability data. Run a gap-check with Verdaio's ESRS Gap Analysis.

European Parliament Calls for Stronger DMA Enforcement, Criticises 'Modest' Fines on Apple and Meta

On 30 April 2026, the European Parliament adopted a resolution (P10_TA(2026)0160) urging the Commission to use all enforcement tools under the Digital Markets Act and to conclude pending non-compliance proceedings without undue delay. MEPs called the €500M Apple and €200M Meta fines 'modest' and warned that pressure from third countries should not weaken EU enforcement.

What changed

In its resolution adopted by show of hands on 30 April 2026, the European Parliament called on the Commission to make full use of all DMA enforcement instruments: regulatory dialogue, market investigations, non-compliance proceedings, inspections, interim measures, fines and periodic penalty payments. MEPs regretted the 'modest' fines imposed on Apple (€500M) and Meta (€200M) in April 2025 and stressed that effective and proportionate fines are essential to ensure deterrence. The resolution focuses on the practical effect of DMA rules on competition, market access and user choice, rather than on formal compliance alone.

Parliament urged the Commission to prioritise enforcement of interoperability, data access, anti-steering and anti-self-preferencing obligations, and called for closer scrutiny of AI-driven search and assistant tools, including Google AI Overviews, Gemini, Apple Siri, Meta WhatsApp AI, Amazon Rufus and Microsoft Copilot. Although the resolution does not name third countries directly, MEPs warned that external pressure must not compromise the EU's sovereignty to enforce its own digital rules. The vote follows the Commission's first DMA review report (28 April 2026), which concluded that the DMA remains fit for purpose.

What it means for your business

If you operate or distribute services on a designated gatekeeper platform (App Store, Google Play, Amazon Marketplace, Facebook, Instagram, TikTok, Search, Booking.com): Expect the Commission to accelerate ongoing non-compliance proceedings and to focus on practical effects (real choice, real interoperability) rather than formal box-ticking. Plan for higher fines on repeat or continued non-compliance, and for closer scrutiny of AI-driven search and assistant tools when integrated with gatekeeper services. Track DMA developments and align your distribution, advertising and consent flows accordingly.

Irish Supreme Court Upholds Stay on €530M TikTok GDPR Fine and Data Transfer Orders

On 30 April 2026, Ireland's Supreme Court unanimously dismissed the Data Protection Commission's appeal in the TikTok case, leaving the High Court stay on the DPC's €530M fine and EEA-to-China data transfer orders in place during the substantive appeal. Justice Hogan held that the legal test for staying a regulator's decision is a matter of national procedural law and does not undermine the full effectiveness of EU data protection law.

What changed

In May 2025 the Irish DPC fined TikTok Technology Limited €530M and ordered it to bring its EEA-to-China transfers into compliance within six months, finding that TikTok had failed to verify the effectiveness of supplementary measures and Standard Contractual Clauses under Article 46(1) GDPR. TikTok appealed to the High Court, which granted a stay on the corrective orders pending the substantive ruling, citing the limited and temporary risk to consumers against the difficulty of quantifying the harm to TikTok from immediate enforcement. The DPC then appealed the stay itself to the Supreme Court.

On 30 April 2026, a five-judge Supreme Court led by Justice Hogan unanimously dismissed the DPC's appeal. The Court held that the test for staying a regulatory decision belongs to national procedural law, not EU law, and that applying the Irish stay test does not undermine the full effectiveness of GDPR enforcement. The €530M fine remains formally imposed but unenforced; the corrective orders to suspend the EEA-to-China transfers are paused. The substantive High Court appeal continues at pace.

What it means for your business

If you operate cross-border data transfers (especially to non-adequacy jurisdictions) or rely on Standard Contractual Clauses with supplementary measures: the DPC decision still stands as the EU benchmark on what 'essentially equivalent protection' under Article 46(1) GDPR requires. The stay only freezes enforcement while the Irish courts review the underlying decision; it does not weaken the substantive compliance obligation. Audit your transfer impact assessments, supplementary measures, and onward-access controls. Run a structured check with Verdaio's GDPR Quick Check.

