{"id":11232,"date":"2025-10-20T12:12:00","date_gmt":"2025-10-20T10:12:00","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=11232"},"modified":"2025-10-20T12:12:01","modified_gmt":"2025-10-20T10:12:01","slug":"data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\/","title":{"rendered":"Data protection digest 4-18 Oct 2025: Transparency the GDPR&#8217;s 2026 enforcement goal, and the Experian case as a model NOT to follow"},"content":{"rendered":"\n<h4 class=\"wp-block-heading\"><strong>Transparency and information obligation<\/strong> under GDPR<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:25% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-4-1024x768.jpeg\" alt=\"\" class=\"wp-image-11243 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-4-1024x768.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-4-300x225.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-4-768x576.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-4.jpeg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The European Data Protection Board (EDPB) announced the topic for Coordinated Enforcement Action 2026 on <a href=\"https:\/\/www.edpb.europa.eu\/news\/news\/2025\/coordinated-enforcement-framework-edpb-selects-topic-2026_en\">transparency and information obligations<\/a>. Articles 12, 13, and 14 of the GDPR require that individuals be informed when their personal data is processed, ensuring transparency and enabling greater control over personal information. Participating data protection authorities will join this action voluntarily in the coming weeks, with enforcement activities scheduled to launch during 2026.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Experian credit checks fine<\/strong><\/h4>\n\n\n\n<p>As the background example of the above transparency obligations, the Dutch data protection authority AP last week imposed a 2.7 million euro fine on Experian Nederland. Experian provided credit ratings on individuals to its customers until 2025. The company collected data on factors such as negative payment behavior, outstanding debts, and bankruptcies. The AP found that Experian violated the GDPR by improperly using personal data, and failed to adequately inform individuals about this.<\/p>\n\n\n\n<p>Experian created credit reports on individuals at the request of clients such as telecom companies, online retailers, and landlords. <a href=\"https:\/\/www.autoriteitpersoonsgegevens.nl\/actueel\/experian-krijgt-boete-van-27-miljoen-euro-voor-privacyovertredingen\">People started contacting the AP after they could no longer pay installments or because they suddenly had to pay a high deposit when switching energy suppliers<\/a>. Only afterward did it become clear that this could be due to Experian&#8217;s credit scores. Because people weren&#8217;t aware of the credit check, they couldn&#8217;t check in time whether the information was accurate. Experian collected data about people from various sources, both public and private, and failed to adequately explain why this data collection was necessary.<\/p>\n\n\n\n<p>Experian acknowledged violating the law and will not appeal the fine. It has ceased operations in the Netherlands and will delete the database containing all personal data.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\"><a href=\"#newslettersignup\"><mark style=\"background-color:#f8d9c3;color:#b694d5\" class=\"has-inline-color\">Stay up to date! Sign up to receive our fortnightly digest via email.<\/mark><\/a><\/h6>\n\n\n\n<h4 class=\"wp-block-heading\">More legal updates<\/h4>\n\n\n\n<p><strong>DMA and GDPR: <\/strong>The EDPB and the European Commission endorsed<a href=\"https:\/\/www.edpb.europa.eu\/our-work-tools\/documents\/public-consultations\/2025\/joint-guidelines-interplay-between-digital_en\"> <\/a>joint guidelines on the <a href=\"https:\/\/www.edpb.europa.eu\/our-work-tools\/documents\/public-consultations\/2025\/joint-guidelines-interplay-between-digital_en\">interplay between the Digital Markets Act (DMA) and the GDPR<\/a>. The DMA and the GDPR both protect individuals in the digital landscape, but their goals are complementary as they address interconnected challenges: individual rights and privacy in the case of the GDPR and fairness and contestability of digital markets under the DMA. However, several activities regulated by the DMA entail the processing of personal data by gatekeepers and refer to definitions and concepts included in the GDPR (eg, on how to lawfully combine or cross-use personal data in core platform services).&nbsp;<\/p>\n\n\n\n<p><strong>Italy&#8217;s new AI law: <\/strong>On 10 October, the Italian law on Provisions and Delegation to Government on Artificial Intelligence, including an age verification requirement, <a href=\"https:\/\/www.normattiva.it\/uri-res\/N2Ls?urn:nir:stato:legge:2025;132\">entered into force<\/a>. It is the first comprehensive legislation adopted by an individual EU member state on research, testing, development, adoption, and application of AI systems and models, with a human-centric approach. The government has appointed the Agency for Digital Italy and the National Cybersecurity Agency to enforce the legislation, which received its final approval in the parliament after a year of debate. The enforcement measure imposes even <a href=\"https:\/\/www.theguardian.com\/world\/2025\/sep\/18\/italy-first-in-eu-to-pass-comprehensive-law-regulating-ai\">prison terms on those who manipulate technology to cause harm<\/a>, such as generating deepfakes.