{"id":11283,"date":"2025-11-03T18:46:53","date_gmt":"2025-11-03T17:46:53","guid":{"rendered":"https:\/\/s8.tgin.eu\/?p=11283"},"modified":"2025-11-04T13:41:28","modified_gmt":"2025-11-04T12:41:28","slug":"data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\/","title":{"rendered":"Data protection digest 19 Oct &#8211; 2 Nov 2025: New AI Act and GDPR study &amp; personal data stored on Blockchain"},"content":{"rendered":"\n<h4 class=\"wp-block-heading\">Blockchain applications and data protection&nbsp;&nbsp;&nbsp;&nbsp;<\/h4>\n\n\n\n<p>The Bank of England, in its October statement, confirmed that many firms in the financial sector are already using AI<strong>, <\/strong>exploring opportunities to use quantum computing, and <a href=\"https:\/\/www.bankofengland.co.uk\/report\/2025\/the-boes-approach-to-innovation-in-ai-dlt-quantum-computing\">piloting DLT applications<\/a>. One example is stablecoins built on DLT networks, which are already being used at scale by individuals and businesses worldwide for faster, cheaper cross-border payments and automated financial contracting. However, the bank admits that key barriers to scaling up blockchain solutions are <strong>regulatory frameworks that are not entirely suited to digital assets and cross-border initiatives<\/strong>. Blockchain\u2019s inherent characteristics present unique challenges for <a href=\"https:\/\/techgdpr.com\/consultancy\/achieve-gdpr-compliance\/\">GDPR compliance<\/a>.&nbsp;<\/p>\n\n\n\n<p>When it comes to handling personal data, blockchains present a significant challenge in respecting data subject rights. Its immutability, for example, contradicts the fundamental \u201cRight to be Forgotten\u201d. The global distribution of blockchain nodes also complicates regulatory supervision. Conducting a Data Protection Impact Assessment<strong> <\/strong>(DPIA) is not just a legal requirement for <strong>high-risk blockchain-based personal data processing<\/strong>, but is an important step towards responsible innovation. To help organisations meet these requirements, TechGDPR has created a free downloadable <a href=\"https:\/\/techgdpr.com\/consultancy\/blockchain-data-protection-impact-assessment-template\/\">Blockchain DPIA Template<\/a>, which guides users through all required areas of GDPR compliance:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Description of the processing operations<\/li>\n\n\n\n<li>Legal basis and necessity assessment<\/li>\n\n\n\n<li>Identification of risks<\/li>\n\n\n\n<li>Safeguards and technical measures<\/li>\n\n\n\n<li>Implementing privacy by design principles<\/li>\n\n\n\n<li>Data subject rights and governance structures<\/li>\n<\/ul>\n\n\n\n<p>The pre-designed template includes ready-to-use sections, prompts, and examples, significantly saving time and ensuring that no critical aspect of your DPIA is overlooked.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><a href=\"#newslettersignup\"><mark style=\"background-color:#fbddc7;color:#c286f9\" class=\"has-inline-color\">Stay up to date! Sign up to receive our fortnightly digest via email.<\/mark><\/a><\/h4>\n\n\n\n<h4 class=\"wp-block-heading\">UK Adequacy<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"655\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-4-1024x655.jpeg\" alt=\"\" class=\"wp-image-11292 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-4-1024x655.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-4-300x192.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-4-768x491.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-4.jpeg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The European Data Protection Board, EDPB, has issued its opinion on the adequate protection of personal data by the United Kingdom. In July 2025, the European Commission started the process towards the adoption of its draft implementing decision on the adequate protection of personal data by the UK. It <a href=\"https:\/\/www.edpb.europa.eu\/our-work-tools\/our-documents\/opinion-art-70\/opinion-262025-regarding-european-commission-draft_en\">extends the validity of certain parts of the previous adequacy decision until December 2031<\/a>. In particular, the EDPB asks for the need to further clarify by the Commission recent changes in the UK post-Brexit legislation regarding:&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>removing the direct application of the principles of EU law, including the right to privacy and data protection<\/li>\n\n\n\n<li>new powers to introduce changes via secondary regulations, which require less Parliamentary scrutiny (eg, on international transfers, automated decision-making)<\/li>\n\n\n\n<li>changes to the rules governing third-country transfers<\/li>\n\n\n\n<li>processing exemptions for law enforcement&nbsp;<\/li>\n\n\n\n<li>restructuring of the Information Commissioner\u2019s Office&nbsp;<\/li>\n\n\n\n<li>safeguards provided by the EU-US Umbrella Agreement, whose privacy and data protection safeguards are incorporated into the UK-US Cloud Act Agreement<\/li>\n\n\n\n<li>encryption to remain essential for ensuring the security and confidentiality of personal data and electronic communications.