You’re tired of generic newsletters that barely scratch the surface of your real challenges? Dastra brings you Dastra Insights, a legal and regulatory watch specially designed for DPOs, legal professionals, and Privacy and AI practitioners.
🎯 Targeted, practical monitoring grounded in the day-to-day realities of data protection and AI.
Here is our selection for August 2026:
[AI Act] Entry into force of transparency obligations
Date: 2 August 2026
Source: European Commission
Since 2 August, the European Commission’s AI Office and the competent national authorities may exercise the supervisory powers provided for under the EU AI Act. The transparency obligations applicable to certain AI systems have also entered into force.
Providers of interactive systems, including chatbots, must inform users that they are interacting with AI. Artificially generated or manipulated content must include machine-detectable labeling, while deepfakes and certain public-interest content must be clearly flagged. The Commission has also rolled out complaint and reporting channels.
[AI Act – Enforcement] The European Commission launches a complaints tool
Date: 2 August 2026 – official page updated on 31 July 2026
Source: European Commission – AI Act complaints handling tool
The European Commission has made available a tool allowing natural and legal persons to refer alleged breaches of the AI Act committed by providers or deployers of systems falling within its exclusive competence to the European AI Office.
Based on Article 85 of the Regulation, the mechanism accepts complaints in all official EU languages and allows supporting documents to be attached, but it is not anonymous: complainants must provide their identity, contact details, the country where the incident occurred, and a detailed description of the facts.
The AI Office handles reports confidentially and may, with the complainant’s prior consent, forward them to the national market surveillance authority or another competent authority. Complaints relating to obligations applicable to general-purpose AI models, in particular those under Articles 53 to 55, are subject to a separate channel.
[Automated decisions] Nearly €825 million fine against Uber
Date: 21 August 2026 – CNIL publication on 24 August
Source: CNIL, in cooperation with the Dutch authority
The Dutch data protection authority imposed a €824,990,000 fine on Uber B.V. and Uber Technologies Inc. for fully automated individual decisions concerning platform drivers.
Temporary or permanent account deactivations, triggered in particular by suspected fraud or low ratings, were found to be automated decisions producing significant effects, due to the absence of human intervention in the process. The case originated from a collective complaint filed with the CNIL on behalf of more than 170 drivers and illustrates the operation of the EU one-stop-shop mechanism.
[Case law – UK] TikTok appeal dismissed over “special purposes”
Date: 5 August 2026
Sources: Upper Tribunal – full decision and ICO press release
The Upper Tribunal dismissed TikTok’s appeal on a preliminary issue relating to the £12.7 million fine imposed in 2023 for the processing of data of children under 13. TikTok argued that certain processing activities fell within journalistic, artistic, academic, or literary purposes, which benefit from specific procedural safeguards under the Data Protection Act 2018.
The Tribunal held that it was not enough for processing to facilitate the dissemination of artistic content: the processing itself must pursue one of those special purposes. The case is referred back to the First-tier Tribunal for consideration on the merits of the other grounds challenging the sanction.
[GDPR governance] The CNIL clarifies how to manage DPO conflicts of interest
Date: 10 August 2026
Source: CNIL
The CNIL has published a practical analysis to help identify roles that may compromise the independence of the data protection officer. Senior management roles are generally incompatible where they lead the DPO to determine the purposes or means of processing. Difficulties may also arise where a DPO also acts as CISO, anti-fraud lead, employee representative, or litigation counsel.
Where a conflict exists, the organization must address it by replacing the DPO, removing the incompatible tasks, or implementing an effective recusal mechanism. Appointing a deputy DPO remains possible, provided that the allocation of responsibilities is documented, that the deputy is given the necessary resources and independence, and that any problematic reporting line is avoided.
[Cybersecurity] ACRO reprimanded over security failings
Date: 12 August 2026
Source: Information Commissioner’s Office
The ICO has reprimanded the ACRO Criminal Records Office following a breach that may have affected 10,920 individuals. The exposed data included contact details, national insurance numbers, banking information, biometric data, and data relating to offenses and other special categories of data.
The investigation found that responsibilities between ACRO and its service providers were not clearly allocated, security patch management was flawed, and alerts were not adequately monitored. The ICO action is based on Article 32 of UK GDPR and is a reminder that outsourcing cybersecurity services does not remove the organization’s responsibility.
[Data breach] DGFiP information system hacked
Date: 18 August 2026
Source: CNIL
The CNIL confirmed that it had received several notifications concerning a breach of the information system of the French Directorate-General for Public Finances. A third party may have viewed and extracted tax and property-record information relating to individuals and professionals, including reference tax income, family quotient, withholding tax rate, addresses, and information concerning real estate assets.
Usernames and passwords do not appear to be affected. The DGFiP must notify the affected individuals individually. The CNIL may carry out investigations to assess whether the security measures complied with GDPR requirements and the state of the art.
[Biometrics] The ICO publishes results of its audits on police facial recognition
Date: 18 August 2026
Source: Information Commissioner’s Office
Following audits carried out across five police forces in England and Wales, the ICO issued 107 recommendations on the use of live and retrospective facial recognition. The audited forces had generally documented a lawful basis and adopted breach notification procedures, but significant gaps remained.
The recommendations cover, in particular, management oversight, training, image traceability, retention periods, the source of photographs, and assessment of risks of error or bias. The ICO says these findings are intended to guide all forces using these technologies.
[Generative AI] The Dutch authority warns Twitch users
Date: 20 August 2026
Source: Autoriteit Persoonsgegevens
The Dutch data protection authority has urged Twitch users to disable sharing their data with Amazon for the training of generative AI models. According to the authority, users’ video streams, images, voice, names, conversations, and messages may be used as training data.
The option would be enabled by default and would require an opt-out action. The authority particularly highlights the sensitivity of facial images and the difficulty of effectively removing data once it has been incorporated into AI systems.
[Education and cloud] CNIL recommendations on school collaboration tools
Date: 24 August 2026
Source: CNIL
The CNIL has clarified the conditions under which schools may use digital workspaces and other online collaborative tools. Each processing operation must rely on an appropriate legal basis; in the context of public education, the public-interest mission can generally be relied on, while consent is often unsuitable because of the relationship of authority.
Schools must verify providers’ safeguards, disable advertising trackers, inform pupils in age-appropriate language, and regulate transfers outside the European Union. Given the large-scale processing of data relating to minors, sometimes sensitive data, the CNIL considers that a DPIA will likely be required in most cases.
