[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f2NlYWcfYMFM0FEiXs4SNxaS0yl1LtByzZzDLhSzQB_c":3,"$fDuOfbrGklFg9DNstLQj01v77JKgm8YTNP3W1V3nd5U4":82,"faq-section-":235,"white_papers":236},{"tableOfContents":4,"markDownContent":5,"htmlContent":6,"metaTitle":7,"metaDescription":8,"wordCount":9,"readTime":10,"title":11,"nbDownloads":12,"excerpt":13,"lang":14,"url":15,"intro":16,"featured":17,"state":18,"author":19,"authorId":20,"datePublication":24,"dateCreation":25,"dateUpdate":26,"mainCategory":27,"categories":43,"metaDatas":71,"imageUrl":72,"imageThumbUrls":73,"id":81},true,"You’re tired of generic newsletters that barely scratch the surface of your real challenges? Dastra brings you **Dastra Insights**, a legal and regulatory watch **specially designed for DPOs, legal professionals, and Privacy and AI practitioners**.\n\n🎯 **Targeted, practical monitoring grounded in the day-to-day realities of data protection and AI.**\n\nHere is our selection for **August 2026**:\n\n## \\[AI Act\\] Entry into force of transparency obligations\n\n**Date**: 2 August 2026\\\n**Source**: [European Commission](https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august)\n\nSince 2 August, the European Commission’s AI Office and the competent national authorities may exercise the supervisory powers provided for under the EU AI Act. The transparency obligations applicable to certain AI systems have also entered into force.\n\nProviders of interactive systems, including chatbots, must inform users that they are interacting with AI. Artificially generated or manipulated content must include machine-detectable labeling, while deepfakes and certain public-interest content must be clearly flagged. The Commission has also rolled out complaint and reporting channels.\n\n## \\[AI Act – Enforcement\\] The European Commission launches a complaints tool\n\n**Date**: 2 August 2026 – official page updated on 31 July 2026\\\n**Source**: [European Commission – AI Act complaints handling tool](https://digital-strategy.ec.europa.eu/fr/policies/ai-act-complaints-tool)\n\nThe European Commission has made available a tool allowing natural and legal persons to refer alleged breaches of the AI Act committed by providers or deployers of systems falling within its exclusive competence to the European AI Office.\n\nBased on Article 85 of the Regulation, the mechanism accepts complaints in all official EU languages and allows supporting documents to be attached, but it is not anonymous: complainants must provide their identity, contact details, the country where the incident occurred, and a detailed description of the facts.\n\nThe AI Office handles reports confidentially and may, with the complainant’s prior consent, forward them to the national market surveillance authority or another competent authority. Complaints relating to obligations applicable to general-purpose AI models, in particular those under Articles 53 to 55, are subject to a separate channel.\n\n## \\[Automated decisions\\] Nearly €825 million fine against Uber\n\n**Date**: 21 August 2026 – CNIL publication on 24 August\\\n**Source**: [CNIL, in cooperation with the Dutch authority](https://www.cnil.fr/fr/decisions-automatisees-sanction-de-pres-de-825-millions-deuros-lencontre-duber)\n\nThe Dutch data protection authority imposed a **€824,990,000** fine on Uber B.V. and Uber Technologies Inc. for fully automated individual decisions concerning platform drivers.\n\nTemporary or permanent account deactivations, triggered in particular by suspected fraud or low ratings, were found to be automated decisions producing significant effects, due to the absence of human intervention in the process. The case originated from a collective complaint filed with the CNIL on behalf of more than 170 drivers and illustrates the operation of the EU one-stop-shop mechanism.\n\n## \\[Case law – UK\\] TikTok appeal dismissed over “special purposes”\n\n**Date**: 5 August 2026\\\n**Sources**: [Upper Tribunal – full decision](https://caselaw.nationalarchives.gov.uk/ukut/aac/2026/277) and [ICO press release](https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/08/ico-statement-on-upper-tribunal-decision/)\n\nThe Upper Tribunal dismissed TikTok’s appeal on a preliminary issue relating to the **£12.7 million** fine imposed in 2023 for the processing of data of children under 13. TikTok argued that certain processing activities fell within journalistic, artistic, academic, or literary purposes, which benefit from specific procedural safeguards under the Data Protection Act 2018.