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">AI Act and the GDPR<\/h4>\n\n\n\n<p>The European Parliament has published a <a href=\"https:\/\/www.europarl.europa.eu\/RegData\/etudes\/STUD\/2025\/778575\/ECTI_STU(2025)778575_EN.pdf\">study<\/a> on the Interplay between the AI Act and the EU digital legislative framework, including the GDPR. In particular, the AI Act introduces requirements for <a href=\"https:\/\/techgdpr.com\/blog\/difference-fundamental-rights-impact-assessment-dpia\/\">fundamental rights impact assessments (FRIAs) in cases that often also trigger data protection impact assessments (DPIAs) <\/a>under the GDPR. These instruments differ in scope, supervision, and procedural requirements, creating duplication and uncertainty. Transparency and logging obligations are also redundant across both regimes. Moreover, there is ambiguity over how data controllers and AI providers should manage rights of access, rectification, and erasure when personal data becomes embedded in complex AI models.&nbsp;<\/p>\n\n\n\n<p>In AI contexts, the GDPR-governed <strong>\u201clegitimate interests\u201d legal basis is widely regarded as the most relevant and frequently invoked basis<\/strong>, states the report. Meanwhile, consent is often impracticable and contractual or legal obligation bases rarely map neatly onto AI training or deployment scenarios. Finally, the AI Act introduces additional governance layers: the AI Office and the European AI Board at the EU level and the national GDPR supervisory bodies with respect to data protection issues, which produce a potentially overlapping set of competent supervisory bodies.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Legal updates<\/h4>\n\n\n\n<p><strong>Dragi report: <\/strong>The Future of Privacy Forum takes a closer look at the <a href=\"https:\/\/commission.europa.eu\/document\/download\/97e481fd-2dc3-412d-be4c-f152a8232961_en\">report<\/a> on European competitiveness issued in 2024 by former Italian Prime Minister Mario Draghi, which calls for simplification of the GDPR, and criticizes \u201cheavy gold-plating\u201d by Member States in GDPR implementation. The Commission is now set to announce a <a href=\"https:\/\/ec.europa.eu\/info\/law\/better-regulation\/have-your-say\/initiatives\/14855-Digital-package-digital-omnibus-_en\">Digital Omnibus<\/a> package with proposals to quickly reduce the burden on businesses.&nbsp;However, changes to the GDPR fundamental principles could bring any <a href=\"https:\/\/fpf.org\/blog\/the-draghi-dilemma-the-right-and-the-wrong-way-to-undertake-gdpr-reform\/\">reform into conflict with the TFEU and the Charter<\/a> and lead to action before the Court of Justice.&nbsp;<\/p>\n\n\n\n<p><strong>GDPR enforcement: <\/strong>On 21 October, the European Parliament passed the regulation on additional procedural rules regarding the enforcement of the GDPR. The document aims to <a href=\"https:\/\/digitalpolicyalert.org\/event\/34445-european-parliament-passed-regulation-laying-down-additional-procedural-rules-relating-to-the-enforcement-of-gdpr\">harmonise the criteria for assessing the admissibility of cross-border complaints and clarifies the rights of complainants and entities under investigation<\/a>. The regulation establishes the same admissibility standards no matter where in the EU the GDPR complaint was filed. Both complainants and companies involved will have the right to be heard at specific stages of the investigation and will receive preliminary findings to express their views before a final decision is issued.&nbsp;<\/p>\n\n\n\n<p><strong>Data for research: <\/strong>From 29 October, researchers can request data access from very large online platforms and search engines to study systemic risks. Access to public platform data has been available since the Digital Services Act (DSA) came into force in February 2024. Researchers now have the opportunity to request access to platforms&#8217; internal data and to investigate its impact on society. Since datasets can allow <a href=\"https:\/\/www.datenschutz.rlp.de\/service\/aktuelles\/detail\/digital-services-act-forschende-erhalten-zugang-zu-nicht-oeffentlichen-plattformdaten\">direct or indirect inferences about individual users through their interactions, profiles, or other published content, researchers must comply with the requirements of the GDPR<\/a> when carrying out their projects.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More from supervisory authorities<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-3-1024x682.jpeg\" alt=\"\" class=\"wp-image-11290 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-3-1024x682.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-3-300x200.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-3-768x512.