Data protection enforcement trends, AI regulation developments, supply chain due diligence guidance, and cross-border transfer analysis from the Priventia team.
The EU AI Act introduces a four-tier risk classification system for AI systems. This article explains the tiers, the Annex III high-risk categories, and the compliance obligations that apply to each.
A DPIA is only as defensible as its methodology. This article examines the EDPB guidelines on DPIAs, the nine criteria for mandatory assessments, and the structure regulators expect.
A Dutch court has found Lidl Nederland and the producer of the sandals liable for copyright infringement over lookalike Birkenstock sandals, protecting one element of the sole unit and one of the Madrid upper while holding the anatomically dictated features unprotected. The lesson reaches beyond footwear: copyright risk can sit inside functional design, and IP governance has to begin with provenance long before litigation.
Revolut’s 2026 data breach shows why an official government email address is not enough. We examine GDPR, UK data-protection and cross-border rules for verifying and responding to law-enforcement requisitions.
Article 5(2) GDPR is not satisfied by holding documentation. It requires you to be able to demonstrate compliance, and the practical difference between those two things is assembly time. This article sets out the eight artefacts a mature programme should be able to produce for any named processing activity, and the failure mode behind each.
The Dutch data protection authority has fined Uber 824,990,000 euros over the automated deactivation of driver accounts. The enforcement lesson is not the size of the fine but the governance of automated decisions: what Article 22 GDPR requires operationally, what meaningful human intervention looks like as a control, and how the Platform Work Directive tightens the position from December 2026.
Cross-border data transfers remain one of the most complex areas of GDPR compliance. This article surveys the current state of transfer mechanisms, including SCCs, the UK IDTA, and the EU-US Data Privacy Framework.
Article 6(1)(f) GDPR permits processing on the basis of legitimate interests, but only where the processing passes a three-part test. This article explains how to conduct a properly structured LIA.
An analysis of enforcement actions under GDPR since 2018, examining the areas that attract the largest fines and what this means for compliance programme design.
The CSDDD introduces mandatory human rights and environmental due diligence obligations across value chains. This article examines the scope thresholds as amended by Directive (EU) 2026/470, the July 2029 application date, and the six-step due diligence process companies must implement.
Germany’s Supply Chain Due Diligence Act has been in force since January 2023. This article reviews early BAFA enforcement actions, common compliance gaps, and what the German experience signals for CSDDD preparedness.
The CSDDD, LkSG, and UNGPs all require organisations to establish or participate in grievance mechanisms. This article examines the effectiveness criteria under UNGP Principle 31 and how to design a complaints procedure that satisfies multiple regulatory frameworks.
The CSDDD covers both human rights and environmental impacts, but it does not treat them identically. This article examines the differences in scope, depth, and the applicable international frameworks for building a compliant due diligence programme.
Organisations training AI models on data that includes personal information, and those deploying AI systems that generate outputs referencing identifiable individuals, face overlapping GDPR and AI Act obligations that require careful analysis.
NIS2 and DORA are both in force and both imposing compliance obligations in 2026. For financial services, the relationship between the two frameworks is the central compliance design question. This article examines the scope, overlap, and design implications of each.
Kenya’s Data Protection Act 2019 is one of Africa’s most comprehensive data protection frameworks. The ODPC has moved firmly into an enforcement phase in 2026, with structured regulatory scrutiny and increasing accountability.
Enforcement decisions, new guidance, and regulatory developments. No marketing. Unsubscribe at any time.