EDPB adopts new guidelines on calculating GDPR fines
The EDPB has adopted Guidelines 04/2026 on administrative fines, replacing the 2017 guidelines, and finalised its DSA–GDPR guidelines.
Insights for the EU, the EEA, and the rest of Europe.
The EDPB has adopted Guidelines 04/2026 on administrative fines, replacing the 2017 guidelines, and finalised its DSA–GDPR guidelines.
Manufacturers must now report actively exploited vulnerabilities and severe incidents under the EU Cyber Resilience Act.
EU authorities can now issue European Production and Preservation Orders directly to service providers.
Amendments to the EU AI Act defer high-risk obligations and soften the AI literacy duty.
The European Commission has renewed its adequacy decisions for the UK, so personal data can continue to flow freely from the EU.
Germany’s NIS2 Implementation Act takes effect, significantly expanding the number of organisations subject to cyber security duties.
The CCB has published CyFun 2025, with more emphasis on supply chain and operational technology security.
The EU Data Act now applies, covering access to connected-product data and cloud switching obligations.
Obligations for providers of general-purpose AI models under the EU AI Act apply from today.
Swiss critical infrastructure operators must now report cyber attacks to the National Cyber Security Centre within 24 hours.
Prohibited AI practices are now banned in the EU, and AI literacy obligations apply.
The Digital Operational Resilience Act applies from today to EU financial entities and their ICT third-party providers.