IT Trends & Tips for Users

European Data Protection in Flux: US Transfers, Fresh ECJ Rulings and the Digital Omnibus

Aug 13, 2026 4 min read
All articles

Several things are shifting in European data protection at once. A fine against an AI chatbot provider, a US court decision with consequences for transatlantic data flows, two clarifications from the European Court of Justice and a reform package out of Brussels. If you process or host personal data, it is worth catching up.

A fine for Character.AI

Italy's data protection authority Garante has penalised the US company Character Technologies. Its platform, Character.AI, lets users chat with virtual characters ranging from mafia bosses to simulated therapists. The regulator objected to opaque privacy notices, missing Italian translations, unclear legal bases and inadequate protection for minors.

At 158,000 euros, the penalty looks mild. Particularly given the cases reported in the US where teenagers took their own lives after interacting with chatbots.

Are US data transfers at risk?

The US Supreme Court ruled that the president may dismiss members of the Federal Trade Commission even without serious misconduct on their part. That strips the FTC of its status as an independent authority. Since it plays a role in the Data Privacy Framework, the ruling caused a stir.

Legal scholar Alexander Golland, who teaches information society law at Osnabrück University of Applied Sciences, is not expecting an immediate earthquake. When the ECJ struck down the predecessor agreement Privacy Shield, its problem was less the FTC than the absence of legal remedies against US intelligence agencies. Things would look considerably worse if the Privacy and Civil Liberties Oversight Board were also classified as dependent.

He still advises companies to keep standard contractual clauses ready as a fallback. Ideally with a suspensive condition, so that existing liability arrangements are not accidentally undermined.

Two clarifications from Luxembourg

The ECJ sharpened GDPR interpretation in two separate cases. The first involved a building services company in Lower Saxony and data from a private eBay account that may have been obtained unlawfully. The court does not rule out its use as evidence in principle. National courts must decide for themselves whether they may use the data and whether doing so cuts too far into the rights of the person concerned.

The second case concerned a publicly accessible list published by the Austrian anti-doping agency, containing names, sports, violations and suspension periods. The mere fact that someone doped does not automatically count as health data, the court found. That can change if the specific substance allows conclusions about an illness. Publication may serve the protection of fair sport, but it has to stay proportionate and account for the individual case.

The Digital Omnibus and the same old fights

With the planned Digital Omnibus, the EU wants to simplify its data protection and digital rules. Parts of it are obviously sensible, such as a single reporting point for both data protection and IT security incidents. Alongside those sit the familiar battles over cookies, personalised advertising and browser signals against tracking. Parliament and member states are far apart on the central questions.

Golland's forecast is sober. He expects a modest tweak at best, and only if the Council, Parliament and Commission leave the most contested cookie rules out of the negotiation entirely.

What this means in practice

Not much changes for you in the short term. The Data Privacy Framework stands, and no sudden collapse is on the horizon. If you use processors in the US, have your standard contractual clauses prepared rather than hunting for them once something breaks. And if you get to choose where data lives, a data centre inside the EU simply makes your life easier.