Kritia Law WatchAI-generated
EU AI events and CRA reporting dates; ICO Police Scotland investigation
AI-generated. This briefing was drafted by artificial intelligence and passed Kritia’s automated source and claims checks. It did not receive human editorial review before publication.
UODO announced an AI lecture, a webinar and a CRA article 14 update. The UK ICO said its Police Scotland SAR investigation remains live and has reached no conclusion.
01 — ENFORCEMENT
Decisions authorities and courts actually published.
ICO investigation into Police Scotland SAR compliance (2 minute read)
UK Information Commissioner’s Office· GBNot law yet
The UK Information Commissioner’s Office said it is investigating Police Scotland’s compliance when handling subject access requests. It said the investigation is seeking to establish whether Police Scotland failed, or is failing, to comply with specified UK GDPR and Data Protection Act obligations, including the statutory response timescale; the ICO said the investigation is live and has reached no conclusion.
Why it matters to you
The statement concerns SAR handling and expressly does not predetermine the outcome. Businesses using AI products may wish to distinguish an announced investigation from a finding of non-compliance.
02 — RULES & GUIDANCE
New or changed official text, guidance and proposals.
CRA Article 14: cybersecurity reporting for digital products (4 minute read)
Polish Personal Data Protection Office (UODO)· EU
UODO said CRA Article 14 applies from 11 September 2026 to products with digital elements, including mobile applications, IoT devices and locally installed IT systems. It described early warnings within 24 hours and reports within 72 hours for actively exploited vulnerabilities and serious incidents, and said the remaining CRA provisions apply from 11 December 2027.
Why it matters to you
UODO says CRA and GDPR notification obligations can operate in parallel in the circumstances it describes. Its account also links product incident information to an administrator’s assessment of possible personal-data breaches.
03 — PRACTICAL
Worth doing, or worth the time to read.
OD AI ACT DO KRAJOWYCH REGULACJI – UODO webinar (3 minute read)
Polish Personal Data Protection Office (UODO)· EU
UODO announced a 30 September 2026 webinar on applying AI in personal-data protection, the role of its president in Poland’s national AI supervision system and issues to examine before deploying AI systems. The programme includes presentations on GDPR and AI Act compliance, risk assessment under both instruments, regulatory sandboxes and initial questions for organisations planning AI use.
Why it matters to you
The webinar is aimed in part at controllers, data protection officers and people responsible for technology purchasing and implementation. It may help a small firm follow the topics UODO has chosen for discussion before using AI products.
04 — THE WIDER VIEW
Written about the rules, not by the people who make them.
Nothing worth your time today.
05 — QUICK LINKS
- Artificial Intelligence and the Law: UODO open expert lecture (2 minute read)
Polish Personal Data Protection Office (UODO) — UODO announced an 11 September open expert lecture on generative models and the European legal framework, covering the AI Act, GDPR and copyright; it said AI development presents new challenges for personal-data protection, copyright and new AI regulations.
06 — COUNTDOWN
78days · 2026-12-02
Machine-readable marking for generative systems placed on the market before 2 Aug 2026.
What this isn’t
News about the law, not legal advice, and not an assessment of your business. Items marked Analysis are someone’s view of the rules, not the rules. Whether a duty applies to you depends on what you actually do. The public guides explain the general rules and link their primary sources.
Get this each publishing day
Free by email, with no account and no card. About a minute to read, every reported item linked to its source.