&nbsp;<\/p>\n\n\n\n<p><strong>US Bulk Data: <\/strong>The US Department of Justice\u2019s <a href=\"https:\/\/www.jdsupra.com\/legalnews\/the-sensitive-data-bulk-transfer-rule-8594212\/\">Sensitive Data Bulk Transfer Rule<\/a> is in effect as of October 6, JD Supra law blog reports. This means if your organisation transfers US sensitive data (from demographic data to cookie data) that hits the bulk thresholds, you need to develop and implement a compliance program, either a stand-alone program or as part of the compliance program (through due diligence and audit procedures).&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Electronic patient files<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:25% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"974\" height=\"1024\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-5-974x1024.png\" alt=\"\" class=\"wp-image-11241 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-5-974x1024.png 974w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-5-285x300.png 285w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-5-768x808.png 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-5.png 1217w\" sizes=\"(max-width: 974px) 100vw, 974px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>In Germany, the electronic patient record (ePA) for everyone has been tested in model regions since January 2025. Since 29 April, it has been available for use nationwide by practices, hospitals, and pharmacies, among others. As of <a href=\"https:\/\/datenschutz-hamburg.de\/news\/die-elektronische-patientenakte\">1 October, it is generally mandatory for practices and other medical facilities to fill out the records<\/a>. At the same time, the information (eg, on ongoing or further treatment) can only be included in the ePA for everyone if the insured person has not fundamentally objected to this with their health insurance provider.<\/p>\n<\/div><\/div>\n\n\n\n<p>Finally, special consent requirements apply to information from genetic testing for diagnostic purposes, as well as on children and adolescent records.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>California privacy updates<\/strong><\/h4>\n\n\n\n<p>At the end of September, California finalised regulations to strengthen consumer privacy that go into effect on 1 January, 2026. However, there is additional time for businesses to comply with some of the new requirements, namely <a href=\"https:\/\/cppa.ca.gov\/announcements\/2025\/20250923.html\">cybersecurity audits, risk assessments, and requirements for automated decision-making technologies<\/a>, as well as updates to existing CCPA regulations. The final regulations and supporting materials will be posted on the <a href=\"https:\/\/cppa.ca.gov\/regulations\/\">regulator&#8217;s website<\/a> as soon as they are processed.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>ISO\/IEC 27701<\/strong><\/h4>\n\n\n\n<p>On 14 October, ISO released ISO\/IEC 27701:2025, the <a href=\"https:\/\/www.iso.org\/standard\/27701\">latest version of the global Privacy Information Management System (PIMS) standard<\/a>. For the first time, ISO\/IEC 27701 is now a standalone standard, no longer just an extension of ISO\/IEC 27001. The standard is designed for personally identifiable information (PII) controllers and processors, who hold responsibility and accountability for processing PII to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>&nbsp;Strengthen data privacy and protection capabilities<\/li>\n\n\n\n<li>&nbsp;Help demonstrate compliance with global privacy regulations such as the GDPR<\/li>\n\n\n\n<li>&nbsp;Support trust-building with partners, clients and regulators<\/li>\n\n\n\n<li>&nbsp;Align with existing ISO\/IEC 27001 systems to streamline implementation<\/li>\n\n\n\n<li>&nbsp;Facilitate accountability and evidence-based privacy management<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Cookie updated guidance<\/strong><\/h4>\n\n\n\n<p> The Swiss FDPIC published an updated version of its cookie guidelines, which contains specific clarifications and additions intended to improve the comprehensibility of the text and clarify practical issues. In particular, the FDPIC found it useful to clarify <a href=\"https:\/\/www.edoeb.admin.ch\/en\/cookie-guidelines-updated-version\">why the use of cookies for the purpose of delivering personalised advertising may require the consent of the data subjects<\/a>. This is the case when the website operator provides third parties with access to visitors&#8217; personal information in return for payment by integrating third-party cookies or similar technologies, and these third parties are embedded in several websites. As the latter are enabled to carry out high-risk profiling, this constitutes a particularly intensive intrusion into the privacy of the data subjects.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>AI systems development guidance<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"574\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-1024x574.jpeg\" alt=\"\" class=\"wp-image-11233 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-1024x574.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-300x168.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-768x430.