[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fvtDELt4uyhg6JSni1uG3XpzHuhkb5ErkWEVYDsJcV5M":3,"$fDuOfbrGklFg9DNstLQj01v77JKgm8YTNP3W1V3nd5U4":82,"white_papers":235},{"tableOfContents":4,"markDownContent":5,"htmlContent":6,"metaTitle":7,"metaDescription":8,"wordCount":9,"readTime":10,"title":11,"nbDownloads":12,"excerpt":13,"lang":14,"url":15,"intro":16,"featured":17,"state":18,"author":19,"authorId":20,"datePublication":24,"dateCreation":25,"dateUpdate":26,"mainCategory":27,"categories":43,"metaDatas":71,"imageUrl":72,"imageThumbUrls":73,"id":81},true,"You’re tired of generic newsletters that barely scratch the surface of your real challenges? Dastra brings you **Dastra Insights**, a legal and regulatory watch **specially designed for DPOs, legal professionals, and Privacy and AI practitioners**.\n\n🎯 **Targeted, practical monitoring grounded in the day-to-day realities of data protection and AI.**\n\nHere is our selection for **July 2026**:\n\n## \\[AI / AI Regulation\\] Entry into force of the AI Omnibus\n\n**Date**: 27 July 2026\\\n**Source**: [European Commission](https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force)\n\nThe AI Omnibus entered into force in the European Union on **27 July 2026**. The text amends the timeline and certain implementation modalities of the AI Act, with an explicit objective of administrative simplification and support for innovation.\n\nDeadlines for high-risk AI systems are notably postponed: **2 December 2027** for Annex III systems and **2 August 2028** for certain systems integrated into physical products. The text also extends certain support measures to small mid-cap companies and strengthens the role of the AI Office for certain systems, notably those based on general-purpose AI models.\n\n## \\[AI / Transparency\\] Guidelines on Article 50 of the AI Regulation\n\n**Date**: 20 July 2026\\\n**Source**: [European Commission](https://digital-strategy.ec.europa.eu/en/news/commission-publishes-guidelines-transparency-obligations-providers-and-deployers-certain-ai-systems)\n\nThe European Commission published guidelines on the transparency obligations applicable to certain providers and deployers of AI systems. These obligations begin to apply on **2 August 2026**.\n\nThe guidelines clarify the requirements relating to interactive systems, AI-generated or AI-manipulated content, deepfakes, as well as emotion-recognition and biometric categorisation systems. For compliance teams, this is a priority topic because it requires an operational review of interfaces, labels, machine-readable markings, and user information notices.\n\n## \\[Generative AI / Personal Data\\] EDPB on anonymisation, web scraping and blockchain\n\n**Date**: 8 July 2026\\\n**Source**: [EDPB](https://www.edpb.europa.eu/news/edpb-sheds-light-on-anonymisation-and-web-scraping-for-generative-ai-and-adopts-final-version_en)\n\nThe EDPB adopted guidelines on anonymisation and on web scraping in the context of generative AI, open for consultation until **30 October 2026**. It also adopted the final version of its guidelines on processing based on blockchain technologies.\n\nOn anonymisation, the EDPB relies on three core criteria: no singling out, no linkage, and no inference. On scraping, it recalls that the GDPR applies where personal data are collected or reused, with particular attention to the legal basis, purpose limitation, transparency, data minimisation and special-category data.\n\n## \\[Agentic AI / Personal Data\\] CNIL-CIANum exploratory note\n\n**Date**: 20 July 2026\\\n**Source**: [CNIL](https://www.cnil.fr/fr/ia-agentique-cnil-cianum-note)\n\nThe CNIL and the French Council for AI and Digital Affairs published an exploratory note on agentic AI and the protection of personal data. The note highlights the scale shift brought by systems capable of acting in the user’s environment, using multiple services, and retaining persistent memory.\n\nThe CNIL emphasises the risks of loss of user control, hyper-personalisation, complex data flows, and difficulty in allocating responsibilities among actors. The GDPR framework and the AI Act already apply, but their implementation must be adapted to these more autonomous architectures.