On July 7, 2026, the European Data Protection Board (“EDPB”) adopted draft Guidelines 02/2026 on Anonymisation (“Guidelines”), updating a 2014 Opinion on Anonymization Techniques. While the EDPB maintains a cautious approach to anonymization, the new Guidelines appear to offer a more structured and practical framework for assessing whether information can be considered anonymous. The Guidelines are open for public consultation until October 30, 2026.
Continue Reading EDPB Publishes Draft Guidelines on Anonymisation
Kristof Van Quathem
Kristof Van Quathem advises clients on information technology matters and policy, with a focus on data protection, cybercrime and various EU data-related initiatives, such as the Data Act, the AI Act and EHDS.
Kristof has been specializing in this area for over twenty years and developed particular experience in the life science and information technology sectors. He counsels clients on government affairs strategies concerning EU lawmaking and their compliance with applicable regulatory frameworks, and has represented clients in non-contentious and contentious matters before data protection authorities, national courts and the Court of the Justice of the EU.
Kristof is admitted to practice in Belgium.
CJEU Clarifies the Conditions for Seizure of Business Emails During Competition Inspections
On July 9, 2026, the Court of Justice of the European Union (“CJEU” or “Court”) delivered its judgment in Sky Österreich Fernsehen (C-234/25), deciding that a streaming offering constitutes a digital service under the Consumer Rights Directive (Directive 2011/83/EU), rather than digital content, where the trader’s offering is of a dynamic nature and goes beyond the stable or continuous provision of specific content. As a result, providers of such streaming offerings cannot rely on the Consumer Rights Directive’s exception to the right of withdrawal for digital content.
The judgment has broad implications for providers of personalised digital services, as it affects whether consumers can cancel a subscription during the 14-day withdrawal period and, if they do, how much providers may charge for use of the service during that period.
Continue Reading CJEU Clarifies the Conditions for Seizure of Business Emails During Competition InspectionsCNIL Updates Two Standards For Health Research (MR-001 and MR-003)
On May 26, 2026, the French data protection authority (“CNIL”) published updated versions of its Reference Methodology 001 (“MR-001”, available here in French) and Reference Methodology 003 (“MR-003”, available here in French), two key frameworks governing the processing of personal data in the context of health research.
Continue Reading CNIL Updates Two Standards For Health Research (MR-001 and MR-003)Italian DPA Publishes Guidelines on Email Tracking Pixels
On April 17, 2026, the Italian data protection authority (the “Garante”) published Provision No. 284 setting out guidelines on the use of “tracking pixels” in emails (the “Guidelines”). This publication closely follows the recommendation issued by the French data protection authority on the same topic, which is discussed in a separate blog post available here.
Tracking pixels are commonly used to measure email open rates and to enable marketing automation tools. Under Italian law, the use of tracking pixels generally requires the recipient’s prior consent, unless a specific exemption applies. In its Guidelines, the Garante provides practical examples to help organizations assess when consent is (and is not) required and clarifies the compliance obligations applicable to businesses relying on these technologies in email communications. This post summarizes the key takeaways.
Continue Reading Italian DPA Publishes Guidelines on Email Tracking PixelsNew EDPB Guidelines on the Use of Personal Data in Scientific Research
On April 15, 2026, the European Data Protection Board (EDPB) published draft Guidelines 1/2026 on the processing of personal data for scientific research purposes (Guidelines). The Guidelines are open for public consultation until 25 June 2026. They aim to clarify how the GDPR applies to academic, public‑sector, and commercial research, including research that relies on AI, large data sets, and the reuse of personal data. The Guidelines do not cover the application of other EU or Member State law regulating scientific research or the processing of genetic, biometric, or health data specifically.
Continue Reading New EDPB Guidelines on the Use of Personal Data in Scientific ResearchItalian DPA Fines Bank over the Transfer of Customer Data in the Context of a Corporate Transaction
On March 12, 2026, the Italian Data Protection (“Garante”) adopted a decision concerning the transfer of personal data of banking customers from Intesa Sanpaolo S.p.A. (the “Bank”) to Isybank S.p.A., a newly established digital bank within the same corporate group. The Garante found that the Bank’s processing in connection with the transfer of approximately 2.4 million customers to Isybank was unlawful.
We set out the decision’s key findings below.
Continue Reading Italian DPA Fines Bank over the Transfer of Customer Data in the Context of a Corporate TransactionEDPB Publishes Report on Stakeholder Event on Anonymisation and Pseudonymisation
On February 18, 2026, the European Data Protection Board (“EDPB”) published its Report on Stakeholder Event on Anonymisation and Pseudonymisation of 12 December 2025 (the “Report”). The Report summarises feedback from a remote stakeholder event convened to inform the EDPB’s ongoing work on Guidelines 01/2025 on Pseudonymisation (version for public consultation available here) and forthcoming guidance on anonymisation. The event gathered input from 115 participants spanning industry, NGOs, academia, law firms, and public sector bodies.
The objective of the Report is to capture stakeholder insights on how the General Data Protection Regulation (“GDPR”) applies to anonymisation and pseudonymisation, particularly following the Court of Justice of the European Union’s (“CJEU”) judgment in EDPS v SRB (C‑413/23 P). (See our previous blog post here.)
Continue Reading EDPB Publishes Report on Stakeholder Event on Anonymisation and PseudonymisationEU Regulators Issue Opinion on Revisions of GDPR and Other Data Laws
On February 11, 2026, the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) (jointly, the Authorities) issued a Joint Opinion on the European Commission’s proposed Digital Omnibus Regulation (Digital Omnibus). This follows their Joint Opinion of January 20, 2026 on the Digital Omnibus on AI.
The Digital Omnibus, as with the other “omnibuses” released by the Commission, aims to streamline several EU laws, reduce administrative burdens for covered entities, and enhance competitiveness in the EU. Once adopted, it should reshape how organizations handle personal data generally, including in relation to AI development, scientific research, and incident reporting. The Authorities welcome efforts to simplify and to promote consistent interpretations of key concepts found in the GDPR, the ePrivacy Directive, the NIS2 Directive, and the remaining Data Acquis. At the same time, they caution that this initiative launched by the Commission must not weaken fundamental rights protections, including data protection.
Below is an overview of the Authorities’ positions. It covers only the key amendments discussed in our previous blog post on the Digital Omnibus.
Continue Reading EU Regulators Issue Opinion on Revisions of GDPR and Other Data LawsBelgian High Court Confirms Full Judicial Review of Supervisory Authority Decisions
On 15 January 2026, the Belgian High Court delivered a judgment in proceedings initiated by the Belgian Supervisory Authority, in which it challenged the scope of judicial review exercised by the Market Court over its enforcement decisions. The authority was unsuccessful on both grounds of appeal.
Continue Reading Belgian High Court Confirms Full Judicial Review of Supervisory Authority DecisionsFrench CNIL Imposes €1M GDPR Fine on Israeli Ad Tech Firm
On December 11, 2025, the CNIL fined an Israeli company €1 million for failing to comply with its GDPR obligations after providing personalized advertising services to an EU music-streaming platform. The service helped the platform to personalize and optimize marketing campaigns to promote its streaming services.
The CNIL held that the GDPR applied to the non-EU processor under Article 3(2), on the basis that it had monitored the behavior of EU users by creating audience segments based on demographics and listening habits, on behalf of the controller.
Continue Reading French CNIL Imposes €1M GDPR Fine on Israeli Ad Tech Firm