{"id":11446,"date":"2026-01-07T10:47:06","date_gmt":"2026-01-07T09:47:06","guid":{"rendered":"https:\/\/techgdpr.com\/?p=11446"},"modified":"2026-01-19T18:08:34","modified_gmt":"2026-01-19T17:08:34","slug":"data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai","status":"publish","type":"post","link":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\/","title":{"rendered":"Data protection digest 3 Jan 2026: Improvements are being made to GDPR enforcement, US consumer privacy, and emerging &#8220;Shadow AI&#8221; concerns"},"content":{"rendered":"\n<h4 class=\"wp-block-heading\"><strong>GDPR enforcement simplified<\/strong><\/h4>\n\n\n\n<p>A new regulation came into force on 1 January, supplementing the GDPR. It speeds up the work of data protection authorities in enforcement <a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=CELEX:32025R2518\">cases that involve multiple countries in the EU\/EEA<\/a>. The regulation provides, among other things, for time limits, stages of investigation, the exchange of information between authorities, and the rights of the parties concerned. In future, data protection authorities will have to issue a resolution proposal on a cross-border case as a rule within 12-15 months. In the most complex cases, the deadline can be extended by 12 months. The regulation will apply from April 2027.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><a href=\"#newslettersignup\"><mark style=\"background-color:#f9e7e1;color:#bf8bef\" class=\"has-inline-color\">Stay up to date! Sign up to receive our fortnightly digest via email.<\/mark><\/a><\/h4>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>UK Adequacy decision<\/strong><\/h4>\n\n\n\n<p>The European Commission adopted <a href=\"https:\/\/ec.europa.eu\/commission\/presscorner\/detail\/fr\/ip_25_3059\">two new adequacy decisions<\/a> for the UK \u2013 one under the GDPR and the other under the Law Enforcement Directive, until 27\u00a0December 2031.\u00a0 In accordance with the new decisions, transfers of personal data from the EU to the UK can continue to take place without any specific framework. Following Brexit, the Commission adopted two adequacy decisions vis-\u00e0-vis the UK in 2021. Sunset clauses had been introduced in each of the decisions. The decisions expired in mid 2025, but have been extended until the end of the year. The EDPS has since issued an <a href=\"https:\/\/www.edpb.europa.eu\/our-work-tools\/our-documents\/opinion-art-70\/opinion-062025-regarding-extension-european-commission_en\">opinion<\/a> on these decisions.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More legal updates<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:25% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"682\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/e-commerce-402822_1280-1024x682.jpg\" alt=\"\" class=\"wp-image-11451 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/e-commerce-402822_1280-1024x682.jpg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/e-commerce-402822_1280-300x200.jpg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/e-commerce-402822_1280-768x512.jpg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/e-commerce-402822_1280.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>US consumer privacy updates: <\/strong>In Kentucky, as well as Indiana, Rhode Island and several other states, GDPR-enhanced legislation related to consumer data privacy took effect on January 1. In <strong>Kentucky<\/strong>, in particular, the new legislation establishes <a href=\"https:\/\/apps.legislature.ky.gov\/record\/24RS\/hb15.html\">the rights to confirm whether data is being processed, to correct any inaccuracies, to delete personal data provided by the consumer<\/a>, to obtain a copy of the consumer\u2019s data, and to opt out of targeted advertising, the sale of data, or profiling of the consumer along with requirements for entities that control and process their data.<\/p>\n<\/div><\/div>\n\n\n\n<p>Similarly, in January, new regulations became effective in <strong>California<\/strong> regarding a <a href=\"https:\/\/www.jdsupra.com\/legalnews\/effective-jan-1-california-regulatory-3038328\/\">risk-assessment framework for certain high-risk data processing activities<\/a>, as well as transparency and notice requirements, disclosure of sensitive personal information, <a href=\"https:\/\/www.dataguidance.com\/news\/california-act-data-breaches-customer-notification-act\">data breach<\/a> reporting, consumer rights requests, and data collection and deletion by <a href=\"https:\/\/leginfo.legislature.ca.gov\/faces\/billTextClient.xhtml?bill_id=202520260SB361\">data brokers<\/a>.