Every month, we deliver the essential data news to you in our newsletter Data4Coffee. Don't miss out on the key updates!
To subscribe, please fill out this form.
[June 16 – July 7, 2026] Arcom has published the first edition of its AI service audience barometer. This tool provides a range of statistics on the use of AI services among minors and young people, highlighting the massive adoption of these services within this demographic. As noted by some commentators, by publishing this barometer, Arcom appears to be gradually positioning the DSA as a lever for regulating AI systems integrated into online platforms. Thanks to the powers granted by the DSA, it can request information, conduct investigations, and monitor compliance with obligations by certain platforms. AI regulation must therefore now also be viewed through the lens of the DSA, as evidenced by the recent designation of ChatGPT as a very large search engine under the regulation.
Sources:
[July 6 – August 14, 2026] On July 6, 2026, the European Commission issued a detailed opinion regarding the proposed legislation aimed at protecting minors from the risks associated with social media use, in the version passed by the Senate. The Commission deemed the text not fully compatible with EU law, as the supervisory powers granted to Arcom would encroach upon the harmonized cooperation mechanism of the DSA. The Commission also noted that age verification or parental consent obligations imposed on platforms would duplicate the requirements for the protection of minors established by the DSA (Articles 28, 34, and 35), and would conflict with Article 8 of the DSA, which prohibits any general obligation to monitor. Following this opinion, the text was amended and a new version was adopted by Parliament. However, this new version of the measure was struck down by the Constitutional Council, which had been referred the matter by 60 members of parliament. In its decision, the Constitutional Council held that the general ban provided for in the text constitutes a disproportionate infringement on freedom of expression and communication, particularly due to the broad scope of the ban covering all social media, and that the legislature had not provided sufficient safeguards to ensure the protection of privacy. A French mechanism to ban certain social media for minors under fifteen remains legally possible, but the legislature's room for maneuver is doubly limited: first, by European law and the harmonization brought about by the DSA, and second, by the fundamental rights guaranteed by the Constitution and the requirement that any infringement upon them be proportionate.
Sources:
[July 6, 2026] The CNIL has announced that it has issued 23 sanctions since January 2026 under its simplified procedure, totaling 133,750 euros in fines. The breaches primarily concern employee video surveillance, cookies, and compliance with individual rights (access and erasure). Of the 23 sanctions, 8 relate to failure to comply with complainants' rights of access or erasure, 4 of which are associated with a failure to cooperate with the CNIL. Notably, the CNIL has issued fines against companies that failed to respond to requests for access or erasure, or took too long to do so. This serves as a useful reminder that both a lack of response and delayed responses to requests to exercise rights are regularly sanctioned.
Source: The CNIL has issued 23 new sanctions since January under the simplified procedure | CNIL
[July 9, 2026] While an employer's management authority allows them to supervise and verify the activity of their staff, the CNIL reiterates the three cumulative conditions for the lawfulness of any monitoring systems that may be implemented. First, the justification and proportionality of the system with regard to the respective rights and interests involved. The employer must clearly define the objective and scope of the monitoring, identify the risks to individual rights, verify that no less intrusive means exist, and determine the data that is strictly necessary, its retention period, and the individuals authorized to access it. The CNIL points out that constant surveillance is, in principle, excessive. Second, the prior consultation of employee representative bodies, namely the Social and Economic Committee (CSE) for companies with more than 50 employees, for any monitoring system deployed. Finally, informing the individuals concerned. Under the obligations of loyalty and transparency, the employer must inform employees of the existence of the system prior to its implementation. These recommendations are not new but consolidate the link between data protection and employee rights, which must be documented by employers.
Source: Work, human resources: monitoring the activity of employees | CNIL
[July 20, 2026] The CNIL and the AI and Digital Council have prepared a briefing note examining the application of the GDPR to agentic AI. The note highlights the new challenges and risks posed by agentic AI, particularly emphasizing its deductive capabilities, which allow for the collection and processing of ever-increasing amounts of information regarding a user's private life. It also stresses that the autonomy of these systems is likely to lead to automated decision-making within the meaning of Article 22 of the GDPR, and that the mere fact that a human intervenes at the end of the decision-making chain does not necessarily rule out this classification. The note provides general recommendations for reconciling the use of agentic AI with GDPR compliance, such as compartmentalizing agent memory. It also explores the possibility of issuing specific recommendations for developers or deployers of agentic AI, or clarifying the application of the automated decision-making regime in the context of agentic AI. Companies developing or deploying agentic AI systems should therefore expect new recommendations or official positions from the competent authorities in the coming months or years.