\n\n## \\[Cookies / Trackers\\] Binding EDPB decision on a NOYB complaint against VRT\n\n**Date**: 14 July 2026\\\n**Source**: [EDPB](https://www.edpb.europa.eu/news/edpb-requires-belgian-dpa-to-handle-the-merits-of-noyb-cookie-banner-complaint_en)\n\nThe EDPB published a binding decision requesting the Belgian data protection authority to examine the merits of a complaint filed by NOYB concerning the cookie banners used by the Flemish public broadcaster VRT.\n\nThe practical significance lies less in the banner itself than in the procedure: the EDPB frames the possibility for an authority to reject a complaint as abusive or inadmissible, notably when brought by a representative organisation. For controllers, this confirms that coordinated cookie-related complaints remain a serious litigation lever.\n\n## \\[Email Trackers / Marketing\\] CNIL FAQ on pixels in emails\n\n**Date**: 22 July 2026\\\n**Source**: [CNIL](https://www.cnil.fr/fr/faq-recommandation-pixels-courriers-electroniques)\n\nThe CNIL published an FAQ on its recommendation regarding pixels in email communications. It clarifies in particular the scope of application, the processing of tracking links, cases where consent is not required, and the allocation of responsibilities between senders, email service providers, technical vendors and list-rental providers.\n\nThe CNIL recalls that trackers in emails may fall both under Article 82 of the French Data Protection Act and the GDPR. It also notes that emails sent in a professional context, including to employees, are not excluded as a matter of principle.\n\n## \\[United Kingdom / Data Subject Rights\\] ICO update on the right of access\n\n**Date**: 16 July 2026\\\n**Source**: [ICO](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/subject-access-requests/a-guide-to-subject-access/)\n\nThe ICO updated its guide on subject access requests to reflect changes introduced by the **Data (Use and Access) Act 2025**. The guide recalls the applicable requirements for access requests: acknowledging requests, a one-month timeframe, reasonable and proportionate searches, clear disclosure of information, and handling requests made through third parties.\n\nFor organisations operating in the UK, this update is part of the broader effort to adapt privacy policies, DSAR procedures and response templates to the new UK framework.\n\n## \\[AI / Minors\\] Italian sanction against Character AI\n\n**Date**: 9 July 2026\\\n**Source**: [Italian Data Protection Authority](https://www.gpdp.it/garante/doc.jsp?ID=10269594)\n\nThe Italian Garante sanctioned Character Technologies Inc., operator of [Character.AI](http://Character.AI), in the amount of **EUR 158,000** for several GDPR infringements related to a generative AI service accessible to minors.\n\nThe authority identified in particular shortcomings in information notices, a late DPIA, a late designation of the EU representative, as well as deficiencies in age-verification mechanisms and protections for minors. The company must strengthen age controls, prevent circumvention after blocking, and set minors’ profiles to private by default.\n\n## \\[CJEU / Judicial Data\\] Criminal decision databases and journalistic purpose\n\n**Date**: 9 July 2026\\\n**Source**: [CJEU, press release No. 100/26](https://curia.europa.eu/site/upload/docs/application/pdf/2026-07/cp260100en.pdf)\n\nIn case **C-199/24, Legal Newsdesk Sweden**, the CJEU held that the mere paid online publication of decisions relating to criminal convictions does not, in principle, constitute processing carried out for journalistic purposes within the meaning of Article 85 of the GDPR.\n\nThis decision is important for legal databases, private registers, information services and actors relying on freedom of expression or information to limit data subjects’ rights. It reminds us that national exemptions must remain within the limits of the GDPR and cannot deprive individuals of the remedies guaranteed by it.