Belgian DPA fines: mailbox management and departing employees

Out with a bang, but with controversial positions? The latest fines of the Belgian DPA represent the last from Hielke Hijmans, the departing Director of the Litigation Chamber. The amounts are modest by international standards (86k, 120k & 176k EUR) but are still relatively high for the Litigation Chamber in its approach to GDPR enforcement. […]

Read Analysis →

Freedom to conduct business: impact of new CJEU judgment on EDPB Opinions

Ask them where they got their legal degree”, someone recently exhorted people to do whenever someone made a link between Recital 4 of the GDPR and Article 16 of the EU Charter of Fundamental Rights, on the freedom to conduct business. Yet now the EU Court of Justice has confirmed for the second time that […]

Read Analysis →

CJEU C-797/23: Freedom to conduct business and online advertising impact

Today’s CJEU judgment on press & fair compensation indirectly impacts the “Consent or Pay” & broader discussions on online advertising, through its teachings on the freedom to conduct business: any measure liable to have a sufficiently direct and significant effect on the freedom of the operators concerned to exercise a trade or profession constitutes a […]

Read Analysis →

Global Privacy Control: practical implications for ePrivacy

Global Privacy Control is great, why can’t that solve cookie fatigue in the EU? Could it be part of the Digital Omnibus 88b proposal?” A recent study examines the GPC in context of EU-level discussions on possible changes to the GDPR and ePrivacy rules. It’s an important question, as the idea of browser-level settings needs […]

Read Analysis →

Conference diversity: need for balanced perspectives

I’ve always said we need a proper debate about key issues. Pity then to see how many one-sided panels there are at the upcoming CPDP conference in Brussels (often with panellists who criticise social media bubbles or deplore lack of diversity of opinion in other contexts). Diversity on panels is important, and perhaps we need […]

Read Analysis →

Personal data definition: Digital Omnibus proposal evolutions

Why is the “personal data” definition aspect of the Digital Omnibus deemed controversial by some? And why are the alleged issues with the definition in fact absent? The Commission’s proposal is to codify recent case law of the EU Court of Justice, notably the SRB judgment (4 Sept 2025), by putting it into the law […]

Read Analysis →

DMA & anonymisation: regulatory risks of under-anonymisation

How solid is your anonymisation? Is “good enough + contractual prohibition to re-identify” really sufficient? The Commission’s DMA team seems to think so, though its own idea of “good enough” relies on magic personal data scrubbers. Perhaps the Commission’s DMA team should read up again on GDPR case law on “personal data” (Breyer, Scania, SRB […]

Read Analysis →

Digital Omnibus & DMA: reconciling anonymisation standards

Double standards: On the Digital Omnibus re GDPR, the EDPB & EDPS claim the Commission shouldn’t have the power to adopt implementing acts to “specify means and criteria to determine whether data resulting from pseudonymisation no longer constitutes personal data for certain entities”. Yet under the Digital Markets Act, no problem at all. The situations […]

Read Analysis →

DMA compliance: challenges in Search query data anonymisation

DMA & data: real risk of over-sharing of identifiable, personal search query data. The European Commission has launched a public consultation on the measures it intends to impose on Google for compliance with Article 6(11) of the Digital Markets Act (DMA) – a specific obligation to anonymise search query data and share it with other […]

Read Analysis →

Biometrics and restrictive data minimisation

Biometrics & Digital Omnibus: EU Council’s draft compromise could cripple biometrics in *all* industries if unchanged. The use of biometrics for identity verification is often based on consent (Art. 9(2)(a) GDPR), and the Commission’s proposal added a consent exemption if “the biometric data or the means needed for the [identity] verification is under the sole […]

Read Analysis →