Noticias privacidad y RGPD

Actualizaciones curadas: decisiones de la autoridad italiana, decisiones EDPB, sanciones y novedades normativas.

Sanción
26reclamaciones, y ninguna multa

Declaras contrato y luego rechazas las oposiciones: Noruega enseña cómo los dos errores viajan juntos

SATS pedía a los socios una foto conservada en el sistema de gestión y usada en recepción para comprobar la identidad de quien entra. Datatilsynet constató que la información indicaba una base jurídica incorrecta, no explicaba el derecho de oposición, y que las oposiciones se rechazaban sin acreditar motivos legítimos imperiosos. El plazo para subsanarlo es el 11 de septiembre de 2026.

26 ago 2026Nuevo 6 min
Normativa
26el artículo que nadie firma antes de emitir

¿Quién responde de la retransmisión del partido de los sub-14? Suecia responde a la pregunta que nadie se hace

El 25 de agosto la autoridad sueca publicó una guía sobre la retransmisión del deporte juvenil. Muchos clubes emiten en línea los partidos de los chavales, y la guía señala los factores que deciden qué está permitido. Pero la parte que merece la pena leer es la otra: la responsabilidad cuando el ayuntamiento es dueño de la instalación y el club quiere instalar las cámaras.

25 ago 2026Nuevo 5 min
Normativa
24meses tras los cuales un incidente ya no se usa

La puntuación con la que te niegan el crédito se puede pedir, y hay que explicarla

El 19 de agosto la CNIL tradujo para el público su recomendación de mayo de 2026 sobre la evaluación de la solvencia. Dentro hay tres cifras y un principio que afectan a cualquiera que haga scoring: veinticuatro meses para los incidentes pasados, seis meses para los datos de una solicitud rechazada, y un derecho de acceso a la puntuación que no se despacha invocando el secreto comercial.

19 ago 2026Nuevo 6 min
Tech & IA
0contraseñas robadas, y ese es el problema

Robados los datos fiscales franceses, y ninguna contraseña: eso es lo que hace peligroso el caso

El 14 de agosto el ministerio de Economía francés comunicó que el sistema de información de la administración tributaria había sufrido una brecha: un tercero pudo consultar y extraer datos de particulares y empresas. Los identificadores y las contraseñas no parecen afectados, y precisamente por eso el riesgo no es el acceso a las cuentas sino el phishing construido con datos fiscales reales.

18 ago 2026Nuevo 5 min
Normativa
2criterios del CEPD y la EIPD pasa a ser obligatoria

En los colegios los rastreadores publicitarios están prohibidos, y no es cuestión de consentimiento

El 24 de agosto la CNIL publicó las reglas para los espacios digitales de trabajo usados en los centros escolares. Lo decisivo no es la protección de los menores sino un principio de derecho administrativo: la neutralidad del servicio público educativo incluye la neutralidad comercial, de modo que los rastreadores con fines publicitarios o de elaboración de perfiles están en principio prohibidos. Si la herramienta los tiene, el responsable debe desactivarlos.

24 ago 2026Nuevo 6 min
Normativa
2documentos sobre la misma materia, con una regla distinta

Misma herramienta, mismo día, regla distinta: por qué en la universidad los rastreadores no están prohibidos

El 24 de agosto la CNIL publicó dos textos sobre la misma materia, uno para los colegios y otro para la universidad. Quien lee solo el primero y lo aplica al segundo se equivoca en un punto concreto: en los colegios los rastreadores publicitarios están «en principio prohibidos», mientras que en la enseñanza superior la CNIL «recomienda privilegiar» herramientas que no los usen. Lo demás —base jurídica, EIPD, garantías del encargado, transferencias— coincide.

24 ago 2026Nuevo 5 min
Sanción
825 mln €la segunda sanción más alta de siempre

Ochocientos veinticinco millones por un algoritmo que desactivaba cuentas sin que nadie mirara

Es la segunda sanción más alta jamás impuesta bajo el RGPD, solo por detrás de los 1.200 millones de Meta. No trata de una transferencia de datos ni de una brecha: trata del art. 22, la norma sobre decisiones automatizadas que casi nadie documenta porque parece cosa de grandes plataformas. Afecta en realidad a cualquiera que deje decidir a un software algo que pesa en la vida de una persona.

24 ago 2026Nuevo 5 min
Sanción
64 mln złfrente a 14 el año anterior

Polonia cuadruplicó sus sanciones en un año, y las tres más altas de siempre son de 2025

Durante años Polonia se consideró un mercado de bajo riesgo sancionador. Ese supuesto ya no se sostiene: en doce meses el importe pasó de catorce a más de sesenta y cuatro millones de eslotis, y las tres sanciones más altas de la historia del país llevan el mismo año. Si llevas un cliente con filial, proveedor o centro de servicios en Polonia, el cálculo del riesgo ha cambiado.

24 ago 2026Nuevo 4 min
Normativa
77áreas documentales

Setenta y siete casillas: lo que un DPD archiva de verdad, y por qué treinta y una no bastaban

Hicimos una pregunta sencilla a quien usa la plataforma: cuando llega un requerimiento de la autoridad, ¿qué papeles sacas? La respuesta contenía cuarenta y seis categorías sin casilla propia, que acababan todas en «Otros documentos». Las hemos añadido. Después hubo que rehacer la página, porque setenta y siete recuadros grises en cuadrícula son peores que treinta y uno.

24 ago 2026Nuevo 6 min
Plataforma
29destinos a los que se llega escribiendo una palabra

El riesgo se valora dentro del registro, y cada función está a una palabra de distancia

Una DPD probó la plataforma unos días y escribió que faltaban el registro de brechas, la valoración del riesgo, la carga de documentos y los precios. Tres de las cuatro ya estaban. No las encontró porque están dentro de la ficha del cliente, y el menú no las muestra. De ahí dos añadidos: la valoración del riesgo, que sí faltaba en el registro, y una barra de búsqueda que responde a «brecha», «72 horas» o «art. 33» diciendo también dónde está lo que busca.

23 ago 2026Nuevo 5 min
Plataforma
35medidas del art. 32 en el catálogo

Las medidas de seguridad ya no se reescriben a mano

El comentario llegó de una DPD durante la prueba gratuita: «en las medidas de seguridad solo puedo escribir». Tenía razón. Ahora las medidas se eligen de un catálogo en nueve grupos, siguen siendo ampliables a mano, y el programa propone las pertinentes mirando las categorías de datos y las transferencias. Cambian también las categorías de datos, con un segundo nivel descriptivo, y el país de destino, que deja de ser un campo libre.