[July 20, 2026] In a joint declaration dated July 20, 2026, France and Germany agreed on the importance of managing the consequences of advanced AI for national and international security. Both states recognize AI as one of the most defining technological advancements of our time and emphasize the need for the safe development and deployment of these systems. To achieve this, France and Germany aim for close cooperation between their key stakeholders to advance the work of the EU, NATO, and the UN. This collaboration is based on a partnership between institutions: on the German side, the Federal Ministry for Digital and Transport, the Federal Ministry of the Interior, and the German AI Safety and Security Institute; on the French side, the General Secretariat for Defense and National Security (SGDSN), the Directorate General for Enterprises (DGE), and the French National Institute for the Evaluation and Security of Artificial Intelligence (INESIA). The methods, guidelines, and evaluation frameworks resulting from this partnership should be monitored closely.
[July 22, 2026] Following its April 14, 2026, recommendation on email tracking pixels, the CNIL has published a FAQ this summer to assist with implementation. Three key takeaways emerge regarding the scope, consent exemptions, and stakeholder liability. Regarding scope, the CNIL clarifies that its recommendation applies to any use of trackers in emails, regardless of the context, the sending organization, or the recipient's status. Regarding consent exemptions, the conditions are strict: the deliverability pixel may only collect the date of the last opening without consent; any other data collected (time of opening, IP address, user-agent, etc.) invalidates the exemption. Regarding liability, the email service provider acts as a processor when inserting the pixel solely on behalf of the sender, but may become a joint controller if it uses the pixel for its own purposes. However, in all cases, the party delegating the collection of consent cannot rely solely on a contractual clause with its provider and must be able to demonstrate its validity. Since the 3-month grace period for addresses collected before April 14, 2026, expired on July 14, 2026, senders must now obtain consent or stop using the pixels in question if they have not sent an information email allowing data subjects to opt out.
Source: Q&A - CNIL recommendation on pixels in electronic mail | CNIL
[August 5, 2026] On August 5, 2026, the CNIL announced the arrival of five new members to its Board: Marie-Luce Cavrois, honorary advisor at the Court of Cassation; Marion Fourtune, association leader, vice-president of France Nature Environnement, and member of the Economic, Social and Environmental Council; Arnaud Latil, professor and researcher in private law, vice-president of AI, strategy and foresight at Sorbonne University, and expert for the AI Office advisory forum; Benjamin Nguyen, professor and researcher at INSA Centre-Val de Loire, specializing in data protection, anonymization, and information system security; and Éric Thiers, State Councilor and historian, specializing in parliamentary and constitutional institutions. The profiles of the new members joining the CNIL's decision-making and deliberative body signal two trends: a strengthening of expertise dedicated to artificial intelligence and the maintenance of a balance between legal and technical skills.
Source: CNIL Board: 5 new members appointed on August 2, 2026 | CNIL
[July 3 - August 10, 2026] Two publications from the CNIL, released one month apart, highlight a growing tension surrounding the role of the Data Protection Officer (DPO). On one hand, the results of the survey published on July 3, 2026, for the fifth edition of the DPO Profession Observatory, reveal a role increasingly consumed by artificial intelligence. While 70% of responding organizations are using or planning to use AI, more than half of the DPO respondents state that the AI Act is already within their scope of responsibility and are often, if not systematically, involved in AI projects, even though only 27% of them feel they have a good grasp of the text. On the other hand, the CNIL's practical guide from August 10, 2026, reiterates the limits of this expandable scope: combining roles is lawful as long as it does not place the DPO in a conflict of interest and does not deprive them of the time necessary for their duties. The CNIL reminds us that this individual cannot be both judge and jury, providing a list of questions designed to identify and manage conflicts of interest. Organizations that identify such a situation are required to put an end to it. These developments raise awareness among companies regarding the position and role of their DPO in an AI era where governance rules are bound to evolve.
