{"id":11391,"date":"2025-12-04T11:02:26","date_gmt":"2025-12-04T10:02:26","guid":{"rendered":"https:\/\/techgdpr.com\/?p=11391"},"modified":"2025-12-04T12:28:55","modified_gmt":"2025-12-04T11:28:55","slug":"data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\/","title":{"rendered":"Data protection digest 18 Nov-2 Dec 2025:\u00a0 \u201cDigital omnibus\u201d package latest &amp; market price of personal data already estimated"},"content":{"rendered":"\n<h4 class=\"wp-block-heading\">\u201cDigital omnibus\u201d package latest<\/h4>\n\n\n\n<p>On 19 November, the European Commission presented proposals for amendments in the digital area legislation, including <a href=\"https:\/\/digitalpolicyalert.org\/event\/35562-commission-announced-proposal-for-digital-omnibus-regulation-eu-20250360-including-data-protection-regulation\">the GDPR, the Data Act, the EU AI Act, and the NIS 2 Directive<\/a>. According to digitalpolicyalert.org analysis, the Digital Omnibus would amend the GDPR by:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>changing the <strong>definition of personal data<\/strong> to specify any entity that is reasonably likely to have the means to identify a person,<\/li>\n\n\n\n<li>exempting certain biometric data and <strong>data used by AI<\/strong> from the restrictions on processing special categories of personal data,<\/li>\n\n\n\n<li>clarifying on further processing of personal data in the public interest or for <strong>scientific research purposes<\/strong>, and<\/li>\n\n\n\n<li>specifying that processing of personal data that is necessary for the interests of a controller in the development or operation of an AI system can be pursued for<strong> \u201dlegitimate interests\u201d<\/strong>.<\/li>\n<\/ul>\n\n\n\n<p>The Digital Omnibus would also exempt personal data processing from the cookie requirements under the ePrivacy Directive. Instead, it would amend the GDPR to <a href=\"https:\/\/www.jdsupra.com\/legalnews\/eu-proposes-sweeping-reforms-to-the-5066004\/\">maintain the consent requirement, while specifying that certain processing activities<\/a>, such as electronic communications transmissions, service provision, audience measurement solely for an online service provider, and maintaining or restoring security, would be considered lawful. Websites and apps would have to allow data subjects to <strong>consent through automated, machine-readable mechanisms<\/strong>; browser manufacturers must likewise enable users to grant or refuse consent.<\/p>\n\n\n\n<p>Finally, personal data breaches that are likely to result in a high risk to the rights and freedoms of natural persons would need to be <a href=\"https:\/\/www.whitecase.com\/insight-alert\/gdpr-under-revision-key-takeaways-from-digital-omnibus-regulation-proposal\">reported to the single-entry point within 96 hours of becoming aware of them<\/a>. Similarly, there would be unified lists of processing activities that do or do not require a Data Protection Impact Assessment, and create a <strong>standard DPIA template and methodology.<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><a href=\"#newslettersignup\"><mark style=\"background-color:#fce0cc;color:#be84f4\" class=\"has-inline-color\">Stay up to date! Sign up to receive our fortnightly digest via email. <\/mark><\/a><br><\/h4>\n\n\n\n<h4 class=\"wp-block-heading\">GDPR enforcement<\/h4>\n\n\n\n<p>On 17 November, the Council of the EU adopted new rules to improve cooperation between national data protection bodies when they <a href=\"https:\/\/www.consilium.europa.eu\/en\/press\/press-releases\/2025\/11\/17\/council-adopts-new-eu-law-to-speed-up-handling-cross-border-data-protection-complaints\/\">enforce the GDPR to speed up the process of handling cross-border data protection complaints<\/a>. Main elements of the new EU regulation include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Admissibility: <\/strong>Regardless of where in the EU a complaint is filed, admissibility will be judged based on the same information\/conditions.&nbsp;<\/li>\n\n\n\n<li><strong>Rights of complainants and parties under investigation: <\/strong>Common rules will apply for the involvement of the complainant in the procedure, and the right to be heard for the company or organisation that is being investigated.<\/li>\n\n\n\n<li><strong>Simple cooperation procedure:<\/strong> For straightforward cases, data protection authorities can decide, to avoid administrative burden, to settle actions without resorting to the full set of cooperation rules.<\/li>\n\n\n\n<li><strong>Deadlines:<\/strong> In the future, an investigation should not take more than <strong>15 months. For the most complex cases, this deadline can be extended by 12 months.<\/strong> In the case of a simple cooperation procedure between national data protection bodies, the investigation should be wrapped up within 12 months.<\/li>\n<\/ul>\n\n\n\n<p>The regulation will enter into force 20 days after its publication in the Official Journal of the EU. It will become applicable 15 months after it enters into force.