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-3.jpeg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>DSA and the GDPR: <\/strong>The EDPB has closed the consultation on the guidelines on the interplay between the Digital Services Act and the GDPR. One of its sections examines the limits on <a href=\"https:\/\/digitalpolicyalert.org\/event\/33426-european-data-protection-board-closes-consultation-on-guidelines-32025-on-the-interplay-between-the-digital-services-act-and-the-general-data-protection-regulation\">automated decision-making that involves the processing of personal data by intermediary service providers<\/a>. The paper also further examines the transparency of processing and deceptive design patterns prohibited by the DSA when these practices involve personal data.&nbsp; It also reviews the relationship between profiling restrictions and advertising technology, systematic risk assessments and minors&#8217; data protection.<\/p>\n<\/div><\/div>\n\n\n\n<p><strong>China privacy updates: <\/strong>China has issued its first <a href=\"https:\/\/www.jdsupra.com\/legalnews\/china-monthly-data-protection-update-6133703\/\">national standard for certification of cross-border personal information processing<\/a>. The standard, which takes effect on March 1, 2026, sets out fundamental principles, security requirements, and obligations for safeguarding individuals\u2019 rights in cross-border data processing. Reportedly, the certification is<strong> <\/strong><a href=\"https:\/\/www.hunton.com\/privacy-and-information-security-law\/personal-information-protection-certification-one-data-export-mechanism-in-china#page=1\">valid for three years<\/a>. The applicant may reapply for certification for continual use of such certification six months before its expiration. In general, under the Chinese<a href=\"https:\/\/cms-lawnow.com\/en\/ealerts\/2024\/03\/china-relaxes-cross-border-data-transfer-rules-with-new-provisions\"> Personal Information Protection Law (PIPL)<\/a>, a data handler may transfer personal information outside of China if one of the following three conditions (with some exemptions) is met:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Apply for and pass the security assessment;<\/li>\n\n\n\n<li>Sign and file the standard contract; or<\/li>\n\n\n\n<li>Obtain the personal information protection certification.<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">Hacked emails<\/h4>\n\n\n\n<p>Almost one in ten people affected by cybercrime in the previous year experienced unauthorised access to an online account or email. To provide targeted support to consumers in such cases, the German Federal Office for Information Security (BSI) published a guide &#8211; <a href=\"https:\/\/www.bsi.bund.de\/SharedDocs\/Downloads\/DE\/BSI\/Publikationen\/Broschueren\/Wegweiser_Checklisten_Flyer\/Checkliste_BSI_ProPK_Fremdzugriff_Account.pdf?__blob=publicationFile&amp;v=4\">Emergency checklist: Hacked account<\/a> (in German). If a person can no longer log in despite having the correct password, their email account may have been hacked. Changes in settings or attempts to log in from new devices can also be signs. To protect your account, the BSI recommends securing it with either a strong password combined with two-factor authentication or with passkeys.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">IoT security<\/h4>\n\n\n\n<p><strong> <\/strong>According to America\u2019s NIST, <a href=\"https:\/\/digitalpolicyalert.org\/event\/33917-national-institute-of-standards-and-technology-closes-consultation-on-nist-internal-report-8259-revision-1-foundational-cybersecurity-activities-for-iot-product-manufacturers-second-public-draft\">IoT products often lack product cybersecurity capabilities that their customers<\/a>, organisations and individuals can use to help mitigate their cybersecurity risks. Manufacturers can help their customers by providing necessary cybersecurity functionality and the cybersecurity-related information they need. To that end, NIST closes public consultations and offers a public draft of <a href=\"https:\/\/csrc.nist.gov\/pubs\/ir\/8259\/r1\/2pd\">Foundational Cybersecurity Activities for IoT Product Manufacturers<\/a>. This publication describes recommended activities that manufacturers should consider performing before their IoT products are sold to customers.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">GenAI guidance<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:25% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-6-1024x768.jpeg\" alt=\"blockchain\" class=\"wp-image-11296 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-6-1024x768.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-6-300x225.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-6-768x576.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-6.jpeg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>European Data Protection Supervisor (EDPS) has published its revised and updated <a href=\"https:\/\/www.edps.europa.eu\/data-protection\/our-work\/publications\/guidelines\/2025-10-28-guidelines-personal-data-and-electronic-communications-eu-institutions_en\">guidelines on the use of generative AI and processing of personal data <\/a>by EU institutions, bodies, offices, and agencies (EUIs), reflecting the fast-moving technological landscape and the evolving challenges posed by generative AI systems. It introduces several key updates, including:<\/p>\n<\/div><\/div>\n\n\n\n<p><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>a refined definition of generative AI for greater clarity and consistency<\/li>\n\n\n\n<li>a new, action-oriented compliance checklist for EUIs to assess and ensure the lawfulness of their processing activities<\/li>\n\n\n\n<li>clarified roles and responsibilities, assisting EUIs in determining whether they act as controllers, joint controllers, or processors<\/li>\n\n\n\n<li>detailed advice on lawful bases, purpose limitation, and the handling of data subjects\u2019 rights in the context of generative AI.