Entries submitted
| Entry | Agency / Authority |
|---|---|
| Spain – Data Protection Commissioner | |
| Luxembourg – National Data Protection Commission / Commission Nationale Pour La Protection Des Données (CNPD) | |
| Nigeria – Nigeria Data Protection Commission | |
| Australia – Office of the Australian Information Commissioner | |
| Republic of Korea – Personal Information Protection Commission | |
| United Kingdom – Information Commissioner’s Office (ICO) | |
| Dubai – International Financial Center |
ARTIFICIAL INTELLIGENCE AND DATA PROTECTION: AGENTIC AI, DATA QUALITY AND GUIDANCE FOR USERS
Brief Description
This initiative provides guidance on four key data protection challenges arising from current AI-enabled data processing: (1) the use of AI agents and agentic AI systems; (2) data quality requirements and their relationship with the principles of accuracy, data minimization, and suitability; (3) the data protection implications of using third-party images in AI systems; and (4) guidance on critical issues related to the use of AI by end users. A sound understanding of these technologies is essential for making informed, evidence based decisions on their deployment in personal data processing, avoiding both the uncritical adoption of AI systems and their outright rejection. To support this objective, the initiative explains their foundations, capabilities and limitations, the vulnerabilities and threats associated with their use, and the measures and safeguards that can be implemented to ensure compliance with data protection and privacy requirements.
Data Accountability from A to Zen (DAAZ)
Brief Description
DAAZ (“Data Accountability from A to Zen”) is a free GDPR compliance tool designed for start-ups and SMEs in Luxembourg. It helps organisations understand, implement and maintain GDPR requirements through practical guidance, interactive learning, gamification and ready-to-use templates. DAAZ supports businesses in strengthening data protection practices, improving transparency and building customer trust. Developed by the Luxembourg National Data Protection Commission (CNPD) in partnership with the Luxembourg House of Cybersecurity (LHC), DAAZ was co funded by the European Union under the ALTO project.
Data Protection Compliance Model/National Data Protection Certification Program
Brief Description
To strengthen data protection compliance in Nigeria, the NDPC adopted a Public-Private Partnership (PPP) model, licensing qualified Data Protection Compliance Organisations (DPCOs) to support compliance activities. By December 2025, the model had created over 41,000 jobs, licensed 306 DPCOs, processed 3,327 compliance audits, and supported over 38,000 DCPMI registrations. To address the resulting skills gap, the NDPC launched the National Certification Programme for Data Protection Officers (DPOs) in January 2025. The programme combines rigorous training, examination, certification, internships with licensed DPCOs, and continuous professional development. This expanded Nigeria’s pool of verified DPOs from 1,928 in 2022 to over 7,000 by 2025, creating a sustainable professional ecosystem and strengthening national data protection capacity.
Commissioner initiated investigation into Bunnings Group Limited (Privacy)
Brief Description
To strengthen data protection compliance in Nigeria, the NDPC adopted a Public-Private Partnership (PPP) model, licensing qualified Data Protection Compliance Organisations (DPCOs) to support compliance activities. By December 2025, the model had created over 41,000 jobs, licensed 306 DPCOs, processed 3,327 compliance audits, and supported over 38,000 DCPMI registrations. To address the resulting skills gap, the NDPC launched the National Certification Programme for Data Protection Officers (DPOs) in January 2025. The programme combines rigorous training, examination, certification, internships with licensed DPCOs, and continuous professional development. This expanded Nigeria’s pool of verified DPOs from 1,928 in 2022 to over 7,000 by 2025, creating a sustainable professional ecosystem and strengthening national data protection capacity.
Transition to a Prevention-Oriented Personal Data Governance Framework
Brief Description
This initiative establishes Korea’s prevention-oriented personal data governance framework by introducing two complementary measures: punitive administrative penalties of up to 10% of total revenue for serious and repeated privacy violations, and mandatory penalty mitigation for organizations that voluntarily invest in data protection. It responds to the recognition that conventional enforcement after an incident is no longer sufficient to deter the rapidly growing number and scale of major personal data breaches. The initiative holds organizations strictly accountable while rewarding those that take meaningful preventive action (including investment beyond statutory requirements) or respond promptly to an incident to mitigate harm and facilitate recovery.
The initiative is designed to overturn the misguided perception that it is cheaper to bear the consequences of a breach than to invest in protecting personal data, thereby fostering a more proactive culture of data protection.
International transfers guidance – making it quicker and easier for organisations to transfer data internationally
Brief Description
The ICO produced new and updated guidance on international transfers, publishing in January 2026. An interactive tool supporting organisations with determining whether they’re making a restricted transfer was launched on the ICO website a few weeks later.
The guidance was developed following a comprehensive internal review, supported by the ICO’s front-end users on the Helpline, and a public call for views. Post publication, we held a webinar on the content which had over 850 attendees, and has been viewed many more times subsequently. It was also followed up with a series of content posts on LinkedIn.
The guidance is broken down into thematic units, and has support products covering a brief introduction and FAQs, to specific detailed guides and a glossary. In particular we developed a ‘three step test’ that sets out when the transfer rules under Chapter 5 apply.
We have also committed to further work on examples, our TRA approach, and the IDTA.
Autonomous Systems Officer Survey, Report and Regulations Amendments
Brief Description
Between March and May 2025, businesses across DIFC were surveyed on AI governance: what the Autonomous Systems Officer role should look like, what it demands, and what it costs. The results showed that:
- The ASO is not just a DPO rebrand. It sits at the intersection of AI/ML literacy, legal and regulatory knowledge, ethics, cybersecurity, and risk management. This is a senior, cross-functional role.
- Governance over pure tech. Respondents prioritised bias monitoring, compliance, impact assessments, and responsible deployment oversight.
- Board-level reporting is the expectation. The ASO should report directly to the CEO and Board, with independence and structured accountability baked in.
- Costs. The report notes that suitable pay would fall in the $100,000 to $200,000 range.
In August 2025, the ASO Report was posted and work began to create and enact amended regulations based on its findings.







