Have any questions? +1 646.844.5712 (US)

  • Facebook
  • LinkedIn
  • Twitter
HiTech ServiceHiTech Service
  • Home
  • About
  • Services
    • Software Development
    • Customer Support
    • Quality Assurance
    • Managed Services
    • Compliance Audit
    • GDPR Compliance
    • Competency Center
    • Emergency IT Support
    • Software as medical device
    • Local AI Agent Development
  • Projects
  • GDPR
  • Articles
  • Case Studies
  • Contact
Menu
  • Home
  • About
  • Services
    • Software Development
    • Customer Support
    • Quality Assurance
    • Managed Services
    • Compliance Audit
    • GDPR Compliance
    • Competency Center
    • Emergency IT Support
    • Software as medical device
    • Local AI Agent Development
  • Projects
  • GDPR
  • Articles
  • Case Studies
  • Contact
A magnifying glass with an EU-star pattern inspecting a grid of data-block icons, with a few blocks highlighted in gold

GDPR Regulators Just Finished Grading Europe on ‘The Right to Be Forgotten.’ Now They’re Grading Honesty.

By Alex

For all of 2025, 32 European data protection authorities quietly investigated the same question: when someone asks a company to delete their personal data, does the company actually do it? The European Data Protection Board published its findings on February 18, 2026 — and a month later, without much pause, launched an entirely new investigation into a different question: do companies even tell people, clearly and honestly, what data they’re collecting and why?

The shift from one to the other isn’t a coincidence or a scheduling accident. It’s the EDPB’s Coordinated Enforcement Framework doing exactly what it’s designed to do — and this year’s pivot, from deletion to disclosure, lands at a moment when AI systems have made both questions harder to answer than they used to be.

What the Erasure Investigation Actually Found

A circuit-board paper shredder destroying data-block icons, with faint ghosted block outlines remaining in the output tray, symbolizing incomplete data deletion

The 2025 Coordinated Enforcement Action targeted Article 17 GDPR — the right to erasure — because it’s one of the rights individuals invoke most often, and one data protection authorities field the most complaints about. Of the 32 participating DPAs, nine opened or continued formal investigations, and 23 ran fact-finding exercises across companies in their jurisdictions.

The report surfaced seven recurring problems, and they’re the kind that suggest structural gaps rather than isolated bad actors. Companies relied on weak anonymization techniques as a substitute for actual deletion — scrubbing a name from a record while leaving enough attached data to re-identify the person. Retention periods were inconsistently defined, so “how long do we keep this” had no clear answer even inside the same company. Backups were a recurring blind spot: front-end systems would delete a record while an untouched copy persisted in backup infrastructure for months. And because the right to erasure isn’t absolute — it has to be balanced against other rights and legal obligations — many controllers simply didn’t have a defined process for making that judgment call consistently.

None of this required malice. It required exactly what you’d expect from data infrastructure that grew organically over years without erasure requests being designed in as a first-class operation from the start.

Why the EDPB Moved to Transparency Next

The 2026 Coordinated Enforcement Framework action, launched March 19, targets Articles 12 through 14 of GDPR — the requirement that companies tell individuals, in clear and accessible language, what data is being collected, why, and what happens to it. Twenty-five DPAs are participating this round.

The logic connecting the two years isn’t obvious at first, but it holds up: you can’t meaningfully exercise a right to erasure, or any other GDPR right, if you were never told in the first place what data existed about you to begin with. Transparency is the precondition every other right depends on. A company can build a technically perfect deletion pipeline and still fail GDPR if the privacy notice describing what it collects is vague, buried, or written to obscure rather than inform. The EDPB running erasure enforcement one year and transparency enforcement the next isn’t a change of subject so much as working backward through the dependency chain — checking the foundation after checking what’s built on top of it.

Why This Lands Differently in an AI Company

A translucent frosted glass box with data blocks flowing in on one side and blurry indistinct shapes flowing out the other, symbolizing an opaque AI model

Transparency and information obligations were always awkward for any company running complex data pipelines, but AI systems make the awkwardness structural rather than incidental. A conventional web form collects a defined, enumerable set of fields — you can write an accurate privacy notice because you know exactly what you’re collecting. A model trained on scraped web data, user interactions, or third-party datasets often can’t produce that same clean enumeration. What data actually went into training, how a specific inference used a specific input, and what happens to conversation logs afterward are questions that many AI-driven products still answer vaguely, not out of bad faith but because the honest technical answer is genuinely more complicated than a form field.

