Data protection and cybersecurity enforcement are increasingly moving from formal compliance to demonstrable effectiveness. Recent developments show regulators testing whether organisations can actually control data, respond to incidents, govern AI use and prevent unlawful tracking in practice.
This month’s RegRally focuses on developments particularly relevant to organisations that use AI, digital advertising, cloud and online services, blockchain, or process personal data at scale.
This month at a glance:
- AI: Certain high-risk AI compliance deadlines have been deferred, but AI transparency obligations remain applicable.
- AI and GDPR: The EDPB has issued guidance on anonymisation and web scraping for generative AI.
- Blockchain: The EDPB’s final guidance highlights the need to address GDPR requirements at the architecture stage.
- Cookies and tracking: European and Lithuanian regulators continue to scrutinise consent mechanisms and actual website behaviour.
- Data breaches: New EU-level reporting proposals and Lithuanian enforcement statistics underline the importance of effective incident-response processes.
- Cybersecurity: Regulators are placing increasing emphasis on continuous vulnerability management and operational resilience.
Quick Navigation
- Digital Omnibus on AI enters into force: high-risk AI deadlines deferred, but transparency duties remain
- EDPB proposes a relative approach to anonymisation
- EDPB clarifies GDPR requirements for web scraping used to train generative AI
- EDPB adopts final Guidelines on blockchain and data protection
- EDPB requires the Belgian DPA to assess the cookie-banner complaint on its merits
- EDPB’s common data breach notification template moves closer to implementation
- Belgian DPA fines IAB Europe €250,000 over Transparency & Consent Framework
- VDAI reports 140 personal data breaches in Lithuania in H1 2026
- VDAI confirms prior consent is required for non-essential cookies
- NKSC urges organisations to strengthen cyber resilience
Digital Omnibus on AI enters into force: high-risk AI deadlines deferred, but transparency duties remain
Source: European Commission | Date: 27 July 2026
Link
The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on 27 July 2026 and amended the EU AI Act.
The most significant change is the postponement of certain high-risk AI compliance deadlines:
- Annex III high-risk AI systems: 2 December 2027, instead of 2 August 2026;
- Embedded high-risk systems under Annex I: 2 August 2028, instead of 2 August 2027.
The deferral does not apply to Article 50 transparency obligations. Requirements concerning the disclosure of AI interactions, AI-generated content, and deepfakes remain applicable as of 2 August 2026. Obligations applicable to providers of general-purpose AI models also remain in force.
Why does it matter for businesses?
The additional time for certain high-risk AI requirements provides organisations with more room to implement compliance frameworks. It should not, however, be treated as a general postponement of AI governance.
Businesses need to distinguish between obligations whose application has been deferred and requirements that are already applicable. In particular, organisations deploying AI systems that interact directly with individuals should review whether their transparency measures are operational now.
Recommended actions
- Review AI systems against the revised implementation timetable.
- Prioritise Article 50 transparency requirements, including AI interaction disclosures and labelling requirements for AI-generated or manipulated content.
- Continue work on AI governance, risk classification, documentation and accountability rather than postponing implementation generally.
- Update internal AI compliance roadmaps and responsibility matrices to reflect the revised deadlines.
EDPB proposes a relative approach to anonymisation
Source: European Data Protection Board | Date: 7 July 2026
Link
The EDPB published draft Guidelines 02/2026 on anonymisation, intended to replace the former Article 29 Working Party Opinion 05/2014.
The draft takes a relative approach to identifiability. Whether data is anonymous may depend on the realistic means available to the organisation handling the data to identify individuals. As a result, the same dataset may potentially be considered personal data in one context but anonymous in another.
Why does it matter for businesses?
The assessment of anonymisation cannot be reduced to whether identifiers have been removed or whether a particular technical anonymisation method has been applied.
Organisations using data for AI development, analytics, research or data sharing may need to demonstrate why identification is not reasonably possible in their particular circumstances and what means of re-identification are realistically available.
Recommended actions
- Reassess existing anonymisation methodologies against the EDPB’s proposed risk-based approach.
- Document the realistic means available for re-identification when assessing whether data remains personal data.
- Review data-sharing and AI-data projects where the organisation currently relies on anonymisation to take the processing outside the GDPR.
- Monitor the finalisation of the Guidelines before making major changes solely on the basis of the draft.
EDPB clarifies GDPR requirements for web scraping used to train generative AI
Source: European Data Protection Board | Date: 8 July 2026
Link
What happened?
The EDPB published draft Guidelines 03/2026 on the use of web scraping to train generative AI models.
The Guidelines address the processing of personal data obtained through web scraping, including the need to consider lawful basis, purpose limitation and transparency.
