Legal prism · 2026-08-21

Legal prism — 2026-08-21

Archive
Updated: 2026-08-21 14:35
The day's news through a legal prism — grounded in our database of EU legislation.
Original — verbatim from the source Analysis — our legal insight (not a source)

Today's news through the legal prism (3)

Selected for a legal angle. For each: original → fact-check and legal basis → substantive analysis.
Filter by area of law:
Original — A News
Finland prepares to resume asylum seeker transfers to Italy Copy link
Finland is preparing to resume transferring asylum seekers to Italy, becoming the fourth country to do so after Germany, Switzerland, and Austria, following the entry into force of the EU's Asylum and Migration Management Regulation.
Analysis
Council Regulation (EU) 2019/1111, Article 27(5), concerns protective measures where a court orders the return of a child.

Core issue

Finland’s practical position is one of preparation, not an established transfer power, because the legal evidence provided contains no operative AMMR provision.

Legal assessment

Because the relevant instrument is described as an EU Regulation, it applies directly in every Member State within its subject matter.

Consequences

For asylum seekers in Finland, the immediate consequence is exposure to prepared transfer procedures to Italy, if the Finnish authorities activate them.

Sources:
Legal basis (3)
COUNCIL REGULATION (EU) 2019/1111 of 25 June 2019 on jurisdiction, the recognition and enforcement of decisions in matrimonial matters and the matters of parental responsibility, and on international child abduction Article 72 (statute)
Article 72 Appeal in certain Member States Where a decision was given in Ireland, Cyprus or the United Kingdom, any form of appeal available in the Member State of…
Article 72 Appeal in certain Member States Where a decision was given in Ireland, Cyprus or the United Kingdom, any form of appeal available in the Member State of origin shall be treated as an ordinary appeal for the purposes of this Chapter.
COUNCIL REGULATION (EU) 2019/1111 of 25 June 2019 on jurisdiction, the recognition and enforcement of decisions in matrimonial matters and the matters of parental responsibility, and on international child abduction Article 105 (statute)
of birth (if available) 5.3.5. Identity number or social security number (if applicable and available) 6. MEMBER STATE TO WHICH THE CHILD(REN) SHOULD BE RETURNED…
of birth (if available) 5.3.5. Identity number or social security number (if applicable and available) 6. MEMBER STATE TO WHICH THE CHILD(REN) SHOULD BE RETURNED ACCORDING TO THE DECISION* Belgium (BE) Bulgaria (BG) Czechia (CZ) Germany (DE) Estonia (EE) Ireland (IE) Greece (EL) Spain (ES) France (FR) Croatia (HR) Italy (IT) Cyprus (CY) Latvia (LV) Lithuania (LT) Luxembourg (LU) Hungary (HU) Malta (MT) Netherlands (NL) Austria (AT) Poland (PL) Portugal (PT) Romania (RO) Slovenia (SI) Slovakia (SK) Finland (FI) Sweden (SE) United Kingdom (UK)
COUNCIL REGULATION (EU) 2019/1111 of 25 June 2019 on jurisdiction, the recognition and enforcement of decisions in matrimonial matters and the matters of parental responsibility, and on international child abduction Article 102 (statute)
Article 102 Member States with two or more legal systems With regard to a Member State in which two or more systems of law or sets of rules concerning matters governed…
Article 102 Member States with two or more legal systems With regard to a Member State in which two or more systems of law or sets of rules concerning matters governed by this Regulation apply in different territorial units: (a) any reference to habitual residence in that Member State shall refer to habitual residence in a territorial unit; (b) any reference to nationality shall refer to the territorial unit designated by the law of that Member State; (c) any reference to the authority of a Member State shall refer to the authority of a territorial unit within that Member State which is concerned; (d) any reference to the rules of the requested Member State shall refer to the rules of the territorial unit in which jurisdiction, recognition or enforcement is invoked.
Original — EU-Startups
10 European Compliance Startups to Watch as AI Act Enforcement Begins Copy link
Europe’s regtech market is entering a new phase as AI Act enforcement powers and transparency requirements start taking effect, creating new opportunities for startups helping companies manage documentation, transparency, security…
Analysis
GDPR Article 35(3)(a) requires a data protection impact assessment for systematic and extensive automated evaluation, including profiling, where decisions produce legal or similarly significant effects.
Under Article 83(2), a natural or legal person may apply only if that person does not carry on a business involving the supply of goods or services of the kind certified.

Core issue

Companies in this market now face a documentation problem before they face a marketing problem, because enforcement has begun while later high-risk rules remain phased.

