In case you missed it – EDPO weekly recap | 06 – 10 July 2026

flashback - 6-12 June 2026

 

Here is a brief recap of the news and updates we shared last week.

The CNIL – Commission Nationale de l’Informatique et des Libertés fined IQVIA Operations France €5 million over breaches relating to health data processing, including information provided to individuals, the exercise of rights and data security. The hashtagCNIL also ordered remedial measures within six months, subject to a daily penalty for delay. [1]

The Council gave its final green light to Omnibus VII measures simplifying certain AI Act rules, including revised application dates for high-risk AI systems and a new ban on AI practices involving non-consensual sexual or intimate content and child sexual abuse material. [2]

noyb.eu said it will file a legal challenge to the EU-US Data Privacy Framework, following a US Supreme Court ruling concerning the Federal Trade Commission, and urged the European Commission to repeal the framework. [3]

The European Data Protection Board and the Anti-Money Laundering Authority will work together on Joint Guidelines on information sharing under Article 75 of the AML Regulation, which will apply from 10 July 2027. [4]

Apple’s Hide My Email feature is reportedly affected by a bug that can expose users’ real email addresses, according to research reported by 404 Media. [5]

A Governance AI study found that EU data protection rules are delaying or blocking some advanced LLM releases in Europe compared with the US, with non-text modalities facing greater barriers than text-based tools. [6]

References:
[1] CNIL fines IQVIA Operations France over health data processing

[2] Council gives final green light to Omnibus VII AI Act simplification measures

[3] Noyb prepares legal challenge to the EU-US Data Privacy Framework

[4] EDPB and AMLA to develop Joint Guidelines on information sharing

[5] Apple Hide My Email bug reportedly exposes real email addresses

[6] Governance AI study on EU data protection rules and LLM releases


*These articles were not written by EDPO. The opinions and views of the author(s) do not necessarily represent those of EDPO.

 

 

About the author

Sérgio Abreu

Sérgio studied International and European Law at Nova University in Lisbon. In his master’s thesis he delved into the impact of facial recognition technologies in Data Protection and Privacy in the EU. He’s CIPP/E certified. Sérgio studied and worked in multiple European cities, including Coimbra, Lisbon, Ljubljana, Brussels and Luxembourg. Sérgio was a Blue Book Trainee at the European Commission’s Data Policy and Innovation Unit, where he was involved in the preparatory work surrounding the Data Act. He also worked at a financial tech company and as a trainee at the Portuguese Competition Authority and at the Portuguese Embassy in Brussels. Sérgio is fluent in Portuguese and English and has an intermediate level in Spanish and French.

Sérgio Abreu

Get our weekly newsletter in your inbox every Monday with fresh GDPR and Data Protection news!