Photo of Virginie de France

Virginie de France

Virginie de France is an associate in the Data Privacy and Cybersecurity Practice Group. She advises clients on the full range of EU technology, data protection, and digital regulatory matters. Virginie supports clients with data protection compliance projects, assisting with investigations led by national authorities, and acting in litigation. She also has substantial experience helping organizations meet European and national cybersecurity obligations.

On July 9, 2026, the Court of Justice of the European Union (“CJEU” or “Court”) delivered its judgment in Sky Österreich Fernsehen (C-234/25), deciding that a streaming offering constitutes a digital service under the Consumer Rights Directive (Directive 2011/83/EU), rather than digital content, where the trader’s offering is of a dynamic nature and goes beyond the stable or continuous provision of specific content. As a result, providers of such streaming offerings cannot rely on the Consumer Rights Directive’s exception to the right of withdrawal for digital content.

The judgment has broad implications for providers of personalised digital services, as it affects whether consumers can cancel a subscription during the 14-day withdrawal period and, if they do, how much providers may charge for use of the service during that period.

Continue Reading CJEU Clarifies the Conditions for Seizure of Business Emails During Competition Inspections

On April 17, 2026, the Italian data protection authority (the “Garante”) published Provision No. 284 setting out guidelines on the use of “tracking pixels” in emails (the “Guidelines”). This publication closely follows the recommendation issued by the French data protection authority on the same topic, which is discussed in a separate blog post available here.

Tracking pixels are commonly used to measure email open rates and to enable marketing automation tools. Under Italian law, the use of tracking pixels generally requires the recipient’s prior consent, unless a specific exemption applies. In its Guidelines, the Garante provides practical examples to help organizations assess when consent is (and is not) required and clarifies the compliance obligations applicable to businesses relying on these technologies in email communications. This post summarizes the key takeaways.

Continue Reading Italian DPA Publishes Guidelines on Email Tracking Pixels

On 15 January 2026, the Belgian High Court delivered a judgment in proceedings initiated by the Belgian Supervisory Authority, in which it challenged the scope of judicial review exercised by the Market Court over its enforcement decisions. The authority was unsuccessful on both grounds of appeal.

Continue Reading Belgian High Court Confirms Full Judicial Review of Supervisory Authority Decisions