A digital data protection bridge between Europe on the left and America on the right, as well as the data flows between the two continents.

EU Cybersecurity & Data Protection Update Q2-2026

In this article, we highlight the top cybersecurity and data protection challenges for the second quarter of 2026.

Trust is a peculiar kind of infrastructure. Like plumbing or wiring, you never think about it until the day it fails, and then you think about nothing else. This quarter, it failed in two places at once, and the two failures turned out to be the same story. Just told at different scales.

At the “small” scale, it was the trust that the person logging into your systems is who they claim to be. Look at this quarter’s major breaches, Instructure, Novo Nordisk, Carnival, and the striking thing is how unfathomably boring the methods were. Nobody smashed through a firewall or used a sophisticated zero-day exploit. They used a good old fashioned stolen token, an unverified account, a deceived employee. They did not break in. They simply logged in. Identity, the quiet business of knowing who is on the other end, often is the softest target.

At the large scale, it was the trust that the institutions vouching for the rules actually work. Here, the quarter delivered something close to a landmark. The legal foundation that lets data flow from Europe to the United States, the Data Privacy Framework (“DPF”), has been quietly losing its American supports for eighteen months. This quarter, the US Supreme Court removed one of the foundations it rested on. We have warned about this framework so often that readers may be tired of hearing it. Yes, as they say, if you sit by the river long enough, eventually your enemy will float by; often in a rather dead state.

In between the two sat the EU’s grand Digital Omnibus, which revealed a split personality: the AI rules were softened and postponed, while, in the same breath, one genuinely tough new prohibition was added, aimed squarely at the deepfake abuses we covered last quarter (the Grok-affair – we reported). Enforcement, meanwhile, kept winning its arguments on substance while stumbling on procedure. Even the regulators are under strain and work night shifts.

There is, we will admit, an Engity-shaped reading of all this. When trust erodes, two questions come to matter more than any other: do you actually know who is accessing your systems, and have you handed the fate of your data to institutions you do not control? We think about the first every day. We think the second deserves more attention than it usually gets.

Let’s take a closer look.

The Data Privacy Framework: This Time the Call Is Coming from Inside the House

Regular readers of this digest will be forgiven for sighing (or yawning). Yes, we are writing about the EU-US Data Privacy Framework. Again. We devoted a deep-dive to it in Q1/2025, we flagged its structural fragility in nearly every edition since, and we updated our blog on server location around it only weeks ago. At some point, harping on the same risk starts to feel like a nervous tic.

Except this quarter, the thing we have been warning about for two years stopped being a forecast and started being a sequence of events. Or dominoes, if you prefer. And the epicenter is not in Luxembourg, but in Washington itself.

A Supreme Court Ruling With European Fallout

The event in question is a decision of the United States Supreme Court, handed down on 29 June 2026, called Trump v. Slaughter. On the surface, it has nothing to do with data protection. It is a case about presidential power: specifically, whether the President can fire the commissioners who run America’s independent regulatory agencies. The Court, by a 6-3 majority, said: Yes, he can.

To a European reader, this may sound like an arcane piece of American constitutional plumbing. It is not. Because one of those independent agencies is the Federal Trade Commission, and the FTC is one of the two foundations on which the entire EU-US Data Privacy Framework rests. The Framework, for the uninitiated, is the legal arrangement that lets companies move personal data, everything from payroll records to customer emails, from the EU to the United States without breaking European privacy law. Without it, or something like it, the routine transatlantic data flows that underpin cloud computing, online advertising, and most of the modern internet become legally precarious. Remove the FTC foundation, and the structure the European Commission certified as “adequate” in 2023 starts to look shoddy.

To see why, we need to look at what the Court actually did, and then at what the DPF actually needs.

What Trump v. Slaughter Actually Did

In its 29 June ruling, the Supreme Court held 6-3 that the for-cause removal protection for Federal Trade Commission commissioners is unconstitutional. Chief Justice Roberts, writing for the majority, overruled Humphrey’s Executor v. United States, a precedent that had stood since 1935 (!) and had, for ninety years, guaranteed that the FTC and agencies like it could operate at arm’s length from the White House. In a companion decision, Trump v. Cook, the Court carved out the Federal Reserve, because apparently some independence is more equal than others. The practical effect: FTC commissioners now serve at the pleasure of the President, who may remove them at will. And we know: the current president does will a lot.