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More legal updates<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"721\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-3-1024x721.jpeg\" alt=\"\" class=\"wp-image-11400 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-3-1024x721.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-3-300x211.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-3-768x541.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-3.jpeg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The European Commission has launched a <strong>whistleblower tool for the <a href=\"https:\/\/techgdpr.com\/blog\/reconciling-the-regulatory-clock\/\">AI Act<\/a><\/strong>. Whistleblowers can provide relevant information in any of the EU official languages and in any relevant format. The tool provides a secure means to report potential law violations that could compromise fundamental rights, health, or public trust. The highest level of confidentiality and data protection is guaranteed through certified encryption mechanisms. Anyone can access the <a href=\"https:\/\/ai-act-whistleblower.integrityline.app\/\">AI Act Whistleblower Tool<\/a> and read more <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/ai-act-whistleblower-tool\">information about the tool<\/a> and the <a href=\"https:\/\/ai-act-whistleblower.integrityline.app\/app-page;appPageName=What%20can%20be%20reported\">frequently asked questions<\/a>.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p><strong>California privacy updates:<\/strong> California has <a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billNavClient.xhtml?bill_id=202520260SB446\">enacted<\/a> a bill which amends the state\u2019s data breach notification law to establish strict new reporting timelines. Beginning January 1, 2026, businesses must notify affected California residents <a href=\"https:\/\/www.jdsupra.com\/legalnews\/right-to-know-november-2025-vol-35-8592002\/\">within 30 calendar days of discovering a security incident involving personal information<\/a>. For incidents affecting more than 500 residents, notice to the California Attorney General must be provided within 15 calendar days of the consumer notice. The amendment allows limited exceptions for law enforcement needs or when necessary to determine the scope of the incident and restore system integrity, JD Supra lawblog reports.&nbsp;<\/p>\n\n\n\n<p>In parallel, starting Jan. 1st, 2027, California will prohibit a business from developing or maintaining a <a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billNavClient.xhtml?bill_id=202520260AB566\">browser, as defined, that does not include functionality configurable by a consumer that enables the browser to send an opt-out preference signal<\/a> to businesses with which the consumer interacts through the browser. The bill would require a business that develops or maintains a browser to make clear to a consumer in its public disclosures how the opt-out preference signal works and the intended effect. The bill would grant a business that develops or maintains a browser that includes this functionality immunity from liability for a violation of those provisions by a business that receives the opt-out preference signal.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Child data protection in the EU<\/strong><\/h4>\n\n\n\n<p><strong> <\/strong>On 26 November, the European Parliament adopted a <a href=\"https:\/\/www.europarl.europa.eu\/doceo\/document\/TA-10-2025-0299_EN.pdf\">resolution on the protection of minors online<\/a> as part of an own-initiative procedure on the topic. The resolution calls, among other things, for the implementation of an <a href=\"https:\/\/digitalpolicyalert.org\/event\/35723-european-parliament-adopted-resolution-on-protection-of-minors-online-20252060ini\">EU-wide harmonised digital minimum age of 16 for accessing social media, video-sharing platforms and AI companions without parental consent<\/a>, with 13 as the minimum age for any social media use by children, even with parental consent.&nbsp;<\/p>\n\n\n\n<p>In parallel, the German Data Protection Conference, DSK, adopted a resolution calling for amendments to the GDPR to strengthen protections for children. It proposes a ban on children\u2019s consent for profiling and advertising, <a href=\"https:\/\/digitalpolicyalert.org\/event\/35738-conference-of-independent-data-protection-supervisory-authorities-of-federal-and-state-governments-adopted-resolution-on-amendments-to-general-data-protection-regulation-focusing-on-child-protection\">limits on children\u2019s ability to consent<\/a> to special-category data processing, and clearer rights for children to access counselling and medical services privately. It also focuses on a prohibition on children consenting to automated decisions, attention to children in breach notifications, data protection by design and default, and consideration of children\u2019s risks in data protection impact assessments, digitalpolicyalert.org sums up.