Uw cookievoorkeuren

EDPB-richtsnoeren · art. 7 AVG

Wij gebruiken essentiële technische cookies om het platform te laten werken (inloggen, beveiliging, sessies). Daarnaast willen wij graag analytische cookies gebruiken om te begrijpen hoe wij het kunnen verbeteren.

U kunt alles accepteren, alles weigeren, of kiezen welke categorieën u aanzet.Uw toestemming is 6 maanden geldig en u kunt deze op elk moment intrekken via de voettekst.

U vindt alles in ons privacyverklaring.

Privacy- en AVG-nieuws

Geselecteerde updates: besluiten van toezichthouders, richtsnoeren van de EDPB, boetes en wijzigingen in de regelgeving. Bekeken vanuit de praktijk van de FG.

Regelgeving
2027en het bevat twee bezwaren, niet één

De Europese ruimte voor gezondheidsgegevens geldt over ruim zes maanden, en de twee bezwaren die erin staan zijn niet hetzelfde

Zij vervangt de AVG niet, zij komt erbij. Wie het register van een zorgklant bijhoudt, moet vier data noteren, niet één, en de eerste valt over minder dan zeven maanden.

03 sep 2026Nieuw 7 min
Regelgeving
57het artikel waarvan de termijn net is verstreken

Op 2 augustus verstreek de plicht om een nationale AI-testomgeving te hebben, en daarbinnen mogen gegevens worden verwerkt die voor iets anders zijn verzameld

Het is de enige plek in het Unierecht waar hergebruik van persoonsgegevens om een model te trainen uitdrukkelijk is geregeld. Er zijn zeven voorwaarden en ze moeten allemaal tegelijk vervuld zijn.

02 sep 2026Nieuw 6 min
Regelgeving
9casestudies, zes systemisch en drie uit bedrijven

Psychosociale risico's komen in de Europese campagne, en de FG heeft er meer mee te maken dan hij denkt

Mentale gezondheid op het werk wordt verplichte preventie, geen vrijwillig welzijnsbeleid. En het moment waarop een bedrijf het welzijn van zijn mensen meet, is het moment waarop het gezondheidsgegevens gaat verwerken — meestal zonder het te merken.

27 aug 2026Nieuw 6 min
Boetes
2miljoen voor het verkopen van nooit gegeven contacten

Twee miljoen voor een Amerikaanse databroker: gerechtvaardigd belang dekt het verkopen van contacten niet

Het bedrijf is Amerikaans en heeft geen vestiging in Italië; de verordening gold toch. Naast de boete: een verbod op het verwerken van gegevens van personen in Italië en een bevel om onrechtmatig verzamelde gegevens te wissen.

27 jul 2026Nieuw 6 min
Regelgeving
3verschillende autoriteiten voor één wet

AI-verordening: wie houdt toezicht op wat, en waarom de rondgaande "eerste boetes" niet bestaan

Het AI-bureau doet de modellen voor algemene doeleinden, de nationale autoriteiten al het overige, de EDPS de EU-instellingen. Weten aan wie een klant verantwoording aflegt komt vóór weten wat hij riskeert. En daarvóór komt het onderscheid tussen bevoegdheden die uitoefenbaar werden en bevoegdheden die zijn uitgeoefend.

04 aug 2026Nieuw 7 min
EDPB / EDPS
1één loket om inbreuken te melden

Eén loket om inbreuken te melden: wat de EDPB en de EDPS vroegen over het cyberbeveiligingspakket

Een inbreuk melden betekent vandaag schrijven aan meerdere autoriteiten in verschillende formats binnen dezelfde drie dagen. Het Comité en de Toezichthouder steunen het enkele loket, en stellen grenzen aan ENISA, aan certificering en aan de verhouding tussen veiligheid en grondrechten.

19 mrt 2026Nieuw 6 min
Regelgeving
7sites die liever verdwenen

Zeven sites zetten het VK uit in plaats van kinderen te beschermen

De Britse toezichthouder beschreef wat er gebeurt vóór formele onderzoeken. Voor de keuze gesteld tussen de dienst veilig maken of niet langer bereikbaar zijn vanuit het VK, kozen zeven platforms het tweede. Een overwinning, maar het laat ook zien hoe goedkoop weglopen is.