Sources:
[Summer 2026] According to a study published by Surfshark, the first half of 2026 set a new record: 43.4 million accounts belonging to French citizens were reportedly compromised between January and June 2026 (a 60% increase compared to the previous half-year). The summer of 2026 does not appear to be reversing this trend, as France recorded an uninterrupted series of cyberattacks between July and August. Among these breaches, the DGFiP confirmed on August 13 that there had been unauthorized access to its information system, with a second intrusion targeting the land registry service being claimed. INSEE, the Ministry of National Education, Santé publique France, Inserm, and Bloctel were also reportedly affected, alongside various companies and sports federations. The hacker ZeroBytes claimed a new attack on the "Zéro Logement Vacant" website using a compromised administrator account, stealing data from 48 million property owners. Two constants emerge. First, service providers have become the primary entry point: the compromise of the software vendor BlgCloud alone reportedly exposed the data of 159 client companies. Second, hijacked legitimate access—using valid accounts and bypassing two-factor authentication—is now replacing traditional technical intrusions. However, the data controller remains responsible even when the breach occurs at their processor: they must notify the CNIL within 72 hours, implement the necessary remediation measures with their processor, and, in the event of a high risk, inform the affected individuals personally.
Sources:
[June 25, 2026] The European Commission has announced that it has informed AWS and Microsoft of its intention to designate them as "gatekeepers" under the DMA, this time for their cloud computing services. While Amazon and Microsoft are already classified as gatekeepers for some of their core platform services (notably the Amazon marketplace and LinkedIn), this would be the first designation of cloud computing service providers. However, this announcement does not constitute a final decision at this stage, as AWS and Microsoft still have the opportunity to submit their comments. If confirmed, AWS and Azure will be subject to the obligations set out in the regulation, particularly regarding restrictions on the use and combination of data from business users.
[July 7, 2026] Amid the rise in AI-driven cyberattacks, the European Commission has unveiled an action plan designed to provide a structured response to the risks posed by AI tools, while also leveraging their potential for cybersecurity. By coordinating with EU member states, businesses, and organizations, the Commission intends to build on the existing legal framework to evaluate AI models, gain access to the most advanced AI systems, and establish a secure testing platform for AI in cybersecurity. This action plan also calls for a necessary shift in awareness among EU stakeholders: organizations must strengthen their cyber hygiene practices, risk management measures, and the application of the principle of security by design. To this end, the European Commission encourages them to utilize currently available AI capabilities to detect and remediate vulnerabilities more rapidly.
[July 8, 2026] The European Data Protection Board has adopted two major sets of draft guidelines: one regarding the concept of anonymous data, taking into account the SRB ruling by the Court of Justice of the European Union (CJEU, September 4, 2025, C-413/23 P, EDPS v SRB), and the other on GDPR compliance for web scraping used to train generative AI models (legal basis, processing of special categories, and the principles of purpose limitation and transparency). These draft guidelines are open for public consultation until October 30, 2026. The European Data Protection Board has also finalized its guidelines on blockchain. These draft guidelines clarify the interpretation of the GDPR in light of new practices and technologies, such as blockchain and generative AI.
[July 8, 2026] In a judgment delivered on July 8, 2026, the General Court of the European Union dismissed all appeals filed by Apple against its designation as a gatekeeper under the Digital Markets Act (DMA). The Commission had applied this classification in September 2023 to the App Store and the iOS operating system, considering them to be an essential intermediary between businesses wishing to offer their services online and end users. Apple had argued, in particular, that its five app stores (for iPhone, iPad, Apple Watch, Mac, and Apple TV) should be assessed separately and could not be treated as a single core platform service. The Court rejected this argument, finding that these stores serve an identical purpose—connecting developers with users—and do not present sufficient differences to constitute distinct services. Apple therefore remains subject to the obligations of the DMA, including the interoperability requirements for its platform.
Sources:
[July 9, 2026] The Court of Justice of the European Union has ruled that a consumer who subscribes to a streaming service is entitled to the 14-day right of withdrawal provided by the Consumer Rights Directive, and that providers cannot contractually exclude this right on the grounds that the contract has already been performed. According to the Court, the provision of a streaming service—whereby a customer accesses digital data stored on a server via a hyperlink or digital application to watch content live, on-demand, or offline after downloading it to a local storage device—constitutes the provision of a digital service rather than digital content, provided the offering has a dynamic nature that goes beyond the mere stable and potentially continuous provision of specific content. Consequently, the right of withdrawal cannot be contractually excluded by the service provider.
