Back issues
Every resource we have surfaced so far, listed by issue, most recent first. Each has a short summary — sometimes a page of its own, sometimes a section of a themed issue — and a link to the original; we point to the source and never host or give away the material itself. 30 resources across 12 issues, with a further four surfaced outside the weekly run, and we hope you find something useful here.
Read the current issue Subscribe by RSS
Issue 12 —
Themed: when is scraping lawful, and what do you have to do to make it so? Three resources on the everyday scraping question rather than the AI-training one, on one summary page.
- Handreiking scraping door particulieren en private organisaties
Autoriteit Persoonsgegevens (Netherlands) · practical guidance — April 2025 edition · Dutch only · scraping outside the AI-training context, with the UK position alongside - Fiche focus : collecte des données par moissonnage (web scraping)
CNIL (France) · fiche pratique — 19 June 2025 · French only · the mandatory measures and additional safeguards expected in a scraping legitimate-interests assessment - Concluding joint statement on data scraping and the protection of privacy
Global Privacy Assembly, International Enforcement Cooperation Working Group · 28 October 2024 · sixteen authorities including the ICO · protecting your own platform from being scraped
Issue 11 —
How do other organisations handle access requests — and where do they struggle? A regulator-authored benchmark for the access-request process.
- Implementation of the Right of Access by Controllers (the CEF 2024 Report and its National Annex)
European Data Protection Board · Coordinated Enforcement Framework report — final, adopted 16 January 2025 · 30 supervisory authorities, 1,185 controllers, seven challenges · appendix of national reports
Issue 10 —
Themed: designing for children’s data — four regulator frameworks that converge, threaded on privacy by design, on one summary page.
- ICO — the Children’s Code (Age Appropriate Design Code)
Information Commissioner’s Office (UK) · fifteen standards for online services likely to be accessed by children · strategy progress update August 2026 - DPC — Children Front and Centre: the Fundamentals
Data Protection Commission (Ireland) · fourteen Fundamentals for a child-oriented approach · final, December 2021 - CNIL — eight recommendations for protecting children online
Commission Nationale de l’Informatique et des Libertés (France) · August 2021 - OAIC — the Children’s Online Privacy Code (in development)
Office of the Australian Information Commissioner · registration due by 10 December 2026
Issue 9 —
What “securely erased” means — the revised NIST media-sanitization guidelines.
- NIST SP 800-88 Rev. 2 — Guidelines for Media Sanitization
National Institute of Standards and Technology (US) · Special Publication — final, 26 September 2025 · supersedes the withdrawn Rev. 1 (2014)
Issue 8 —
Themed: what counts as a tracking technology? Two new resources, read together with four revisited from issue #3: the EDPB Guidelines 2/2023, the ICO storage-and-access guidance, the EDPS Website Evidence Collector and the EDPB Website Auditing Tool.
- CNIL Recommendation — Tracking Pixels in Emails
Commission nationale de l’informatique et des libertés (France) · Recommendation — Délibération n° 2026-042, 12 March 2026 - Garante Linee Guida — Tracking Pixels in Email
Garante per la protezione dei dati personali (Italy) · Guidelines — Provvedimento n. 284, 17 April 2026 · compliance due 29 October 2026
Issue 7 —
Deciding whether data can be released as anonymous.
- The Anonymisation Decision-Making Framework (2nd Edition)
UK Anonymisation Network (UKAN), University of Manchester · Practitioner framework — first published 2016, 2nd edition 2020
Issue 6 —
Security measures under Art. 32.
- CNIL Practice Guide — Security of Personal Data
Commission nationale de l’informatique et des libertés (France) · Practice guide — 2024 edition; French PDF updated 2026
Issue 5 —
Agentic AI and where responsibility sits.
- Agentic Artificial Intelligence from the Perspective of Data Protection
Agencia Española de Protección de Datos (Spain) · Guidance — final
Issue 4 —
DPIA — method, templates and risk management.
- Template for a Data Protection Impact Assessment (and its Explainer)
European Data Protection Board · Draft — consultation closed, not finalised - Risk Management and Impact Assessment in the Processing of Personal Data
Agencia Española de Protección de Datos (Spain) · Guidance — final - The PIA Guides and the Open-Source PIA Software
Commission Nationale de l'Informatique et des Libertés (France) · Guidance + open-source tool - DPIA Templates — including a Template for AI Solutions
Datatilsynet (Denmark) · Templates — final · Danish only
Issue 3 —
Cookies, trackers and website auditing.
- EDPB Website Auditing Tool
European Data Protection Board · Open-source tool - Website Evidence Collector (WEC) & WEC Online
European Data Protection Supervisor · Open-source tool - Guidelines 2/2023 on the Technical Scope of Art. 5(3) ePrivacy Directive
European Data Protection Board · Guidelines — adopted - ICO Guidance on the Use of Storage and Access Technologies
Information Commissioner's Office (UK) · Guidance — final
Issue 2 —
Method, maturity, benchmarking — and a training curriculum.
- The Standard Data Protection Model (SDM)
Datenschutzkonferenz (Germany) · Methodology / framework - Privacy Maturity Assessment Framework (PMAF)
Government Chief Privacy Officer (New Zealand) · Maturity model - GDPR Enforcement Tracker
CMS (law firm) · Reference database - Law & Compliance in AI Security & Data Protection (EDPB SPE)
EDPB Support Pool of Experts · Expert training
Issue 1 —
The launch issue.
- Software Development with Data Protection by Design and by Default
Datatilsynet (Norway) · Practical guidance - Guidelines 01/2025 on Pseudonymisation
EDPB · Guidelines (draft) - Building Accountable AI Programs: Mapping Emerging Best Practices to the CIPL Accountability Framework
CIPL · White paper - Cost of a Data Breach Report 2025
IBM / Ponemon · Annual report
Also in the Hub
Resources surfaced outside the weekly issues. Each has a summary page of its own and links to the original.
- Vejledning om tilsyn med databehandlere — supervising data processors
Datatilsynet (Denmark) · guidance — October 2021 · Danish only · a four-factor point scale and six supervision concepts for Art. 28 oversight - Guide pratique : Les durées de conservation
CNIL (France), with SIAF · practical guide — version July 2020 · French only · the three-phase data lifecycle, an analysis grid, and the sector retention référentiels - La protección de datos en las relaciones laborales
AEPD (Spain) · practical guide — updated December 2025 · Spanish only · recruitment, social-media screening, automated sifting, monitoring and biometrics at work - Recommendations 1/2026 — Processor Binding Corporate Rules (Art. 47 GDPR)
European Data Protection Board · draft — adopted for public consultation 15 January 2026, consultation closed 2 March 2026, final pending · English