  • A startup cannot reduce that position to a single “AI Act compliant” badge where its tool also processes personal data or certifies compliance claims.
  • The precise legal question is whether AI governance, audit, healthcare, tax, security, and agent-control tools trigger enforceable duties relating to automated personal-data processing, impact assessment, transparency, and control of certification marks.
  • The rules identified in the evidence are GDPR Article 2(1), GDPR Article 35(3), GDPR Article 35(7), GDPR Article 14, GDPR Article 6(3), GDPR Article 83(8), and Articles 3, 25, 26, 31, and 83 of Regulation (EU) 2017/1001.
  • Both Regulation (EU) 2016/679 and Regulation (EU) 2017/1001 apply directly in every Member State.

Legal assessment

GDPR Article 2(1) brings personal-data processing within scope where it is wholly or partly automated, or where non-automated data form part of a filing system.

  • This is relevant to the AI tools described in the item, particularly those handling clinical trials, audit files, agent activity, regulatory workflows, tax records, or cross-border compliance data.
  • GDPR Article 35(3)(b) also requires such an assessment for large-scale processing of special-category data under Article 9(1) or criminal-conviction data under Article 10.
  • Under GDPR Article 35(7), the assessment must contain the envisaged processing operations, the purposes of processing, an assessment of necessity and proportionality, the risks to data subjects, and the measures envisaged to address those risks.
  • Those measures include safeguards, security measures, and mechanisms demonstrating compliance.
  • This aligns with the item’s emphasis on documentation, transparency, security, traceability, and human oversight.
  • GDPR Article 14 requires meaningful information about the logic involved, as well as the significance and envisaged consequences, where the rule applies to information provided to data subjects.
  • For agentic AI tools, this makes evidence-linked reasoning and traceability legally relevant where personal data are involved.
  • GDPR Article 6(3) requires Union or Member State law for processing based on a legal obligation or public-interest authority, and that law must pursue a public-interest objective and be proportionate.
  • The evidence contains no case law, so no precedent can be applied.
  • For compliance labels, Article 83(1) of Regulation (EU) 2017/1001 defines an EU certification mark as a mark distinguishing certified goods or services by material, mode of manufacture, performance, quality, accuracy, or other characteristics.
  • Article 31(1) requires an EU trade mark application to contain a request, the applicant’s identity, the goods or services, and a representation of the mark.
  • Article 26(4) allows the Office to reject a registration application if a notified deficiency is not corrected within the specified period.

Consequences

For companies deploying AI, the practical consequence is the need to map each tool against automated processing, data categories, decision effects, and documentation duties.

  • For healthcare and clinical-trial tools, the strongest GDPR trigger identified in the evidence is large-scale processing of special-category data under GDPR Article 35(3)(b).
  • For audit, tax, payments, and agent-monitoring tools, the trigger depends on whether the system processes personal data and supports decisions producing legal or similarly significant effects.
  • For vendors, claims about auditability and explainability become commercially useful only if they generate records corresponding to the content required by GDPR Article 35(7).
  • Certification-style marketing is subject to a separate constraint.
  • A company selling the certified services cannot itself be the proprietor of an EU certification mark for those same services under Article 83(2) of Regulation (EU) 2017/1001.
  • A licensee may also face trade mark consequences if it breaches licence terms concerning duration, form, scope, territory, or quality under Article 25(2).
  • The next step after 21 August 2026 is further enforcement and phased implementation as described in the item, but the evidence provides no future procedural deadline or expected decision document.
Legal basis (3)
Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR) Article 35 (statute)
the advice of the data protection officer, where designated, when carrying out a data protection impact assessment. 3. A data protection impact assessment referred to in…
the advice of the data protection officer, where designated, when carrying out a data protection impact assessment. 3. A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of: (a) a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person; (b) processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or (c) a systematic monitoring of a publicly accessible area on a large scale.
REGULATION (EU) 2017/1001 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL Article 3 (statute)
Article 3 Capacity to act For the purpose of implementing this Regulation, companies or firms and other legal bodies shall be regarded as legal persons if, under the…
Article 3 Capacity to act For the purpose of implementing this Regulation, companies or firms and other legal bodies shall be regarded as legal persons if, under the terms of the law governing them, they have the capacity in their own name to have rights and obligations of all kinds, to make contracts or accomplish other legal acts, and to sue and be sued. CHAPTER II THE LAW RELATING TO TRADE MARKS SECTION 1 Definition of an EU trade mark and obtaining an EU trade mark
Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR) Article 14 (statute)
in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
Original — Fasken
Canada’s National AI Strategy: What It Signals for AI Regulation, Privacy and Online Safety Copy link
On June 4, 2026, the Government of Canada released “AI for All,” a five-year national artificial intelligence strategy aimed at accelerating AI adoption, strengthening Canada’s domestic AI capabilities, and building public trust. Rather…
Analysis
Under Article 35(1) GDPR, a controller must carry out a data protection impact assessment before commencing high-risk processing involving new technologies.
The follow-up point is the progress of Bill C-36, Bill C-34, and any resulting regulatory guidance.