22 ago 2026Nuevo 4 min
Plataforma
501reglas legales, nueve ordenamientos

Cuánto tiempo se conservan los datos: 501 reglas, nueve ordenamientos y un método

La limitación del plazo de conservación es el principio que peor se demuestra en una inspección, porque la respuesta cambia para cada categoría de dato y cada país. La plataforma incorpora 501 reglas ya escritas. Pero lo relevante no es el número: de 232 reglas portuguesas solo 99 tienen una duración expresable con una cifra, y 95 se declaran «referencia corriente» en vez de «verificada». Decirlo es más útil que ocultarlo.

22 ago 2026Nuevo 5 min
Sanción
80solicitudes de acceso denegadas

El cliente quiebra, el proveedor se queda solo con los datos: y pasa a ser responsable

Una cadena de tiendas quiebra. Los antiguos empleados necesitan sus propios partes horarios para documentar los salarios impagados, pero el único que los tiene es el proveedor del software de control horario, que contesta que no puede comunicar nada a nadie —«ni siquiera a los propios interesados»— porque el contrato con el responsable ha terminado. La autoridad noruega decidió lo contrario: cuando eres el único que decide sobre los datos, el responsable eres tú.

21 ago 2026Nuevo 4 min
Jurisprudencia
200 €por la pérdida de control

Datos reales de los empleados en el software de pruebas: cuánto vale la pérdida de control

Probar un nuevo sistema de gestión de personal con datos reales no está prohibido: lo está transferir más campos de los que la prueba necesita. El Tribunal Federal de Trabajo alemán condenó a un empleador a doscientos euros por haber cargado salario, domicilio particular, número fiscal y estado civil pese a haber acordado con el comité de empresa una lista de nueve campos. Y confirmó que el retraso en responder a una solicitud de acceso no es, por sí mismo, un daño.

21 ago 2026Nuevo 5 min
Normativa
2 dic 2027il nuovo termine per l'alto rischio

El 2 de agosto no ha desaparecido: se ha estrechado

Quien solo ha leído el titular —«el Reglamento de IA se retrasa»— está trabajando con una información equivocada. La fecha del 2 de agosto de 2026 no ha desaparecido: ha cambiado de contenido. Lo que se ha quedado afecta a muchos más clientes que lo que se ha movido.

19 ago 2026Nuevo 5 min
Tech & IA
4i momenti in cui si decide

La autoridad neerlandesa publica una autoevaluación para la IA generativa

Hacía falta algo que poner en manos del cliente que dice «hemos activado la IA en el programa de gestión». La autoridad neerlandesa ha publicado una autoevaluación sobre sistemas de IA generativa: cuatro momentos, y en cada uno una decisión que hay que documentar.

18 ago 2026Nuevo 4 min
Normativa
133.000le PMI raggiunte dalla catena

La NIS2 es ley en los Países Bajos, y sin periodo de gracia

La Cyberbeveiligingswet entró en vigor el 15 de agosto de 2026. La cifra que cuenta no es ocho mil: es ciento treinta y tres mil, las pymes neerlandesas a las que la ley alcanza no por estar en el ámbito, sino por suministrar a quien sí lo está.

15 ago 2026Nuevo 5 min
Tech & IA
1 su 4le violazioni con IA

Las notificaciones de brechas ya superan todo 2025

Los datos del primer semestre de 2026 dicen dos cosas distintas. La primera es que el número de personas avisadas lo dominan poquísimos incidentes enormes. La segunda, más incómoda para quien evalúa el riesgo, es que la IA aparece en una brecha de cada cuatro.

14 ago 2026Nuevo 4 min
Normativa
3le vie per chiudere il conflitto

El DPD que decide no puede controlarse a sí mismo

El 10 de agosto de 2026 la autoridad francesa puso por escrito cómo se identifica y se resuelve un conflicto de intereses del DPD. El criterio es uno solo: si en sus otras funciones el DPD determina los fines y medios de un tratamiento, no puede después supervisarlo. Nadie puede ser juez y parte.

10 ago 2026Nuevo 5 min
Jurisprudencia
7i criteri di bilanciamento CEDU

No se borra el artículo, se borra el nombre

El 5 de agosto de 2026 la autoridad francesa aclaró los límites de un derecho que se ejerce a menudo y se entiende mal. Frente a un medio siguen siendo aplicables la oposición y la supresión, no el acceso ni la rectificación. Y la negativa debe motivarse en concreto: seis fórmulas genéricas se señalan como inadmisibles.

05 ago 2026Nuevo 4 min
EDPB / SEPD
12-14gli articoli sotto esame

En 2026 todas las autoridades europeas miran lo mismo: las cláusulas informativas

Cada año el CEPD elige un tema y todas las autoridades nacionales lo verifican juntas, en el mismo periodo, mediante cuestionarios e inspecciones. Para 2026 el tema es la transparencia: cómo los responsables informan a las personas de lo que ocurre con sus datos. En el punto de mira están el art. 13, cuando los datos proceden del interesado, y el art. 14, cuando proceden de otra fuente. La autoridad checa ya lo ha incluido en su plan de inspecciones.

10 ago 2026Nuevo 6 min
Normativa

La CNPD portuguesa escribe dónde mirará hasta 2029

El 24 de julio de 2026 la autoridad portuguesa aprobó su plan plurianual 2027-2029 y el plan de actividades para 2027. Es el tipo de documento que casi nadie lee y que dice, con años de antelación, dónde se concentrará la supervisión: formación digital, vulnerabilidad digital, capacidad reguladora sobre el DSA, competencias en IA y neurodatos.

24 jul 2026Nuevo 4 min
Sanción
4,3milioni EUR

Portugal: la mayor sanción de su historia enseña una sola cosa. Verificar al encargado es un deber sustantivo, no un formulario

Mediante la Deliberación 2022/1072 la CNPD portuguesa impuso al INE una sanción única de 4,3 millones de euros por cinco infracciones cometidas durante el censo de 2021. La más instructiva no es la de los datos de salud y religión: es que el INE, pese a existir una oficina de la empresa en Lisboa, contrató con la sociedad con sede en EE. UU., aceptando el foro de California y el tránsito de los datos por doscientos servidores, con cláusulas contractuales tipo y ninguna medida complementaria.

