The Tech Counsel - July 2026
Welcome to the July edition of The Tech Counsel — in this month’s issue we take a look at a broad set of developments shaping technology, data protection and platform regulation in Europe and beyond. We cover new regulatory guidance for the video game industry, fresh EDPB guidance on anonymisation, web scraping and blockchain, important GDPR case law, DSA and DMA enforcement against major platforms, evolving rules for e-commerce and cookie consent, and emerging international approaches to AI, child safety and data transfers.
Artificial Intelligence
Digital Omnibus on AI finally signed
On 8 July 2026, the Presidents of the European Parliament and the Council formally signed the Digital Omnibus on AI, which updates and modernises the original EU AI Act as part of the broader Digital Omnibus package aimed at simplifying regulations and reducing administrative burdens.
The compliance deadlines for the strictest obligations have been extended to 2 December 2027 for standalone high-risk AI systems, and 2 August 2028 for AI systems embedded as safety components in other products. The Omnibus introduces a strict, accelerated prohibition (from 2 December 2026) on AI systems that generate child sexual abuse material or non-consensual intimate imagery of real individuals, and a four-month transition period for machine-readable watermarking of AI-generated content. Permission to process sensitive personal data to detect and correct bias has been expanded from high-risk providers to all providers of AI systems and general-purpose AI models, and the obligation to train staff on AI literacy has been eased.
EDPB issues new guidance on AI data scraping, anonymisation and blockchain
On 8 July, the EDPB issued three measures reshaping how organisations approach data protection in AI development and distributed technologies.
Anonymisation: the guidance clarifies when data qualifies as truly anonymous by focusing on whether individuals can be isolated, linked to other datasets, or reidentified through inference. It incorporates the Court of Justice’s reasoning in Case C-413/23 P (EDPS v SRB) and adopts a relative, context-based test — the bar is fact-specific, not categorical.
Web scraping for generative AI: the guidelines detail the requirements for relying on legitimate interest as the legal basis for scraping data to train generative AI, including scraping only from reliable sources, data minimisation, and recognising that processing special categories of data is in principle prohibited absent both an Article 6 basis and an Article 9(2) exception. Both draft guidelines were open for consultation until 30 October 2026.
Blockchain: the final guidelines confirm that storing personal data on-chain should be avoided wherever it conflicts with GDPR principles, that on-chain identifiers such as wallet addresses can qualify as personal data, and that technical impossibility cannot excuse non-compliance. A DPIA is mandatory before implementation.
Canada’s Safe Social Media Act
Canada introduced Bill C-34, the Safe Social Media Act, aimed at making social media services and AI-powered chatbots safer for children. The bill establishes age-appropriate design obligations and, significantly, extends regulatory coverage to AI chatbots — a category not comprehensively addressed by most existing child-safety frameworks — through three core duties: the Duty to Protect Children, the Duty to Act Responsibly, and the Duty to Make Certain Content Inaccessible.
German court finds Google’s AI Overview is a “publisher”
The Regional Court of Munich I issued a landmark ruling (Case No. 26 O 869/26, 28 May 2026) holding that Google is directly liable as a “publisher” for defamatory content generated by its AI Overview feature. The court found that AI Overview content constitutes Google’s own speech, not merely an aggregation of third-party content, because it independently synthesises, structures and presents information in a way that creates new statements not found in the underlying sources. The court rejected Google’s reliance on the DSA hosting safe harbour. The ruling remains subject to appeal but is an important precedent for AI content liability.
Google expands AI training on user data
Google changed its privacy settings to use data from services such as Search, Gmail and Docs to train its generative AI systems. Available opt-out controls are fragmented across multiple interfaces, and data already collected may have been used for training before any opt-out. For EU users, the GDPR’s requirements around lawful basis, purpose limitation, and transparent disclosure apply directly, and the EDPB’s guidance underscores that training generative AI on personal data triggers the full suite of GDPR obligations.
Privacy
US Supreme Court ruling raises questions for the EU-US Data Privacy Framework
In Trump v. Slaughter, the US Supreme Court held that the FTC Act’s for-cause removal protection for FTC commissioners is unconstitutional. Because the Commission’s adequacy decision for the Data Privacy Framework relies on the FTC as an enforcement body for the commercial pillar, privacy advocates argue the ruling undermines the framework’s independence safeguards. There has been no formal EU finding that the DPF is invalid; organisations may continue relying on it, but should maintain fallback mechanisms such as Standard Contractual Clauses.
