Photo of Kristof Van Quathem

Kristof Van Quathem

Kristof Van Quathem advises clients on information technology matters and policy, with a focus on data protection, cybercrime and various EU data-related initiatives, such as the Data Act, the AI Act and EHDS.

Kristof has been specializing in this area for over twenty years and developed particular experience in the life science and information technology sectors. He counsels clients on government affairs strategies concerning EU lawmaking and their compliance with applicable regulatory frameworks, and has represented clients in non-contentious and contentious matters before data protection authorities, national courts and the Court of the Justice of the EU.

Kristof is admitted to practice in Belgium.

In recent months, children’s online safety and privacy have moved to the top of the EU’s digital agenda. The European Commission is expected to outline its proposal on minors’ access to social media this week, a potentially significant development that would build on the recommendations of the Commission’s Special Panel on child safety online and mounting pressure from Member States.

The EU is not moving in isolation. Similar debates on minors’ access to online platforms, age assurance, and safety-by-design obligations are emerging in other jurisdictions. These include Australia and the United Kingdom, as well as a rapidly developing patchwork of state-level age-verification, app-store, and device-based age-assurance requirements in the United States.

This post provides a horizon-scanning update on the principal regulatory developments at the EU level, selected national developments, and some relevant developments outside the EU.

Continue Reading Horizon Scan: Children’s Online Safety and Privacy (EU and Beyond)

On July 7, 2026, the European Data Protection Board (“EDPB”) adopted draft Guidelines 02/2026 on Anonymisation (“Guidelines”), updating a 2014 Opinion on Anonymization Techniques. While the EDPB maintains a cautious approach to anonymization, the new Guidelines appear to offer a more structured and practical framework for assessing whether information can be considered anonymous. The Guidelines are open for public consultation until October 30, 2026.

Continue Reading EDPB Publishes Draft Guidelines on Anonymisation

On July 16, 2026, the Court of Justice of the European Union (“CJEU”) issued a decision clarifying that EU law does not, as a rule, prevent a national competition authority from seizing business emails stored on a company’s systems without prior authorisation from a court. However, strict legal safeguards and effective ex post judicial review must be implemented.

This blog post provides an overview of the decision.

Continue Reading CJEU Clarifies the Conditions for Seizure of Business Emails During Competition Inspections

On May 26, 2026, the French data protection authority (“CNIL”) published updated versions of its Reference Methodology 001 (“MR-001”, available here in French) and Reference Methodology 003 (“MR-003”, available here in French), two key frameworks governing the processing of personal data in the context of health research.

Continue Reading CNIL Updates Two Standards For Health Research (MR-001 and MR-003)

On April 17, 2026, the Italian data protection authority (the “Garante”) published Provision No. 284 setting out guidelines on the use of “tracking pixels” in emails (the “Guidelines”). This publication closely follows the recommendation issued by the French data protection authority on the same topic, which is discussed in a…

Continue Reading Italian DPA Publishes Guidelines on Email Tracking Pixels

On April 20, 2026, the Spanish Data Protection Agency (AEPD) has published new guidance on how to comply with the GDPR when using AI‑powered voice transcription tools. The guidance builds on earlier AEPD guidance on this topic from January 2026. This blog post sets out the key takeaways of both guidance documents, which are only available in Spanish.

The AEPD’s guidance confirms a risk‑based approach to AI‑powered voice transcription. Organizations using these tools should not treat transcription as a purely technical feature, but as a processing activity that requires continuous governance, clear transparency, and proactive safeguards. Given the widespread and growing use of transcription tools across business functions, this guidance is likely to be relevant well beyond Spain.

Continue Reading Spain’s Supervisory Authority Issues New Guidance on AI‑Based Voice Transcription

On April 15, 2026, the European Data Protection Board (EDPB) published draft Guidelines 1/2026 on the processing of personal data for scientific research purposes (Guidelines). The Guidelines are open for public consultation until 25 June 2026. They aim to clarify how the GDPR applies to academic, public‑sector, and commercial research, including research that relies on AI, large data sets, and the reuse of personal data. The Guidelines do not cover the application of other EU or Member State law regulating scientific research or the processing of genetic, biometric, or health data specifically.

Continue Reading New EDPB Guidelines on the Use of Personal Data in Scientific Research

On March 19, 2026, the CJEU issued its judgment in the Brillen Rottler case (C‑526/24).  The case concerns the GDPR right of access and the conditions for claiming damages.  In the underlying facts, an Austrian individual subscribed to Brillen Rottler’s newsletter and, two weeks later, exercised his right of access.

Continue Reading EU Court Defines Limits to the GDPR Right of Access

On March 12, 2026, the Italian Data Protection (“Garante”) adopted a decision concerning the transfer of personal data of banking customers from Intesa Sanpaolo S.p.A. (the “Bank”) to Isybank S.p.A., a newly established digital bank within the same corporate group.  The Garante found that the Bank’s processing in connection with the transfer of approximately 2.4 million customers to Isybank was unlawful.

We set out the decision’s key findings below.

Continue Reading Italian DPA Fines Bank over the Transfer of Customer Data in the Context of a Corporate Transaction