StartNews
News
Neuigkeiten und Fachbeiträge von EuroCloud und dem INPLP-Netzwerk – 723 Artikel, chronologisch.
Oktober 2026723 Artikel
08.10.2026Legal Alert: Bill Postpones Effective Date of the Personal Data Protection LawTwo regulatory developments marked the beginning of September in the area of personal data protection: the introduction of a bill seeking to postpone the effective date of the new legislation and the formal acknowledgment of the regulations on models for preventing violations.08.10.2026Ecuador’s Risk Management Guide for Personal Data Protection. A practical viewEcuador’s Superintendence of Personal Data Protection has published its first risk management guide. The document is ambitious: it demands that organizations justify every assumption, calibrate expert opinion, and adopt measurable models. However, it leaves a critical question unanswered, as, what methodology should companies actually use? Unlike Spain, where proportionality and maturity guide the choice of methods, Ecuador’s guide presents multiple options without prioritization. This article argues that such neutrality, while flexible, creates practical uncertainty. It suggests that organizations should adopt a mixed model, anchored in the traditional risk matrix but enriched with qualitative rationales and, where possible, quantitative tools.08.10.2026The CNIL's new approach to AI models Memorisation, extractability and anonymisation under the GDPRAs generative AI becomes increasingly powerful, the CNIL’s 2026 guidance shifts the GDPR debate from how personal data is used in training to whether AI models themselves can retain and reveal information about individuals. By focusing on memorisation, extractability, and anonymisation, the framework offers a practical roadmap for assessing when AI models may still pose privacy risks and therefore remain subject to European data protection law.08.10.2026Israel's First Administrative Fines under Amendment 13: A New Enforcement Era for Privacy ComplianceAmendment 13 to Israel's Protection of Privacy Law, 1981 (the "PPL") entered into force on 14 August 2025, giving the Israeli Privacy Protection Authority (the "PPA") — for the first time — the ability to impose meaningful financial sanctions directly on organisations that breach Israeli data protection rules. A little over a year later, the first sanctions have arrived. Between July and September 2026 the PPA published three decisions imposing fines on a health fund, a small leisure business and a municipality. Modest in amount, they are significant in signal: Israeli privacy obligations that were long treated as formalities now carry a direct price tag.08.10.2026Brazil’s ECA Digital: Is Child Safety Now a Product Requirement?Six months after entering into force, Brazil’s Digital Statute for Children and Adolescents (Law No. 15,211/2025) has moved from text to enforcement, and the ANPD’s age-assurance guidance is setting the practical bar. This article maps the core obligations, the six requirements behind “reliable” age assurance and what providers, in Brazil and abroad, should prioritise now.07.10.2026Decree 356/2025/ND-CP: The Next Chapter in Vietnam’s Personal Data Protection FrameworkVietnam’s data protection landscape just got sharper. Decree No. 356/2025/ND-CP delivers the detailed rules businesses have been waiting for, tighter timelines, clearer roles and fewer grey areas. Now is the time for organisations to put their policies, people and data practices to the test before the new regime takes hold.07.10.2026When Anonymization Fails: Readable Data in a Published ContractA decision of the Office for Personal Data Protection of the Slovak Republic confirms that the anonymization of a document intended for publication must be technically effective, rather than merely visual. If personal data become readable after text is copied from a PDF document, the controller may be in breach of its obligation to ensure the ongoing confidentiality of personal data under Article 32(1) of the GDPR, even where contracts are subject to mandatory publication in the Central Register of Contracts.07.10.2026North Macedonian Administrative Court Upholds Agency Decision on Unlawful Processing of Patient Health DataThe Administrative Court of North Macedonia has upheld a decision of the Personal Data Protection Agency concerning the unlawful processing of a patient’s personal and health data within the national electronic healthcare system.07.10.2026Age Assurance and Privacy: Israel’s Draft GuidanceOn 11 June 2026, the Israeli Privacy Protection Authority (“PPA”) published draft guidance for public comment on online age assurance measures. The guidance is addressed to online service providers and treats age assurance as a data processing activity to be designed, assessed, and governed accordingly, rather than merely as a child safety tool. Non-compliance can attract administrative fines and civil claims.07.10.2026China Implements Strict Requirements for Cybersecurity Incident ReportingWith a rising number of data breaches and cybersecurity incidents in recent years, China has rolled out stringent new rules that set clear requirements on incident reporting items, time limits and procedures for all network operators. This article provides an overview to navigate the incident reporting obligations.07.10.2026Is Lithuania Finally Ready for B2B Direct Marketing? Almost.From 1 July 2026, Lithuania's amended Law on Electronic Communications finally lifts its blanket opt-in requirement for B2B electronic direct marketing, allowing businesses to contact other businesses on an opt-out basis – joining the majority of EU member states that never imposed such a restriction in the first place. For B2C direct marketing, however, a strict six-condition regime remains immovably in place, with no room for partial compliance.07.10.2026Invisible trackers in your Inbox: Italian Data Protection Authority issues binding Guidelines on email tracking pixels
