Hello,

the Digital Policy Alert added new events. Please find a brief overview below.

Best regards,

the DPA Team

Latest Events

European Union

June 29, 2026 | Law Adoption | Data Governance

Council of the European Union adopted Digital Omnibus on AI Regulation (2025/0359) including data protection regulation for "high-risk" AI systems

On 29 June 2026, the Council of the European Union adopted the Regulation on the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI Regulation). The Regulation would extend the legal basis for processing special categories of personal data for bias detection and correction. Under the AI Act (Regulation (EU) 2024/1689), this legal basis applied only to providers of high-risk AI systems. The Regulation would extend it to deployers of high-risk AI systems and to providers and deployers of other AI systems and models, where processing is strictly necessary and subject to appropriate safeguards. The Regulation would also set fixed application dates for data governance obligations: obligations for AI systems listed in Annex III of the AI Act would apply from 2 December 2027, and obligations for AI systems covered by Article 6(1) of the AI Act would apply from 2 August 2028. The Regulation will enter into force 3 days after its publication in the EU’s Official Journal.

June 29, 2026 | Law Adoption | Authorisation, Registration And Licensing

Council of the European Union adopted Digital Omnibus on AI Regulation (2025/0359) including changes to business registration requirement for "high-risk AI systems"

On 29 June 2026, the Council of the European Union adopted the Regulation on the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI Regulation). The Regulation would require providers that consider their AI systems to be exempt from classification as high-risk to register those systems in the EU database for high-risk AI systems. The Regulation would also simplify the content of registration notifications under Article 49(2) of the AI Act. SME exemptions from certain requirements would be extended to small mid-cap enterprises (SMCs), defined by reference to Commission Recommendation (EU) 2025/1099. The Regulation will enter into force 3 days after its publication in the EU’s Official Journal.

June 29, 2026 | Law Adoption | Data Governance

Council of the European Union adopted Digital Omnibus on AI Regulation (2025/0359) including cybersecurity requirements for "high-risk AI systems"

On 29 June 2026, the Council of the European Union adopted the Regulation on the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI Regulation). The Regulation would set fixed application dates for cybersecurity obligations for high-risk AI systems: obligations for Annex III systems would apply from 2 December 2027 and obligations for Article 6(1) systems would apply from 2 August 2028. The Regulation would clarify the relationship between the cybersecurity requirements of the AI Act (Article 15 of Regulation (EU) 2024/1689) and those of the Cyber Resilience Act (Article 12 of Regulation (EU) 2024/2847): for high-risk AI systems in products covered by the Cyber Resilience Act, the requirements of the Cyber Resilience Act would apply in place of those of the AI Act. The Machinery Regulation (EU) 2023/1230 would be exempt from direct applicability of the AI Act, with the Commission empowered to adopt delegated acts adding health and safety requirements for high-risk AI systems by 2 August 2028. The Regulation will enter into force 3 days after its publication in the EU’s Official Journal.

G7

June 26, 2026 | Declaration Adoption | Data Governance

G7 Data Protection and Privacy Authorities adopted statement on privacy-preserving age assurance

On 26 June 2026, the Data Protection and Privacy Authorities of Canada, France, Germany, Italy, Japan, the United Kingdom, and the United States jointly adopted a statement on privacy-preserving age assurance within the G7 framework. The statement addresses online service providers that implement age assurance mechanisms, defined as technical solutions used to verify or estimate the age of users, including age verification and age estimation approaches. The statement sets out seven data protection principles for the design and deployment of age assurance mechanisms. These principles cover lawfulness and transparency, purpose limitation, data minimisation, privacy by design and by default, security, data retention limitation, and accountability. The principles draw on existing data protection frameworks applicable across G7 jurisdictions, including the General Data Protection Regulation, Canada's Personal Information Protection and Electronic Documents Act, and the United States Children's Online Privacy Protection Act. The statement builds on the G7 Data Protection and Privacy Authorities Action Plan of 19 June 2025 and references the Joint Statement on a Common International Approach to Age Assurance of 19 September 2024, the European Data Protection Board statement on age assurance of 12 February 2025, and the joint statement of the United Kingdom's Information Commissioner's Office and the Office of Communications on age assurance of 25 March 2026.

You are receiving this message, because you are subscribed to Digital Policy Alert notifications.

Update your subscription settings here.

To unsubscribe from this and any other DPA notification services, please click here.