Datenschutz- und DSGVO-Nachrichten

Kuratierte Updates: Entscheidungen der italienischen Behörde, EDSA-Entscheidungen, Bußgelder und regulatorische Neuerungen.

Bußgeld
26Beschwerden, und kein Bußgeld

Man nennt den Vertrag und weist dann die Widersprüche ab: Norwegen zeigt, wie die beiden Fehler zusammen reisen

SATS verlangte von Mitgliedern ein Foto, das im Mitgliederverwaltungssystem bleibt und am Empfang zur Identitätsprüfung beim Eintritt genutzt wird. Datatilsynet stellte fest, dass die Information eine falsche Rechtsgrundlage nannte, das Widerspruchsrecht nicht erläuterte und dass Widersprüche ohne Nachweis zwingender berechtigter Gründe zurückgewiesen wurden. Frist zur Behebung: 11. September 2026.

26. Aug. 2026Neu 6 min
Regulierung
26der Artikel, den vor dem Senden niemand unterschreibt

Wer haftet für den Livestream des U14-Spiels? Schweden beantwortet die Frage, die niemand stellt

Am 25. August hat die schwedische Aufsichtsbehörde einen Leitfaden zum Streaming von Jugendsport veröffentlicht. Viele Vereine übertragen Kinderspiele online, und der Leitfaden nennt die Faktoren, die über die Zulässigkeit entscheiden. Lesenswert ist aber der andere Teil: die Verantwortlichkeit, wenn die Kommune die Anlage besitzt und der Verein dort Kameras installieren will.

25. Aug. 2026Neu 5 min
Regulierung
24Monate, nach denen ein Vorfall nicht mehr verwendet wird

Den Score, mit dem der Kredit abgelehnt wird, darf man erfragen — und er muss erklärt werden

Am 19. August hat die CNIL ihre Empfehlung vom Mai 2026 zur Bonitätsprüfung für die Öffentlichkeit übersetzt. Darin stehen drei Zahlen und ein Grundsatz, die jeden betreffen, der Scoring betreibt: vierundzwanzig Monate für zurückliegende Vorfälle, sechs Monate für die Daten eines abgelehnten Antrags und ein Auskunftsrecht zum Score, das sich nicht mit dem Hinweis auf das Geschäftsgeheimnis erledigen lässt.

19. Aug. 2026Neu 6 min
Tech & KI
0gestohlene Passwörter — und genau das ist das Problem

Steuerdaten gestohlen, und kein einziges Passwort: genau das macht den Fall gefährlich

Am 14. August teilte das französische Finanzministerium mit, dass das Informationssystem der Steuerverwaltung von einer Datenschutzverletzung betroffen war: Ein Dritter konnte Daten von Privatpersonen und Unternehmen einsehen und ausleiten. Kennungen und Passwörter sind offenbar nicht betroffen — und gerade deshalb liegt das Risiko nicht in der Kontoübernahme, sondern im Phishing auf Basis echter Steuerdaten.

18. Aug. 2026Neu 5 min
Regulierung
2EDSA-Kriterien und die DSFA wird Pflicht

An Schulen sind Werbe-Tracker verboten, und das ist keine Frage der Einwilligung

Am 24. August hat die CNIL die Regeln für die in Schulen genutzten digitalen Arbeitsumgebungen veröffentlicht. Ausschlaggebend ist nicht der Schutz Minderjähriger, sondern ein verwaltungsrechtlicher Grundsatz: die Neutralität des öffentlichen Bildungsdienstes umfasst die kommerzielle Neutralität, weshalb Tracker zu Werbe- oder Profilbildungszwecken grundsätzlich verboten sind. Hat das Werkzeug sie, muss der Verantwortliche sie abschalten.

24. Aug. 2026Neu 6 min
Regulierung
2Dokumente zum selben Thema, mit einer abweichenden Regel

Gleiches Werkzeug, gleicher Tag, andere Regel: warum Tracker an der Hochschule nicht verboten sind

Am 24. August hat die CNIL zwei Texte zum selben Thema veröffentlicht, einen für die Schule und einen für die Hochschule. Wer nur den ersten liest und ihn auf den zweiten anwendet, irrt an einer bestimmten Stelle: in der Schule sind Werbe-Tracker «grundsätzlich verboten», im Hochschulbereich «empfiehlt» die CNIL, Werkzeuge ohne sie zu bevorzugen. Der Rest — Rechtsgrundlage, DSFA, Garantien des Auftragsverarbeiters, Übermittlungen — stimmt überein.

24. Aug. 2026Neu 5 min
Bußgeld
825 mln €das zweithöchste Bußgeld aller Zeiten

Achthundertfünfundzwanzig Millionen für einen Algorithmus, der Konten sperrte, ohne dass jemand hinsah

Es ist das zweithöchste jemals nach der DSGVO verhängte Bußgeld, nur hinter den 1,2 Milliarden gegen Meta. Es geht weder um eine Datenübermittlung noch um eine Sicherheitsverletzung, sondern um Art. 22 — die Vorschrift über automatisierte Entscheidungen, die fast niemand dokumentiert, weil sie nach einem Problem großer Plattformen aussieht. Sie betrifft in Wahrheit jeden, der Software über etwas entscheiden lässt, das im Leben eines Menschen Gewicht hat.

24. Aug. 2026Neu 5 min
Bußgeld
64 mln złgegenüber 14 im Jahr davor

Polen hat seine Bußgelder in einem Jahr vervierfacht, und die drei höchsten aller Zeiten stammen alle aus 2025

Polen galt jahrelang als Markt mit geringem Sanktionsrisiko. Diese Annahme trägt nicht mehr: In zwölf Monaten stieg die Summe von vierzehn auf über vierundsechzig Millionen Zloty, und die drei höchsten Bußgelder der Landesgeschichte tragen dasselbe Jahr. Wer einen Mandanten mit Niederlassung, Lieferanten oder Servicezentrum in Polen betreut, muss das Risiko neu rechnen.

24. Aug. 2026Neu 4 min
Regulierung
77Dokumentationsbereiche

Siebenundsiebzig Fächer: was ein Datenschutzbeauftragter wirklich ablegt, und warum einunddreißig nicht reichten

Wir haben den Nutzerinnen und Nutzern eine einfache Frage gestellt: Wenn eine Anfrage der Behörde kommt, welche Unterlagen ziehen Sie heraus? Die Antwort enthielt sechsundvierzig Kategorien ohne eigenes Fach, die alle in „Sonstige Unterlagen" landeten. Wir haben sie ergänzt. Dann mussten wir die Seite neu bauen, denn siebenundsiebzig graue Kacheln im Raster sind schlechter als einunddreißig.

24. Aug. 2026Neu 6 min
Plattform
29Ziele, die ein einziges Wort erreichbar macht

Das Risiko wird im Verzeichnis bewertet, und jede Funktion ist ein Wort entfernt

Eine DSB hat die Plattform einige Tage genutzt und geschrieben, es fehlten das Verzeichnis der Datenpannen, die Risikobewertung, der Dokumentenupload und die Preise. Drei der vier gab es bereits. Sie hat sie nicht gefunden, weil sie in der Mandantenakte liegen und im Menü nicht erscheinen. Daher zwei Ergänzungen: die Risikobewertung, die im Verzeichnis tatsächlich fehlte, und eine Suchleiste, die auf «Datenpanne», «72 Stunden» oder «Art. 33» antwortet und dabei auch sagt, wo das Gesuchte liegt.

