The GDPR still sets the template most other privacy regimes borrow from, and its enforcement record is now deep enough to show what supervisory authorities actually punish. This hub covers fines, EDPB guidance, and lawful-basis disputes with an eye to US businesses in scope.
UK Data Protection
September 7, 2026
The Data (Use and Access) Act 2025 is a nine-part statute covering smart data schemes, digital identity, buried pipes, birth registers, data protection, a new regulator and much else. Its commencement is the part most easily got wrong: Royal Assent brought almost none of it into force, and a reader working from the Act alone cannot tell what is law today.
Read more →
Cross-Border Transfers
September 1, 2026
The adequacy decision underpinning EU-US data transfers has been through one court challenge and one periodic review. This post states the status of Implementing Decision 2023/1795 by its own terms, describes the redress mechanism it relies on, and takes the posture of the legal challenge from the General Court's judgment and the notice of appeal rather than from commentary.
Read more →
Cross-Border Transfers
August 24, 2026
Chapter V of the GDPR restricts transfers of personal data out of the EEA without ever saying what a transfer is. The European Data Protection Board filled the gap with a three-part test, and the machinery built on top — adequacy, standard clauses, impact assessments — now has imitators worldwide that share its vocabulary but not its logic.
Read more →
GDPR
August 12, 2026
The GDPR reaches companies with no European office, no European entity and no European staff. Article 3 ties application to conduct rather than to presence. This guide covers the two extraterritorial triggers, the six lawful bases, what data subjects can require, the transfer rules, and the fine structure that makes the analysis matter.
Read more →