Newsletter 06-07/2026


News and updates

REGULATION

AI Omnibus approved: what the June 16 Parliament vote means for you

The EU Parliament voted to delay most high-risk AI obligations to December 2027. The change is not yet final: the Council needs to formally adopt the text before August 2. Until then, the original AI Act deadlines remain in force. One deadline that stays unchanged regardless: December 2, 2026 for generative AI watermarking.

Email rules clarified: new CNIL guidance on opt-in, soft opt-in, and legitimate interest

France’s data protection authority published updated guidance on commercial email and SMS, clarifying the rules around opt-in, soft opt-in for existing customers, and legitimate interest. A key requirement: you must be able to provide documented proof of consent for every contact you email, including the date, method, and wording shown at the point of collection. Most EU regulators take the same approach under the ePrivacy Directive, so this applies beyond France. Your consentmanager consent log records all of this automatically. Use it to verify and export proof of consent for any contact in your dashboard.

A compliance deadline from 19 June you may have missed

A new rule came into force on 19 June. UK controllers must now have a formal internal process for handling data protection complaints under the Data (Use and Access) Act 2025, with written acknowledgement within 30 days and records kept. If you haven’t yet, now’s a good time to put a complaints-handling process in place. consentmanager’s audit-ready consent logs can help you keep the documentation side covered.

EVENTS

DMEXCO, Cologne: come find us in September

We’ll be at DMEXCO in Cologne this September, at Hall 8.1, stand F027. If you’d like to meet with our team to discuss your consent setup, upcoming regulatory changes, or enterprise requirements, get in touch now to secure a slot before the calendar fills.

What’s new this month

Here’s a quick summary of recent improvements.

IMPROVED

  • JavaScript module cache TTL reduced from 30 days to 1 day, ensuring CMP updates reach end users significantly faster.
  • Crawl limits are now enforced, preventing runaway crawl jobs and improving overall crawler stability.

FIXED

  • iOS SDK v3 now correctly shows the Privacy Manager after ATT is declined; restricted consent is no longer auto-set and forceOpen works as expected.
  • Dashboard loading performance restored and login redirect loop resolved.
  • Feedback endpoint now returns the correct response body for accepted consent events.
  • App Tracking Transparency (ATT) behaviour on iOS corrected; prompt and consent flow now work as expected.
  • Crawl results now display correctly when the staging environment is enabled on a domain.

These updates are already available and do not require any changes to your current setup.

Go to your dashboard →