<\/li>\n<\/ul>\n\n\n<div id=\"newslettersignup\"><\/div>\n<div id=\"role-block_258af959c3fa96c7c49dee6665d960ff\" class=\"text-t-black bg-t-pink p-6 md:p-12 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center role\">\n  \n      <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">\n      Receive our digest by email     <\/h2>\n        <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">Sign up to receive our digest by email every 2 weeks<\/h3>\n  \n  <div id=\"rmOrganism\">\n    <div class=\"rmEmbed rmLayout--vertical rmBase\">\n      <div data-page-type=\"formSubscribe\" class=\"rmBase__body rmSubscription\">\n                  <form method=\"post\" action=\"https:\/\/mailing.techgdpr.com\/145\/6351\/5e9fc3cdda\/subscribe\/form.html?_g=1698845230\" class=\"rmBase__content\">\n                  <div class=\"rmBase__container mx-auto max-w-screen-sm\">          \n            <div class=\"rmBase__section\">\n              <div class=\"text-left rmBase__el rmBase__el--input rmBase__el--label-pos-none\" data-field=\"email\">\n                <label for=\"email\" class=\"rmBase__compLabel rmBase__compLabel--hideable hidden\">\n                  Email address\n                <\/label>\n                <div class=\"rmBase__compContainer mb-2\">\n                  <input type=\"text\" name=\"email\" id=\"email\" placeholder=\"Email\" value=\"\" class=\"p-4 border rounded border-gray-400 w-full rmBase__comp--input comp__input\">\n                  <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section mb-4\">\n              <div class=\"rmBase__el rmBase__el--consent\" data-field=\"consent_text\">\n                <div class=\"rmBase__comp--checkbox\">\n                  <label for=\"consent_text\" class=\"flex space-x-2 items-baseline text-left vFormCheckbox comp__checkbox\">\n                    <input type=\"checkbox\" value=\"yes\" name=\"consent_text\" id=\"consent_text\" class=\"vFormCheckbox__input\">\n                    <div class=\"vFormCheckbox__indicator hidden\"><\/div>\n                    <div class=\"vFormCheckbox__label\">\n                                              I consent to the processing of my data and to receiving regular updates from TechGDPR. Data is processed according to our <a href=\"https:\/\/techgdpr.com\/privacy-policy\/\"> Privacy Notice<\/a>.\r\n                                          <\/div>\n                  <\/label>\n                <\/div>\n                <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--cta\">\n                <button type=\"submit\" class=\"inline-flex items-center justify-center px-8 py-3 text-white visited:text-white font-bodybold rounded-md bg-t-navy border-3 border-t-navy hover:border-t-navy hover:bg-transparent hover:text-t-navy transition-all hover:text-white cursor-pointer rmBase__comp--cta\">\n                  Subscribe\n                <\/button>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/form>\n      <\/div>\n      <div data-page-type=\"pageSubscribeSuccess\" class=\"rmBase__body rmSubscription hidden\">\n        <div class=\"rmBase__content\">\n          <div class=\"rmBase__container\">\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--heading\">\n                <div class=\"rmBase__comp--heading\">\n                  Thank you for your subscription!\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--text\">\n                <div class=\"rmBase__comp--text\">\n                  We have sent you an email &#8211; please confirm your email address by clicking the activation link in it.\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n\n      <script src=\"https:\/\/mailing.techgdpr.com\/form\/145\/6069\/8a53c9178b\/embedded.js\" async><\/script>\n  \n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\">Capita fine<\/h4>\n\n\n\n<p><strong> <\/strong>The UK\u2019s privacy regulator, ICO, issued a fine of 14 million pounds to Capita for failing to ensure the security of personal data related to a breach in 2023 that saw hackers steal millions of people\u2019s information, from pension records to the details of customers of organisations Capita supports. For some people, this included sensitive information such as details of criminal records, financial data or special category data. Capita processes personal information on behalf of over 600 organisations providing pension schemes, with 325 of these organisations also impacted by the data breach.