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image.jpeg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong> <\/strong>In Germany, the Data Protection Conference (DSK) publishes guidance on AI systems with Retrieval Augmented Generation (RAG). It provides legal and technical information on how to harness the potential of such AI systems while simultaneously reducing the risks for those affected. <a href=\"https:\/\/www.datenschutzkonferenz-online.de\/media\/oh\/DSK_OH_RAG.pdf\">RAG is an AI technology that augments large language models with targeted access to company or government agency knowledge sources<\/a> to deliver context-specific answers.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p>Typical application examples include <strong>in-house chatbots that access current business data and scientific assistance systems that leverage research databases<\/strong>.&nbsp;<\/p>\n\n\n\n<p>Thus, RAG use must be designed in compliance with data protection by design and by default. Controllers must ensure transparency, purpose limitation, and the protection of data subjects&#8217; rights at all times. Controllers wishing to implement such RAG systems must conduct data protection assessments of the various processing operations on a case-by-case basis and always keep their technical and organisational measures up to date.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More from supervisory authorities<\/h4>\n\n\n\n<p><strong>Union membership: <\/strong>The Latvian data protection authority DVI explains whether an employer needs to know about a worker\u2019s union membership. The answer is that the employer cannot request such information from the employee at any time. The most appropriate justification for processing such data is when such rights are established for the employer by law; however, there is also the possibility of obtaining the employee&#8217;s consent or finding out this information when the employee has disclosed it themself.&nbsp;<\/p>\n\n\n\n<p><a href=\"https:\/\/www.dvi.gov.lv\/lv\/jaunums\/dviskaidro-vai-darba-devejam-ir-jazina-ka-esmu-arodbiedriba\">Such a question should not be asked during a job interview, when drawing up an employment contract or during an employment relationship<\/a>, as long as the employer does not intend to terminate the employment relationship with the employee in question. If an employee is to be dismissed, asking about union membership is important because union members may have special protections, such as the need to obtain the union\u2019s consent to termination.&nbsp;<\/p>\n\n\n\n<p><strong>Commercial robocalls: <\/strong>The DVI also explains what a company should consider if it wants to use commercial robocalls. The regulatory framework stipulates that the use of automated calling systems, which operate without human intervention for the purpose of <a href=\"https:\/\/www.dvi.gov.lv\/lv\/jaunums\/dviskaidro-kas-jaievero-uznemumam-ja-velas-izmantot-komercialus-robotzvanus\">sending commercial communications, is permitted only if the recipient of the service has given their prior free and explicit consent<\/a>. Thus, sending commercial communications in this way is lawful only if the person concerned has previously (before making the call) given their free and explicit consent to be disturbed by automated calling devices.\u00a0<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Google Analytics fine confirmed by court<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:25% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-2-1024x682.jpeg\" alt=\"\" class=\"wp-image-11237 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-2-1024x682.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-2-300x200.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-2-768x512.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-2.jpeg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>In 2023, Sweden\u2019s data protection authority IMY decided after an inspection that Tele2 (mobile network provider) must pay a penalty fee of SEK 12 million because they violated the GDPR. The Court of Appeal has now ruled in favor of IMY. The violation concerned the fact that the company, in connection with the use of Google Analytics, transferred personal data to the US without adequate protection. <\/p>\n<\/div><\/div>\n\n\n\n<p>IMY assessed that the data transferred to the US via Google&#8217;s statistical tool was personal data, since the <a href=\"https:\/\/www.imy.se\/nyheter\/kammarratten-bekraftar-sanktionsavgift-for-tele2\/\">data transferred could be linked with other data that Google had access to and thus enabled Google to distinguish and identify specific persons<\/a>.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Minors&#8217; data in the EU<\/strong><\/h4>\n\n\n\n<p><strong> <\/strong>On 16 October, the European Parliament\u2019s Committee on the Internal Market and Consumer Protection adopted its report on the Protection of minors online. The report calls for an <a href=\"https:\/\/digitalpolicyalert.org\/event\/34312-european-parliaments-internal-market-committee-adopted-report-on-protection-of-minors-online-20252060ini\">EU-wide digital minimum age of 16 for accessing social media, video-sharing platforms and AI companions without parental consent, and a minimum age of 13 for any social media use<\/a>. It urges the European Commission to strengthen enforcement of the Digital Services Act and to swiftly adopt guidelines on measures ensuring a high level of privacy, safety, and security for minors. The Parliament is expected to vote on the final recommendations during the November plenary session.