Data Protection & Privacy Regulations (GDPR)·Denmark·Datatilsynet·7 days ago
Datatilsynet: adequacy-country transfers need no further exporter measures, while Article 46 SCC/BCR transfers require a prior TIA, aided by the CNIL guide and EDPS checklist.
Digital Operational Resilience (DORA)·Estonia·Finantsinspektsioon·2 weeks ago·4 documents
The DORA information-register round is collected in early 2027 as of 31 December 2026, and a new section sets threat-led testing under the TIBER-EE national guide.
Cloud Computing & Data Sovereignty Rules·France·Légifrance·2 weeks ago
Hosted health-data storage must sit exclusively in the EU/EEA, contracts gain compelled-transfer disclosure clauses, and hosts must publish a live map of third-country transfers and remote access.
Electronic Records & Digital Evidence Standards·France·Légifrance·2 weeks ago
Polynesian communes go paperless on PES v2+: three signature options, probative electronic data, and a tripartite convention with suspension fallbacks.
Digital Operational Resilience (DORA)·Estonia·Finantsinspektsioon·2 weeks ago
Finantsinspektsioon's recommended TIBER-EE guide in force since 15 September 2026 sets the national playbook for DORA threat-led penetration testing, with voluntary use subject to prior coordination.
Data Protection & Privacy Regulations (GDPR)·European Union·EUR-Lex·3 weeks ago
Advocate General Spielmann opines in Case C-317/25 that ISP 'partners' consent cannot support Groupe Canal +'s marketing without fresh consent, proposing the Court answer the first question accordingly.
Digital Operational Resilience (DORA)·Germany·Rechtsprechung des Bundes·4 weeks ago·3 documents
BaFin ordinance of 26 August 2026 (BGBl I Nr. 256) extends the audit report to DORA ICT duties for Wertpapierinstitute and crowdfunding providers, first for years starting after 31 Dec 2024.
Digital Operational Resilience (DORA)·Norway·Finanstilsynet·1 month ago
From 1 September 2026, financing, debt-collection and estate-agency firms face adapted DORA requirements. The supervisor specifies temporary incident-reporting channels.
Cybersecurity Laws & NIS2 Framework·Estonia·Riigi Teataja·1 month ago
The new regulation preserves compatible existing security measures and allows pre-existing compliance documentation to remain valid for up to three years.
Data Protection & Privacy Regulations (GDPR)·Finland·Finlex·1 month ago
KHO upheld the consent order. Visiting a news site did not amount to expressly requesting content personalised through tracking and analysis.
Data Protection & Privacy Regulations (GDPR)·Finland·Finlex·1 month ago
The design steered users towards acceptance. Following IAB Europe’s TCF standard did not prove compliance with cookie rules.
Data Protection & Privacy Regulations (GDPR)·Sweden·Regeringskansliets rättsdatabaser·1 month ago
From 2 January 2027, the scope includes partly publicly funded private activities under Lag (2026:1637); the duty covers technical processing and storage, including subcontractors.