&nbsp;<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>AI use by banks<\/strong><\/h4>\n\n\n\n<p> The Hungarian data protection regulator issued a report on the processing of personal data by AI systems used by banks in Hungary (available in English). <a href=\"https:\/\/www.naih.hu\/\">Some good practices<\/a> indicated by the report include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>AI recognition of images, voices and texts must be reliable, without compromising data security. Principles of <strong><a href=\"https:\/\/techgdpr.com\/blog\/reconciling-the-regulatory-clock\/\">data minimisation and storage limitation<\/a><\/strong> must be observed.<\/li>\n\n\n\n<li>The quality of the data used for AI training is important, as well as identifying whether or not the training data needs to be linked to a specific natural person. In many cases, <strong>pseudonymisation or anonymisatio<\/strong>n can be used to mitigate privacy risks before training.<\/li>\n\n\n\n<li>The use of <strong>\u2018Shadow AI\u2019<\/strong> is becoming a new phenomenon. It covers all cases where, in an organisation, users use AI systems in an unregulated, non-transparent, uncoordinated manner from the point of view of the organisation, either for work or for some personal use, using the organisation\u2019s IT infrastructure.&nbsp;<\/li>\n\n\n\n<li>In their operations, certain banks under review also use analytical models to analyse and predict <strong>creditworthiness<\/strong> and product affinity, the precise classification of which may raise questions. They often<strong> operate on a statistical basis, but may also have an AI-based component<\/strong>, and it is necessary to apply the appropriate safeguards.&nbsp;<\/li>\n<\/ul>\n\n\n\n<h4 class=\"wp-block-heading\">More from supervisory authorities<\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:25% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"766\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/image-1024x766.jpeg\" alt=\"\" class=\"wp-image-11449 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/image-1024x766.jpeg 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/image-300x225.jpeg 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/image-768x575.jpeg 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/image.jpeg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p><strong>EU Data Act: <\/strong>The French privacy regulator CNIL explained how the EU <a href=\"https:\/\/www.cnil.fr\/fr\/reglement-donnees-data-act-nouveau-cadre-europeen-pour-partage-utilisation-donnees\">Data Act is going to reform the EU digital economy<\/a>, gradually implemented through 2026-2027. The Act sets fair rules on the access and use of personal or non-personal data generated by connected objects. It allows anyone who owns or uses <a href=\"https:\/\/www.jdsupra.com\/legalnews\/top-10-questions-about-the-eu-data-act-7649617\/\">connected products<\/a> to access the data generated by this object. It also facilitates their sharing with other actors, in particular by prohibiting unfair contractual clauses. <\/p>\n<\/div><\/div>\n\n\n\n<p>The implementation of this regulation must be done in conjunction with the GDPR. In particular, it provides that in the event of a contradiction between the two texts, it is the GDPR that prevails when personal data is concerned. <\/p>\n\n\n\n<p>Similarly, the <strong>Digital Governance Act<\/strong> should be taken into account, which has set up new trusted intermediaries to encourage voluntary data sharing.<\/p>\n\n\n\n<p><strong>Bodycam use<\/strong>: At the end of December, the CJEU ruled in a case regarding a data controller&#8217;s obligation to provide information when collecting personal data via a body-worn camera worn by ticket inspectors on public transport. The <a href=\"https:\/\/curia.europa.eu\/jcms\/upload\/docs\/application\/pdf\/2025-12\/cp250161en.pdf\">collection of personal data by means of body-worn cameras constitutes collection directly from the data subject<\/a>. The information obligation must therefore be respected at the time of collection, Article 13 of the GDPR. The information obligation can operate at several levels, where the most important information is, for example, stated in a warning sign, while the remaining information can be provided in another appropriate (and easily accessible) way.