GDPR & AI Act News: what you shouldn't have missed in August 2026
August 2026 was anything but quiet for regulators: the AI Act’s obligations for high-risk AI systems have come into force, the CNIL has issued guidance on training AI with health data (alongside a €2.5M fine for a SaaS provider), the EDPB has released guidelines on the "pay-or-consent" model, and the CJEU has delivered a major ruling expanding the definition of compensable non-material damage under Article 82 of the GDPR. Here is an overview of the key texts and a checklist for DPOs as they return from the summer break.

While many were enjoying a well-deserved summer break, our French and European regulators did not slow down. The CNIL, the EDPB, and the CJEU have continued to push forward a particularly packed regulatory agenda on the AI and data protection front, much to the chagrin of legal departments.
AI Act: a major milestone for high-risk systems
The implementation timeline for Regulation (EU) 2024/1689 (the AI Act) is accelerating. This August 2026 marks the direct application of obligations for high-risk AI systems as defined in Annex III of the regulation.
CNIL and AI in healthcare: what Deliberation No. 2026-084 changes
At the end of August, the CNIL published deliberation no. 2026-084 of August 27, 2026, which specifically regulates the training of AI models using health data.
In response to the proliferation of medical AI projects and the growth of health data warehouses (EDS), the authority has clarified the rules for the secondary use of medical data.
Pseudonymization and re-identification
The CNIL reaffirms that simply removing names or coding patient files does not constitute irreversible anonymization, given the inference capabilities of AI models. In almost all cases, reused health data remains pseudonymized data subject to the full scope of the GDPR (Article 9).
Patient information and the right to object
The deliberation requires clear, individual notification to patients regarding the reuse of their health data for AI training, coupled with a simple opt-out procedure that does not disrupt their medical care.
EDS governance
Access to clinical databases for algorithm fine-tuning must be subject to a specific DPIA and systematically governed by contractual commitments prohibiting re-identification.
€2.5M CNIL fine: when a SaaS provider reuses client data for its AI
In deliberation SAN-2026-012 of August 20, 2026, the CNIL's restricted committee imposed a heavy fine on a SaaS management software provider. The reason: the company had reused client databases (containing health and wellness data) to train its own internal AI model without a valid legal basis or compliant notification.
EDPB: harmonized rules for the "pay or consent" model
The European Data Protection Board (EDPB) adopted its Guidelines 02/2026 on August 18, 2026, definitively regulating alternative pricing models applied to online platforms.
Freedom of consent : the paid alternative offered to refuse targeted advertising must not be prohibitively expensive. The cost of ad-free access must be justified and proportionate to ensure a truly free choice for the user.
Choice architecture : the EDPB explicitly bans dark patterns designed to complicate the user journey for those wishing to opt for the version without behavioral tracking compared to the data-payment option.
In-depth analysis: the CJEU ruling of August 14, 2026 (Case C-384/25)
The ruling delivered on August 14, 2026, by the Court of Justice of the European Union (Case C-384/25) marks a decisive step forward in case law regarding Article 82 of the GDPR (right to compensation for damages).
Deciphering the decision
The CJEU was referred a preliminary question regarding a personal data breach resulting from a cyberattack. Several affected individuals sought compensation without providing proof of actual fraudulent use of their data (such as identity theft or direct financial loss).
Loss of control constitutes compensable non-material damage in itself
The Court confirms that the term "damage" under Article 82 of the GDPR must be interpreted broadly. Feelings of anxiety, fear of future malicious use, or the simple sense of losing control over one's personal data constitute legitimate non-material harm that can give rise to compensation, without the need to establish physical or financial injury.
No de minimis threshold for severity
The CJEU reiterates that there is no minimum threshold of severity required to claim compensation. As long as the data subject demonstrates actual non-material damage, even if minor, and a direct causal link to the controller's GDPR violation, compensation cannot be denied solely on the grounds that the inconvenience suffered is "minimal."
Reversal of the burden of proof
While the data subject must prove the reality of their non-material harm (the anxiety suffered), it is up to the data controller to prove that they are in no way responsible for the event that caused the breach (Article 82, paragraph 3), by demonstrating the optimal effectiveness and state-of-the-art nature of the security measures (Article 32 GDPR) deployed prior to the incident.
Operational impact and litigation risk
This ruling significantly increases legal risk in the event of a data breach. It facilitates the success of class actions brought by consumer associations or victim groups following a cyberattack by removing the hurdle of proving individualized financial loss.
DPO checklist for the new season
To prepare for your September steering committees:
- Audit your AI & health projects: if your organization handles health data, verify the compliance of your data warehouses and privacy notices in accordance with CNIL deliberation no. 2026-084
- Review your SaaS contracts and policies: ensure your subcontractors do not claim the right to reuse your data to train their own AI algorithms
- Consolidate your data breach management plan: incorporate the risk of compensation for non-material damage into your financial impact assessments for cyberattacks and re-evaluate the adequacy of your cyber insurance policies
FAQ - August 2026 GDPR and AI Act updates
Which AI systems are subject to the "high-risk" obligations of the AI Act?
Systems covered by Annex III of Regulation (EU) 2024/1689, particularly tools used in human resources, diagnostics, or automated scoring, which are now subject to a risk management system, a FRIA for the public sector, and an audit of their training datasets
Can an AI model be trained using pseudonymized health data?
Not without complying with the GDPR: the CNIL reiterates in its deliberation no. 2026-084 that removing names and first names is not enough to anonymize a patient file, which therefore remains pseudonymized data subject to Article 9 of the GDPR
Is the "pay or consent" model authorized by the EDPB?
Yes, under certain conditions: the EDPB requires that the price of the alternative without targeted advertising not be prohibitive and that the user journey contain no dark patterns that nudge users toward paying with their data
Must financial loss be proven to receive compensation following a data breach?
No, in its ruling of August 14, 2026, the CJEU confirmed that the loss of control over one's data and the resulting anxiety are sufficient to constitute non-material damage eligible for compensation under Article 82 of the GDPR, with no minimum threshold of severity.