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Cloud computing<\/strong><\/h4>\n\n\n\n<p>The European Commission has published <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/draft-recommendation-non-binding-model-contractual-terms-data-access-and-use-and-non-binding\">non-binding Model Contractual Terms for data access and use and Standard Contractual Clauses for cloud computing contracts<\/a>. They have been developed to help parties, especially SMEs, implement the provisions of the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/data-act\">Data Act<\/a>. Their use is voluntary and open to users\u2019 possible amendments. Although they were mainly drafted for business-to-business contracts, they can also be used in relations between businesses and consumers, if relevant consumer protection rules are added.&nbsp;<\/p>\n\n\n\n<p>Three sets of Model Contractual Terms (MCTs) were drafted to cover the relationships where data sharing is mandatory, between data holders, users and data recipients of data generated when using connected products. Plus, proposed <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/draft-recommendation-non-binding-model-contractual-terms-data-access-and-use-and-non-binding\">Standard Contractual Clauses (SCCs) translate the provisions of \u2018cloud switching\u2019 into ready-to-use contractual terms that can be inserted in data processing contracts<\/a>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>SCC Switching &amp; Exit<\/li>\n\n\n\n<li>SCC Termination&nbsp;<\/li>\n\n\n\n<li>SCC Security &amp; Business continuity (including provider notification of significant incidents).<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Email security<\/strong><\/h4>\n\n\n\n<p>The German Federal Office for Information Security, BSI,&nbsp; has published a White paper on <a href=\"https:\/\/www.bsi.bund.de\/DE\/Service-Navi\/Presse\/Pressemitteilungen\/Presse2025\/251124_E-Mail-Sicherheit.html\">requirements for the protection, transparency, and user-friendliness of webmails that systematically and future-orientedly increase consumer security<\/a>. The paper considers not only technical security functions, but also usability, transparency and trust as essential components of digital sovereignty. A <strong>fundamental part of e-mail security currently still rests on the shoulders of users<\/strong>. They should be familiar with two-factor authentication, passkey and encryption. The BSI sees responsibility primarily with the providers: they must provide effective procedures regarding authentication, encryption, spam protection and account recovery that work without major user intervention.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Data Act implementation<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-1024x576.png\" alt=\"Digital omnibus\" class=\"wp-image-11395 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-1024x576.png 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-300x169.png 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-768x432.png 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image.png 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>The Data Act has been in effect since September 2025. This new European regulation is intended to give consumers within the EU more control over the use of their data. For instance, a car owner will have the right to access the data their car collects. If repairs are needed, they can share the data with a garage of their choice, explains the Dutch data protection agency AP, which will jointly oversee the implementation process at a national level, starting from 21 November. <\/p>\n<\/div><\/div>\n\n\n\n<p>The Data Act and the implementing laws do not override the rules of the GDPR. <a href=\"https:\/\/www.autoriteitpersoonsgegevens.nl\/actueel\/toezicht-op-europese-dataverordening-van-start\">In the event of conflicting rules, the GDPR takes precedence<\/a>. This means that any data sharing involving personal data must comply with the GDPR, stresses the regulator.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More from supervisory authorities<\/h4>\n\n\n\n<p><strong>Market research data processing:<\/strong> In Poland, the data protection regulator UODO approved the &#8220;Code of Conduct on the Processing of Personal Data by Private Research Agencies&#8221;. The reason for the development of the code was <a href=\"https:\/\/uodo.gov.pl\/pl\/138\/3979\">numerous discrepancies in the processing of the personal data of research participants<\/a>. As a result, in the case of identical surveys, their participants, depending on the entity conducting the study, could receive divergent information, for instance, on the legal basis for the processing of personal data. Information obligations were also fulfilled differently. The Code also provides guidance to help carry out a risk assessment or, where justified, a data protection impact assessment.