28 aug 2026Nieuw 5 min
Boetes
1,17 Mgedigitaliseerde dossiers, en niemand wist waar ze waren

Anderhalf miljoen adoptieverhalen op dragers die niemand nog kon vinden

Het ernstigste geval komt voort uit het digitaliseren van papieren archieven tussen 2013 en 2022: ruim 1,17 miljoen dossiers, waarvan 1,14 miljoen over geadopteerden en zo'n 30.000 over vermiste kinderen, op slecht beveiligde apparaten en zonder enige registratie van hun verplaatsingen. Het bestuur merkte pas bij controles in 2024 en 2026 dat de dragers zoek waren.

28 aug 2026Nieuw 5 min
Boetes
153,7miljoen real, voor een zelfopgegeven leeftijd

In Brazilië kostte het 153,7 miljoen real om naar de leeftijd te vragen en het antwoord te geloven

Besluit van 25 augustus 2026. De Braziliaanse toezichthouder constateerde tekortkomingen in de leeftijdscontrole, zowel in de feed zonder registratie als in die met account. Naast de boete: het bevel onrechtmatig verzamelde gegevens te wissen en profielen onder de 16 standaard op de strengste instelling te zetten.

25 aug 2026Nieuw 5 min
Boetes
280.000euro voor een nooit bevestigd account

De gebruiker bevestigde het account niet: voor de Italiaanse toezichthouder is er geen contract en zijn de mails onrechtmatig

Besluit van 18 juni 2026, bekendgemaakt op 29 juli. Een burger krijgt reclamemails zonder ooit het lidmaatschapsformulier te hebben ingevuld. Uit het onderzoek blijkt dat wie de aanmaak van het account niet bevestigde toch op de lijsten belandde: de dubbele opt-in bestond, maar was nergens op aangesloten.

29 jul 2026Nieuw 6 min
EDPB / EDPS
171paragrafen, en één ervan gaat over uw registers

"We bewaren het voor onderzoeksdoeleinden": de EDPB legt uit waarom dat geen antwoord is

Op 15 april 2026 heeft de EDPB de ontwerprichtsnoeren 1/2026 over wetenschappelijk onderzoek vastgesteld. De openbare raadpleging sloot op 25 juni en de definitieve tekst is er nog niet. Wie registers bijhoudt, doet er goed aan het hoofdstuk over bewaring te lezen: een onderzoeksdoel alleen rechtvaardigt geen open termijn.

15 apr 2026Nieuw 7 min
Boetes
26klachten, en geen boete

Je verklaart contract en wijst daarna de bezwaren af: Noorwegen laat zien hoe die twee fouten samen reizen

SATS vroeg leden om een foto die in het ledensysteem blijft en aan de balie wordt gebruikt om de identiteit van binnenkomende leden te controleren. Datatilsynet stelde vast dat de informatie een verkeerde grondslag noemde, het recht van bezwaar niet uitlegde, en dat bezwaren werden afgewezen zonder dwingende gerechtvaardigde gronden aan te tonen. Termijn om het te herstellen: 11 september 2026.

26 aug 2026Nieuw 6 min
Regelgeving
26het artikel dat niemand tekent vóór de uitzending

Wie is aansprakelijk voor de livestream van de wedstrijd onder 14? Zweden beantwoordt de vraag die niemand stelt

Op 25 augustus publiceerde de Zweedse toezichthouder een handreiking over het streamen van jeugdsport. Veel verenigingen zenden kinderwedstrijden online uit, en de handreiking noemt de factoren die bepalen wat is toegestaan. Maar het lezenswaardige deel is het andere: de verantwoordelijkheid als de gemeente eigenaar is van de accommodatie en de vereniging er camera's wil ophangen.

25 aug 2026Nieuw 5 min
Regelgeving
24maanden waarna een incident niet meer wordt gebruikt

De score waarmee uw krediet wordt geweigerd, mag u opvragen — en die moet worden uitgelegd

Op 19 augustus vertaalde de CNIL haar aanbeveling van mei 2026 over de beoordeling van kredietwaardigheid voor het publiek. Daarin staan drie getallen en één beginsel die iedereen aangaan die aan scoring doet: vierentwintig maanden voor eerdere incidenten, zes maanden voor de gegevens van een afgewezen aanvraag, en een recht van inzage in de score dat niet met een beroep op bedrijfsgeheim kan worden afgedaan.

19 aug 2026Nieuw 6 min
Tech & AI
0gestolen wachtwoorden, en dat is nu juist het probleem

Franse fiscale gegevens gestolen, en geen enkel wachtwoord: juist dat maakt de zaak gevaarlijk

Op 14 augustus meldde het Franse ministerie van Economie dat het informatiesysteem van de belastingdienst was getroffen door een datalek: een derde kon gegevens van particulieren en ondernemingen inzien en onttrekken. Inloggegevens en wachtwoorden lijken niet betrokken — en juist daarom is het risico niet accountovername maar phishing gebouwd op echte fiscale gegevens.