\n\nThe Tribunal held that it was not enough for processing to facilitate the dissemination of artistic content: the processing itself must pursue one of those special purposes. The case is referred back to the First-tier Tribunal for consideration on the merits of the other grounds challenging the sanction.\n\n## \\[GDPR governance\\] The CNIL clarifies how to manage DPO conflicts of interest\n\n**Date**: 10 August 2026\\\n**Source**: [CNIL](https://www.cnil.fr/fr/dpo-identifier-gerer-conflits-interets)\n\nThe CNIL has published a practical analysis to help identify roles that may compromise the independence of the data protection officer. Senior management roles are generally incompatible where they lead the DPO to determine the purposes or means of processing. Difficulties may also arise where a DPO also acts as CISO, anti-fraud lead, employee representative, or litigation counsel.\n\nWhere a conflict exists, the organization must address it by replacing the DPO, removing the incompatible tasks, or implementing an effective recusal mechanism. Appointing a deputy DPO remains possible, provided that the allocation of responsibilities is documented, that the deputy is given the necessary resources and independence, and that any problematic reporting line is avoided.\n\n## \\[Cybersecurity\\] ACRO reprimanded over security failings\n\n**Date**: 12 August 2026\\\n**Source**: [Information Commissioner’s Office](https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/08/acro-reprimanded-following-cyber-security-failings/)\n\nThe ICO has reprimanded the ACRO Criminal Records Office following a breach that may have affected **10,920 individuals**. The exposed data included contact details, national insurance numbers, banking information, biometric data, and data relating to offenses and other special categories of data.\n\nThe investigation found that responsibilities between ACRO and its service providers were not clearly allocated, security patch management was flawed, and alerts were not adequately monitored. The ICO action is based on Article 32 of UK GDPR and is a reminder that outsourcing cybersecurity services does not remove the organization’s responsibility.\n\n## \\[Data breach\\] DGFiP information system hacked\n\n**Date**: 18 August 2026\\\n**Source**: [CNIL](https://www.cnil.fr/fr/piratage-du-systeme-dinformation-des-impots-les-verifications-sont-en-cours)\n\nThe CNIL confirmed that it had received several notifications concerning a breach of the information system of the French Directorate-General for Public Finances. A third party may have viewed and extracted tax and property-record information relating to individuals and professionals, including reference tax income, family quotient, withholding tax rate, addresses, and information concerning real estate assets.\n\nUsernames and passwords do not appear to be affected. The DGFiP must notify the affected individuals individually. The CNIL may carry out investigations to assess whether the security measures complied with GDPR requirements and the state of the art.\n\n## \\[Biometrics\\] The ICO publishes results of its audits on police facial recognition\n\n**Date**: 18 August 2026\\\n**Source**: [Information Commissioner’s Office](https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/08/facial-recognition-in-policing/)\n\nFollowing audits carried out across five police forces in England and Wales, the ICO issued **107 recommendations** on the use of live and retrospective facial recognition. The audited forces had generally documented a lawful basis and adopted breach notification procedures, but significant gaps remained.\n\nThe recommendations cover, in particular, management oversight, training, image traceability, retention periods, the source of photographs, and assessment of risks of error or bias. The ICO says these findings are intended to guide all forces using these technologies.\n\n## \\[Generative AI\\] The Dutch authority warns Twitch users\n\n**Date**: 20 August 2026\\\n**Source**: [Autoriteit Persoonsgegevens](https://autoriteitpersoonsgegevens.nl/actueel/ap-adviseert-twitch-gebruikers-zet-instellingen-uit-voor-delen-van-data-met-amazon-ai)\n\nThe Dutch data protection authority has urged Twitch users to disable sharing their data with Amazon for the training of generative AI models. According to the authority, users’ video streams, images, voice, names, conversations, and messages may be used as training data.