12 dic 2022Nuevo 7 min
Jurisprudencia
3condizioni cumulative del test

El interés legítimo no es la base jurídica de reserva

En el asunto C-621/22 el Tribunal de Justicia estableció que un interés comercial puede constituir un interés legítimo conforme al art. 6.1.f). Muchos leyeron solo esa línea. El resto de la sentencia recuerda que las condiciones siguen siendo tres y acumulativas, y que la tercera - la ponderación con las expectativas razonables del interesado - es donde el caso concreto se perdió. Para el DPD la consecuencia es práctica: el interés legítimo existe solo si está escrito en algún sitio.

12 ago 2026Nuevo 6 min
Jurisprudencia
3elementi da provare, cumulativi

La indemnización por infracción del RGPD: qué debe probar quien reclama

Las multas de las autoridades salen en la prensa; las demandas civiles pagan a los abogados. Desde 2023 el Tribunal de Justicia ha aclarado que la indemnización del art. 82 exige tres elementos acumulativos - infracción, daño y nexo causal - sin ningún umbral de gravedad. Y ha establecido que el temor fundado a que los datos hayan caído en malas manos ya es daño inmaterial. Para el responsable cambia el terreno de juego: ya no la gravedad, sino la prueba de las medidas adoptadas.

11 ago 2026Nuevo 7 min
EDPB / SEPD
28 agotermine per candidarsi

Competencia y protección de datos: el EDPB abre la mesa, y hay un plazo

Tras el DSA y antes del DMA y del Reglamento de IA, la cuarta pieza del mosaico normativo europeo aborda la relación entre competencia y protección de datos. No es un tema teórico: afecta a los datos como activo de mercado, a las concentraciones y a la posición de quien trata datos porque domina un mercado. El EDPB y la Comisión piden aportaciones antes de escribir, y esta vez el plazo está cerca.

30 jul 2026Nuevo 6 min
EDPB / SEPD
10 lug 2027quando si potra' condividere

Blanqueo de capitales y privacidad: el EDPB y AMLA escriben juntos las reglas para compartir

El 1 de julio de 2026 el EDPB y la Autoridad europea antiblanqueo anunciaron directrices conjuntas sobre un punto que ninguno de los dos podía resolver solo: cómo pueden bancos, profesionales y autoridades intercambiar información sobre sospechas sin construir listas de sospechosos fuera de control. La facultad se aplica desde el 10 de julio de 2027 y la consulta pública se espera en la primera mitad de ese año. Quien asesora a sujetos obligados tiene un año para prepararse.

01 jul 2026Nuevo 6 min
EDPB / SEPD
16-17luglio 2026

CEPD desde Dublín: hace falta una base jurídica para que las autoridades compartan información entre sectores distintos

El número y la complejidad de las reclamaciones aumentan, en parte por el mayor uso de la IA, y las autoridades dicen abiertamente que los recursos no bastan. Las soluciones sobre la mesa: operaciones conjuntas, puesta en común de recursos entre autoridades y el futuro Reglamento de procedimiento.

17 jul 2026Nuevo 6 min
EDPB / SEPD
65art. GDPR

CEPD, decisión vinculante 1/2026: una reclamación sobre cookies no se archiva alegando que el interesado abusa de sus derechos

La autoridad principal quería cerrar el caso alegando abuso de los arts. 77 y 80.1. La autoridad austriaca se opuso y el CEPD le dio la razón: no se demostró ni el componente objetivo ni el subjetivo del abuso. La reclamación vuelve atrás y debe resolverse sobre el fondo.

14 jul 2026Nuevo 7 min
Normativa
3condizioni

Control de la plantilla: la CNIL recuerda que las condiciones son tres y hay que cumplirlas todas. La proporcionalidad es solo la primera

El 9 de julio de 2026 la CNIL actualizó su página sobre el control de la actividad del personal. El contenido parece un repaso, pero hay un punto que la práctica infravalora constantemente: las condiciones son tres, son acumulativas, y dos de las tres no tienen nada que ver con lo invasiva que sea la herramienta.

09 jul 2026Nuevo 6 min
Normativa
71%lo vuole

El 71 % de los DPD quiere el Reglamento de IA en su ámbito. El 27 % dice conocerlo. El 85 % nunca ha hecho un curso de IA

El 3 de julio de 2026 el ministerio de Trabajo francés, la AFCDP y la CNIL publicaron la quinta edición del Observatorio de la profesión de DPD, realizada por la Afpa. La lectura fácil es que los DPD se están convirtiendo en los referentes de la IA. La lectura útil es otra: entre quienes quieren el Reglamento de IA en su ámbito y quienes dicen conocerlo hay una brecha de 44 puntos, y el Reglamento de IA no menciona nunca al DPD.

03 jul 2026Nuevo 6 min
Jurisprudencia
13milioni EUR

Austria: el Tribunal Supremo Administrativo rebaja la multa de 18 a 13 millones. Pero la parte que hay que leer es donde dice que un programa de cumplimiento no excusa nada

El 24 de junio de 2026 el Verwaltungsgerichtshof austriaco cerró un procedimiento pendiente desde 2019 y redujo a 13 millones de euros la sanción por el tratamiento de 'afinidades de partido' calculadas para unos 2,2 millones de personas. Los titulares hablarán del descuento. Para un DPD importa el resto: el Tribunal afirma que para sancionar a una persona jurídica no se requiere ningún acto de sus órganos de dirección, que disponer de recursos para asesorarse eleva el umbral en lugar de rebajarlo, y que las imputaciones sobre la EIPD y el registro de actividades caen por absorción, no porque esos documentos fueran correctos.

24 jun 2026Nuevo 7 min
Sanción
2.126.075persone

Suecia: 6 millones de coronas por una inyección SQL. Lo más duro no es la multa, es que el riesgo estaba en su propio registro desde 2021

El 26 de enero de 2026 la autoridad sueca sancionó a Sportadmin i Skandinavien AB con 6.000.000 de coronas por infringir el artículo 32.1. La plataforma gestiona socios, facturación y sitios web de clubes deportivos: el ataque del 16 de enero de 2025 expuso los datos de 2.126.075 personas, en su mayoría menores, incluidas alergias y discapacidades. Pero el pasaje que conviene leer dos veces es otro: desde 2021 la empresa había identificado el riesgo de inyección SQL en sus propias revisiones anuales, y la IMY lo cita precisamente para fundamentar la negligencia grave.

