access by design

Data protection digest 16 Sep 2026: CRA reporting, data ‘access by design’ & Digital ID wallet – EU latest

Data Act ‘access by design’ rule now applicable

From 12 September, a new ‘access by design’ requirement applies to connected products and related services placed on the EU market. As part of the EU Data Act, it gives consumers and business users direct access to the collected, communicated or generated data. Smartwatches, cars, medical devices, home devices, monitoring apps, support software services, industrial machinery and more are covered by the new rules. 

Stay up to date! Sign up to receive our fortnightly digest via email. 

Manufacturers and providers have to design products and services so that users can access relevant data directly by default, where technically feasible, easily, securely and free of charge. Users must be able to access or export data, through a built-in interface, app or other technical tool, without having to request access from the data holder. 

This also includes metadata necessary to interpret and use them. 

The Data Act is fully compliant with the GDPR rules. This is an important consideration, as the co-generated data often contains both personal and non-personal data, which may be difficult to separate. Where the user is not the data subject whose data is being requested, personal data can only be made available if there is a valid legal basis under Art. 6 and 9 of the GDPR. (eg, consent). 

Legal updates

Cyber Resilience Act (CRA) reporting reminder: As of 11 September, manufacturers of products with digital components sold in the EU must report actively exploited vulnerabilities and serious incidents. Companies targeting the European market have to report in two situations: 

  • An actively exploited vulnerability: there is reliable evidence that someone with malicious intent has exploited a vulnerability in your product. 
  • A serious incident that affects the security of the product. Older products are also subject to the reporting obligation.

Companies have to issue an early warning within 24 hours and a more detailed report within 72 hours. This is followed by a final report for a vulnerability, no later than 14 days after a solution is available; and for an incident, within 1 month of the report. Reports are submitted uniformly across the EU via the system developed and provided by the European Union Agency for Cybersecurity (ENISA) – Single Reporting Platform. The recipients of the reports are the respective coordinating Computer Security Incident Response Team (CSIRT) of an EU member state and ENISA. 

Detailed guidelines for CRA reporting can be seen here (English) and here (German). 

Personal Data (Digital Twins) Bill in the UK: A bill to curb the creation of digital twins of real people by tech companies is to be debated in the House of Commons, computerweekly.com reports. If passed into law, it would regulate software or algorithms that use personal data to model an individual’s preferences or behaviours, and would require explicit consent before a digital twin of a person could be created. Such models can be used in various ways, but mostly for targeted ads. They are based on data points drawn from lists of friends and contacts on social media, “liked” content, purchasing and streaming histories, etc. 

EU Digital Identity Wallet

access by design

According to a Euronews article, the EU envisages launching the EU Digital Identity Wallet (EUDI Wallet) by the end of 2026. It will be a private digital space, free of charge, where citizens, residents and businesses can store and share personal documents, access private and public services, and sign documents digitally. Reportedly, there won’t be a single digital wallet app for the entire EU.

Instead, each member state has to create its own. These apps will share the same technical standards, allowing users to access their wallets and service providers to deliver services across the EU. 

Digital rights experts warn of privacy and security risks of such apps, where thieves or malicious actors could gain access to citizens’ sensitive information, as well as surveillance risks by governments and private actors, through centralised infrastructures. 

Read which EU countries are actively preparing for the initiative (and which are not) in the original publication

Meta AI glasses 

access by design

Hamburg’s Data Protection Commissioner presents a technical and data protection audit report (available in English). The review concludes that, from a data protection perspective, recording individuals who are not part of a person’s close circle of friends and family will generally not be permissible, except in rare cases involving legitimate interest, since informed consent cannot realistically be obtained due to a lack of transparency. 

If Meta AI’s training is not objected to, the legal assessment changes significantly. An additional legal basis is required for the transfer of third parties’ personal data to Meta for the purpose of AI training. This leads to further transparency requirements, particularly since third parties generally do not expect that recordings will be permanently incorporated into Meta’s AI models. 