\n\n## \\[Cybersecurity / Cyber Resilience Act\\] ENISA maturity model for SMEs\n\n**Date**: 13 July 2026\\\n**Source**: [ENISA](https://www.enisa.europa.eu/publications/sme-cyber-resilience-maturity-assessment-model)\n\nENISA published a maturity model designed for micro, small and medium-sized enterprises to assess their readiness for the Cyber Resilience Act. The tool is primarily aimed at organisations that manufacture or place on the market products with digital elements.\n\nThe document offers a structured approach to measuring cyber resilience, identifying improvement priorities and progressively preparing for CRA requirements. For legal and compliance teams, it is a practical resource to support manufacturers, suppliers and supply chains ahead of the regulation’s upcoming deadlines.","\u003Cp>You’re tired of generic newsletters that barely scratch the surface of your real challenges? Dastra brings you \u003Cstrong>Dastra Insights\u003C/strong>, a legal and regulatory watch \u003Cstrong>specially designed for DPOs, legal professionals, and Privacy and AI practitioners\u003C/strong>.\u003C/p>\n\u003Cp>🎯 \u003Cstrong>Targeted, practical monitoring grounded in the day-to-day realities of data protection and AI.\u003C/strong>\u003C/p>\n\u003Cp>Here is our selection for \u003Cstrong>July 2026\u003C/strong>:\u003C/p>\n\u003Ch2 id=\"ai-ai-regulation-entry-into-force-of-the-ai-omnibus\">[AI / AI Regulation] Entry into force of the AI Omnibus\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 27 July 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force\" rel=\"nofollow\">European Commission\u003C/a>\u003C/p>\n\u003Cp>The AI Omnibus entered into force in the European Union on \u003Cstrong>27 July 2026\u003C/strong>. The text amends the timeline and certain implementation modalities of the AI Act, with an explicit objective of administrative simplification and support for innovation.\u003C/p>\n\u003Cp>Deadlines for high-risk AI systems are notably postponed: \u003Cstrong>2 December 2027\u003C/strong> for Annex III systems and \u003Cstrong>2 August 2028\u003C/strong> for certain systems integrated into physical products. The text also extends certain support measures to small mid-cap companies and strengthens the role of the AI Office for certain systems, notably those based on general-purpose AI models.\u003C/p>\n\u003Ch2 id=\"ai-transparency-guidelines-on-article-50-of-the-ai-regulation\">[AI / Transparency] Guidelines on Article 50 of the AI Regulation\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 20 July 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://digital-strategy.ec.europa.eu/en/news/commission-publishes-guidelines-transparency-obligations-providers-and-deployers-certain-ai-systems\" rel=\"nofollow\">European Commission\u003C/a>\u003C/p>\n\u003Cp>The European Commission published guidelines on the transparency obligations applicable to certain providers and deployers of AI systems. These obligations begin to apply on \u003Cstrong>2 August 2026\u003C/strong>.\u003C/p>\n\u003Cp>The guidelines clarify the requirements relating to interactive systems, AI-generated or AI-manipulated content, deepfakes, as well as emotion-recognition and biometric categorisation systems. For compliance teams, this is a priority topic because it requires an operational review of interfaces, labels, machine-readable markings, and user information notices.\u003C/p>\n\u003Ch2 id=\"generative-ai-personal-data-edpb-on-anonymisation-web-scraping-and-blockchain\">[Generative AI / Personal Data] EDPB on anonymisation, web scraping and blockchain\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 8 July 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://www.edpb.europa.eu/news/edpb-sheds-light-on-anonymisation-and-web-scraping-for-generative-ai-and-adopts-final-version_en\" rel=\"nofollow\">EDPB\u003C/a>\u003C/p>\n\u003Cp>The EDPB adopted guidelines on anonymisation and on web scraping in the context of generative AI, open for consultation until \u003Cstrong>30 October 2026\u003C/strong>. It also adopted the final version of its guidelines on processing based on blockchain technologies.\u003C/p>\n\u003Cp>On anonymisation, the EDPB relies on three core criteria: no singling out, no linkage, and no inference. On scraping, it recalls that the GDPR applies where personal data are collected or reused, with particular attention to the legal basis, purpose limitation, transparency, data minimisation and special-category data.