← Carolina Clear Tech

Legal & Privacy Brief

2026-02-26

Listen to this brief (9:01)

Download MP3
Show Notes

Show Notes - 2026-02-26

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - February 26, 2026

Today: European DPAs issued three enforcement actions for GDPR violations, including a €2,000 fine against a Romanian dental clinic for failing to cooperate during a data breach investigation. Federal courts are establishing new precedent on the discoverability of AI-generated content, with attorney-written prompts receiving work product protection while client and employee prompts remain discoverable. Estonia's DPA ordered a media publisher to remove identifying information from news articles citing diminished public interest and excessive harm to the data subject.

Enforcement Actions

ANSPDCP (Romania) - 20.02.2026

Romania's DPA (ANSPDCP) fined SC Hayat Dent SRL €2,000 (RON 10,190) for violating Article 83(5)(e) GDPR by failing to cooperate during a data breach investigation. The case originated when the dental clinic reported that a former employee copied the contact details and medical records of all patients to solicit appointments at a competing clinic. The controller failed to respond to the DPA's information requests after an initial warning and compliance order.

AKI (Estonia) - 2.1-1/24/1246-3074-22

Estonia's DPA (AKI) ordered media publisher Delfi Media AS to remove photographs and replace full names with initials in news articles under Article 17 GDPR after finding excessive harm to the data subject and diminished public interest over time. The publisher had refused the erasure request and offered only de-indexing as an alternative. The DPA set a compliance deadline of October 27, 2025, with penalty payments of €200 per violation for noncompliance.

APD/GBA (Belgium) - 37/2026

Belgium's DPA (APD/GBA) issued a warning to an employer for deleting a video recording of a job interview after the candidate submitted an access request under Article 15 GDPR. The controller argued the recording had a short retention period for its intended purpose (reviewing the interview after the interviewer left early) and that anonymization would be disproportionate. The DPA found the controller should have retained the recording at least long enough to process the access request, violating Articles 12(2), 12(4), and 15 GDPR.

Litigation Updates

The Discoverability of Artificial Intelligence Prompts

Federal district courts in the Ninth Circuit and Southern District of New York have established diverging standards for the discoverability of AI prompts and outputs in litigation. In Tremblay v. OpenAI, Inc., 2024 WL 3748003 (N.D. Cal. Aug. 8, 2024), and Concord Music Group, Inc. v. Anthropic PBC, 2025 WL 1482734 (N.D. Cal. May 23, 2025), courts held that AI prompts written by attorneys for litigation purposes constitute opinion work product entitled to near-absolute protection. The courts reasoned that attorney-crafted prompts contain mental impressions and litigation strategy. In contrast, United States v. Heppner, No. 25 CR. 503 (JSR), 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026), Judge Rakoff ruled that AI-generated documents created by a client and transmitted to counsel are not protected by attorney-client privilege or work product doctrine because the act of communicating with the AI tool constitutes disclosure to a third party. The court emphasized that the AI tool used had an express provision that submissions were not confidential. AI prompts and outputs from non-legal corporate employees have also been deemed discoverable in Concord Music Group, Inc. v. Anthropic PBC, 2025 WL 2267950 (N.D. Cal. Aug. 8, 2025).

Compliance Takeaways