\n\nThe option would be enabled by default and would require an opt-out action. The authority particularly highlights the sensitivity of facial images and the difficulty of effectively removing data once it has been incorporated into AI systems.\n\n## \\[Education and cloud\\] CNIL recommendations on school collaboration tools\n\n**Date**: 24 August 2026\\\n**Source**: [CNIL](https://www.cnil.fr/fr/enseignement-premier-second-degres-bonnes-pratiques-outils-collaboratifs)\n\nThe CNIL has clarified the conditions under which schools may use digital workspaces and other online collaborative tools. Each processing operation must rely on an appropriate legal basis; in the context of public education, the public-interest mission can generally be relied on, while consent is often unsuitable because of the relationship of authority.\n\nSchools must verify providers’ safeguards, disable advertising trackers, inform pupils in age-appropriate language, and regulate transfers outside the European Union. Given the large-scale processing of data relating to minors, sometimes sensitive data, the CNIL considers that a DPIA will likely be required in most cases.","\u003Cp>You’re tired of generic newsletters that barely scratch the surface of your real challenges? Dastra brings you \u003Cstrong>Dastra Insights\u003C/strong>, a legal and regulatory watch \u003Cstrong>specially designed for DPOs, legal professionals, and Privacy and AI practitioners\u003C/strong>.\u003C/p>\n\u003Cp>🎯 \u003Cstrong>Targeted, practical monitoring grounded in the day-to-day realities of data protection and AI.\u003C/strong>\u003C/p>\n\u003Cp>Here is our selection for \u003Cstrong>August 2026\u003C/strong>:\u003C/p>\n\u003Ch2 id=\"ai-act-entry-into-force-of-transparency-obligations\">[AI Act] Entry into force of transparency obligations\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 2 August 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august\" rel=\"nofollow\">European Commission\u003C/a>\u003C/p>\n\u003Cp>Since 2 August, the European Commission’s AI Office and the competent national authorities may exercise the supervisory powers provided for under the EU AI Act. The transparency obligations applicable to certain AI systems have also entered into force.\u003C/p>\n\u003Cp>Providers of interactive systems, including chatbots, must inform users that they are interacting with AI. Artificially generated or manipulated content must include machine-detectable labeling, while deepfakes and certain public-interest content must be clearly flagged. The Commission has also rolled out complaint and reporting channels.\u003C/p>\n\u003Ch2 id=\"ai-act-enforcement-the-european-commission-launches-a-complaints-tool\">[AI Act – Enforcement] The European Commission launches a complaints tool\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 2 August 2026 – official page updated on 31 July 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://digital-strategy.ec.europa.eu/fr/policies/ai-act-complaints-tool\" rel=\"nofollow\">European Commission – AI Act complaints handling tool\u003C/a>\u003C/p>\n\u003Cp>The European Commission has made available a tool allowing natural and legal persons to refer alleged breaches of the AI Act committed by providers or deployers of systems falling within its exclusive competence to the European AI Office.\u003C/p>\n\u003Cp>Based on Article 85 of the Regulation, the mechanism accepts complaints in all official EU languages and allows supporting documents to be attached, but it is not anonymous: complainants must provide their identity, contact details, the country where the incident occurred, and a detailed description of the facts.\u003C/p>\n\u003Cp>The AI Office handles reports confidentially and may, with the complainant’s prior consent, forward them to the national market surveillance authority or another competent authority. Complaints relating to obligations applicable to general-purpose AI models, in particular those under Articles 53 to 55, are subject to a separate channel.