Scope: Data Protection

Can't find what you're looking for? Try the search bar!

Blinded by the LED: smart glasses, GDPR, and the illusion of hardware indicators

Smart glasses are attracting much attention these days. Already significant sales seem to pale in comparison to the explosion of social commentary on them, just as the segment of camera-enabled wearables is growing also in terms of form factors and devices, with AI-powered pins, portable speakers and even headphones around the corner. A few months […]

Read Analysis →

Who interprets the GDPR? EDPB (soft) law and the case for reform

The European Data Protection Board (EDPB) can adopt various legal instruments, including Guidelines and Opinions, that are formally non-binding. Yet if supervisory authorities rarely (if ever) depart from them, controllers and processors structure their compliance efforts around them, and data subjects rely upon them in complaints and litigation, perhaps that formal status deserves a second […]

Read Analysis →

EDPB Guidelines on Anonymisation: where unforeseeable is reasonable?

How the EDPB’s attempt to rewrite key data protection concepts creates more issues than it solves Through its Guidelines 02/2026 on Anonymisation of 7 July 2026, the European Data Protection Board seems at first glance to have done the honourable thing: admitting defeat and moving on. But behind the apparent recognition of the relative nature […]

Read Analysis →

Incidental processing and GDPR: from bystanders to spontaneous notes, do data protection rules apply?

Another week, another product announcement from someone involving AI in your pocket, on your wrist, in front of your eyes. I have met people whose lives have literally been transformed as a result of some of these tools, such as an individual who is suddenly able to use a camera in glasses to film his […]

Read Analysis →

CNIL IQVIA decision: critical analysis

OK, a few words about the CNIL decision re IQVIA. Spoiler alert: it’s in my view a completely wrong decision, and it deliberately misquotes the CJEU’s SRB judgment: 1. “[T]his role as controller prevents, in itself, the data from being regarded as anonymous” (CNIL, §90): incorrect! The CJEU explicitly states the following in §76 of […]

Read Analysis →

Digital Omnibus: pros & cons of Council’s ePrivacy proposals

The Digital Omnibus evolutions at the level of the EU Council continue to have a mix of good and bad. Today, a quick focus on ePrivacy rules. First, some good: – There’s an interesting new Recital 46a on standardisation re consent preferences, stressing that technical solutions should allow data subjects to “easily set their consent […]

Read Analysis →

GDPR at 8: applicability and future enforcement

Confused about these GDPR 10-year anniversary posts in May 2026? While I have been working on it for a decade, I’m not keen on May 2016 (entry into force) but rather May 2018, when the GDPR became *applicable*, even more than April 2016, when it was *adopted*. Why? Before May 2018: – Enforcement of data […]

Read Analysis →

ICO Adtech Report: consent exemptions and first-party use cases

The ICO’s new adtech report to the UK government contains important lessons, also for legislators & regulators from all over Europe. Its suggestion is to foresee a consent exemption under ePrivacy rules (PECR in the UK) for “first-party” use of storage & processing capabilities of a device for the following purposes, if certain safeguards are […]

Read Analysis →

Belgian DPA fines: mailbox management and departing employees

Out with a bang, but with controversial positions? The latest fines of the Belgian DPA represent the last from Hielke Hijmans, the departing Director of the Litigation Chamber. The amounts are modest by international standards (86k, 120k & 176k EUR) but are still relatively high for the Litigation Chamber in its approach to GDPR enforcement. […]

Read Analysis →

Freedom to conduct business: impact of new CJEU judgment on EDPB Opinions

Ask them where they got their legal degree”, someone recently exhorted people to do whenever someone made a link between Recital 4 of the GDPR and Article 16 of the EU Charter of Fundamental Rights, on the freedom to conduct business. Yet now the EU Court of Justice has confirmed for the second time that […]

Read Analysis →