<\/p>\n\n\n\n<p>It is worth noting that<strong> the code obliges all entities that join it to appoint a Data Protection Officer (DPO)<\/strong>.&nbsp;<\/p>\n\n\n\n<p><strong>Sound recording and CCTV: <\/strong>Organisations often choose to conduct video surveillance with sound recording. Sometimes, they also do not disable the camera manufacturer&#8217;s default audio function. As a result, the additional risks posed not only by image capture, but also by sound recording are not sufficiently assessed. In addition, the processing of personal data related to it is not always carried out legally: <a href=\"https:\/\/www.dvi.gov.lv\/lv\/jaunums\/dviskaidro-skanas-ierakstisana-veicot-videonoverosanu\">recording sound and image are two different data processing operations, so both audio and video require different legal bases<\/a>.&nbsp;<\/p>\n\n\n\n<p>The processing of personal data by performing video surveillance with audio recording is not justified in most cases. There are rare situations where it is legal and permissible, mainly when it is associated with an increased risk to the essential interests of the organisation or society. Often, the legal basis for such processing can be found in the special regulatory framework applicable to a particular industry in which the organisation operates.<\/p>\n\n\n<div id=\"newslettersignup\"><\/div>\n<div id=\"role-block_3cc8eadb3cbfdbf88e3d3b9e8419fd5a\" class=\"text-t-black bg-t-pink p-6 md:p-12 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center role\">\n  \n      <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">\n      Receive our digest by email     <\/h2>\n        <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">Sign up to receive our digest by email every 2 weeks<\/h3>\n  \n  <div id=\"rmOrganism\">\n    <div class=\"rmEmbed rmLayout--vertical rmBase\">\n      <div data-page-type=\"formSubscribe\" class=\"rmBase__body rmSubscription\">\n                  <form method=\"post\" action=\"https:\/\/mailing.techgdpr.com\/145\/6351\/5e9fc3cdda\/subscribe\/form.html?_g=1698845230\" class=\"rmBase__content\">\n                  <div class=\"rmBase__container mx-auto max-w-screen-sm\">          \n            <div class=\"rmBase__section\">\n              <div class=\"text-left rmBase__el rmBase__el--input rmBase__el--label-pos-none\" data-field=\"email\">\n                <label for=\"email\" class=\"rmBase__compLabel rmBase__compLabel--hideable hidden\">\n                  Email address\n                <\/label>\n                <div class=\"rmBase__compContainer mb-2\">\n                  <input type=\"text\" name=\"email\" id=\"email\" placeholder=\"Email\" value=\"\" class=\"p-4 border rounded border-gray-400 w-full rmBase__comp--input comp__input\">\n                  <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section mb-4\">\n              <div class=\"rmBase__el rmBase__el--consent\" data-field=\"consent_text\">\n                <div class=\"rmBase__comp--checkbox\">\n                  <label for=\"consent_text\" class=\"flex space-x-2 items-baseline text-left vFormCheckbox comp__checkbox\">\n                    <input type=\"checkbox\" value=\"yes\" name=\"consent_text\" id=\"consent_text\" class=\"vFormCheckbox__input\">\n                    <div class=\"vFormCheckbox__indicator hidden\"><\/div>\n                    <div class=\"vFormCheckbox__label\">\n                                              I consent to the processing of my data and to receiving regular updates from TechGDPR. Data is processed according to our <a href=\"https:\/\/techgdpr.com\/privacy-policy\/\"> Privacy Notice<\/a>.                                          <\/div>\n                  <\/label>\n                <\/div>\n                <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--cta\">\n                <button type=\"submit\" class=\"inline-flex items-center justify-center px-8 py-3 text-white visited:text-white font-bodybold rounded-md bg-t-navy border-3 border-t-navy hover:border-t-navy hover:bg-transparent hover:text-t-navy transition-all hover:text-white cursor-pointer rmBase__comp--cta\">\n                  Subscribe\n                <\/button>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/form>\n      <\/div>\n      <div data-page-type=\"pageSubscribeSuccess\" class=\"rmBase__body rmSubscription hidden\">\n        <div class=\"rmBase__content\">\n          <div class=\"rmBase__container\">\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--heading\">\n                <div class=\"rmBase__comp--heading\">\n                  Thank you for your subscription!\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--text\">\n                <div class=\"rmBase__comp--text\">\n                  We have sent you an email &#8211; please confirm your email address by clicking the activation link in it.