EDPB Issues Recommendations on Legal Basis for User Accounts on E-commerce Sites
The EDPB recommends e-commerce sites offer guest checkout to protect user privacy, allowing mandatory accounts only for specific services under GDPR rules.
The EDPB recommends e-commerce sites offer guest checkout to protect user privacy, allowing mandatory accounts only for specific services under GDPR rules.
The EU court ruled that websites hosting user content must actively protect user privacy and comply with GDPR, including for anonymous users, or face heavy fines.
The EU Digital Omnibus complicates consent management for publishers, risking lower consent rates and favoring big tech with closed ecosystems.
EU officials’ location data was easily accessed through commercial brokers despite GDPR protections, raising concerns about data privacy enforcement in Europe.
EDPS updated guidance strengthens data protection rules for generative AI used by EU institutions, adding a practical compliance checklist and clearer controller/processor responsibilities.
EDPB and European Commission issued joint guidelines clarifying how gatekeepers must apply GDPR obligations when complying with the Digital Markets Act; public consultation open until 4 Dec 2025.
Austrian regulator found Microsoft 365 Education illegally tracked students via cookies; Microsoft must grant data access and faces scrutiny over transparency and GDPR compliance.
EU plans to force scanning of encrypted messages were postponed after Germany opposed Chat Control; critics say it would weaken encryption, harm security and push users to risky alternatives.
EU plans to simplify cookie consent rules to reduce repetitive banners, propose browser-level preferences and possible GDPR alignment, drawing industry support and privacy concerns.
The EU’s Entry/Exit System will record fingerprints, facial images and passport data of non-EU short-stay visitors for up to three years to streamline checks and enforce the 90/180-day rule.
The CNIL fined Google (€325M) and SHEIN (€150M) for cookie and ad consent breaches, stressing free, informed consent and sanctioning covert tracking and cookie-wall practices.
EDPS finds the European Commission’s Microsoft 365 use compliant with Regulation (EU) 2018/1725 after contractual, technical and organisational measures addressed purpose limitation, transfers and disclosures.