\u003C/p>\n\u003Ch2 id=\"automated-decisions-nearly-825-million-fine-against-uber\">[Automated decisions] Nearly €825 million fine against Uber\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 21 August 2026 – CNIL publication on 24 August\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://www.cnil.fr/fr/decisions-automatisees-sanction-de-pres-de-825-millions-deuros-lencontre-duber\" rel=\"nofollow\">CNIL, in cooperation with the Dutch authority\u003C/a>\u003C/p>\n\u003Cp>The Dutch data protection authority imposed a \u003Cstrong>€824,990,000\u003C/strong> fine on Uber B.V. and Uber Technologies Inc. for fully automated individual decisions concerning platform drivers.\u003C/p>\n\u003Cp>Temporary or permanent account deactivations, triggered in particular by suspected fraud or low ratings, were found to be automated decisions producing significant effects, due to the absence of human intervention in the process. The case originated from a collective complaint filed with the CNIL on behalf of more than 170 drivers and illustrates the operation of the EU one-stop-shop mechanism.\u003C/p>\n\u003Ch2 id=\"case-law-uk-tiktok-appeal-dismissed-over-special-purposes\">[Case law – UK] TikTok appeal dismissed over “special purposes”\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 5 August 2026\u003Cbr />\n\u003Cstrong>Sources\u003C/strong>: \u003Ca href=\"https://caselaw.nationalarchives.gov.uk/ukut/aac/2026/277\" rel=\"nofollow\">Upper Tribunal – full decision\u003C/a> and \u003Ca href=\"https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/08/ico-statement-on-upper-tribunal-decision/\" rel=\"nofollow\">ICO press release\u003C/a>\u003C/p>\n\u003Cp>The Upper Tribunal dismissed TikTok’s appeal on a preliminary issue relating to the \u003Cstrong>£12.7 million\u003C/strong> fine imposed in 2023 for the processing of data of children under 13. TikTok argued that certain processing activities fell within journalistic, artistic, academic, or literary purposes, which benefit from specific procedural safeguards under the Data Protection Act 2018.\u003C/p>\n\u003Cp>The Tribunal held that it was not enough for processing to facilitate the dissemination of artistic content: the processing itself must pursue one of those special purposes. The case is referred back to the First-tier Tribunal for consideration on the merits of the other grounds challenging the sanction.\u003C/p>\n\u003Ch2 id=\"gdpr-governance-the-cnil-clarifies-how-to-manage-dpo-conflicts-of-interest\">[GDPR governance] The CNIL clarifies how to manage DPO conflicts of interest\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 10 August 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://www.cnil.fr/fr/dpo-identifier-gerer-conflits-interets\" rel=\"nofollow\">CNIL\u003C/a>\u003C/p>\n\u003Cp>The CNIL has published a practical analysis to help identify roles that may compromise the independence of the data protection officer. Senior management roles are generally incompatible where they lead the DPO to determine the purposes or means of processing. Difficulties may also arise where a DPO also acts as CISO, anti-fraud lead, employee representative, or litigation counsel.\u003C/p>\n\u003Cp>Where a conflict exists, the organization must address it by replacing the DPO, removing the incompatible tasks, or implementing an effective recusal mechanism. Appointing a deputy DPO remains possible, provided that the allocation of responsibilities is documented, that the deputy is given the necessary resources and independence, and that any problematic reporting line is avoided.\u003C/p>\n\u003Ch2 id=\"cybersecurity-acro-reprimanded-over-security-failings\">[Cybersecurity] ACRO reprimanded over security failings\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 12 August 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/08/acro-reprimanded-following-cyber-security-failings/\" rel=\"nofollow\">Information Commissioner’s Office\u003C/a>\u003C/p>\n\u003Cp>The ICO has reprimanded the ACRO Criminal Records Office following a breach that may have affected \u003Cstrong>10,920 individuals\u003C/strong>. The exposed data included contact details, national insurance numbers, banking information, biometric data, and data relating to offenses and other special categories of data.\u003C/p>\n\u003Cp>The investigation found that responsibilities between ACRO and its service providers were not clearly allocated, security patch management was flawed, and alerts were not adequately monitored. The ICO action is based on Article 32 of UK GDPR and is a reminder that outsourcing cybersecurity services does not remove the organization’s responsibility.