[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fe6SIe-JGu7Y-mrn4n9tJj9IrRJsMSIDofoPTNTDHN0g":3,"$fDuOfbrGklFg9DNstLQj01v77JKgm8YTNP3W1V3nd5U4":77,"white_papers":232},{"tableOfContents":4,"markDownContent":5,"htmlContent":6,"metaTitle":7,"metaDescription":8,"wordCount":9,"readTime":10,"title":7,"nbDownloads":11,"excerpt":12,"lang":13,"url":14,"intro":8,"featured":4,"state":15,"author":16,"authorId":17,"datePublication":22,"dateCreation":23,"dateUpdate":24,"mainCategory":25,"categories":41,"metaDatas":66,"imageUrl":67,"imageThumbUrls":68,"id":76},false,"*The AI Act's transparency rules are going live. Here's what actually changes.*\n\n## Context\n\nThe EU AI Act entered into force in August 2024, and its obligations have been phasing in since then: prohibited practices and AI literacy requirements from February 2025, governance rules and obligations for general-purpose AI models from August 2025. The next milestone is August 2, 2026, when Article 50 becomes applicable, which sets out transparency obligations for certain AI systems.\n\nArticle 50 **is not tied to the Act's risk-based classification.** It applies regardless of whether a system qualifies as high-risk, prohibited, or minimal-risk. Its purpose is narrower and more specific: giving people the information they need to recognize when they are dealing with AI, and when content has been artificially generated or manipulated.\n\n## What Article 50 requires\n\nTwo categories of obligations are worth distinguishing.\n\nThe first concerns **systems that interact with people**. Providers of AI systems intended to interact directly with natural persons must design them so that users are **informed** they are dealing with AI. This disclosure must be clear and made upfront, not buried in terms of service. An exception applies where it is obvious from the circumstances that AI is involved.\n\n> *For example: customer service chatbots, virtual assistants, or automated phone systems.*\n\nThe second concerns **generated or manipulated content.** \\\nProviders of systems that generate synthetic audio, image, video, or text must ensure the output is **marked** in a machine-readable format that allows it to be identified as artificially generated or manipulated. \\\nDeployers of AI systems that produce deepfakes, meaning image, audio, or video content resembling real people, places, or events, must disclose that the content has been artificially generated or manipulated.\n\n> *For example: a company using an AI-generated video of its CEO for a product announcement. The tool provider must embed a machine-readable marker in the output; the company publishing it, as deployer, must separately disclose to viewers that the footage was AI-generated, since it depicts a real person in a way that could otherwise pass as authentic.*\n\nDeployers who publish AI-generated or AI-manipulated text on matters of public interest must also disclose this, unless the content has undergone human review and a natural or legal person holds editorial responsibility for its publication.\n\nThe European Commission published a [Code of Practice on Transparency of AI-Generated Content in June 2026](https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content), covering the technical marking obligations under Article 50(2) and the deployer labelling obligations under Article 50(4).\n\nOrganizations that follow the Code can rely on it as a way to demonstrate compliance, though it remains voluntary.\n\n## What the Omnibus actually delays\n\nSince the AI Act's adoption, the Commission has proposed and, as of the Council's final approval on June 29, 2026, adopted a Digital Omnibus package intended to simplify parts of the framework. This has led to some confusion about what is and is not postponed ahead of August 2.\n\nThe most significant change concerns high-risk AI systems under Annex III. Obligations tied to that classification, including conformity assessments and related documentation, have been pushed from August 2026 to December 2, 2027. Same goes for the obligations pertaining to high-risk AI systems under Annex I who have been pushed to August 2028.\n\nArticle 50's **general transparency obligations are a separate set of rules and are not covered by that deferral, with one exception described below.** The disclosure obligations for AI systems interacting with people, and for deployers labelling deepfakes or public-interest text, apply as scheduled from August 2, 2026.