\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n\n      <script src=\"https:\/\/mailing.techgdpr.com\/form\/145\/6069\/8a53c9178b\/embedded.js\" async><\/script>\n  \n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Employment clauses and personal data processing<\/strong><\/h4>\n\n\n\n<p>Labour clauses are widely used by both public and private contracting authorities to ensure fair wages and working conditions for suppliers. Contracting entities often require the supplier to provide documentation of its compliance with the labour clauses, typically in the form of employees&#8217; salaries and timesheets, and employment contracts. This gives rise to questions about the supplier&#8217;s legal basis for disclosing such personal data to the contracting authority, notes Denmark\u2019s data protection agency. To that end, there will generally be an <a href=\"https:\/\/www.datatilsynet.dk\/presse-og-nyheder\/nyhedsarkiv\/2025\/nov\/videregivelse-af-personoplysninger-som-dokumentation-for-overholdelse-af-arbejdsklausuler\">overriding legitimate interest that these may form the basis for the disclosure of the information in question<\/a>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>TechSonar 2025-2026<\/strong><\/h4>\n\n\n\n<p><strong> <\/strong>EDPS\u2019s latest guidance on new technology concentrating on the TechSonar report 2025-2026 explores six trends: <strong>agentic AI, AI companions, automated proctoring, AI-driven personalised learning, coding assistants and confidential computing<\/strong>. While each of these technologies serves a distinct purpose, they are deeply interconnected. Together, they illustrate how AI is progressively reshaping not only business processes or common daily tasks, but also the human experience of technology. Continue reading the full report <a href=\"https:\/\/www.edps.europa.eu\/system\/files\/2025-11\/25-11-25_techsonar-2025-2026_en.pdf\">here<\/a>.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">In other news<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-1-1024x682.jpeg\" alt=\"Digital omnibus\" class=\"wp-image-11394 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-1-1024x682.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-1-300x200.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-1-768x512.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-1.jpeg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Data security in cloud-based EdTech:<\/strong> The US Federal Trade Commission will require education technology provider Illuminate Education, Inc. (Illuminate) to implement a data security program and delete unnecessary data to settle allegations that the company\u2019s data security failures led to a major data breach, which allowed <a href=\"https:\/\/www.ftc.gov\/legal-library\/browse\/cases-proceedings\/222-3105-illuminate-education-inc-matter\">hackers to access the personal data of more than 10 million students<\/a>.&nbsp;<\/p>\n<\/div><\/div>\n\n\n\n<p>Illuminate sells cloud-based technology products and collects and maintains personal information about students on behalf of schools and school districts. In its complaint, the FTC alleged that in 2021, a hacker used the credentials of a former employee, who had departed Illuminate three and a half years prior, to breach Illuminate\u2019s databases stored on a third-party cloud provider.&nbsp;<\/p>\n\n\n\n<p><strong>Medical data breach:<\/strong> The Norwegian data protection regulator upheld the fine on Argon Medical Devices. In 2023, it issued an American company Argon Medical Devices an infringement fee of approximately. 127,000 euros for violating the GDPR. In 2021, Argon discovered a <a href=\"https:\/\/www.datatilsynet.no\/aktuelt\/aktuelle-nyheter-2025\/personvernnemnda-opprettholder-overtredelsesgebyr-til-argon-medical-devices\/\">security breach that affected the personal data of all of its European employees, including those in Norway<\/a>. Argon sent the Norwegian regulator a notification of a breach long after the 72-hour deadline for reporting such breaches.&nbsp;<\/p>\n\n\n\n<p>Argon believed that they did not need to report the breach until they had a complete overview of the incident and all its consequences. This view was enshrined in their procedures, and this was the basis for the delay.&nbsp; The case is an important<strong> reminder that controllers must have appropriate measures in place to determine whether a breach has occurred <\/strong>and to promptly notify the supervisory authority and the data subject.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Mobile app gaming company fine<\/strong><\/h4>\n\n\n\n<p><strong> <\/strong>California\u2019s Attorney General settled with Jam City, Inc., resolving allegations that the mobile app gaming company violated the state\u2019s Consumer Privacy Act (CCPA) by failing to offer consumers methods to opt out of the sale or sharing of their personal information across its popular gaming apps. Jam City creates games for mobile platforms, including games based on popular franchises such as Frozen, Harry Potter, and Family Guy. In addition to 1.4 million dollars in civil penalties, <a href=\"https:\/\/oag.ca.gov\/news\/press-releases\/attorney-general-bonta-secures-14-million-settlement-mobile-app-gaming-company\">Jam City must provide in-app methods for consumers to opt out of the sale or sharing of their data and must not sell or share the personal information of consumers under 16<\/a> years old without their affirmative \u201copt-in\u201d consent.