GRC Report Staff

EU’s Simplified Sustainability Reporting Standards Become Final

More than a year after Brussels set out to make its sustainability reporting regime less burdensome, the revised European Sustainability Reporting Standards have made their way into the Official Journal. Commission Delegated Regulation (EU) 2026/1563 was published on September 21, replacing the existing ESRS annexes under Delegated Regulation (EU) 2023/2772. The regulation enters into force on November 10, 2026, and the revised standards will apply to financial years beginning on or after January 1, 2027.

Biedronka & Transport Companies Fined $150 Million Over Labor Market Collusion

For nearly seven years, transport companies serving the Polish supermarket chain agreed not to compete with one another for drivers, according to Poland’s Office of Competition and Consumer Protection, or UOKiK. Moving from one participating carrier to another could require the permission of the employer the driver was trying to leave. Without it, the driver could be kept out of the distribution center for months.

ENISA Warns Digital Dependencies Are Widening Europe’s Cyber Attack Surface

More than half of the cyber incidents recorded by the European Union’s cybersecurity agency last year were distributed denial-of-service attacks. Most were not especially damaging, but they were, however, remarkably easy to summon. A political statement, an election, a protest or another turn in the war in Ukraine could be enough. Hacktivist groups claimed 4,709 attacks against EU Member States during 2025, according to ENISA’s latest Threat Landscape report, and more than 89% involved DDoS attacks. Public administrations bore much of it.

Spanish Boards Under the Microscope in CNMV’s 2025 Governance Review

The Spanish National Securities Market Commission (CNMV) published its annual reports on corporate governance and board remuneration on September 21, drawing together disclosures submitted by listed companies for the 2025 financial year. Spain’s listed companies reported greater adherence to the country’s Good Governance Code in 2025, even as the largest companies lost some ground on a measure the code is meant to encourage: independent oversight in the boardroom.

AI Is Expanding the DPO’s Role Faster Than Organizations Are Preparing for It

A study released Tuesday by France’s data protection authority, the CNIL, alongside the French Ministry of Labour and Solidarity and the French Association of Data Protection Officers (AFCDP), found that 55% of DPOs already consider the EU AI Act part of their responsibilities. Seventy-one percent would like their role formally extended to include compliance with the regulation.

New York Sets November Registration for Major AI Developers Under RAISE Act

New York will begin directing large frontier AI developers to register with the state in November, giving companies roughly two months to prepare before the central requirements of the state's RAISE Act take effect in January.

EDPB Sets Five-Step Method for GDPR Fines & Finalizes DSA Privacy Guidelines

Europe’s data protection authorities have never lacked ways to punish a GDPR violation. They can warn an organization, reprimand it, order it to change what it is doing, restrict its processing or stop that processing altogether. And, of course, they can fine it. What has been less settled is how an authority should decide among those choices.