18 aug 2026Nieuw 5 min
Regelgeving
2EDPB-criteria en de DPIA wordt verplicht

Op school zijn advertentietrackers verboden, en dat is geen kwestie van toestemming

Op 24 augustus publiceerde de CNIL de regels voor de digitale werkomgevingen die op scholen worden gebruikt. Doorslaggevend is niet de bescherming van minderjarigen maar een bestuursrechtelijk beginsel: de neutraliteit van de openbare onderwijsdienst omvat de commerciële neutraliteit, zodat trackers voor reclame of profilering in beginsel verboden zijn. Heeft de tool ze, dan moet de verwerkingsverantwoordelijke ze uitschakelen.

24 aug 2026Nieuw 6 min
Regelgeving
2documenten over hetzelfde onderwerp, met één andere regel

Zelfde tool, zelfde dag, andere regel: waarom trackers op de universiteit niet verboden zijn

Op 24 augustus publiceerde de CNIL twee teksten over hetzelfde onderwerp, één voor de school en één voor de universiteit. Wie alleen de eerste leest en op de tweede toepast, zit op één punt fout: op school zijn advertentietrackers «in beginsel verboden», in het hoger onderwijs «beveelt» de CNIL aan tools te verkiezen die ze niet gebruiken. De rest — rechtsgrond, DPIA, waarborgen van de verwerker, doorgiften — valt samen.

24 aug 2026Nieuw 5 min
Boetes
825 mln €de op één na hoogste boete ooit

Achthonderdvijfentwintig miljoen voor een algoritme dat accounts uitzette terwijl niemand keek

Het is de op één na hoogste boete ooit onder de AVG, alleen achter de 1,2 miljard voor Meta. Het gaat niet over een doorgifte of een datalek: het gaat over artikel 22, de regel over geautomatiseerde besluiten die vrijwel niemand vastlegt omdat die op een probleem van grote platforms lijkt. Hij raakt in werkelijkheid iedereen die software laat beslissen over iets dat in iemands leven zwaar weegt.

24 aug 2026Nieuw 5 min
Boetes
64 mln złtegen 14 het jaar ervoor

Polen verviervoudigde zijn boetes in een jaar, en de drie hoogste ooit stammen alle uit 2025

Polen gold jarenlang als markt met een laag handhavingsrisico. Die aanname houdt geen stand meer: in twaalf maanden ging het totaal van veertien naar ruim vierenzestig miljoen zloty, en de drie hoogste boetes uit de geschiedenis van het land dragen hetzelfde jaartal. Begeleidt u een klant met een vestiging, leverancier of servicecentrum in Polen, dan is de risicoberekening veranderd.

24 aug 2026Nieuw 4 min
Regelgeving
77documentgebieden

Zevenenzeventig vakken: wat een FG werkelijk archiveert, en waarom eenendertig niet volstonden

We stelden gebruikers een eenvoudige vraag: als er een verzoek van de toezichthouder binnenkomt, welke papieren haal je erbij? Het antwoord bevatte zesenveertig categorieën zonder eigen vak, die allemaal in «Overige documenten» belandden. We hebben ze toegevoegd. Daarna moest de pagina opnieuw, want zevenenzeventig grijze tegels in een raster zijn slechter dan eenendertig.

24 aug 2026Nieuw 6 min
Platform
29bestemmingen die u met een woord bereikt

Het risico wordt in het register beoordeeld, en elke functie ligt op één woord afstand

Een FG gebruikte het platform een paar dagen en schreef dat het register van datalekken, de risicobeoordeling, het uploaden van documenten en de prijzen ontbraken. Drie van de vier waren er al. Ze vond ze niet omdat ze in het klantdossier zitten, en het menu toont ze niet. Vandaar twee toevoegingen: de risicobeoordeling, die in het register werkelijk ontbrak, en een zoekbalk die antwoordt op «datalek», «72 uur» of «art. 33» en ook zegt waar het gezochte staat.

23 aug 2026Nieuw 5 min
Platform
35maatregelen uit art. 32 in de catalogus

Beveiligingsmaatregelen hoeven niet meer te worden overgetypt

De opmerking kwam van een FG tijdens de gratis proefperiode: «bij beveiligingsmaatregelen kan ik alleen typen». Ze had gelijk. Maatregelen kiest u nu uit een catalogus in negen groepen, ze blijven met de hand aan te vullen, en het programma zet de relevante bovenaan door naar de gegevenscategorieën en de doorgiftes te kijken. Ook de gegevenscategorieën krijgen een beschrijvend tweede niveau, en het land van bestemming is geen vrij veld meer.