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Microsoft use of children data<\/strong><\/h4>\n\n\n\n<p>The Austrian data protection authority ruled on a complaint regarding Microsoft\u2019s handling of children&#8217;s data under the GDPR. It found that the Federal High School and the Federal Ministry for Education, acting as joint controllers, violated the complainant\u2019s right of access and right to be informed. They failed to provide complete and timely information on data processed through Microsoft Education 365, including cookies and third-party data transfers, (content, log, and cookie data). Microsoft was also found to have infringed the complainant\u2019s right of access by not providing complete information on cookie data, its own processing purposes, and transfers to third parties such as LinkedIn, OpenAI, and Xandr, <a href=\"https:\/\/digitalpolicyalert.org\/event\/34185-austrian-data-protection-authority-issued-its-ruling-following-investigation-into-microsoft-over-alleged-violation-of-gdpr-in-handling-of-childrens-data\">digitalpolicyalert.org<\/a> reports.\u00a0<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Doping scandals and personal data<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:25% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-3-1024x682.jpeg\" alt=\"\" class=\"wp-image-11239 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-3-1024x682.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-3-300x200.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-3-768x512.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-3.jpeg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>A CJEU Advocate General has ruled on the publication of the name of professional athletes who have infringed anti-doping rules. In the related case in Austria, <a href=\"https:\/\/idpc.org.mt\/news-latest\/cjeu-advocate-general-the-publication-of-the-name-of-any-professional-athlete-who-has-infringed-the-anti-doping-rules-is-contrary-to-eu-law\/\">four athletes concerned submit that that publication contravenes the GDPR<\/a>. Such publication is provided for by law. It aims, first, to deter athletes from committing infringements of the anti-doping rules and thus to prevent doping in sport. <\/p>\n<\/div><\/div>\n\n\n\n<p>Second, it aims to prevent circumvention of the anti-doping rules by informing all persons likely to sponsor or engage the athlete in question that he or she is suspended. In that context, the Austrian court asked the Court of Justice to interpret the GDPR. The first opinion was that <a href=\"https:\/\/curia.europa.eu\/jcms\/upload\/docs\/application\/pdf\/2025-09\/cp250128en.pdf\">such practice is contrary to EU law<\/a>. The principle of proportionality requires account to be taken of the specific circumstances of each individual case. In the Advocate General\u2019s view, publishing the relevant name, but limited to the relevant bodies and sports federations, accompanied, for example, by pseudonymised publication on the internet, would make it possible to achieve both those objectives.<\/p>\n\n\n<div id=\"newslettersignup\"><\/div>\n<div id=\"role-block_ebc1104f6164959e4219b35db5180920\" class=\"text-t-black bg-t-pink p-6 md:p-12 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center role\">\n  \n      <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">\n      Receive our digest by email     <\/h2>\n        <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">Sign up to receive our digest by email every 2 weeks<\/h3>\n  \n  <div id=\"rmOrganism\">\n    <div class=\"rmEmbed rmLayout--vertical rmBase\">\n      <div data-page-type=\"formSubscribe\" class=\"rmBase__body rmSubscription\">\n                  <form method=\"post\" action=\"https:\/\/mailing.techgdpr.com\/145\/6351\/5e9fc3cdda\/subscribe\/form.html?_g=1698845230\" class=\"rmBase__content\">\n                  <div class=\"rmBase__container mx-auto max-w-screen-sm\">          \n            <div class=\"rmBase__section\">\n              <div class=\"text-left rmBase__el rmBase__el--input rmBase__el--label-pos-none\" data-field=\"email\">\n                <label for=\"email\" class=\"rmBase__compLabel rmBase__compLabel--hideable hidden\">\n                  Email address\n                <\/label>\n                <div class=\"rmBase__compContainer mb-2\">\n                  <input type=\"text\" name=\"email\" id=\"email\" placeholder=\"Email\" value=\"\" class=\"p-4 border rounded border-gray-400 w-full rmBase__comp--input comp__input\">\n                  <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section mb-4\">\n              <div class=\"rmBase__el rmBase__el--consent\" data-field=\"consent_text\">\n                <div class=\"rmBase__comp--checkbox\">\n                  <label for=\"consent_text\" class=\"flex space-x-2 items-baseline text-left vFormCheckbox comp__checkbox\">\n                    <input type=\"checkbox\" value=\"yes\" name=\"consent_text\" id=\"consent_text\" class=\"vFormCheckbox__input\">\n                    <div class=\"vFormCheckbox__indicator hidden\"><\/div>\n                    <div class=\"vFormCheckbox__label\">\n                                              I consent to the processing of my data and to receiving regular updates from TechGDPR. Data is processed according to our <a href=\"https:\/\/techgdpr.com\/privacy-policy\/\"> Privacy Notice<\/a>.