The fact that information is publicly accessible does not, by itself, remove it from the scope of the GDPR.
Why does it matter for businesses?
This is particularly relevant to organisations developing AI systems, procuring AI models, or using datasets obtained from publicly accessible websites.
Public availability does not automatically mean that personal data can be collected and reused for AI training without further assessment. Organisations need to consider the original context in which information was collected and whether its proposed use for AI training is compatible with applicable data protection requirements.
Recommended actions
Organisations developing or procuring AI trained on scraped data should:
- identify and document the applicable lawful basis for collecting and using training data;
- assess compatibility between the original purpose of collection and the proposed AI-training purpose;
- review transparency measures and privacy notices covering AI-related processing;
- assess contractual and due-diligence arrangements where AI models or datasets are supplied by third parties.
EDPB adopts final Guidelines on blockchain and data protection
Source: European Data Protection Board | Date: 8 July 2026
Link
What happened?
The EDPB adopted its final Guidelines on blockchain and data protection, addressing how GDPR principles such as data minimisation, storage limitation, rectification and erasure apply to blockchain-based processing.
Why does it matter for businesses?
Blockchain architecture can create a structural tension with GDPR requirements where personal data is stored directly on-chain and cannot subsequently be modified or deleted.
The guidance reinforces the importance of addressing data protection at the design and architecture stage, rather than attempting to resolve GDPR compliance after a blockchain solution has already been implemented.
Recommended actions
Businesses using blockchain in connection with personal data should:
- avoid storing personal data directly on-chain where possible;
- assess whether personal data can instead be kept in appropriately secured off-chain systems;
- consider data minimisation and pseudonymisation before deploying the architecture;
- assess how the proposed architecture will support data-subject rights, particularly erasure and rectification.
EDPB requires the Belgian DPA to assess the cookie-banner complaint on its merits
Source: European Data Protection Board | Date: 14 July 2026
Link
The EDPB ruled that a GDPR complaint concerning cookie banners, lodged with the Belgian DPA, must be assessed on its merits, rejecting the argument that the complaint constituted an abuse of rights.
Why does it matter for businesses?
The decision reinforces that cookie compliance remains an active enforcement area.
For organisations, the question is not simply whether a cookie banner is present. Regulators and complainants can examine whether the underlying consent mechanism actually complies with GDPR requirements, including whether consent is freely given, sufficiently granular and capable of being withdrawn.
Recommended actions
Organisations using cookies and other tracking technologies should:
- test whether consent is genuinely freely given and granular;
- review cookie-banner design for interfaces that steer users towards acceptance;
- verify that non-essential tracking technologies are not activated before valid consent;
- review the configuration and actual behaviour of their consent-management platform.
EDPB’s common data breach notification template moves closer to implementation
Source: European Data Protection Board | Date: 5 August 2026
Link
What happened?
The EDPB’s draft common template for notifying personal data breaches under Article 33 GDPR was open for consultation until 5 August 2026.
The proposed template contains approximately 120 fields across seven sections, with predefined response options, and is intended to harmonise breach reporting across the EU/EEA.
Why does it matter for businesses?
A standardised reporting approach could increase consistency between national supervisory authorities, but it also places greater emphasis on an organisation’s ability to obtain accurate incident information quickly.
For businesses, the practical issue is not the template itself but whether their incident-response process can generate the required information within the GDPR’s 72-hour notification period.
Recommended actions
- Map the proposed information requirements against existing breach-response procedures.
- Identify information that cannot currently be obtained quickly during an incident.
- Clarify responsibilities between legal, IT, security, HR and management teams during a breach.
- Test whether the organisation can assess, document and escalate a personal data breach within the 72-hour timeframe.
Belgian DPA fines IAB Europe €250,000 over Transparency & Consent Framework
Source: Belgian Data Protection Authority | Date: 31 July 2026
Link
What happened?
The Belgian Data Protection Authority, acting in agreement with the other European data protection authorities involved in the procedure, imposed a €250,000 fine on IAB Europe concerning its Transparency and Consent Framework (TCF).
The Belgian DPA identified several GDPR compliance shortcomings, including issues relating to legal basis, DPO appointment, DPIA requirements and records of processing activities. IAB Europe disputes the findings and is considering a legal challenge.
Why does it matter for businesses?
The decision highlights an important distinction between using an industry-standard consent framework and demonstrating compliance with the GDPR as an individual controller.
A standardised consent signal does not necessarily resolve the organisation’s own obligations concerning lawful basis, transparency, accountability, DPIAs or records of processing. This is particularly relevant to publishers, adtech businesses, and other organisations that use consent management and advertising technology frameworks.
