Hello,
the Digital Policy Alert added new events. Please find a brief overview below.
Best regards,
the DPA Team
May 27, 2026
| Order Consultation Closed | Data Governance
On 27 May 2026, the European Commission closes its consultation on the draft implementing regulation laying down the implementation arrangements for the digital product passport registry set up under Regulation (EU) 2024/1781. The draft requires each verified economic operator to maintain accurate, complete, and up-to-date registration data in the registry and to update it following any relevant change, including changes to its legal representative. Verified economic operators may delegate access rights to users acting on their behalf, but remain fully responsible for all actions carried out by those users. Each Member State must appoint a designated national administrator as the single official contact point with the Commission for managing registry access rights, with authority to delegate those rights to relevant national authorities. The Commission acts as controller under Regulation (EU) 2018/1725 when processing personal data, which includes names, authentication credentials, postal addresses, email addresses, metadata embedded in uploaded documents, and personal identifiers such as passport numbers and national eID numbers. Personal data may only be used for managing registry access and must be deleted upon account removal or revocation of access, unless retention is required under Union law. Member States processing personal data for their duties are regarded as controllers under Regulation (EU) 2016/679. The Commission must prepare an IT Security Plan, conduct technical audits and random checks, log all security events, and may suspend registry availability without prior notice in the event of a malfunction, cyber-attack, or urgent security need. Records of outages must be retained for at least five years. The registry must comply with the Cloud Sovereignty Framework. Identity verification requires qualified electronic signatures, seals, or attestations under Regulation (EU) No 910/2014, with verified status valid for up to three years. Unrenewed operators lose the capacity to register new digital product passports. The draft applies to products under Regulation (EU) 2024/1781, Regulation (EU) 2023/1542, Regulation (EU) 2024/3110, Regulation (EU) 2025/2509, and Regulation (EU) 2026/405. The Commission must also establish a semantic repository serving as an authoritative, machine-readable source for data models, semantic definitions, and vocabularies, developed in accordance with Regulation (EU) 2024/903, accessible via publicly documented application programming interfaces (APIs) supporting common data formats, free of charge.
May 27, 2026
| Law Drafting | Authorisation, Registration And Licensing
On 27 May 2026, the European Commission proposed a Regulation on the procedure for authorisation of systems providing mobile satellite services (MSS) using the harmonised 2 GHz frequency band and repealing Decision No 626/2008/EC (COM(2026) 311 final). The proposed Regulation establishes a Union-level comparative selection procedure to grant rights of use of the 2 GHz MSS band, comprising the 1,980–2,010 MHz band for Earth-to-space communications and the 2,170–2,200 MHz band for space-to-Earth communications, and to authorise selected undertakings to provide MSS systems or hybrid systems under common conditions across all Member States, repealing Decision No 626/2008/EC under which two operators were authorised until May 2027. The available spectrum is divided into six paired blocks of 5 MHz: two reserved for a secure MSS or hybrid system providing secure governmental communications services, two reserved for Union new entrants, and two open to all applicants, subject to a spectrum cap of a paired block of 10 MHz per commercial operator. Admissibility requirements for the secure MSS or hybrid system restrict eligibility to undertakings controlled exclusively by the Union, one or more Member States, or nationals of Member States only, and not subject to third-country jurisdiction. All applicants must commit to covering at least 95% of the population and 90% of the aggregate land area of each Member State within five years of commencing continuous provision of MSS and must route all traffic from Union-based end-users within Union territory. The holder of the authorisation for the secure MSS or hybrid system must integrate with the Union's Infrastructure for Resilience, Interconnectivity and Security by Satellite (IRIS²) programme. Rights of use are granted for 20 years, renewable once. The Commission may impose fines of up to 5% of total worldwide annual turnover for breaches and may withdraw Union authorisations for serious or persistent non-compliance. The proposed Regulation affects satellite operators seeking rights to use the 2 GHz MSS band, including incumbents Viasat and Echostar, Union new entrants, and third-country commercial applicants. Governmental users — Union and Member State public authorities receiving secure communications services for crisis management, law enforcement, public safety, and defence — are also affected. Member State competent authorities are affected in their monitoring and enforcement role, as spectrum authorisation moves to Union level.
May 26, 2026
| Investigation Ruling | Data Governance
On 26 May 2026, the National Commission for Informatics and Liberty (CNIL) imposed an administrative fine of EUR 5 million on IQVIA Operations France for breaches of Article 66 of Law No. 78-17 of 6 January 1978 relating to information technology, data files and freedoms (the Data Protection Act) and Articles 14 and 25 of Regulation (EU) 2016/679 (the GDPR). IQVIA Operations France operates two health data warehouses authorised by the CNIL, the Longitudinal prescription data warehouse (LRX) and the Electronic medical records warehouse (EMR). Breaches of Article 66 of the Data Protection Act were established for failure to implement network segmentation and regular log analysis for the LRX warehouse, provision of inaccurate patient information on data retention periods for the EMR warehouse, absence of an effective right-to-object mechanism for the EMR warehouse, and failure to implement strong authentication and network segmentation for the EMR warehouse. A further Article 66 breach was established for conducting studies from the LRX warehouse without CNIL authorisation or compliance with reference methodology MR-004. A breach of Article 14 of the GDPR was established for failure to ensure partner pharmacies provided patients with individual information notices. A breach of Article 25 of the GDPR was established for systematic transmission of patient data from non-participating pharmacies. The CNIL also issued a compliance injunction with a penalty of EUR 10,000 per day of delay after six months.