<\/p>\n\n\n<div id=\"newslettersignup\"><\/div>\n<div id=\"role-block_a795a1b7e20c1f3f243aeead5da80b01\" class=\"text-t-black bg-t-pink p-6 md:p-12 rounded-tr-50 rounded-bl-50 mb-4 lg:mb-12 text-center role\">\n  \n      <h2 class=\"text-xl lg:text-2xl max-w-screen-lg mx-auto text-t-black font-display mb-4\">\n      Receive our digest by email     <\/h2>\n        <h3 class=\"text-base max-w-screen-lg mx-auto text-t-black font-body mb-4\">Sign up to receive our digest by email every 2 weeks<\/h3>\n  \n  <div id=\"rmOrganism\">\n    <div class=\"rmEmbed rmLayout--vertical rmBase\">\n      <div data-page-type=\"formSubscribe\" class=\"rmBase__body rmSubscription\">\n                  <form method=\"post\" action=\"https:\/\/mailing.techgdpr.com\/145\/6351\/5e9fc3cdda\/subscribe\/form.html?_g=1698845230\" class=\"rmBase__content\">\n                  <div class=\"rmBase__container mx-auto max-w-screen-sm\">          \n            <div class=\"rmBase__section\">\n              <div class=\"text-left rmBase__el rmBase__el--input rmBase__el--label-pos-none\" data-field=\"email\">\n                <label for=\"email\" class=\"rmBase__compLabel rmBase__compLabel--hideable hidden\">\n                  Email address\n                <\/label>\n                <div class=\"rmBase__compContainer mb-2\">\n                  <input type=\"text\" name=\"email\" id=\"email\" placeholder=\"Email\" value=\"\" class=\"p-4 border rounded border-gray-400 w-full rmBase__comp--input comp__input\">\n                  <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section mb-4\">\n              <div class=\"rmBase__el rmBase__el--consent\" data-field=\"consent_text\">\n                <div class=\"rmBase__comp--checkbox\">\n                  <label for=\"consent_text\" class=\"flex space-x-2 items-baseline text-left vFormCheckbox comp__checkbox\">\n                    <input type=\"checkbox\" value=\"yes\" name=\"consent_text\" id=\"consent_text\" class=\"vFormCheckbox__input\">\n                    <div class=\"vFormCheckbox__indicator hidden\"><\/div>\n                    <div class=\"vFormCheckbox__label\">\n                                              I consent to the processing of my data and to receiving regular updates from TechGDPR. Data is processed according to our <a href=\"https:\/\/techgdpr.com\/privacy-policy\/\"> Privacy Notice<\/a>.                                          <\/div>\n                  <\/label>\n                <\/div>\n                <div class=\"rmBase__compError text-left font-display font-bold text-xs\"><\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--cta\">\n                <button type=\"submit\" class=\"inline-flex items-center justify-center px-8 py-3 text-white visited:text-white font-bodybold rounded-md bg-t-navy border-3 border-t-navy hover:border-t-navy hover:bg-transparent hover:text-t-navy transition-all hover:text-white cursor-pointer rmBase__comp--cta\">\n                  Subscribe\n                <\/button>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/form>\n      <\/div>\n      <div data-page-type=\"pageSubscribeSuccess\" class=\"rmBase__body rmSubscription hidden\">\n        <div class=\"rmBase__content\">\n          <div class=\"rmBase__container\">\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--heading\">\n                <div class=\"rmBase__comp--heading\">\n                  Thank you for your subscription!\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n            <div class=\"rmBase__section\">\n              <div class=\"rmBase__el rmBase__el--text\">\n                <div class=\"rmBase__comp--text\">\n                  We have sent you an email &#8211; please confirm your email address by clicking the activation link in it.\n      <!-- this linebreak is important, don't remove it! this will force trailing linebreaks to be displayed -->\n                  <br>\n                <\/div>\n              <\/div>\n            <\/div>\n          <\/div>\n        <\/div>\n      <\/div>\n    <\/div>\n  <\/div>\n\n      <script src=\"https:\/\/mailing.techgdpr.com\/form\/145\/6069\/8a53c9178b\/embedded.js\" async><\/script>\n  \n<\/div>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>Disney US settlement<\/strong><\/h4>\n\n\n\n<div class=\"wp-block-media-text is-stacked-on-mobile\" style=\"grid-template-columns:25% auto\"><figure class=\"wp-block-media-text__media\"><img decoding=\"async\" width=\"1024\" height=\"700\" src=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/image-1024x700.png\" alt=\"\" class=\"wp-image-11447 size-full\" srcset=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/image-1024x700.png 1024w, https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/image-300x205.png 300w, https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/image-768x525.png 768w, https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/image.png 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p><\/p>\n\n\n\n<p>On 31 of December, a