Personalised ads in chatbots
The US company OpenAI plans to soon begin displaying personalised advertising to European users via its AI chatbots – ChatGPT Free and Go plans – similar to what is already being done in other countries. This personalised advertising will be based on user consent pursuant to the GDPR. Current and past chats of users will also be analysed. Even in the ads-free versions, the context of the current chat thread and basic contextual information such as general location and language will be used for advertising purposes, based on a legitimate interest.
Stay up to date! Sign up to receive our fortnightly digest via email.
Several German state data protection authorities point out the data protection risks of such profiling. The risk stems primarily from the use of ChatGPT in all conceivable areas of life and on all conceivable topics, including highly personal ones. Many people increasingly perceive AI chatbots as personal conversation partners rather than machines and interact with them accordingly. Furthermore, users’ moods will be able to be determined in real time.
Anyone who wishes to continue using chatbots and to limit profiling for advertising purposes from chats as much as possible should proceed as follows:
- Do not consent to personalised advertising.
- Use the ad-free premium versions.
- Check if ad personalisation is enabled in the privacy settings and disable it if necessary.
- Disable the use of chat for model improvement.
- Use the “Temporary Chat” function for sensitive topics.
- Do not enter any confidential or secretive information into it.
- Regularly delete the chat history, etc.
EU KIDS Act

On 17 September, the European Commission proposed a new KIDS Act to introduce a gradual uptake of social media for children across the EU. It will apply to online services used by minors, including social media, video-sharing platforms, online games, and AI companions and chatbots. The proposal recognises the risks that minors face on certain platforms and therefore limits autonomous account creation on those specific platforms and systems by children below the age of 15 years. It also prohibits social media accounts under 13.
Age will be verified through certified solutions independent of the platforms, a free EU age verification app or, in the near future, the European Digital Identity Wallet. When providers already have an estimation of the user’s age based on multiple signals such as account creation date or credit card details, there will be no age verification required for most existing users. The KIDS Act also prohibits designing services to encourage compulsive or excessive use by minors, such as:
- endless autoplay and infinite scrolling without real breaks
- notifications designed to pull the child back, unrelated to anything the child did
- rewards for posting or streaming to mass audiences
- ‘streak’ mechanics that penalise a child for not returning every day
- time limits and usage breaks, designed to protect children’s sleep and school time.
Finally, by providing an EU-wide minimum age, it harmonises diverging national rules, removing obstacles to the implementation of the Digital Single Market, ensuring legal certainty and a similar level of protection for all children.
More legal updates

California child data reinforced: On 10 September, Governor Gavin Newsom signed landmark bipartisan legislation strengthening California’s nation-leading protections for children online and when using AI. The new laws strengthen safeguards for companion chatbots, prohibit social media platforms from offering addictive features to users under 16, and expand privacy protections for children. These bills, among other things, will help protect children by:
- crisis protocols in the case of suicidal ideation,
- notifications and parental controls should a child disable safety settings,
- independent child safety audits and annual risk assessments,
- prohibition of algorithmic feeds based on user history and profile,
- protection from targeted advertising,
- and rules on the use of child data in AI systems.
UK ICO reform: On 30 September, the Information Commissioner’s Office formally transitioned to the Information Commission. Under new governance arrangements introduced by the Data (Use and Access) Act 2025, the work of the ICO is now overseen by a new Information Commission Board that brings together a range of new skills, but does not change the Commission’s core responsibilities. The transition also comes as the regulator opens its new headquarters in Manchester.
Asia privacy reinforcements: According to a recent DLA Piper analysis, in the Asia-Pacific region, privacy and cybersecurity regulation continues to evolve rapidly, with regulators increasingly moving from legislative build-out to practical compliance and enforcement, in particular:
- The Vietnamese data protection and cybersecurity sanctions framework took effect in August (financial penalties, cross-border transfer impact assessment requirements);
- South Korea’s amendments to the Personal Information Protection Act took effect in September (increased penalties, data breach notification, executive accountability, certifications);
- Indonesia’s Personal Data Protection Law implementing regulation has been promulgated. It will take effect in mid January 2027 (lawful bases and consent, ROPA, data retention policies, impact assessments, data protection officers, joint controllers and processors, etc.).
Personal data in research

