Hello,
the Digital Policy Alert added new events. Please find a brief overview below.
Best regards,
the DPA Team
March 26, 2026
| Law Rejection | Data Governance
On 26 March 2026, the European Parliament rejected the proposal to extend Regulation (EU) 2021/1232 on derogation from the ePrivacy Directive until 2028. This regulation sets out interim rules on data processing for the purpose of combating online child sexual abuse material (CSAM). The regulation would have temporarily derogated from the ePrivacy Directive, enabling providers of online communication services to voluntarily detect, report, and remove CSAM. The Commission proposed extending this interim framework, due to expire on 3 April 2026, until 3 April 2028. The European Parliament adopted an alternative extension proposal on 11 March 2026 to extend the deadline until 3 August 2027.
March 11, 2026
| Law Amendment | Data Governance
On 11 March 2026, the European Parliament amended the proposal to change the extension date of Regulation (EU) 2021/1232 on derogation from the ePrivacy Directive from 2028 to 2027. This regulation sets out interim rules on data processing for the purpose of combatting online child sexual abuse material (CSAM). The Regulation would temporarily derogate from the ePrivacy Directive, enabling providers of online communication services to voluntarily detect, report, and remove CSAM. The Commission had proposed extending this interim framework, due to expire on 3 April 2026, until 3 April 2028.
March 25, 2026
| Inquiry Closure | Data Governance
On 25 March 2026, the Global Privacy Enforcement Network (GPEN) published a sweep report examining children's privacy practices across 876 websites and applications. The inquiry found that, while age assurance use has increased since 2015, 88% of platforms relied solely on easily circumvented self-declaration methods. It also highlighted that data collection has intensified, with 85% of privacy policies disclosing third-party data sharing, up from 51% a decade ago. It also found that only 56% of platforms set personal information to private by default, and 71% lacked child-friendly privacy communications, with parental dashboards present on only 25–35% of platforms featuring high-risk content or design features. Further, mobile applications were assessed as less safe than websites, and free services raised greater concerns than paid ones, reflecting differences in data-driven monetisation incentives. It also found that account deletion has improved, with 64% of platforms now offering an accessible process compared to just 29% in 2015.