<\/p>\n\n\n\n<p>The investigation found that Capita, in its capacity as a data controller, had failed to ensure the security of the processing, as well as lacking the appropriate technical and organisational measures. In particular, Capita <a href=\"https:\/\/ico.org.uk\/media2\/pv5nhks4\/capita-plc-and-cpsl-monetary-penalty-notice.pdf\">did not prevent both privilege escalation and unauthorised lateral movement through the network, and did not effectively respond to security alerts <\/a>when detected.&nbsp;&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">Grindr fine confirmed<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-1-1024x682.jpeg\" alt=\"\" class=\"wp-image-11286 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-1-1024x682.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-1-300x200.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-1-768x512.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-1.jpeg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>On October 21, Norway&#8217;s Borgarting Court of Appeal upheld Grindr&#8217;s multi-million privacy fine for violating Art. 9 of the GDPR, which forbids the processing of specific categories of personal data. The court decided that <a href=\"https:\/\/digitalpolicyalert.org\/event\/34840-borgarting-court-of-appeal-upheld-nok-65-million-fine-against-grindr-over-personal-data-breach\">sharing a dating app user ID with advertisers revealed sensitive information<\/a> regarding their sexual orientation. It further stated that consent was invalid since it was combined with service access, giving customers no real option. <\/p>\n<\/div><\/div>\n\n\n\n<p>Grindr&#8217;s multi-page privacy policy was also unclear concerning the extent and beneficiaries of data sharing, according to the Digital Policy Alert legal blog.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">In other news<\/h4>\n\n\n\n<p><strong>Data security fine: <\/strong>Australian Clinical Labs (ACL) has been ordered to pay <a href=\"https:\/\/privacymatters.dlapiper.com\/2025\/10\/australian-clinical-labs-ordered-to-pay-aud5-8-million-following-cyber-incident\/\">AUD 5.8 million for breach of the Privacy Act 1988 following a 2022 cyber incident<\/a> which impacted the personal information of over 223,000 individuals. This is the first civil penalty under the Privacy Act, DLA Piper law blog reports. The incident occurred within the IT environment of ACL\u2019s subsidiary, Medlab Pathology, which was acquired only 3 months prior. Critical vulnerabilities in the subsidiary\u2019s IT systems were not properly identified before the acquisition, as part of the due diligence process, as ACL intended to fully integrate them into its own IT environment within the following 6 months.<\/p>\n\n\n\n<p><strong>Insurance data security fines: <\/strong>The New York state Attorney General secured a 14.2 million fine from car Insurance companies over data breaches. Eight car insurance companies\u2019 poor cybersecurity allowed hackers to steal driver\u2019s license numbers to fraudulently obtain unemployment benefits, failing to protect the private information of more than 825,000 New Yorkers. These companies allowed people to obtain a car insurance price quote using an online tool. Some of the companies also provided password-protected tools to insurance agents to generate quotes for customers.&nbsp;The investigation found that data <a href=\"https:\/\/ag.ny.gov\/press-release\/2025\/attorney-general-james-secures-142-million-car-insurance-companies-over-data\">thieves were able to exploit a \u201cpre-fill\u201d function in the companies\u2019 online quoting tools<\/a>. <\/p>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"618\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-1024x618.jpeg\" alt=\"blockchain\" class=\"wp-image-11284 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-1024x618.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-300x181.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-768x464.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image.jpeg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Electronic identification services fine:<\/strong> In Finland, the Data Protection Ombudsman has imposed an 865,000 euro fine on Aktia Bank for neglecting information security in its electronic identification service. Due to a short-term disruption, some <a href=\"https:\/\/tietosuoja.fi\/-\/aktialle-seuraamusmaksu-tietoturvapuutteista-vahvan-sahkoisen-tunnistamisen-palvelussa\">people who logged into various services with Aktia&#8217;s bank codes had access to other customers&#8217; highly personal information, as the service mixed up the identification of people<\/a>. The regulator found that the bank had shortcomings in the planning, implementation and testing of a technical change made to the service. <\/p>\n<\/div><\/div>\n\n\n\n<h4 class=\"wp-block-heading\">Patient data breaches<\/h4>\n\n\n\n<p>Polish regulator UODO imposed an approximately 10,000 euro fine on Gyncentrum for failing to report a personal data breach. A medical centre specialising in infertility treatment, among other things, sent a communication, the subject line of which indicated the name of a genetic test, to another person, also a patient of the centre (with the same name). The document contained personal data: first name, last name, bank account number, and address. It also included the transfer amount and the name of the test performed, revealing that it was part of an extensive prenatal diagnostic program. The patient herself learned of the incident from another patient at the centre.