Information Technology 2026

EU Trends and Developments Contributed by: Ekaterina Bronsky, Yuriy Brisov, Alexandra Zviagintseva and Yasmin Komshilova, Digital & Analogue Partners

and interoperable digital ecosystems, and the Strate - gic Roadmap for Digitalisation and AI in Energy, which supports the deployment of European digital and AI solutions in the energy sector. Taken together, these developments show that AI localisation is no longer limited to discussions of data governance or model development but is increasingly shaping industrial, infrastructure and innovation policy across the EU. Data localisation Data localisation has a specific framework in EU law, particularly through the GDPR rules on international transfers, and AI companies are not treated differently in that respect. However, the processing of European personal data by foreign AI providers is drawing closer regulatory scrutiny. And DeepSeek has become the clearest test case. On 28 January 2025, Italy’s data protection authority (Garante) sent DeepSeek a formal request for informa - tion, asking the company to clarify what personal data they collected, its sources and purposes, the applica - ble legal bases, whether data was stored in China and what data had been used to train the model. Deep - Seek responded within the deadline but argued that it did not operate in Italy and was therefore outside the scope of the GDPR. The Garante rejected that position: it found that DeepSeek unquestionably offered its services to Ital - ian users, triggering GDPR applicability, including the obligation under Article 27 to appoint an EU repre - sentative. It also found that DeepSeek’s own privacy policy confirmed data was stored in China, in breach of the security-of-processing safeguards under Arti - cle 32. On 30 January 2025, the Garante imposed a definitive limitation on the processing of Italian users’ data, citing both DeepSeek’s lack of co-operation and the unresolved risk to users’ personal data. The Italian intervention was not an isolated case. Ireland and Belgium opened their own information requests around the same time. In June 2025, Berlin Commissioner for Data Protection and Freedom of Information later asked Apple and Google to remove the app from German app stores over concerns about

data transfers to China, while the Netherlands banned its use on government devices. Taken together, these actions suggest that cross- border data transfers by AI providers are increasingly assessed not only as a matter of privacy compliance but also through the broader lens of security and tech - nological sovereignty. For businesses, the practical takeaway of this trend is that infrastructure choices are becoming legal and commercial decisions, not just technical ones. Which cloud provider, which AI model, and where data is pro - cessed may increasingly determine market access, procurement eligibility, and regulatory exposure across the EU. Trend 2: the end of privacy in the digital environment A growing global trend is the gradual disappearance of privacy in the digital environment. Data collection has reached a scale where preserving privacy in prac - tice is increasingly difficult: individuals are monitored not only by governments and corporations but also by algorithms, connected devices and online communi - ties. Personal data is no longer used solely to person - alise services; it increasingly drives pricing strategies, behavioural targeting, recommender systems, political messaging and AI training. This matters for businesses because regulators are paying closer attention to how data is collected, com - bined, analysed and used, creating new legal and commercial risk for data-driven business models. The EU’s emerging response does not prohibit personali - sation outright. It aims to strengthen transparency and user control so that individuals understand when their data is used, and businesses cannot rely on opacity or information asymmetries. Reshaping the rules of personalised pricing Personalised pricing is not a new regulatory concern. The EU already has several legal instruments capable of addressing data-driven pricing practices. Under the GDPR, the use of personal data for pricing purposes must rely on a lawful basis and comply with restric - tions on profiling, automated decision-making, and the processing of special category data. Consumer

45 CHAMBERS.COM

Powered by