26 ene 2026Nuevo 8 min
Normativa
5priorita' 2026

Netherlands: who supervises the AI Act, and where they will start. Prohibited practices and AI literacy, not high-risk systems

The Dutch government has designated the Autoriteit Persoonsgegevens and the Rijksinspectie Digitale Infrastructuur as coordinating national supervisors for the AI Act. The 2026 work agenda lists five priorities: overarching system supervision, transparency and explainability, frameworks and standards, testing for bias and fairness against discrimination, and AI literacy. The first formal enforcement actions are expected during 2026, starting with organisations using prohibited practices or demonstrably neglecting the AI literacy obligation.

01 ago 2026 5 min
Sanción
23sanzioni in 6 mesi

France: 23 fines in six months under the simplified procedure. Small amounts, new target

In the review published on 6 July 2026 the CNIL counts 23 new fines adopted since January under its simplified procedure, totalling EUR 133,750. Three infringements recur: excessive video surveillance, non-compliant cookie banners, and failure to respond to access and erasure requests. One example of the kind of target: EUR 7,500 against a company operating public toilet facilities, on 2 April.

06 jul 2026 5 min
Sanción
5milioni EUR

France: EUR 5 million for IQVIA. The pharmacy software kept sending the data even when the patient had said no

On 26 May 2026 the CNIL's restricted committee fined IQVIA Operations France EUR 5 million. The company runs two health data warehouses for third-party studies: LRX, authorised in 2018 and fed by around 14,000 pharmacies, and EMR, authorised in 2021 and fed by several thousand doctors. Among the findings, the most instructive: the practice management software used in pharmacies transmitted customer data to IQVIA even where the customer had objected.

26 may 2026 7 min
Jurisprudencia
792.639EUR confermati

Finland: the Supreme Administrative Court upholds the fine on Verkkokauppa.com. The failing: never having defined how long to keep the data

On 12 June 2026 the Korkein hallinto-oikeus, Finland's Supreme Administrative Court, dismissed Verkkokauppa.com's appeal against the penalty imposed by the Finnish Data Protection Ombudsman's sanctions board (decision KHO 12.6.2026/1604). The original amount was EUR 856,000, reduced by the Administrative Court to EUR 792,639 on the basis of the company's most recent turnover. The finding does not concern a data breach: it concerns the fact that the company had never defined retention periods for customer account data.

12 jun 2026 6 min
Sanción
749firmatari esposti

Poland: a municipality fined not for publishing the data of 749 petition signatories, but for never reporting it

On 25 May 2026 the President of the UODO fined the mayor of Myslenice PLN 7,700. An un-anonymised petition had been published in the municipality's Public Information Bulletin: names, surnames, home addresses and signature specimens of 749 people. The core of the decision is not the publication, which the municipality corrected by replacing the file: it is that the breach was never notified to the authority, not even after the authority asked.

25 may 2026 6 min
Jurisprudencia
600.000EUR annullati

Netherlands: the Council of State confirms the annulment of the EUR 600,000 fine for Enschede's wifi tracking

On 29 July 2026 the Administrative Jurisdiction Division of the Raad van State dismissed the appeal of the Autoriteit Persoonsgegevens against the municipality of Enschede, upholding the February 2024 judgment of the Overijssel District Court. The EUR 600,000 fine, imposed in March 2021 for counting city-centre visitors through sensors capturing the MAC addresses of wifi-enabled devices, remains annulled. The reason is not that the tracking was lawful: it is that the authority did not sufficiently demonstrate that the MAC addresses collected qualified as personal data and that processing of personal data had therefore taken place.

29 jul 2026 6 min
Sanción
10.145PLN al responsabile

Poland: WhatsApp in the sales network brings a fine for the processor, and a reprimand for the controller that never vetted it

On 22 June 2026 the President of the UODO, Miroslaw Wroblewski, closed the proceedings opened after a breach notification by Energa-Obrot: reprimands for the controller and the processors, and an administrative fine of PLN 10,145 for one of the processors. At the root of it, the use of WhatsApp by sales representatives of a door-to-door network during the pandemic: on a former agent's private phone there were scans and photographs of customer contracts, in group conversations, for many months.

22 jun 2026 7 min
Sanción
277.500EUR

Ireland: EUR 277,500 for Permanent TSB over a contact centre that could be fooled, and for reporting late

On 8 May 2026 the Irish Data Protection Commission closed its inquiry into a series of personal data breaches at Permanent TSB, first notified in May 2022. Malicious actors, holding certain customer information, called the Open24 contact centre posing as customers, gained access to accounts and amended account details. Some customers lost money. The authority issued a reprimand and fines totalling EUR 277,500.

08 may 2026 6 min
Normativa
3priorita'

La autoridad neerlandesa fija sus prioridades para 2026-2028: vigilancia masiva, inteligencia artificial y resiliencia digital

La Autoriteit Persoonsgegevens ha establecido tres prioridades estratégicas para 2026-2028: vigilancia masiva, inteligencia artificial y resiliencia digital. En su plan anual de 2026 la autoridad declara que destina más capacidad a la IA y a los algoritmos y que se centrará en sistemas a gran escala con impacto social relevante, sin distinguir entre sector público y privado.

01 ago 2026 6 min
Normativa
2autorita'

Netherlands and Poland: two authorities that raised the bar in 2026

The Dutch Autoriteit Persoonsgegevens has increased its budget and headcount and has named transparency, tracking and cookies among its 2026 supervisory priorities, with an approach that is openly less advisory and more enforcement-driven. In Poland the President of the UODO has shifted attention towards small and medium enterprises, a segment until recently little touched by inspections. For anyone with clients in those countries, or considering it, these are two signals that change the cost-benefit balance of compliance.

30 jul 2026 4 min
Sanción
460keuro

Piaggio sancionada con 460.000 euros: 112 correos corporativos leídos y copias de seguridad conservadas cinco años tras el despido

La autoridad italiana de protección de datos ha impuesto a Piaggio & C. Spa una sanción de 460.000 euros por la gestión de las cuentas de correo corporativo. La investigación, iniciada tras las reclamaciones de dos exempleados, acreditó la obtención de 112 correos durante la relación laboral, algunos de aproximadamente dos años antes de que surgiera la sospecha, posible gracias a copias de seguridad conservadas durante toda la relación laboral y hasta cinco años después de su finalización. Además de la sanción, la autoridad prohibió a la empresa acceder a los datos recogidos.