\u003C/p>\n\u003Ch2 id=\"data-breach-dgfip-information-system-hacked\">[Data breach] DGFiP information system hacked\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 18 August 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://www.cnil.fr/fr/piratage-du-systeme-dinformation-des-impots-les-verifications-sont-en-cours\" rel=\"nofollow\">CNIL\u003C/a>\u003C/p>\n\u003Cp>The CNIL confirmed that it had received several notifications concerning a breach of the information system of the French Directorate-General for Public Finances. A third party may have viewed and extracted tax and property-record information relating to individuals and professionals, including reference tax income, family quotient, withholding tax rate, addresses, and information concerning real estate assets.\u003C/p>\n\u003Cp>Usernames and passwords do not appear to be affected. The DGFiP must notify the affected individuals individually. The CNIL may carry out investigations to assess whether the security measures complied with GDPR requirements and the state of the art.\u003C/p>\n\u003Ch2 id=\"biometrics-the-ico-publishes-results-of-its-audits-on-police-facial-recognition\">[Biometrics] The ICO publishes results of its audits on police facial recognition\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 18 August 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/08/facial-recognition-in-policing/\" rel=\"nofollow\">Information Commissioner’s Office\u003C/a>\u003C/p>\n\u003Cp>Following audits carried out across five police forces in England and Wales, the ICO issued \u003Cstrong>107 recommendations\u003C/strong> on the use of live and retrospective facial recognition. The audited forces had generally documented a lawful basis and adopted breach notification procedures, but significant gaps remained.\u003C/p>\n\u003Cp>The recommendations cover, in particular, management oversight, training, image traceability, retention periods, the source of photographs, and assessment of risks of error or bias. The ICO says these findings are intended to guide all forces using these technologies.\u003C/p>\n\u003Ch2 id=\"generative-ai-the-dutch-authority-warns-twitch-users\">[Generative AI] The Dutch authority warns Twitch users\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 20 August 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://autoriteitpersoonsgegevens.nl/actueel/ap-adviseert-twitch-gebruikers-zet-instellingen-uit-voor-delen-van-data-met-amazon-ai\" rel=\"nofollow\">Autoriteit Persoonsgegevens\u003C/a>\u003C/p>\n\u003Cp>The Dutch data protection authority has urged Twitch users to disable sharing their data with Amazon for the training of generative AI models. According to the authority, users’ video streams, images, voice, names, conversations, and messages may be used as training data.\u003C/p>\n\u003Cp>The option would be enabled by default and would require an opt-out action. The authority particularly highlights the sensitivity of facial images and the difficulty of effectively removing data once it has been incorporated into AI systems.\u003C/p>\n\u003Ch2 id=\"education-and-cloud-cnil-recommendations-on-school-collaboration-tools\">[Education and cloud] CNIL recommendations on school collaboration tools\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 24 August 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://www.cnil.fr/fr/enseignement-premier-second-degres-bonnes-pratiques-outils-collaboratifs\" rel=\"nofollow\">CNIL\u003C/a>\u003C/p>\n\u003Cp>The CNIL has clarified the conditions under which schools may use digital workspaces and other online collaborative tools. Each processing operation must rely on an appropriate legal basis; in the context of public education, the public-interest mission can generally be relied on, while consent is often unsuitable because of the relationship of authority.\u003C/p>\n\u003Cp>Schools must verify providers’ safeguards, disable advertising trackers, inform pupils in age-appropriate language, and regulate transfers outside the European Union. Given the large-scale processing of data relating to minors, sometimes sensitive data, the CNIL considers that a DPIA will likely be required in most cases.