Within the framework of legitimate interests, the rights and freedoms of the affected third parties generally outweigh Meta’s interest in training. Furthermore, users cannot invoke the household exemption. Rather, they become joint controllers with Meta with respect to the training data.

GDPR claims and compensation

The Latvian DVI explains that, for a person to be able to go to court and claim compensation for damage caused by a personal data protection breach, it is not necessary to first receive a decision from a supervisory authority. The decision of the supervisory authority and the recovery of compensation are two different issues. The supervisory authority assesses whether personal data protection provisions have been breached, while the issue of compensation is related to whether the individual has suffered damage as a result of the breach and what the extent of the damage is.

A personal data breach also does not automatically give rise to compensation. The CJEU has stated that the purpose of compensation is to compensate for the actual damage suffered, not to punish the controller. According to internationally accepted methodologies, a leak of general personal data, such as name, surname and email address, is generally not considered to be a high-impact event if the data itself does not reveal, for example, the financial situation of the individual and does not include special categories of personal data. 

In other news

US drivers’ data on the dark web: A new identity theft service launched on the dark web in September is selling digital scans of more than 153 million drivers’ licenses from people in the US and Canada, KrebsOnSecurity blog reports. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely used identity verification company based in Louisiana.

The New Orleans field office of the Federal Bureau of Investigation (FBI) has launched an official inquiry into the source of the images. 

Schufa shadow database: Privacy protection group NOYB recently sent a cease-and-desist letter to SCHUFA regarding its shadow database. At the same time, the group announced that it would bring an injunction should the credit reference agency refuse to comply with the requests set out therein. It appears that in a public statement, SCHUFA has rejected the allegations. Therefore, NOYB is planning to file for an injunction. People can also still express their interest in a potential class action here

Receive our digest by email

Sign up to receive our digest by email every 2 weeks

Enforcement decisions

Banco Bilbao fine: Banco Bilbao Vizcaya Argentaria Italia (BBVA) has been fined over 5.5 million euros, following a complaint from a customer. Despite expressing his opposition to receiving commercial communications via the app and subsequently reiterating his refusal to do so to customer service, he continued to receive promotional messages. A technical error, according to the bank, prevented the correct alignment between company systems and the platform responsible for managing commercial communications to customers.  

Italy’s Garante regulator emphasises that it’s not enough for a customer’s “no” to be recorded by a system if the organisation is then unable to ensure its effective implementation. Compliance with privacy regulations, therefore, cannot stop at a single app or database. Different company systems must be able to communicate effectively, and procedures must ensure that the customer’s choice is respected throughout all phases of data processing. 

Hospital fine: The French CNIL fined Hôpital Privé de la Loire 500 000 euros. A cyber attacker connected to the electronic system which centralises all the data of individuals under care. They thus accessed the data of 524 867 patients and 202 246 persons designated as “trusted third parties”. It appears that the authentication procedure to connect to the system, used by users outside the hospital, in particular doctors not affiliated with the institution, was not sufficiently robust, due to the lack of VPNs and multifactor authentication. 

Moreover, the access control policy was inadequate. It did not take into account the concept of a care team, so that only professionals actually involved in the treatment of a patient had access to the information covered by medical confidentiality.  

And Finally

Space race: Privacy International tried to find out who owns satellite observation data, and who benefits from it. The modern satellite ecosystem illustrates how corporate power, state backing, and dual-use narratives have created an environment in which satellites are becoming critical infrastructure for the provision of essential civilian services while simultaneously serving as strategic military assets, making the commercial companies behind them increasingly “too central and too big to regulate”.

Satellite networks now span multiple jurisdictions, blending commercial, civilian, and military functions in ways that traditional oversight frameworks were never designed to manage, PI concludes. This requires:

  • stronger human rights due diligence throughout the development, deployment, and operation of satellite technologies;
  • transparent procurement and contracting processes for public authorities; and
  • auditable documentation that clearly defines how companies access, process, retain, and share data generated through their systems. 

Do you need support on data protection, privacy or GDPR? TechGDPR can help.

Request your free consultation

Tags

Show more +