Kritia Law WatchAI-generated
EU: Polish Banking Law judgment, EDPB fines guidelines, minors statement
AI-generated. This briefing was drafted by artificial intelligence and passed Kritia’s automated source and claims checks. It did not receive human editorial review before publication.
This issue covers a Polish Supreme Administrative Court judgment reported by UODO, new EDPB guidelines on GDPR fines, and two press or industry alerts on minors’ protection and AI safety. The Polish judgment is national and concerns Polish Banking Law, not an EU-level judgment.
01 — ENFORCEMENT
Decisions authorities and courts actually published.
Supreme Administrative Court agrees with the position of the President of the Personal Data Protection Office concerning individuals conducting business activities (3 minute read)
Personal Data Protection Office of Poland (UODO)· EU
UODO reports that Poland’s Supreme Administrative Court interpreted Articles 105a(2) and (3) of the Polish Banking Law as also applying to natural persons conducting business activities. Where the stated conditions are met, banks and financial institutions may process relevant personal data without consent, including for up to five years after an obligation has expired.
Why it matters to you
This is a Polish judgment concerning Polish Banking Law, not an EU-level data-processing judgment. Its stated interpretation may be relevant when an AI product is used in banking or financial-institution contexts in Poland.
02 — RULES & GUIDANCE
New or changed official text, guidance and proposals.
Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR (2 minute read)
European Data Protection Board· EU
The European Data Protection Board published Guidelines 04/2026 on applying the power to impose administrative fines alongside other corrective powers under the GDPR. The page also lists Guidelines 3/2025 on the interplay between the DSA and the GDPR as a related document.
Why it matters to you
The document addresses the relationship between GDPR administrative fines and other corrective powers. The evidence provided does not state its detailed interpretation or practical effect.
03 — PRACTICAL
Worth doing, or worth the time to read.
Nothing new here today.
04 — THE WIDER VIEW
Written about the rules, not by the people who make them.
Nothing worth your time today.
05 — QUICK LINKS
- Press statement of the 20th meeting of the European Board for Digital Services (2 minute read) Not law yet
European Commission — A European Commission page carries the European Board for Digital Services’ press statement: the Board discussed the Commission’s announcements on child safety and welcomed attention to minors’ protection in the proposed EU Kids Act. - INDUSTRY ALERT: Attorney General James Urges Workers With Knowledge of Unsafe AI Development to File Whistleblower Complaints (2 minute read)
New York Attorney General — The New York Attorney General’s alert says the RAISE Act takes effect on January 1, 2027 and requires large AI developers to disclose safety measures and report incidents; it separately says the SHIELD Act requires companies generally to maintain reasonable data-security practices.
06 — COUNTDOWN
64days · 2026-12-02
Machine-readable marking for generative systems placed on the market before 2 Aug 2026.
What this isn’t
News about the law, not legal advice, and not an assessment of your business. Items marked Analysis are someone’s view of the rules, not the rules. Whether a duty applies to you depends on what you actually do. The public guides explain the general rules and link their primary sources.
Get this each publishing day
Free by email, with no account and no card. About a minute to read, every reported item linked to its source.