\n\nThe one exception set by Omnibus on AI, is a grace period for the technical watermarking measures under Article 50(2), which runs until 2 December 2026, and applies only to generative AI systems already on the market before August 2026. This grace period does not extend to systems placed on the market on or after August 2, 2026, and it does not affect the deployer-facing obligations under Article 50(4), such as deepfake labelling or disclosure of AI-generated public-interest text.\n\n> Organizations should treat this as a limited transitional accommodation rather than a general postponement of Article 50.\n\n## What organizations should be doing now\n\n**Legal, compliance, and product teams have a few weeks left to close any gaps.**\n\nA practical starting point is an **inventory of AI systems** that interact with users or generate content on the organization's behalf: chatbots, virtual assistants, voice systems, image or video generation tools, and any generative AI used for text published externally.\n\nFor each system, **the relevant question is which Article 50 obligation applies and who is responsible for meeting it, provider or deployer**, since the two roles carry different duties.\n\n- For user-facing systems, this typically means adding a clear, upfront disclosure at the point of interaction.\n- For generated content, it means confirming whether machine-readable marking is technically in place, and if not, whether the system qualifies for the transitional grace period or needs to comply by August 2.\n- For any AI-generated text published on matters of public interest, organizations should establish and document a human review and editorial responsibility process if they intend to rely on that exemption, since the burden will be on the organization to show the review took place.\n\n**Vendor and contractual review is also worth prioritizing.** Many organizations deploy AI systems built by third-party providers, and deployer obligations under Article 50 sit with the organization using the system, not necessarily the one that built it. **Contracts and technical documentation should confirm** what marking or disclosure capabilities the provider has built in, and what remains the deployer's responsibility to implement.\n\nFinally, given the penalties involved, up to €15 million or 3% of total worldwide annual turnover, whichever is higher, **this is a reasonable moment for governance and compliance functions to confirm ownership of Article 50 compliance internally** and to brief leadership on what has changed, what has not, and what remains to be done before August 2.","\u003Cp>\u003Cem>The AI Act's transparency rules are going live. Here's what actually changes.\u003C/em>\u003C/p>\n\u003Ch2 id=\"context\">Context\u003C/h2>\n\u003Cp>The EU AI Act entered into force in August 2024, and its obligations have been phasing in since then: prohibited practices and AI literacy requirements from February 2025, governance rules and obligations for general-purpose AI models from August 2025. The next milestone is August 2, 2026, when Article 50 becomes applicable, which sets out transparency obligations for certain AI systems.\u003C/p>\n\u003Cp>Article 50 \u003Cstrong>is not tied to the Act's risk-based classification.\u003C/strong> It applies regardless of whether a system qualifies as high-risk, prohibited, or minimal-risk. Its purpose is narrower and more specific: giving people the information they need to recognize when they are dealing with AI, and when content has been artificially generated or manipulated.\u003C/p>\n\u003Ch2 id=\"what-article-50-requires\">What Article 50 requires\u003C/h2>\n\u003Cp>Two categories of obligations are worth distinguishing.\u003C/p>\n\u003Cp>The first concerns \u003Cstrong>systems that interact with people\u003C/strong>. Providers of AI systems intended to interact directly with natural persons must design them so that users are \u003Cstrong>informed\u003C/strong> they are dealing with AI. This disclosure must be clear and made upfront, not buried in terms of service. An exception applies where it is obvious from the circumstances that AI is involved.\u003C/p>\n\u003Cblockquote>\n\u003Cp>\u003Cem>For example: customer service chatbots, virtual assistants, or automated phone systems.\u003C/em>\u003C/p>\n\u003C/blockquote>\n\u003Cp>The second concerns \u003Cstrong>generated or manipulated content.