Adviser to EU top court says consent to use of personal data for direct marketing does not extend to subsequent use by unidentified “partners”
22 September 26
Alessandra Vaes
The Advocate General of the Court of Justice of the EU considered that consent to direct marketing by a company's “partners” is valid only if individuals are informed of the partners’ identities when giving consent. If this is not the case, such partners must obtain fresh consent to lawfully process the individuals’ personal data for direct marketing purposes.
EU Digital & Media Weekly Report
20 September 26
Alessandra Vaes
This edition features the Commission’s proposal for a Kids Act; the European Parliament’s adoption of a report calling for an EU strategy to protect minors online; Parliament’s call for stronger enforcement of the Digital Services Act to address systemic online risks; the provisions of the Payment Services Regulation on combatting fraud that are relevant to telecoms providers and online platforms; and an opinion by an adviser to the EU’s top court in a data protection case concerning consent to direct marketing by unidentified partners.
How would the EU Payment Services Regulation impact telecoms operators and online platforms?
15 September 26
Javier Huerta Bravo
This report analyses the new measures, expected to be adopted in December 2026, to prevent impersonation fraud involving payment services providers (PSPs). Both telecoms operators and online platforms would be required to detect and prevent the use of their services for this type of fraud. The regulation would explicitly allow them to cooperate and share information with PSPs. Very large online platforms would have to verify that advertisements for financial services are from authorised providers. Platforms would also have to compensate PSPs for the amounts refunded to their customers in some cases, such as if they had failed to expeditiously remove the fraudulent content after becoming aware of it.
EU Digital & Media Weekly Report
13 September 26
Alessandra Vaes
This edition features a story on the application of the Cyber Resilience Act’s reporting requirements; a new edition of the EU Timeline, highlighting key EU policy and regulatory developments foreseen until the end of 2026; and an update of the Digital Economy Trackers.
Dutch data protection authority imposes €825m fine on Uber for violating GDPR requirements on automated decision-making
13 September 26
Alessandra Vaes
It is the second-largest fine imposed under the GDPR to date. The Dutch data protection authority found that, by suspending drivers’ accounts without human intervention, Uber subjected the drivers to decisions based solely on automated processing. Under the GDPR, such automated decision-making (ADM) is generally prohibited where it produces legal effects or similarly significantly affects the individuals concerned, subject to certain exceptions.
EU Timeline
10 September 26
Marianna Mattera
This edition of Cullen International’s EU Timeline highlights key policy and regulatory developments foreseen at EU level until the end of 2026.