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Data brokers fine<\/strong><\/h4>\n\n\n\n<p>The Belgian data protection authority GBA, meanwhile, has imposed a <a href=\"https:\/\/cybernews.com\/security\/fined-data-broker-infobel\/\">40,000 euros fine on data broker Infobel for illegally reselling data<\/a> for marketing purposes, cybernews.com reports. A consumer complained to the GBA <strong>after getting a marketing brochure in the mail from a firm with which he was not a customer<\/strong>. The complainant asks how the corporation received his information. The customer was informed that his information had been given by a media agency. The agency obtained his information via Infobel, a data broker that received it from a telecom operator.&nbsp;<\/p>\n\n\n\n<p>Infobel said it had permission to sell the complainant&#8217;s information to the media agency since it had secured approval from data subjects. However, the data protection authorities claimed that there was no explicit, informed, or unambiguous consent.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Cookie consent fine<\/strong><\/h4>\n\n\n\n<p><strong> <\/strong>On November 20, the French regulator CNIL fined the French company Conde Nast Publications 750,000 euros for non-compliance with the rules applicable to cookies deposited on the terminals of users visiting the &#8220;vanityfair.fr&#8221; site. In particular, cookies subject to consent were placed on the terminals of <a href=\"http:\/\/vanityfair.fr\">users visiting the &#8220;vanityfair.fr&#8221; site as soon as they arrived on the site, even before they interacted with the cookie banner to express a choice<\/a>. Also, when a user clicked on the &#8220;Refuse all&#8221; button in the banner, or when they decided to withdraw their consent to the registration of trackers on their terminal, new cookies subject to consent were nevertheless deposited, and other cookies, already present, continued to be read.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">And finally\u2026<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:30% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-2-1024x682.jpeg\" alt=\"\" class=\"wp-image-11398 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-2-1024x682.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-2-300x200.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-2-768x512.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/image-2.jpeg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>Meta multi-million file: <\/strong>A Spanish court has ordered Meta to pay 479 million euros to Spanish digital media outlets for unfair competition practices and infringing the GDPR, a ruling the company will appeal, Reuters reports. The settlement, which will be given to 87 digital press publishers and news organisations, is related to Meta&#8217;s use of personal data for behavioural advertising.<\/p>\n<\/div><\/div>\n\n\n\n<p>The complaint filed by the Spanish outlets centred on Meta&#8217;s shift in the legal basis for processing personal data after the GDPR went into effect in May 2018. Meta changed &#8220;user consent&#8221; to &#8220;performance of a contract&#8221; to support behavioural advertising. Later, regulators judged that it was insufficient. Meta returned to consent as its legal foundation in 2023. The judge assessed that <a href=\"https:\/\/www.reuters.com\/sustainability\/boards-policy-regulation\/spanish-court-orders-meta-pay-550-mln-digital-media-companies-2025-11-20\/\">Meta generated at least 5.3 billion euros in advertising income during those five years<\/a>.<\/p>\n\n\n\n<p><strong>Personal data monetisation: <\/strong>The French CNIL commissioned a survey on the perception of the French people regarding the use of their personal data. From a representative sample of 2,082 people aged 15 and over, <a href=\"https:\/\/www.cnil.fr\/fr\/monetisation-des-donnees-personnelles-combien-valent-nos-donnees\">65% of them say they are willing to sell their data<\/a>. Of these, only 6% would be willing to sell it for less than 1 euro per month, while 14% preferred a fee of more than 200 euros per month.&nbsp;<\/p>\n\n\n\n<p><strong>The most common valuation was between 10 and 30 euros per month, preferred by 28% of respondents.<\/strong> This coincides with the latest market research based on Meta services estimation, where, for a price of 5 euros, 20% of people would be willing to sell their data, and 90% of companies would be willing to buy it. Taken together, these results make it possible to approximate a market price for data that would be around 40 euros per month (and per subscribed service).