&nbsp;<\/p>\n\n\n\n<p>In Guernsey, the Medical Specialist Group (MSG) was also fined 100,000 pounds following a cyber-attack. In 2021, the MSG became aware of a personal data breach after it received suspicious emails indicating that its email server had been accessed by cybercriminals. These vulnerabilities enabled criminals to access and steal e-mails stored on the server, some of which contained sensitive patient health data. These <a href=\"https:\/\/www.odpa.gg\/news\/news-article\/?id=744842ad-8dad-f011-bbd2-7ced8d13a51c\">e-mails were subsequently used to facilitate multiple phishing campaigns targeting MSG patients over a series of months<\/a>. The MSG notified the regulator of this breach. The inquiry found that the company routinely failed to install security updates to its e-mail server over the course of 13 months. This included updates directly related to the breach exploit and other critical vulnerabilities.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">California privacy violations<\/h4>\n\n\n\n<p>California\u2019s Attorney General secured a settlement with Sling TV, a streaming service, resolving allegations that the company violated the California Consumer Privacy Act (CCPA) by failing to provide an easy-to-use method for consumers to stop the sale of their personal information and by failing to provide sufficient privacy protections for children.&nbsp;Sling TV is an internet-based live TV service that offers both a paid subscription and a free, ad-supported streaming service. Unlike traditional television, where advertising is based on the content of the programming, Sling TV uses its internet-based platform to deliver highly targeted advertising, using <a href=\"https:\/\/oag.ca.gov\/news\/press-releases\/attorney-general-bonta-secures-530000-settlement-sling-tv-first-enforcement\">detailed consumer data such as age, gender, location, and income to personalise ads for viewers, often without their awareness<\/a>.&nbsp;&nbsp;&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">In case you missed it<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"654\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-2-1024x654.jpeg\" alt=\"\" class=\"wp-image-11287 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-2-1024x654.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-2-300x191.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-2-768x490.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-2.jpeg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Digital health care: <\/strong>Privacy International suggests that a <a href=\"https:\/\/privacyinternational.org\/long-read\/5695\/whose-business-your-healthcare-why-digital-health-tools-need-careful-assessment\">Digital Health Technology Assessment (dHTA)<\/a> is needed to make sure that tools developed by the private sector and relied on by public healthcare providers do not harm people and their rights. The Health Technology Assessment (HTA) is a longstanding practice that is used to assess the effectiveness and safety of technological innovations before they can be used in the diagnosis, treatment, management and prevention of health problems.<\/p>\n<\/div><\/div>\n\n\n\n<p>Thus, there is an overwhelming need for clear and specific rules that engage with the specific needs and challenges of new and emerging practices.<\/p>\n\n\n\n<p><strong>Multi-party computation: <\/strong>An EDPS blog article states that across sectors from health research to financial systems, data sharing continues to drive innovation, yet it also intensifies privacy and compliance challenges, making the <a href=\"https:\/\/www.edps.europa.eu\/press-publications\/press-news\/blog\/secure-multi-party-computation-powering-privacy-through-collaboration_en\">balance between access to data and confidentiality increasingly difficult. Secure multi-party computation (SMPC) proposes a way to reconcile<\/a> these seemingly conflicting goals &#8211; enabling organisations to jointly compute insights without revealing their underlying data. Under SMPC, multiple parties can work together to compute a result from their private data without ever exposing that data to one another. Unlike traditional encryption, which protects data only while it\u2019s stored or transmitted, SMPC ensures confidentiality throughout the computation process itself for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>hospitals improving disease prediction models using patient data, <\/li>\n\n\n\n<li>banks detecting cross-border fraud patterns, <\/li>\n\n\n\n<li>governments analysing the impact of social policies, <\/li>\n<\/ul>\n\n\n\n<p>From a legal perspective, SMPC challenges traditional interpretations of privacy law. Frameworks like the GDPR were not designed with cooperative computation in mind; thus, they must be embedded within transparent governance frameworks and ethical oversight.