Sources:
[July 20, 2026] The European Commission has published the final version of its transparency guidelines (Art. 50 of the AI Act). As previously announced, these guidelines complement the code of practice published last June. They provide useful clarifications regarding the scope of each paragraph of Article 50 of the AI Act and its exceptions, how to inform users in various situations, and the interaction with other European legal instruments, such as the DSA or consumer protection directives. Affected parties have been required to ensure compliance with Article 50 since August 2, 2026, with the exception of the obligation regarding the labeling of AI-generated content (Art. 50(2) of the AI Act), the implementation of which was postponed to December 2, 2026, following the publication of the AI Omnibus.
[July 24, 2026] The regulation simplifying the AI Act has been officially published and enters into force on July 27, 2026. This publication confirms the postponement of obligations regarding high-risk AI systems embedded in products covered by sectoral regulations (August 2, 2028), obligations for other high-risk AI systems (December 2, 2027), labeling obligations for AI-generated content applicable to providers (December 2, 2026), and the establishment of regulatory sandboxes (August 2, 2027). The text also introduces notable amendments to the AI Act, including: the addition of a new Article 4a on the processing of sensitive data for bias correction, a new prohibition on AI systems that generate non-consensual sexual and intimate content or child sexual abuse material (Art. 5), an amendment to the definition (Art. 3) of safety components and the addition of express exclusions (Art. 6), and amendments to the articles on the development (Art. 10) and technical documentation (Art. 11) of high-risk AI systems. Although the implementation timeline for the text has been slightly adjusted, certain obligations—notably regarding transparency—as well as the Commission's oversight and sanctioning powers, took effect on August 2, 2026. Affected companies must continue their compliance efforts regarding the obligations coming into force in the months and years ahead.
Source: AI Omnibus enters into force | European Commission
[July 29, 2026] After dismissing two employees in March 2023, Piaggio failed to respond in a timely manner to their request to deactivate their professional email accounts and proceeded to collect numerous emails for the purpose of a "defensive" investigation and monitoring following internal reports regarding the individuals. While the Italian Data Protection Authority does not challenge the legality of this type of monitoring, it emphasizes that such checks can only cover data acquired after a suspicion of illegal behavior has arisen. The use of keywords and filters, as well as the balancing test conducted with the Data Protection Officer, are therefore insufficient to legitimize monitoring that covers a prior period. The authority notes that this retroactive monitoring was made possible by the excessive retention of professional email backups (5 years after the termination of the employment contract). Regarding the deactivation request, the authority reiterates that a professional email address and the associated correspondence constitute personal data, and that a deactivation request qualifies as a request for erasure under Article 17 of the GDPR, which Piaggio should have honored. In light of these failures, the Italian authority imposed a 460,000-euro fine on the employer. This case brings the management of professional email accounts back to the center of the debate.
Source: Garante per la protezione dei dati personali (Italy) - 476/2026 | GDPRHub
[June 29 - August 3, 2026] In the Trump v. Slaughter ruling, the U.S. Supreme Court held that the legal protection preventing the discretionary removal of Federal Trade Commission (FTC) commissioners was incompatible with the principle of separation of powers. A few weeks after this decision, the European Data Protection Board requested that the European Commission assess the impact of this ruling on the adequacy decision based on the Data Privacy Framework. According to the non-governmental organization NOYB, undermining the independence of the Federal Trade Commission (FTC) weakens one of the foundations of the adequacy decision and justifies its withdrawal, as well as new litigation before the Court of Justice of the European Union. An IAPP article offers a more nuanced analysis, noting that the adequacy decision remains legally valid and that data transfers may continue under the same conditions. In practice, the adequacy decision therefore remains applicable to this day, even if its future may depend on future legal challenges and the assessment of European institutions.
Sources:
[August 7, 2026] In August 2023, a law firm conducted an internal investigation for a client regarding alleged misconduct by a company executive. Two compliance reports were produced, containing the grievances, the identities of whistleblowers and witnesses, and a summary of the findings. To verify the accuracy of the claims made against her, the employee submitted an access request based on Article 15 of the GDPR. Citing the confidentiality of the reports and trade secret protection, the company refused the request. After a first-instance decision granted the request for a copy of the reports, the court of appeal ultimately rejected the claims on the grounds that the final compliance reports do not contain exclusively personal data. The information contained in the documents, such as legal analyses that merely reflect the data controller's assessment of the legal situation, is therefore not necessary for the data subject to verify the accuracy of their personal data and the lawfulness of the processing. This decision highlights the limits of the right of access, which is intended solely to allow individuals to verify the conditions under which their personal data is processed.