\u003C/p>\n","Dastra Insights Privacy & AI: what happened in August?","A legal and regulatory watch specially designed for DPOs, legal professionals, and Privacy and AI experts.",1298,7,"Dastra Insights: What happened in August in Privacy and AI?",0,null,"en","dastra-insights-what-happened-in-august-in-privacy-and-ai","A legal and regulatory watch service specially designed for DPOs, in-house lawyers, and Privacy and AI professionals.",false,"Published",{"id":20,"displayName":21,"avatarUrl":22,"bio":13,"blogUrl":13,"color":13,"userId":20,"creationDate":23},20352,"Leïla Sayssa","https://static.dastra.eu/tenant-3/avatar/20352/TDYeY3C8Rz1lLE/dpo-avatar-h01-150.png","2025-03-03T11:08:22","2026-08-31T08:00:00","2026-08-25T13:50:29.6245462","2026-08-31T10:27:50.8967419",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":33},2,"Blog","A list of curated articles provided by the community","blog","#28449a",[34,37,40],{"lang":35,"name":29,"description":36},"fr","Une liste d'articles rédigés par la communauté",{"lang":38,"name":29,"description":39},"es","Una lista de artículos escritos por la comunidad",{"lang":41,"name":29,"description":42},"de","Eine Liste von Artikeln, die von der Community verfasst wurden",[44,49],{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":45},[46,47,48],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},{"id":50,"name":51,"description":52,"url":53,"color":54,"parentId":28,"count":13,"imageUrl":13,"parent":55,"order":60,"translations":61},9,"News","Stay up to date with the latest news from data protection authorities: decisions, fines, guidelines, and regulatory trends in GDPR and privacy.","news","#1676ca",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":56},[57,58,59],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},4,[62,65,68],{"lang":35,"name":63,"description":64},"Actualités","Suivez les dernières actualités des autorités de protection des données (CNIL, EDPS, etc.) : décisions, sanctions, lignes directrices et tendances réglementaires en matière de RGPD et de privacy.",{"lang":38,"name":66,"description":67},"Actualidad","Todos los artículos relativos a las autoridades de protección de datos",{"lang":41,"name":69,"description":70},"Nachrichten","Alle Artikel mit Bezug zu Datenschutzbehörden",[],"https://static.dastra.eu/content/1fed04ca-537d-47fe-ad5a-c7fb8c4139b0/dastractu-original.jpg",[74,75,76,77,78,79,80],"https://static.dastra.eu/content/1fed04ca-537d-47fe-ad5a-c7fb8c4139b0/dastractu-1000.webp","https://static.dastra.eu/content/1fed04ca-537d-47fe-ad5a-c7fb8c4139b0/dastractu.webp","https://static.dastra.eu/content/1fed04ca-537d-47fe-ad5a-c7fb8c4139b0/dastractu-1500.webp","https://static.dastra.eu/content/1fed04ca-537d-47fe-ad5a-c7fb8c4139b0/dastractu-800.webp","https://static.dastra.eu/content/1fed04ca-537d-47fe-ad5a-c7fb8c4139b0/dastractu-600.webp","https://static.dastra.eu/content/1fed04ca-537d-47fe-ad5a-c7fb8c4139b0/dastractu-300.webp","https://static.dastra.eu/content/1fed04ca-537d-47fe-ad5a-c7fb8c4139b0/dastractu-100.webp",60512,{"total":83,"items":84,"parent":230},8,[85,106,126,147,169,179,197,213],{"id":86,"name":87,"description":88,"url":89,"color":90,"parentId":28,"count":13,"imageUrl":13,"parent":91,"order":83,"translations":96},20,"Inside Dastra","Go behind the scenes at Dastra: company news, culture, events, team highlights, and the people driving our GDPR solution.","dastra-life","#e3cf68",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":92},[93,94,95],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},[97,100,103],{"lang":35,"name":98,"description":99},"Vie de Dastra","Plongez dans les coulisses de Dastra : actualités internes, culture d’entreprise, événements, équipes et engagements. Découvrez qui se cache derrière notre solution RGPD.",{"lang":41,"name":101,"description":102},"Innerhalb von Dastra","Eintauchen in das Unternehmen",{"lang":38,"name":104,"description":105},"Dentro de Dastra","Sumérjase en la empresa",{"id":107,"name":108,"description":109,"url":110,"color":111,"parentId":28,"count":13,"imageUrl":13,"parent":112,"order":10,"translations":117},69,"Expertise","Gain insights from our experts on GDPR compliance, data protection, and privacy challenges. In-depth articles, professional analysis, and real-world best practices.","indepth","#000000",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":113},[114,115,116],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},[118,120,123],{"lang":35,"name":108,"description":119},"Bénéficiez des conseils de nos experts sur la conformité RGPD, la protection des données et les enjeux privacy. Articles de fond, analyses et retours d’expérience