Moderate
Guidance
Published
Spain · Jul 21, 2026
AEPD publishes technical guidance on data accuracy and minimisation in AI processing
The Spanish Data Protection Agency (AEPD) released a technical note interpreting the GDPR accuracy and data‑minimisation principles for AI‑driven personal data processing. It provides criteria for controllers, processors and DPOs to assess…
Agencia Española de Protección de Datos · RGPD
Moderate
Guidance
Announced
European Union · Jul 17, 2026
EDPB calls for legal basis for cross‑regulatory information sharing
The European Data Protection Board urged the European Commission to create a clear legal basis for regulators to share information across competences. It highlighted the need for stronger legislation to enable confidential information…
European Data Protection Board · General Data Protection Regulation
Moderate
Interpretation
Published
Belgium · Jul 14, 2026 · effective May 28, 2026
EDPB orders Belgian DPA to assess NOYB cookie banner complaint on merits
The European Data Protection Board issued a binding decision on 28 May 2026 requiring the Belgian DPA to evaluate a NOYB complaint about VRT's cookie banners on the merits rather than dismiss it on procedural grounds. The decision found no…
European Data Protection Board · General Data Protection Regulation
Moderate
Guidance
Published
European Union · May 28, 2026
ENISA releases NIS360 report showing improved cybersecurity maturity of EU critical sectors
The ENISA NIS360 report released on 28 May 2026 indicates that cybersecurity maturity across EU critical sectors has improved, while sector criticality remains relatively stable. The report identifies a risk zone of sectors with lower…
ENISA · NIS2 Directive
Moderate
Guidance
Published
European Union · Feb 11, 2026
EU DPAs reject key proposals in Digital Omnibus GDPR changes
The European Data Protection Board and the European Data Protection Supervisor issued a joint opinion rejecting the Commission's proposal to narrow the definition of personal data and to restrict the right of access. They also raised…
European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) · ePrivacy Directive
Moderate
Guidance
Announced
European Union · Dec 10, 2025
EU‑US data transfers face imminent risk as US legal changes could undermine TAFPF and SCCs
The blog notes that most EU‑US transfers rely on the Transatlantic Data Privacy Framework (TAFPF) or Standard Contract Clauses (SCCs), which depend on fragile US laws and executive orders. It warns that upcoming US Supreme Court decisions…
EDPB · General Data Protection Regulation
Moderate
Guidance
Published
European Union · Oct 1, 2025
ENISA releases cybersecurity awareness tools and skills framework for EU workplaces
ENISA, together with the European Commission, promotes cybersecurity in the EU through the European Cybersecurity Month and new guidance tools such as AR-in-a-Box and the European Cybersecurity Skills Framework. The agency highlights the…
ENISA · NIS2 Directive
Moderate
Guidance
Announced
European Union · Jul 24, 2025
Report flags 'Pay or Okay' consent‑bypass systems as violating GDPR free‑consent requirement
The noyb report documents the spread of “Pay or Okay” systems across Europe, where users must pay to refuse tracking, resulting in near‑universal consent rates that breach the GDPR’s freely‑given consent standard. It cites a July 2023 CJEU…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate
Guidance
Published
United States (federal) · Mar 31, 2025
2024 HMDA Modified LAR Data Now Available on FFIEC Platform
The Home Mortgage Disclosure Act (HMDA) Modified Loan Application Register data for 2024 have been released on the FFIEC HMDA Platform for about 4,898 filers. The loan‑level data are modified to protect consumer privacy and are now…
Consumer Financial Protection Bureau · Home Mortgage Disclosure Act
Moderate
Interpretation
In effect
European Union · Dec 2, 2024 · effective Dec 2, 2024
noyb qualified as EU 'Qualified Entity' to bring collective GDPR redress actions
noyb has been approved as a Qualified Entity under Directive (EU) 2020/1828, allowing it to bring collective injunctions and redress actions across the EU. Approvals were issued by Austria's Bundeskartellamt on 2 December 2024 and…
Bundeskartellamt; Irish Ministry for Justice · General Data Protection Regulation
