AI Act Digital Omnibus: addressing the deployer gap

An unintentional oversight? The proposed Digital Omnibus on the AI Act contains certain deadline extensions but a key one is missing, suggesting a disconnect between the text itself and the reality that organisations face. While many other aspects merit discussion (such as the yet unresolved overlap issues between the GDPR and the AI act), there […]

Read Analysis →

Personal data: relative concepts and cross-border tensions

Not just a good excuse to brush up my limited German! Yesterday’s dual-language event in Zurich was an excellent blend of discussions regarding the concept of “personal data” and the tensions with data sharing frameworks. The juxtaposition of my opening keynote (in English) on case law on the notion of personal data (+ Digital Omnibus […]

Read Analysis →

The Digital Omnibus and the future of PETs

What to expect from the EDPB and EDPS on 10 February re the Digital Omnibus on GDPR and ePrivacy? Today I had the privilege of attending an event organised by The Lisbon Council with a very select group of representatives of companies, industry associations, BEUC, the Commission and the EDPB. We discussed the Digital Omnibus […]

Read Analysis →

Improving stakeholder engagement at the EDPB

Great to see the European Data Protection Board listening to feedback! For their next stakeholder event, the EDPB is giving time to people to register their interest in participating – and it might even consider making a distinction between active and passive participants (speakers vs observers). Don’t dismiss this one just because it’s about a […]

Read Analysis →

Podcast: Discussing the Digital Omnibus on the ADPO podcast

Podcast alert: Almost an hour, but lots of topics about the GDPR & ePrivacy Digital Omnibus in the launch episode of the ADPO’s podcast (Irish Association of DPOs) Thanks to Dr Maria Moloney & Gonzalo Caro for having me on their inaugural podcast! Topics include the importance of a dialogue, sensitive categories of personal data, […]

Read Analysis →

Document access and the right to information

When do contracts have to be provided in response to a data subject access request? And should a controller maintain a copy thereof to enable data subject requests? A new Belgian DPA decision deals with this issue, applying the EU Court of Justice’s CRIF judgment to the issue of bank account contracts. Article 15 GDPR […]

Read Analysis →

Navigating third-party data access requests

The Irish DPC’s guide on accessing data on behalf of someone else remains relevant but incomplete. (It dates back to 2021 and has just been republished, in case anyone thought it sounded familiar.) It touches upon a very difficult issue – and one less clear-cut than the Irish DPC suggests. Yes, there are good reasons […]

Read Analysis →

Synthetic data: accuracy and real-life limitations

This does not surprise me – as I was explaining yesterday to two podcast hosts, synthetic data is great on paper but it does not help with accuracy or real-life outliers/divergent situations. It’s easy to claim that synthetic data is the best way to comply with data minimisation and that “you don’t really need all […]

Read Analysis →

Privacy notices: managing marketing and consent risks

How a simple sentence in your privacy notice can restrict your digital marketing: the Belgian DPA issued an injunction to adapt digital marketing practices for a fitness club that had sent marketing e-mails to a club member, including for non-sporting events. The case highlights a classic misalignment between documentation and marketing practices, as well as […]

Read Analysis →

IAB Europe case: Market Court narrows enforcement scope

IAB Europe & TCF case: Belgian Market Court confirms Belgian DPA went too far in seeking enforcement of full range of measures against IAB Europe. Pleased to see the judgment of the Market Court/MC of Wednesday 7 January 2026, which set aside the BDPA’s decision of January 2023 (through which it had validated IAB Europe’s […]

Read Analysis →