Consent management is a critical point of digital sovereignty: the CLOUD Act can enable US authorities to access European consent data regardless of storage location.
Microsoft’s GDID helped investigators identify a cybercriminal, but technical details about the scope and sources of data collection remain unclear in the indictment and affect data protection assessments.
dict.cc violates GDPR by forcing users with a single click to share data uncontrollably with 1,741 partners, making informed consent practically impossible.
The EU Council removed Article 88b (browser-based privacy settings instead of cookie banners) from the Digital Omnibus under pressure from Google and individual member states; data protection organisations are now mobilising the European Parliament.
The mere transmission of personal data to an unauthorised person is sufficient to establish a claim for non-material damages under GDPR, even without demonstrable economic loss.
Anthropic Claude session contents were indexed by Google and became publicly accessible, highlighting a fundamental data leakage risk when using public AI platforms.
Thousands of Claude chats were accessible via Google search because the platform had not explicitly blocked crawlers until Anthropic subsequently corrected this.
AI glasses intensify existing data exfiltration risks through a lower abuse threshold, but enforcement of bans fails technically, legally, and practically.
66% of enterprises are delaying or halting Copilot deployments due to concerns about data security and the risk of confidential information disclosure.
IT security tools such as logging, access control and asset inventory are essential instruments for operationalizing and demonstrating compliance with data subject rights under GDPR.