EU Officials’ Location Data For Sale
EU officials’ location data was easily accessed through commercial brokers despite GDPR protections, raising concerns about data privacy enforcement in Europe.
EU officials’ location data was easily accessed through commercial brokers despite GDPR protections, raising concerns about data privacy enforcement in Europe.
EDPS updated guidance strengthens data protection rules for generative AI used by EU institutions, adding a practical compliance checklist and clearer controller/processor responsibilities.
EDPB and European Commission issued joint guidelines clarifying how gatekeepers must apply GDPR obligations when complying with the Digital Markets Act; public consultation open until 4 Dec 2025.
Austrian regulator found Microsoft 365 Education illegally tracked students via cookies; Microsoft must grant data access and faces scrutiny over transparency and GDPR compliance.
EU plans to force scanning of encrypted messages were postponed after Germany opposed Chat Control; critics say it would weaken encryption, harm security and push users to risky alternatives.
EU plans to simplify cookie consent rules to reduce repetitive banners, propose browser-level preferences and possible GDPR alignment, drawing industry support and privacy concerns.
The EU’s Entry/Exit System will record fingerprints, facial images and passport data of non-EU short-stay visitors for up to three years to streamline checks and enforce the 90/180-day rule.
The CNIL fined Google (€325M) and SHEIN (€150M) for cookie and ad consent breaches, stressing free, informed consent and sanctioning covert tracking and cookie-wall practices.
EDPS finds the European Commission’s Microsoft 365 use compliant with Regulation (EU) 2018/1725 after contractual, technical and organisational measures addressed purpose limitation, transfers and disclosures.
Microsoft France admits it cannot guarantee French citizen data in EU datacenters is fully protected from U.S. government access, highlighting digital sovereignty challenges.
Polish Data Protection Authority fined McDonald’s and its processor over €3.6 million for GDPR violations after employee data exposure due to poor security and oversight.
Germany’s data watchdog accuses DeepSeek of unlawful data transfers to China, prompting potential EU-wide app bans under GDPR rules.