23. Aug. 2026Neu 5 min
Plattform
35Maßnahmen nach Art. 32 im Katalog

Sicherheitsmaßnahmen müssen nicht mehr abgetippt werden

Der Hinweis kam von einer DSB während der kostenlosen Testphase: «bei den Sicherheitsmaßnahmen kann ich nur schreiben». Sie hatte recht. Maßnahmen werden nun aus einem Katalog in neun Gruppen gewählt, bleiben frei ergänzbar, und das Programm hebt die passenden hervor, indem es Datenkategorien und Übermittlungen betrachtet. Auch die Datenkategorien erhalten eine beschreibende zweite Ebene, und das Zielland ist kein freies Feld mehr.

22. Aug. 2026Neu 4 min
Plattform
501gesetzliche Regeln, neun Rechtsordnungen

Wie lange Daten aufbewahrt werden: 501 Regeln, neun Rechtsordnungen und eine Methode

Die Speicherbegrenzung ist der Grundsatz, der sich bei einer Prüfung am schlechtesten belegen lässt, weil die Antwort für jede Datenkategorie und jedes Land anders ausfällt. Die Plattform bringt 501 bereits ausformulierte Regeln mit. Entscheidend ist aber nicht die Zahl: von 232 portugiesischen Regeln haben nur 99 eine als Zahl ausdrückbare Dauer, und 95 sind als «laufende Referenz» statt «geprüft» ausgewiesen. Das zu sagen ist nützlicher, als es zu verbergen.

22. Aug. 2026Neu 5 min
Bußgeld
80abgelehnte Auskunftsanträge

Der Kunde geht insolvent, der Dienstleister bleibt allein mit den Daten – und wird Verantwortlicher

Eine Handelskette wird insolvent. Die ehemaligen Beschäftigten brauchen ihre Stundenzettel, um ausstehende Löhne zu belegen, doch der Einzige, der sie hat, ist der Anbieter der Zeiterfassungssoftware. Er antwortet, er dürfe niemandem etwas offenlegen – „nicht einmal den betroffenen Personen selbst" –, weil der Vertrag mit dem Verantwortlichen beendet sei. Die norwegische Behörde entschied das Gegenteil: Wer als Einziger noch über die Daten bestimmt, ist der Verantwortliche.

21. Aug. 2026Neu 4 min
Rechtsprechung
200 €für den Kontrollverlust

Echte Beschäftigtendaten im Testsystem: was der Kontrollverlust wert ist

Ein neues Personalverwaltungssystem mit echten Daten zu testen ist nicht verboten – mehr Felder zu übertragen, als der Test braucht, schon. Das Bundesarbeitsgericht hat einen Arbeitgeber zu zweihundert Euro verurteilt, weil er Gehalt, Privatanschrift, Steuer-ID und Familienstand hochgeladen hatte, obwohl er mit dem Betriebsrat eine Liste von neun Feldern vereinbart hatte. Und es hat bestätigt, dass eine verspätete Auskunft für sich genommen kein Schaden ist.

21. Aug. 2026Neu 5 min
Regulierung
2 dic 2027il nuovo termine per l'alto rischio

Der 2. August ist nicht entfallen — er ist enger geworden

Wer nur die Überschrift gelesen hat — «die KI-Verordnung wird verschoben» — arbeitet mit einer falschen Information. Der 2. August 2026 ist nicht verschwunden: Er hat seinen Inhalt geändert. Was geblieben ist, betrifft weit mehr Mandanten als das, was verschoben wurde.

19. Aug. 2026Neu 5 min
Tech & KI
4i momenti in cui si decide

Die niederländische Aufsicht veröffentlicht eine Selbstbewertung für generative KI

Es fehlte etwas, das man dem Mandanten in die Hand geben kann, der sagt: «Wir haben die KI in der Software eingeschaltet.» Die niederländische Aufsicht hat eine Selbstbewertung zu generativen KI-Systemen veröffentlicht: vier Momente, und in jedem eine Entscheidung, die dokumentiert werden muss.

18. Aug. 2026Neu 4 min
Regulierung
133.000le PMI raggiunte dalla catena

NIS2 ist in den Niederlanden Gesetz — ohne Schonfrist

Die Cyberbeveiligingswet ist am 15. August 2026 in Kraft getreten. Die entscheidende Zahl ist nicht achttausend, sondern hundertdreiunddreißigtausend: die niederländischen KMU, die das Gesetz nicht erfasst, weil sie in den Anwendungsbereich fallen, sondern weil sie jemanden beliefern, der darin fällt.

15. Aug. 2026Neu 5 min
Tech & KI
1 su 4le violazioni con IA

Die Meldungen von Datenschutzverletzungen übertreffen bereits das ganze Jahr 2025

Die Zahlen des ersten Halbjahrs 2026 sagen zweierlei. Erstens: Die Zahl der benachrichtigten Personen wird von sehr wenigen riesigen Vorfällen bestimmt. Zweitens, unangenehmer für die Risikobewertung: KI taucht in jeder vierten Verletzung auf.

14. Aug. 2026Neu 4 min
Regulierung
3le vie per chiudere il conflitto

Wer entscheidet, kann sich nicht selbst überwachen

Am 10. August 2026 hat die CNIL schriftlich festgehalten, wie ein Interessenkonflikt des Datenschutzbeauftragten erkannt und gelöst wird. Der Maßstab ist ein einziger: Bestimmt der DSB in seinen übrigen Funktionen Zwecke und Mittel einer Verarbeitung, kann er sie danach nicht überwachen. Niemand kann Richter in eigener Sache sein.

10. Aug. 2026Neu 5 min
Rechtsprechung
7i criteri di bilanciamento CEDU

Nicht der Artikel wird gelöscht, sondern der Name

Am 5. August 2026 hat die CNIL die Grenzen eines Rechts geklärt, das häufig ausgeübt und weithin missverstanden wird. Gegenüber einem Presseorgan bleiben Widerspruch und Löschung anwendbar, Auskunft und Berichtigung nicht. Und eine Ablehnung ist konkret zu begründen: sechs allgemeine Formeln werden als unzulässig benannt.

05. Aug. 2026Neu 4 min
EDSA / EDSB
12-14gli articoli sotto esame

2026 schauen alle europäischen Behörden auf dasselbe: die Datenschutzhinweise

Jedes Jahr wählt der EDSA ein Thema, und alle nationalen Behörden prüfen es gemeinsam, im selben Zeitraum, mit Fragebögen und Prüfungen. Für 2026 lautet das Thema Transparenz: wie Verantwortliche Menschen darüber informieren, was mit ihren Daten geschieht. Im Fokus stehen Art. 13, wenn die Daten von der betroffenen Person stammen, und Art. 14, wenn sie anderswoher kommen. Die tschechische Behörde hat das Thema bereits in ihren Prüfplan aufgenommen.