Core issue

Although Canada’s AI for All strategy does not establish a comprehensive AI statute, organizations now face a targeted compliance trajectory. This is significant because privacy reform, online safety obligations, procurement rules, standards, and sector-specific regulation are being positioned as the next legal channels. The immediate legal question is whether AI deployments give rise to obligations under existing or proposed targeted regimes, rather than under a revived AIDA. Under Article 3 GDPR, the Regulation applies to Union establishments and to non-Union controllers or processors offering goods or services to data subjects in the Union. Under Article 3 GDPR, it also applies to non-Union actors monitoring behaviour where that behaviour takes place within the Union. The GDPR is a Regulation and therefore applies directly in every Member State. For AI systems using personal data, Article 2 GDPR applies to automated processing and to processing of personal data forming part of a filing system. Council Directive 2011/16/EU on administrative cooperation in the field of taxation (DAC) is a Directive and therefore binds through national transposition.

Legal assessment

Canada’s strategy is expressly not legislation and does not itself impose compliance obligations. Its legal significance lies in the fact that Bill C-36 and Bill C-34 are presented as early targeted examples of the same policy direction. Bill C-36 would enact the Protecting Privacy and Consumer Data Act and replace Part 1 of PIPEDA with a new federal private-sector privacy law. Bill C-34 would regulate certain AI chatbot services and social media services through online safety obligations. Under Article 35(2) GDPR, the controller must seek the advice of the data protection officer where one has been designated. Under Article 35(3) GDPR, a DPIA is required for systematic and extensive automated evaluation producing legal or similarly significant effects. Under Article 35(3) GDPR, a DPIA is also required for large-scale processing of special-category data or large-scale monitoring of publicly accessible areas. The content of the DPIA is defined by Article 35(7) GDPR. It must describe the processing operations and purposes, assess necessity and proportionality, assess risks, and identify safeguards and security measures. Under Article 35(11) GDPR, the controller must review processing where a change in risk makes such review necessary. Under Article 57 GDPR, supervisory authorities may investigate, maintain DPIA lists, advise on processing, and encourage codes of conduct and certification mechanisms. Under Article 22(1) GDPR, a data subject has the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Under Article 22(2) GDPR, that protection does not apply where the decision is permitted by contractual necessity, law, or explicit consent. Under Article 22(3) GDPR, cases based on contract or consent require human intervention, the right to express one’s views, and rights to contest the decision.

Consequences

For organizations, the practical consequence is that governance work is required before any single Canadian AI statute emerges. The evidence supports preparation around transparency, human review, vendor commitments, data use, model governance, security, explainability, cross-border processing, and subcontracting. For chatbot and social media services, Bill C-34 signals possible obligations concerning harmful content, harmful chatbot behaviour, crisis intervention, user reporting, safety plans, records, and oversight. For private-sector privacy programs, Bill C-36 signals continued consent-based reform built around the PPCDA and many PIPEDA principles. Organizations with EU-facing activities must assess Article 3 GDPR before treating the matter as purely Canadian. Controllers using high-risk AI processing should prepare DPIAs under Article 35 GDPR before processing begins. Automated decision-making systems need a pathway for human intervention, user submissions, and contestation where Article 22(3) GDPR applies. Vendor reviews should address auditability, security, explainability, data use, service continuity, and emerging Canadian standards. The next legal step evidenced is not a dated revival of AIDA.

Legal basis (3)
Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR) Article 35 (statute)
the advice of the data protection officer, where designated, when carrying out a data protection impact assessment. 3. A data protection impact assessment referred to in…
the advice of the data protection officer, where designated, when carrying out a data protection impact assessment. 3. A data protection impact assessment referred to in paragraph 1 shall in particular be required in the case of: (a) a systematic and extensive evaluation of personal aspects relating to natural persons which is based on automated processing, including profiling, and on which decisions are based that produce legal effects concerning the natural person or similarly significantly affect the natural person; (b) processing on a large scale of special categories of data referred to in Article 9(1), or of personal data relating to criminal convictions and offences referred to in Article 10; or (c) a systematic monitoring of a publicly accessible area on a large scale.
Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR) Article 2 (statute)
Article 2 Material scope 1. This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated…
Article 2 Material scope 1. This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system. 2. This Regulation does not apply to the processing of personal data: (a) in the course of an activity which falls outside the scope of Union law; (b) by the Member States when carrying out activities which fall within the scope of Chapter 2 of Title V of the TEU; (c) by a natural person in the course of a purely personal or household activity; (d) by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.
Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR) Article 98 (statute)
Article 98 Review of other Union legal acts on data protection The Commission shall, if appropriate, submit legislative proposals with a view to amending other Union…
Article 98 Review of other Union legal acts on data protection The Commission shall, if appropriate, submit legislative proposals with a view to amending other Union legal acts on the protection of personal data, in order to ensure uniform and consistent protection of natural persons with regard to processing. This shall in particular concern the rules relating to the protection of natural persons with regard to processing by Union institutions, bodies, offices and agencies and on the free movement of such data.