Member states and Google push to preserve cookie consent banners
A coalition of EU member states, supported by Google, is advocating to retain the current cookie consent framework, opposing privacy advocates who argue banners cause “consent fatigue.” While the Commission initially wanted to abolish banners under the Digital Omnibus and replace them with an automated signal, the Council’s June position paper indicates the banners will remain.
First EU regulatory guidance targets data protection in video games
In June 2026, the Spanish (AEPD) and Belgian (APD) authorities jointly published Recommendations and Best Practices for Data Protection in Video Games — the first regulatory guidance specifically targeting the video game industry. The 104-page document positions privacy by design and by default as non-negotiable, insists on rigorous GDPR role mapping across publishers, developers, platforms, ad networks and analytics providers (including the “Russian dolls” problem of nested SDKs), and subjects monetisation mechanics such as loot boxes to heightened scrutiny. Protections for minors run throughout the framework.
EDPB and AMLA to develop joint guidelines on data sharing for AML
The EDPB and the newly established Anti-Money Laundering Authority announced a partnership to develop joint guidelines on data sharing for anti-money laundering purposes, addressing longstanding tensions between privacy compliance and financial crime prevention. The legal basis is Article 75 of the AML Regulation, applicable from 10 July 2027, with a public consultation planned for the first half of 2027.
EDPB case digest on the right to object and right to erasure
The EDPB released a case digest synthesising one-stop-shop decisions concerning the right to object (Article 21) and the right to erasure (Article 17). Key themes include treating the two rights as closely linked, ensuring rights are easy to exercise, requesting additional identification only where there is reasonable doubt, and recognising that erasure may be required even without a formal request. The right to erasure is not absolute, but retention exceptions must be necessary for a specific legal purpose and clearly explained.
CJEU rules GDPR breach does not automatically exclude evidence
In NTH Haustechnik GmbH v EM (Case C-484/24), the CJEU confirmed that GDPR compliance remains relevant in litigation but does not create an automatic evidence-exclusion rule. National law governs the admissibility of evidence, subject to EU-law principles of proportionality and data protection. Employers should ensure HR files, investigation materials and device logs are retained under clear litigation-hold rules rather than indefinite “just in case” practices.
EU Council moves to reinstate interim CSAM measures
The Council took steps to reinstate interim measures for combating child sexual abuse material online, extending obligations for electronic communications providers while negotiations on the comprehensive “Chat Control” framework continue. The extension preserves the status quo but does not resolve the underlying disputes over encryption and mass surveillance.
Other digital topics
Commission preliminarily finds Instagram and Facebook in DSA breach
The Commission issued preliminary findings that Meta violated the DSA through the “addictive design” of Instagram and Facebook. The two-year investigation concluded that Meta failed to properly assess the risks its platform design imposes on users’ wellbeing, particularly for minors, identifying features such as personalised recommendations, autoplay and infinite scroll. If a final infringement decision follows, fines may reach up to 6% of Meta’s total worldwide annual turnover.
EU’s new “withdrawal button” changes e-commerce
From 19 June 2026, online shoppers across the EU can cancel an online purchase as easily as they made it. Directive (EU) 2023/2673 introduces a new Article 11a requiring traders to provide a dedicated “withdrawal function” — a prominent button labelled “withdraw from contract” that remains visible throughout the withdrawal period. The obligation applies broadly to distance contracts for which EU law grants a right of withdrawal, and to non-EU businesses directing activity at EU consumers.
Apple loses EU court challenge to DMA gatekeeper designation
The General Court dismissed Apple’s challenge to its designation as a gatekeeper under the DMA, affirming the Commission’s authority to subject the company to the regulation’s obligations, including enabling alternative app distribution, prohibiting self-preferencing, and ensuring interoperability. The judgment confirms that procedural challenges to gatekeeper designations face a high bar.
Commission preliminarily finds AWS and Azure should be DMA gatekeepers
The Commission published its preliminary view that Amazon Web Services and Microsoft Azure should be designated as gatekeepers in relation to their cloud computing services, notwithstanding that they do not meet the DMA’s quantitative thresholds, on the basis that they act as important gateways with entrenched positions, high switching costs and large surrounding ecosystems. Both companies retain their rights of defence before any final decision.