Why an American Constitutional Ruling Breaks a European Adequacy Decision

The DPF itself, as an adequacy decision under Article 45 GDPR, rests on two foundations. The first concerns government access: the safeguards in Executive Order 14086 limiting US surveillance of communications, the oversight performed by the Privacy and Civil Liberties Oversight Board (PCLOB), and the redress offered by the Data Protection Review Court. The second concerns commercial enforcement: the promise that the FTC will actually hold certified US companies to the framework’s principles.

Both foundations are now compromised, and it happened in the space of eighteen months.

Foundation one was hollowed out in January 2025, when the administration removed the three Democratic members of the PCLOB, leaving it without a quorum and, as of this writing, still unable to issue official findings. We covered this at the time. The body the European Commission specifically relied on to certify that US surveillance oversight was adequate has been sitting dark for a year and a half.

Foundation two is what Trump v. Slaughter just knocked out. An FTC that can be fired at will is not an independent enforcement authority in any sense the Commission’s 2023 adequacy assessment assumed. This is precisely the point made by Max Schrems in an open letter to the European Commission dated 30 June 2026, one day after the ruling.

The name should give Brussels pause. Schrems is the Austrian lawyer and privacy campaigner who has already brought down two transatlantic data deals before the Court of Justice: Safe Harbor in 2015 (Schrems I) and Privacy Shield in 2020 (Schrems II). When the man who has demolished the two previous frameworks starts publicly inspecting the foundations of the third, it is not to be brushed off lightly. In the letter, Schrems argues that with FTC independence gone, no other US authority can plausibly remedy the deficiency on the commercial side, and his organization NOYB is openly reviewing a broader, structural challenge, having concluded that the pending Latombe case is too narrow to do the job. A “Schrems III” is no longer a hypothetical. It is, it seems, in the making.

Speaking of Latombe: the appeal is alive. The General Court dismissed his challenge in September 2025 (T-553/23), but he appealed to the Court of Justice in October (C-703/25 P), and the case is pending. In a telling sign of who has skin in this game, on 4 June 2026 the CJEU granted Microsoft permission to intervene in support of the Commission. When Redmond shows up to defend your adequacy decision in person, you can infer how much commercial infrastructure is riding on it.

And underneath all of this, Section 702 of America’s Foreign Intelligence Surveillance Act, the bulk-surveillance power that sank Safe Harbor and Privacy Shield, is limping along on a 45-day extension granted in April while Congress argues about renewal. Or to be more clear: There is rot there, too.

What All This Means, and Why We Keep Reporting It

Let us be precise, because that precision may matter at this point. As of today, the DPF is still valid law. The Commission has not suspended it, the adequacy decision stands, and companies may still rely on it as a transfer mechanism. Anyone telling you the DPF is dead is a bit ahead of the facts.

But “still valid” is not the same as “safe to build on.” The entire value proposition of the DPF was that it let you stop thinking about where your data goes. That was always a comfortable fiction, and comfortable fictions have a shelf life. What changed this quarter is that the mechanisms the Commission relied on to call the US “adequate” have been dismantled by the US itself, on camera, one after another. If the CJEU follows the pattern it set in Schrems I and Schrems II, the third framework will meet the fate of the first two. The only real question is timing.

This is where we at Engity stop being neutral observers, and we will own our bias openly – it is on the record anyway. Digital sovereignty is not a marketing slogan we reach for when it is convenient. It is a risk-management conclusion. When your identity and access infrastructure runs on European-operated systems, the entire question of whether an American executive order survives the next administration, or whether the FTC still exists as an independent body, simply stops being your problem.

We will, no doubt, be writing about the DPF again next quarter. We would genuinely prefer not to.

Identity Is the Battlefield

Every quarter, we report on data and security breaches. And every quarter, a pattern becomes clearer. Security incidents do not look like they do in the movies. In fact, the effective ones are often boring: the attackers are not breaking in. They are logging in.

