Data Protection Newsletter – Issue 22

Welcome to our latest Data Protection Newsletter, where we explore key data protection and AI developments. This edition covers essential updates and insights to help your organisation stay compliant and informed.
Data Protection Newsletter – Issue 22.png

In this issue, we cover:

EU–US Data Privacy Framework

The European General Court upheld the EU–US Data Privacy Framework, confirming that US laws allow only targeted data collection and that the DPRC meets EU independence standards. This provides certainty for over 3,000 US companies, though further challenges are expected. Organisations should still consider SCCs and DTIAs as alternatives.

EU Data Act now in force

Effective from 12 September, the EU Data Act sets rules for fair access and sharing of data from connected devices. It applies to manufacturers, service providers and cloud providers, giving users rights to access and share data. Businesses should review obligations under the Act.

UK Data (Use and Access) Act 2025

The UK has introduced changes to UK GDPR, including a new lawful basis for “recognised legitimate interests”, broader research consent and updated SAR rules. International transfer provisions and enforcement fines have also been revised. Organisations should review compliance in these areas.

GDPR Omnibus proposals

Proposed amendments aim to ease compliance for small and mid-cap enterprises by extending record-keeping exemptions and updating codes of conduct and certification schemes. Organisations should continue operating under current GDPR until changes are confirmed.

Recent fines

The DPC fined CDETB €125,000 for breach notification failures, TikTok €530 million for unlawful transfers to China, and DSP €550,000 for biometric data issues. These cases highlight the need for strong breach management, transparency and robust DPIAs.

Preparing for Ireland’s auto enrolment pension reform

From January 2026, MyFutureFund will automatically enrol eligible employees into pension schemes. Employers and employees will contribute equally, with government top-ups. Employers must register with NAERSA in December 2025 and prepare payroll systems now.

Document

Data Protection Newsletter – Issue 22

Contact