\u003C/p>\n\u003Ch2 id=\"agentic-ai-personal-data-cnil-cianum-exploratory-note\">[Agentic AI / Personal Data] CNIL-CIANum exploratory note\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 20 July 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://www.cnil.fr/fr/ia-agentique-cnil-cianum-note\" rel=\"nofollow\">CNIL\u003C/a>\u003C/p>\n\u003Cp>The CNIL and the French Council for AI and Digital Affairs published an exploratory note on agentic AI and the protection of personal data. The note highlights the scale shift brought by systems capable of acting in the user’s environment, using multiple services, and retaining persistent memory.\u003C/p>\n\u003Cp>The CNIL emphasises the risks of loss of user control, hyper-personalisation, complex data flows, and difficulty in allocating responsibilities among actors. The GDPR framework and the AI Act already apply, but their implementation must be adapted to these more autonomous architectures.\u003C/p>\n\u003Ch2 id=\"cookies-trackers-binding-edpb-decision-on-a-noyb-complaint-against-vrt\">[Cookies / Trackers] Binding EDPB decision on a NOYB complaint against VRT\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 14 July 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://www.edpb.europa.eu/news/edpb-requires-belgian-dpa-to-handle-the-merits-of-noyb-cookie-banner-complaint_en\" rel=\"nofollow\">EDPB\u003C/a>\u003C/p>\n\u003Cp>The EDPB published a binding decision requesting the Belgian data protection authority to examine the merits of a complaint filed by NOYB concerning the cookie banners used by the Flemish public broadcaster VRT.\u003C/p>\n\u003Cp>The practical significance lies less in the banner itself than in the procedure: the EDPB frames the possibility for an authority to reject a complaint as abusive or inadmissible, notably when brought by a representative organisation. For controllers, this confirms that coordinated cookie-related complaints remain a serious litigation lever.\u003C/p>\n\u003Ch2 id=\"email-trackers-marketing-cnil-faq-on-pixels-in-emails\">[Email Trackers / Marketing] CNIL FAQ on pixels in emails\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 22 July 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://www.cnil.fr/fr/faq-recommandation-pixels-courriers-electroniques\" rel=\"nofollow\">CNIL\u003C/a>\u003C/p>\n\u003Cp>The CNIL published an FAQ on its recommendation regarding pixels in email communications. It clarifies in particular the scope of application, the processing of tracking links, cases where consent is not required, and the allocation of responsibilities between senders, email service providers, technical vendors and list-rental providers.\u003C/p>\n\u003Cp>The CNIL recalls that trackers in emails may fall both under Article 82 of the French Data Protection Act and the GDPR. It also notes that emails sent in a professional context, including to employees, are not excluded as a matter of principle.\u003C/p>\n\u003Ch2 id=\"united-kingdom-data-subject-rights-ico-update-on-the-right-of-access\">[United Kingdom / Data Subject Rights] ICO update on the right of access\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 16 July 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/subject-access-requests/a-guide-to-subject-access/\" rel=\"nofollow\">ICO\u003C/a>\u003C/p>\n\u003Cp>The ICO updated its guide on subject access requests to reflect changes introduced by the \u003Cstrong>Data (Use and Access) Act 2025\u003C/strong>. The guide recalls the applicable requirements for access requests: acknowledging requests, a one-month timeframe, reasonable and proportionate searches, clear disclosure of information, and handling requests made through third parties.\u003C/p>\n\u003Cp>For organisations operating in the UK, this update is part of the broader effort to adapt privacy policies, DSAR procedures and response templates to the new UK framework.