\u003C/strong> \u003Cbr />\nProviders of systems that generate synthetic audio, image, video, or text must ensure the output is \u003Cstrong>marked\u003C/strong> in a machine-readable format that allows it to be identified as artificially generated or manipulated. \u003Cbr />\nDeployers of AI systems that produce deepfakes, meaning image, audio, or video content resembling real people, places, or events, must disclose that the content has been artificially generated or manipulated.\u003C/p>\n\u003Cblockquote>\n\u003Cp>\u003Cem>For example: a company using an AI-generated video of its CEO for a product announcement. The tool provider must embed a machine-readable marker in the output; the company publishing it, as deployer, must separately disclose to viewers that the footage was AI-generated, since it depicts a real person in a way that could otherwise pass as authentic.\u003C/em>\u003C/p>\n\u003C/blockquote>\n\u003Cp>Deployers who publish AI-generated or AI-manipulated text on matters of public interest must also disclose this, unless the content has undergone human review and a natural or legal person holds editorial responsibility for its publication.\u003C/p>\n\u003Cp>The European Commission published a \u003Ca href=\"https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content\" rel=\"nofollow\">Code of Practice on Transparency of AI-Generated Content in June 2026\u003C/a>, covering the technical marking obligations under Article 50(2) and the deployer labelling obligations under Article 50(4).\u003C/p>\n\u003Cp>Organizations that follow the Code can rely on it as a way to demonstrate compliance, though it remains voluntary.\u003C/p>\n\u003Ch2 id=\"what-the-omnibus-actually-delays\">What the Omnibus actually delays\u003C/h2>\n\u003Cp>Since the AI Act's adoption, the Commission has proposed and, as of the Council's final approval on June 29, 2026, adopted a Digital Omnibus package intended to simplify parts of the framework. This has led to some confusion about what is and is not postponed ahead of August 2.\u003C/p>\n\u003Cp>The most significant change concerns high-risk AI systems under Annex III. Obligations tied to that classification, including conformity assessments and related documentation, have been pushed from August 2026 to December 2, 2027. Same goes for the obligations pertaining to high-risk AI systems under Annex I who have been pushed to August 2028.\u003C/p>\n\u003Cp>Article 50's \u003Cstrong>general transparency obligations are a separate set of rules and are not covered by that deferral, with one exception described below.\u003C/strong> The disclosure obligations for AI systems interacting with people, and for deployers labelling deepfakes or public-interest text, apply as scheduled from August 2, 2026.\u003C/p>\n\u003Cp>The one exception set by Omnibus on AI, is a grace period for the technical watermarking measures under Article 50(2), which runs until 2 December 2026, and applies only to generative AI systems already on the market before August 2026. This grace period does not extend to systems placed on the market on or after August 2, 2026, and it does not affect the deployer-facing obligations under Article 50(4), such as deepfake labelling or disclosure of AI-generated public-interest text.\u003C/p>\n\u003Cblockquote>\n\u003Cp>Organizations should treat this as a limited transitional accommodation rather than a general postponement of Article 50.\u003C/p>\n\u003C/blockquote>\n\u003Ch2 id=\"what-organizations-should-be-doing-now\">What organizations should be doing now\u003C/h2>\n\u003Cp>\u003Cstrong>Legal, compliance, and product teams have a few weeks left to close any gaps.\u003C/strong>\u003C/p>\n\u003Cp>A practical starting point is an \u003Cstrong>inventory of AI systems\u003C/strong> that interact with users or generate content on the organization's behalf: chatbots, virtual assistants, voice systems, image or video generation tools, and any generative AI used for text published externally.\u003C/p>\n\u003Cp>For each system, \u003Cstrong>the relevant question is which Article 50 obligation applies and who is responsible for meeting it, provider or deployer\u003C/strong>, since the two roles carry different duties.\u003C/p>\n\u003Cul>\n\u003Cli>For user-facing systems, this typically means adding a clear, upfront disclosure at the point of interaction.\u003C/li>\n\u003Cli>For generated content, it means confirming whether machine-readable marking is technically in place, and if not, whether the system qualifies for the transitional grace period or needs to comply by August 2.\u003C/li>\n\u003Cli>For any AI-generated text published on matters of public interest, organizations should establish and document a human review and editorial responsibility process if they intend to rely on that exemption, since the burden will be on the organization to show the review took place.