22 aug 2026Nieuw 4 min
Platform
611wettelijke regels, negen rechtsstelsels

Hoe lang gegevens worden bewaard: 611 regels, negen rechtsstelsels en een methode

Opslagbeperking is het beginsel dat bij een controle het slechtst aan te tonen is, omdat het antwoord verschilt per categorie gegevens en per land. Het platform bevat 611 reeds uitgeschreven regels. Maar het gaat niet om het getal: van 232 Portugese regels hebben er slechts 99 een in cijfers uit te drukken duur, en 95 zijn aangeduid als «lopende referentie» in plaats van «geverifieerd». Dat zeggen is nuttiger dan het verzwijgen.

22 aug 2026Nieuw 5 min
Boetes
80geweigerde inzageverzoeken

De klant gaat failliet, de leverancier blijft alleen achter met de gegevens — en wordt verwerkingsverantwoordelijke

Een winkelketen gaat failliet. Oud-werknemers hebben hun urenregistratie nodig om onbetaald loon te onderbouwen, maar de enige die die gegevens heeft is de leverancier van de tijdregistratiesoftware. Die antwoordt dat hij aan niemand iets mag verstrekken — „zelfs niet aan de betrokkenen zelf" — omdat het contract met de verwerkingsverantwoordelijke is geëindigd. De Noorse toezichthouder oordeelde het tegendeel: wie als enige nog over de gegevens beslist, is de verwerkingsverantwoordelijke.

21 aug 2026Nieuw 4 min
Rechtspraak
200 €voor het verlies van controle

Echte werknemersgegevens in de testomgeving: wat verlies van controle waard is

Een nieuw HR-systeem testen met echte gegevens is niet verboden: méér velden overdragen dan de test nodig heeft wel. Het Duitse federale arbeidshof veroordeelde een werkgever tot tweehonderd euro omdat hij salaris, privéadres, fiscaal nummer en burgerlijke staat had geüpload, terwijl hij met de ondernemingsraad een lijst van negen velden had afgesproken. En het bevestigde dat een late reactie op een inzageverzoek op zichzelf geen schade is.

21 aug 2026Nieuw 5 min
Regelgeving
2 dic 2027il nuovo termine per l'alto rischio

2 augustus is niet vervallen: het is versmald

Wie alleen de kop las — "de AI-verordening wordt uitgesteld" — werkt met verkeerde informatie. De datum van 2 augustus 2026 is niet verdwenen: de inhoud is veranderd. Wat bleef raakt veel meer klanten dan wat verschoof.

19 aug 2026Nieuw 5 min
Tech & AI
4i momenti in cui si decide

De Nederlandse toezichthouder publiceert een zelfevaluatie voor generatieve AI

Er ontbrak iets om te geven aan de klant die zegt: "we hebben de AI in ons pakket aangezet". De Nederlandse toezichthouder heeft een zelfevaluatie over generatieve AI-systemen gepubliceerd: vier momenten, en op elk een beslissing die moet worden vastgelegd.

18 aug 2026Nieuw 4 min
Regelgeving
133.000le PMI raggiunte dalla catena

NIS2 is wet in Nederland, zonder overgangsperiode

De Cyberbeveiligingswet is op 15 augustus 2026 in werking getreden. Het getal dat telt is niet achtduizend, maar honderddrieëndertigduizend: de Nederlandse mkb-bedrijven die de wet bereikt, niet omdat zij binnen het bereik vallen, maar omdat zij leveren aan iemand die daarbinnen valt.

15 aug 2026Nieuw 5 min
Tech & AI
1 su 4le violazioni con IA

Meldingen van datalekken hebben heel 2025 al overtroffen

De cijfers over het eerste halfjaar van 2026 zeggen twee verschillende dingen. Het eerste: het aantal gewaarschuwde personen wordt bepaald door zeer weinig enorme incidenten. Het tweede, ongemakkelijker voor wie risico beoordeelt: AI komt voor bij één op de vier lekken.

14 aug 2026Nieuw 4 min
Regelgeving
3le vie per chiudere il conflitto

Een FG die beslist, kan zichzelf niet controleren

Op 10 augustus 2026 heeft de CNIL op papier gezet hoe een belangenconflict bij de functionaris voor gegevensbescherming wordt herkend en opgelost. Er is één maatstaf: bepaalt de FG in zijn overige functies het doel en de middelen van een verwerking, dan kan hij daar geen toezicht op houden. Niemand kan rechter in eigen zaak zijn.