Look closely at the major incidents of this quarter and the exotic zero-day, the Hollywood-style attack on a security hole nobody has patched yet, is almost entirely absent. What you find instead is rather dull yet far more dangerous. A stolen credential. An account that should not have existed. An employee who trusted the wrong voice on the phone. In each case, the front door opened not because the lock was picked, but because someone, or something, walked up with a valid key. It is Identity, not technology, where these battles are now lost.

Three incidents from April to June make the point.

Instructure: The Account That Should Not Have Existed

In late April, Instructure, the company behind the Canvas learning platform used at more than 40 percent of US colleges and universities, detected unauthorized activity in its systems. By the time it was over, the extortion group ShinyHunters had stolen 3.65 terabytes and 275 million records across roughly 8,800 institutions – or so they say. What Instructure has confirmed is narrower but still telling: names, email addresses, student ID numbers, and private messages were exposed, and course pages at Harvard, the University of Pennsylvania, Duke, and Wisconsin were defaced with ransom notes. Some of this during final exam season – imagine the horror.

The instructive detail is how they got in. The entry point was tied to the “Free-For-Teacher” program, which let anyone sign up for a Canvas account without institutional verification. Instructure’s remediation sums up the story a bit better than any analysis could: it revoked privileged credentials, rotated API keys, and then permanently shut the Free-For-Teacher program down. Who would have guessed that an account-creation pathway with no identity verification, sitting in front of a platform used by thousands of schools, would turn out to be an exploitable weakness.

Novo Nordisk: One Token to Rule Them All

In June, the Danish pharmaceutical company Novo Nordisk, maker of Ozempic and Wegovy, drugs that also seem to work if not on identity, then at least on appearance, disclosed that attackers had reached internal IT systems and copied non-public data. The extortion group FulcrumSec claimed a haul of around 1.3 terabytes, including source code, clinical trial data, internal AI models, and, they alleged, the formula for Ozempic itself. Novo Nordisk has confirmed the intrusion and the copying of pseudonymized trial data and healthcare-professional records, but not the group’s broader inventory. Treat the shopping list as unproven.

The entry point, however, is very well documented, and it is a lesson in miniature. FulcrumSec found a high-privilege developer credential, a GitHub token that functioned as an all-access pass, sitting in plain sight in the website code that any visitor’s browser downloads. From that single over-powered token, they moved laterally using more credentials left lying in code repositories, and did so quietly for more than two months. No perimeter was breached. They simply authenticated. When a single leaked token unlocks source code, AI models, and customer data, most of the rest of a security program stops mattering.

There is a data protection aspect worth noting. Because the clinical trial data was pseudonymized, Novo Nordisk could credibly tell patients the records could not be tied back to them without separately protected information. De-identification did precisely the job it is designed to do, a real-world demonstration of why the concept sits at the center of the Digital Omnibus debate we turn to below.

Carnival: The Human Key

The simplest attack of the quarter was also among the largest. In April, an unauthorized actor used social engineering to trick a single employee of Carnival, the cruise ship company, into granting access to part of the cruise operator’s IT systems. You might think a holiday company is not a promising target for data theft, until you remember they store not just names but passport numbers. Nearly six million people were affected. ShinyHunters, once again, claimed responsibility.

What makes this one sting is that Carnival has been here before. Repeatedly. The company suffered four separate data breaches between 2019 and 2021, and in 2022 New York’s financial regulator fined it five million dollars for the resulting security failures, singling out, among other things, the absence of multi-factor authentication and inadequate staff security training. A separate settlement with 46 US attorneys general addressed a 2019 breach that Carnival had sat on for some ten months before telling anyone. Fast forward to 2026, and the way in is an undertrained employee persuaded to open the door. The fines were paid. The lesson, however, was not learned.

No malware of note, no vulnerability, no clever exploit. One person, deceived. As a CISO quoted in the coverage observed, threat actors no longer need sophisticated zero-days when they can exploit human trust, impersonation, and operational pressure to obtain legitimate access. In a large organization, one compromised employee account is a door into everything behind it, and Carnival has now been caught holding that door open for the better part of a decade. The editor of this digest will, for sure, never use Carnival’s services.