29 jul 2026 7 min
Normativa
5settori

AI Act en Italia: la autoridad de protección de datos será vigilancia de mercado para los sistemas de alto riesgo en justicia, fronteras y procesos democráticos

La autoridad italiana de protección de datos ha emitido informe favorable sobre el proyecto de decreto legislativo que desarrolla el AI Act en Italia. El decreto define la gobernanza nacional y designa a la autoridad como vigilancia de mercado para los sistemas de inteligencia artificial de alto riesgo empleados en los ámbitos más sensibles para los derechos fundamentales: justicia, actividades policiales, inmigración, gestión de fronteras y procesos democráticos. Entre las condiciones planteadas, una interesa a cualquier organización: extender la prohibición de decisiones basadas únicamente en sistemas automatizados a las evaluaciones que inciden en la relación laboral.

29 jul 2026 6 min
Autoridad italiana
12keuro

Registro documental mal configurado: 12.000 euros a la Ciudad Metropolitana de Sassari

Tras una notificación de brecha de seguridad y una reclamación, la autoridad italiana de protección de datos sancionó a la Ciudad Metropolitana de Sassari por haber configurado erróneamente su registro documental electrónico, dejando accesibles documentos con datos personales a personas que, por su puesto y funciones, no estaban autorizadas a tratarlos. La sanción es de 12.000 euros, pero el principio vale para cualquier organismo y cualquier empresa con un sistema de gestión documental: registrar documentos no es una actividad neutra, y un valor predeterminado de visibilidad total infringe los principios de integridad y confidencialidad.

29 jul 2026 6 min
Normativa
2 agoma non tutto

AI Act, 2 August: what actually applies and what has been postponed to 2027

For two years 2 August 2026 was presented as the day obligations for high-risk AI systems would start. The Digital Omnibus package changed that calendar: requirements for Annex III high-risk systems move to 2 December 2027 for stand-alone systems and 2 August 2028 for those embedded in products already covered by sectoral legislation. 2 August nonetheless remains an operative date: the transparency obligations of Article 50 become applicable, together with the full operation of governance and penalties, with national authorities acquiring full powers.

29 jul 2026 5 min
Normativa
0multe dirette

Denmark: cookies are the 2026 priority, and fines are decided by a court

The Danish authority has flagged cookie consent as a supervisory priority for 2026, coordinating with the Digitaliseringsstyrelsen, which oversees the ePrivacy implementation while Datatilsynet applies the GDPR. But Denmark has a peculiarity that changes how every one of its decisions should be read: its constitutional order does not allow an administrative authority to impose punitive financial penalties. Recital 151 GDPR expressly anticipates this for Denmark and Estonia: the fine is decided by a court as a criminal penalty, following a report by the authority to the police.

28 jul 2026 4 min
Normativa
14 luggia' scaduta

Email tracking pixels: France has already closed its grace period, Italy's runs to October

With deliberation no. 2026-042 of 12 March 2026, made public on 14 April, the French CNIL adopted its final recommendation on email tracking pixels: for most marketing uses, prior consent is required, just as for cookies. Existing contact bases were given three months to inform recipients and allow them to object, a period that ended on 14 July 2026, with checks announced from that date. In Italy the authority reached the same conclusion with decision no. 284 of 17 April 2026, but with a longer compliance window.

26 jul 2026 4 min
Sanción
365milaclienti

Wind Tre, EUR 1.7 million: the breach started with a phone call

The Italian DPA fined Wind Tre EUR 1,715,600 (decision no. 348 of 14 May 2026, made public with the 16 July newsletter). The starting point was not a sophisticated cyberattack: people posing as support technicians convinced staff at two retail outlets to allow access to company systems. From there, identification and contact data of 365,048 customers were exfiltrated; for 41,359 of them, payment method information as well, including IBANs, postal payment slips and credit cards with partially masked numbers and expiry dates. The charges: breach of the integrity and confidentiality principle (Art. 5(1)(f)) and of security obligations (Art. 32(1)(b)).

26 jul 2026 4 min
Sanción
1,5MEUR

Cookies, France holds the line: EUR 1.5 million to American Express and the topic stays a 2026 priority

In January 2026 the CNIL fined American Express EUR 1.5 million for cookie violations, confirming that the topic remains a standalone enforcement priority alongside artificial intelligence and cybersecurity. In 2025 there had been 21 cookie decisions, totalling over EUR 475 million. The recurring charges are always the same: trackers set before consent, a reject button less visible or further away than the accept button, inadequate information.

25 jul 2026 3 min
Normativa
art. 15GDPR

Call centre recordings: the customer has a right to access them, and a transcript is enough

A customer had asked to access their own data contained in a recorded call with customer service. The company refused, considering the protection of the agent's confidentiality to prevail. The authority held that the request could be satisfied by providing the transcript, provided the elements identifying other people involved are redacted: given the professional context of the call and its subject, a supply contract, redaction would not have prejudiced the agent's confidentiality.

25 jul 2026 3 min
Normativa
3linee guida

EDPB adopts guidelines on anonymisation, web scraping for generative AI, and blockchain

At its July 2026 plenary, the European Data Protection Board adopted guidelines on anonymisation and on web scraping in the context of generative artificial intelligence, together with the final version of the guidelines on processing personal data through blockchain technologies. Three documents addressing three recurring questions: when data is truly anonymous, on what conditions data may be collected from the web to train models, and how the immutability of a chain can be reconciled with data subjects' rights.

24 jul 2026 3 min
Sanción
18MEUR

Spain: EUR 18 million to Amadeus for reusing booking data for product development

The Spanish authority fined Amadeus IT Group EUR 18 million (reduced to 14.4 with voluntary payment) for aggregating travellers' booking data into profiles for product development. The cross-border investigation found the reuse of data collected years earlier from airlines and agencies, for purposes data subjects could not reasonably expect, without an Article 14 notice and without a valid legitimate-interest balancing test.