10 aug 2026Nieuw 5 min
Rechtspraak
7i criteri di bilanciamento CEDU

Niet het artikel wordt gewist, maar de naam

Op 5 augustus 2026 verduidelijkte de Franse toezichthouder de grenzen van een recht dat vaak wordt ingeroepen en breed wordt misverstaan. Tegenover een persorgaan blijven bezwaar en wissing van toepassing, inzage en rectificatie niet. En een weigering moet concreet worden gemotiveerd: zes algemene formuleringen worden als ontoelaatbaar benoemd.

05 aug 2026Nieuw 4 min
EDPB / EDPS
12-14gli articoli sotto esame

In 2026 kijken alle Europese toezichthouders naar hetzelfde: de privacyverklaringen

Elk jaar kiest de EDPB een thema dat alle nationale toezichthouders samen onderzoeken, in dezelfde periode, met vragenlijsten en inspecties. Het thema voor 2026 is transparantie: hoe verwerkingsverantwoordelijken mensen vertellen wat er met hun gegevens gebeurt. In beeld zijn art. 13, wanneer de gegevens van de betrokkene komen, en art. 14, wanneer ze ergens anders vandaan komen. De Tsjechische toezichthouder heeft het thema al in zijn inspectieplan opgenomen.

10 aug 2026Nieuw 6 min
Regelgeving

De Portugese CNPD schrijft op waar zij tot 2029 zal kijken

Op 24 juli 2026 stelde de Portugese autoriteit haar meerjarenplan 2027-2029 en het activiteitenplan 2027 vast. Het is het soort document dat vrijwel niemand leest en dat jaren vooruit zegt waar het toezicht zich op zal richten: digitale opleiding, digitale kwetsbaarheid, reguleringscapaciteit voor de DSA, AI-competenties en neurodata.

24 jul 2026Nieuw 4 min
Boetes
4,3milioni EUR

Portugal: de hoogste boete ooit leert maar één ding. Een verwerker toetsen is een inhoudelijke plicht, geen formulier

Met besluit 2022/1072 legde de Portugese CNPD het INE één boete van 4,3 miljoen euro op voor vijf overtredingen tijdens de volkstelling van 2021. De leerzaamste gaat niet over gezondheids- en religiegegevens: het INE sloot, hoewel de leverancier een kantoor in Lissabon had, het contract met de Amerikaanse vennootschap, aanvaardde de rechter in Californië als bevoegde rechter en het transport van gegevens langs tweehonderd servers, met modelcontractbepalingen en zonder enige aanvullende maatregel.

12 dec 2022Nieuw 7 min
Rechtspraak
3condizioni cumulative del test

Gerechtvaardigd belang is geen terugvalgrondslag

In zaak C-621/22 oordeelde het Hof van Justitie dat een commercieel belang een gerechtvaardigd belang in de zin van artikel 6, lid 1, onder f) kan vormen. Velen lazen alleen die regel. De rest van het arrest herinnert eraan dat het bij drie cumulatieve voorwaarden blijft, en dat de derde - de afweging tegen de redelijke verwachtingen van de betrokkene - degene is waarop de zaak werd verloren. Voor de FG is het gevolg praktisch: gerechtvaardigd belang bestaat alleen als het ergens is opgeschreven.

12 aug 2026 6 min
Rechtspraak
3elementi da provare, cumulativi

Schadevergoeding onder de AVG: wat de eiser werkelijk moet bewijzen

Boetes van toezichthouders halen de krant, civiele vorderingen vullen de agenda's van advocaten. Sinds 2023 heeft het Hof van Justitie verduidelijkt dat vergoeding op grond van artikel 82 drie cumulatieve elementen vereist - inbreuk, schade en causaal verband - zonder enige drempel van ernst. En het heeft geoordeeld dat de gegronde vrees dat je gegevens in verkeerde handen zijn gevallen al immateriële schade is. Voor de verwerkingsverantwoordelijke verschuift daarmee het speelveld: niet langer de ernst, maar het bewijs van de getroffen maatregelen.

