Scope: cookies

Can't find what you're looking for? Try the search bar!

Digital Omnibus: pros & cons of Council’s ePrivacy proposals

The Digital Omnibus evolutions at the level of the EU Council continue to have a mix of good and bad. Today, a quick focus on ePrivacy rules. First, some good: – There’s an interesting new Recital 46a on standardisation re consent preferences, stressing that technical solutions should allow data subjects to “easily set their consent […]

Read Analysis →

Global Privacy Control: limitations as a GDPR refusal mechanism

Stunned to see that Global Privacy Control won’t work as a refusal mechanism under the GDPR / Digital Omnibus, as it doesn’t support active change notifications. Some context: While the GDPR contains a “data subject request forwarding” obligation regarding erasure, rectification & rectification requests, it doesn’t in relation to consent withdrawal (or objections). In the […]

Read Analysis →

ICO Adtech Report: consent exemptions and first-party use cases

The ICO’s new adtech report to the UK government contains important lessons, also for legislators & regulators from all over Europe. Its suggestion is to foresee a consent exemption under ePrivacy rules (PECR in the UK) for “first-party” use of storage & processing capabilities of a device for the following purposes, if certain safeguards are […]

Read Analysis →

Freedom to conduct business: impact of new CJEU judgment on EDPB Opinions

Ask them where they got their legal degree”, someone recently exhorted people to do whenever someone made a link between Recital 4 of the GDPR and Article 16 of the EU Charter of Fundamental Rights, on the freedom to conduct business. Yet now the EU Court of Justice has confirmed for the second time that […]

Read Analysis →

CJEU C-797/23: Freedom to conduct business and online advertising impact

Today’s CJEU judgment on press & fair compensation indirectly impacts the “Consent or Pay” & broader discussions on online advertising, through its teachings on the freedom to conduct business: any measure liable to have a sufficiently direct and significant effect on the freedom of the operators concerned to exercise a trade or profession constitutes a […]

Read Analysis →

Global Privacy Control: practical implications for ePrivacy

Global Privacy Control is great, why can’t that solve cookie fatigue in the EU? Could it be part of the Digital Omnibus 88b proposal?” A recent study examines the GPC in context of EU-level discussions on possible changes to the GDPR and ePrivacy rules. It’s an important question, as the idea of browser-level settings needs […]

Read Analysis →

Digital Omnibus Art. 88a: implications for the ePrivacy Directive

Recently, there have been a few strange comments on the ePrivacy aspects of the Digital Omnibus. I’ll tackle browser-level settings later, but today I want to focus on one issue: what are the ePrivacy Directive consequences of the new Art. 88a proposal? Article 5(3) of the ePrivacy Directive (ePD) is known as the “cookie rule” […]

Read Analysis →

Political Advertising: insights from EDPB stakeholder event

EDPB stakeholder event write-up: From “no one wants political ads” to “political parties have to be able to reach their local audience”, today’s topic wasn’t very sexy (the “processing of personal data for the targeting or delivery of political advertisements”) but it still was a colourful event. No bar fight unlike some previous stakeholder events, […]

Read Analysis →

Political advertising regulation, scope and data protection risks

What is “political advertising” – or not? And when is it permitted? Scope creep beyond legislative intent is a real danger, a risk *everyone* should care about (even if you don’t think political ads concern you). The descriptively named “EU Regulation on Transparency and Targeting of Political Advertising” (“TTPA” for short) has two key aims: […]

Read Analysis →

Anonymisation of personal data: compliance vs utility, regulators vs the law

The clear repudiation of an “absolute” concept of personal data has thrown a sharp focus on the process of pseudonymisation in the world of data protection. Through its SRB judgment of 4 September 2025, the Court of Justice of the European Union (CJEU) made it clear that personal data that has undergone pseudonymisation can be […]

Read Analysis →