Italian Garante: Hotels and B&Bs Cannot Retain Copies of Guest ID Documents After Police Reporting

On 29 April 2026, the Italian Garante issued a clarifying note to industry trade associations confirming that hotels, B&Bs, and short-term rentals cannot retain photocopies or digital images of guests' identity documents beyond the time strictly necessary to transmit the data to public security authorities. Once the Alloggiati Web reporting is complete, any document copies must be deleted or destroyed; only the automated transmission receipt may be kept (for up to five years as proof of compliance).

What changed

Italian public security law requires accommodation operators to identify guests and transmit their data to police authorities through the "Alloggiati Web" portal. The Garante's note clarifies that this legal obligation does not authorise hotels, B&Bs, or short-term rental operators to retain photocopies, scans, or smartphone images of identity documents. The Authority issued the note in response to a rise in data breaches and complaints, including the practice of receiving documents via WhatsApp or other messaging apps, which exposes guests to identity theft and unauthorised access risks.

Once data transmission to public security authorities is complete, any copy of an identity document acquired for that purpose must be immediately deleted or destroyed. The only record accommodation providers may retain is the automated receipt produced by the Alloggiati Web portal, kept for up to five years to evidence the reporting obligation. The Garante also reminds operators that, as GDPR data controllers, they must adopt adequate security measures, properly train staff handling guest data, and notify the Authority within 72 hours of any personal data breach (and, where appropriate, inform affected individuals).

What it means for your business

If you operate a hotel, B&B, or short-term rental in Italy (or process Italian guest data from abroad): Audit your check-in workflow now. Stop photographing or storing identity documents after the Alloggiati Web reporting; keep only the transmission receipt. Review your retention policy, train front-desk staff on the new guidance, and ensure your booking and PMS systems do not preserve ID images by default. Run a gap-check with Verdaio's GDPR Quick Check.

AI Omnibus Trilogue Collapses: 2 August 2026 High-Risk AI Act Deadline Stays in Force

The 28 April 2026 political trilogue on the Digital Omnibus on AI ended without agreement after roughly 12 hours of negotiations, with the conformity assessment architecture for AI in regulated products (Annex I) the unresolved sticking point. A follow-up trilogue is scheduled for around 13 May 2026; until and unless agreement is reached, the EU AI Act's 2 August 2026 high-risk obligations remain legally in force.

What changed

The European Parliament, Council, and Commission entered the second political trilogue on the Digital Omnibus on AI on 28 April 2026, aiming to postpone the high-risk compliance deadline (originally 2 August 2026) and integrate AI Act obligations more closely with sectoral product safety law. After approximately 12 hours of negotiations the talks broke down on Annex I, where the European Parliament pushed to move sectoral legislation (machinery, medical devices, in-vitro diagnostics) from Section A (combined AI Act and sectoral assessment) to Section B for primarily sectoral handling. The Council declined to move and the single disagreement was sufficient to block the entire package.

A follow-up political trilogue is scheduled for around 13 May 2026. The Cypriot Council Presidency is expected to attempt closure before its term ends on 30 June 2026, after which the Lithuanian Presidency would take over. With no agreed Omnibus, the original AI Act timetable stands: providers and deployers of high-risk AI systems remain on the hook for the 2 August 2026 obligations under Articles 9-15: risk management, data governance, technical documentation, logging, transparency, human oversight, and accuracy and robustness.

What it means for your business

If you build, deploy or distribute high-risk AI systems (particularly in HR, education, credit scoring, biometrics, or AI embedded in regulated products): Plan as if the 2 August 2026 deadline will hold. Trilogue uncertainty is not a basis for delaying compliance work. Even if a postponement is later agreed, an early start protects you from a compressed timeline. Run a classification check with Verdaio's EU AI Act Assessment.