federal judge required Disney to pay 10 million dollars to <a href=\"https:\/\/www.ftc.gov\/news-events\/news\/press-releases\/2025\/09\/disney-pay-10-million-settle-ftc-allegations-company-enabled-unlawful-collection-childrens-personal\">settle FTC allegations<\/a> that the company allowed personal data to be collected from children who viewed child-directed videos on YouTube without notifying parents or obtaining their consent as required by the Children\u2019s Online Privacy Protection Rule (COPPA Rule). <a href=\"https:\/\/www.ftc.gov\/system\/files\/ftc_gov\/pdf\/DisneyComplaint.pdf\">A complaint<\/a> alleged that <a href=\"https:\/\/www.ftc.gov\/legal-library\/browse\/cases-proceedings\/disney\">Disney violated the COPPA Rule by failing to properly label some videos that it uploaded to YouTube as \u201cMade for Kids<\/a>\u201d. <\/p>\n<\/div><\/div>\n\n\n\n<p>The complaint alleged that by mislabeling these videos, Disney allowed for the collection, through YouTube, of personal data from children under 13 who viewed child-directed videos and used that data for targeted advertising to children.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\">More enforcement decisions<\/h4>\n\n\n\n<p><strong>TikTok investigations: <\/strong>According to <a href=\"http:\/\/vitallaw.com\">vitallaw.com<\/a><strong>, <\/strong>the Spanish and Norwegian data protection authorities have issued warnings to TikTok users regarding the company\u2019s transfer of personal data to China, where national laws could require that data be shared with Chinese authorities. TikTok already faces EU fines over violations of the GDPR and was ordered to stop transferring personal data to China.&nbsp;<\/p>\n\n\n\n<p>So far, TikTok has been granted an interim injunction that allows the company to continue transferring personal data to China until the case is resolved. As a result, regulators are warning users to <a href=\"https:\/\/www.aepd.es\/prensa-y-comunicacion\/notas-de-prensa\/recomendaciones-usuarios-trasnferencias-tiktok?mkt_tok=MTM4LUVaTS0wNDIAAAGe5j2Oz_grrBD9cpnFlN2RUK4TKCbN19HNsb0RknpPYbpv4fgzz5y9cpCJx817NKT-H4BXP1sujCQtDhkCiFgtTy5BWXFFURPVZeY97QAvhthj\">read the online platform\u2019s notifications and privacy policies<\/a>, <a href=\"https:\/\/www.datatilsynet.no\/aktuelt\/aktuelle-nyheter-2025\/tiktok-fortsetter-a-overfore-personopplysninger-til-kina\/?mkt_tok=MTM4LUVaTS0wNDIAAAGe5j2OzsWt83I-_MmXFTq7o0_qfKq5GN3bp_DoP1WxsvWFk4mx5NBtF77qa2WqciZqiYKISvX2QMbcKDMkhyquskt4Zt9bD7-EGnqzXMzU1QJ5\">check their privacy settings and think about what they share in the app<\/a>. It is also recommended that businesses consider whether to continue using TikTok and conduct risk assessments.<\/p>\n\n\n\n<p><strong>PCRM software fine:<\/strong> Finally, the French CNIL has fined Nexpublica 1,700,000 euros for failing to provide sufficient security measures for a tool for managing the relationship with users in the field of social action.&nbsp; Nexpublica (formerly Inetum Software), specialises in the design of computer systems and <a href=\"https:\/\/www.cnil.fr\/fr\/securite-des-donnees-sanction-de-1-700-000-euros-lencontre-de-la-societe-nexpublica-france\">PCRM software used in particular by homes for disabled people<\/a>.<\/p>\n\n\n\n<p>At the end of 2022, Nexpublica customers made data breach notifications with the CNIL, because users of the portal had access to documents concerning third parties. The CNIL then carried out inspections of the company, which revealed the inadequacy of the technical and organisational measures. It is considered that the vulnerabilities found:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>were mostly the result of a <strong>lack of knowledge<\/strong> of the state of the art and basic safety principles;<\/li>\n\n\n\n<li>were known and identified by the company through <strong>several audit reports<\/strong>.<\/li>\n<\/ul>\n\n\n\n<p>Despite this, the flaws were only patched after the data breaches.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>GDPR enforcement simplified A new regulation came into force on 1 January, supplementing the GDPR. It speeds up the work of data protection authorities in enforcement cases that involve multiple countries in the EU\/EEA. The regulation provides, among other things, for time limits, stages of investigation, the exchange of information between authorities, and the rights [&hellip;]<\/p>\n","protected":false},"author":21,"featured_media":11454,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[8,94,88],"tags":[51,129,58,79,118,266,180],"class_list":["post-11446","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai","category-data-protection-digest","category-gdpr","tag-artificial-intelligence","tag-consumer-data-protection","tag-gdpr-compliance","tag-international-transfers","tag-law-enforcement-directive","tag-minors-data","tag-pseudonymisation"],"acf":[],"featured_image_urls":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280.jpg",1280,717,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280-300x168.jpg",300,168,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280-768x430.jpg",640,358,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280-1024x574.jpg",640,359,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280.jpg",1280,717,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280.jpg",1280,717,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable":"<p>GDPR enforcement simplified A new regulation came into force on 1 January, supplementing the GDPR. It speeds up the work of data protection authorities in enforcement cases that involve multiple countries in the EU\/EEA. The regulation provides, among other things, for time limits, stages of investigation, the exchange of information between authorities, and the rights of the parties concerned. In future, data protection authorities will have to issue a resolution proposal on a cross-border case as a rule within 12-15 months. In the most complex cases, the deadline can be extended by 12 months. The regulation will apply from April&hellip;<\/p>\n","category_list":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/ai\/\" rel=\"category tag\">Artificial Intelligence<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num":"0 comments","featured_image_urls_v2":{"full":["https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280.jpg",1280,717,false],"thumbnail":["https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280-150x150.jpg",150,150,true],"medium":["https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280-300x168.jpg",300,168,true],"medium_large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280-768x430.jpg",640,358,true],"large":["https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280-1024x574.jpg",640,359,true],"1536x1536":["https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280.jpg",1280,717,false],"2048x2048":["https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280.jpg",1280,717,false],"image-200-200":["https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280-200x200.jpg",200,200,true]},"post_excerpt_stackable_v2":"<p>GDPR enforcement simplified A new regulation came into force on 1 January, supplementing the GDPR. It speeds up the work of data protection authorities in enforcement cases that involve multiple countries in the EU\/EEA. The regulation provides, among other things, for time limits, stages of investigation, the exchange of information between authorities, and the rights of the parties concerned. In future, data protection authorities will have to issue a resolution proposal on a cross-border case as a rule within 12-15 months. In the most complex cases, the deadline can be extended by 12 months. The regulation will apply from April&hellip;<\/p>\n","category_list_v2":"<a href=\"https:\/\/techgdpr.com\/blog\/category\/ai\/\" rel=\"category tag\">Artificial Intelligence<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/data-protection-digest\/\" rel=\"category tag\">Data Protection Digest<\/a>, <a href=\"https:\/\/techgdpr.com\/blog\/category\/gdpr\/\" rel=\"category tag\">GDPR<\/a>","author_info_v2":{"name":"Olya Vasylyk","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"},"comments_num_v2":"0 comments","yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Data protection digest 3 Jan 2026: Improvements are being made to GDPR enforcement, US consumer privacy, and emerging &quot;Shadow AI&quot; concerns - TechGDPR<\/title>\n<meta name=\"description\" content=\"TechGDPR\u2019s review of the most important data-related stories: GDPR enforcement, US consumer privacy, and the emerging &quot;Shadow AI&quot;\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Data protection digest 3 Jan 2026: Improvements are being made to GDPR enforcement, US consumer privacy, and emerging &quot;Shadow AI&quot; concerns - TechGDPR\" \/>\n<meta property=\"og:description\" content=\"TechGDPR\u2019s review of the most important data-related stories: GDPR enforcement, US consumer privacy, and the emerging &quot;Shadow AI&quot;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/techgdpr.com\/blog\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\/\" \/>\n<meta property=\"og:site_name\" content=\"TechGDPR\" \/>\n<meta property=\"article:published_time\" content=\"2026-01-07T09:47:06+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-01-19T17:08:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1280\" \/>\n\t<meta