11 aug 2026 7 min
EDPB / EDPS
28 agotermine per candidarsi

Mededinging en gegevensbescherming: de EDPB opent de tafel, en er is een termijn

Na de DSA en vóór de DMA en de AI-verordening gaat het vierde stuk van de Europese regelgevingsmozaïek over de verhouding tussen mededinging en gegevensbescherming. Dat is niet theoretisch: het raakt gegevens als marktactivum, concentraties, en de positie van wie gegevens verwerkt omdát hij een markt beheerst. De EDPB en de Commissie vragen om input vóórdat zij schrijven - en deze keer is de termijn dichtbij.

30 jul 2026 6 min
EDPB / EDPS
10 lug 2027quando si potra' condividere

Witwasbestrijding en privacy: EDPB en AMLA schrijven samen de regels voor delen

Op 1 juli 2026 kondigden de EDPB en de Europese antiwitwasautoriteit gezamenlijke richtsnoeren aan over een vraag die geen van beiden alleen kon oplossen: hoe banken, beroepsbeoefenaren en toezichthouders informatie over verdenkingen kunnen delen zonder ongecontroleerde lijsten van verdachten te bouwen. De mogelijkheid geldt vanaf 10 juli 2027 en de openbare consultatie wordt in de eerste helft van dat jaar verwacht. Wie meldingsplichtige klanten begeleidt, heeft een jaar om zich voor te bereiden.

01 jul 2026 6 min
EDPB / EDPS
16-17luglio 2026

EDPB vanuit Dublin: er is een rechtsgrondslag nodig zodat toezichthouders over sectoren heen informatie kunnen delen

Het aantal en de complexiteit van klachten nemen toe, mede door het toegenomen gebruik van AI, en toezichthouders zeggen openlijk dat de middelen tekortschieten. De oplossingen op tafel: gezamenlijke operaties, het bundelen van middelen tussen autoriteiten en de komende Procedureverordening.

17 jul 2026 6 min
EDPB / EDPS
65art. GDPR

EDPB, bindend besluit 1/2026: een cookieklacht wordt niet afgewezen met het verwijt dat de klager misbruik maakt van zijn rechten

De leidende autoriteit wilde de zaak sluiten wegens vermeend misbruik van art. 77 en art. 80, lid 1. De Oostenrijkse toezichthouder maakte bezwaar en de EDPB gaf hem gelijk: noch het objectieve, noch het subjectieve bestanddeel van misbruik was aangetoond. De klacht gaat terug en moet inhoudelijk worden beoordeeld.

14 jul 2026 7 min
Regelgeving
3condizioni

Controle van werknemers: de CNIL herinnert eraan dat er drie voorwaarden zijn en dat ze alle drie gelden. Proportionaliteit is pas de eerste

Op 9 juli 2026 heeft de CNIL haar pagina over de controle van de activiteit van werknemers bijgewerkt. De inhoud lijkt herhaling, maar één punt wordt in de praktijk voortdurend onderschat: de voorwaarden zijn er drie, ze zijn cumulatief, en twee van de drie hebben niets te maken met hoe ingrijpend het middel is.

09 jul 2026 6 min
Regelgeving
71%lo vuole

71 % van de FG's wil de AI-verordening binnen het eigen bereik. 27 % zegt haar te kennen. 85 % volgde nooit een AI-opleiding

Op 3 juli 2026 publiceerden het Franse ministerie van Werk, de AFCDP en de CNIL de vijfde editie van het Observatorium van het FG-beroep, uitgevoerd door de Afpa. De makkelijke lezing is dat FG's de AI-aanspreekpunten worden. De nuttige lezing is een andere: tussen wie de AI-verordening in het eigen bereik wil en wie zegt haar te kennen zit 44 punten verschil, en de AI-verordening noemt de FG nergens.

03 jul 2026 6 min
Rechtspraak
13milioni EUR

Oostenrijk: het hoogste bestuursrechtscollege verlaagt de boete van 18 naar 13 miljoen. Maar u moet de passage lezen waarin het zegt dat een compliance-programma niets verontschuldigt

Op 24 juni 2026 sloot het Oostenrijkse Verwaltungsgerichtshof een sinds 2019 lopende procedure af en verlaagde de boete voor het verwerken van 'partijaffiniteiten', berekend voor ongeveer 2,2 miljoen personen, tot 13 miljoen euro. De koppen zullen over de korting gaan. Voor een FG telt de rest: het college zegt dat voor het bestraffen van een rechtspersoon geen handelen van de bestuursorganen nodig is, dat het beschikken over middelen voor advies de lat hoger legt in plaats van lager, en dat de verwijten over de DPIA en het verwerkingsregister wegvallen door absorptie - niet omdat die documenten juist waren.

