For senior privacy teams, useful insight is not a stream of headlines. It is a way to decide what needs ownership, evidence or review before a regulator, board member or data subject asks the same question.

This briefing brings together the developments currently shaping privacy operations: evidence-led accountability, the overlap between data protection and AI governance, stronger complaint-handling expectations, and the practical lessons emerging from regulator annual reports.

Accountability is becoming more operational

The GDPR accountability principle has always required controllers to comply and to demonstrate compliance. The practical emphasis is increasingly on whether an organisation can reconstruct a decision: who owned it, what evidence was considered, what was approved, what changed and whether the control worked in practice.

That is visible in the DPC Annual Report 2025 and our three-year review of DPC and EDPB governance trends. The lesson for DPOs is not simply to create more documentation. It is to keep the records that explain live decisions and connect those records to risk, ownership and follow-up.

Good privacy evidence should help a team see what happened, not merely prove that a template existed.

AI governance now sits inside privacy operations

The EU AI Act is in force and applies in phases. Article 50 transparency obligations have applied since 2 August 2026, while the Commission continues to develop supporting guidance for other parts of the framework. Privacy teams therefore need to distinguish between obligations already applying, provisions with later dates and draft guidance that may still change.

The practical work is familiar: map data flows, establish roles, assess necessity and fairness, document human oversight, test supplier claims and maintain evidence across the system lifecycle. Our provider and deployer guide and AI impact assessment and DPIA guide set out how those duties fit together.

Complaints are a governance signal

UK organisations must now provide a route for data protection complaints, acknowledge complaints within 30 days, investigate appropriately, keep the complainant informed and communicate the outcome. The requirements came into force on 19 June 2026.

For privacy operations teams, complaints should not sit in a disconnected inbox. They can reveal weak explanations, incomplete evidence, repeated process failures or a defensible decision that has not been communicated clearly. This is especially important for DSAR disputes and AI-assisted complaints, where polished or broad wording should be met with disciplined triage rather than assumptions about merit.

What senior teams should check

  • Can each significant privacy decision be traced to an owner, evidence set and approval?
  • Does the AI register distinguish current legal duties from draft guidance and future milestones?
  • Are complaints linked to the original request, incident, DPIA or processing activity?
  • Do board metrics explain risk and action, rather than only counting activity?
  • Are external links, regulatory statuses and training materials reviewed on a defined cycle?

The useful question is not whether the organisation has a privacy framework. It is whether the framework helps people reach sound decisions, surface gaps and produce a reliable record when challenged.

Sources and further reading