23 jul 2026 4 min
Sanción
6Miscritti

Norway: loyalty programme under scrutiny, more than six million members involved

The Norwegian authority concluded proceedings opened after an audit of the Nordic entities of a retail group, finding several breaches relating to its loyalty programme: invalid consent, new processing purposes introduced without assessment, insufficient legitimate-interest balancing, and failure to answer data subject requests within the deadline. More than six million members across the Nordic region were affected.

22 jul 2026 3 min
Sanción
3provvedimenti

Credit scoring in utilities: the Italian DPA hits the whole chain with three decisions in one day

With three decisions adopted in the same session on 3 July 2026, the Italian DPA targeted the credit-scoring chain applied to energy supply contracts: Experian Italia, Hera Comm and Cerved. The charges are similar and paint a clear picture: deficient notices, breaches of minimisation and storage limitation, privacy by design and by default disregarded, inadequate responses to access requests and poorly governed Article 28 relationships along the chain.

21 jul 2026 4 min
Normativa
art. 21d.lgs. 24/23

Whistleblowing: without consulting the unions, the procedure is not compliant

A preliminary requirement that almost everyone overlooks is back in the spotlight: Article 4 of Legislative Decree 24/2023 requires internal reporting channels to be activated after hearing worker representatives or trade unions. The ANAC guidelines clarify that failing to do so makes the procedure non-compliant and may trigger a sanction under Article 21. It also applies to substantial updates, not just first activation.

20 jul 2026 3 min
Sanción
1,7MEUR

Data breach: Italian DPA fines Wind Tre EUR 1.7 million after exfiltration of 365,000 customers' data

In its 16 July 2026 newsletter the Italian DPA announced a EUR 1.7 million fine to telecom operator Wind Tre following a data breach with exfiltration of roughly 365,000 customers' data. The case confirms the authority's line on large operators: the incident itself is not the fault - the fault lies in security measures inadequate to the risk (Art. 32) and in how the breach was handled. In the same newsletter: two debt-collection companies fined (EUR 50k and 30k) and the customer's right to access the audio of their own support calls (Enel case).

17 jul 2026 3 min
Sanción
158KEUR

Character.AI fined EUR 158,000: minors, late DPIA and missing EU representative

With a decision of 3 July 2026 (announced 9 July) the Italian DPA fined Character Technologies Inc., the US company behind Character.AI, EUR 158,000: deficient privacy notice (Arts. 12-14), a DPIA prepared late relative to the service launch, late designation of the EU representative (Art. 27) and shortcomings in minor protection and age verification. Beyond the fine, corrective measures within 120 days: working age verification, an effective cooling-off period against re-registration by blocked minors, minors' profiles private by default.

16 jul 2026 4 min
Autoridad italiana
2/2genitori

Children's photos on social media: both parents must consent

In its 17 June 2026 newsletter the Italian DPA restated a principle that matters well beyond family disputes: publishing photos of minor children on social media requires the consent of BOTH parents. In case of disagreement, the child's protection prevails. For the DPO it is an operational criterion affecting schools, nurseries, sports clubs, parishes and companies publishing images of minors for promotional purposes.

15 jul 2026 3 min
Autoridad italiana
STOPcopie

Italian DPA to hoteliers: do not keep copies of guests' ID documents

In a notice addressed to the hospitality sector, the Italian DPA reiterated that hoteliers may not keep copies of guests' identity documents: the legal duty (Art. 109 of the Italian public-security code) is to identify the guest and transmit the data to the police via the Alloggiati Web portal - after that, document copies must be destroyed or deleted. A widespread habit becomes a concrete sanction risk.

14 jul 2026 3 min
Normativa
EDPBconsultazione

Data breach: EDPB puts a new EU-wide notification template up for consultation

The EDPB has opened a public consultation on a new harmonised data-breach notification template, designed to align the information requested by authorities across Member States. For DPOs it is operational news: the content of the Art. 33 notification is becoming standardised, and anyone with a structured internal procedure (facts, categories, risk assessment, measures) will find the work already done.

13 jul 2026 3 min
Sanción
563KEUR

Enel Energia fined EUR 563,000: the 'administrative' call that turns into a sales pitch

With decision no. 170/2026 the Italian DPA fined Enel Energia EUR 563,052: during purely administrative contacts (supply paperwork, takeover confirmations), including via third parties, commercial offers were made without a valid legal basis - even to customers on the opt-out register or who had expressly refused marketing consent. Also challenged: a re-contact mechanism based on opt-out (an SMS with 90 seconds to refuse) and partner vetting - one agency was contracted two months after being sanctioned by the DPA for marketing.

09 jul 2026 4 min
Sanción
55KEUR

Italy's DPA fines AgID: EUR 55,000 to the Agency for Digital Italy over transparency and privacy by design

With injunction order no. 419 of 28 May 2026 the Italian DPA declared unlawful certain personal data processing carried out by AgID - the Agency for Digital Italy, with a EUR 55,000 fine and publication of the decision on the authority's website. The breaches concern lawfulness, fairness and purpose limitation (Art. 5), information duties towards data subjects (Arts. 12 and 14) and data protection by design (Art. 25).

08 jul 2026 3 min
Art. 5
AI Act
Sanción

Italy's DPA halts stress and emotion monitoring at work: not even in aggregate form

With decision no. 342 of 2026, the Italian DPA reaffirmed that data on employees' health or psychological journey cannot be made accessible to the employer, not even in aggregate form. The case closes the loop with the AI Act, which expressly prohibits AI systems that infer people's emotions in the workplace (Art. 5): organisational wellbeing cannot turn into emotional surveillance.

06 jul 2026 4 min
8
mesi
Sanción

Trenitalia tells customers about a data breach eight months after the attack: an Art. 34 lesson

In July 2026 Trenitalia informed its customers of a data breach suffered roughly eight months earlier. Beyond the outcome, the case is a textbook lesson on the difference between notifying the authority within 72 hours (Art. 33) and communicating to data subjects 'without undue delay' when the risk to their rights is high (Art. 34): eight months are hard to justify, and in the meantime the persons affected could not protect themselves.

04 jul 2026 3 min
Autoridad italiana
37,7MEUR

Italian DPA annual report: collected fines +54.5%, almost 7 data breaches notified per day, AI at the centre

On 2 July 2026 the Italian DPA presented its 2025 activity report to Parliament: 807 collegial decisions, 506 corrective and sanctioning measures, over EUR 37.7 million in fines collected (+54.5% on 2024), 2,415 data breaches notified (+10%), 130 inspections. AI takes centre stage: from DeepSeek to deepfakes, from facial recognition at the airport to worker surveillance.