\r\n                                          <\/div>\n                  <\/label>\n                <\/div>\n                <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--cta\">\n                <button type=\"submit\" class=\"inline-flex items-center justify-center px-8 py-3 text-white visited:text-white font-bodybold rounded-md bg-t-navy border-3 border-t-navy hover:border-t-navy hover:bg-transparent hover:text-t-navy transition-all hover:text-white cursor-pointer rmBase__comp--cta\">\n                  Subscribe\n                <\/button>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/form>\n      <\/div>\n      <div data-page-type=\"pageSubscribeSuccess\" class=\"rmBase__body rmSubscription hidden\">\n        <div class=\"rmBase__content\">\n          <div class=\"rmBase__container\">\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--heading\">\n                <div class=\"rmBase__comp--heading\">\n                  Thank you for your subscription!\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--text\">\n                <div class=\"rmBase__comp--text\">\n                  We have sent you an email &#8211; please confirm your email address by clicking the activation link in it.\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n\n      <script src=\"https:\/\/mailing.techgdpr.com\/form\/145\/6069\/8a53c9178b\/embedded.js\" async><\/script>\n  \n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\">In other news<\/h4>\n\n\n\n<p><strong>Clearview AI fine confirmed: <\/strong>On 7 October, the UK Upper Tribunal confirmed that Clearview AI\u2019s facial recognition business is subject to the EU and UK GDPRs. Clearview had argued that its scraping of billions of online images to produce facial recognition services for sale to foreign law enforcement agencies placed it outside of GDPR\u2019s material and territorial scope. The <a href=\"https:\/\/privacyinternational.org\/news-analysis\/5692\/tribunal-confirms-clearview-ai-bound-gdpr\">tribunal rejected the claim and made it clear that Clearview\u2019s activities involve \u2018behavioural monitoring<\/a>\u2019. Clearview sought a narrow interpretation of the GDPR, but the tribunal rightly adopted a broader one that clearly encompasses automated processing.<\/p>\n\n\n\n<p>This decision follows the Information Commissioner and Privacy International\u2019s appeal against a 2023 First Tier Tribunal ruling that had quashed Clearview\u2019s 7,552,800 pounds fine. Clearview trawls through sites like Instagram, YouTube and Facebook, as well as personal blogs and professional websites. It uses facial recognition technology to extract the unique features of people\u2019s faces, effectively building a gigantic biometrics database. Clearview has previously been found to be in breach of the GDPR in France, Italy, Austria and Greece, resulting in fines totalling 65,200,000 euros.<\/p>\n\n\n\n<p><strong>Meta AI bots: <\/strong>The Guardian reports that <a href=\"https:\/\/www.theguardian.com\/technology\/2025\/oct\/18\/parents-will-be-able-to-block-meta-bots-from-talking-to-their-children-under-new-safeguards\">parents will be able to block their children\u2019s interactions with Meta\u2019s AI character chatbots<\/a>. The social media company is adding new safeguards to its \u201cteen accounts\u201d, which are a default setting for under-18 users, by letting parents turn off their children\u2019s chats with AI characters. These chatbots, which are created by users, are available on Facebook, Instagram and the Meta AI app. Parents will also be able to block specific AI characters and get \u201cinsights\u201d into the topics their children are chatting about with AI. Meta said the changes would be rolled out early next year, initially to the US, UK, Canada and Australia.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">In case you missed it<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"574\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-1-1024x574.jpeg\" alt=\"\" class=\"wp-image-11235 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-1-1024x574.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-1-300x168.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-1-768x430.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/image-1.jpeg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>AI for everyday tasks: <\/strong>As more and more companies are using their users&#8217; personal data to train AI models, the French data protection regulator CNIL explains how to oppose it for the main platforms. The practical cases include: <a href=\"https:\/\/www.cnil.fr\/fr\/ia-comment-sopposer-la-reutilisation-de-ses-donnees-personnelles-entrainement-agent-conversationnel\">Google &#8211; Gemini, Meta \u2013 Meta AI, Open AI \u2013 ChatGPT, Microsoft \u2013 Copilot, X &#8211; Grok, DeepSeek, Mistral \u2013 The Cat, Anthropic &#8211; Claude, and LinkedIn<\/a>.