EDPB Issues Opinion on EU-Brazil Data Protection Adequacy Decision
The EDPB supports the EU-Brazil data adequacy decision but requests clarifications on DPIAs, transparency, law enforcement data use, and national security definitions.
The EDPB supports the EU-Brazil data adequacy decision but requests clarifications on DPIAs, transparency, law enforcement data use, and national security definitions.
New EU rules set deadlines and streamlined procedures for cross-border GDPR enforcement, strengthen complainant rights, and promote early consensus among national data protection authorities.
EDPB supports six-year extension of UK adequacy decisions to 2031 but urges the Commission to address legal changes, monitor risks and ensure robust oversight and remedies.
EDPS updated guidance strengthens data protection rules for generative AI used by EU institutions, adding a practical compliance checklist and clearer controller/processor responsibilities.
Norwegian court upheld a major GDPR fine against Grindr for improper processing and sharing of sensitive and location data, stressing stricter requirements for consent, minimization and safeguards.
EU signs PNR data-sharing deals with Norway and Iceland, adding privacy safeguards and awaiting EP consent and Council conclusion to strengthen counterterrorism and serious crime cooperation.
EDPB and European Commission issued joint guidelines clarifying how gatekeepers must apply GDPR obligations when complying with the Digital Markets Act; public consultation open until 4 Dec 2025.
The EDPB will coordinate an EU-wide enforcement action on GDPR transparency and information obligations, with national DPAs participating voluntarily and the action launching in 2026.
Meta appeals the General Court’s dismissal of its challenge to EDPB Opinion 08/2024, arguing procedural and legal errors on reviewability, liability, judicial protection, and reasoning.
The CNIL fined Google (€325M) and SHEIN (€150M) for cookie and ad consent breaches, stressing free, informed consent and sanctioning covert tracking and cookie-wall practices.
The Austrian Federal Administrative Court confirmed that newspaper Der Standard breached the EU’s data protection rules by using a “pay […]
AEPD fines Iberostar unit €70,000 for requiring full ID copies at booking; authority stresses GDPR data minimisation and that copies are unnecessary and risky for guest registration.