🇪🇺 Parliament and Council didn't reach agreement on sectoral regulations – new trilogue in two weeks | Check out the NIST AI Risk Management Framework (linked under 'Various updates/resources')
"But wait, there's more..." Is the EU really living up to its simplification promises? Added the Commission's work program for 2026, and links to 'Cloud and AI development Act' + 'Quantum Act'.
A breach happens. What now? When are you "aware", how do you assess the risk – and who do you need to notify? 📝 Homework: download the revised breach flowchart, tailor it to your organisation and ensure you have a step-by-step process in place.
10 Oct: Estonia's thresholds for 'large-scale' (5k, 10k, 50k) | Breaking down Article 37(1)(b) key terms: 'core activities', 'regular', 'systematic', 'monitoring' and 'large scale'. And what should you do if you're still unsure whether you need to appoint a DPO? Appoint one voluntarily?
NB: On 9 July, CNIL appears to have updated the webpage with that date, though there don’t seem to be any actual changes – and the PDFs are still from January. Either way, here’s a quick reminder! 💬 "CNIL TIA template is one of the best templates available to the public!"