The Pattern, the Point – and Engity’s sales pitch

Notice the recurring name. ShinyHunters surfaced in this digest last quarter behind the Match Group and Panera breaches, and here they are again at Carnival and Instructure, while a newer crew, FulcrumSec, runs the same playbook against Novo Nordisk. These groups are not winning because they are technically brilliant. They are winning because identity, credentials, account provenance, privileged access, the verification of who is actually on the other end, remains the softest part of most organizations’ defenses.

That is the uncomfortable takeaway, and yes, as an identity and access management company we would say this, so weigh it accordingly. But the facts are the facts: an unverified account program, an over-powered token in plain sight, and a trusting employee did more damage this quarter than any zero-day. It is no longer about sophisticated tech. The question every organization should be asking is no longer “is our firewall strong,” but “do we actually know who is logging in, with what rights, and how do we revoke it when we are wrong.”

That is not a product issue. It is a human shaped threat.

Institutions Under Pressure

We opened this edition with one institution buckling: the American legal architecture propping up the Data Privacy Framework. That was not an isolated story. Across the quarter, the bodies and rulebooks meant to govern the digital world showed signs of strain, some from outside pressure, most self-inflicted. Here is more of the pattern.

The Digital Omnibus: Simplification, Which Is to Say, Delay

When the Commission unveiled the Digital Omnibus in November 2025, it promised to make Europe’s digital rulebook more workable. Q2 showed what that means in practice, and it is a study in two speeds.

The package split in two. The AI-related amendments, the “AI Omnibus,” were carved out and rushed through on their own, because the AI Act’s high-risk obligations were bearing down on an August 2026 deadline (that nobody felt ready to meet). The sprint was remarkable by Brussels standards: provisional agreement on 7 May, Parliament adoption on 16 June, Council sign-off on 29 June, five months from proposal to done. The core achievement, once one strips out the press-release language, is a postponement. High-risk systems under Annex III now have until December 2027, a sixteen-month reprieve; embedded high-risk systems under Annex I until August 2028. The risk-based architecture of the AI Act survives intact. It simply arrives later.

There is one very specific exception to the loosening, and it runs in the opposite direction. The Omnibus adds a new entry to Article 5 of the AI Act, the short list of practices banned outright, no compliance path, no exceptions, where things like government social scoring already sit: AI systems designed to generate non-consensual intimate imagery, the so-called “nudifier apps”, along with AI-generated child sexual abuse material. The ban covers both those who place such systems on the market and those who deploy them, and it takes effect on 2 December 2026, well ahead of the delayed high-risk rules. In a package otherwise devoted to pushing deadlines back, nudifiers just got moved into the same category as state social scoring.

Meanwhile, the other half of the package, the amendments to the GDPR, ePrivacy, and the Data Act, went nowhere fast. It never even reached the trilogue stage this quarter, the closed-door negotiation where Parliament, the Council, and the Commission hammer a final text into shape. In Council, the Cyprus presidency’s compromise text of 10 June simply deleted the most contested provisions, including the planned changes to cookie-consent rules and the proposed legitimate-interest basis for AI training, after ambassadors failed to agree. The grand GDPR reform, in other words, is being quietly pared down to whatever survives the Council’s appetite for a fight. For a regulation that was supposed to be modernized with confidence, that is a thin result.

Grok, Continued: From Scandal to Statute

Regular readers will remember Grok, the AI chatbot from Elon Musk’s xAI, whose image tool spent the turn of the year generating sexualized deepfakes on an industrial scale, roughly three million images in eleven days according to the Center for Countering Digital Hate, some 23,000 of them appearing to depict children. We covered the crisis and the flurry of investigations it triggered. This quarter, the consequences began to land, and they landed in an instructive order: the courts moved first, the regulators second, and the legislators last.

As the last quarter closed, on 26 March, the Amsterdam District Court issued what is widely regarded as Europe’s first binding injunction against an AI image generator. It ordered xAI and X’s EU-facing entity to stop generating and distributing non-consensual sexualized imagery of people in the Netherlands, on pain of 100,000 euros per day per company, capped at 10 million euros each. Tellingly, the case was not brought by a data protection authority. It was brought by two civil-society organizations, the online-abuse center Offlimits and the victim-support fund Fonds Slachtofferhulp, who went to court precisely because they had concluded that regulatory enforcement was moving too slowly for the pace of the harm. When the watchdogs are too slow, someone else has to pick up the leash.

