Blinded by the LED: smart glasses, GDPR, and the illusion of hardware indicators

Smart glasses are attracting much attention these days. Already significant sales seem to pale in comparison to the explosion of social commentary on them, just as the segment of camera-enabled wearables is growing also in terms of form factors and devices, with AI-powered pins, portable speakers and even headphones around the corner. A few months […]

Read Analysis →

Who interprets the GDPR? EDPB (soft) law and the case for reform

The European Data Protection Board (EDPB) can adopt various legal instruments, including Guidelines and Opinions, that are formally non-binding. Yet if supervisory authorities rarely (if ever) depart from them, controllers and processors structure their compliance efforts around them, and data subjects rely upon them in complaints and litigation, perhaps that formal status deserves a second […]

Read Analysis →

EDPB Guidelines on Anonymisation: where unforeseeable is reasonable?

How the EDPB’s attempt to rewrite key data protection concepts creates more issues than it solves Through its Guidelines 02/2026 on Anonymisation of 7 July 2026, the European Data Protection Board seems at first glance to have done the honourable thing: admitting defeat and moving on. But behind the apparent recognition of the relative nature […]

Read Analysis →

Incidental processing and GDPR: from bystanders to spontaneous notes, do data protection rules apply?

Another week, another product announcement from someone involving AI in your pocket, on your wrist, in front of your eyes. I have met people whose lives have literally been transformed as a result of some of these tools, such as an individual who is suddenly able to use a camera in glasses to film his […]

Read Analysis →

New data protection enforcement decision database

Around the time I created my data breach risk assessment tool (after really interesting exchanges with ENISA on cybersecurity & data protection), Olivier Sustronck released something similar that he just made available for free. My firm got an award for mine, his went under the radar – but he truly deserves praise for the quality […]

Read Analysis →

CNIL IQVIA decision: critical analysis

OK, a few words about the CNIL decision re IQVIA. Spoiler alert: it’s in my view a completely wrong decision, and it deliberately misquotes the CJEU’s SRB judgment: 1. “[T]his role as controller prevents, in itself, the data from being regarded as anonymous” (CNIL, §90): incorrect! The CJEU explicitly states the following in §76 of […]

Read Analysis →

Digital Omnibus: pros & cons of Council’s ePrivacy proposals

The Digital Omnibus evolutions at the level of the EU Council continue to have a mix of good and bad. Today, a quick focus on ePrivacy rules. First, some good: – There’s an interesting new Recital 46a on standardisation re consent preferences, stressing that technical solutions should allow data subjects to “easily set their consent […]

Read Analysis →

GDPR at 8: applicability and future enforcement

Confused about these GDPR 10-year anniversary posts in May 2026? While I have been working on it for a decade, I’m not keen on May 2016 (entry into force) but rather May 2018, when the GDPR became *applicable*, even more than April 2016, when it was *adopted*. Why? Before May 2018: – Enforcement of data […]

Read Analysis →

Global Privacy Control: limitations as a GDPR refusal mechanism

Stunned to see that Global Privacy Control won’t work as a refusal mechanism under the GDPR / Digital Omnibus, as it doesn’t support active change notifications. Some context: While the GDPR contains a “data subject request forwarding” obligation regarding erasure, rectification & rectification requests, it doesn’t in relation to consent withdrawal (or objections). In the […]

Read Analysis →

ICO Adtech Report: consent exemptions and first-party use cases

The ICO’s new adtech report to the UK government contains important lessons, also for legislators & regulators from all over Europe. Its suggestion is to foresee a consent exemption under ePrivacy rules (PECR in the UK) for “first-party” use of storage & processing capabilities of a device for the following purposes, if certain safeguards are […]

Read Analysis →