Brazil was the partner country at this year’s HANNOVER MESSE. The trade fair was opened three weeks ago by Chancellor Merz and President Lula in person. Brazil was represented more strongly than any partner country before it. Ahead of the fair, the Brazilian Embassy invited selected guests from business, politics and academia to a formal […]
data protection
AEPD’s Asesora Brecha: A Practical Tool for Article 33 GDPR Breach Notification Decisions
One of the most time-sensitive obligations under the GDPR is the requirement for data controllers to notify their supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons (Art. 33 para. 1 […]
Egypt’s Personal Data Protection Law – Before You Process, You Need a Licence
The Arab Republic of Egypt enacted a comprehensive data protection law in 2020. For five years, its practical impact remained limited. There was no supervisory authority, no executive regulations and no enforcement. That changed on 1 November 2025. From 31 October 2026, full compliance will be mandatory. Background: Egypt’s Path to Data Protection Egypt is […]
China’s New Draft Rules for Small Personal Information Controllers
On 3 April 2026 China’s Cyberspace Administration (CAC) published a draft regulation titled the Provisions on Simplified Measures for Personal Information Protection by Small Personal Information Controllers (Draft for Comment) (the „Draft“). The Draft is open for public comment and, once finalized, will introduce a tiered compliance framework under China’s Personal Information Protection Law (PIPL). […]
One Click Withdrawal: New Obligations for Online-Shops
On 5 February 2026, Germany passed a new law transposing EU-Directive 2023/2673. Of particular importance are the new requirements regarding the right of consumers to withdraw from contracts via a new online interface: the so-called “withdrawal button”. These obligations will enter into force across the whole European Union at the latest on 19 June 2026. […]
Unlawful Profiling and Poor Transparency: Key Takeaways from the Garante’s Fine Against Intesa Sanpaolo
The Italian Data Protection Authority (Garante) has imposed a €17.6 million fine on Intesa Sanpaolo, one of the largest banking groups in Italy, for unlawful processing of personal data affecting approximately 2.4 million customers in the context of their transfer to the digital bank Isybank. What makes this case particularly relevant is not only its […]
Spanish AEDP v FC Barcelona: DPIA Required for Processing Biometric Data
The Spanish Data Protection Authority (AEPD) recently imposed a €500,000 fine on Fútbol Club Barcelona for failing to properly conduct a Data Protection Impact Assessment (DPIA) when implementing biometric systems used during the club’s membership census process. This complex decision ultimately focuses on Article 35 GDPR, with the AEPD concluding that the club failed to […]
Biometric Data: Key GDPR Lessons from an AEPD Decision
The Spanish Data Protection Authority (AEPD) recently imposed a €950,000 fine on a company offering digital identity and age verification services that rely on facial analysis technology. The decision is particularly relevant for organisations deploying facial analysis technologies, including AI-based age estimation and identity verification systems that generate biometric templates, as it illustrates how regulators […]
Digital Accessibility and Data Protection: Insights from the Italian Data Protection Authority
Digital accessibility is becoming a central compliance topic across Europe. With the entry into application of the European Accessibility Act (Directive (EU) 2019/882, EAA), EU Member States must ensure that a wide range of digital products and services meet accessibility requirements so that people with disabilities can access them without barriers. These requirements apply to […]
EU-Brazil Adequacy Decisions: What Changes in Practice
On 26 January 2026, Brazil and Europe adopted mutual adequacy decisions regarding international transfers of personal data. The European Commission adopted an adequacy decision for Brazil under Article 45 GDPR, enabling transfers from the EU to Brazil. The Brazilian data protection authority (ANPD) adopted Resolution No. 32/2026 recognizing the EU as providing an adequate level […]
Digital Omnibus Part 2: What Organisations Need to Know About the Joint Opinion of EDBP and EDPS
The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have published their Joint Opinion (the Joint Opinion) on the European Commission’s Digital Omnibus Proposal (the Proposal). Following our earlier analysis (Part 1) of the Proposal itself, this article examines how key elements of the reform are viewed by these supervisory bodies. […]
No Account, No Purchase? EDPB Pushes Back on Mandatory Registration
Requiring users to create an account in order to complete an online purchase is a widespread practice in e-commerce. Businesses commonly justify this requirement by reference to operational efficiency, customer convenience, or the development of long-term commercial strategies. With its Recommendations 2/2025, the European Data Protection Board (EDPB) addresses this practice directly and clarifies the […]
Reading Between the Lines of the Italian DPA’s 2026 Inspection Plan
With its Resolution of 30 December 2025, the Italian Data Protection Authority (Garante per la protezione dei dati personali) published its inspection plan for the period January to July 2026. The plan sets out the Authority’s inspection focus for the first semester of the year and provides for at least 40 targeted inspections across the […]
U.S. Data Privacy Developments in 2025 – A Year in Review
Every year at this time I sit down to write a blog article, tying the experiences that I have during the holiday season into the world of data privacy. This year I have struggled to come up with a topic that really spoke to me. But, as I sat down to write my family’s annual […]
Beyond the Theory: CNIL Sanctions Under the Light of the Digital Omnibus
As the French data protection authority (Commission nationale de l’informatique et des libertés, CNIL) recently imposed two high-amount sanctions, we take this opportunity to try and make a practical application of some rules from the recently published draft of the Digital Omnibus. What Happened? In the span of a week, the CNIL imposed major sanctions […]