Commission and EDPB Launch Joint Guidance on the Interplay Between EU Competition Law and the GDPR

On 28 April 2026, the European Commission's competition services and the European Data Protection Board announced joint work on guidance clarifying how EU competition law and the GDPR interact. The initiative builds on the prior DMA-GDPR joint guidelines and will inform a remote stakeholder event on 29 June 2026.

What changed

Commission services and the EDPB will jointly develop guidance on situations where data protection law is relevant for competition law assessment, and conversely where competition considerations matter for data protection. According to the announcement, the guidance is expected to address dominant digital platforms, access to user data, data portability, online advertising, contractual conditions linked to data use, and digital ecosystems. The work formalises a coordination model already piloted through the joint DMA-GDPR guidelines.

The EDPB has invited stakeholders to a remote event on 29 June 2026 to inform the upcoming guidelines, with a call for expressions of interest to follow in the coming weeks. The announcement signals continued integration of GDPR analysis into EU competition enforcement, particularly for gatekeepers and platforms whose business models rely on personal data. Companies operating across both regimes (large platforms, ad-tech, marketplaces and data brokers) should expect more cross-regulatory scrutiny.

What it means for your business

If you operate a digital platform, ad-tech product, or any service whose terms condition access on data use: Expect EU competition authorities to assess your data-handling practices through a GDPR lens, and the EDPB to factor competition outcomes into its guidance. Review the alignment of your privacy notices, consent flows and data-portability mechanisms with both frameworks. Run a gap-check with Verdaio's GDPR Quick Check.

Italian Garante Adopts Guidelines on Tracking Pixels in Email: Consent Mandatory, 6 Months to Comply

The Italian Garante adopted Guidelines on the use of tracking pixels in email communications on 17 April 2026, confirming that pixel tracking falls under Article 122 of the Italian Privacy Code and, in ordinary cases, requires prior, free, specific and informed consent. Senders and email platform providers have six months from publication in the Official Gazette to comply.

What changed

Tracking pixels are minimal-size images, typically invisible to the recipient, inserted into email messages to detect opens, clicks and device or behavioural signals. The Garante's Guidelines classify them as "instruments of access and storage of information" under Article 122 of the Italian Privacy Code (the national transposition of the ePrivacy Directive) and require prior, free, specific, informed and unambiguous consent before any tracking pixel is activated. Controllers must provide clear, transparent information, easy and granular consent-revocation mechanisms, and privacy-by-design and privacy-by-default measures such as non-intelligible identifiers separated from the email address.

The Guidelines apply broadly to information-society service providers, email service providers, managers of bulk-email sending platforms and any entity using tracking pixels in electronic communications. Limited consent exemptions cover cybersecurity (anti-phishing, fraud prevention), aggregated anonymous statistics that cannot identify recipients, and strictly necessary institutional or service communications. The Garante grants operators six months from publication in the Official Gazette to bring their systems into compliance.

What it means for your business

If you run email marketing, transactional emails or newsletters targeting Italian recipients: Review every pixel, open-tracker and click-tracker in your ESP or CRM stack, map each to a specific legal basis, and align your consent flows and privacy notices with the Guidelines. Revisit data-minimisation controls (pseudonymous IDs, short retention) and document the exemption you rely on where no consent is collected. Run a gap-check with Verdaio's GDPR Quick Check.

Italian Garante Fines Poste Italiane and Postepay €12.5M for Unlawful App Data Monitoring

Italy's data protection authority (Garante) imposed fines totalling over €12.5 million on Poste Italiane (€6.624M) and Postepay (€5.877M) for the BancoPosta and Postepay mobile apps' unlawful monitoring of users' device data. Users were required to authorise access to installed applications as a mandatory condition of service.

What changed

The Garante ruled that the BancoPosta and Postepay mobile apps' mandatory authorisation to monitor installed applications and running processes on users' devices was excessively invasive and not strictly necessary for fraud prevention. The investigation followed complaints received by the Authority from April 2024. Additional violations found include inadequate user information, absence of a proper Data Protection Impact Assessment, failure to adopt adequate security and retention measures, and irregularities in the designation of data controllers and processors.