property=\"og:image:height\" content=\"717\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Olya Vasylyk\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:site\" content=\"@techgdpr\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Olya Vasylyk\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\\\/\"},\"author\":{\"name\":\"Olya Vasylyk\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\"},\"headline\":\"Data protection digest 3 Jan 2026: Improvements are being made to GDPR enforcement, US consumer privacy, and emerging &#8220;Shadow AI&#8221; concerns\",\"datePublished\":\"2026-01-07T09:47:06+00:00\",\"dateModified\":\"2026-01-19T17:08:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\\\/\"},\"wordCount\":1227,\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/business-5475661_1280.jpg\",\"keywords\":[\"Artificial Intelligence\",\"consumer data protection\",\"GDPR Compliance\",\"International transfers\",\"Law Enforcement Directive\",\"minors data\",\"pseudonymisation\"],\"articleSection\":[\"Artificial Intelligence\",\"Data Protection Digest\",\"GDPR\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\\\/\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\\\/\",\"name\":\"Data protection digest 3 Jan 2026: Improvements are being made to GDPR enforcement, US consumer privacy, and emerging \\\"Shadow AI\\\" concerns - TechGDPR\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/business-5475661_1280.jpg\",\"datePublished\":\"2026-01-07T09:47:06+00:00\",\"dateModified\":\"2026-01-19T17:08:34+00:00\",\"description\":\"TechGDPR\u2019s review of the most important data-related stories: GDPR enforcement, US consumer privacy, and the emerging \\\"Shadow AI\\\"\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\\\/#primaryimage\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/business-5475661_1280.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2026\\\/01\\\/business-5475661_1280.jpg\",\"width\":1280,\"height\":717,\"caption\":\"enforcement\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/techgdpr.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Data protection digest 3 Jan 2026: Improvements are being made to GDPR enforcement, US consumer privacy, and emerging &#8220;Shadow AI&#8221; concerns\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#website\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"name\":\"TechGDPR\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/techgdpr.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#organization\",\"name\":\"TechGDPR\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"contentUrl\":\"https:\\\/\\\/staging.techgdpr.com\\\/wp-content\\\/uploads\\\/2018\\\/04\\\/TGDPR_logo_500px.png\",\"width\":501,\"height\":334,\"caption\":\"TechGDPR\"},\"image\":{\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/techgdpr\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/techgdpr\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/#\\\/schema\\\/person\\\/07e9c14fd01b25bd2c1907537e8547e8\",\"name\":\"Olya Vasylyk\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"contentUrl\":\"https:\\\/\\\/techgdpr.com\\\/wp-content\\\/uploads\\\/2021\\\/10\\\/readyIMG_3694-1-2-150x150.jpg\",\"caption\":\"Olya Vasylyk\"},\"description\":\"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.\",\"url\":\"https:\\\/\\\/techgdpr.com\\\/blog\\\/author\\\/olyav\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Data protection digest 3 Jan 2026: Improvements are being made to GDPR enforcement, US consumer privacy, and emerging \"Shadow AI\" concerns - TechGDPR","description":"TechGDPR\u2019s review of the most important data-related stories: GDPR enforcement, US consumer privacy, and the emerging \"Shadow AI\"","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\/","og_locale":"en_US","og_type":"article","og_title":"Data protection digest 3 Jan 2026: Improvements are being made to GDPR enforcement, US consumer privacy, and emerging \"Shadow AI\" concerns - TechGDPR","og_description":"TechGDPR\u2019s review of the most important data-related stories: GDPR enforcement, US consumer privacy, and the emerging \"Shadow AI\"","og_url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\/","og_site_name":"TechGDPR","article_published_time":"2026-01-07T09:47:06+00:00","article_modified_time":"2026-01-19T17:08:34+00:00","og_image":[{"width":1280,"height":717,"url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280.jpg","type":"image\/jpeg"}],"author":"Olya Vasylyk","twitter_card":"summary_large_image","twitter_creator":"@techgdpr","twitter_site":"@techgdpr","twitter_misc":{"Written