DPO Newsletter: Global Data Protection & Privacy News (issue #155)

DPO Newsletter: Global Data Protection & Privacy News

We’ve compiled the latest in Data Protection and Privacy news for your convenience below.

1) Newly Published Documentation

๐Ÿ‡ช๐Ÿ‡บ European Union โ€“ EDPB Publishes 2025 Annual Report
The EDPBโ€™s 2025 Annual Report says national DPAs issued a record โ‚ฌ1.15 billion in fines last year. It also highlights the Helsinki Statement and the Boardโ€™s first joint DMA/GDPR guidance.

๐Ÿ‡ซ๐Ÿ‡ท France โ€“ CNIL Publishes HR Data Retention Guide
Franceโ€™s CNIL published a practical guide (in French) on how long employers should keep HR data, covering recruitment, payroll, workplace accidents, disciplinary files, and more. Itโ€™s a useful reference for DPOs and HR teams working under French law.

๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom โ€“ ICO Opens Consultation on Automated Decision-Making Guidance
The ICO launched a consultation on updated guidance on automated decision-making and profiling, with feedback open until 29 May 2026. The draft matters for employers and any business using AI or algorithmic decision tools.

2) Notable Case Law

๐Ÿ‡ช๐Ÿ‡บ European Union โ€“ CJEU Says a First GDPR Access Request Can Still Be Abusive
The CJEU ruled (PDF) that even a first access request can be refused if it is abusive and made mainly to build a damages claim, not to check whether data is being processed lawfully. The ruling also confirms that unjustified refusals can themselves create compensation risk.

๐Ÿ‡ฎ๐Ÿ‡น Italy โ€“ Garante Fines Intesa Sanpaolo โ‚ฌ31.8 Million
Italyโ€™s Garante fined Intesa Sanpaolo after finding that a single employee repeatedly accessed thousands of customersโ€™ banking data over more than two years, while internal systems failed to detect it. The authority also criticized the bankโ€™s late and incomplete breach notification in its decision (in Italian).

๐Ÿ‡บ๐Ÿ‡ธ United States โ€“ FTC Settles with OkCupid and Match Over Secret Data Sharing
The FTC announced a settlement with OkCupid and Match after finding that user photos, location data, and other personal data were shared with a third party despite privacy promises. The companies are now barred from misrepresenting their data-sharing practices.

3) New and Upcoming Legislation

๐Ÿ‡ช๐Ÿ‡บ European Union โ€“ AI Act Omnibus Enters Negotiation Phase
The European Parliament adopted its position on the Digital Omnibus on AI, opening the way for interinstitutional negotiations. One key proposal is replacing the fixed August 2026 deadline for high-risk AI obligations with a standards-readiness trigger.

๐Ÿ‡บ๐Ÿ‡ธ United States โ€“ Oklahoma Enacts a Comprehensive State Privacy Law
Oklahoma signed SB 546 into law, becoming the 20th U.S. state to enact a comprehensive privacy law. It grants consumers rights to access, correct, delete, and opt out of certain processing, with enforcement led by the Attorney General.

4) Strong Impact Tech

๐Ÿ‡ช๐Ÿ‡บ European Union โ€“ NOYB Signals More Collective Actions After Cyber Incidents
At the IAPP Global Summit, Max Schrems said in an IAPP discussion that NOYBโ€™s new qualified-entity status could be used to bring collective actions, with cyber incidents and data breaches likely to be an early focus.

๐Ÿ‡จ๐Ÿ‡ญ Switzerland โ€“ Swiss Finance Minister Files Complaint Over Grok Output
Swiss Finance Minister Karin Keller-Sutter filed a criminal complaint after Grok generated abusive content about her, asking prosecutors to assess potential liability in the new report.

Other key information from the past weeks

๐Ÿ‡ช๐Ÿ‡บ๐Ÿ‡บ๐Ÿ‡ธ EU-U.S. Data Privacy Framework โ€“ Adoption Continues, but Legal Uncertainty Remains
At the IAPP Global Summit, speakers noted in an IAPP update that more companies are joining the DPF, while many larger businesses continue using SCCs in parallel as a safeguard.

๐Ÿ‡ช๐Ÿ‡บ European Union โ€“ EDPB Launches 2026 Transparency Enforcement Action
The EDPB launched its 2026 coordinated enforcement action on GDPR transparency and information obligations, with 25 DPAs set to contact organizations across sectors and consolidate findings into a final report.

๐Ÿ‘ Enjoyed this issue? Share it on LinkedIn and subscribe for weekly updates

About us

iubenda

Attorney-level solutions to make your websites and apps compliant with the law across multiple countries and legislations.

www.iubenda.com

Follow us on: