Zum Inhalt springen
aig Advertising Information Group
© aig
Werbung und Marktkommunikation, Fachverband

AIG Newsletter 20 July 2026

Advertising Information Group-Newsletter

Lesedauer: 5 Minuten

Einen Moment bitte. Ladevorgang läuft ...
0:00
Audio konnte nicht geladen werden. Erneut versuchen
0:00
0:00
20.07.2026

CONTENT:


NEWS

In this week's edition before the summer break: the European Commission finds the Code of Practice on Transparency of AI-generated content adequate to support compliance with key AI Act transparency obligations and the European Data Protection Board has also adopted new guidance on anonymisation, AI web scraping and blockchain technologies. Meanwhile, the European Parliament's ITRE and LIBE committees begin scrutiny of the Digital Omnibus proposal, the CJEU clarifies the rules governing online access to public domain works across Member States, and the Commission issues preliminary findings against Meta under the Digital Services Act over the alleged addictive design of Instagram and Facebook. Finally, the Commission reaffirms the importance of the EU–US Data Privacy Framework as the basis for transatlantic personal data transfers. 

This newsletter will return on 14 September. Until then, we wish you a relaxing and pleasant summer.


EU FINDS AI TRANSPARENCY CODE ADEQUATE

The Commission published its opinion finding that the Code of Practice on Transparency of AI-generated content adequately covers the AI Act transparency obligations under Articles 50(2), (4) and (5). The voluntary code is intended to help providers and deployers of generative AI systems comply with rules on marking, detecting and labelling AI-generated or manipulated content, including deepfakes and certain public-interest text. The AI Board also assessed the code as adequate, noting that it sets out eight commitments covering obligations for both providers of AI systems and deployers using AI systems to generate deepfakes or certain text. Providers and deployers may rely on the code to demonstrate compliance across the EU, but adherence does not constitute conclusive evidence of compliance, and competent authorities may still assess actual implementation.


EDPB ADOPTS AI AND ANONYMISATION GUIDELINES

On 8 July, the European Data Protection Board (EDPB) adopted new guidelines on anonymisation and web scraping in the context of generative AI, alongside the final version of its guidelines on blockchain technologies. The anonymisation guidance aims to provide greater legal certainty on when data can be considered truly anonymous, while the web-scraping guidance clarifies how GDPR requirements apply when personal data is collected online for AI training and development. The Board also finalised its blockchain guidance, providing recommendations for organisations processing personal data through blockchain-based systems. The developments are likely to be of particular interest to businesses using AI tools, data analytics and emerging technologies that rely on large-scale data processing.


ITRE & LIBE REVIEW DIGITAL OMNIBUS DRAFT

On 13 July, the EP's ITRE and LIBE Committees discussed the draft Digital Omnibus report, which supports simplification through measures including a single reporting portal, more risk-based data protection rules, reduced cookie-banner fatigue, and improved data access for research and AI. The draft also preserves key safeguards, such as GDPR protections, data subjects' rights and SME protections under the Platform-to-Business Regulation.

Politically, EPP, Renew and ECR backed simplification and competitiveness, while S&D, Greens/EFA and The Left stressed that reforms must not weaken privacy, consumer protection or fundamental rights. Amendments are being tabled over the summer, with Parliament awaiting an impact assessment later this year. IMCO and JURI votes are expected in November.


CJEU BACKS EU-WIDE SHARING OF PUBLIC DOMAIN WORKS

On 9 July, the CJEU ruled in Case C-788/24, Anne Frank Fonds, that a work in the public domain in some Member States may be published online free of charge, even if it remains protected by copyright in another Member State. The Court clarified that the website must use an effective technological measure, such as state-of-the-art geo-blocking, to prevent access from Member States where the work is still protected. If the geo-blocking is not effective and the work is unlawfully communicated to the public, responsibility lies with the person who made the work available online, not the VPN provider used to bypass the restriction.


COMMISSION FINDS META'S DESIGN BREACHES DSA

On 10 July, the Commission preliminarily found Meta in breach of the Digital Services Act over the addictive design of Instagram and Facebook. The investigation focuses on features such as infinite scroll, autoplay, push notifications and highly personalised recommender systems, which the Commission says may contribute to compulsive use. The Commission considers that Meta did not adequately assess risks to users' physical and mental wellbeing, especially for minors and vulnerable adults, and that its time-management tools, parental controls and safety information are not sufficiently effective. The preliminary findings are part of the Commission's DSA proceedings against Meta, launched in May 2024. Meta can now respond, and the European Board for Digital Services will be consulted. EVP Henna Virkkunen stressed that the DSA provides a framework to hold platforms accountable for addictive design.


EU-US DATA FLOWS REMAIN UNDER SCRUTINY

The European Commission has reiterated that the EU–US Data Privacy Framework (DPF) remains the basis for the free flow of personal data from the EU to participating US organisations. The framework was adopted to address concerns raised by the Court of Justice of the EU in the Schrems II judgment and includes safeguards limiting access to data by US intelligence authorities, alongside redress mechanisms for EU individuals. For businesses operating across the Atlantic, the DPF continues to provide an important mechanism for international data transfers, supporting digital services, advertising, cloud computing and other data-driven activities while facilitating compliance with EU data protection rules.


DATES FOR YOUR DIARY

July 20-24: Green Week – The European Parliament will then go into summer recess. Committees work will resume the week of 31 August

July 20: Informal meeting of competitiveness ministers (Research and innovation) over two days

July 23: Informal meeting of environment and energy ministers over two days