métier.",{"lang":41,"name":121,"description":122},"Fachwissen","Entdecken Sie die Artikel unserer DSGVO-Experten",{"lang":38,"name":124,"description":125},"Experiencia","Descubre los artículos de nuestros expertos en Privacy",{"id":60,"name":127,"description":128,"url":129,"color":130,"parentId":28,"count":13,"imageUrl":13,"parent":131,"order":136,"translations":137},"Use cases","Discover how companies use Dastra to manage their GDPR compliance. Testimonials, use cases, and real-world integrations of our privacy management solution.","case-studies","#b61b9c",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":132},[133,134,135],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},6,[138,141,144],{"lang":35,"name":139,"description":140},"Retours d'expérience","Découvrez comment les entreprises utilisent Dastra pour piloter leur conformité RGPD. Témoignages, cas d’usage et intégrations concrètes de notre solution de privacy management.",{"lang":41,"name":142,"description":143},"Case Studies","Entdecken Sie die Erfahrungsberichte unserer Kunden",{"lang":38,"name":145,"description":146},"Casos prácticos","Descubra los testimonios de nuestros clientes",{"id":148,"name":149,"description":150,"url":151,"color":152,"parentId":28,"count":13,"imageUrl":13,"parent":153,"order":158,"translations":159},10,"Release notes","Keep up with the latest features of Dastra: product updates, new functionalities, and improvements to our GDPR compliance and data management platform.","release","#8c316a",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":154},[155,156,157],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},5,[160,163,166],{"lang":35,"name":161,"description":162},"Notes de version","Restez informé(e) des dernières fonctionnalités de Dastra : mises à jour, évolutions produit et améliorations de notre solution de conformité RGPD et de gestion des données personnelles.",{"lang":41,"name":164,"description":165},"Veröffentlichungen","Alle Versionshinweise und Funktionen von Dastra",{"lang":38,"name":167,"description":168},"Lanzamientos","Todas las notas de la versión e información sobre las funciones de Dastra",{"id":50,"name":51,"description":52,"url":53,"color":54,"parentId":28,"count":13,"imageUrl":13,"parent":170,"order":60,"translations":175},{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":171},[172,173,174],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},[176,177,178],{"lang":35,"name":63,"description":64},{"lang":38,"name":66,"description":67},{"lang":41,"name":69,"description":70},{"id":180,"name":181,"description":182,"url":183,"color":111,"parentId":28,"count":13,"imageUrl":13,"parent":184,"order":189,"translations":190},221,"AI Governance","Best practices, regulatory frameworks and real-world insights to manage AI responsibly and in compliance with the AI Act.","ai-governance",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":185},[186,187,188],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},3,[191,194],{"lang":35,"name":192,"description":193},"Gouvernance de l'IA","Bonnes pratiques, cadres réglementaires et retours d'expérience pour piloter l'IA de façon responsable et conforme à l'AI Act.",{"lang":41,"name":195,"description":196},"KI-Governance","Best Practices, regulatorische Rahmenbedingungen und Praxiserfahrungen für einen verantwortungsvollen KI-Einsatz im Einklang mit dem AI Act.",{"id":198,"name":199,"description":200,"url":201,"color":111,"parentId":28,"count":13,"imageUrl":13,"parent":202,"order":28,"translations":207},220,"Compliance","Regulatory news, practical guides and analysis to keep your organization compliant with the GDPR and beyond.","compliance",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":203},[204,205,206],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},[208,211],{"lang":35,"name":209,"description":210},"Conformité","Actualités réglementaires, guides pratiques et analyses pour maintenir votre organisation en conformité RGPD et au-delà.",{"lang":41,"name":199,"description":212},"Regulatorische Neuigkeiten, Praxisleitfäden und Analysen, um Ihre Organisation DSGVO-konform und darüber hinaus aufzustellen.",{"id":214,"name":215,"description":216,"url":217,"color":111,"parentId":28,"count":13,"imageUrl":13,"parent":218,"order":223,"translations":224},219,"Privacy","Principles, techniques and trends in personal data protection — from privacy by design to data subject