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Blockchain applications and data protection&nbsp;&nbsp;&nbsp;&nbsp; The Bank of England, in its October statement, confirmed that many firms in the financial sector are already using AI, exploring opportunities to use quantum computing, and piloting DLT applications. One example is stablecoins built on DLT networks, which are already being used at scale by individuals and businesses worldwide [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":11294,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[5,94,88],"tags":[51,46,58,105,79],"class_list":["post-11283","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blockchain","category-data-protection-digest","category-gdpr","tag-artificial-intelligence","tag-blockchain","tag-gdpr-compliance","tag-health-tech","tag-international-transfers"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5.jpeg",1280,853,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5-150x150.jpeg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5-300x200.jpeg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5-768x512.jpeg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5-1024x682.jpeg",640,426,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5.jpeg",1280,853,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5.jpeg",1280,853,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5-200x200.jpeg",200,200,true]},"post_excerpt_stackable":"<p>Blockchain applications and data protection&nbsp;&nbsp;&nbsp;&nbsp; The Bank of England, in its October statement, confirmed that many firms in the financial sector are already using AI, exploring opportunities to use quantum computing, and piloting DLT applications. One example is stablecoins built on DLT networks, which are already being used at scale by individuals and businesses worldwide for faster, cheaper cross-border payments and automated financial contracting. However, the bank admits that key barriers to scaling up blockchain solutions are regulatory frameworks that are not entirely suited to digital assets and cross-border initiatives. Blockchain\u2019s inherent characteristics present unique challenges for GDPR compliance.&nbsp; When&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/blockchain\/\" rel=\"category tag\">Blockchain<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5.jpeg",1280,853,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5-150x150.jpeg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5-300x200.jpeg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5-768x512.jpeg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5-1024x682.jpeg",640,426,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5.jpeg",1280,853,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5.jpeg",1280,853,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5-200x200.jpeg",200,200,true]},"post_excerpt_stackable_v2":"<p>Blockchain applications and data protection&nbsp;&nbsp;&nbsp;&nbsp; The Bank of England, in its October statement, confirmed that many firms in the financial sector are already using AI, exploring opportunities to use quantum computing, and piloting DLT applications. One example is stablecoins built on DLT networks, which are already being used at scale by individuals and businesses worldwide for faster, cheaper cross-border payments and automated financial contracting. However, the bank admits that key barriers to scaling up blockchain solutions are regulatory frameworks that are not entirely suited to digital assets and cross-border initiatives. Blockchain\u2019s inherent characteristics present unique challenges for GDPR compliance.&nbsp; When&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/blockchain\/\" rel=\"category tag\">Blockchain<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info_v2":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection digest 19 Oct - 2 Nov 2025: New AI Act and GDPR study &amp; personal data stored on Blockchain - TechGDPR<\/title>\n<meta name=\"description\" content=\"TechGDPR\u2019s review of the most important data-related stories: New AI Act and GDPR study &amp; personal data stored on Blockchain\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection digest 19 Oct - 2 Nov 2025: New AI Act and GDPR study &amp; personal data stored on Blockchain - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"TechGDPR\u2019s review of the most important data-related stories: New AI Act and GDPR study &amp; personal data stored on Blockchain\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2025-11-03T17:46:53+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-11-04T12:41:28+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"853\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Olya Vasylyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Vasylyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"14 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\\\/\"},\"author\":{\"name\":\"Olya Vasylyk\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\"},\"headline\":\"Data protection digest 19 Oct &#8211; 2 Nov 2025: New AI Act and GDPR study &amp; personal