Governance and regulation

What organisations are now required to do about security and personal data, when each obligation starts, and what has happened to the ones that did not. Every entry is the issuing body’s own publication, linked to the original.

1
Deadlines ahead
9
Rules tracked
4
Enforcement actions
5
Guidance

What is coming

EnforcementEU2026-09-09

Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR

Background information Date of final decision: 3 September 2026 National case Controller: Hôpital Privé de la Loire Legal Reference: Article 32 (Security of processing), Article 34 (Communication of a personal data breach to the data subject), Decision: Administrative fine Keywords: Cybersecurity, Personal data breaches, Health and research Summary of the Decision Origin of the case In summer 2025, an attacker managed to connect to the Computerised Patient Summary (DPI) of the Hôpital Privé de la Loire (Loire’s private hospital), which centralises all the data of the individuals under care. It thus accessed the data of 524 867 patients (some of them health data) and 202 246 persons designated as “trusted third parties”. As a result of this data breach, the CNIL carried out a check that identified several failures of the Hôpital Privé de la Loire to comply with the obligations laid down in the General Data Protection Regulation (GDPR). Key findings Failure to ensure the security of personal data (Article 32 GDPR) The authentication procedure to connect to the hospital’s e-Health Patient Summary, used by users outside the hospital, in particular doctors not affiliated with

European Data Protection BoardGDPR
EnforcementEU2026-09-03

Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE)

Background information Date of final decision: 28 August 2026 National case Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 32 (Security of processing), Article 33 (Notification of a personal data breach to the supervisory authority), Article 34 (Communication of a personal data breach to the data subject) Decision: Administrative fine, Compliance order, Communication order personal data breach Key words: GDPR enforcement, Data subjects rights, Fines, Health and research Summary of the Decision Origin of the case This Inquiry commenced on 24 May 2024 as a result of two personal data breaches notified to the Data Protection Commission (DPC) in October 2023 and November 2023. In both cases, individuals gained unauthorised access to paper records stored and retained in both St. Loman’s Hospital (Mullingar, County Westmeath) and St Conal’s Hospital (Letterkenny, County Donegal). Both locations are former disused psychiatric hospitals.Videos uploaded to social media by intruders highlighted that medical records were stored and retained in both facilities. Key Findings The Data Protection Commission (DPC) has announced its final decision

European Data Protection BoardGDPR
GuidanceEU2026-07-30

Stakeholder event on guidelines on the interplay between data protection and competition law: overview of topics available

Brussels, 30 July – The EDPB and the European Commission organise a remote stakeholder event in the context of their joint work on upcoming guidelines on the interplay between competition and data protection . The event will take place on 15 October 2026 and is an opportunity for stakeholders to inform and support the ongoing work on this topic. The event reflects the EDPB’s commitment to stakeholder engagement and cross-regulatory cooperation, as outlined in the Helsinki statement and in the EDPB Strategy 2024-2027 . Who can participate? The EDPB and the European Commission welcome participation from individuals and organisations with relevant expertise in the topic of the event. How to take part? The call is now closed. Overview of key topics Please find here the overview of topics and questions for the EDPB–EC Stakeholder Event on GDPR & Competition Law . Further background reading Position paper on Interplay between data protection and competition law OECD - The intersection between competition and data privacy (this document has not been produced by the EDPB)

European Data Protection BoardGDPR
RuleEU2026-07-08

EDPB sheds light on anonymisation and web scraping for generative AI and adopts final version of guidelines on blockchain

Brussels, 8 July– During its latest plenary, the EDPB has adopted guidelines on anonymisation and guidelines on web scraping in the context of generative AI. In addition, the Board has adopted the final version of its guidelines on the processing of personal data through blockchain technologies. Understanding anonymous data The new EDPB guidelines bring clarity to the notion of anonymous data , taking also into account the ruling of the Court of Justice of the EU in the case C-413/23 P EDPS v SRB of 4 September 2025 and other CJEU jurisprudence. The guidelines mark a significant milestone in clarifying the notion of anonymous data, establishing clear standards that facilitate the use of data while protecting individuals' fundamental rights. In developing these guidelines, we incorporated valuable input from our stakeholder event, showing, once more, our strong commitment to collaborative dialogue as outlined in the EDPB Helsinki statement. EDPB Chair, Anu Talus Data is anonymous if it does not relate to an identified or identifiable natural person. Whether this is the case may vary from one entity to another. Information can relate to an individual because of its content, purpose,

European Data Protection Board
GuidanceEU2026-07-01

EDPB and AMLA to develop Joint Guidelines on partnerships for information sharing

Brussels/Frankfurt, 1 July – The EDPB and the Anti-Money Laundering Authority (AMLA) are working together to bring greater clarity to a question of growing importance for industry and authorities alike: how to share information to fight financial crime while protecting personal data. Why information sharing matters The fight against financial crime depends on cooperation, and information sharing can help detect and prevent money laundering and terrorist financing. Art. 75 of the AML Regulation makes this possible, allowing companies and professionals covered by anti-money laundering rules to share information with each other and with public authorities, within clear limits. The new information sharing possibility will apply from 10 July 2027. To provide clarity on this possibility, the EDPB and AMLA will work together on the development of Joint Guidelines. Clearer rules for industry and authorities Sharing information of this kind means processing personal data, which is why data protection safeguards are essential. The Joint Guidelines, developed by the EDPB and AMLA, will set out in practical terms how partnerships can be built so that effective information sharing and th

European Data Protection Board

Sources: the US Federal Register, the Securities and Exchange Commission, the Federal Trade Commission, the European Data Protection Board and the UK National Cyber Security Centre. Dates are as published and are shown in UTC. This is a tracker, not legal advice, and an obligation that applies to you is a question for your own counsel.