Hello,

the Digital Policy Alert added new events. Please find a brief overview below.

Best regards,

the DPA Team

Upcoming Events

European Union

June 11, 2026 | Law Implementation | Data Governance

Implemented Regulation 2024/2847 amending the Cyber Resilience Act (2020/1828) including notification of conformity assessment bodies

On 11 June 2026, Regulation 2024/2847 on horizontal cybersecurity requirements for products with digital elements, amending Regulations (EU) No 168/2013 and (EU) No 2019/1020 and the Cyber Resilience Act (2020/1828), enters into force. The EU Regulation (2024/2847) on the Cyber Resilience Act aims to enhance the cybersecurity of products with digital elements by establishing uniform cybersecurity requirements across the EU. The regulation applies to all products with digital elements, including hardware and software, that are placed on the EU market, excluding those covered by specific existing regulations, such as medical devices and motor vehicles. Chapter IV outlines the process for notifying and monitoring conformity assessment bodies (CABs) in the EU. Member States designate authorities to assess and notify CABs, ensuring their independence, competence, and impartiality. CABs must meet strict requirements and report to authorities, while the Commission maintains a public list of notified bodies. Coordination and information exchange between Member States and CABs ensure consistency and compliance with the Cyber Resilience Act across the Union.

June 9, 2026 | Order Consultation Closed | Data Governance

European Data Protection Board closes consultation on template for data protection impact assessments

On 9 June 2026, the European Data Protection Board closes the consultation on a template for data protection impact assessments under the General Data Protection Regulation (GDPR). The template applies to controllers undertaking high-risk processing activities, including large-scale processing of special categories of personal data, systematic monitoring of publicly accessible areas, automated decision-making with legal or similarly significant effects on individuals, profiling, matching or combining datasets, and processing involving vulnerable data subjects. It requires controllers to document a systematic description of the processing activity covering data types, purposes, data flows, and supporting technical assets, and analyse lawfulness under Article 6 of the GDPR, including legitimate interests balancing tests where applicable. It also requires controllers to demonstrate compliance with data minimisation, retention, and data quality obligations and detail measures supporting data subjects' rights, data protection by design and by default, and security of processing. Controllers must further assess the necessity and proportionality of the processing, conduct an inherent risk assessment identifying threats arising both from deliberate design choices and from accidental or unlawful events, and develop an action plan setting out additional mitigating measures alongside a residual risk assessment. The template also requires documentation of the Data Protection Officer's advice and, where appropriate, the views of data subjects or their representatives, before concluding with a formal decision to approve, conditionally approve, reject, or refer the processing to the relevant supervisory authority.

You are receiving this message, because you are subscribed to Digital Policy Alert notifications.

Update your subscription settings here.

To unsubscribe from this and any other DPA notification services, please click here.