On July 20, 2026, the European Commission (EC) published new Guidelines on Transparency of AI-Generated Content to complement the Code of Practice on Transparency of AI-Generated Content it released on June 10, 2026. The materials arrive just weeks before the AI Act’s transparency obligations take effect on August 2, 2026, and give businesses clearer direction […]
EU Regulators Outline GDPR Requirements for AI Web Scraping
On July 8, 2026, the European Data Protection Board (“EDPB”), the body that coordinates the EU’s national data protection authorities, published its first draft of Guidelines 03/2026 on web scraping in the context of generative AI (the “Guidelines”). The Guidelines address practical compliance challenges for companies that develop AI models or systems and scrape personal […]
Connected Vehicles Under the Spotlight: French DPA Issues Landmark Guidance on Vehicle Data Privacy
On 30 June 2026, the French Data Protection Authority (CNIL) published comprehensive new guidance on the processing of personal data generated by connected vehicles, with a particular focus on geolocation data (available in French here). For automotive manufacturers, suppliers, and mobility companies with operations or customers in the EU, this 60-page guidance provides much-needed clarity […]
European Commission Publishes Draft Guidelines on Classification of High-Risk AI Systems Under the EU AI Act
On May 19, 2026, the European Commission (EC) published draft guidance on how to determine whether an AI system qualifies as a high-risk AI system (HRAIS) under the EU’s Regulation 2024/1689 on artificial intelligence (AI Act). The draft reflects input from stakeholders and EU Member States through the EU AI Board and represents the most […]
Dutch DPA Fines Taxi App €100M Over Unlawful Transfers of Personal Data to Russia, Despite Use of EU Standard Contractual Clauses
On April 1, 2026, the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, AP) imposed a €100 million fine on MLU B.V., the Dutch operator of the Yango taxi app. The AP found that personal data of EU users was unlawfully transferred to affiliated entities in Russia, despite the formal use of the EU Standard Contractual Clauses […]