September 2026
28.09.2026GREECE ADOPTS LEGISLATION IMPLEMENTING THE AI ACT: A PIVOTAL ROLE FOR THE DATA PROTECTION AUTHORITY WITHIN THE NEW REGULATORY FRAMEWORKIn July 2026, Greece adopted Law 5321/2026 (“the Law”) which introduced measures implementing Regulation (EU) 2024/1689 (“AI Act”). In line with the AI Act, the Law aims to establish an appropriate framework for achieving the effective supervision of Artificial Intelligence Systems, to ensure a high level of protection of health, safety and fundamental rights in the use of such systems, and support innovation. In particular, the Law designates, for the purposes of the AI Act, the market surveillance authorities, the single point of contact and the notifying authorities, and regulates issues relating to cooperation and coordination between the competent authorities. Moreover, the Law governs issues pertaining to AI regulatory sandboxes and testing of AI systems in real world conditions. With regards to infringements of the AI Act and the Law, effective, proportionate and dissuasive penalties are determined, while provisions relating to judicial protection and the exercise of the right to appeal against decisions issued pursuant to the AI Act and the Law are also included. In the above regulatory framework, the Hellenic Data Protection Authority is assigned a particularly important and multifaceted role.27.09.2026Panama Establishes a Legal Framework to Pursue CybercrimesSince 5 August 2025, Law 478 has expanded Panama’s Criminal Code to cover offences committed through computer systems, including phishing, thereby establishing a stronger framework for prosecuting cybercrime.09.09.2026Singapore's New Generative AI GuidanceAs organisations race to adopt generative AI, Singapore's regulators have provided their clearest indication yet of what responsible AI governance should look like in practice. This article examines how the PDPC and IMDA's latest Guidelines reshape expectations around consent, web scraping, accountability across the AI supply chain, and user-facing transparency, revealing a common theme: effective AI governance begins before a model is deployed.09.09.2026Spain meets JapanINPLP members from Spain and Japan, Belén Arribas and Satoshi Shono, met in Tokyo and discussed hot topics on privacy law in their countries and their respective legal markets
Juli 2026
16.07.2026Germany: Rising Data Subject Requests at Data Protection Supervisory AuthoritiesAI as an Amplifier and the Growing Risk for Companies14.07.2026The Office of the Information Commissioner in Jamaica establishes the Data Protection Working GroupOn March 17, 2026, the Office of the Information Commissioner (OIC) established one of the most significant intstitutional developments in Jamaica’s privacy regime since the passage of the Data Protec…09.07.2026A Record-breaking Year: 2025 Annual Report of Ireland’s Data Protection RegulatorIreland’s Data Protection Commission (DPC) published its Annual Report outlining its regulatory activities in 2025. Highlights include: a 45% increase in complaints, the arrival of AI-driven complaints, a decrease in reported breaches, the DPC’s international and growing inter-regulatory role and reprimands as the chosen enforcement power.07.07.2026Data Sovereignty and India’s New Privacy LawIndia is one of the world’s biggest generators of online data, and the new Digital Personal Data Protection Act, 2023, continues a regulatory trend aiming to safeguard Indian data.02.07.2026Brillen Rottler – A review of the DSAR mechanismOn 19 March 2026, the Court of Justice of the European Union (CJEU) delivered its judgment in Brillen Rottler GmbH & Co KG v TC (Case C-526/24) addressing key issues surrounding data subject access requests (DSAR) and abusive practices. This decision has been anticipated as a potential opportunity to provide further guidance on balancing the right of access under Article 15 GDPR with controllers’ competing rights.
Juni 2026
23.06.2026A new member has joined the INPLP: Stefan MartinićLaw Office Stefan Martinić is a Croatian law office based in Zagreb providing legal advice in the fields of information technology law, EU law, commercial and corporate law, and employment law. Stefan…18.06.2026Consolidation of the French doctrine on personal data and pseudonymisation after the CJEU’s SRB rulingFollowing the CJEU's SRB ruling (C-413/23, 4 September 2025), French doctrine on the qualification of personal data and pseudonymisation has consolidated through the decisions of the Conseil d'État (13 February 2026, n° 498628) and the CNIL in the IQVIA case (26 May 2026, n°SAN-2026-008): pseudonymisation remains a risk-reducing security measure, not a passport to anonymity.17.06.2026A new member has joined the INPLP: Pedro Andrés Videla HermansenJohansson & Langlois - Patents & Innovatios: multidisciplinary team of engineers and specialists handle patent prosecution, utility models, industrial designs, integrated circuit topographies,…