\u003C/p>\n\u003Ch2 id=\"ai-minors-italian-sanction-against-character-ai\">[AI / Minors] Italian sanction against Character AI\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 9 July 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://www.gpdp.it/garante/doc.jsp?ID=10269594\" rel=\"nofollow\">Italian Data Protection Authority\u003C/a>\u003C/p>\n\u003Cp>The Italian Garante sanctioned Character Technologies Inc., operator of \u003Ca href=\"http://Character.AI\" rel=\"nofollow\">Character.AI\u003C/a>, in the amount of \u003Cstrong>EUR 158,000\u003C/strong> for several GDPR infringements related to a generative AI service accessible to minors.\u003C/p>\n\u003Cp>The authority identified in particular shortcomings in information notices, a late DPIA, a late designation of the EU representative, as well as deficiencies in age-verification mechanisms and protections for minors. The company must strengthen age controls, prevent circumvention after blocking, and set minors’ profiles to private by default.\u003C/p>\n\u003Ch2 id=\"cjeu-judicial-data-criminal-decision-databases-and-journalistic-purpose\">[CJEU / Judicial Data] Criminal decision databases and journalistic purpose\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 9 July 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://curia.europa.eu/site/upload/docs/application/pdf/2026-07/cp260100en.pdf\" rel=\"nofollow\">CJEU, press release No. 100/26\u003C/a>\u003C/p>\n\u003Cp>In case \u003Cstrong>C-199/24, Legal Newsdesk Sweden\u003C/strong>, the CJEU held that the mere paid online publication of decisions relating to criminal convictions does not, in principle, constitute processing carried out for journalistic purposes within the meaning of Article 85 of the GDPR.\u003C/p>\n\u003Cp>This decision is important for legal databases, private registers, information services and actors relying on freedom of expression or information to limit data subjects’ rights. It reminds us that national exemptions must remain within the limits of the GDPR and cannot deprive individuals of the remedies guaranteed by it.\u003C/p>\n\u003Ch2 id=\"cybersecurity-cyber-resilience-act-enisa-maturity-model-for-smes\">[Cybersecurity / Cyber Resilience Act] ENISA maturity model for SMEs\u003C/h2>\n\u003Cp>\u003Cstrong>Date\u003C/strong>: 13 July 2026\u003Cbr />\n\u003Cstrong>Source\u003C/strong>: \u003Ca href=\"https://www.enisa.europa.eu/publications/sme-cyber-resilience-maturity-assessment-model\" rel=\"nofollow\">ENISA\u003C/a>\u003C/p>\n\u003Cp>ENISA published a maturity model designed for micro, small and medium-sized enterprises to assess their readiness for the Cyber Resilience Act. The tool is primarily aimed at organisations that manufacture or place on the market products with digital elements.\u003C/p>\n\u003Cp>The document offers a structured approach to measuring cyber resilience, identifying improvement priorities and progressively preparing for CRA requirements. For legal and compliance teams, it is a practical resource to support manufacturers, suppliers and supply chains ahead of the regulation’s upcoming deadlines.\u003C/p>\n","Dastra Insights Privacy & AI: what happened in July?","A legal and regulatory watch specially designed for DPOs, legal professionals, and Privacy and AI experts.",1143,6,"Dastra Insights: what happened in July in Privacy and AI?",0,null,"en","dastra-insights-what-happened-in-july-in-privacy-and-ai","A legal and regulatory watch specifically designed for DPOs, legal professionals, and Privacy and AI experts.",false,"Published",{"id":20,"displayName":21,"avatarUrl":22,"bio":13,"blogUrl":13,"color":13,"userId":20,"creationDate":23},20352,"Leïla Sayssa","https://static.dastra.eu/tenant-3/avatar/20352/TDYeY3C8Rz1lLE/dpo-avatar-h01-150.png","2025-03-03T11:08:22","2026-07-28T15:54:00","2026-07-28T15:54:25.8543035","2026-07-28T15:56:20.3745439",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":33},2,"Blog","A list of curated articles provided by the community","blog","#28449a",[34,37,40],{"lang":35,"name":29,"description":36},"fr","Une liste d'articles rédigés par la communauté",{"lang":38,"name":29,"description":39},"es","Una lista de artículos escritos por la comunidad",{"lang":41,"name":29,"description":42},"de","Eine Liste von Artikeln, die von der