Join our two-day NIS2 and cybersecurity workshop with the CCB

NIS2: Looking forward to giving a 2-day workshop with Chris A. De Vuyst from the Centre for Cybersecurity Belgium (= Belgian cybersecurity authority) next week, further to tremendous preparatory work by Chris and Val�ry Vander Geeten. [Thanks again Val�ry as well as the Data Protection Institute for thinking of me in this respect!] The Network […]

Read Analysis →

Data evidence: importance of verifiable consent records

Two victories before the Belgian DPA this week: dismissal of a complaint against a privacy-friendly analytics provider (re ads & content) due to lack of evidence of processing of personal data (Breyer + SRB having an impact), and one decision confirming that where data is shared pre-GDPR, the controller using it post-GDPR is the one […]

Read Analysis →

Digital Omnibus and ePrivacy: complexity and regulatory gaps

Digital Omnibus & ePrivacy: good intentions but bad outcome. While I have praised the Commission’s attempt at GDPR-related pragmatism (though a good idea re special categories of data didn’t make it), I have remained silent on the ePrivacy front. There, the proposal is not good in my view. It would create an alternative to Art. […]

Read Analysis →

GDPR Digital Omnibus debate: key takeaways

Do (re)watch our 53-minute civilised, proper debate on some of the key GDPR parts of the Digital Omnibus proposal! From the notion of “personal data” to special categories of data, AI development & training and even scientific research, a lot of ground covered from two perspectives. [I had a few awkward moments of the “unmute” […]

Read Analysis →

Analysis of the GDPR and Data Act Omnibus draft

From fishing (instead of the GDPR) to a random “v” having appeared instead of a few words (a typo upon deletion?), the Commission’s GDPR & Data Act Omnibus feels like a rushed document. But what does it cover really? I’m focussing here on GDPR & ePrivacy: – Personal data definition: I like the idea of […]

Read Analysis →

Previews of IAPP Congress and Digital Omnibus discussions

If the European Commission unveils the (final) full Digital Omnibus proposals on 19 November, what will they cover? Many of us will discuss this during panels at the IAPP conference, but those might be gut reactions depending on the timing of the publication by the Commission. Glad to announce that I will be exchanging on […]

Read Analysis →

EDPB accountability and the right to challenge guidance

Really interesting insights from Greet Gysen from the EDPB at the Nordic Privacy and Innovation Summit in Stockholm. Part of the consequences of the “Helsinki statement” adopted by the European Data Protection Board are that the EDPB will be consulting stakeholders more in advance – this much we knew already. She also highlighted that the […]

Read Analysis →

Nordic Privacy Summit: balancing SCD definitions and workability

Hopefully thought-provoking? My keynote on “Personal Data in a Digital World: What Are We Protecting?” kicked off the Nordic Privacy & Innovation Summit 2025 today in Stockholm. Among my topics: SRB, OT, ePrivacy, AI and AI model training, plus how to make the GDPR more workable (see slides, which show that data protection involves a […]

Read Analysis →

Aligning perspectives on the future of data protection legislation

On some topics our views may differ, but on the future of data protection rules, I find that Mark and I are pretty aligned. Dr M.R. (Mark) Leiser’s comments come from the observation that the law needs to *make sense* to be effective, and where the law isn’t the problem to start with but its […]

Read Analysis →

Are privacy-enhancing technologies facing death by ePrivacy regulations?

Privacy-enhancing technologies: “death by ePrivacy”? PETs were on the agenda of the IAPP DPC24 in Brussels this week, but few talked about the dangers to PETs caused by evolving positions of regulators. PETs (for ads with less data, content-focussed analytics, etc.) are being worked on by companies of all backgrounds and sizes and touted as […]

Read Analysis →