All news
Regulation June 10, 2026 5 min

The Garante's 2026 inspection plan: six areas and how to be ready

Decision 797 of 30 December 2025 sets the H1 inspection areas. Data breaches in public databases top the list

TL;DR for the DPO

Decision 797 of 30 December 2025 sets the Garante's H1 2026 inspection areas. Inspections involve the Finance Police tech-fraud unit, so they can have criminal implications. Notice can be short.

Areas in focus

  • Data breaches in public databases, abusive access and resale of information
  • Large-scale processing and special categories
  • Security measures and the ability to demonstrate what was done (accountability)

The lesson from recent decisions

After Intesa Sanpaolo (EUR 31.8M) the standard is clear: not suffering an attack is not enough, you must be able to PROVE you did the right things. Documented self-assessment changes the sanctioning outcome.

Official source:Garante - Decision 797 of 30 December 2025

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Regulation
26the article nobody signs before broadcasting

Who answers for the live stream of the under-14 match? Sweden answers the question nobody asks

On 25 August the Swedish authority published guidance on streaming youth sport. Many clubs stream children's matches online, and the guidance sets out the factors that decide what is allowed. But the part worth reading is the other one: responsibility when the municipality owns the venue and the club wants to install cameras.

Aug 25, 2026New 5 min
Regulation
24months after which a past incident should not be used

The score they refuse your credit with can be requested, and it has to be explained

On 19 August the CNIL translated for the public its May 2026 recommendation on assessing creditworthiness. Inside are three numbers and one principle that concern anyone doing scoring: twenty-four months for past incidents, six months for the data of a refused application, and a right of access to the score that cannot be dismissed by invoking trade secrecy.

Aug 19, 2026New 6 min
Regulation
2EDPB criteria and the DPIA becomes mandatory

In schools, advertising trackers are prohibited — and consent has nothing to do with it

On 24 August the CNIL published its rules for the digital workspaces used in schools. The decisive point is not the protection of minors but a principle of administrative law: the neutrality of the public education service includes commercial neutrality, so trackers used for advertising or profiling are prohibited in principle. If the tool has them, the controller must switch them off.

Aug 24, 2026New 6 min