This Week in ICT & Cybersecurity — Brussels (#31, 2026)
Commission approves Poland's €7.9bn NextGenerationEU payment; ECB Decision clarifies joint data responsibilities; key milestones for digital infrastructure.
August 09, 2026 to August 15, 2026
Commission approves Poland's €7.9bn NextGenerationEU payment; ECB Decision clarifies joint data responsibilities; key milestones for digital infrastructure.
📋 In This Week's Newsletter
• 🇪🇺 European Commission
• ⚖️ EU Legislation
• 📚 What We're Reading This Week
European Commission
Commission Approves Poland's Fifth Payment Request for €7.9 Billion Under NextGenerationEU
On 9 August 2026, the European Commission gave a positive assessment of Poland's fifth payment request for €7.9 billion in the framework of the Recovery and Resilience Facility, part of NextGenerationEU. The disbursement aligns with the fulfilment of 16 milestones and 13 targets, supporting digital technologies in education, integration of satellite data, grid digitalisation, low-emission urban transport zones, and new trams for cities including Wrocław, Poznań, and Kraków. Measures also include the deployment of a data hub for the electricity market, improved network connection rules, and support for power quality monitoring and IT systems. The Commission's assessment now moves to the Economic and Financial Committee, which has four weeks to give its opinion before the Commission can authorise payment. Poland submitted this payment request on 19 June 2026. The total disbursed to Poland under the Facility is set to reach €42.05 billion, corresponding to 76.85% of the total plan.

EU Legislation (Official Journal)
ECB Decision on Joint Control of Personal Data in Prudential Supervision of Credit Institutions (Decision (EU) 2026/1942)
Decision (EU) 2026/1942 of the European Central Bank, dated 30 July 2026 and published in OJ L, clarifies the allocation of responsibilities between the ECB and national competent authorities (NCAs) regarding personal data processing in prudential supervision, pursuant to Regulation (EU) 2018/1725 and Regulation (EU) 2016/679 (GDPR). The legal act formalises joint controller arrangements within the Single Supervisory Mechanism for fit and proper assessments, authorisations, ongoing supervision, and related tasks. The Decision also describes division of responsibility for data subject requests, data breach management, and compensation for infringements. The measure takes effect on notification to the participating NCAs. (CELEX: 32026D1942)

What We're Reading This Week
- Germany battling ‘daily’ hybrid warfare attacks, minister warns: Germany faces relentless hybrid warfare efforts targeting its infrastructure and institutions, prompting heightened national security responses.
- French taxpayers' data stolen in hack of Finance Ministry: A cyberattack on France's Finance Ministry has compromised personal data of taxpayers, raising concerns over governmental cybersecurity.