\u003C/li>\n\u003C/ul>\n\u003Cp>\u003Cstrong>Vendor and contractual review is also worth prioritizing.\u003C/strong> Many organizations deploy AI systems built by third-party providers, and deployer obligations under Article 50 sit with the organization using the system, not necessarily the one that built it. \u003Cstrong>Contracts and technical documentation should confirm\u003C/strong> what marking or disclosure capabilities the provider has built in, and what remains the deployer's responsibility to implement.\u003C/p>\n\u003Cp>Finally, given the penalties involved, up to €15 million or 3% of total worldwide annual turnover, whichever is higher, \u003Cstrong>this is a reasonable moment for governance and compliance functions to confirm ownership of Article 50 compliance internally\u003C/strong> and to brief leadership on what has changed, what has not, and what remains to be done before August 2.\u003C/p>\n","AI Act Transparency Rules: What Changes August 2, 2026","Article 50 goes live Aug 2, 2026. See what's delayed and what to do now.",991,6,0,"","en","ai-act-transparency-rules-what-changes-august-2-2026","Published",{"id":17,"displayName":18,"avatarUrl":19,"bio":20,"blogUrl":20,"color":20,"userId":17,"creationDate":21},20352,"Leïla Sayssa","https://static.dastra.eu/tenant-3/avatar/20352/TDYeY3C8Rz1lLE/dpo-avatar-h01-150.png",null,"2025-03-03T11:08:22","2026-07-17T08:45:00","2026-07-17T08:45:20.2441472","2026-07-17T15:43:17.596057",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":20,"count":20,"imageUrl":20,"parent":20,"order":11,"translations":31},2,"Blog","A list of curated articles provided by the community","blog","#28449a",[32,35,38],{"lang":33,"name":27,"description":34},"fr","Une liste d'articles rédigés par la communauté",{"lang":36,"name":27,"description":37},"es","Una lista de artículos escritos por la comunidad",{"lang":39,"name":27,"description":40},"de","Eine Liste von Artikeln, die von der Community verfasst wurden",[42,47],{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":20,"count":20,"imageUrl":20,"parent":20,"order":11,"translations":43},[44,45,46],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},{"id":48,"name":49,"description":50,"url":51,"color":52,"parentId":26,"count":20,"imageUrl":20,"parent":53,"order":58,"translations":59},221,"AI Governance","Best practices, regulatory frameworks and real-world insights to manage AI responsibly and in compliance with the AI Act.","ai-governance","#000000",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":20,"count":20,"imageUrl":20,"parent":20,"order":11,"translations":54},[55,56,57],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},3,[60,63],{"lang":33,"name":61,"description":62},"Gouvernance de l'IA","Bonnes pratiques, cadres réglementaires et retours d'expérience pour piloter l'IA de façon responsable et conforme à l'AI Act.",{"lang":39,"name":64,"description":65},"KI-Governance","Best Practices, regulatorische Rahmenbedingungen und Praxiserfahrungen für einen verantwortungsvollen KI-Einsatz im Einklang mit dem AI Act.",[],"https://static.dastra.eu/content/137bd945-1a3f-4dd5-b7bc-f4f0616071c2/visuel-article-6-original.jpg",[69,70,71,72,73,74,75],"https://static.dastra.eu/content/137bd945-1a3f-4dd5-b7bc-f4f0616071c2/visuel-article-6-1000.webp","https://static.dastra.eu/content/137bd945-1a3f-4dd5-b7bc-f4f0616071c2/visuel-article-6.webp","https://static.dastra.eu/content/137bd945-1a3f-4dd5-b7bc-f4f0616071c2/visuel-article-6-1500.webp","https://static.dastra.eu/content/137bd945-1a3f-4dd5-b7bc-f4f0616071c2/visuel-article-6-800.webp","https://static.dastra.eu/content/137bd945-1a3f-4dd5-b7bc-f4f0616071c2/visuel-article-6-600.webp","https://static.dastra.eu/content/137bd945-1a3f-4dd5-b7bc-f4f0616071c2/visuel-article-6-300.webp","https://static.dastra.eu/content/137bd945-1a3f-4dd5-b7bc-f4f0616071c2/visuel-article-6-100.webp",60164,{"total":78,"items":79,"parent":227},8,[80,101,121,142,164,185,194,210],{"id":81,"name":82,"description":83,"url":84,"color":85,"parentId":26,"count":20,"imageUrl":20,"parent":86,"order":78,"translations":91},20,"Inside Dastra","Go behind the scenes at Dastra: company news, culture, events, team highlights, and the people driving our GDPR solution.","dastra-life","#e3cf68",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":20,"count":20,"imageUrl":20,"parent":20,"order":11,"translations":87},[88,89,90],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},[92,95,98],{"lang":33,"name":93,"description":94},"Vie