If a DSAR is made solely to engineer a compensation claim rather than to verify lawful processing, it can be refused as abusive – even if it's the first request.
A breach happens. What now? When are you "aware", how do you assess the risk – and who do you need to notify? 📝 Homework: download the revised breach flowchart, tailor it to your organisation and ensure you have a step-by-step process in place.
💡 EDPB only to do a "targeted update" to DPO Guidelines | "Easing compliance is at the top of the EDPB agenda" – lets see how that plays out in practice.
2025 report ready | 2026 topic: 📝 transparency & information | The EDPB created the CEF initiative under its 2021-2023 Strategy to enhance enforcement and strengthen cooperation among DPAs. Each year, they collectively choose a priority enforcement topic for coordinated (voluntary) action.
🇩🇰 DPA concludes the case, applies the dreaded EDPB Opinion and signal enforcement change – and shares takeaways in webinar. Must-read if you're in Denmark but crucial to everyone using third-country processors, especially US ones.