10. Aug. 2026Neu 6 min
Regulierung

Portugals CNPD schreibt auf, wohin sie bis 2029 schauen wird

Am 24. Juli 2026 hat die portugiesische Behörde ihren Mehrjahresplan 2027-2029 und den Tätigkeitsplan 2027 verabschiedet. Es ist die Art von Dokument, die fast niemand liest und die Jahre im Voraus sagt, worauf sich die Aufsicht konzentrieren wird: digitale Schulung, digitale Verwundbarkeit, Regulierungskapazität für den DSA, KI-Kompetenzen und Neurodaten.

24. Juli 2026Neu 4 min
Bußgeld
4,3milioni EUR

Portugal: das höchste Bußgeld des Landes lehrt nur eines. Die Prüfung des Auftragsverarbeiters ist eine inhaltliche Pflicht, kein Formular

Mit dem Beschluss 2022/1072 verhängte die portugiesische CNPD gegen das INE ein einheitliches Bußgeld von 4,3 Millionen Euro für fünf Verstöße im Rahmen der Volkszählung 2021. Der lehrreichste betrifft nicht die Gesundheits- und Religionsdaten: Das INE schloss den Vertrag, obwohl der Anbieter ein Büro in Lissabon hatte, mit der US-Gesellschaft, akzeptierte den Gerichtsstand Kalifornien und den Datentransit über zweihundert Server, mit Standardvertragsklauseln und ohne jede zusätzliche Maßnahme.

12. Dez. 2022Neu 7 min
Rechtsprechung
3condizioni cumulative del test

Das berechtigte Interesse ist keine Auffang-Rechtsgrundlage

In der Rechtssache C-621/22 hat der Gerichtshof entschieden, dass ein wirtschaftliches Interesse ein berechtigtes Interesse im Sinne von Artikel 6 Absatz 1 Buchstabe f sein kann. Viele haben nur diese Zeile gelesen. Der Rest des Urteils erinnert daran, dass es bei drei kumulativen Voraussetzungen bleibt und dass die dritte - die Abwägung mit den vernünftigen Erwartungen der betroffenen Person - diejenige ist, an der der konkrete Fall gescheitert ist. Für den DSB folgt daraus etwas sehr Praktisches: das berechtigte Interesse existiert nur, wenn es irgendwo aufgeschrieben ist.

12. Aug. 2026Neu 6 min
Rechtsprechung
3elementi da provare, cumulativi

Schadenersatz nach der DSGVO: was der Kläger tatsächlich beweisen muss

Bußgelder der Behörden machen Schlagzeilen, Zivilklagen machen den Umsatz der Anwälte. Seit 2023 hat der Gerichtshof geklärt, dass der Ersatz nach Artikel 82 drei kumulative Elemente verlangt - Verstoß, Schaden, Kausalzusammenhang - ohne jede Erheblichkeitsschwelle. Und er hat entschieden, dass die begründete Befürchtung, die eigenen Daten seien in falsche Hände geraten, bereits ein immaterieller Schaden ist. Für den Verantwortlichen verschiebt sich damit das Spielfeld: nicht mehr die Schwere, sondern der Nachweis der getroffenen Maßnahmen.

11. Aug. 2026Neu 7 min
EDSA / EDSB
28 agotermine per candidarsi

Wettbewerb und Datenschutz: der EDSA öffnet den Tisch, und es gibt eine Frist

Nach dem DSA und vor DMA und KI-Verordnung betrifft das vierte Stück des europäischen Regulierungsmosaiks das Verhältnis von Wettbewerb und Datenschutz. Das ist nicht theoretisch: es geht um Daten als Marktgut, um Zusammenschlüsse und um die Stellung dessen, der Daten verarbeitet, weil er einen Markt beherrscht. EDSA und Kommission bitten um Beiträge, bevor sie schreiben - und diesmal ist die Frist nah.

30. Juli 2026Neu 6 min
EDSA / EDSB
10 lug 2027quando si potra' condividere

Geldwäschebekämpfung und Datenschutz: EDSA und AMLA schreiben die Regeln des Teilens gemeinsam

Am 1. Juli 2026 haben der EDSA und die europäische Geldwäschebehörde gemeinsame Leitlinien zu einer Frage angekündigt, die keiner von beiden allein lösen konnte: wie Banken, Berufsträger und Behörden Informationen über Verdachtsfälle austauschen können, ohne unkontrollierte Verdächtigenlisten zu bauen. Die Möglichkeit gilt ab dem 10. Juli 2027, die öffentliche Konsultation wird in der ersten Jahreshälfte erwartet. Wer Verpflichtete berät, hat ein Jahr Zeit.

01. Juli 2026Neu 6 min
EDSA / EDSB
16-17luglio 2026

EDSA aus Dublin: Es braucht eine Rechtsgrundlage, damit Behörden über Regelungsbereiche hinweg Informationen austauschen können

Zahl und Komplexität der Beschwerden steigen, auch wegen des zunehmenden Einsatzes von KI, und die Behörden sagen offen, dass die Ressourcen nicht reichen. Die Lösungen auf dem Tisch: gemeinsame Aktionen, Bündelung von Ressourcen zwischen Behörden und die kommende Verfahrensverordnung.

17. Juli 2026Neu 6 min
EDSA / EDSB
65art. GDPR

EDSA, verbindlicher Beschluss 1/2026: Eine Cookie-Beschwerde lässt sich nicht mit dem Vorwurf des Rechtsmissbrauchs abweisen

Die federführende Behörde wollte den Fall wegen angeblichen Missbrauchs von Art. 77 und Art. 80 Abs. 1 schließen. Die österreichische Behörde widersprach, der EDSA gab ihr recht: Weder die objektive noch die subjektive Komponente des Missbrauchs war nachgewiesen. Die Beschwerde geht zurück und ist in der Sache zu prüfen.

14. Juli 2026Neu 7 min
Regulierung
3condizioni

Kontrolle von Beschäftigten: die CNIL erinnert daran, dass es drei Bedingungen sind und alle erfüllt sein müssen. Verhältnismäßigkeit ist nur die erste

Am 9. Juli 2026 hat die CNIL ihre Seite zur Kontrolle der Tätigkeit von Beschäftigten aktualisiert. Der Inhalt wirkt wie eine Wiederholung, aber ein Punkt wird in der Praxis ständig unterschätzt: es sind drei Bedingungen, sie sind kumulativ, und zwei der drei haben nichts damit zu tun, wie eingriffsintensiv das Mittel ist.

09. Juli 2026Neu 6 min
Regulierung
71%lo vuole

71 % der Datenschutzbeauftragten wollen die KI-Verordnung im eigenen Zuständigkeitsbereich. 27 % sagen, sie kennen sie. 85 % hatten nie eine KI-Schulung

Am 3. Juli 2026 haben das französische Arbeitsministerium, die AFCDP und die CNIL die fünfte Ausgabe des Observatoriums zum Beruf des Datenschutzbeauftragten veröffentlicht, durchgeführt von der Afpa. Die einfache Lesart lautet, Datenschutzbeauftragte würden zu KI-Ansprechpartnern. Die nützliche Lesart ist eine andere: zwischen denen, die die KI-Verordnung im Zuständigkeitsbereich wollen, und denen, die sagen, sie kennen sie, liegen 44 Punkte - und die KI-Verordnung erwähnt den Datenschutzbeauftragten nie.

03. Juli 2026Neu 6 min
Rechtsprechung
13milioni EUR

Österreich: der Verwaltungsgerichtshof setzt das Bußgeld von 18 auf 13 Millionen herab. Zu lesen ist aber die Stelle, an der er sagt, dass ein Compliance-Programm nichts entschuldigt

Am 24. Juni 2026 hat der österreichische Verwaltungsgerichtshof ein seit 2019 laufendes Verfahren abgeschlossen und die Geldbuße für die Verarbeitung von „Partei-Affinitäten“, berechnet für rund 2,2 Millionen Personen, auf 13 Millionen Euro herabgesetzt. Die Schlagzeilen werden vom Abschlag sprechen. Für einen Datenschutzbeauftragten zählt der Rest: der Gerichtshof sagt, dass für die Bestrafung einer juristischen Person kein Handeln der Leitungsorgane erforderlich ist, dass Mittel für rechtliche Beratung die Anforderungen erhöhen statt sie zu senken, und dass die Vorwürfe zu Datenschutz-Folgenabschätzung und Verarbeitungsverzeichnis durch Konsumtion wegfallen - nicht weil diese Dokumente richtig waren.

24. Juni 2026Neu 7 min
Bußgeld
2.126.075persone

Schweden: 6 Millionen Kronen für eine SQL-Injection. Das Härteste ist nicht das Bußgeld, sondern dass das Risiko seit 2021 im eigenen Risikoregister stand

Am 26. Januar 2026 verhängte die schwedische Aufsichtsbehörde gegen Sportadmin i Skandinavien AB ein Bußgeld von 6.000.000 Kronen wegen Verstoßes gegen Art. 32 Abs. 1. Die Plattform verwaltet Mitglieder, Rechnungen und Websites von Sportvereinen: der Angriff vom 16. Januar 2025 legte die Daten von 2.126.075 Personen offen, überwiegend Kinder, samt Allergien und Behinderungen. Die Stelle, die Sie zweimal lesen sollten, ist aber eine andere: seit 2021 hatte das Unternehmen das Risiko von SQL-Injections in den eigenen Jahresprüfungen identifiziert, und genau darauf stützt die IMY die grobe Fahrlässigkeit.

26. Jan. 2026Neu 8 min
Regulierung
5priorita' 2026

Netherlands: who supervises the AI Act, and where they will start. Prohibited practices and AI literacy, not high-risk systems

The Dutch government has designated the Autoriteit Persoonsgegevens and the Rijksinspectie Digitale Infrastructuur as coordinating national supervisors for the AI Act. The 2026 work agenda lists five priorities: overarching system supervision, transparency and explainability, frameworks and standards, testing for bias and fairness against discrimination, and AI literacy. The first formal enforcement actions are expected during 2026, starting with organisations using prohibited practices or demonstrably neglecting the AI literacy obligation.

01. Aug. 2026 5 min
Bußgeld
23sanzioni in 6 mesi

France: 23 fines in six months under the simplified procedure. Small amounts, new target

In the review published on 6 July 2026 the CNIL counts 23 new fines adopted since January under its simplified procedure, totalling EUR 133,750. Three infringements recur: excessive video surveillance, non-compliant cookie banners, and failure to respond to access and erasure requests. One example of the kind of target: EUR 7,500 against a company operating public toilet facilities, on 2 April.

06. Juli 2026 5 min
Bußgeld
5milioni EUR

France: EUR 5 million for IQVIA. The pharmacy software kept sending the data even when the patient had said no

On 26 May 2026 the CNIL's restricted committee fined IQVIA Operations France EUR 5 million. The company runs two health data warehouses for third-party studies: LRX, authorised in 2018 and fed by around 14,000 pharmacies, and EMR, authorised in 2021 and fed by several thousand doctors. Among the findings, the most instructive: the practice management software used in pharmacies transmitted customer data to IQVIA even where the customer had objected.

26. Mai 2026 7 min
Rechtsprechung
792.639EUR confermati

Finland: the Supreme Administrative Court upholds the fine on Verkkokauppa.com. The failing: never having defined how long to keep the data

On 12 June 2026 the Korkein hallinto-oikeus, Finland's Supreme Administrative Court, dismissed Verkkokauppa.com's appeal against the penalty imposed by the Finnish Data Protection Ombudsman's sanctions board (decision KHO 12.6.2026/1604). The original amount was EUR 856,000, reduced by the Administrative Court to EUR 792,639 on the basis of the company's most recent turnover. The finding does not concern a data breach: it concerns the fact that the company had never defined retention periods for customer account data.

12. Juni 2026 6 min
Bußgeld
749firmatari esposti

Poland: a municipality fined not for publishing the data of 749 petition signatories, but for never reporting it

On 25 May 2026 the President of the UODO fined the mayor of Myslenice PLN 7,700. An un-anonymised petition had been published in the municipality's Public Information Bulletin: names, surnames, home addresses and signature specimens of 749 people. The core of the decision is not the publication, which the municipality corrected by replacing the file: it is that the breach was never notified to the authority, not even after the authority asked.

25. Mai 2026 6 min
Rechtsprechung
600.000EUR annullati

Netherlands: the Council of State confirms the annulment of the EUR 600,000 fine for Enschede's wifi tracking

On 29 July 2026 the Administrative Jurisdiction Division of the Raad van State dismissed the appeal of the Autoriteit Persoonsgegevens against the municipality of Enschede, upholding the February 2024 judgment of the Overijssel District Court. The EUR 600,000 fine, imposed in March 2021 for counting city-centre visitors through sensors capturing the MAC addresses of wifi-enabled devices, remains annulled. The reason is not that the tracking was lawful: it is that the authority did not sufficiently demonstrate that the MAC addresses collected qualified as personal data and that processing of personal data had therefore taken place.

29. Juli 2026 6 min
Bußgeld
10.145PLN al responsabile

Poland: WhatsApp in the sales network brings a fine for the processor, and a reprimand for the controller that never vetted it

On 22 June 2026 the President of the UODO, Miroslaw Wroblewski, closed the proceedings opened after a breach notification by Energa-Obrot: reprimands for the controller and the processors, and an administrative fine of PLN 10,145 for one of the processors. At the root of it, the use of WhatsApp by sales representatives of a door-to-door network during the pandemic: on a former agent's private phone there were scans and photographs of customer contracts, in group conversations, for many months.