Poste Italiane has announced it will appeal to the Rome Court, arguing that access to device data complied with PSD2 and had been recognised by Banca d'Italia as a legitimate fraud-prevention measure. The total €12.5M enforcement action is one of the largest Italian GDPR fines issued in 2026 and continues the Garante's focus on mobile-app privacy following prior decisions against banking and payment apps.

What it means for your business

If you run a mobile app that reads device state (installed apps, running processes, device fingerprinting): The Garante's decision sets a clear precedent that mandatory, all-or-nothing authorisations to access device data are disproportionate, even for fraud prevention. Review data minimisation, user-information flows, DPIA coverage, and security/retention controls for your mobile apps. Run a gap-check with Verdaio's GDPR Quick Check.

EDPB Plenary: Scientific Research Guidelines Adopted, Europrivacy Seal Approved for Transfers

At its 16 April 2026 plenary, the European Data Protection Board adopted Guidelines 1/2026 on processing personal data for scientific research and, for the first time, approved a European Data Protection Seal (Europrivacy) as a valid Article 46 tool for international data transfers.

What changed

Guidelines 1/2026 clarify the boundaries of the GDPR "scientific research" concept. The EDPB sets six indicative factors for identifying research processing (methodical approach, ethical standards, verifiability, autonomy, research objective, and contribution to knowledge) and explains how data subject rights, including the right to erasure and the right to object, can be limited under Article 89 GDPR. The Board also covers appropriate technical and organisational safeguards, including pseudonymisation, anonymisation, secure processing environments, and ethical oversight. The Guidelines are open for public consultation until 25 June 2026. A separate EDPB "sprint team" was created to finalise the long-pending Guidelines on anonymisation by summer.

The Board also adopted Opinion 15/2026 recognising the Europrivacy certification criteria as a European Data Protection Seal under Articles 42 and 46(2)(f) GDPR. This is the first time a certification mechanism has been approved at EU level as a valid tool for transfers. Data importers outside the EU/EEA who are not subject to the GDPR can now apply for Europrivacy certification and rely on it, together with binding and enforceable commitments, to receive personal data from EU controllers.

What it means for your business

If you process personal data for research: Start mapping your activities against the six indicative factors and review how you document consent, safeguards and the limits on data subject rights. If you transfer personal data outside the EU/EEA: Certification is now a practical alternative to Standard Contractual Clauses and BCRs, useful where providers are reluctant to sign SCCs, or where the destination jurisdiction creates uncertainty. Review your GDPR posture and see whether certification-based transfers fit your vendor stack.

Italian Garante: "FaceBoarding" Facial Recognition at Milan Linate Violates GDPR

The Italian Garante declared the "FaceBoarding" facial-recognition boarding system at Milan Linate airport, operated by SEA, unlawful, ordering a definitive stop to biometric processing. The decision aligns with the EDPB's 2025 opinion on airport facial recognition and targets missing encryption, excessive retention, and non-consensual data capture.

What changed

The Authority found that SEA, the Milan Linate airport operator, processed passengers' biometric data (facial templates) without a valid legal basis, failed to encrypt stored biometric models, retained templates for up to 12 months (an excessive period), and provided inaccurate information to data subjects. The system also captured facial images of passengers who had not opted into FaceBoarding but used hybrid boarding gates, processing their biometric data without consent.

The decision confirms a provisional limitation measure adopted in September 2025 and is explicitly aligned with the EDPB's 2025 opinion on facial recognition in airports, which concluded that passenger convenience does not justify default biometric processing. FaceBoarding is the first high-profile Italian application of the EDPB opinion and reinforces EU-wide expectations for airport biometrics: encryption of templates, minimised retention, explicit opt-in, and genuine non-biometric alternatives.

