Get tomorrow's brief in your inbox
Today: The Electronic Frontier Foundation published a formal governance policy restricting LLM-assisted code contributions to its open-source projects, establishing a disclosure-and-comprehension standard that sets a practical benchmark for AI code review obligations in security-sensitive environments. Austria's DSB and Germany's Regional Court of Hildesheim each issued new GDPR-related decisions (cases 2024-0.199.724 and 3 O 26/24, respectively), continuing the EU's steady output of enforcement decisions and civil liability rulings under Articles 58 and 82. Amazon Ring terminated its data-sharing partnership with Flock Safety, a signal that surveillance-tech vendor associations carry growing legal and reputational risk under state biometric and privacy statutes.
DSB (Austria) - 2024-0.199.724
Austria's Data Protection Authority (Datenschutzbehörde, DSB) issued decision 2024-0.199.724 (ECLI: AT:DSB:2024:2024.0.199.724), published on the Austrian legal information system RIS and indexed on GDPRhub. The DSB holds supervisory authority under GDPR Article 51 and regularly issues decisions on consent validity, data subject rights responses, and lawfulness of processing claims. Austrian DSB enforcement has historically focused on inadequate consent mechanisms, failure to respond to data subject access requests within the Article 12 one-month deadline, and unlawful data transfers to third countries. The specific subject matter, parties, and penalty amount for this decision were not available in the collected source content at time of publication; the full decision text is accessible through RIS (ris.bka.gv.at).
LG Hildesheim - 3 O 26/24
Germany's Regional Court of Hildesheim (Landgericht Hildesheim) issued civil decision 3 O 26/24, published in the VORIS legal database. German regional courts handle private GDPR enforcement claims under Article 82, which provides data subjects a right to compensation for both material damages and non-material damages (including distress, loss of control over personal data, and reputational harm) caused by GDPR violations. German courts have been among the most active in Europe on Article 82 non-material damages, with awards ranging from 100 EUR for minor notice deficiencies to several thousand EUR for substantive violations such as unauthorized disclosure or unlawful profiling. LG Hildesheim 3 O 26/24 adds to this body of civil precedent; the specific parties, alleged violation, and damages amount were not included in the available source content at time of collection.
ÚS SR - PL. ÚS 11/2025-116 (Slovak Constitutional Court)
The Constitutional Court of the Slovak Republic (Ústavný súd Slovenskej republiky) issued decision PL. ÚS 11/2025-116, which references Slovak Act 2026-13 published on epi.sk. Constitutional court challenges in Slovakia (filed under PL. ÚS plenary jurisdiction) address whether legislation complies with fundamental rights protections in the Slovak Constitution, including the Article 19 right to privacy and personal data protection. A successful constitutional challenge can suspend or annul legislative provisions. The case was filed in 2025 and resolved in early 2026; the decision's full text is available in Slovak on epi.sk and in summary on GDPRhub. The specific nature of Act 2026-13 and whether the constitutional challenge succeeded were not extractable from the collected content.
Amazon Ring Terminates Data-Sharing Partnership with Flock Safety
Amazon Ring canceled its partnership with Flock Safety, a surveillance technology company that sells automated license plate reader (ALPR) networks to law enforcement agencies and private businesses. The termination is significant because it reflects how sustained public and advocacy pressure can fracture surveillance-tech commercial relationships even between established players. Flock Safety markets its ALPR systems to local police departments and HOAs, building bulk location databases from passive vehicle tracking. Ring's own law enforcement data-sharing history, including its Neighbors app partnership program with police departments that drew congressional and FTC scrutiny, makes the decision notable: if Ring considers Flock's practices reputationally untenable, the surveillance-tech market is recalibrating. The breakup signals that private-sector surveillance partnerships now carry tangible legal and business risk, particularly as state biometric privacy statutes (Illinois BIPA, Texas CUBI, Washington My Health MY Data Act) expand to cover location and behavioral data in some contexts.
EFF Publishes Formal Policy on LLM-Assisted Open-Source Contributions
The Electronic Frontier Foundation published a governance policy for LLM-assisted code contributions to its open-source projects. The policy stops short of a blanket ban, which EFF acknowledges is impractical given how pervasive AI coding tools have become, but establishes three requirements: (1) contributors must fully understand all code they submit, regardless of how it was generated; (2) comments and documentation must be authored by a human; and (3) contributors must disclose any LLM assistance. EFF's rationale is operational and security-focused: LLM-generated code can replicate bugs at scale, is difficult to review with small maintainer teams, and introduces risks of hallucination, omission, and misrepresentation in security-sensitive codebases. The policy also acknowledges broader concerns around AI-generated code and copyright, though EFF notes it has separately concluded that extending copyright is an impractical solution to AI content issues.
The policy is relevant to compliance programs beyond open-source participation. Organizations using AI coding assistants (GitHub Copilot, Cursor, Claude, CodeWhisperer) in regulated environments, particularly those handling protected health information, payment card data, or personal data subject to GDPR or CCPA, face analogous risks: AI-generated data handling code may contain subtle privacy or security flaws that pass code review. EFF's disclosure-and-comprehension standard provides a defensible policy framework that can be adapted for internal SDLC governance.
GDPR Article 82 civil liability is now a routine litigation risk in Germany. LG Hildesheim 3 O 26/24 continues a pattern of German regional court awards for non-material GDPR damages. Conduct a privacy notice audit against Articles 13/14 requirements and ensure all consent records are timestamped and retrievable. Even deficiencies courts characterize as minor have resulted in awards of 100-500 EUR per claimant; in class-action-style actions, exposure scales rapidly.
Track Austrian DSB decision 2024-0.199.724 on RIS for sector-specific enforcement signals. The DSB issues decisions across consent, data subject rights, and transfer compliance. Subscribe to GDPRhub's DSB category or set a Google Alert for "Datenschutzbehörde 2024-0.199.724" to catch the full published decision. If your organization operates in Austria, review your Article 12 response timelines now.
Audit surveillance vendor contracts for law enforcement data-sharing clauses before your next renewal. Ring's exit from the Flock partnership is a market signal that ALPR and smart surveillance partnerships carry escalating legal exposure. Review third-party security vendor agreements for provisions that could constitute third-party data sharing under CCPA or create BIPA disclosure obligations. Document the audit and any remediation in your vendor management program.
Adopt an AI code disclosure and comprehension policy in your SDLC before a security incident forces one. EFF's policy provides a ready-made template. Require disclosure for any AI-assisted code touching PII, authentication, or regulated data systems. Pair disclosure with a mandatory human-review checklist for AI-generated functions. SOC 2 and ISO 27001 auditors are increasingly asking about AI tool governance in development environments.
Monitor Slovak Act 2026-13 and PL. ÚS 11/2025-116 if you have EU cross-border operations. Constitutional decisions in EU member states can void or confirm mandatory data processing obligations with immediate effect. Engage local Slovak counsel to assess whether Act 2026-13 affects your data retention schedules, mandatory disclosure obligations, or legal basis documentation for Slovak data subjects.