22. Juni 2026 7 min
Bußgeld
277.500EUR

Ireland: EUR 277,500 for Permanent TSB over a contact centre that could be fooled, and for reporting late

On 8 May 2026 the Irish Data Protection Commission closed its inquiry into a series of personal data breaches at Permanent TSB, first notified in May 2022. Malicious actors, holding certain customer information, called the Open24 contact centre posing as customers, gained access to accounts and amended account details. Some customers lost money. The authority issued a reprimand and fines totalling EUR 277,500.

08. Mai 2026 6 min
Regulierung
3priorita'

Die niederländische Behörde nennt ihre Schwerpunkte 2026-2028: Massenüberwachung, künstliche Intelligenz, digitale Widerstandsfähigkeit

Die Autoriteit Persoonsgegevens hat drei strategische Schwerpunkte für 2026-2028 festgelegt: Massenüberwachung, künstliche Intelligenz und digitale Widerstandsfähigkeit. Im Jahresplan 2026 erklärt die Behörde, mehr Kapazität für KI und Algorithmen bereitzustellen und sich auf großflächige Systeme mit erheblicher gesellschaftlicher Wirkung zu konzentrieren, ohne zwischen öffentlichem und privatem Sektor zu unterscheiden.

01. Aug. 2026 6 min
Regulierung
2autorita'

Netherlands and Poland: two authorities that raised the bar in 2026

The Dutch Autoriteit Persoonsgegevens has increased its budget and headcount and has named transparency, tracking and cookies among its 2026 supervisory priorities, with an approach that is openly less advisory and more enforcement-driven. In Poland the President of the UODO has shifted attention towards small and medium enterprises, a segment until recently little touched by inspections. For anyone with clients in those countries, or considering it, these are two signals that change the cost-benefit balance of compliance.

30. Juli 2026 4 min
Bußgeld
460keuro

Piaggio mit 460.000 Euro sanktioniert: 112 dienstliche E-Mails gelesen, Backups fünf Jahre nach dem Ausscheiden

Die italienische Datenschutzbehörde hat gegen Piaggio & C. Spa ein Bußgeld von 460.000 Euro verhängt, weil das Unternehmen dienstliche E-Mail-Postfächer in unzulässiger Weise verwaltet hat. Das Verfahren, ausgelöst durch Beschwerden zweier ehemaliger Beschäftigter, ergab, dass während des Beschäftigungsverhältnisses insgesamt 112 E-Mails erhoben wurden, teils aus einer Zeit rund zwei Jahre vor dem Aufkommen des Verdachts. Möglich wurde dies durch Backups, die für die gesamte Dauer des Arbeitsverhältnisses und bis zu fünf Jahre danach aufbewahrt wurden. Neben dem Bußgeld untersagte die Behörde dem Unternehmen den Zugriff auf die erhobenen Daten.

29. Juli 2026 7 min
Regulierung
5settori

KI-Verordnung in Italien: die Datenschutzbehörde wird Marktüberwachungsbehörde für Hochrisiko-Systeme in Justiz, Grenzverwaltung und demokratischen Prozessen

Die italienische Datenschutzbehörde hat eine zustimmende Stellungnahme zum Entwurf des Gesetzesdekrets zur Umsetzung der KI-Verordnung in Italien abgegeben. Das Dekret regelt die nationale Governance und benennt die Behörde als Marktüberwachungsbehörde für Hochrisiko-KI-Systeme in den für die Grundrechte sensibelsten Bereichen: Justiz, Strafverfolgung, Migration, Grenzverwaltung und demokratische Prozesse. Eine der gestellten Bedingungen betrifft jede Organisation: das Verbot ausschließlich automatisierter Entscheidungen auf Bewertungen auszudehnen, die das Arbeitsverhältnis berühren.

29. Juli 2026 6 min
Italienische Behörde
12keuro

Falsch konfiguriertes Dokumentenregister: 12.000 Euro für die Metropolitanstadt Sassari

Nach einer Meldung einer Datenschutzverletzung und einer Beschwerde hat die italienische Datenschutzbehörde gegen die Metropolitanstadt Sassari ein Bußgeld verhängt, weil deren elektronisches Dokumentenregister so konfiguriert war, dass Dokumente mit personenbezogenen Daten für Beschäftigte zugänglich waren, die aufgrund ihrer Rolle und Aufgaben nicht zu deren Verarbeitung befugt waren. Das Bußgeld beträgt 12.000 Euro, doch der Grundsatz gilt für jede Behörde und jedes Unternehmen mit einem Dokumentenmanagementsystem: Die Registrierung ist keine neutrale Tätigkeit, und eine Voreinstellung mit vollständiger Sichtbarkeit verletzt die Grundsätze der Integrität und Vertraulichkeit.

29. Juli 2026 6 min
Regulierung
2 agoma non tutto

AI Act, 2 August: what actually applies and what has been postponed to 2027

For two years 2 August 2026 was presented as the day obligations for high-risk AI systems would start. The Digital Omnibus package changed that calendar: requirements for Annex III high-risk systems move to 2 December 2027 for stand-alone systems and 2 August 2028 for those embedded in products already covered by sectoral legislation. 2 August nonetheless remains an operative date: the transparency obligations of Article 50 become applicable, together with the full operation of governance and penalties, with national authorities acquiring full powers.

29. Juli 2026 5 min
Regulierung
0multe dirette

Denmark: cookies are the 2026 priority, and fines are decided by a court

The Danish authority has flagged cookie consent as a supervisory priority for 2026, coordinating with the Digitaliseringsstyrelsen, which oversees the ePrivacy implementation while Datatilsynet applies the GDPR. But Denmark has a peculiarity that changes how every one of its decisions should be read: its constitutional order does not allow an administrative authority to impose punitive financial penalties. Recital 151 GDPR expressly anticipates this for Denmark and Estonia: the fine is decided by a court as a criminal penalty, following a report by the authority to the police.

28. Juli 2026 4 min
Regulierung
14 luggia' scaduta

Email tracking pixels: France has already closed its grace period, Italy's runs to October

With deliberation no. 2026-042 of 12 March 2026, made public on 14 April, the French CNIL adopted its final recommendation on email tracking pixels: for most marketing uses, prior consent is required, just as for cookies. Existing contact bases were given three months to inform recipients and allow them to object, a period that ended on 14 July 2026, with checks announced from that date. In Italy the authority reached the same conclusion with decision no. 284 of 17 April 2026, but with a longer compliance window.

26. Juli 2026 4 min
Bußgeld
365milaclienti

Wind Tre, EUR 1.7 million: the breach started with a phone call

The Italian DPA fined Wind Tre EUR 1,715,600 (decision no. 348 of 14 May 2026, made public with the 16 July newsletter). The starting point was not a sophisticated cyberattack: people posing as support technicians convinced staff at two retail outlets to allow access to company systems. From there, identification and contact data of 365,048 customers were exfiltrated; for 41,359 of them, payment method information as well, including IBANs, postal payment slips and credit cards with partially masked numbers and expiry dates. The charges: breach of the integrity and confidentiality principle (Art. 5(1)(f)) and of security obligations (Art. 32(1)(b)).

26. Juli 2026 4 min
Bußgeld
1,5MEUR

Cookies, France holds the line: EUR 1.5 million to American Express and the topic stays a 2026 priority

In January 2026 the CNIL fined American Express EUR 1.5 million for cookie violations, confirming that the topic remains a standalone enforcement priority alongside artificial intelligence and cybersecurity. In 2025 there had been 21 cookie decisions, totalling over EUR 475 million. The recurring charges are always the same: trackers set before consent, a reject button less visible or further away than the accept button, inadequate information.

25. Juli 2026 3 min
Regulierung
art. 15GDPR

Call centre recordings: the customer has a right to access them, and a transcript is enough

A customer had asked to access their own data contained in a recorded call with customer service. The company refused, considering the protection of the agent's confidentiality to prevail. The authority held that the request could be satisfied by providing the transcript, provided the elements identifying other people involved are redacted: given the professional context of the call and its subject, a supply contract, redaction would not have prejudiced the agent's confidentiality.

25. Juli 2026 3 min
Regulierung
3linee guida

EDPB adopts guidelines on anonymisation, web scraping for generative AI, and blockchain

At its July 2026 plenary, the European Data Protection Board adopted guidelines on anonymisation and on web scraping in the context of generative artificial intelligence, together with the final version of the guidelines on processing personal data through blockchain technologies. Three documents addressing three recurring questions: when data is truly anonymous, on what conditions data may be collected from the web to train models, and how the immutability of a chain can be reconciled with data subjects' rights.

24. Juli 2026 3 min
Bußgeld
18MEUR

Spain: EUR 18 million to Amadeus for reusing booking data for product development

The Spanish authority fined Amadeus IT Group EUR 18 million (reduced to 14.4 with voluntary payment) for aggregating travellers' booking data into profiles for product development. The cross-border investigation found the reuse of data collected years earlier from airlines and agencies, for purposes data subjects could not reasonably expect, without an Article 14 notice and without a valid legitimate-interest balancing test.

23. Juli 2026 4 min
Bußgeld
6Miscritti

Norway: loyalty programme under scrutiny, more than six million members involved

The Norwegian authority concluded proceedings opened after an audit of the Nordic entities of a retail group, finding several breaches relating to its loyalty programme: invalid consent, new processing purposes introduced without assessment, insufficient legitimate-interest balancing, and failure to answer data subject requests within the deadline. More than six million members across the Nordic region were affected.

22. Juli 2026 3 min
Bußgeld
3provvedimenti

Credit scoring in utilities: the Italian DPA hits the whole chain with three decisions in one day

With three decisions adopted in the same session on 3 July 2026, the Italian DPA targeted the credit-scoring chain applied to energy supply contracts: Experian Italia, Hera Comm and Cerved. The charges are similar and paint a clear picture: deficient notices, breaches of minimisation and storage limitation, privacy by design and by default disregarded, inadequate responses to access requests and poorly governed Article 28 relationships along the chain.

21. Juli 2026 4 min
Regulierung
art. 21d.lgs. 24/23

Whistleblowing: without consulting the unions, the procedure is not compliant

A preliminary requirement that almost everyone overlooks is back in the spotlight: Article 4 of Legislative Decree 24/2023 requires internal reporting channels to be activated after hearing worker representatives or trade unions. The ANAC guidelines clarify that failing to do so makes the procedure non-compliant and may trigger a sanction under Article 21. It also applies to substantial updates, not just first activation.

20. Juli 2026 3 min
Bußgeld
1,7MEUR

Data breach: Italian DPA fines Wind Tre EUR 1.7 million after exfiltration of 365,000 customers' data

In its 16 July 2026 newsletter the Italian DPA announced a EUR 1.7 million fine to telecom operator Wind Tre following a data breach with exfiltration of roughly 365,000 customers' data. The case confirms the authority's line on large operators: the incident itself is not the fault - the fault lies in security measures inadequate to the risk (Art. 32) and in how the breach was handled. In the same newsletter: two debt-collection companies fined (EUR 50k and 30k) and the customer's right to access the audio of their own support calls (Enel case).

17. Juli 2026 3 min
Bußgeld
158KEUR

Character.AI fined EUR 158,000: minors, late DPIA and missing EU representative

With a decision of 3 July 2026 (announced 9 July) the Italian DPA fined Character Technologies Inc., the US company behind Character.AI, EUR 158,000: deficient privacy notice (Arts. 12-14), a DPIA prepared late relative to the service launch, late designation of the EU representative (Art. 27) and shortcomings in minor protection and age verification. Beyond the fine, corrective measures within 120 days: working age verification, an effective cooling-off period against re-registration by blocked minors, minors' profiles private by default.

16. Juli 2026 4 min
Italienische Behörde
2/2genitori

Children's photos on social media: both parents must consent

In its 17 June 2026 newsletter the Italian DPA restated a principle that matters well beyond family disputes: publishing photos of minor children on social media requires the consent of BOTH parents. In case of disagreement, the child's protection prevails. For the DPO it is an operational criterion affecting schools, nurseries, sports clubs, parishes and companies publishing images of minors for promotional purposes.

15. Juli 2026 3 min
Italienische Behörde
STOPcopie

Italian DPA to hoteliers: do not keep copies of guests' ID documents

In a notice addressed to the hospitality sector, the Italian DPA reiterated that hoteliers may not keep copies of guests' identity documents: the legal duty (Art. 109 of the Italian public-security code) is to identify the guest and transmit the data to the police via the Alloggiati Web portal - after that, document copies must be destroyed or deleted. A widespread habit becomes a concrete sanction risk.

14. Juli 2026 3 min
Regulierung
EDPBconsultazione

Data breach: EDPB puts a new EU-wide notification template up for consultation

The EDPB has opened a public consultation on a new harmonised data-breach notification template, designed to align the information requested by authorities across Member States. For DPOs it is operational news: the content of the Art. 33 notification is becoming standardised, and anyone with a structured internal procedure (facts, categories, risk assessment, measures) will find the work already done.

13. Juli 2026 3 min
Bußgeld
563KEUR

Enel Energia fined EUR 563,000: the 'administrative' call that turns into a sales pitch

With decision no. 170/2026 the Italian DPA fined Enel Energia EUR 563,052: during purely administrative contacts (supply paperwork, takeover confirmations), including via third parties, commercial offers were made without a valid legal basis - even to customers on the opt-out register or who had expressly refused marketing consent. Also challenged: a re-contact mechanism based on opt-out (an SMS with 90 seconds to refuse) and partner vetting - one agency was contracted two months after being sanctioned by the DPA for marketing.

09. Juli 2026 4 min
Bußgeld
55KEUR

Italy's DPA fines AgID: EUR 55,000 to the Agency for Digital Italy over transparency and privacy by design

With injunction order no. 419 of 28 May 2026 the Italian DPA declared unlawful certain personal data processing carried out by AgID - the Agency for Digital Italy, with a EUR 55,000 fine and publication of the decision on the authority's website. The breaches concern lawfulness, fairness and purpose limitation (Art. 5), information duties towards data subjects (Arts. 12 and 14) and data protection by design (Art. 25).

