The European Data Protection Supervisor (EDPS) issued a decision reprimanding the European Parliament for violating data protection law on its COVID‑testing website. The use of Google Analytics and Stripe was found to breach the CJEU's Schrems II ruling on EU‑US data transfers, and the Parliament’s cookie banners were deemed deceptive and non‑transparent. The EP was ordered to update its data‑protection notice within one month and to cease unlawful transfers.
Why it matters: The decision signals stricter enforcement of EU data‑transfer rules and consent requirements for public institutions using US services.
Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.