&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u201cDigital omnibus\u201d package latest On 19 November, the European Commission presented proposals for amendments in the digital area legislation, including the GDPR, the Data Act, the EU AI Act, and the NIS 2 Directive. According to digitalpolicyalert.org analysis, the Digital Omnibus would amend the GDPR by: The Digital Omnibus would also exempt personal data processing [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":11402,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[94],"tags":[51,101,129,100,89,58],"class_list":["post-11391","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-protection-digest","tag-artificial-intelligence","tag-consent-management","tag-consumer-data-protection","tag-cookies","tag-dpo","tag-gdpr-compliance"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280.jpg",1280,853,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280-300x200.jpg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280-768x512.jpg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280-1024x682.jpg",640,426,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280.jpg",1280,853,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280.jpg",1280,853,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable":"<p>\u201cDigital omnibus\u201d package latest On 19 November, the European Commission presented proposals for amendments in the digital area legislation, including the GDPR, the Data Act, the EU AI Act, and the NIS 2 Directive. According to digitalpolicyalert.org analysis, the Digital Omnibus would amend the GDPR by: changing the definition of personal data to specify any entity that is reasonably likely to have the means to identify a person, exempting certain biometric data and data used by AI from the restrictions on processing special categories of personal data, clarifying on further processing of personal data in the public interest or for&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280.jpg",1280,853,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280-300x200.jpg",300,200,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280-768x512.jpg",640,427,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280-1024x682.jpg",640,426,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280.jpg",1280,853,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280.jpg",1280,853,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable_v2":"<p>\u201cDigital omnibus\u201d package latest On 19 November, the European Commission presented proposals for amendments in the digital area legislation, including the GDPR, the Data Act, the EU AI Act, and the NIS 2 Directive. According to digitalpolicyalert.org analysis, the Digital Omnibus would amend the GDPR by: changing the definition of personal data to specify any entity that is reasonably likely to have the means to identify a person, exempting certain biometric data and data used by AI from the restrictions on processing special categories of personal data, clarifying on further processing of personal data in the public interest or for&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>","author_info_v2":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection digest 18 Nov-2 Dec 2025:\u00a0 \u201cDigital omnibus\u201d package latest &amp; market price of personal data already estimated - TechGDPR<\/title>\n<meta name=\"description\" content=\"TechGDPR\u2019s review of the most important data-related stories: \u201cDigital omnibus\u201d package latest &amp; market price of personal data\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection digest 18 Nov-2 Dec 2025:\u00a0 \u201cDigital omnibus\u201d package latest &amp; market price of personal data already estimated - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"TechGDPR\u2019s review of the most important data-related stories: \u201cDigital omnibus\u201d package latest &amp; market price of personal data\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2025-12-04T10:02:26+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-12-04T11:28:55+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"853\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Olya Vasylyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Vasylyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"14 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\\\/\"},\"author\":{\"name\":\"Olya Vasylyk\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\"},\"headline\":\"Data protection digest 18 Nov-2 Dec 2025:\u00a0 \u201cDigital omnibus\u201d package latest &amp; market price of personal data already estimated\",\"datePublished\":\"2025-12-04T10:02:26+00:00\",\"dateModified\":\"2025-12-04T11:28:55+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\\\/\"},\"wordCount\":2748,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/network-7055821_1280.jpg\",\"keywords\":[\"Artificial Intelligence\",\"consent management\",\"consumer data protection\",\"cookies\",\"dpo\",\"GDPR Compliance\"],\"articleSection\":[\"Data Protection Digest\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\\\/\",\"name\":\"Data protection digest 18 Nov-2 Dec 2025:\u00a0 \u201cDigital omnibus\u201d package latest &amp; market price of personal data already estimated - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/network-7055821_1280.jpg\",\"datePublished\":\"2025-12-04T10:02:26+00:00\",\"dateModified\":\"2025-12-04T11:28:55+00:00\",\"description\":\"TechGDPR\u2019s review of the most important data-related stories: \u201cDigital omnibus\u201d package latest & market price of personal data\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/network-7055821_1280.