02 jul 2026 4 min
1,5M
cittadini
Sanción

SPID under scrutiny: Lepida fined, data of 1.5 million citizens viewable 'out of mere curiosity'

With a decision of 29 April 2026, the Italian DPA fined Lepida (EUR 100,000), one of Italy's main SPID identity providers: over 7,000 counter operators could view data and download copies of ID documents and health cards of more than 1.5 million citizens, even with no operational need. The DPA found accesses 'out of mere curiosity' and documents left stored on operators' workstations after identification.

01 jul 2026 4 min
AI Act
update
Normativa

Digital Omnibus: EU Council approves changes to the AI Act. What it means if you are preparing

On 29 June 2026 the EU Council approved the proposed regulation that streamlines and simplifies certain AI rules, amending the AI Act (the 'Digital Omnibus' package). Negotiations with Parliament continue: until final adoption, the current AI Act text remains the reference, including the August 2026 transparency deadlines.

29 jun 2026 3 min
Sanción
180kEUR

Italy's DPA fines Emirates EUR 180,000: passenger health data kept for 7 years and an unclear notice

The Italian DPA fined Emirates EUR 180,000 over the handling of reduced-mobility passengers' health data. The case started from a complaint by a passenger asked to fill in a medical form despite not being in the categories required to do so. The key point for DPOs: the collection itself was lawful, but the authority faulted an inadequate notice and excessive retention (7 years).

17 jun 2026 4 min
Art. 5
GDPR
Sanción

Loyalty-card data used to fire an employee: Italy's DPA says no. A lesson on purpose limitation

With decision no. 311 of 29 April 2026, the Italian DPA found unlawful the employer's use of data collected through the loyalty card to support an employee's dismissal. That data had been collected to run the loyalty programme, not to monitor or discipline staff. The point for DPOs: having a piece of data does not mean you can use it for any purpose.

15 jun 2026 4 min
Normativa
12-14artt.

EDPB 2026: the EU coordinated action targets transparency (Art. 12-14). What to check in privacy notices

For 2026 the EDPB chose TRANSPARENCY as the topic of its coordinated enforcement action: authorities will examine how organisations inform data subjects under Art. 12-14. In short: clear, complete, verifiable notices. A good moment to review your clients' documents.

12 jun 2026 5 min
Sanción
7,1mld EUR

GDPR fines top EUR 7.1 billion: enforcement accelerates and SMEs are not exempt

Cumulative GDPR fines have passed EUR 7.1 billion across 1,400+ decisions. Enforcement is accelerating, not plateauing. And contrary to a common myth, SMEs do get fined: smaller amounts, same proportional severity.

12 jun 2026 5 min
5M
EUR
Sanción

France fines IQVIA EUR 5M: pseudonymisation does not take you out of the GDPR

In France the authority (CNIL) fined IQVIA EUR 5 million, clarifying a point many confuse: pseudonymising data - even health data - is not the same as anonymising it. Pseudonymised data remains personal data and must be handled with all the safeguards of the Regulation, including the enhanced ones in Art. 9.

10 jun 2026 3 min
Normativa
15MEUR

Rome Court annuls the Garante's EUR 15M fine against OpenAI: the one-stop-shop decides

The Rome Court annulled the EUR 15M fine the Italian Garante imposed on OpenAI in 2024. The judge does not rule on the merits (legal basis, notice, age verification): it upholds the jurisdiction argument. For cross-border processing the one-stop-shop and lead authority govern.

10 jun 2026 6 min
Normativa
6ambiti

The Garante's 2026 inspection plan: six areas and how to be ready

The Italian Garante set its 2026 inspection areas, backed by the Finance Police tech-fraud unit. Topics include data breaches in public databases and abusive access. Those who document self-assessment and lesson learning get treated differently.

10 jun 2026 5 min
Sanción
5MEUR

France: CNIL fines France Travail EUR 5 million - 36.8 million data subjects and a social-engineering attack

The CNIL fined France Travail (formerly Pole Emploi) EUR 5 million after a breach exposing the data of around 36.8 million people. Attackers used social engineering against partner advisers' accounts. The lesson: having security plans is not enough, they must actually be implemented.

09 jun 2026 6 min
Sanción
1,7MEUR

France: EUR 1.7 million to Nexpublica - health and disability data accessible to other users through long-known flaws

The CNIL fined software vendor Nexpublica EUR 1.7 million: its PCRM tool, used by social services, exposed sensitive documents (including disability data) to other users. The flaws were known from prior audits but left open. A textbook case for anyone processing health data.

09 jun 2026 6 min
Sanción
10MEUR

Spain: AEPD fines Aena EUR 10 million for biometric boarding without adequate DPIA

The Spanish Data Protection Agency fined Aena over EUR 10 million for launching its biometric boarding programme without completing an adequate DPIA. Not a data breach: a failure of preventive accountability.

25 may 2026 8 min
Sanción
290MEUR

Netherlands: the EUR 290 million Uber fine and the Dutch Authority's new priorities for 2026

The Autoriteit Persoonsgegevens confirmed the EUR 290 million fine against Uber for unlawful transfers to the US. Meanwhile the Authority sets three strategic priorities for the next two years every DPO should know.

22 may 2026 7 min
Sanción
85kEUR

Data breach: Italy's DPA fines The European House - Ambrosetti EUR 85,000 over plaintext passwords and late notification

The Italian DPA fined The European House - Ambrosetti spa EUR 85,000 following a 2024 data breach affecting 61,670 people. The attack, via a technical vulnerability, led to the exfiltration of names, emails, usernames and passwords. The point for DPOs: the breach was notified to the regulator within 72 hours, but data subjects were informed only after two months and after the authority stepped in.

21 may 2026 4 min
EDPB / SEPD
25DPA

EDPB CEF 2026: 25 European DPAs verify transparency of privacy notices

The European Data Protection Board has launched the 2026 coordinated action on transparency and information obligations. 25 national DPAs (including the Italian Garante) are already contacting controllers in various sectors. What to expect and how to prepare.