What it means for your business

If you deploy biometric systems (facial recognition, fingerprint) for access, authentication, or customer experience: Biometric processing in public or semi-public spaces must satisfy strict necessity, encryption, and retention standards, even with consent. Review the Article 9 GDPR legal basis, technical safeguards, and whether you offer a real non-biometric alternative. Biometric systems may also trigger EU AI Act obligations. Check your posture with Verdaio's GDPR Quick Check and EU AI Act Assessment.

EDPB Adopts Harmonised DPIA Template: Public Consultation Open Until 9 June 2026

The European Data Protection Board adopted a harmonised Data Protection Impact Assessment template to help controllers structure, harmonise and evidence their DPIA reporting across the EU. It is the first EU-level DPIA template and is open for public consultation until 9 June 2026.

What changed

Delivering on the EDPB's Helsinki Statement commitment to simplify GDPR compliance, the Board adopted a common DPIA template covering all core Article 35 elements: description of processing and its purposes, necessity and proportionality assessment, risks to data subjects, and mitigating measures. The template is accompanied by an explainer document breaking down key concepts in plain language and addressing common questions from controllers.

Use of the template is not mandatory, but organisations that use it will benefit from predefined fields that prompt complete, structured responses and evidence of accountability. After the public consultation closes on 9 June 2026, national supervisory authorities will take steps to adopt the template either as their sole standard or as a meta-template to which existing national-specific templates will align.

What it means for your business

If you conduct DPIAs: This is the first time the EU has offered a single, consistent DPIA format that will be recognised across Member States. Multinational controllers benefit most, one template, one structure, accepted by every DPA. Action: Review your current DPIA methodology against the draft template, submit feedback before 9 June if relevant, and plan to migrate existing DPIAs once national DPAs formally adopt it. Run a gap-check with Verdaio's GDPR Quick Check.

NIS2 Compliance Deadline: October 2026: First Audits Due by June

Companies in scope of the NIS2 Directive have until October 2026 to achieve full compliance. The first audit deadline has been set for 30 June 2026, and Member States must identify critical entities by 17 July 2026.

What changed

The NIS2 Directive (2022/2555) significantly expanded the scope of EU cybersecurity obligations from the original NIS Directive. It covers medium and large organisations in 18 sectors including energy, transport, banking, health, digital infrastructure, and ICT service management. Companies must implement risk management measures, incident reporting procedures, supply chain security assessments, and business continuity plans.

The first compliance audit deadline was originally set for 31 December 2025 but has been moved to 30 June 2026. By 17 July 2026, each Member State must formally identify the critical entities in their jurisdiction. Penalties for non-compliance include fines of up to €10M or 2% of global turnover for essential entities, and €7M or 1.4% for important entities. Senior management can be held personally liable.

What it means for your business

If you operate in any of the 18 NIS2 sectors: The compliance deadline is now less than 6 months away. Start with a gap assessment to understand your current posture, particularly around incident reporting (72-hour notification requirement), supply chain risk management, and board-level accountability. Not sure if NIS2 applies to you? Run the free NIS2 Readiness Assessment.

CSRD Omnibus Now Law: Scope Cut by 80%, Only 1,000+ Employee Companies In

The EU's Omnibus I simplification package raises the CSRD reporting threshold to companies with 1,000+ employees and €450M+ in turnover, removing roughly 80% of previously in-scope businesses. Listed SMEs are fully exempt.

What changed

The Omnibus I Directive has raised the CSRD applicability threshold from the original 250-employee threshold to 1,000 employees and €450 million in net turnover. The law also removes listed SMEs from mandatory scope entirely, they will only report on a voluntary basis using a simplified VSME standard.

The wave 2 deadline (financial year 2025, reporting in 2026) and wave 3 deadline (FY 2026) are both postponed by two years. Wave 1 companies (those already reporting for FY 2024) are not affected. The Omnibus I Directive was published in the EU Official Journal on 26 February 2026 and entered into force on 19 March 2026. These changes are now binding law.