In Germany, the “electronic patient record” (ePA), introduced in 2025, aims not only to digitise the German healthcare system nationwide. Health data from the ePA can also be used for research purposes from October 2026 onwards, without requiring patient consent. Therefore, patients will have to actively object to its use for research purposes. They can do this either via their health insurance provider’s ePA app or by contacting the provider’s ombudsman.
The first health data from the ePA can likely be transferred to the Research Data Centre for Health (FDZ Gesundheit) from the end of October onwards, to make it available to researchers for public-benefit research purposes upon request. The FDZ Gesundheit is a public body established at the Federal Institute for Drugs and Medical Devices (BfArM). Before the data is made available, all direct identifying characteristics, such as the patient’s name or address, must be removed and replaced with pseudonyms.
More official guidance
Banking data protection and microentrepreneurs: The Supreme Administrative Court in Poland confirmed that banking data protections apply to individual entrepreneurs. The case involved the interpretation of ‘natural person’ under the country’s Banking Law. Until now, the provisions governing the conditions for processing personal data had been interpreted as applying to consumers, but not to natural persons who had entered into a relationship with, for example, a bank in connection with conducting business activities (eg, sharing a debtor’s personal data without their consent). The court decided that individual entrepreneurs are entitled to the same data protections as consumers, upholding the data protection regulator UODO’s decision.
DSA and GDPR interplay: Ensuring the coherent interpretation and application of the Digital Services Act (DSA) and the GDPR by providers that are covered by both regulations is important, according to the EDPB in its recent guidelines. This is particularly the case where provisions of the DSA affect the processing of personal data by intermediary service providers. Several provisions of the DSA specifically refer to the protection of personal data as well as definitions and concepts under the GDPR, such as ‘profiling’ and ‘special categories of personal data’.
The DSA does not derogate, as lex specialis, from the general rules on the processing of personal data under the GDPR and the ePrivacy Directive. Nonetheless, settled case law of the Court of Justice of the European Union (CJEU) provides that, where two EU legal acts of the same hierarchical value do not establish priority of one over the other, they should be applied in a compatible manner, which enables their coherent application.
In other news

Poland new mass data leak: The media is reporting a new leak that may involve the medical data of up to five million Poles. The Central Bureau for Combating Cybercrime is investigating the matter, and the President of the Personal Data Protection Office (UODO) has already announced an audit of the company responsible for the Medyc software.
The incident is the result of an attack on the Medyc app (by Qbusoft Sp. z o.o). It was announced that the technical and organisational measures applied, including risk analysis, will be subject to UODO inspection at the company. Only in August, the MyDr medical data breach affected 19 million Poles. The UODO received over 50 complaints and reports related to this incident. Over 2,000 notifications have been received from data controllers.
Digital education data: In Finland, the Data Protection Ombudsman has reassessed the processing of personal data on an electronic educational platform in basic education in the City of Espoo following a decision by the Supreme Administrative Court. The new decision specifies that data can be processed in an electronic curriculum for organising basic education, but that the personal data of students may not be used for the purposes of the service provider or other parties (such as developing services or profiling, which are not necessary for teaching purposes).
Receive our digest by email
Sign up to receive our digest by email every 2 weeks
More enforcement decisions
Google fine over location data: The Irish data protection authority has decided in a case regarding Google’s processing of location data and fined Google 403 million euros. The scope of the inquiry concerned Google’s processing of location data in three specific features – “Web & App Activity”, “Location History” and “Location Accuracy” between 2018 and 2020.
Illicit AI tool warning: The Spanish data protection agency AEPD has issued a warning to a company regarding the possible implementation of an AI tool for screening and evaluating candidates in personnel selection. The system would be used to analyse resumes, assign scores, and, where appropriate, prioritise applications, and could directly influence decisions regarding hiring and career advancement. This tool has not yet been implemented, although the company had informed its staff about its upcoming rollout.
Healthcare data fine: The Italian data protection authority Garante fined IQVIA Solutions Srl 7 million euros. The company, part of a multinational group active in healthcare data analysis and clinical research, had created a database containing health information on one million patients of 800 general practitioners, which was used for studies commissioned by pharmaceutical companies.
These data were not anonymous, as the company claimed. Combined with highly detailed information (year of birth, sex, diagnosis, symptoms, prescriptions, tests, vaccinations, as well as location data), it made it possible to isolate individual patients and, with modest means, re-identify them. The company also processed health data without an appropriate legal basis and without adequately informing patients. It did not define retention periods: the data dated back to 2001; and it failed to carry out an impact assessment.
And Finally

Multi-party computation and GDPR: The EDPS reminds us that secure multi-party computation (SMPC) is a field of cryptography that enables different organisations to collaborate with their data while keeping their information private. This is particularly valuable in fields such as medicine and finance, where organisations can benefit from jointly processing the data that each organisation possesses, whether client or patient data, but cannot share it for legal reasons.
At the same time, SMPC should not be regarded as a mechanism for circumventing legal or regulatory obligations, especially those stemming from the GDPR. The use of SMPC does not, in itself, render data anonymous, nor does it remove all the responsibilities associated with processing personal data. Where personal data is involved, the processing carried out through SMPC remains subject to obligations relating to lawfulness, transparency, purpose limitation, security, accountability and the rights of data subjects.