24 jun 2026 7 min
Boetes
2.126.075persone

Zweden: 6 miljoen kronen voor een SQL-injectie. Het hardste is niet de boete, maar dat het risico al sinds 2021 in hun eigen risicoregister stond

Op 26 januari 2026 legde de Zweedse toezichthouder Sportadmin i Skandinavien AB een boete van 6.000.000 kronen op wegens schending van artikel 32, lid 1. Het platform beheert leden, facturatie en websites van sportverenigingen: de aanval van 16 januari 2025 legde de gegevens van 2.126.075 personen bloot, overwegend kinderen, inclusief allergieën en beperkingen. De passage die u twee keer moet lezen is echter een andere: sinds 2021 had het bedrijf het risico van SQL-injectie in zijn eigen jaarlijkse doorlichtingen vastgesteld, en juist daarop baseert de IMY de grove nalatigheid.

26 jan 2026 8 min
Regelgeving
5priorita' 2026

Wie houdt toezicht op de AI-verordening, en waar begint dat. Verboden praktijken en AI-geletterdheid, niet de hoogrisicosystemen

De Nederlandse regering heeft de Autoriteit Persoonsgegevens en de Rijksinspectie Digitale Infrastructuur aangewezen als coördinerende nationale toezichthouders voor de AI-verordening. De werkagenda voor 2026 noemt vijf prioriteiten: overkoepelend systeemtoezicht, transparantie en uitlegbaarheid, kaders en normen, toetsing op bias en eerlijkheid tegen discriminatie, en AI-geletterdheid. De eerste formele handhavingsacties worden in de loop van 2026 verwacht, te beginnen bij organisaties die verboden praktijken toepassen of de verplichting tot AI-geletterdheid aantoonbaar verwaarlozen.

01 aug 2026 5 min
Boetes
23sanzioni in 6 mesi

France: 23 fines in six months under the simplified procedure. Small amounts, new target

In the review published on 6 July 2026 the CNIL counts 23 new fines adopted since January under its simplified procedure, totalling EUR 133,750. Three infringements recur: excessive video surveillance, non-compliant cookie banners, and failure to respond to access and erasure requests. One example of the kind of target: EUR 7,500 against a company operating public toilet facilities, on 2 April.

06 jul 2026 5 min
Boetes
5milioni EUR

France: EUR 5 million for IQVIA. The pharmacy software kept sending the data even when the patient had said no

On 26 May 2026 the CNIL's restricted committee fined IQVIA Operations France EUR 5 million. The company runs two health data warehouses for third-party studies: LRX, authorised in 2018 and fed by around 14,000 pharmacies, and EMR, authorised in 2021 and fed by several thousand doctors. Among the findings, the most instructive: the practice management software used in pharmacies transmitted customer data to IQVIA even where the customer had objected.

26 mei 2026 7 min
Rechtspraak
792.639EUR confermati

Finland: the Supreme Administrative Court upholds the fine on Verkkokauppa.com. The failing: never having defined how long to keep the data

On 12 June 2026 the Korkein hallinto-oikeus, Finland's Supreme Administrative Court, dismissed Verkkokauppa.com's appeal against the penalty imposed by the Finnish Data Protection Ombudsman's sanctions board (decision KHO 12.6.2026/1604). The original amount was EUR 856,000, reduced by the Administrative Court to EUR 792,639 on the basis of the company's most recent turnover. The finding does not concern a data breach: it concerns the fact that the company had never defined retention periods for customer account data.

12 jun 2026 6 min
Boetes
749firmatari esposti

Poland: a municipality fined not for publishing the data of 749 petition signatories, but for never reporting it

On 25 May 2026 the President of the UODO fined the mayor of Myslenice PLN 7,700. An un-anonymised petition had been published in the municipality's Public Information Bulletin: names, surnames, home addresses and signature specimens of 749 people. The core of the decision is not the publication, which the municipality corrected by replacing the file: it is that the breach was never notified to the authority, not even after the authority asked.

25 mei 2026 6 min
Rechtspraak
600.000EUR annullati

Raad van State bevestigt vernietiging van de boete van 600.000 euro voor wifitracking in Enschede

Op 29 juli 2026 heeft de Afdeling bestuursrechtspraak van de Raad van State het hoger beroep van de Autoriteit Persoonsgegevens tegen de gemeente Enschede ongegrond verklaard en daarmee de uitspraak van de rechtbank Overijssel van februari 2024 bevestigd. De boete van 600.000 euro, in maart 2021 opgelegd voor het tellen van bezoekers in het centrum met sensoren die MAC-adressen van apparaten met ingeschakelde wifi opvingen, blijft vernietigd. De reden is niet dat het tellen rechtmatig was: de AP heeft onvoldoende aangetoond dat de verzamelde MAC-adressen als persoonsgegevens konden worden aangemerkt en dat er dus sprake was van verwerking van persoonsgegevens.