What it means for your business

If you have under 1,000 employees: You are likely out of mandatory scope under the new threshold. However, large customers and financial institutions may still require CSRD-aligned disclosures through their own value chain reporting. If you have 1,000+ employees: Mandatory reporting continues, the core ESRS standards remain unchanged. Use the delay to strengthen your data collection processes.

AI Act High-Risk Deadline: Extension to December 2027 in Final Negotiations

The EU Digital Omnibus proposes extending the compliance deadline for high-risk AI systems from August 2026 to December 2027. Trilogue negotiations are underway with political agreement expected by late April 2026. Until formally adopted, August 2, 2026 remains the legal deadline.

What changed

The EU Digital Omnibus package proposes extending the deadline for high-risk AI system compliance under the EU AI Act. The original Article 6 Annex III deadline is August 2, 2026. The proposal would push this to December 2027 for stand-alone high-risk systems, and to August 2028 for high-risk AI embedded in regulated products (medical devices, machinery). Trilogue negotiations between the European Parliament and Council started on 26 March 2026, with political agreement expected by 28 April 2026.

The proposed extension covers obligations under Articles 9-15 of the AI Act: risk management systems, data governance, technical documentation, logging, transparency, human oversight, and accuracy/robustness requirements. The prohibited practices ban (effective February 2025) and GPAI model obligations (effective August 2025) are not affected. The Omnibus also proposes adding a new prohibited practice: AI systems generating non-consensual intimate imagery.

What it means for your business

If you deploy high-risk AI: The extension is very likely to pass, but it is not yet law. The responsible approach is to prepare for the August 2026 deadline while expecting the relief. If adopted as expected, you will have until December 2027 for Annex III systems. Use the time to build compliant processes rather than waiting. We will update this story when the final text is published.

ECB, EBA and ESMA Warn: ESRS Simplifications Risk Undermining Data Quality

Four EU financial regulators published joint opinions warning that the Omnibus reliefs and permanent exemptions in the revised ESRS could significantly reduce the availability of decision-useful sustainability data.

What changed

In February 2026, the European Central Bank (ECB), European Banking Authority (EBA), European Insurance and Occupational Pensions Authority (EIOPA), and European Securities and Markets Authority (ESMA) published their opinions on the revised European Sustainability Reporting Standards. All four regulators share a core concern: the cumulative effect of permanent reliefs, phase-ins, and exemptions risks undermining the availability of key quantitative data that financial institutions need for risk assessment and lending decisions.

The regulators also highlighted that several reliefs go beyond, or deviate from, the IFRS/ISSB framework, creating interoperability gaps between EU and international sustainability reporting standards. This matters for companies with global investors or operations, who may need to report under both frameworks.

What it means for your business

If you report under ESRS: Even though the Omnibus reduces mandatory scope, the financial sector, your banks, investors, and insurers, still expects comprehensive sustainability data. Companies that only meet the minimum simplified requirements may face challenges accessing green finance or satisfying due diligence requests from larger clients.

EU Taxonomy Reporting Simplified: 10% Materiality Threshold Introduced

A new EU delegated act introduces a 10% materiality threshold for Taxonomy reporting, significantly reducing the number of activities companies must assess and disclose.

What changed

The European Commission adopted a new delegated act amending the EU Taxonomy Disclosures Delegated Regulation. The key change is a 10% materiality threshold: companies no longer need to assess and report on Taxonomy alignment for activities that represent less than 10% of their total revenue, capital expenditure (CapEx), or operating expenditure (OpEx).

The delegated act also introduces simplifications to the "Do No Significant Harm" (DNSH) assessment, reduces the number of mandatory data points, and provides clearer guidance on how to handle activities that span multiple NACE codes.

What it means for your business

If you're already reporting: Review which activities fall below the 10% threshold, you may be able to exclude a significant portion of your current assessment scope. If you haven't started: This simplification makes first-time Taxonomy reporting considerably more manageable. The threshold applies for reporting periods from 2025 onwards.