20 may 2026 9 min
Autoridad italiana
1 lug 2026deadline

Italian DPA cracks down on WhatsApp and Telegram in public administration: ban on operational communications with citizens from July 1, 2026

The Italian DPA (Garante) issued a general provision banning Italian public administrations from using WhatsApp, Telegram, Messenger and other commercial messaging apps for operational communications with citizens. Banned also for requesting documents, certificates or personal data. PAs must use institutional channels (PEC, portals, SPID-auth) by July 1, 2026. Fines up to 100,000 EUR.

19 may 2026 9 min
Tech & IA
1ain UE

Spain: AEPD publishes Europe's first guidance on agentic AI and data protection

The Spanish Data Protection Agency is the first European Authority to publish elaborate guidance on agentic AI. It explains the concept, the vulnerabilities in processing personal data and mitigation measures for controllers and processors.

18 may 2026 7 min
Sanción
45MEUR

Vodafone Germany fined EUR 45 million: the Art. 28 GDPR lesson on processor controls

The German Federal Commissioner for Data Protection (BfDI) imposed a total fine of EUR 45 million on Vodafone GmbH: 15M for Art. 28 violation (processor oversight) and 30M for Art. 32 (security). A decision that redefines accountability expectations on processors.

15 may 2026 8 min
Normativa
18settori essenziali

NIS2 and GDPR: how to orchestrate them operationally after Italian Decree 138/2024. The DPO checklist for the NIS Operator

After the NIS2 transposition with Legislative Decree 138/2024, Italian companies qualified as 'essential entities' or 'important entities' must coordinate NIS2 obligations (cyber security, 24h incident reporting) with GDPR obligations (72h data breach). The DPO is not the NIS Coordinator but must interface: risk of double sanctions if not properly orchestrated.

15 may 2026 11 min
EDPB / SEPD
12raccomandazioni

EDPB publishes guidelines on public DPO profiles: transparency, accountability and data subject rights

The EDPB clarifies how to process the professional data of DPOs exposed publicly on online directories: legal basis, purposes, data subject rights and platform responsibilities.

12 may 2026 8 min
Tech & IA
Aug 2026

AI Act August 2026: high-risk systems deadline. Mandatory DPIA for enterprise LLMs

The EU AI Act enters its critical phase: August 2026 triggers obligations for high-risk systems. The Italian Garante has already anticipated enforcement with the EUR 5M fine to Luka (Replika). What DPOs must do now.

08 may 2026 10 min
Normativa
Art. 26AI Act

AI Act and DPO: how the DPO role changes with deployer obligations entering into force in August 2026

In less than 3 months, the AI Act sections dedicated to deployers (users) of high-risk AI systems enter into force. The DPO becomes a key interlocutor for impact assessment, data subject information and monitoring.

08 may 2026 10 min
Autoridad italiana

Corporate email post-termination: Italian DPA fines ITAS Mutua

The Italian Data Protection Authority addresses the management of corporate emails after employment termination. ITAS Mutua sanctioned for undocumented access and retention beyond necessary.

07 may 2026 5 min
Jurisprudencia
530MEUR

TikTok vs Irish DPC: Supreme Court suspends 530 million euro fine

The Irish Supreme Court confirms the suspension of the record 530M EUR fine imposed by the DPC on TikTok for EEA data transfer to China. The case exposes the structural problem of enforcement timing against big tech.

30 abr 2026 6 min
Normativa
6mesi

Email tracking pixels: new Italian DPA Guidelines

On April 17, 2026, the Italian DPA adopted Guidelines on tracking pixels in emails. For DPOs: 6 months to align privacy notices, consent flows, and privacy-by-design techniques.

17 abr 2026 5 min
Sanción
31.8MEUR

Intesa Sanpaolo: 31.8M euro fine from the Italian DPA

The Italian Data Protection Authority fines Intesa Sanpaolo for a data breach affecting 2.4 million customers. Late notification and incomplete information among the key issues.

26 mar 2026 4 min
Jurisprudencia
15MEUR

Rome Court annuls 15M euro fine against OpenAI

The Rome Court annuls the fine that the Italian DPA had imposed on OpenAI for the ChatGPT case. A decision that redefines the scope of GDPR enforcement on generative AI models.

20 mar 2026 4 min
Sanción
500KEUR

Enel Energia fined over 500,000 euros: telemarketing without consent

The Italian DPA fines Enel Energia for promotional calls to subjects who had not provided consent or had registered their number in the public opposition register.

12 mar 2026 3 min
Jurisprudencia
120giorni

Italian Supreme Court 984/2026: the DPA 120-day deadline is final

With its January 17, 2026 ruling, the Italian Supreme Court confirms that the 120-day deadline for concluding the DPA's enforcement proceedings is final. A relevant decision for those handling privacy litigation.

18 feb 2026 3 min
EDPB / SEPD

EDPB: DPOs are under-resourced and disconnected from top management

EDPB publishes the results of the coordinated enforcement action: insufficient resources, lack of access to top management, conflict of interest risk. A snapshot that also concerns Italian external DPOs.

17 feb 2026 4 min
Jurisprudencia

France's Conseil d'Etat: the line between anonymization and pseudonymization narrows

France's State Council confirms CNIL's approach on pseudonymized health data. A ruling that redefines the practical scope of GDPR anonymization and impacts all data analytics projects.

13 feb 2026 5 min
EDPB / SEPD

EDPS strengthens DPO independence: new binding rules

The European Data Protection Supervisor (EDPS) adopts new binding rules to protect DPO independence within Union institutions. A signal strengthening the role.

13 feb 2026 3 min
EDPB / SEPD
96h

Digital Omnibus: EDPB and EDPS call for simplification without setbacks

EDPB and EDPS publish the joint opinion on the EU Commission's Digital Omnibus package. Positive measures on data breach and DPIA, but strong opposition to the revision of the personal data definition.

11 feb 2026 5 min
Autoridad italiana
40ispezioni

Italian DPA 2026 inspection plan: data breach, whistleblowing, AI in schools

The Italian DPA published its inspection activities plan for January-June 2026. Sectors at risk: banking data breaches, health dossiers, energy telemarketing, and AI in schools.

29 ene 2026 3 min
Sanción
42MEUR

CNIL fines Free Mobile and Free 42 million euros: 24 million customer data breach

The French Authority separately fines Free Mobile (27M) and Free (15M) for a breach that exposed 24 million subscribers in October 2024. A decision that clarifies the scope of Art. 34 GDPR.

13 ene 2026 7 min