Get tomorrow's brief in your inbox
Today: European DPAs issued three enforcement actions for GDPR violations, including a €2,000 fine against a Romanian dental clinic for failing to cooperate during a data breach investigation. Federal courts are establishing new precedent on the discoverability of AI-generated content, with attorney-written prompts receiving work product protection while client and employee prompts remain discoverable. Estonia's DPA ordered a media publisher to remove identifying information from news articles citing diminished public interest and excessive harm to the data subject.
ANSPDCP (Romania) - 20.02.2026
Romania's DPA (ANSPDCP) fined SC Hayat Dent SRL €2,000 (RON 10,190) for violating Article 83(5)(e) GDPR by failing to cooperate during a data breach investigation. The case originated when the dental clinic reported that a former employee copied the contact details and medical records of all patients to solicit appointments at a competing clinic. The controller failed to respond to the DPA's information requests after an initial warning and compliance order.
AKI (Estonia) - 2.1-1/24/1246-3074-22
Estonia's DPA (AKI) ordered media publisher Delfi Media AS to remove photographs and replace full names with initials in news articles under Article 17 GDPR after finding excessive harm to the data subject and diminished public interest over time. The publisher had refused the erasure request and offered only de-indexing as an alternative. The DPA set a compliance deadline of October 27, 2025, with penalty payments of €200 per violation for noncompliance.
APD/GBA (Belgium) - 37/2026
Belgium's DPA (APD/GBA) issued a warning to an employer for deleting a video recording of a job interview after the candidate submitted an access request under Article 15 GDPR. The controller argued the recording had a short retention period for its intended purpose (reviewing the interview after the interviewer left early) and that anonymization would be disproportionate. The DPA found the controller should have retained the recording at least long enough to process the access request, violating Articles 12(2), 12(4), and 15 GDPR.
The Discoverability of Artificial Intelligence Prompts
Federal district courts in the Ninth Circuit and Southern District of New York have established diverging standards for the discoverability of AI prompts and outputs in litigation. In Tremblay v. OpenAI, Inc., 2024 WL 3748003 (N.D. Cal. Aug. 8, 2024), and Concord Music Group, Inc. v. Anthropic PBC, 2025 WL 1482734 (N.D. Cal. May 23, 2025), courts held that AI prompts written by attorneys for litigation purposes constitute opinion work product entitled to near-absolute protection. The courts reasoned that attorney-crafted prompts contain mental impressions and litigation strategy. In contrast, United States v. Heppner, No. 25 CR. 503 (JSR), 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026), Judge Rakoff ruled that AI-generated documents created by a client and transmitted to counsel are not protected by attorney-client privilege or work product doctrine because the act of communicating with the AI tool constitutes disclosure to a third party. The court emphasized that the AI tool used had an express provision that submissions were not confidential. AI prompts and outputs from non-legal corporate employees have also been deemed discoverable in Concord Music Group, Inc. v. Anthropic PBC, 2025 WL 2267950 (N.D. Cal. Aug. 8, 2025).
Implement legal hold procedures that automatically suspend data retention schedules when GDPR access, erasure, or rectification requests are received. The Belgian DPA warning confirms that deleting data after an access request violates Articles 12 and 15 even if the retention period would otherwise justify deletion.
Establish incident response protocols that prioritize timely cooperation with supervisory authority investigations. Romania's €2,000 fine demonstrates that failure to respond to DPA information requests is itself a GDPR violation under Article 83(5)(e) regardless of the underlying breach circumstances.
Audit AI tool usage policies to identify which platforms maintain confidentiality of user inputs. Following United States v. Heppner, assume that AI-generated content created by clients or non-legal employees using consumer AI tools is discoverable and not protected by attorney-client privilege or work product doctrine.
Review archived media content and marketing materials containing personal data for continued public interest justification. Estonia's erasure order against Delfi Media demonstrates that the passage of time and diminished public interest can require removal of identifying information even from previously legitimate publications.
Route all litigation-related AI tool usage through corporate counsel to preserve work product protection. The Tremblay and Concord Music Group decisions establish that attorney-written prompts receive opinion work product protection, while employee-generated AI content remains discoverable.