Community verfasst wurden",[44,49],{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":45},[46,47,48],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},{"id":50,"name":51,"description":52,"url":53,"color":54,"parentId":28,"count":13,"imageUrl":13,"parent":55,"order":60,"translations":61},9,"News","Stay up to date with the latest news from data protection authorities: decisions, fines, guidelines, and regulatory trends in GDPR and privacy.","news","#1676ca",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":56},[57,58,59],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},4,[62,65,68],{"lang":35,"name":63,"description":64},"Actualités","Suivez les dernières actualités des autorités de protection des données (CNIL, EDPS, etc.) : décisions, sanctions, lignes directrices et tendances réglementaires en matière de RGPD et de privacy.",{"lang":38,"name":66,"description":67},"Actualidad","Todos los artículos relativos a las autoridades de protección de datos",{"lang":41,"name":69,"description":70},"Nachrichten","Alle Artikel mit Bezug zu Datenschutzbehörden",[],"https://static.dastra.eu/content/8861b754-948a-47b5-9e2f-98edf02cb3e2/dastractu-original.jpg",[74,75,76,77,78,79,80],"https://static.dastra.eu/content/8861b754-948a-47b5-9e2f-98edf02cb3e2/dastractu-1000.webp","https://static.dastra.eu/content/8861b754-948a-47b5-9e2f-98edf02cb3e2/dastractu.webp","https://static.dastra.eu/content/8861b754-948a-47b5-9e2f-98edf02cb3e2/dastractu-1500.webp","https://static.dastra.eu/content/8861b754-948a-47b5-9e2f-98edf02cb3e2/dastractu-800.webp","https://static.dastra.eu/content/8861b754-948a-47b5-9e2f-98edf02cb3e2/dastractu-600.webp","https://static.dastra.eu/content/8861b754-948a-47b5-9e2f-98edf02cb3e2/dastractu-300.webp","https://static.dastra.eu/content/8861b754-948a-47b5-9e2f-98edf02cb3e2/dastractu-100.webp",60228,{"total":83,"items":84,"parent":230},8,[85,106,127,147,169,179,197,213],{"id":86,"name":87,"description":88,"url":89,"color":90,"parentId":28,"count":13,"imageUrl":13,"parent":91,"order":83,"translations":96},20,"Inside Dastra","Go behind the scenes at Dastra: company news, culture, events, team highlights, and the people driving our GDPR solution.","dastra-life","#e3cf68",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":92},[93,94,95],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},[97,100,103],{"lang":35,"name":98,"description":99},"Vie de Dastra","Plongez dans les coulisses de Dastra : actualités internes, culture d’entreprise, événements, équipes et engagements. Découvrez qui se cache derrière notre solution RGPD.",{"lang":41,"name":101,"description":102},"Innerhalb von Dastra","Eintauchen in das Unternehmen",{"lang":38,"name":104,"description":105},"Dentro de Dastra","Sumérjase en la empresa",{"id":107,"name":108,"description":109,"url":110,"color":111,"parentId":28,"count":13,"imageUrl":13,"parent":112,"order":117,"translations":118},69,"Expertise","Gain insights from our experts on GDPR compliance, data protection, and privacy challenges. In-depth articles, professional analysis, and real-world best practices.","indepth","#000000",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":113},[114,115,116],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},7,[119,121,124],{"lang":35,"name":108,"description":120},"Bénéficiez des conseils de nos experts sur la conformité RGPD, la protection des données et les enjeux privacy. Articles de fond, analyses et retours d’expérience métier.",{"lang":41,"name":122,"description":123},"Fachwissen","Entdecken Sie die Artikel unserer DSGVO-Experten",{"lang":38,"name":125,"description":126},"Experiencia","Descubre los artículos de nuestros expertos en Privacy",{"id":60,"name":128,"description":129,"url":130,"color":131,"parentId":28,"count":13,"imageUrl":13,"parent":132,"order":10,"translations":137},"Use cases","Discover how companies use Dastra to manage their GDPR compliance. Testimonials, use cases, and real-world integrations of our privacy management solution.","case-studies","#b61b9c",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":133},[134,135,136],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},[138,141,144],{"lang":35,"name":139,"description":140},"Retours