In case you missed it – EDPO weekly recap | 20 – 24 July 2026

flashback - 6-12 June 2026

 

Here is a brief recap of the news and updates we shared last week.

The European Parliament revived a temporary derogation to e-Privacy rules, allowing big tech platforms to voluntarily scan private messages for child sexual abuse material until 2028, although the measures do not apply to end-to-end encrypted messages. [1]


French lawmakers approved a ban on social media access for children under 15, with the government aiming for the law to be in place by the start of the next academic year. [2]

The Spanish Data Protection Agency published guidance on data quality and the GDPR’s accuracy principle in AI processing, highlighting the importance of quality standards for both inputs and outputs where personal data is involved. [3]

The European Commission fined Google €890 million for two breaches of the Digital Markets Act, covering self-preferencing of its search services and anti-steering tactics on its Android mobile app store. [4]

The European Commission completed its first review of the 2021 adequacy decision for the Republic of Korea, confirming that the country continues to provide an adequate level of protection for personal data transferred from the EU. [5]

The Digital Omnibus on AI was published in the Official Journal of the European Union, introducing targeted amendments to the EU AI Act and setting out updated application dates for certain AI Act obligations. [6]

References:
[1] Why the EU’s so-called ‘chat control’ law has privacy experts up in arms – Euronews

[2] French lawmakers vote for social media ban for children – Reuters

[3] AEPD guidance on data quality and the GDPR accuracy principle in AI

[4] Google fined €890 million for breaching EU’s Big Tech rules – Euractiv

[5] Commission finds Republic of Korea continues to provide adequate level of protection for personal data – European Commission

[6] Digital Omnibus on AI – Official Journal of the European Union

*These articles were not written by EDPO. The opinions and views of the author(s) do not necessarily represent those of EDPO.

 

 

About the author

Sérgio Abreu

Sérgio studied International and European Law at Nova University in Lisbon. In his master’s thesis he delved into the impact of facial recognition technologies in Data Protection and Privacy in the EU. He’s CIPP/E certified. Sérgio studied and worked in multiple European cities, including Coimbra, Lisbon, Ljubljana, Brussels and Luxembourg. Sérgio was a Blue Book Trainee at the European Commission’s Data Policy and Innovation Unit, where he was involved in the preparatory work surrounding the Data Act. He also worked at a financial tech company and as a trainee at the Portuguese Competition Authority and at the Portuguese Embassy in Brussels. Sérgio is fluent in Portuguese and English and has an intermediate level in Spanish and French.

Sérgio Abreu

Get our weekly newsletter in your inbox every Monday with fresh GDPR and Data Protection news!