EU AI Act: Prohibited AI Practices Are Now Enforceable

From 2 February 2025, the EU AI Act's ban on unacceptable-risk AI systems became legally enforceable across all Member States. Systems that manipulate users, exploit vulnerabilities, or enable social scoring are now prohibited by law.

What changed

Article 5 of the EU AI Act, listing AI systems with unacceptable risk, became enforceable on 2 February 2025, six months after the regulation entered into force. This includes absolute prohibitions on: AI systems that use subliminal techniques to influence behaviour, systems that exploit vulnerabilities of specific groups, real-time biometric identification in public spaces (with narrow exceptions), social scoring by public authorities, and AI used to infer emotions in workplaces and schools.

Member States were required to designate national market surveillance authorities and notify the European AI Office by this date. The AI Office, established within the European Commission, oversees enforcement for general-purpose AI models. National authorities handle enforcement for other AI systems.

What it means for your business

Immediate action required: If your organisation uses or deploys AI systems, review them against the Article 5 prohibited practices list now. Violations can result in fines of up to €35M or 7% of global annual turnover. Most business AI tools (productivity, analytics, customer service) are not prohibited, but AI used in recruitment, credit scoring, or affecting individuals in sensitive contexts requires careful review.

First DMA Penalties: Apple Fined €500M, Meta €200M

The European Commission issued its first-ever Digital Markets Act enforcement decisions, fining Apple €500M and Meta €200M for failing to comply with their DMA obligations as designated gatekeepers.

What changed

On 23 April 2025, the European Commission issued its first enforcement decisions under the Digital Markets Act (DMA). Apple was fined €500M for its App Store practices, specifically for not allowing app developers to freely direct users to alternative purchasing options outside the App Store. Meta was fined €200M for its "pay or consent" advertising model on Facebook and Instagram, which the Commission found did not give users a genuine free alternative to data-based advertising.

Both companies were also ordered to remedy their non-compliant practices within 60 days. The DMA targets large digital platforms designated as "gatekeepers", currently Apple, Alphabet, Meta, Amazon, Microsoft, ByteDance, and Booking.com. The fines can reach up to 10% of global annual turnover (20% for repeat infringements) and up to 5% of average daily worldwide turnover per day for non-compliance with interim measures.

What it means for your business

If you use gatekeeper platforms: These decisions signal that app stores, search rankings, and advertising systems on major platforms may change to comply with DMA requirements, potentially affecting your distribution and marketing strategies. If you are a gatekeeper platform: The DMA is now actively enforced. Non-compliance carries substantial financial risk.

GDPR Enforcement Record: TikTok Fined €530M for Sending EU Data to China

Ireland's Data Protection Commission fined TikTok €530M, the third largest GDPR fine on record, for transferring EU users' personal data to China without adequate legal safeguards under Chapter V of the GDPR.

What changed

The Irish Data Protection Commission (DPC) concluded a multi-year investigation into TikTok's international data transfers, finding that TikTok had transferred EU/EEA user data to its parent company ByteDance in China without meeting the strict adequacy requirements of GDPR Chapter V. The €530M fine consists of €485M for the transfer violations and €45M for a transparency infringement regarding TikTok's privacy policy.

This is the third largest GDPR fine ever issued, behind Meta's €1.2B fine (2023) and Amazon's €746M fine (2021). TikTok was also ordered to bring its data processing into compliance within six months. More than 360 GDPR fines were issued across Europe in 2025, with total enforcement reaching a record high.

What it means for your business

For any company that transfers personal data outside the EU/EEA: This fine reinforces that transfer mechanisms must be watertight. Standard Contractual Clauses (SCCs) are not sufficient if the destination country's laws prevent the data importer from complying with them in practice. Review your data transfer impact assessments (DTIAs), particularly for transfers to the US, India, and China. Consider data localisation where technically feasible.