<\/p>\n<\/div><\/div>\n\n\n\n<p><strong>\u2018Self-aware\u2019 AI: <\/strong>Guernsey&#8217;s data protection authority meanwhile publishes its observations on how <a href=\"https:\/\/www.odpa.gg\/news\/news-article\/?id=ce1ec118-e293-f011-b4cb-6045bda06883\">AI has formed the basis of a number of companion apps<\/a> and the creation of numerous digital friends and partners. It is important to remember, for all of us, personally and professionally, that such products are not \u2018living beings\u2019, while more and more news stories continue to emerge of tragic outcomes in which a digital companion played a part. Individuals <a href=\"https:\/\/techgdpr.com\/blog\/data-subject-rights-in-ai-a-practical-guide-for-businesses\/\">have the right not to be subject to automated decision making<\/a> which is at the core of such products, without appropriate safeguards being in place. And for organisations functioning as data controllers, these are vested with the responsibility on any decisions AI makes or advice it provides to people.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Transparency and information obligation under GDPR The European Data Protection Board (EDPB) announced the topic for Coordinated Enforcement Action 2026 on transparency and information obligations. Articles 12, 13, and 14 of the GDPR require that individuals be informed when their personal data is processed, ensuring transparency and enabling greater control over personal information. Participating data [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":11246,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[94,88],"tags":[100,58,96,266,330],"class_list":["post-11232","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection-digest","category-gdpr","tag-cookies","tag-gdpr-compliance","tag-google-analytics","tag-minors-data","tag-transparency"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280.jpg",1280,596,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280-300x140.jpg",300,140,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280-768x358.jpg",640,298,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280-1024x477.jpg",640,298,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280.jpg",1280,596,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280.jpg",1280,596,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable":"<p>Transparency and information obligation under GDPR The European Data Protection Board (EDPB) announced the topic for Coordinated Enforcement Action 2026 on transparency and information obligations. Articles 12, 13, and 14 of the GDPR require that individuals be informed when their personal data is processed, ensuring transparency and enabling greater control over personal information. Participating data protection authorities will join this action voluntarily in the coming weeks, with enforcement activities scheduled to launch during 2026.&nbsp; Experian credit checks fine As the background example of the above transparency obligations, the Dutch data protection authority AP last week imposed a 2.7 million euro&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280.jpg",1280,596,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280-300x140.jpg",300,140,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280-768x358.jpg",640,298,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280-1024x477.jpg",640,298,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280.jpg",1280,596,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280.jpg",1280,596,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable_v2":"<p>Transparency and information obligation under GDPR The European Data Protection Board (EDPB) announced the topic for Coordinated Enforcement Action 2026 on transparency and information obligations. Articles 12, 13, and 14 of the GDPR require that individuals be informed when their personal data is processed, ensuring transparency and enabling greater control over personal information. Participating data protection authorities will join this action voluntarily in the coming weeks, with enforcement activities scheduled to launch during 2026.&nbsp; Experian credit checks fine As the background example of the above transparency obligations, the Dutch data protection authority AP last week imposed a 2.7 million euro&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info_v2":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection digest 4-18 Oct 2025: Transparency the GDPR&#039;s 2026 enforcement goal, and the Experian case as a model NOT to follow - TechGDPR<\/title>\n<meta name=\"description\" content=\"TechGDPR\u2019s review of the data-related stories: Transparency the GDPR&#039;s 2026 enforcement goal, and the Experian case as a model NOT to follow\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection digest 4-18 Oct 2025: Transparency the GDPR&#039;s 2026 enforcement goal, and the Experian case as a model NOT to follow - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"TechGDPR\u2019s review of the data-related stories: Transparency the GDPR&#039;s 2026 enforcement goal, and the Experian case as a model NOT to follow\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2025-10-20T10:12:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-10-20T10:12:01+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"596\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Olya Vasylyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Vasylyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\\\/\"},\"author\":{\"name\":\"Olya Vasylyk\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\"},\"headline\":\"Data protection digest 4-18 Oct 2025: Transparency the GDPR&#8217;s 