d'expérience","Découvrez comment les entreprises utilisent Dastra pour piloter leur conformité RGPD. Témoignages, cas d’usage et intégrations concrètes de notre solution de privacy management.",{"lang":41,"name":142,"description":143},"Case Studies","Entdecken Sie die Erfahrungsberichte unserer Kunden",{"lang":38,"name":145,"description":146},"Casos prácticos","Descubra los testimonios de nuestros clientes",{"id":148,"name":149,"description":150,"url":151,"color":152,"parentId":28,"count":13,"imageUrl":13,"parent":153,"order":158,"translations":159},10,"Release notes","Keep up with the latest features of Dastra: product updates, new functionalities, and improvements to our GDPR compliance and data management platform.","release","#8c316a",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":154},[155,156,157],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},5,[160,163,166],{"lang":35,"name":161,"description":162},"Notes de version","Restez informé(e) des dernières fonctionnalités de Dastra : mises à jour, évolutions produit et améliorations de notre solution de conformité RGPD et de gestion des données personnelles.",{"lang":41,"name":164,"description":165},"Veröffentlichungen","Alle Versionshinweise und Funktionen von Dastra",{"lang":38,"name":167,"description":168},"Lanzamientos","Todas las notas de la versión e información sobre las funciones de Dastra",{"id":50,"name":51,"description":52,"url":53,"color":54,"parentId":28,"count":13,"imageUrl":13,"parent":170,"order":60,"translations":175},{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":171},[172,173,174],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},[176,177,178],{"lang":35,"name":63,"description":64},{"lang":38,"name":66,"description":67},{"lang":41,"name":69,"description":70},{"id":180,"name":181,"description":182,"url":183,"color":111,"parentId":28,"count":13,"imageUrl":13,"parent":184,"order":189,"translations":190},221,"AI Governance","Best practices, regulatory frameworks and real-world insights to manage AI responsibly and in compliance with the AI Act.","ai-governance",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":185},[186,187,188],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},3,[191,194],{"lang":35,"name":192,"description":193},"Gouvernance de l'IA","Bonnes pratiques, cadres réglementaires et retours d'expérience pour piloter l'IA de façon responsable et conforme à l'AI Act.",{"lang":41,"name":195,"description":196},"KI-Governance","Best Practices, regulatorische Rahmenbedingungen und Praxiserfahrungen für einen verantwortungsvollen KI-Einsatz im Einklang mit dem AI Act.",{"id":198,"name":199,"description":200,"url":201,"color":111,"parentId":28,"count":13,"imageUrl":13,"parent":202,"order":28,"translations":207},220,"Compliance","Regulatory news, practical guides and analysis to keep your organization compliant with the GDPR and beyond.","compliance",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":203},[204,205,206],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},[208,211],{"lang":35,"name":209,"description":210},"Conformité","Actualités réglementaires, guides pratiques et analyses pour maintenir votre organisation en conformité RGPD et au-delà.",{"lang":41,"name":199,"description":212},"Regulatorische Neuigkeiten, Praxisleitfäden und Analysen, um Ihre Organisation DSGVO-konform und darüber hinaus aufzustellen.",{"id":214,"name":215,"description":216,"url":217,"color":111,"parentId":28,"count":13,"imageUrl":13,"parent":218,"order":223,"translations":224},219,"Privacy","Principles, techniques and trends in personal data protection — from privacy by design to data subject rights.","privacy",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":219},[220,221,222],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},1,[225,227],{"lang":35,"name":215,"description":226},"Principes, techniques et tendances autour de la protection des données personnelles — de la privacy by design aux droits des personnes.",{"lang":41,"name":228,"description":229},"Datenschutz","Grundsätze, Methoden und Trends zum Schutz personenbezogener Daten — von Privacy by Design bis