This will be an atypical edition of Zero Party Data. We are back late: you will have already noticed that we have had some trouble with that paper that proves that your favorite AI agent likelyhas surely betrayed you by telling Adtech more about you than your mother has told your friends on any of those unforgettable occasions.
We will start with an amalgamation of news that we want to highlight, without being exhaustive—since we’ve already missed the boat on that—and then we’ll move on to the current events section.
IAB Europe finally decided to explain to the user in TCF 5.0.b) what fingerprinting is (”Special Feature 2” is no longer called “actively scan device characteristics” and is now “link devices based on actively collected information”). Apple notoriously damages the wording of the ATT under pressure from the Bundeskartellamt (the body, not the famous CJEU ruling). Uber was hit with 825 million for deactivating driver accounts automatically without notice and without human oversight.
Lusha was sanctioned by the Garante with two million for almost exactly the same thing that the CNIL qualified as “outside the scope of the GDPR”. Attendees of my training are well aware of this latest resolution.
The French Supreme Court threw out the ban on social media for children under 15. The The Audiencia Nacional ratified the precautionary suspension of activity ordered by the AEPD regarding Worldcoin (now World, or rather “Boo” harhar because it’s been left all interruptus). What a summer Sam Altman is having.
Interesting post from Natzir about a most curious thing: Claude’s watermark on its synthetic text. It explains what it is and how to break it. I wrote this other piece with one of my favorite gifs illustrating it.
You are reading ZERO PARTY DATA. The newsletter on current affairs and technology law by Jorge García Herrero and Darío López Rincón.
In the spare time this newsletter leaves us, we solve complicated issues related to personal data protection regulations and artificial intelligence. If you have any of those, give us a wave. Or contact us by email at jgh(arroba)jorgegarciaherrero.com
🗞️Data World News 🌍
.- It seems the Irish Presidency of the Council is trying to water down the issue for major AI players (even more so) by facilitating legitimate interest for scraping data for improvement/development and operation + a broad-brush approach to considering pseudonymized data as non-personal if the person cannot be identified (avoiding any nuance regarding technical measures). Noyb reports and criticizes this in detail in a post from this week:
.- The Irish DPC hits Google with 403 million for processing, as we all know, location data/what we do across its services: “Web & App Activity,” “Location History,” and “Location Precision.” The mind-boggling thing is that these are stated to be facts reported by the BEUC and consumer associations in 2020. The usual 6 years of investigation.
The resolution is not yet published, but the DPC provides a very clear infographic in the note. It is something the rest of the authorities could copy.
.- To the list of algorithmic information and transparency traces from that Ministry of Labor guide or the provision in the Workers’ Statute on mandatory information to the workers’ legal representatives (RLT), an additional one is coming that does not change much of the above: guaranteeing the information to the employee themselves on the subject in the employment contract or alternatively with proof for the company. Royal Decree 723/2026
From October 5th, when it enters into force, it will be necessary to provide or publish accessible information on the different algorithmic or automated decision-making systems applied, very much in line with the GDPR if it is something that does not structurally reach article 22, or something more detailed if it does:
“The existence of algorithmic or automated decision-making systems. The foregoing shall include the guidelines, criteria, and operating rules of said systems when used for decision-making regarding the determination, establishment, variation, or modification of working conditions, such as the duration and distribution of working hours, the assignment of tasks, the determination of salaries, professional progression, the workplace, or the termination of the contract”
For a more detailed analysis, we recommend the following note seen on LinkedIn.
.- We now have the draft Regulation that will make that magical age verification app, which still has zero-knowledge proof doubts, mandatory. It is proposed before Parliament, but it is already here: EU Kids Act.
Curiously, it will be able to overlap in everything concerning the avoidance of dark patterns and transparency with the also future Digital Fairness Act.
👦 The main interest is the prohibition of access to social networks and content-sharing platforms for children under 13, but it is surprising that it mentions video games and many other daily applications. And regarding video games, it is being looked into whether Parliament will include something in the Digital for Stop Killing Games.
Software application stores;
Operating systems;
Artificial intelligence assistants: “an artificial intelligence system, including general-purpose AI systems, that offers continuous and personalized interaction or companionship that simulates or facilitates a social, emotional, or interpersonal relationship with a user”; and
General conversational chatbots.
👧 Complete ban for those under 13, limited under guardianship for those 13 to 15, and with their own account and fewer restrictions from 15 to 18, but exclusively for social media and content sharing platforms. This is where it mandates the use of the EU Identity Wallet/app from a validated provider as the only option.
👦 Alternative third-party verification solutions in other cases of store limitations and that “secure by default” state of not having anything harmful enabled. As long as they are completely zero-knowledge proof and meet the same requirements as the official one. The funny thing is: which third-party service seen so far truly delivers on this, if not even the official one is guaranteed?
👧 Regarding data protection on this same topic of age verification, it introduces a specific Article 28 that requires any system of this type not to identify, locate, track, cross-reference, profile, or perform any commercial activity. Not much of a surprise, but it is taking a stand.
👨👩👧 A 6-month period would be granted for checking existing users, but it is interesting that a provider who is already clear on whether a user is an adult or old enough to have an account on their own can simply count them as verified. Never forget that Discord, which backtracked on the issue, clearly acknowledged that with the current profiling they performed on users, they could already infer their age quite accurately.
