Analysis, regulatory developments and practical perspectives across AI, cybersecurity, data, digital regulation, product compliance and European standardisation.
At the Cyberstand.eu webinar on CRA standardisation, Maria Raphael presented the scope of the Cyber Resilience Act, product classification and conformity assessment, and the work underway on the first horizontal framework deliverable for CRA standards.
The EDPB’s draft Guidelines 03/2026 address the use of web-scraped personal data for generative AI development. Their central message is operational: the fact that information is publicly accessible online does not remove GDPR requirements. Organisations need to address lawful basis, source selection, transparency, data minimisation, special-category data and technical safeguards before the training dataset is built.
How multinational organisations can standardise transfer governance across Europe and Saudi Arabia while preserving the jurisdiction-specific legal analysis each regime requires.
Article 50 transparency obligations now apply to relevant AI systems. Certain third-country GPAI providers must separately address Article 54 EU Authorised Representative requirements.
At UCLan Cyprus’s 2022 CPD webinar, Maria Raphael presented on SCCs, Transfer Impact Assessments and the emerging post-Schrems II framework. Several of the developments discussed then have since become established EU transfer law.
From the invalidated 2006 Data Retention Directive to targeted retention, IP addresses, preservation and renewed EU policy work, the CJEU has developed an increasingly differentiated framework for communications metadata.
At the 3rd Digital Banking & Payments Conference, Maria Raphael spoke on the relationship between PSD2 and GDPR in payment initiation and account-information services. The underlying data-protection questions remain relevant as the EU moves toward PSD3 and the PSR.
Maria Raphael contributed the Cyprus chapter to the IAPP’s comparative resource mapping how EU Member States implemented the national options and derogations permitted by the GDPR.
3 min read
EXPLORE
Explore by category.
Seven ways to explore OSTRAI analysis, perspectives and participation.