← All briefings

Kritia Law WatchAI-generated

Securitas Direct fined €100,000; CNIL releases survey; NHS commission sets out AI blueprint

AI-generated. This briefing was drafted by artificial intelligence and passed Kritia’s automated source and claims checks. It did not receive human editorial review before publication.

The EDPB says Spain’s AEPD imposed a €100,000 fine on Securitas Direct and ordered changes to notices. CNIL reports DPO survey findings, while an NHS-led commission recommends AI measures that GOV.UK says the government and MHRA will consider before a formal response.

01ENFORCEMENT

Decisions authorities and courts actually published.

The Spanish DPA fined Securitas Direct 100 000 EUR for making the exercise of data subject rights more difficult by directing individuals to a chargeable telephone number (3 minute read)

European Data Protection Board / AEPD· EU

The EDPB says the Spanish DPA (AEPD) imposed a EUR 100,000 fine on Securitas Direct for infringing Article 12 GDPR. It also ordered the company to replace, within 12 months, notices referring to the chargeable 902 telephone number.

Why it matters to you

The decision concerns how a business presents channels for exercising data-subject rights. The EDPB says other free website channels did not remedy the notice’s specific reference to the chargeable number.

02RULES & GUIDANCE

New or changed official text, guidance and proposals.

Independent Commission led by NHS doctors sets out blueprint to accelerate safe AI adoption in healthcare (4 minute read)

Medicines and Healthcare products Regulatory Agency / GOV.UK· GBNot law yet

The commission recommends continuous, real-world monitoring of AI-enabled medical devices throughout their working life, public access to safety information, and stronger MHRA powers. GOV.UK says the government and MHRA will carefully consider the recommendations, with a formal response to follow in due course.

Why it matters to you

This is a commission blueprint, not a final response or confirmed change in law. Its recommendations point to ongoing monitoring, safety transparency and possible stronger regulatory powers for AI-enabled medical devices.

03PRACTICAL

Worth doing, or worth the time to read.

The role of the Data Protection Officer (DPO) in the age of artificial intelligence: survey results released (3 minute read)

CNIL· EU

CNIL reports that 70% of responding organisations use or plan to use AI, while governance is often still largely unstructured. It says less than a quarter have a formal AI strategy or policy, and that 31% have started preparing for the AI Regulation’s entry into force.

Why it matters to you

The survey describes reported organisational practice, not a compliance assessment of any particular firm. It may help firms compare their own AI governance discussions with the patterns CNIL reports.

04THE WIDER VIEW

Written about the rules, not by the people who make them.

Nothing worth your time today.

05COUNTDOWN

70days · 2026-12-02

Machine-readable marking for generative systems placed on the market before 2 Aug 2026.

What this isn’t

News about the law, not legal advice, and not an assessment of your business. Items marked Analysis are someone’s view of the rules, not the rules. Whether a duty applies to you depends on what you actually do. The public guides explain the general rules and link their primary sources.

Get this each publishing day

Free by email, with no account and no card. About a minute to read, every reported item linked to its source.