de Dastra","Plongez dans les coulisses de Dastra : actualités internes, culture d’entreprise, événements, équipes et engagements. Découvrez qui se cache derrière notre solution RGPD.",{"lang":39,"name":96,"description":97},"Innerhalb von Dastra","Eintauchen in das Unternehmen",{"lang":36,"name":99,"description":100},"Dentro de Dastra","Sumérjase en la empresa",{"id":102,"name":103,"description":104,"url":105,"color":52,"parentId":26,"count":20,"imageUrl":20,"parent":106,"order":111,"translations":112},69,"Expertise","Gain insights from our experts on GDPR compliance, data protection, and privacy challenges. In-depth articles, professional analysis, and real-world best practices.","indepth",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":20,"count":20,"imageUrl":20,"parent":20,"order":11,"translations":107},[108,109,110],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},7,[113,115,118],{"lang":33,"name":103,"description":114},"Bénéficiez des conseils de nos experts sur la conformité RGPD, la protection des données et les enjeux privacy. Articles de fond, analyses et retours d’expérience métier.",{"lang":39,"name":116,"description":117},"Fachwissen","Entdecken Sie die Artikel unserer DSGVO-Experten",{"lang":36,"name":119,"description":120},"Experiencia","Descubre los artículos de nuestros expertos en Privacy",{"id":122,"name":123,"description":124,"url":125,"color":126,"parentId":26,"count":20,"imageUrl":20,"parent":127,"order":10,"translations":132},4,"Use cases","Discover how companies use Dastra to manage their GDPR compliance. Testimonials, use cases, and real-world integrations of our privacy management solution.","case-studies","#b61b9c",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":20,"count":20,"imageUrl":20,"parent":20,"order":11,"translations":128},[129,130,131],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},[133,136,139],{"lang":33,"name":134,"description":135},"Retours d'expérience","Découvrez comment les entreprises utilisent Dastra pour piloter leur conformité RGPD. Témoignages, cas d’usage et intégrations concrètes de notre solution de privacy management.",{"lang":39,"name":137,"description":138},"Case Studies","Entdecken Sie die Erfahrungsberichte unserer Kunden",{"lang":36,"name":140,"description":141},"Casos prácticos","Descubra los testimonios de nuestros clientes",{"id":143,"name":144,"description":145,"url":146,"color":147,"parentId":26,"count":20,"imageUrl":20,"parent":148,"order":153,"translations":154},10,"Release notes","Keep up with the latest features of Dastra: product updates, new functionalities, and improvements to our GDPR compliance and data management platform.","release","#8c316a",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":20,"count":20,"imageUrl":20,"parent":20,"order":11,"translations":149},[150,151,152],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},5,[155,158,161],{"lang":33,"name":156,"description":157},"Notes de version","Restez informé(e) des dernières fonctionnalités de Dastra : mises à jour, évolutions produit et améliorations de notre solution de conformité RGPD et de gestion des données personnelles.",{"lang":39,"name":159,"description":160},"Veröffentlichungen","Alle Versionshinweise und Funktionen von Dastra",{"lang":36,"name":162,"description":163},"Lanzamientos","Todas las notas de la versión e información sobre las funciones de Dastra",{"id":165,"name":166,"description":167,"url":168,"color":169,"parentId":26,"count":20,"imageUrl":20,"parent":170,"order":122,"translations":175},9,"News","Stay up to date with the latest news from data protection authorities: decisions, fines, guidelines, and regulatory trends in GDPR and privacy.","news","#1676ca",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":20,"count":20,"imageUrl":20,"parent":20,"order":11,"translations":171},[172,173,174],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},[176,179,182],{"lang":33,"name":177,"description":178},"Actualités","Suivez les dernières actualités des autorités de protection des données (CNIL, EDPS, etc.) : décisions, sanctions, lignes directrices et tendances réglementaires en matière de RGPD et de privacy.",{"lang":36,"name":180,"description":181},"Actualidad","Todos los artículos relativos a las autoridades de protección de datos",{"lang":39,"name":183,"description":184},"Nachrichten","Alle Artikel mit Bezug zu