data stored on Blockchain\",\"datePublished\":\"2025-11-03T17:46:53+00:00\",\"dateModified\":\"2025-11-04T12:41:28+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\\\/\"},\"wordCount\":2616,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/11\\\/image-5.jpeg\",\"keywords\":[\"Artificial Intelligence\",\"Blockchain\",\"GDPR Compliance\",\"health tech\",\"International transfers\"],\"articleSection\":[\"Blockchain\",\"Data Protection Digest\",\"GDPR\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\\\/\",\"name\":\"Data protection digest 19 Oct - 2 Nov 2025: New AI Act and GDPR study &amp; personal data stored on Blockchain - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/11\\\/image-5.jpeg\",\"datePublished\":\"2025-11-03T17:46:53+00:00\",\"dateModified\":\"2025-11-04T12:41:28+00:00\",\"description\":\"TechGDPR\u2019s review of the most important data-related stories: New AI Act and GDPR study & personal data stored on Blockchain\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/11\\\/image-5.jpeg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/11\\\/image-5.jpeg\",\"width\":1280,\"height\":853,\"caption\":\"blockchain\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection digest 19 Oct &#8211; 2 Nov 2025: New AI Act and GDPR study &amp; personal data stored on Blockchain\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\",\"name\":\"Olya Vasylyk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"caption\":\"Olya Vasylyk\"},\"description\":\"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olyav\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection digest 19 Oct - 2 Nov 2025: New AI Act and GDPR study &amp; personal data stored on Blockchain - TechGDPR","description":"TechGDPR\u2019s review of the most important data-related stories: New AI Act and GDPR study & personal data stored on Blockchain","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\/","og_locale":"en_US","og_type":"article","og_title":"Data protection digest 19 Oct - 2 Nov 2025: New AI Act and GDPR study &amp; personal data stored on Blockchain - TechGDPR","og_description":"TechGDPR\u2019s review of the most important data-related stories: New AI Act and GDPR study & personal data stored on Blockchain","og_url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\/","og_site_name":"TechGDPR","article_published_time":"2025-11-03T17:46:53+00:00","article_modified_time":"2025-11-04T12:41:28+00:00","og_image":[{"width":1280,"height":853,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5.jpeg","type":"image\/jpeg"}],"author":"Olya Vasylyk","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya Vasylyk","Est. reading time":"14 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\/"},"author":{"name":"Olya Vasylyk","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8"},"headline":"Data protection digest 19 Oct &#8211; 2 Nov 2025: New AI Act and GDPR study &amp; personal data stored on Blockchain","datePublished":"2025-11-03T17:46:53+00:00","dateModified":"2025-11-04T12:41:28+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\/"},"wordCount":2616,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5.jpeg","keywords":["Artificial Intelligence","Blockchain","GDPR Compliance","health tech","International transfers"],"articleSection":["Blockchain","Data Protection Digest","GDPR"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\/","url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\/","name":"Data protection digest 19 Oct - 2 Nov 2025: New AI Act and GDPR study &amp; personal data stored on Blockchain - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5.jpeg","datePublished":"2025-11-03T17:46:53+00:00","dateModified":"2025-11-04T12:41:28+00:00","description":"TechGDPR\u2019s review of the most important data-related stories: New AI Act and GDPR study & personal data stored on Blockchain","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5.jpeg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/11\/image-5.jpeg","width":1280,"height":853,"caption":"blockchain"},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03112025-new-ai-act-and-gdpr-study-personal-data-stored-on-blockchain\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Data protection digest 19 Oct &#8211; 2 Nov 2025: New AI Act and GDPR study &amp; personal data stored on Blockchain"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8","name":"Olya Vasylyk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","caption":"Olya Vasylyk"},"description":"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11283","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=11283"}],"version-history":[{"count":20,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11283\/revisions"}],"predecessor-version":[{"id":11317,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11283\/revisions\/11317"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/11294"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=11283"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=11283"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=11283"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}