Javascript is required
logo-dastralogo-dastra

Dastra Insights: what happened in July in Privacy and AI?

Dastra Insights: what happened in July in Privacy and AI?
Leïla Sayssa
Leïla Sayssa
July 28, 2026·6 minutes read time

You’re tired of generic newsletters that barely scratch the surface of your real challenges? Dastra brings you Dastra Insights, a legal and regulatory watch specially designed for DPOs, legal professionals, and Privacy and AI practitioners.

🎯 Targeted, practical monitoring grounded in the day-to-day realities of data protection and AI.

Here is our selection for July 2026:

[AI / AI Regulation] Entry into force of the AI Omnibus

Date: 27 July 2026
Source: European Commission

The AI Omnibus entered into force in the European Union on 27 July 2026. The text amends the timeline and certain implementation modalities of the AI Act, with an explicit objective of administrative simplification and support for innovation.

Deadlines for high-risk AI systems are notably postponed: 2 December 2027 for Annex III systems and 2 August 2028 for certain systems integrated into physical products. The text also extends certain support measures to small mid-cap companies and strengthens the role of the AI Office for certain systems, notably those based on general-purpose AI models.

[AI / Transparency] Guidelines on Article 50 of the AI Regulation

Date: 20 July 2026
Source: European Commission

The European Commission published guidelines on the transparency obligations applicable to certain providers and deployers of AI systems. These obligations begin to apply on 2 August 2026.

The guidelines clarify the requirements relating to interactive systems, AI-generated or AI-manipulated content, deepfakes, as well as emotion-recognition and biometric categorisation systems. For compliance teams, this is a priority topic because it requires an operational review of interfaces, labels, machine-readable markings, and user information notices.

[Generative AI / Personal Data] EDPB on anonymisation, web scraping and blockchain

Date: 8 July 2026
Source: EDPB

The EDPB adopted guidelines on anonymisation and on web scraping in the context of generative AI, open for consultation until 30 October 2026. It also adopted the final version of its guidelines on processing based on blockchain technologies.

On anonymisation, the EDPB relies on three core criteria: no singling out, no linkage, and no inference. On scraping, it recalls that the GDPR applies where personal data are collected or reused, with particular attention to the legal basis, purpose limitation, transparency, data minimisation and special-category data.

[Agentic AI / Personal Data] CNIL-CIANum exploratory note

Date: 20 July 2026
Source: CNIL

The CNIL and the French Council for AI and Digital Affairs published an exploratory note on agentic AI and the protection of personal data. The note highlights the scale shift brought by systems capable of acting in the user’s environment, using multiple services, and retaining persistent memory.

The CNIL emphasises the risks of loss of user control, hyper-personalisation, complex data flows, and difficulty in allocating responsibilities among actors. The GDPR framework and the AI Act already apply, but their implementation must be adapted to these more autonomous architectures.

[Cookies / Trackers] Binding EDPB decision on a NOYB complaint against VRT

Date: 14 July 2026
Source: EDPB

The EDPB published a binding decision requesting the Belgian data protection authority to examine the merits of a complaint filed by NOYB concerning the cookie banners used by the Flemish public broadcaster VRT.

The practical significance lies less in the banner itself than in the procedure: the EDPB frames the possibility for an authority to reject a complaint as abusive or inadmissible, notably when brought by a representative organisation. For controllers, this confirms that coordinated cookie-related complaints remain a serious litigation lever.

[Email Trackers / Marketing] CNIL FAQ on pixels in emails

Date: 22 July 2026
Source: CNIL

The CNIL published an FAQ on its recommendation regarding pixels in email communications. It clarifies in particular the scope of application, the processing of tracking links, cases where consent is not required, and the allocation of responsibilities between senders, email service providers, technical vendors and list-rental providers.

The CNIL recalls that trackers in emails may fall both under Article 82 of the French Data Protection Act and the GDPR. It also notes that emails sent in a professional context, including to employees, are not excluded as a matter of principle.

[United Kingdom / Data Subject Rights] ICO update on the right of access

Date: 16 July 2026
Source: ICO

The ICO updated its guide on subject access requests to reflect changes introduced by the Data (Use and Access) Act 2025. The guide recalls the applicable requirements for access requests: acknowledging requests, a one-month timeframe, reasonable and proportionate searches, clear disclosure of information, and handling requests made through third parties.

For organisations operating in the UK, this update is part of the broader effort to adapt privacy policies, DSAR procedures and response templates to the new UK framework.

[AI / Minors] Italian sanction against Character AI

Date: 9 July 2026
Source: Italian Data Protection Authority

The Italian Garante sanctioned Character Technologies Inc., operator of Character.AI, in the amount of EUR 158,000 for several GDPR infringements related to a generative AI service accessible to minors.

The authority identified in particular shortcomings in information notices, a late DPIA, a late designation of the EU representative, as well as deficiencies in age-verification mechanisms and protections for minors. The company must strengthen age controls, prevent circumvention after blocking, and set minors’ profiles to private by default.

[CJEU / Judicial Data] Criminal decision databases and journalistic purpose

Date: 9 July 2026
Source: CJEU, press release No. 100/26

In case C-199/24, Legal Newsdesk Sweden, the CJEU held that the mere paid online publication of decisions relating to criminal convictions does not, in principle, constitute processing carried out for journalistic purposes within the meaning of Article 85 of the GDPR.

This decision is important for legal databases, private registers, information services and actors relying on freedom of expression or information to limit data subjects’ rights. It reminds us that national exemptions must remain within the limits of the GDPR and cannot deprive individuals of the remedies guaranteed by it.

[Cybersecurity / Cyber Resilience Act] ENISA maturity model for SMEs

Date: 13 July 2026
Source: ENISA

ENISA published a maturity model designed for micro, small and medium-sized enterprises to assess their readiness for the Cyber Resilience Act. The tool is primarily aimed at organisations that manufacture or place on the market products with digital elements.

The document offers a structured approach to measuring cyber resilience, identifying improvement priorities and progressively preparing for CRA requirements. For legal and compliance teams, it is a practical resource to support manufacturers, suppliers and supply chains ahead of the regulation’s upcoming deadlines.


See Dastra in action

In just a few minutes, schedule a personalized demo and discover how Dastra can adapt to your organization.

Ask for a demo
Subscribe to our newsletter

We'll send you occasional emails to keep you informed about our latest news and updates to our solution

* You can unsubscribe at any time using the link provided in each newsletter.