08. Juli 2026 3 min
Art. 5
AI Act
Bußgeld

Italy's DPA halts stress and emotion monitoring at work: not even in aggregate form

With decision no. 342 of 2026, the Italian DPA reaffirmed that data on employees' health or psychological journey cannot be made accessible to the employer, not even in aggregate form. The case closes the loop with the AI Act, which expressly prohibits AI systems that infer people's emotions in the workplace (Art. 5): organisational wellbeing cannot turn into emotional surveillance.

06. Juli 2026 4 min
8
mesi
Bußgeld

Trenitalia tells customers about a data breach eight months after the attack: an Art. 34 lesson

In July 2026 Trenitalia informed its customers of a data breach suffered roughly eight months earlier. Beyond the outcome, the case is a textbook lesson on the difference between notifying the authority within 72 hours (Art. 33) and communicating to data subjects 'without undue delay' when the risk to their rights is high (Art. 34): eight months are hard to justify, and in the meantime the persons affected could not protect themselves.

04. Juli 2026 3 min
Italienische Behörde
37,7MEUR

Italian DPA annual report: collected fines +54.5%, almost 7 data breaches notified per day, AI at the centre

On 2 July 2026 the Italian DPA presented its 2025 activity report to Parliament: 807 collegial decisions, 506 corrective and sanctioning measures, over EUR 37.7 million in fines collected (+54.5% on 2024), 2,415 data breaches notified (+10%), 130 inspections. AI takes centre stage: from DeepSeek to deepfakes, from facial recognition at the airport to worker surveillance.

02. Juli 2026 4 min
1,5M
cittadini
Bußgeld

SPID under scrutiny: Lepida fined, data of 1.5 million citizens viewable 'out of mere curiosity'

With a decision of 29 April 2026, the Italian DPA fined Lepida (EUR 100,000), one of Italy's main SPID identity providers: over 7,000 counter operators could view data and download copies of ID documents and health cards of more than 1.5 million citizens, even with no operational need. The DPA found accesses 'out of mere curiosity' and documents left stored on operators' workstations after identification.

01. Juli 2026 4 min
AI Act
update
Regulierung

Digital Omnibus: EU Council approves changes to the AI Act. What it means if you are preparing

On 29 June 2026 the EU Council approved the proposed regulation that streamlines and simplifies certain AI rules, amending the AI Act (the 'Digital Omnibus' package). Negotiations with Parliament continue: until final adoption, the current AI Act text remains the reference, including the August 2026 transparency deadlines.

29. Juni 2026 3 min
Bußgeld
180kEUR

Italy's DPA fines Emirates EUR 180,000: passenger health data kept for 7 years and an unclear notice

The Italian DPA fined Emirates EUR 180,000 over the handling of reduced-mobility passengers' health data. The case started from a complaint by a passenger asked to fill in a medical form despite not being in the categories required to do so. The key point for DPOs: the collection itself was lawful, but the authority faulted an inadequate notice and excessive retention (7 years).

17. Juni 2026 4 min
Art. 5
GDPR
Bußgeld

Loyalty-card data used to fire an employee: Italy's DPA says no. A lesson on purpose limitation

With decision no. 311 of 29 April 2026, the Italian DPA found unlawful the employer's use of data collected through the loyalty card to support an employee's dismissal. That data had been collected to run the loyalty programme, not to monitor or discipline staff. The point for DPOs: having a piece of data does not mean you can use it for any purpose.

15. Juni 2026 4 min
Regulierung
12-14artt.

EDPB 2026: the EU coordinated action targets transparency (Art. 12-14). What to check in privacy notices

For 2026 the EDPB chose TRANSPARENCY as the topic of its coordinated enforcement action: authorities will examine how organisations inform data subjects under Art. 12-14. In short: clear, complete, verifiable notices. A good moment to review your clients' documents.

12. Juni 2026 5 min
Bußgeld
7,1mld EUR

GDPR fines top EUR 7.1 billion: enforcement accelerates and SMEs are not exempt

Cumulative GDPR fines have passed EUR 7.1 billion across 1,400+ decisions. Enforcement is accelerating, not plateauing. And contrary to a common myth, SMEs do get fined: smaller amounts, same proportional severity.

12. Juni 2026 5 min
5M
EUR
Bußgeld

France fines IQVIA EUR 5M: pseudonymisation does not take you out of the GDPR

In France the authority (CNIL) fined IQVIA EUR 5 million, clarifying a point many confuse: pseudonymising data - even health data - is not the same as anonymising it. Pseudonymised data remains personal data and must be handled with all the safeguards of the Regulation, including the enhanced ones in Art. 9.

10. Juni 2026 3 min
Regulierung
15MEUR

Rome Court annuls the Garante's EUR 15M fine against OpenAI: the one-stop-shop decides

The Rome Court annulled the EUR 15M fine the Italian Garante imposed on OpenAI in 2024. The judge does not rule on the merits (legal basis, notice, age verification): it upholds the jurisdiction argument. For cross-border processing the one-stop-shop and lead authority govern.

10. Juni 2026 6 min
Regulierung
6ambiti

The Garante's 2026 inspection plan: six areas and how to be ready

The Italian Garante set its 2026 inspection areas, backed by the Finance Police tech-fraud unit. Topics include data breaches in public databases and abusive access. Those who document self-assessment and lesson learning get treated differently.

10. Juni 2026 5 min
Bußgeld
5MEUR

France: CNIL fines France Travail EUR 5 million - 36.8 million data subjects and a social-engineering attack

The CNIL fined France Travail (formerly Pole Emploi) EUR 5 million after a breach exposing the data of around 36.8 million people. Attackers used social engineering against partner advisers' accounts. The lesson: having security plans is not enough, they must actually be implemented.

09. Juni 2026 6 min
Bußgeld
1,7MEUR

France: EUR 1.7 million to Nexpublica - health and disability data accessible to other users through long-known flaws

The CNIL fined software vendor Nexpublica EUR 1.7 million: its PCRM tool, used by social services, exposed sensitive documents (including disability data) to other users. The flaws were known from prior audits but left open. A textbook case for anyone processing health data.

09. Juni 2026 6 min
Bußgeld
10MEUR

Spain: AEPD fines Aena EUR 10 million for biometric boarding without adequate DPIA

The Spanish Data Protection Agency fined Aena over EUR 10 million for launching its biometric boarding programme without completing an adequate DPIA. Not a data breach: a failure of preventive accountability.

25. Mai 2026 8 min
Bußgeld
290MEUR

Netherlands: the EUR 290 million Uber fine and the Dutch Authority's new priorities for 2026

The Autoriteit Persoonsgegevens confirmed the EUR 290 million fine against Uber for unlawful transfers to the US. Meanwhile the Authority sets three strategic priorities for the next two years every DPO should know.

22. Mai 2026 7 min
Bußgeld
85kEUR

Data breach: Italy's DPA fines The European House - Ambrosetti EUR 85,000 over plaintext passwords and late notification

The Italian DPA fined The European House - Ambrosetti spa EUR 85,000 following a 2024 data breach affecting 61,670 people. The attack, via a technical vulnerability, led to the exfiltration of names, emails, usernames and passwords. The point for DPOs: the breach was notified to the regulator within 72 hours, but data subjects were informed only after two months and after the authority stepped in.

