Get tomorrow's brief in your inbox
Today: Five European court and regulatory decisions involving GDPR compliance were catalogued this week across Lithuania, Germany, France, the Netherlands, and Romania, reflecting active enforcement and adjudication across multiple EU member states simultaneously. Debevoise & Plimpton flag a structural gap in standard B2B data agreements: AI tools now allow counterparties to train models on shared data and enter direct competition without triggering existing NDA or non-compete provisions. Security researcher Bruce Schneier introduces the "Promptware Kill Chain" framework, reframing LLM prompt injection as a multi-stage attack sequence with direct compliance implications for organizations deploying AI in regulated workflows.
VDAI (Lithuania) - Nr. 3R-219 (2.13-1.E)
Lithuania's State Data Protection Inspectorate (VDAI) issued decision Nr. 3R-219 (2.13-1.E) on February 6, 2026. The ruling is catalogued in GDPRhub as a GDPR enforcement decision. The original decision is published in Lithuanian on the VDAI official site. Specific penalty amounts, the identity of the respondent, and the violation type are not disclosed in the extracted content, but the VDAI handles administrative enforcement under Articles 83 and 58 of the GDPR.
OLG Bamberg (Germany) - 10 U 61/25 e
Germany's Higher Regional Court Bamberg (Oberlandesgericht Bamberg) issued a civil ruling in case 10 U 61/25 e on or around January 21, 2026. The case is catalogued in GDPRhub as a GDPR-related court decision. Civil GDPR litigation at the OLG level in Germany typically involves claims for non-material damages under Article 82 GDPR, injunctive relief, or disputes over whether a data processing action was lawful. The original German text is published on REWIS. No damages figure or ruling outcome is available from the extracted content.
CA Paris (France) - 25/04270
The Paris Court of Appeal (Cour d'appel de Paris) issued a ruling in case 25/04270. The GDPRhub entry references a Cour de Cassation source, which suggests the case involves either a cassation referral or an appeal touching data protection law at a high appellate level. French courts have been active in applying GDPR in the context of employee surveillance, algorithmic processing, and consent enforcement. The original French text is available through the Cour de Cassation's public decision portal. Specific parties, ruling, and any damages are not available from the extracted content.
RVS (Netherlands) - 202203874/1/A3
The Netherlands Council of State (Raad van State) ruled in administrative case 202203874/1/A3 (ECLI:NL:RVS:2026:746) with GDPR implications. The "avg" keyword in the Rechtspraak search metadata confirms the case involves the Algemene verordening gegevensbescherming (GDPR as enacted in Dutch law). The Council of State is the highest administrative court in the Netherlands and handles appeals against government data processing decisions. Administrative GDPR cases at this level often involve public registers, municipal data sharing, or law enforcement data access requests. The original Dutch decision is published on Rechtspraak.nl.
CC (Romania) - 04.02.2026
Romania's Constitutional Court (Curtea Constitutionala) issued a decision on February 4, 2026, catalogued in GDPRhub with data protection relevance. Romania's Constitutional Court reviews legislation for conformity with constitutional provisions, which include fundamental rights to privacy under Article 26 and 28 of the Romanian Constitution. Constitutional Court decisions that intersect with GDPR frequently address domestic laws implementing data retention, national security data access, or biometric identification requirements. The original decision is in Romanian and published on the Court's official communications portal.
AI Is Making Everyone a Potential Competitor - Are Your Data Contracts Ready?
Debevoise & Plimpton's data blog identifies a structural gap in standard B2B data agreements: NDAs and data use restrictions were designed for a competitive environment where counterparties remained in their defined business roles. AI changes this assumption. A vendor, partner, or supplier can now train models on data shared in the ordinary course of business, then deploy those models to enter markets previously exclusive to the disclosing party. Existing NDA provisions typically restrict disclosure to third parties and prohibit use "outside the purpose of the agreement," but these clauses were drafted for human employees and defined business lines, not automated training pipelines. Non-compete provisions similarly cover specific business activities, not AI-mediated competitive development. The article's central point: enforcement of data use limitations has historically been low-stakes, but the leverage an AI model can extract from a counterparty's shared data now makes these clauses material.
The Promptware Kill Chain
Bruce Schneier, writing on Schneier on Security, presents a new analytical framework called the "Promptware Kill Chain," co-authored with academic collaborators. The piece reframes LLM prompt injection attacks as a multi-stage attack sequence, analogous to the Lockheed Martin Cyber Kill Chain used in traditional threat analysis. The argument: the dominant framing of "prompt injection" as a single vulnerability obscures a more complex attack surface. The full attack chain involves multiple distinct stages, including reconnaissance of the LLM's access scope, payload embedding, execution trigger, and post-execution actions such as data exfiltration or process manipulation. Defenses targeting only input sanitization address one stage; organizations deploying LLMs in regulated contexts and assuming vendor-provided injection filters constitute full coverage are exposed to the remaining stages. The compliance implication is direct: AI systems used in HIPAA, GLBA, FERPA, or GDPR-regulated workflows that are compromised through multi-stage promptware attacks can generate breach notification obligations.
AI training clauses are now standard contract hygiene. Existing B2B NDAs and data agreements do not prohibit counterparties from training AI models on shared data. Legal and procurement teams should add explicit AI training prohibitions to all new agreements and flag existing high-value contracts for renegotiation. Apply to vendor, partner, and customer agreements where competitive risk exists.
European GDPR enforcement is broad and simultaneous. Five GDPR-related decisions across Lithuania, Germany, France, the Netherlands, and Romania surfaced in one week. Organizations with EU operations should maintain active monitoring of GDPRhub and national DPA publications, not just CJEU and EDPB output. Member state courts and DPAs are developing jurisdiction-specific interpretations that affect compliance obligations independently of EU-level guidance.
Dutch Council of State GDPR ruling warrants tracking. ECLI:NL:RVS:2026:746 is an administrative GDPR case at the highest Dutch administrative court level. Public sector and semi-public entities in the Netherlands, and private organizations with data-sharing relationships with Dutch government bodies, should review the full ruling once translated.
Romanian domestic GDPR law subject to constitutional review. The Romanian Constitutional Court's February 4 decision signals active fundamental rights scrutiny of data protection legislation. Compliance frameworks relying on Law 190/2018 or other Romanian domestic implementing measures should be checked for gaps if the Court's ruling invalidates or modifies statutory provisions.
LLM deployments require multi-stage threat modeling. The Promptware Kill Chain framework establishes that prompt injection filtering is one control, not a comprehensive defense. Any LLM in a regulated workflow (healthcare, financial services, legal, HR) needs a structured threat model covering the full attack surface. Build this requirement into AI procurement reviews and annual vendor assessments.