Recommended actions
Businesses relying on the TCF or similar industry frameworks should:
- monitor further developments, including any appeal;
- assess whether the consent signals they receive are sufficient for their specific processing activities;
- independently verify their legal basis and transparency requirements;
- review DPIA and accountability documentation where advertising or profiling activities present higher risks.
VDAI reports 140 personal data breaches in Lithuania in H1 2026
Source: State Data Protection Inspectorate (VDAI) | Date: 16 July 2026
Link
What happened?
The VDAI received 140 personal data breach notifications in Lithuania during the first half of 2026, affecting more than 1.64 million data subjects.
Cyber incidents accounted for 36% of reported breaches, while human error accounted for 48%. Reported examples included sending information to the wrong recipient, using “CC” instead of “BCC” and improperly anonymising disclosures.
The VDAI reported that 81% of controllers notified breaches within the required 72-hour period. The authority also imposed fines of €4,500 in March and €450,000 on a healthcare company in June for data security failures.
Why does it matter for businesses?
The figures demonstrate that data protection risk is not limited to sophisticated cyberattacks. Human error remains a significant source of personal data breaches.
This means that effective GDPR compliance depends not only on policies and technical security measures but also on access controls, employee practices, escalation procedures and the organisation’s ability to respond quickly when something goes wrong.
Recommended actions
Organisations should test, rather than merely document, their incident-response and security controls, with particular attention to:
- access management and encryption;
- employee handling of personal data;
- incident detection and escalation;
- internal responsibilities during a breach;
- the ability to assess and notify a reportable breach within 72 hours.
VDAI confirms prior consent is required for non-essential cookies
Source: State Data Protection Inspectorate (VDAI) | Date: 23 July 2026
Link
The VDAI reiterated that non-essential cookies, tracking pixels and similar technologies may only be used after obtaining the website visitor’s prior, freely given consent.
The authority expressly stated that legitimate interest cannot substitute for consent where prior consent is legally required.
Why does it matter for businesses?
Cookie compliance cannot be assessed solely by reviewing the wording of a cookie banner.
The actual technical behaviour of the website and consent-management platform matters. Organisations should verify whether tracking technologies are activated before consent, whether consent is properly recorded and whether users can withdraw it effectively.
Recommended actions
- Test the actual technical behaviour of websites and applications before and after consent is given.
- Verify that non-essential cookies and tracking technologies are blocked until valid consent is obtained.
- Check that consent can be withdrawn as easily as it was given.
- Review whether any processing currently relies on legitimate interest where prior consent is legally required.
NKSC urges organisations to strengthen cyber resilience
Source: National Cyber Security Centre (NKSC) | Date: 28 July 2026
Link
The NKSC highlighted the increasingly short period between the discovery of vulnerabilities and their exploitation. The authority noted that AI-assisted tools are enabling attackers to identify and exploit security weaknesses more rapidly.
Organisations are being encouraged to strengthen continuous infrastructure monitoring, vulnerability management and incident response.
Why does it matter for businesses?
The speed of exploitation makes periodic security reviews increasingly insufficient for organisations exposed to significant cyber risk.
Vulnerability management needs to operate as an ongoing process, with the ability to identify, prioritise, and remediate critical vulnerabilities before they are exploited.
Recommended actions
Organisations should assess whether:
- vulnerability monitoring is sufficiently continuous;
- critical vulnerabilities are prioritised according to actual business risk;
- patching processes can respond quickly to newly disclosed vulnerabilities;
- incident-response procedures can operate effectively alongside vulnerability management.
What businesses should take from this month’s developments
Across the EU and Lithuania, regulators are increasingly focusing on how compliance works in practice.
For businesses, the key message is not simply to update policies when new guidance or enforcement decisions are published. Organisations should be able to demonstrate that their controls work: that AI systems are appropriately governed, tracking technologies behave as intended, personal data is protected, and breaches can be assessed and reported quickly.
The same principle applies across GDPR, AI and ICT compliance: documented compliance is becoming less persuasive where operational reality tells a different story.
Need assistance?
ECOVIS ProventusLaw advises organisations on the practical implementation of data protection, AI and ICT regulatory requirements, including:
- GDPR compliance programmes and data protection governance
- AI governance and GDPR compliance for AI systems
- personal data breach assessment and incident response
- DPIAs and data protection risk assessments
- cookie and tracking technology compliance
- cybersecurity and ICT regulatory compliance
- data protection policies, procedures and accountability documentation
If you are reviewing your organisation’s GDPR, AI, or ICT compliance framework in light of recent regulatory developments, our team can help assess your current position and identify areas requiring action.
LT
RU
CN
DE