<img height="1" width="1" style="display:none;" alt="" src="https://px.ads.linkedin.com/collect/?pid=8691193&amp;fmt=gif">
  • Blog
  • Q3 2026 Privacy Bulletin: AI, Biometrics, and New Regulatory Requirements

Q3 2026 Privacy Bulletin: AI, Biometrics, and New Regulatory Requirements

ALIANDO

Issue #3 September 2026


In this third issue of the privacy newsletter, we review the main regulatory milestones, recent reports, rulings, and relevant cases related to data protection and cybersecurity.

1. The annulment of the AEPD’s Guidance on Biometrics Does Not Mean a Free-for-All for the Use of Biometric Systems.

In June 2026, the National Court annulled the AEPD’s 2023 Guidelines on Attendance Monitoring Using Biometric Systems. This marks the first time a court has overturned an AEPD guideline. It was annulled for the following reasons:

  • Although it was presented as “guidance,” in practice it imposed mandatory requirements.
  • The court characterized it as a “disguised circular”: it should have been approved through the legally required procedure (and safeguards).
  • This is a procedural ruling, not a substantive one: the court did not question whether the content was correct.
  • The guidelines can no longer be used as a basis for imposing sanctions.

The ruling does not address the legality of biometric processing. It would be a mistake to think that this “frees up” the use of biometrics because the following still applies:

  • Biometric data is a special category that requires a specific legal basis.
  • Employee consent remains a weak basis (due to the imbalance between employer and employee).
  • The strict test of necessity and proportionality remains in place: if less invasive alternatives exist, it will be difficult to justify the use of biometrics.

Companies must continue to justify the necessity, proportionality, and legal basis of biometric systems before implementing them.

2. AI: Practical Issues Regarding Transparency Obligations.

Most of the transparency obligations set forth in Article 50 of the Artificial Intelligence Regulation (AIR) have been in effect since August 2, 2026. Among these is the obligation to inform users when they interact with a chatbot and to enable the identification of content generated or manipulated by AI.

What will be important starting August 2, 2026?

  • Notifying users when they are interacting with certain artificial intelligence systems.
  • Ensuring that content generated or modified by AI is clearly identified.
  • Warning users about the use of emotion recognition or biometric categorization systems.
  • Clearly label content that constitutes deepfakes.
  • Indicate the use of AI in certain texts of public interest when there is no effective human review or editorial responsibility.
  • Be prepared for oversight actions and potential penalties, which can reach up to 15 million euros or 3% of annual global revenue.

3. 825 million euro fine against Uber.

The Dutch Data Protection Authority has fined Uber 825 million euros for making automated individual decisions regarding drivers on its platform without prior human oversight.

The systems used could automatically deactivate drivers’ accounts. Uber justified this practice on the grounds of suspected fraud or based on drivers’ excessively low ratings.

The data protection authority’s ruling finds a violation of the GDPR in that the automated decisions have significant effects on drivers (inability to access the Uber platform, with the resulting loss of income).

Additionally, Uber failed to properly inform drivers of this situation.

Automated decision-making with significant effects requires enhanced safeguards: the Uber case demonstrates that a lack of human oversight and adequate information can result in fines running into the millions.

4. AI in business: knowing how to use it is more important than choosing the model.

The issue is not just which AI model to choose, but how to use it safely and responsibly.

To this end, it is essential to have a clear internal AI policy tailored to the company, establishing rules, responsibilities, and limits.

What should it include?

  • Authorized and prohibited tools.
  • Data that cannot be entered into AI systems.
  • Permitted and prohibited uses.
  • Mandatory human review before major decisions are made.
  • Minimum training for employees.
  • Retention of evidence regarding certain uses.
  • Periodic audits.

Conclusion: A well-designed internal policy allows organizations to harness the potential of AI while reducing risks and promoting safe, responsible, and compliant use.

5. Security Breaches at Service Providers and Corporate Liability.

Security incidents affecting personal data processed by data processors can have significant consequences for the responsible company, including financial penalties.

Key steps to reduce risks:

  • Enter into a written and signed data processor agreement in accordance with Article 28 of the GDPR.
  • Establish a specific procedure in the contract for managing and reporting security incidents.
  • Assess the security measures implemented by the service provider.
  • Entering into the agreement after a breach has occurred does not remedy the breach that has already taken place.
  • EDPS Guidelines 07/2020 require that the legal agreement be in writing and signed.
  • The AEPD has imposed fines of up to €100,000 in this area.

A proper data processor contract is not merely a formality. It can be key to preventing risks, properly managing a breach, and reducing exposure to fines.

Privacy, data protection, and cybersecurity are no longer just legal issues—they are real business risks.

We’re committed to helping you understand these changes in a clear and practical way.

Would you like to receive this newsletter every quarter? Subscribehere at .

Do you need help with privacy or cybersecurity in your organization? Talk to our team.

A clear, useful, and actionable summary for IT, legal, compliance, and security leaders.
We publish a new issue every quarter.

Related Post of the Article