GDPR & AI Data Protection
Regulatory news — what they mean for Swedish companies.
Canvas Breach Forces Immediate GDPR Action
The Swedish Data Protection Authority has confirmed a significant data breach at Canvas, the learning platform owned by US firm Instructure. With this tool wide...
EU Forces Standardized Data Breach Reporting
The European Data Protection Board has just approved a standardized template for reporting personal data breaches, a move designed to cut through the red tape t...
US Ruling Threatens EU Data Transfers
A recent US Supreme Court ruling in *Trump v. Slaughter* has fundamentally altered the landscape of American regulatory oversight, granting the president the po...
EU Now Enforcing One GDPR Standard
The European Data Protection Board met in Dublin last July, bringing together data protection authorities from across the EU and EEA to tackle a persistent head...
EU Signals Tighter Scrutiny on Law Enforcement Data
The European Data Protection Board has published individual replies from national supervisory authorities regarding the European Commission’s evaluation of the...
Web Scraping for AI May Violate GDPR
The European Data Protection Board has issued critical guidance clarifying that anonymizing data scraped from the web for generative AI training is far more dif...
Your Consent Mechanism May Be Illegal
The European privacy watchdog NOYB has filed a formal complaint against the popular online dictionary dict.cc, challenging a consent mechanism that bundles 1,74...
AI Scraping Rules Now Hit Swedish Firms
The European Data Protection Board has officially adopted new guidelines on web scraping for training generative AI, a move that fundamentally shifts how compan...
Blockchain Is Not a GDPR Exemption
The European Data Protection Board has just finalized its stance on anonymization and blockchain data processing. For Swedish tech leaders, this is not just bur...
Nordic Regulators Tighten AI Data Grip
The Nordic data protection authorities recently gathered in Stockholm for a high-stakes summit that signals a tightening grip on how artificial intelligence is...
Your AI Vendor Won't Save You From GDPR
The Swedish Data Protection Authority (IMY) has released a crucial report clarifying the responsibilities of companies using AI applications under GDPR. The cor...
Your Swedish License Won't Save You From GDPR
The European Court of Justice has delivered a pivotal ruling on the intersection of data protection and Sweden’s unique voluntary publishing license system for...
EDPB Won't Answer Your Questions
Stop emailing the European Data Protection Board for answers. The EDPB has made it abundantly clear that its secretariat will not respond to individual inquirie...
IMY Now Polices Your AI Compliance
Sweden has officially designated the Swedish Authority for Privacy Protection (IMY) as the market surveillance authority for the EU AI Act. This is not just a b...
US Supreme Court Ruling Threatens Your EU Data Transfers
The US Supreme Court has just dismantled the legal foundation of the EU-US Data Privacy Framework. In a ruling that upends decades of transatlantic data flow as...
Your Consent Button Might Be Lying to Users
The French data protection authority CNIL has fined Condé Nast €750,000 for failing to obtain valid consent before placing cookies on its Vanity Fair website. T...
EU Kills Browser Privacy Signal Boosting Cookie Risks
The European Commission’s plan to replace intrusive cookie banners with automated browser signals has been scrapped. In a baffling reversal, key EU Member State...
EU Rejects Easier GDPR Rules for AI
The European Data Protection Board and the European Data Protection Supervisor have issued a stark warning against the European Commission’s proposed Digital Om...
Criteo Fine Warns Swedish Tech Firms
The French highest administrative court has upheld a €40 million GDPR fine against ad-tech giant Criteo, rejecting its final appeal. This ruling is a stark warn...
EU Enforcement Gap Risks Your Biometric Data
The Hamburg data protection authority is being sued for inaction after five years of ignoring clear GDPR violations by PimEyes, a facial recognition engine that...
Audit Your Vendor Scoring APIs Now
Austrian credit reference agency CRIF is facing a landmark class action and injunction from NOYB for building a secret shadow registry of nearly every adult in...
Your Paid Model May Violate GDPR Access Rights
LinkedIn is facing a formal complaint from NOYB for locking GDPR access rights behind a paid Premium subscription. The core issue is simple: if LinkedIn sells i...
Your Consent Banner May Be Illegal
Schibsted, the Nordic media giant behind Aftonbladet and VG, has triggered a regulatory backlash by implementing a “Pay or Okay” consent model. Complaints filed...
TikTok Fines Warn Swedish Tech Leaders
TikTok is under fire for unlawfully tracking users across other apps, including sensitive dating app usage, while simultaneously failing to provide complete dat...
Microsoft Tracking Order Shakes EU Data Rules
Microsoft has been ordered to stop tracking school children via cookies in its Education suite, a ruling that sends a clear warning to every Swedish CTO and CIS...
Your Cookie Banner Might Be Illegal Now
The Austrian Federal Administrative Court has ruled that ORF.at’s cookie banner violates GDPR by using dark patterns to trick users into consenting to tracking....
83% of Companies Fail GDPR Data Requests
The European Commission is pushing to restrict the GDPR right of access, citing alleged abuse by citizens. The reality is starkly different. A new analysis by N...
Meta Ruling Forces Full Data Transparency
The Austrian Supreme Court has issued a final, binding ruling against Meta, mandating that the tech giant provide users with full, granular access to their pers...
Scraped Data Is Tainting Your AI Models
A major investigation by noyb into Austrian credit agency CRIF has exposed how public registries are being systematically scraped and repurposed for commercial...
GDPR Fines Are Rare But The Process Is Brutal
The privacy watchdog NOYB has just dismantled five pervasive myths surrounding the GDPR, delivering a stark reality check for Swedish tech leaders. Their latest...
EU Simplification Plan Ignores Your Compliance Reality
The European Commission’s Digital Omnibus proposal aims to cut regulatory burdens by restricting data subject rights and loosening rules for AI training. Howeve...
Microsoft Ruling Shatters Cloud Compliance Illusion
The Austrian Data Protection Authority has ruled that Microsoft 365 Education illegally tracks students and withheld personal data in response to access request...
EU Draft Could Collapse GDPR Protections for AI
The European Commission has quietly drafted a massive reform of the GDPR, disguised as a simplification measure called the "Digital Omnibus." Leaked documents r...
EU Plan to Gut GDPR Protections for Big Tech
The EU Commission has unveiled its "Digital Omnibus" proposal, a sweeping reform that civil society groups and privacy advocates are calling a massive attack on...
EU-US Data Bridge Collapses: Your Compliance Is Gone
The legal foundation for transferring EU personal data to the United States is collapsing. NOYB argues that recent US Supreme Court proceedings and shifting exe...