2026 enforcement goal, and the Experian case as a model NOT to follow\",\"datePublished\":\"2025-10-20T10:12:00+00:00\",\"dateModified\":\"2025-10-20T10:12:01+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\\\/\"},\"wordCount\":2416,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/circuit-board-6568867_1280.jpg\",\"keywords\":[\"cookies\",\"GDPR Compliance\",\"Google Analytics\",\"minors data\",\"Transparency\"],\"articleSection\":[\"Data Protection Digest\",\"GDPR\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\\\/\",\"name\":\"Data protection digest 4-18 Oct 2025: Transparency the GDPR's 2026 enforcement goal, and the Experian case as a model NOT to follow - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/circuit-board-6568867_1280.jpg\",\"datePublished\":\"2025-10-20T10:12:00+00:00\",\"dateModified\":\"2025-10-20T10:12:01+00:00\",\"description\":\"TechGDPR\u2019s review of the data-related stories: Transparency the GDPR's 2026 enforcement goal, and the Experian case as a model NOT to follow\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/circuit-board-6568867_1280.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/circuit-board-6568867_1280.jpg\",\"width\":1280,\"height\":596,\"caption\":\"transparency and information obligation\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection digest 4-18 Oct 2025: Transparency the GDPR&#8217;s 2026 enforcement goal, and the Experian case as a model NOT to follow\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\",\"name\":\"Olya Vasylyk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"caption\":\"Olya Vasylyk\"},\"description\":\"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olyav\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection digest 4-18 Oct 2025: Transparency the GDPR's 2026 enforcement goal, and the Experian case as a model NOT to follow - TechGDPR","description":"TechGDPR\u2019s review of the data-related stories: Transparency the GDPR's 2026 enforcement goal, and the Experian case as a model NOT to follow","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\/","og_locale":"en_US","og_type":"article","og_title":"Data protection digest 4-18 Oct 2025: Transparency the GDPR's 2026 enforcement goal, and the Experian case as a model NOT to follow - TechGDPR","og_description":"TechGDPR\u2019s review of the data-related stories: Transparency the GDPR's 2026 enforcement goal, and the Experian case as a model NOT to follow","og_url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\/","og_site_name":"TechGDPR","article_published_time":"2025-10-20T10:12:00+00:00","article_modified_time":"2025-10-20T10:12:01+00:00","og_image":[{"width":1280,"height":596,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280.jpg","type":"image\/jpeg"}],"author":"Olya Vasylyk","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya Vasylyk","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\/"},"author":{"name":"Olya Vasylyk","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8"},"headline":"Data protection digest 4-18 Oct 2025: Transparency the GDPR&#8217;s 2026 enforcement goal, and the Experian case as a model NOT to follow","datePublished":"2025-10-20T10:12:00+00:00","dateModified":"2025-10-20T10:12:01+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\/"},"wordCount":2416,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280.jpg","keywords":["cookies","GDPR Compliance","Google Analytics","minors data","Transparency"],"articleSection":["Data Protection Digest","GDPR"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\/","url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\/","name":"Data protection digest 4-18 Oct 2025: Transparency the GDPR's 2026 enforcement goal, and the Experian case as a model NOT to follow - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280.jpg","datePublished":"2025-10-20T10:12:00+00:00","dateModified":"2025-10-20T10:12:01+00:00","description":"TechGDPR\u2019s review of the data-related stories: Transparency the GDPR's 2026 enforcement goal, and the Experian case as a model NOT to follow","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/10\/circuit-board-6568867_1280.jpg","width":1280,"height":596,"caption":"transparency and information obligation"},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-20102025-transparency-the-gdprs-2026-enforcement-goal-and-the-experian-case-as-a-model-not-to-follow\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Data protection digest 4-18 Oct 2025: Transparency the GDPR&#8217;s 2026 enforcement goal, and the Experian case as a model NOT to follow"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8","name":"Olya Vasylyk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","caption":"Olya Vasylyk"},"description":"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11232","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=11232"}],"version-history":[{"count":17,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11232\/revisions"}],"predecessor-version":[{"id":11263,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11232\/revisions\/11263"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/11246"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=11232"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=11232"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=11232"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}