And that the “age signal” can be saved to avoid future verification.
.- Let no one forget that Brazil is already a safe third country with signed adequacy decision. More was said about the negotiation period leading up to it than about the closing and signing (dated January 2026). And it seems to be without any annex or additional bolstering, beyond the European Commission praying very hard that this house of cards holds up.
̷̷ Coffee-obsessed data documents ☕️
.- EDPB guidelines on the imposition of fines by authorities, since we then see strange cases where some millionaire company collapses for not having strictly complied with this issue.
Some important reminders:
Absolute incompatibility between warnings and fines:
That the duty of cooperation in the procedure begins to be a mitigating factor if it can be demonstrated that the offender complies beyond the letter of the GDPR or the DPA order.
That the avoidance of cost or indirect benefit as a result of blatantly ignoring the GDPR must no longer be considered minor and should incur a fine to rebalance karma and the bottom line.
And the following 5-step test. Highlighting that one must correctly interpret whether the infringement is intentional or negligent. In the latter case, softening the tone:
“The intentional or negligent character of the infringement (Article 83(2)(b) GDPR) should be assessed taking into account the objective elements of conduct gathered from the facts of the case. The EDPB highlighted that it is generally admitted that intentional infringements, “demonstrating contempt for the provisions of the law, are more severe than unintentional ones”25. In case of an intentional infringement, the supervisory authority is likely to attribute more weight to this factor. Depending on the circumstances of the case, the supervisory authority may also attach weight to the degree of negligence. At best, negligence could be regarded as neutral.”
.- CNIL hat-trick:
The famous one from a few weeks ago of the 825 million euro joint fine with the Dutch authority for Amazon. The fully automated decision with significant effects of the temporary deactivation due to possible fraud or low rating of its drivers turned out to be expensive. The completely irrelevant effect that this deactivation meant a full impediment to being able to work/earn income, and the complete lack of human supervision anywhere.
500,000 euros for a hospital which had security of the level that the 32 is interested in, at the level of the Louvre’s. By not having two-factor authentication or access profile limitations so that only assigned doctors can see them, someone got right into their kitchen with access to the medical records of all the hospital’s patients. And to top off the breach, they did not inform the 200,000 people the patients designated as trusted third parties (their personal data was among what was accessed).
300,000 for an IT company that did not believe much in satisfying the rights of erasure exercised by candidates or former employees, for the most part. Without ignoring that there was surely an underlying swell, it is not reported here whether it had been managed or if a response was given out of time.
💀Death by Meme🤣
📃The paper of the week
.- Interesting paper that plays with the Kafka analogy to recall the problem of legal compliance in AI. That “appearance of good law” at first glance that later turns into failing like a shotgun in detail. KafkaGPT: On algorithmic bureaucracy and keeping law’s promise. Once again, the importance of human control being decisive and that the legal aspect must be in the very genesis of the AI system to avoid decisions with machine learning that ignore the fundamental nuances of the law.
“Failure looks different across the three modes of doing law. In text-driven systems, the danger is indeterminacy and the quiet expansion of discretion off the page. In code-driven systems, the danger is over-specification: the flattening of legal meaning to what the programmer thought the words must mean, with context squeezed out. In data-driven systems, the danger is under-specification: targets that proxy the wrong thing, labels that embed past error, shifts in population or policy that make last year’s regularities misleading, and an explanatory surface that offers importance weights where the law demands reasons. Code- and data-driven systems also present novel problems of automaticity and cadence that can render systems inhuman, in a very real sense.”
.- “A relative mess”: relative identifiability and legal liability gaps in the application of SRB/ Scania to multi-party environments;
The AI stuff
🛠️Useful tools
.- It has been quite a while since the EDPS released the original cookie inspection tool (WEC), although they later made a more limited ‘easy’ to use one. The ‘easy’ part was clearly intended for someone who wasn’t a legal expert but was accustomed to poking around on GitHub. For everyone else, it was a mess to be solved with time and carefully selected questions for Claude.
For whatever reason, we managed to install it and get it working in the browser, so we’re sharing it with you. In artifact format with all the information, and with a link to a zip file for testing. It has been reduced to the bare minimum that the EDPS should have put on the table: a turn-key installer that doesn’t do anything strange, and one that starts the analysis each time by asking you to enter the website to be inspected.
Out of pure caution, although it comes exclusively from the EDPS GitHub and we subjected Claude to a KGB-style interrogation to check that nothing calls any server and does nothing other than save the result locally, the right thing to do is test it in a test environment.
If anyone wants a Windows installer that works, just ask and we’ll upload it to Github.
And as useful and recommended tools for this summer: Antares, TurboVec, LocalAI by Marlon Paz, Marlon Paz and Hoang Van Hao.
Last but not least: keep an eye on Open Router.
🙄 The final nonsense
Let whoever hasn’t gone to Claude with a questionable prompt, but one that it later understood better than even you thought it would, hit the keyboard. It’s the 2.0 version of asking Google for a song by giving it any invented thing you might have heard.
If you miss any doc, comment, or bit of nonsense that manifestly should have been in this week’s Zero Party Data, write to us or leave a comment and we’ll consider it for the next one.
Thanks for reading Zero Party Data! Subscribe for free to receive new posts and support my work.