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2025\\\/12\\\/network-7055821_1280.jpg\",\"width\":1280,\"height\":853,\"caption\":\"Digital omnibus\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection digest 18 Nov-2 Dec 2025:\u00a0 \u201cDigital omnibus\u201d package latest &amp; market price of personal data already estimated\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\",\"name\":\"Olya Vasylyk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"caption\":\"Olya Vasylyk\"},\"description\":\"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olyav\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection digest 18 Nov-2 Dec 2025:\u00a0 \u201cDigital omnibus\u201d package latest &amp; market price of personal data already estimated - TechGDPR","description":"TechGDPR\u2019s review of the most important data-related stories: \u201cDigital omnibus\u201d package latest & market price of personal data","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\/","og_locale":"en_US","og_type":"article","og_title":"Data protection digest 18 Nov-2 Dec 2025:\u00a0 \u201cDigital omnibus\u201d package latest &amp; market price of personal data already estimated - TechGDPR","og_description":"TechGDPR\u2019s review of the most important data-related stories: \u201cDigital omnibus\u201d package latest & market price of personal data","og_url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\/","og_site_name":"TechGDPR","article_published_time":"2025-12-04T10:02:26+00:00","article_modified_time":"2025-12-04T11:28:55+00:00","og_image":[{"width":1280,"height":853,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280.jpg","type":"image\/jpeg"}],"author":"Olya Vasylyk","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya Vasylyk","Est. reading time":"14 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\/"},"author":{"name":"Olya Vasylyk","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8"},"headline":"Data protection digest 18 Nov-2 Dec 2025:\u00a0 \u201cDigital omnibus\u201d package latest &amp; market price of personal data already estimated","datePublished":"2025-12-04T10:02:26+00:00","dateModified":"2025-12-04T11:28:55+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\/"},"wordCount":2748,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280.jpg","keywords":["Artificial Intelligence","consent management","consumer data protection","cookies","dpo","GDPR Compliance"],"articleSection":["Data Protection Digest"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\/","url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\/","name":"Data protection digest 18 Nov-2 Dec 2025:\u00a0 \u201cDigital omnibus\u201d package latest &amp; market price of personal data already estimated - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280.jpg","datePublished":"2025-12-04T10:02:26+00:00","dateModified":"2025-12-04T11:28:55+00:00","description":"TechGDPR\u2019s review of the most important data-related stories: \u201cDigital omnibus\u201d package latest & market price of personal data","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2025\/12\/network-7055821_1280.jpg","width":1280,"height":853,"caption":"Digital omnibus"},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-4122025-digital-omnibus-latest-and-market-price-of-personal-data\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Data protection digest 18 Nov-2 Dec 2025:\u00a0 \u201cDigital omnibus\u201d package latest &amp; market price of personal data already estimated"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8","name":"Olya Vasylyk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","caption":"Olya Vasylyk"},"description":"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11391","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=11391"}],"version-history":[{"count":18,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11391\/revisions"}],"predecessor-version":[{"id":11422,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11391\/revisions\/11422"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/11402"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=11391"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=11391"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=11391"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}