gdpr rules

Data protection digest 2-15 Aug 2026: Before implementing an AI tool, check if it complies with GDPR rules – Polish UODO

Does your new AI tool comply with the GDPR rules?

The Polish Data Protection Office (UODO) published a list of initial questions worth asking before deciding to create or use AI systems (in Polish only). These questions do not replace risk analysis, data protection impact assessment, or fundamental rights impact assessment as prescribed by the GDPR rules and the AI Act, but they provide a good starting point for these analyses. 

Stay up to date! Sign up to receive our fortnightly digest via email. 

A recent survey conducted by the UODO experts showed that 41% to 58.5% of entities do not perceive a connection between AI tools and the processing of personal data. Furthermore, as many as 95.9% do not consider themselves prepared to implement AI in accordance with the GDPR rules. 

Compliance questions are usually asked when the tool is already operational and decisions regarding the data used and the provider have already been made. A set of questions by UODO is tailored to specific groups and stages of AI implementation:

  • Small and medium-sized enterprises. They often use ready-made AI systems. Therefore, they do not undergo the training phase and do not have extensive legal knowledge. 
  • Public sector entities, taking into account the principle of legality and the rules of administrative procedures.
  • Organisations that do not fall into any of the above groups, including those building or training their own AI models. 

E-evidence in the EU streamlined

In August, new rules are coming into effect in the EU that will change the way judicial authorities can access electronic evidence. Known as the EU e-evidence package. After a three-year transition period, judicial authorities in one Member State can request electronic evidence directly from service providers in another, in most cases without involving the authorities of the provider’s country of establishment.

Yet, many national frameworks on which the regulation depends are not yet in place, a Bird&Bird legal analysis shows.   

Nowadays, over half of all criminal investigations include a request for cross-border access to electronic evidence such as texts, e-mails or messages in apps. However, gaining access to electronic evidence presents significant legal and technical challenges. For instance, evidence may be stored in an unknown location, servers can be spread across different countries, and there are no harmonised deadlines for how long service providers have to preserve data or reply to legal requests. 

France spam calls banned

In France, the rules of cold calling that are binding on companies came into force on 11 August. Calls will only be permitted if they relate to a contract a person has already entered into, or the company has obtained prior consent. It also puts an end to the mostly unknown Bloctel system, which offered consumers the opportunity to register on a list of opposition to this canvassing. In essence:

  • The consumer’s consent must be free, specific, clear, unambiguous and revocable.
  •  It is only valid for a maximum of one year.
  • Proof of the consumer’s consent must be kept by the professional for a minimum period of 3 years and is made available to the consumer at his request.
  • Cold calling is completely forbidden in terms of energy renovation, adaptation of housing to the loss of autonomy, and personal training.
  • Consumers receiving calls should exercise their rights on the phone straight away (eg, withdraw consent, ask for the origin of the data), object to the processing, and keep evidence for further formal complaints (eg, call recording).

Telemarketing calls are already severely restricted in some European countries, including Germany, Austria, and Italy. In the UK, most telemarketing calls are legal provided the recipient has not objected to the call and their number is not on a statutory list of people or businesses who do not wish to receive calls. 

Other legal updates

EU Cyber Resilience Act: The European Commission published practical guidance to help manufacturers, developers, and businesses of all sizes meet their obligations under the new Cyber Resilience Act (CRA). The Act entered into force on 10 December 2024, introducing mandatory cybersecurity requirements for manufacturers, covering the planning, design, development and maintenance of digital products from apps and computer programs to baby monitors and smartwatches.

The main obligations under the CRA will apply from 11 December 2027, with reporting obligations on vulnerabilities and incidents as of 11 September 2026.  

Gen AI in courts: In Ireland, new guidance on the use of generative AI tools in the High Court states that all court users are responsible for the content of their court documents. The rule applies to all documents used in proceedings in the High Court, including pleadings, submissions, affidavits, witness statements and expert reports, and to all persons involved in those proceedings, including parties, litigants in person, legal practitioners, witnesses, experts and any other third party required to produce documents. 

Several known risks and limitations of using GenAI in court proceedings may include:

  • inaccurate output and hallucinations, 
  • bias and incompleteness,
  • factual errors, and
  • confidentiality and privacy risks. 

The High Court also highlights the risk that information entered into GenAI tools may be required to be disclosed in legal proceedings and may lose the protections of legal privilege, as explained by Gazette.ie.

Cameras and healthcare

GDPR rules

The Czech Office for Personal Data Protection published a recommendation on camera systems located at healthcare providers (in Czech only). It is dedicated to two groups of administrators in the health sector: a) smaller administrators of CCTV systems in individual practices and b) larger providers of health services. In principle, the processing of personal data through a camera system that is not strictly necessary for the provision of health services should disrupt the relationship between the patient and the health professional as little as possible,

and take into account the patient’s rights to privacy and dignity.  The guidance distinguishes four basic processing purposes:

  • diagnostic purposes,
  • surveillance purposes, 
  • property protection purposes, and 
  • educational purposes. 