Source: BAG - 8 AZR 169/25 | GDPRHub
[August 24, 2026] The Dutch Data Protection Authority, in collaboration with the CNIL, has imposed a fine of nearly 825 million euros on Uber for automatically deactivating driver accounts without genuine human intervention. This decision follows a complaint filed with the CNIL by the Human Rights League on behalf of more than 170 drivers. The investigation was subsequently conducted by the Dutch authority, as Uber's European headquarters are located in the Netherlands. According to the Dutch authority, Uber used software to analyze driver behavior, trips, and customer ratings, as well as to detect potential fraud, which could lead to the automatic blocking of a driver's account. Despite the involvement of some Uber employees in the decision-making process, the authority concluded that no real analysis was performed, characterizing it as a fully automated decision under Article 22 of the GDPR. The authority also criticized Uber for failing to properly inform drivers about how these systems function. This case serves as a reminder that simply adding a human validation step at the end of a decision-making process is not enough to fall outside the scope of Article 22 of the GDPR; the human intervention must be genuine, based on an in-depth analysis, and carried out by a person with the skills and authority to make such a decision.
Sources:
[July 13, 2026] Meta employees have filed a lawsuit accusing the company of using artificial intelligence tools to select staff for a wave of layoffs affecting approximately 8,000 people. The plaintiffs claim that these systems disadvantaged employees who had taken protected leave (sick, parental, or family leave) or who have disabilities. Specifically, they allege that Meta used automated performance, activity, and AI tool usage metrics to generate ranking scores. According to the plaintiffs, these methods automatically penalized absent individuals, who had less performance data available. The complaint argues that Meta failed to adequately account for legal protections related to leave and disability status. Meta denies these accusations, asserting that layoff decisions were made by human managers rather than AI. The case highlights growing concerns regarding the use of algorithms in HR decisions and the risks of indirect discrimination associated with automated systems. France addressed this issue in May 2026, when the Court of Cassation affirmed the obligation to consult the Social and Economic Committee (CSE) before implementing any AI tool capable of altering employees' working conditions.
Source: Meta used AI to tag workers who took leave to be laid off, lawsuit claims | The Guardian
[July 20, 2026] At the opening of the first Singapore Data Festival, the local data protection authority (the Personal Data Protection Commission, PDPC) unveiled its guidelines on the use of personal data for developing and improving generative AI models. The stated goal is to facilitate the development of these models, notably by authorizing the scraping of personal data without consent, subject to the exception for "publicly available" data. However, for the reuse of data for training purposes, the guidelines place an obligation on providers to provide specific information to the individuals concerned (data involved, purposes, rights to object and withdraw consent). Finally, the text clarifies the division of responsibilities between model providers and system providers. The Singapore Data Festival was also an opportunity for the PDPC to announce the signing of a cross-border personal data transfer agreement with Japan. This first edition of the festival demonstrates how much issues related to data protection in the context of artificial intelligence tools are of interest on the international stage.
Source: Singapore spells out how personal data can be used in GenAI | Computer Weekly
[August 3, 2026] In its 2026 Threat Hunting Report, CrowdStrike highlights a profound shift in the operating methods of cyberattackers toward stealthy offensives that blend into normal business activity (exploiting legitimate accounts, SaaS applications, and cloud infrastructure). The cause: the rise of AI. CrowdStrike reveals that, in addition to creating a new risk front for victims, AI tools are being used by cyberattackers to automate vulnerability reconnaissance, refine targeting, and accelerate intrusions. In this context, intrusions leveraging these capabilities have increased by 89%, while the time between the detection of a security flaw and the attack has been significantly reduced to between 24 and 48 hours. This acceleration drastically narrows the window for cyber teams to apply necessary patches and secure exposed systems. Corporate IT security policies must now adapt to account for these new risks.
Sources:
Caroline Chancé, Jeannie Mongouachon, Clémentine Beaussier, Victoire Grosjean and Juliette Lobstein
.png)