Hello,
the Digital Policy Alert added new events. Please find a brief overview below.
Best regards,
the DPA Team
July 20, 2026
| Outline Adoption | Data Governance
On 20 July 2026, the National Commission for Information Technology and Civil Liberties (CNIL) and the Council for AI and Digital Technology (CIANum) published a note examining the implications of agentic artificial intelligence for the application of the General Data Protection Regulation (GDPR). The note states that features such as persistent memory and access to external data sources may affect the application of principles including purpose limitation, data minimisation, transparency and storage limitation. It further states that the distributed architecture of agentic systems, involving multiple agents and third-party services, may complicate the allocation of responsibilities and increase security considerations. The note also states that the right not to be subject to solely automated decision-making under Article 22 of the GDPR remains applicable, referring to the Court of Justice of the European Union's SCHUFA judgment. CNIL and CIANum recommend measures including enhanced transparency, human validation for critical decisions, compartmentalised agent memory, sandboxed deployment and user-controlled deactivation mechanisms. The note also states that, while the AI Act will become fully applicable in 2027, it does not contain provisions specific to AI agents.