Hello,

the Digital Policy Alert added new events. Please find a brief overview below.

Best regards,

the DPA Team

Latest Events

European Union

July 9, 2026 | Civil Lawsuit Ruling | Data Governance

Court of Justice ruled paid online publication of criminal conviction data does not qualify as a journalistic purpose and cannot be excluded from General Data Protection Regulation remedies

On 9 July 2026, the Court of Justice of the European Union (CJEU) delivered its judgment concerning the dispute over the online publication, in return for payment, of personal data relating to criminal convictions through the Lexbase database (C-199/24, Legal Newsdesk Sweden). The CJEU ruled that Article 85 of the General Data Protection Regulation (GDPR) does not treat such a publication as processing carried out for journalistic purposes. This applies where the content has not been prepared according to ethical rules or an editorial policy and has not undergone verification or editing. It clarified that personal data are processed for journalistic purposes only where the aim is to inform the public or disclose opinions or ideas, where the content follows an editorial policy, and where the underlying facts have been verified. According to the CJEU, holding otherwise would allow any company to invoke journalistic purposes merely by publishing information online, stripping the GDPR of practical effect in cases involving sensitive personal data such as criminal convictions. It added, however, that Member States may still adopt exemptions under Article 85 for purposes other than journalistic, academic, artistic or literary expression, within the limits set by the regulation itself. The CJEU further held that Member States cannot limit a data subject's only available remedy to criminal or civil defamation proceedings. Articles 77, 78, 79 and 82 of the GDPR grant remedies that must be exercisable directly, independent of any national constitutional protection for freedom of expression.

July 17, 2026 | Inquiry Closure | Data Governance

European Data Protection Board issued recommendation on establishing a legal basis for cross-regulatory information sharing

On 17 July 2026, the European Data Protection Board (EDPB) called upon the European Commission to propose a legal basis for cross-regulatory information sharing. The EDPB made the call at a high-level meeting held in Dublin on 16 and 17 July 2026. The call concerns cooperation between regulators operating in adjacent areas of competence under European Union law. The legal basis sought by the EDPB would enable those regulators to exchange information, including confidential information, relevant to enforcement within their respective areas of competence. The EDPB aims for the legal basis to remove barriers to cooperation and to improve enforcement outcomes and cross-regulatory coherence. At the same meeting, the EDPB addressed the consistency and enforcement of the General Data Protection Regulation (GDPR). The EDPB noted a rise in the number and complexity of complaints, attributed in part to the increased use of artificial intelligence, which places strain on the resources of Data Protection Authorities (DPAs). The EDPB set out practical measures to strengthen cross-border enforcement, including greater use of joint operations, the pooling of resources between DPAs and the possibility for complaint-receiving authorities to make resources available to lead supervisory authorities. The DPAs will organise a series of workshops on enforcement procedures and on the exchange of information on national practices, in the context of the implementation of the Regulation laying down additional procedural rules relating to the enforcement of the GDPR. The EDPB also reviewed the follow-up to its 2025 Helsinki Statement on enhanced clarity, support and engagement. Any legal basis would follow a legislative proposal by the European Commission.

France

July 16, 2026 | Investigation Interim Ruling | Authorisation, Registration And Licensing

National Gaming Authority ordered blocking of Polymarket for alleged unauthorised operation of a prediction market platform in France

On 16 July 2026, the President of the National Gaming Authority (ANJ) ordered French internet service providers to block access to Polymarket, a prediction market operated by Adventure One QSS Inc. through the websites www.polymarket.com and polymarket.com. The ANJ classified Polymarket as an unauthorised gambling offer and found that the Polymarket homepage, which displays live odds for events open to betting, promotes that unauthorised offer. Under French law, advertising an unauthorised gambling or betting site is a criminal offence punishable by a fine of EUR 100'000, and the same penalty covers disseminating the odds of unauthorised sites to the public. The ANJ had flagged Polymarket as a possible unauthorised gambling offer since November 2024, and following a first formal notice Adventure One QSS introduced a geoblock preventing financial transactions from French territory, which was circumvented in practice. In February 2026, the ANJ reiterated that prediction market sites are not authorised in France and are treated as illegal gambling sites. On 4 May 2026, the cybercrime section of the Paris public prosecutor opened an investigation, entrusted to the Anti-Cybercrime Office (OFAC), into suspected tampering with weather probes used to settle weather bets, which revealed the absence of a user identification (know your customer) mechanism on the Polymarket platforms available to the French and European public. Polymarket recorded 578'751 visits and 205'057 unique visitors from France in June 2026. On this basis, the ANJ exercised its administrative blocking power, under which it blocked 1'290 URLs in 2025.

You are receiving this message, because you are subscribed to Digital Policy Alert notifications.

Update your subscription settings here.

To unsubscribe from this and any other DPA notification services, please click here.