
Annual Report of the Czech Data Protection Authority for 2025
The annual report of the Czech Data Protection Authority (ÚOOÚ) for 2025 shows that the authority perceived the past year primarily as a period marked by the strong emergence of new digital regulation and growing demands in terms of methodological, legislative and supervisory activities. In addition to inspections and decision-making practice, the report also highlights the significant methodological and awareness-raising role of the authority — in 2025, the authority received 219 requests for opinions, issued 168 sets of comments, and recorded exceptional interest in expert seminars, including a record-attended seminar on CCTV systems in schools.
Brazil now “without SCCs”: the EU has expanded the map of safe data transfers
On 26 January 2026, the European Commission adopted an adequacy decision in relation to Brazil under Article 45 GDPR. In practice, this means that personal data may now be transferred from the European Union to Brazil without additional specific safeguards, including standard contractual clauses, similarly to other countries for which the European Commission has adopted such a decision.
The right to erasure under the GDPR remains a weak spot in corporate practice
In February of this year, the EDPB published the results of its coordinated enforcement action on the right to erasure and pointed out that the overall level of compliance is only average. The most common issues concern unclear internal processes, deletion of data in backups, poor distinction between erasure and account deletion, and insufficient information provided to data subjects.
Transparency under the GDPR will be another major topic in 2026
The findings of the coordinated enforcement action on the right to erasure were followed in March by the EDPB’s launch of a new coordinated enforcement action focusing on transparency and information obligations under the GDPR. This is a clear signal that, in 2026, supervisory authorities will be examining in greater detail how companies explain their processing activities to data subjects and how clearly and effectively they comply with their information obligations.
The dispute over the “simplification of the GDPR” has intensified
In February 2026, the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) issued a joint opinion on the proposed Digital Omnibus. While they supported the effort to simplify digital regulation, improve the clarity of the rules and reduce unnecessary administrative burden, they also strongly warned against certain proposed amendments to the GDPR. Their strongest criticism was directed at the proposal to change the definition of personal data. According to the EDPB and the EDPS, such a change would not merely constitute a technical clarification, but could substantially narrow the concept of personal data and thereby limit the scope of the GDPR. Both bodies also stated that the proposed wording is inconsistent with the case law of the Court of Justice of the European Union and could lead to greater legal uncertainty rather than genuine simplification.
The EDPB aims to make GDPR compliance easier in practice
In February 2026, the EDPB announced that, as part of its 2026–2027 work programme, it would prepare specific templates and practical materials intended to help organisations comply with the GDPR. These are expected to include, for example, templates for legitimate interest assessments, records of processing activities, privacy notices, personal data breach notifications, and data protection impact assessments.
WhatsApp v EDPB: a direct action may be brought against a binding EDPB decision
In February 2026, the Court of Justice of the European Union ruled that a binding EDPB decision under Article 65 GDPR may, in itself, be subject to judicial review. For companies, this means that in cross-border cases they may challenge an EDPB decision directly, rather than having to wait solely for the final decision of the national supervisory authority.
CJEU: the right of access to personal data has its limits
In its Brillen Rottler judgment of 19 March 2026, the Court of Justice of the European Union confirmed that the data subject’s right of access to personal data under Article 15 GDPR is very broad, but not unlimited. A request may exceptionally be considered abusive and the controller may refuse it if it was made solely for the purpose of subsequently bringing a claim for damages for an alleged GDPR infringement. At the same time, the Court stressed that such a conclusion must be assessed restrictively and that, in order to obtain compensation under Article 82 GDPR, actual damage must be proven.
Regulators continue to impose strict penalties for insufficient personal data security
A notable example from the first quarter of 2026 is the decision of the French supervisory authority, the CNIL, which on 13 January 2026 imposed fines totalling EUR 42 million on FREE MOBILE and FREE for failing to ensure an adequate level of security for their customers’ personal data. This case once again confirms that supervisory authorities regard technical and organisational security measures, preparedness for security incidents, and the protection of customer data as one of the key areas on which they have long focused in enforcing the GDPR.
Spring Digital Legal Update 2026 here.