21. Mai 2026 4 min
EDSA / EDSB
25DPA

EDPB CEF 2026: 25 European DPAs verify transparency of privacy notices

The European Data Protection Board has launched the 2026 coordinated action on transparency and information obligations. 25 national DPAs (including the Italian Garante) are already contacting controllers in various sectors. What to expect and how to prepare.

20. Mai 2026 9 min
Italienische Behörde
1 lug 2026deadline

Italian DPA cracks down on WhatsApp and Telegram in public administration: ban on operational communications with citizens from July 1, 2026

The Italian DPA (Garante) issued a general provision banning Italian public administrations from using WhatsApp, Telegram, Messenger and other commercial messaging apps for operational communications with citizens. Banned also for requesting documents, certificates or personal data. PAs must use institutional channels (PEC, portals, SPID-auth) by July 1, 2026. Fines up to 100,000 EUR.

19. Mai 2026 9 min
Tech & KI
1ain UE

Spain: AEPD publishes Europe's first guidance on agentic AI and data protection

The Spanish Data Protection Agency is the first European Authority to publish elaborate guidance on agentic AI. It explains the concept, the vulnerabilities in processing personal data and mitigation measures for controllers and processors.

18. Mai 2026 7 min
Bußgeld
45MEUR

Vodafone Germany fined EUR 45 million: the Art. 28 GDPR lesson on processor controls

The German Federal Commissioner for Data Protection (BfDI) imposed a total fine of EUR 45 million on Vodafone GmbH: 15M for Art. 28 violation (processor oversight) and 30M for Art. 32 (security). A decision that redefines accountability expectations on processors.

15. Mai 2026 8 min
Regulierung
18settori essenziali

NIS2 and GDPR: how to orchestrate them operationally after Italian Decree 138/2024. The DPO checklist for the NIS Operator

After the NIS2 transposition with Legislative Decree 138/2024, Italian companies qualified as 'essential entities' or 'important entities' must coordinate NIS2 obligations (cyber security, 24h incident reporting) with GDPR obligations (72h data breach). The DPO is not the NIS Coordinator but must interface: risk of double sanctions if not properly orchestrated.

15. Mai 2026 11 min
EDSA / EDSB
12raccomandazioni

EDPB publishes guidelines on public DPO profiles: transparency, accountability and data subject rights

The EDPB clarifies how to process the professional data of DPOs exposed publicly on online directories: legal basis, purposes, data subject rights and platform responsibilities.

12. Mai 2026 8 min
Tech & KI
Aug 2026

AI Act August 2026: high-risk systems deadline. Mandatory DPIA for enterprise LLMs

The EU AI Act enters its critical phase: August 2026 triggers obligations for high-risk systems. The Italian Garante has already anticipated enforcement with the EUR 5M fine to Luka (Replika). What DPOs must do now.

08. Mai 2026 10 min
Regulierung
Art. 26AI Act

AI Act and DPO: how the DPO role changes with deployer obligations entering into force in August 2026

In less than 3 months, the AI Act sections dedicated to deployers (users) of high-risk AI systems enter into force. The DPO becomes a key interlocutor for impact assessment, data subject information and monitoring.

08. Mai 2026 10 min
Italienische Behörde

Corporate email post-termination: Italian DPA fines ITAS Mutua

The Italian Data Protection Authority addresses the management of corporate emails after employment termination. ITAS Mutua sanctioned for undocumented access and retention beyond necessary.

07. Mai 2026 5 min
Rechtsprechung
530MEUR

TikTok vs Irish DPC: Supreme Court suspends 530 million euro fine

The Irish Supreme Court confirms the suspension of the record 530M EUR fine imposed by the DPC on TikTok for EEA data transfer to China. The case exposes the structural problem of enforcement timing against big tech.

30. Apr. 2026 6 min
Regulierung
6mesi

Email tracking pixels: new Italian DPA Guidelines

On April 17, 2026, the Italian DPA adopted Guidelines on tracking pixels in emails. For DPOs: 6 months to align privacy notices, consent flows, and privacy-by-design techniques.

17. Apr. 2026 5 min
Bußgeld
31.8MEUR

Intesa Sanpaolo: 31.8M euro fine from the Italian DPA

The Italian Data Protection Authority fines Intesa Sanpaolo for a data breach affecting 2.4 million customers. Late notification and incomplete information among the key issues.

26. März 2026 4 min
Rechtsprechung
15MEUR

Rome Court annuls 15M euro fine against OpenAI

The Rome Court annuls the fine that the Italian DPA had imposed on OpenAI for the ChatGPT case. A decision that redefines the scope of GDPR enforcement on generative AI models.

20. März 2026 4 min
Bußgeld
500KEUR

Enel Energia fined over 500,000 euros: telemarketing without consent

The Italian DPA fines Enel Energia for promotional calls to subjects who had not provided consent or had registered their number in the public opposition register.

12. März 2026 3 min
Rechtsprechung
120giorni

Italian Supreme Court 984/2026: the DPA 120-day deadline is final

With its January 17, 2026 ruling, the Italian Supreme Court confirms that the 120-day deadline for concluding the DPA's enforcement proceedings is final. A relevant decision for those handling privacy litigation.

18. Feb. 2026 3 min
EDSA / EDSB

EDPB: DPOs are under-resourced and disconnected from top management

EDPB publishes the results of the coordinated enforcement action: insufficient resources, lack of access to top management, conflict of interest risk. A snapshot that also concerns Italian external DPOs.

17. Feb. 2026 4 min
Rechtsprechung

France's Conseil d'Etat: the line between anonymization and pseudonymization narrows

France's State Council confirms CNIL's approach on pseudonymized health data. A ruling that redefines the practical scope of GDPR anonymization and impacts all data analytics projects.

13. Feb. 2026 5 min
EDSA / EDSB

EDPS strengthens DPO independence: new binding rules

The European Data Protection Supervisor (EDPS) adopts new binding rules to protect DPO independence within Union institutions. A signal strengthening the role.

13. Feb. 2026 3 min
EDSA / EDSB
96h

Digital Omnibus: EDPB and EDPS call for simplification without setbacks

EDPB and EDPS publish the joint opinion on the EU Commission's Digital Omnibus package. Positive measures on data breach and DPIA, but strong opposition to the revision of the personal data definition.

11. Feb. 2026 5 min
Italienische Behörde
40ispezioni

Italian DPA 2026 inspection plan: data breach, whistleblowing, AI in schools

The Italian DPA published its inspection activities plan for January-June 2026. Sectors at risk: banking data breaches, health dossiers, energy telemarketing, and AI in schools.

29. Jan. 2026 3 min
Bußgeld
42MEUR

CNIL fines Free Mobile and Free 42 million euros: 24 million customer data breach

The French Authority separately fines Free Mobile (27M) and Free (15M) for a breach that exposed 24 million subscribers in October 2024. A decision that clarifies the scope of Art. 34 GDPR.

13. Jan. 2026 7 min