That’s exactly the gap Articles 12-14 enforcement is built to probe: not just “did you disclose something” but “was the disclosure accurate, specific, and actually understandable to the person reading it.” A privacy notice that says a chatbot “may process your data to improve our services” technically discloses something, and still likely fails the standard the EDPB is now checking for.

What This Means Right Now

Nothing about the 2026 CEF creates new legal obligations — Articles 12-14 have applied since GDPR took effect in 2018. What changes is the odds of getting checked, and the state of the last equivalent audit as a preview of what auditors tend to find. If the erasure investigation is any guide, the coming transparency findings are more likely to surface structural gaps — privacy notices that haven’t kept pace with what a product’s data pipeline actually does — than to uncover companies with no notice at all. For any company running AI-driven features on European users, the practical task isn’t waiting for a fine; it’s the less dramatic work of making sure the privacy notice actually describes, in plain language, what the system does with data today, not what it did when the notice was last written.

  • On May 9, 2026
  • 0 Comment
Tags: compliance, data privacy, EDPB, GDPR, regulation

Leave Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts
  • Why Load Test Numbers Lie
  • When Config Became Executable: The Twenty-Year Pattern Behind Supply Chain Attacks
  • How Software Became a Medical Device
  • Compliant With What? A Working Map of GDPR, HIPAA, SOC 2 and ISO 27001
  • Local AI vs Cloud AI: The Break-Even Is About Utilization, Not Tokens
Categories
  • ai (7)
  • android (18)
  • apple (36)
  • chart (18)
  • cloud (1)
  • fix (42)
  • games (11)
  • google (31)
  • hardware (73)
  • healthcare (3)
  • how to (231)
  • internet (92)
  • ios (23)
  • macos (3)
  • microsoft (82)
  • mobile (36)
  • news (74)
  • optimization (17)
  • osx (4)
  • outsourcing (8)
  • qa (3)
  • regulation (7)
  • review (120)
  • security (37)
  • software (159)
  • windows (150)
Archives
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • August 2025
  • March 2025
  • February 2025
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • March 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • June 2018
  • May 2018
  • April 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • January 2016
  • December 2015
  • November 2015
  • October 2015
  • September 2015
  • July 2015
  • January 2015
Archives
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • August 2025
  • March 2025
  • February 2025
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • March 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • September 2019
  • August 2019
  • April 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • October 2018
  • September 2018
  • June 2018
  • May 2018
  • April 2018
  • February 2018
  • January 2018
  • December 2017
  • November 2017
  • October 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • December 2016
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • January 2016
  • December 2015
  • November 2015
  • October 2015
  • September 2015
  • July 2015
  • January 2015

The EU Just Gave AI Companies 16 More Months — Here's What the AI Act Delay Actually Changes

Previous thumb

Microsoft Patched This SharePoint Bug in May. CISA Gave Agencies 3 Days to Fix It in July. Here's the Gap That Matters.

Next thumb
Scroll

Services

  • Software Development
  • Quality Assurance
  • Customer Support
  • Managed Services
  • 24/7 Emergency IT Support
  • Competency Center
  • Local AI Agent Development
  • Software as a Medical Device

Compliance

  • Compliance Audit
  • GDPR Compliance
  • What is GDPR
  • ISO 9001:2015 Certification

Company

  • About Us
  • All Services
  • Projects
  • Case Studies
  • Articles
  • Contact
About HiTech Service

With 10 year experience of working together, we have reached tangible synergetic effect in performance and productivity, which results in highest quality services and satisfied clients.

Privacy Policy   Cookie Policy

 

  • Facebook
  • X
  • LinkedIn
CONTACT INFO
  • 900 Foulk Rd, Suite 201, Wilmington, DE, USA, 19803
  • Kudryavs’kyi descent 5b, Kyiv, Ukraine, 04053
  • +1 646.844.5712 (US)
ISO 9001:2015 certificate issued to HiTech Service LLC by Veritas
RIPE Atlas logo, the network measurement community HiTech Service takes part in
BrainBasket Foundation logo, IT education initiative HiTech Service supports
HiTech Service LLC membership badge of the Hi-Tech Office Ukraine association Dun & Bradstreet verified business badge for HiTech Service LLC
YouTeam partner badge for HiTech Service LLC
Hitech Service LLC

Copyright 2026