rights.","privacy",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":219},[220,221,222],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},1,[225,227],{"lang":35,"name":215,"description":226},"Principes, techniques et tendances autour de la protection des données personnelles — de la privacy by design aux droits des personnes.",{"lang":41,"name":228,"description":229},"Datenschutz","Grundsätze, Methoden und Trends zum Schutz personenbezogener Daten — von Privacy by Design bis zu Betroffenenrechten.",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":231},[232,233,234],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},[],{"items":237,"total":304,"size":223,"page":223},[238],{"title":239,"nbDownloads":189,"excerpt":240,"lang":14,"url":241,"intro":242,"featured":17,"state":18,"author":243,"authorId":244,"datePublication":248,"dateCreation":249,"dateUpdate":250,"mainCategory":251,"categories":257,"metaDatas":290,"imageUrl":294,"imageThumbUrls":295,"id":303},"AI Act Transparency Notice Template (Word Format) Compliant with Article 50","Download a Microsoft Word template for AI transparency notices compliant with Article 50 of the EU AI Act, including four ready-to-use notice variants for AI providers and deployers.","ai-act-transparency-notice-template-word-format-compliant-with-article-50","Since 2 August 2026, Article 50 of the European Artificial Intelligence Act (AI Act) has introduced transparency obligations for several categories of AI systems. AI providers and deployers must inform individuals when they interact with AI, are exposed to AI-generated content, are subject to emotion recognition or biometric categorisation, or encounter AI-generated deepfakes. To help organisations comply with these requirements, Dastra provides a free Microsoft Word template that can be adapted and integrated into your documentation, websites and user interfaces.",{"id":244,"displayName":245,"avatarUrl":246,"bio":13,"blogUrl":13,"color":13,"userId":244,"creationDate":247},38,"Paul-Emmanuel Bidault","https://static.dastra.eu/tenant-27/avatar/38/paul-emmanuel-bidault-150.jpg","2019-12-03T19:09:28","2026-08-06T12:40:00","2026-08-06T12:40:04.9054724","2026-08-06T12:59:59.293083",{"id":252,"name":253,"description":13,"url":254,"color":255,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":189,"translations":256},70,"Livre blanc","white-papers","#1795d3",[],[258,263,268,270,278,286],{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":259},[260,261,262],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},{"id":264,"name":265,"description":13,"url":266,"color":111,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":136,"translations":267},48,"Ressources","resources",[],{"id":252,"name":253,"description":13,"url":254,"color":255,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":189,"translations":269},[],{"id":271,"name":272,"description":273,"url":274,"color":275,"parentId":264,"count":13,"imageUrl":276,"parent":13,"order":12,"translations":277},83,"IA","Toutes les ressources sur l'IA","intelligence-artificielle","#342d9f","https://static.dastra.eu/tag/9bce43f2-c750-4e6c-9b31-18ea1409a5ba/dalle-2024-11-25-225448-a-modern-and-sleek-square-logo-for-artificial-intellige-original.webp",[],{"id":279,"name":280,"description":281,"url":282,"color":283,"parentId":264,"count":13,"imageUrl":284,"parent":13,"order":12,"translations":285},92,"Artificial intelligence","Key ressources for AI","ai-ressources","#0f1cd7","https://static.dastra.eu/tag/3cf3f039-04ed-4b3a-b386-a99b43cb4e64/ai-act-bis-original.png",[],{"id":180,"name":181,"description":182,"url":183,"color":111,"parentId":28,"count":13,"imageUrl":13,"parent":13,"order":189,"translations":287},[288,289],{"lang":35,"name":192,"description":193},{"lang":41,"name":195,"description":196},[291],{"typeMetaDataId":60,"value":292,"id":293},"https://static.dastra.eu/backofficefilescontainer/875e1e54-f479-43ff-9572-c4add516b85c/Dastra-AI-transparency-notice-template-art50-EN.docx",117744,"https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-original.png",[296,297,298,299,300,301,302],"https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-1000.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-1500.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-800.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-600.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-300.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-100.webp",60275,14]