Datenschutzbehörden",{"id":48,"name":49,"description":50,"url":51,"color":52,"parentId":26,"count":20,"imageUrl":20,"parent":186,"order":58,"translations":191},{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":20,"count":20,"imageUrl":20,"parent":20,"order":11,"translations":187},[188,189,190],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},[192,193],{"lang":33,"name":61,"description":62},{"lang":39,"name":64,"description":65},{"id":195,"name":196,"description":197,"url":198,"color":52,"parentId":26,"count":20,"imageUrl":20,"parent":199,"order":26,"translations":204},220,"Compliance","Regulatory news, practical guides and analysis to keep your organization compliant with the GDPR and beyond.","compliance",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":20,"count":20,"imageUrl":20,"parent":20,"order":11,"translations":200},[201,202,203],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},[205,208],{"lang":33,"name":206,"description":207},"Conformité","Actualités réglementaires, guides pratiques et analyses pour maintenir votre organisation en conformité RGPD et au-delà.",{"lang":39,"name":196,"description":209},"Regulatorische Neuigkeiten, Praxisleitfäden und Analysen, um Ihre Organisation DSGVO-konform und darüber hinaus aufzustellen.",{"id":211,"name":212,"description":213,"url":214,"color":52,"parentId":26,"count":20,"imageUrl":20,"parent":215,"order":220,"translations":221},219,"Privacy","Principles, techniques and trends in personal data protection — from privacy by design to data subject rights.","privacy",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":20,"count":20,"imageUrl":20,"parent":20,"order":11,"translations":216},[217,218,219],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},1,[222,224],{"lang":33,"name":212,"description":223},"Principes, techniques et tendances autour de la protection des données personnelles — de la privacy by design aux droits des personnes.",{"lang":39,"name":225,"description":226},"Datenschutz","Grundsätze, Methoden und Trends zum Schutz personenbezogener Daten — von Privacy by Design bis zu Betroffenenrechten.",{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":20,"count":20,"imageUrl":20,"parent":20,"order":11,"translations":228},[229,230,231],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},{"items":233,"total":270,"size":220,"page":220},[234],{"title":235,"nbDownloads":165,"excerpt":20,"lang":13,"url":236,"intro":237,"featured":4,"state":15,"author":238,"authorId":17,"datePublication":239,"dateCreation":240,"dateUpdate":241,"mainCategory":242,"categories":248,"metaDatas":256,"imageUrl":260,"imageThumbUrls":261,"id":269},"Your Checklist to Multi-State Privacy Impact Assessments ","your-checklist-to-multi-state-privacy-impact-assessment-compliance","Master multi-state Privacy Impact Assessments by downloading this checklist.",{"id":17,"displayName":18,"avatarUrl":19,"bio":20,"blogUrl":20,"color":20,"userId":17,"creationDate":21},"2026-02-23T10:07:00","2026-02-23T10:07:01.6114712","2026-02-24T15:38:38.0037058",{"id":243,"name":244,"description":20,"url":245,"color":246,"parentId":20,"count":20,"imageUrl":20,"parent":20,"order":58,"translations":247},70,"Livre blanc","white-papers","#1795d3",[],[249,254],{"id":26,"name":27,"description":28,"url":29,"color":30,"parentId":20,"count":20,"imageUrl":20,"parent":20,"order":11,"translations":250},[251,252,253],{"lang":33,"name":27,"description":34},{"lang":36,"name":27,"description":37},{"lang":39,"name":27,"description":40},{"id":243,"name":244,"description":20,"url":245,"color":246,"parentId":20,"count":20,"imageUrl":20,"parent":20,"order":58,"translations":255},[],[257],{"typeMetaDataId":122,"value":258,"id":259},"https://static.dastra.eu/backofficefilescontainer/6c9c6770-09f5-44d2-ac35-466a87c40426/US PIA Cross State Checklist Best Practices.pdf",117305,"https://static.dastra.eu/content/a321130b-375a-4a3f-b9d5-e9d9afea648e/visuel-article-18-original.jpg",[262,263,264,265,266,267,268],"https://static.dastra.eu/content/a321130b-375a-4a3f-b9d5-e9d9afea648e/visuel-article-18-1000.webp","https://static.dastra.eu/content/a321130b-375a-4a3f-b9d5-e9d9afea648e/visuel-article-18.webp","https://static.dastra.eu/content/a321130b-375a-4a3f-b9d5-e9d9afea648e/visuel-article-18-1500.webp","https://static.dastra.eu/content/a321130b-375a-4a3f-b9d5-e9d9afea648e/visuel-article-18-800.webp","https://static.dastra.eu/content/a321130b-375a-4a3f-b9d5-e9d9afea648e/visuel-article-18-600.webp","https://static.dastra.eu/content/a321130b-375a-4a3f-b9d5-e9d9afea648e/visuel-article-18-300.webp","https://static.dastra.eu/content/a321130b-375a-4a3f-b9d5-e9d9afea648e/visuel-article-18-100.webp",59886,12]