The court was not particularly charitable about xAI’s defenses. The company argued, first, that liability rests with the users who write the prompts, and second, that it had already fixed the problem with safeguards implemented on 20 January. The judges rejected both. On the first, they held that the designer and operator of the tool, not merely its users, is the responsible party, an important marker for AI platform liability across Europe. On the second, they had an awkward fact to work with: on 9 March, the very day xAI submitted its written denial that any such content could still be produced, the claimants demonstrated that Grok would still generate a sexualized video of a real person from a single uploaded photograph, with no check on consent. It is difficult to argue your safeguards are watertight while the other side is holding the water.

The legal pressure only built from there. Baltimore became the first US city to sue xAI in late March; a British MP filed a High Court claim in London in June; class actions advanced in California. And the exposure is no longer contained to a startup, because xAI merged into SpaceX in February, meaning Grok’s mounting liabilities now sit on the balance sheet of a company preparing for what may be the largest tech IPO in history.

If you have made it this far, you will remember the nudifier ban the EU wrote straight into Article 5 of the AI Act. This was a direct consequence of the mess described above: no scandal, no injunctions, no three million images in eleven days, and there is no ban. Brussels can spend a decade deliberating over the cookie banner. But give it the right incentive, and above all the right villain, and it turns out the machinery can move in months. Grok did in one quarter what years of earnest lobbying for stronger AI safeguards could not: it made the case for the rules by breaking everything the rules were meant to prevent.

Enforcement: Excuses Stop Working (Sort of)

If there is a lesson in this quarter’s enforcement, it is that the familiar arguments companies use to explain away their data practices are wearing thin.

IQVIA: “The Data Is Anonymous” (It Wasn’t)

On 26 May, France’s CNIL fined IQVIA Operations France five million euros. IQVIA is not a household name, but it is an American company and one of the largest health-data operations in the world: its business is harvesting prescription and medical records, aggregating them, and selling the resulting insights back to the pharmaceutical industry. In France it ran two authorized “health-data warehouses,” one fed by roughly 14,000 pharmacies, the other by several thousand doctors, together holding data on tens of millions of people.

IQVIA’s central defense was that the data was anonymous, and therefore outside the GDPR altogether. It leaned on the Court of Justice’s September 2025 SRB ruling to make the point. The CNIL was unmoved: the data is pseudonymized, not anonymous, because whoever holds the keys can still re-identify individuals by reasonable means. Pseudonymized data, in other words, is still personal data, with the full weight of the GDPR attached.

This is the same principle that let Novo Nordisk credibly reassure its trial patients earlier in this edition, seen from the other side. And it matters far beyond IQVIA: the CNIL noted that the same pseudonymization architecture underpins over a hundred authorized health-data warehouses in France. There is an irony worth savoring, too. IQVIA itself had declared this very data “personal” when it applied for its CNIL authorizations back in 2017 and 2019, and only discovered its anonymous character once a fine was on the table (shocking!). The regulator declined to be impressed.

The security findings will interest anyone in our line of work: among the breaches, the CNIL flagged that one of the two warehouses had no multi-factor authentication protecting access to the health records of millions, and neither had any routine monitoring of access logs to spot abnormal activity. Sensitive data, guarded by a password and hope.

The second case is smaller, but rhymes with the first one. On 20 May, the Conseil d’Etat, France’s highest administrative court, ruled on the data broker Tagadamedia, which ran online contests to harvest personal data and sell it to advertising partners. The consent forms were built as “dark patterns”, nudging users toward “I accept” while burying the alternative. The court upheld the substance without hesitation: this is not valid consent, and it never was. It did, however, trim the fine from 75,000 to 50,000 euros, on the grounds that the CNIL had switched the precise legal basis for the penalty mid-procedure without giving the company a chance to respond.

The Pattern: Winning on Substance, Stumbling on Process

That procedural trim is itself part of a 2026 pattern worth watching. This year has seen several marquee fines survive on substance but get clipped, remanded, or annulled on procedure, from Tagadamedia’s haircut to far larger reversals elsewhere in Europe.

The regulators are winning the argument about what the law requires. They are increasingly being made to show their work on how they got to the number. Even enforcement, it seems, is an institution under pressure.

We shall report.