The Tech Counsel: Monthly Newsletter on Technology Law
Welcome to the first edition of The Tech Counsel — our monthly overview of key legal and regulatory developments across AI, privacy and the broader digital landscape.
Artificial Intelligence
Recent developments on the Digital Omnibus on AI
The Digital Omnibus on AI forms part of the broader Digital Omnibus package published in November 2025, aimed at simplifying EU digital regulation and resolving implementation challenges under the AI Act.
On 7 May 2026, EU lawmakers reached a provisional agreement on the Digital Omnibus on AI following previously unsuccessful trilogue negotiations. The deadlock primarily concerned the regulatory framework for AI systems used in regulated products listed in Annex I, particularly the interaction between the AI Act’s conformity assessment requirements and existing sectoral safety legislation, including the Machinery Regulation and the Medical Device Regulation.
The agreement postpones the application of rules for high-risk AI systems to fixed dates: 2 December 2027 for AI systems with a high-risk use case (Annex III), and 2 August 2028 for high-risk AI systems embedded in regulated products (Annex I). Watermarking obligations under Article 50 are postponed only until 2 December 2026.
The co-legislators also expanded the list of prohibited AI practices to include a ban on AI systems used for generating non-consensual sexual or intimate content, as well as child sexual abuse material, with compliance required by 2 December 2026. The definition of “safety component” has been narrowed, meaning AI systems that merely assist users or optimise performance are not automatically classified as high-risk.
Draft Transparency Code of Practice and Guidelines
The European Commission published the second draft of the Code of Practice on Marking and Labelling of AI-generated content on 5 March 2026, and draft guidelines on implementing transparency obligations under Article 50 of the AI Act on 8 May 2026.
The Code supports providers and deployers in meeting transparency obligations scheduled to apply from 2 August 2026. It introduces a two-layer marking approach consisting of secured metadata and watermarking, complemented by optional fingerprinting, logging mechanisms, and detection protocols, and provides concrete design and placement requirements for icons, labels, and disclaimers for deepfakes and AI-generated content published on matters of public interest.
The draft Transparency Guidelines clarify that disclosures are insufficient where provided solely in terms and conditions, URLs or documentation; where markings are not perceivable by users; where signals are unclear or ambiguous; or where descriptions are purely technical. Compliance must account for vulnerable users such as children or those with low digital literacy.
AEPD issues guidance on AI voice transcription tools
The Spanish Data Protection Authority published a two-part guidance series on AI-powered voice transcription tools and their GDPR implications. The AEPD confirms that a person’s voice constitutes personal data, and that beyond spoken content, voice recordings may reveal identifying characteristics such as accent, tone, speech patterns, emotional state, or health-related information.
The AEPD describes two separate processing operations — generation of the transcription itself, and subsequent use of recordings or transcripts for AI model training, fine-tuning, or service improvement — which require independent legal assessment and transparency. Controllers must identify both a valid Article 6 legal basis and an applicable Article 9 exemption before processing special categories of data, and should inform individuals clearly and in advance that conversations are being recorded and transcribed using AI tools.
Privacy
CNIL publishes recommendation on email tracking pixels
France’s data protection authority (CNIL) adopted a recommendation on 12 March 2026 addressing tracking pixels in emails. The CNIL confirms that tracking pixels constitute operations of reading information from a user’s terminal and fall within Article 82 of the French Data Protection Act, in line with the regime applicable to cookies.
Prior consent is required in most situations, particularly for tracking used in marketing analytics, campaign optimisation, behavioural profiling, audience measurement, or cross-channel targeting. Limited exemptions apply for security (authentication), deliverability management, and transactional emails, but these are narrowly construed and collected data cannot be repurposed for marketing analytics. For addresses collected before publication, the CNIL provided a transitional period until 14 July 2026.
EDPB drafts a new DPIA template
The European Data Protection Board released a draft Data Protection Impact Assessment template to support controllers in meeting GDPR obligations. The template guides controllers through a structured process with predefined fields, while preserving their discretion in conducting risk analysis. The public consultation ran until 9 June 2026.
Dutch DPA issues guidance on explainability in automated decision-making
The Dutch Data Protection Authority provided detailed guidance on explainability in automated decision-making under Article 22 GDPR. Rather than debating whether a “right to explanation” exists, the guidance focuses on what information must be provided to make individuals’ rights effective in practice — general information in privacy notices, and a tailored explanation of the specific decision on request. Explainability is framed as a design obligation, documented in processes such as DPIAs.
Expiry of the ePrivacy Directive CSAM derogation
The temporary derogation permitting providers of electronic communications services to process personal data for voluntary detection of child sexual abuse material expired on 3 April 2026. Following the European Parliament and Council’s failure to agree on a further extension, the derogation lapsed without a successor framework, renewing focus on the stalled Child Sexual Abuse Regulation (also known as the “chat control” regulation).
Other digital topics
Commission preliminary findings against Meta for inadequate minor protection
The European Commission issued preliminary findings on 29 April 2026 indicating that Meta may breach Digital Services Act obligations regarding Instagram and Facebook, citing failures to adequately assess and mitigate risks associated with minors under 13 accessing the platforms — including reliance on self-declared birth dates, ineffective user-reporting workflows, and flawed risk assessment. If upheld, sanctions may include administrative fines up to 6% of Meta’s total worldwide annual turnover.
Formal investigation into SHEIN under the DSA
On 17 February 2026, the Commission opened formal proceedings against SHEIN under the DSA, focusing on the sale of illegal products within the EU, addictive design features, and recommender system transparency. Possible outcomes include interim measures, commitments, or fines up to 6% of global annual turnover.
Authors: Teodora Drašković and Alexandra Dirriglová.