Moderate
Interpretation
Published
European Union · Apr 25, 2024
CJEU Advocate General says Facebook must limit personal data for ads under GDPR data‑minimisation
The Advocate General’s opinion interprets Article 5(1)(c) GDPR to require Meta to restrict the use of personal data for targeted advertising by time, type and source. It also addresses purpose‑limitation, stating that publicly disclosed…
EDPB · General Data Protection Regulation
Moderate
Interpretation
Published
European Union · Apr 17, 2024
EDPB opinion bars Meta from using 'Pay or Okay' consent model
The European Data Protection Board issued an opinion stating that Meta may not rely on a pay‑or‑consent scheme to process personal data for behavioural advertising. The decision requires Meta to offer a genuine opt‑in choice rather than a…
European Data Protection Board · General Data Protection Regulation
Moderate
Guidance
Announced
European Union · Mar 19, 2024
EDPB to issue binding opinion on Meta's 'Pay or Okay' consent model
The European Data Protection Board (EDPB) plans to issue a binding opinion on the legality of Meta's "Pay or Okay" system that charges users to refuse tracking. The opinion could legitimize the practice across the EU, threatening the GDPR…
European Data Protection Board · General Data Protection Regulation
Moderate
Guidance
Announced
European Union · Feb 16, 2024
28 NGOs urge EU Data Protection Board to reject Meta's 'Pay or Okay' consent model
A coalition of 28 NGOs, including Wikimedia Europe, Bits of Freedom and the Norwegian Consumer Council, sent a joint letter to the European Data Protection Board requesting a binding opinion on Meta's "Pay or Okay" system, which forces…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate
Interpretation
Announced
European Union · Oct 3, 2023
Meta proposes 'Pay for your Rights' model charging EU users €160/year for non‑consent
Meta plans to charge EU users €160 per year if they do not consent to the processing of their personal data on Facebook and Instagram. The proposal references an obiter dictum from the CJEU case C‑252/21 that an alternative to ads may be…
Irish Data Protection Commission · General Data Protection Regulation
Moderate
Guidance
Announced
European Union · Apr 4, 2023
noyb launches free tool for broad Facebook opt‑out under GDPR
The privacy NGO noyb released an online tool that lets users submit a broad objection to Meta’s processing of personal data for targeted advertising, which Meta bases on “legitimate interest”. The tool simplifies the GDPR right to object…
EDPB · General Data Protection Regulation
Moderate
Guidance
Published
European Union · Jan 24, 2023
EDPB releases draft report on minimum requirements for cookie consent banners
The European Data Protection Board's task force issued a draft report outlining unlawful cookie banner practices under EU law. It sets a minimum threshold for consent banners, including the need for a visible reject option and prohibition…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate
Interpretation
Announced
European Union · May 22, 2022
Open Letter warns EU‑US data transfer deal lacks material US law changes
The open letter published on 2022‑05‑22 criticises the announced Trans‑Atlantic Data Privacy Framework for relying on US executive orders without substantive changes to US surveillance law. It argues that the framework repeats the…
EDPB · General Data Protection Regulation
Moderate
Interpretation
Published
Austria · May 2, 2022
Austrian DPA rejects risk‑based approach for EU‑US data transfers, deems Google IP anonymisation insufficient
The Austrian Data Protection Authority issued a decision stating that the GDPR does not permit a risk‑based approach for transfers to insecure third countries such as the United States. It also concluded that Google’s IP anonymisation does…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate
Guidance
Published
Ireland · Dec 4, 2021
Irish DPC tried to embed Facebook consent bypass into EDPB Guidelines, but final 2019 guidelines omitted it
A letter shows the Irish DPC held ten meetings with Facebook and agreed on a GDPR bypass by moving consent into terms and conditions. The DPC then drafted EDPB guideline language to allow this approach, but other DPAs criticised it…
Irish Data Protection Commission (DPC) · General Data Protection Regulation