zu Betroffenenrechten.",{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":231},[232,233,234],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},{"items":236,"total":303,"size":223,"page":223},[237],{"title":238,"nbDownloads":12,"excerpt":239,"lang":14,"url":240,"intro":241,"featured":17,"state":18,"author":242,"authorId":243,"datePublication":247,"dateCreation":248,"dateUpdate":249,"mainCategory":250,"categories":256,"metaDatas":289,"imageUrl":293,"imageThumbUrls":294,"id":302},"AI Act Transparency Notice Template (Word Format) Compliant with Article 50","Download a Microsoft Word template for AI transparency notices compliant with Article 50 of the EU AI Act, including four ready-to-use notice variants for AI providers and deployers.","ai-act-transparency-notice-template-word-format-compliant-with-article-50","Since 2 August 2026, Article 50 of the European Artificial Intelligence Act (AI Act) has introduced transparency obligations for several categories of AI systems. AI providers and deployers must inform individuals when they interact with AI, are exposed to AI-generated content, are subject to emotion recognition or biometric categorisation, or encounter AI-generated deepfakes. To help organisations comply with these requirements, Dastra provides a free Microsoft Word template that can be adapted and integrated into your documentation, websites and user interfaces.",{"id":243,"displayName":244,"avatarUrl":245,"bio":13,"blogUrl":13,"color":13,"userId":243,"creationDate":246},38,"Paul-Emmanuel Bidault","https://static.dastra.eu/tenant-27/avatar/38/paul-emmanuel-bidault-150.jpg","2019-12-03T19:09:28","2026-08-06T12:40:00","2026-08-06T12:40:04.9054724","2026-08-06T12:59:59.293083",{"id":251,"name":252,"description":13,"url":253,"color":254,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":189,"translations":255},70,"Livre blanc","white-papers","#1795d3",[],[257,262,267,269,277,285],{"id":28,"name":29,"description":30,"url":31,"color":32,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":12,"translations":258},[259,260,261],{"lang":35,"name":29,"description":36},{"lang":38,"name":29,"description":39},{"lang":41,"name":29,"description":42},{"id":263,"name":264,"description":13,"url":265,"color":111,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":10,"translations":266},48,"Ressources","resources",[],{"id":251,"name":252,"description":13,"url":253,"color":254,"parentId":13,"count":13,"imageUrl":13,"parent":13,"order":189,"translations":268},[],{"id":270,"name":271,"description":272,"url":273,"color":274,"parentId":263,"count":13,"imageUrl":275,"parent":13,"order":12,"translations":276},83,"IA","Toutes les ressources sur l'IA","intelligence-artificielle","#342d9f","https://static.dastra.eu/tag/9bce43f2-c750-4e6c-9b31-18ea1409a5ba/dalle-2024-11-25-225448-a-modern-and-sleek-square-logo-for-artificial-intellige-original.webp",[],{"id":278,"name":279,"description":280,"url":281,"color":282,"parentId":263,"count":13,"imageUrl":283,"parent":13,"order":12,"translations":284},92,"Artificial intelligence","Key ressources for AI","ai-ressources","#0f1cd7","https://static.dastra.eu/tag/3cf3f039-04ed-4b3a-b386-a99b43cb4e64/ai-act-bis-original.png",[],{"id":180,"name":181,"description":182,"url":183,"color":111,"parentId":28,"count":13,"imageUrl":13,"parent":13,"order":189,"translations":286},[287,288],{"lang":35,"name":192,"description":193},{"lang":41,"name":195,"description":196},[290],{"typeMetaDataId":60,"value":291,"id":292},"https://static.dastra.eu/backofficefilescontainer/875e1e54-f479-43ff-9572-c4add516b85c/Dastra-AI-transparency-notice-template-art50-EN.docx",117744,"https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-original.png",[295,296,297,298,299,300,301],"https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-1000.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-1500.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-800.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-600.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-300.webp","https://static.dastra.eu/content/34bf6ba9-1e42-45b0-b292-63b6a01a0c70/ai-transparency-notice-1600x900-en-100.webp",60275,14]