In case you missed it – EDPO weekly recap | 27 – 31 July 2026

flashback - 6-12 June 2026

 

Here is a brief recap of the news and updates we shared last week.

MEPs approved the extension of “Chat Control 1.0” until April 2028, allowing platforms to continue voluntarily scanning private digital messages and emails for child sexual abuse material. [1]

Anthropic’s Claude shared chats reportedly appeared in Google Search results, making some public conversations discoverable online. [2]

AI security remained in focus after reports that OpenAI models breached Hugging Face’s systems during testing and were active online for several days. Anthropic also disclosed that some Claude models accessed three companies during cybersecurity tests. [3] [4] [7]

noyb filed a GDPR complaint against dict.cc, alleging that users were nudged into consenting to tracking by 1,741 partners with one click. [5]

A BBC report highlighted Mozilla Foundation research into period tracking apps, finding that some share users’ health data with third parties. [6]

The European Commission announced that AI Act enforcement and new transparency requirements will apply from 2 August 2026. [8]

References:

[1] Euronews: What is the EU’s “Chat Control”?

[2] Cyber Security News: Claude AI Shared Chats Reportedly Exposed in Google Search Results

[3] TechCrunch: OpenAI’s Hugging Face breach has reignited the debate over alignment and control

[4] Politico: OpenAI’s rogue models roamed the internet for 4 days and staged a second attack

[5] noyb: 1,741 “informed” consents with one click?! GDPR complaint against dict.cc filed

[6] BBC: How period trackers share your private details

[7] Reuters: Anthropic’s AI hacked three companies during tests

[8] European Commission: Commission starts enforcing AI Act rules and new transparency requirements on 2 August

*These articles were not written by EDPO. The opinions and views of the author(s) do not necessarily represent those of EDPO.

 

 

About the author

Sérgio Abreu

Sérgio studied International and European Law at Nova University in Lisbon. In his master’s thesis he delved into the impact of facial recognition technologies in Data Protection and Privacy in the EU. He’s CIPP/E certified. Sérgio studied and worked in multiple European cities, including Coimbra, Lisbon, Ljubljana, Brussels and Luxembourg. Sérgio was a Blue Book Trainee at the European Commission’s Data Policy and Innovation Unit, where he was involved in the preparatory work surrounding the Data Act. He also worked at a financial tech company and as a trainee at the Portuguese Competition Authority and at the Portuguese Embassy in Brussels. Sérgio is fluent in Portuguese and English and has an intermediate level in Spanish and French.

Sérgio Abreu

Get our weekly newsletter in your inbox every Monday with fresh GDPR and Data Protection news!