Before deploying a camera system based on the controller’s legitimate interest, a balancing test must be carried out, the aim of which is to select a solution that, given the existing real threat, will fulfil the desired purposes with the least possible impact on the privacy of data subjects. As part of the balancing test, the regulator therefore recommends that controllers consider all options (e.g., without the use of a camera system, and variants that combine a camera system with other means or measures that could ensure the achievement of the specified purpose). 

More from supervisory authorities

Who has to report a data leak? In connection with the leak of personal data of almost 19 million Poles from the provider of the MyDr Electronic Medical Records system, the Polish UODO reminds personal data controllers who have entrusted MyDr with the processing of personal data of the obligation to carry out an analysis in terms of the risk of violating the rights or freedoms of natural persons. It is necessary to assess whether a personal data breach has occurred, and to notify the UODO and the persons affected by the breach. 

If a personal data breach occurred in the organisation of a processor to which the controller entrusted its personal data, the controller should receive information from the aforementioned processor confirming that the incident also involved the controller’s data. The controller shall notify the supervisory authority without undue delay – where possible, but no later than 72 hours after becoming aware of the breach. Any notification submitted to the supervisory authority after 72 hours shall be accompanied by an explanation of the reasons for the delay. 

Receive our digest by email 

Sign up to receive our digest by email every 2 weeks

Free GDPR training in the UK: Small and medium-sized organisations, and sole traders across the UK are being encouraged to boost their business fitness by taking new online training from the Information Commissioner’s Office. Data Protection Essentials (on-demand courses and advice) has been designed to give smaller organisations clarity on data protection when handling information about:

  • children and families, 
  • patients,
  • service users, 
  • clients and customers, 
  • tenants or employees, etc.

It covers common activities such as sharing information with others, managing records securely, supporting marketing and customer engagement activities, and reducing the risk of data breaches.  

DPO conflict of interest and “substitute DPO”

GDPR rules

The French data protection regulator CNIL reminds organisations that the Data Protection Officer may exercise, in addition to those provided for in Article 39 of the GDPR, other functions within the body that appoints him (part-time DPO). The performance of these missions or tasks must not be likely to interfere with the performance of the duties they perform as DPO, including by depriving them of the time necessary to carry out these tasks.

Moreover, the combination of missions must not place them in a situation of conflict of interest. The existence of such a conflict of interest is assessed on a case-by-case basis. It is recommended to carry out an analysis before the appointment or the assignment of new functions or missions to the DPO. Several questions can help the organisation identify a conflict of interest: 

  • What are the other functions and/or missions combined with those of the DPO?
  • Does the DPO carry out management functions?
  • Do the DPO and/or the members of their team have decision-making power in determining the purpose and/or means of the data processing implemented by the organisation? 
  • Is the DPO required, in the context of his or her third-party functions, to take a position on subjects or projects related to the processing of personal data? 
  • Does the DPO perform the functions of a staff representative or a union mandate within the organisation? 

Finally, if an internal DPO is in a situation of conflict of interest, a possible remedial measure is appointing a “substitute DPO”, who can perform the functions of DPO on the perimeter of the conflict of interest. 

In other news

Telecom spam fine: The Italian data protection authority Garante fined Telecom Italia (TIM) 9,516,000 euros after an investigation revealed a complex telemarketing scheme. It involved unauthorised call centres using spoofed telephone numbers to contact Italian consumers, including those registered on the national opt-out list. These consumers were then routed through an official TIM partner webpage, creating the illusion of compliant, voluntary callback requests, according to GDPRbuzz.com

Meta glasses ban in the UK: According to a Guardian article, courts in England and Wales have joined several restaurants, theatres and pubs in banning Meta glasses, amid a mounting backlash against what has been described as “spyware”. Taking images or videos in court buildings is prohibited in the UK without official permission and can be prosecuted as contempt of court. While lawyers and members of the public are allowed to enter courts with smartphones, which can record both video and audio, the new rule makes it clear that no such exception would be made for smart glasses.

Australian minors’ accounts: According to Reuters, Facebook ​and Instagram owner Meta had taken down more than 750,000 accounts it suspected ‌were held by Australians aged under 16 since a world-first ban on teen accounts, and promised more action in the face of possible regulatory intervention. The Australian government proposed the landmark ​law, which came into force on 10 December, on concerns about social media’s impact on the physical and mental ​health of children and teens. Other countries around the world, such as the UK, Denmark and France, are implementing similar age restrictions. 

And finally

Women’s health apps: If women track their menstrual cycle in an app, they are sharing highly sensitive information. However, it is often unclear what an app does with this information or with whom this data is shared. This involves very intimate data such as whether the woman has a partner, is pregnant or has had a miscarriage, or what hormonal symptoms she experiences.

The Dutch Data Protection Authority (AP) calls for caution and does not rule out an investigation. In practice, it is unclear whether the apps share this information with advertising partners, and whether users are properly informed about this. The AP advises checking what you are consenting to when installing the app. If the information is unclear or if, for example, there is no option to refuse data sharing, do not share any information you wish to keep private. 

Do you need support on data protection, privacy or GDPR? TechGDPR can help.

Request your free consultation

Tags

Show more +