by":"Olya Vasylyk","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\/#article","isPartOf":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\/"},"author":{"name":"Olya Vasylyk","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8"},"headline":"Data protection digest 3 Jan 2026: Improvements are being made to GDPR enforcement, US consumer privacy, and emerging &#8220;Shadow AI&#8221; concerns","datePublished":"2026-01-07T09:47:06+00:00","dateModified":"2026-01-19T17:08:34+00:00","mainEntityOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\/"},"wordCount":1227,"publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280.jpg","keywords":["Artificial Intelligence","consumer data protection","GDPR Compliance","International transfers","Law Enforcement Directive","minors data","pseudonymisation"],"articleSection":["Artificial Intelligence","Data Protection Digest","GDPR"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\/","url":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\/","name":"Data protection digest 3 Jan 2026: Improvements are being made to GDPR enforcement, US consumer privacy, and emerging \"Shadow AI\" concerns - TechGDPR","isPartOf":{"@id":"https:\/\/techgdpr.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\/#primaryimage"},"image":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\/#primaryimage"},"thumbnailUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280.jpg","datePublished":"2026-01-07T09:47:06+00:00","dateModified":"2026-01-19T17:08:34+00:00","description":"TechGDPR\u2019s review of the most important data-related stories: GDPR enforcement, US consumer privacy, and the emerging \"Shadow AI\"","breadcrumb":{"@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/techgdpr.com\/blog\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\/#primaryimage","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2026\/01\/business-5475661_1280.jpg","width":1280,"height":717,"caption":"enforcement"},{"@type":"BreadcrumbList","@id":"https:\/\/techgdpr.com\/blog\/data-protection-digest-03012026-improvements-are-being-made-to-gdpr-enforcement-us-consumer-privacy-and-emerging-shadow-ai\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/techgdpr.com\/"},{"@type":"ListItem","position":2,"name":"Data protection digest 3 Jan 2026: Improvements are being made to GDPR enforcement, US consumer privacy, and emerging &#8220;Shadow AI&#8221; concerns"}]},{"@type":"WebSite","@id":"https:\/\/techgdpr.com\/#website","url":"https:\/\/techgdpr.com\/","name":"TechGDPR","description":"","publisher":{"@id":"https:\/\/techgdpr.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/techgdpr.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/techgdpr.com\/#organization","name":"TechGDPR","url":"https:\/\/techgdpr.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/","url":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","contentUrl":"https:\/\/staging.techgdpr.com\/wp-content\/uploads\/2018\/04\/TGDPR_logo_500px.png","width":501,"height":334,"caption":"TechGDPR"},"image":{"@id":"https:\/\/techgdpr.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/techgdpr","https:\/\/www.linkedin.com\/company\/techgdpr"]},{"@type":"Person","@id":"https:\/\/techgdpr.com\/#\/schema\/person\/07e9c14fd01b25bd2c1907537e8547e8","name":"Olya Vasylyk","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","url":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","contentUrl":"https:\/\/techgdpr.com\/wp-content\/uploads\/2021\/10\/readyIMG_3694-1-2-150x150.jpg","caption":"Olya Vasylyk"},"description":"Creator and editor of TechGDPR\u2019s weekly Digest. Postgraduate masters Diploma in Data Protection, Digital law and Management. Over a decade Olga previously was a broadcast journalist in Ukraine and France specializing in international affairs.","url":"https:\/\/techgdpr.com\/blog\/author\/olyav\/"}]}},"_links":{"self":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11446","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/comments?post=11446"}],"version-history":[{"count":9,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11446\/revisions"}],"predecessor-version":[{"id":11468,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/posts\/11446\/revisions\/11468"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media\/11454"}],"wp:attachment":[{"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/media?parent=11446"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/categories?post=11446"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techgdpr.com\/wp-json\/wp\/v2\/tags?post=11446"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}