29 jul 2026 6 min
Boetes
10.145PLN al responsabile

Poland: WhatsApp in the sales network brings a fine for the processor, and a reprimand for the controller that never vetted it

On 22 June 2026 the President of the UODO, Miroslaw Wroblewski, closed the proceedings opened after a breach notification by Energa-Obrot: reprimands for the controller and the processors, and an administrative fine of PLN 10,145 for one of the processors. At the root of it, the use of WhatsApp by sales representatives of a door-to-door network during the pandemic: on a former agent's private phone there were scans and photographs of customer contracts, in group conversations, for many months.

22 jun 2026 7 min
Boetes
277.500EUR

Ireland: EUR 277,500 for Permanent TSB over a contact centre that could be fooled, and for reporting late

On 8 May 2026 the Irish Data Protection Commission closed its inquiry into a series of personal data breaches at Permanent TSB, first notified in May 2022. Malicious actors, holding certain customer information, called the Open24 contact centre posing as customers, gained access to accounts and amended account details. Some customers lost money. The authority issued a reprimand and fines totalling EUR 277,500.

08 mei 2026 6 min
Regelgeving
3priorita'

De AP maakt haar prioriteiten voor 2026-2028 bekend: massasurveillance, kunstmatige intelligentie en digitale weerbaarheid

De Autoriteit Persoonsgegevens heeft drie strategische prioriteiten vastgesteld voor 2026-2028: massasurveillance, kunstmatige intelligentie en digitale weerbaarheid. In het jaarplan 2026 geeft de AP aan meer capaciteit vrij te maken voor AI en algoritmen en zich te richten op grootschalige systemen met aanzienlijke maatschappelijke impact, zonder onderscheid tussen publieke en private handen. Voor wie klanten in Nederland begeleidt is dit de nuttigste informatie van het jaar - en zij kost niets.

01 aug 2026 6 min
Regelgeving
2autorita'

Netherlands and Poland: two authorities that raised the bar in 2026

The Dutch Autoriteit Persoonsgegevens has increased its budget and headcount and has named transparency, tracking and cookies among its 2026 supervisory priorities, with an approach that is openly less advisory and more enforcement-driven. In Poland the President of the UODO has shifted attention towards small and medium enterprises, a segment until recently little touched by inspections. For anyone with clients in those countries, or considering it, these are two signals that change the cost-benefit balance of compliance.

30 jul 2026 4 min
Boetes
460keuro

Piaggio fined 460,000 euro: 112 company emails read, backups kept for five years after termination

The Italian data protection authority has fined Piaggio & C. Spa 460,000 euro over the way the company managed employee email accounts. The investigation, opened after complaints by two former employees, established that 112 emails had been acquired during the employment relationship, some dating from roughly two years before any suspicion arose, made possible by backups retained for the whole duration of employment and up to five years after termination. Alongside the fine, the authority banned the company from accessing the data it had collected.

29 jul 2026 7 min
Regelgeving
5settori

AI Act in Italy: the data protection authority becomes market surveillance authority for high-risk systems in justice, borders and democratic processes

The Italian data protection authority has issued a favourable opinion on the draft legislative decree implementing the AI Act in Italy. The decree sets out national governance and designates the authority as market surveillance authority for high-risk AI systems used in the areas most sensitive for fundamental rights: justice, law enforcement, immigration, border management and democratic processes. Among the conditions attached, one concerns any organisation: extending the ban on decisions based solely on automated systems to assessments affecting the employment relationship.

29 jul 2026 6 min
Italiaanse toezichthouder
12keuro

Misconfigured document register: 12,000 euro fine for the Metropolitan City of Sassari

Following a data breach notification and a complaint, the Italian data protection authority fined the Metropolitan City of Sassari for misconfiguring its electronic document register, making documents containing personal data accessible to staff who, given their role and duties, were not authorised to process them. The fine is 12,000 euro, but the principle applies to every public body and every company running a document management system: filing is not a neutral activity, and a default of total visibility breaches the principles of integrity and confidentiality.

29 jul 2026 6 min
Regelgeving
2 agoma non tutto

AI Act, 2 August: what actually applies and what has been postponed to 2027

For two years 2 August 2026 was presented as the day obligations for high-risk AI systems would start. The Digital Omnibus package changed that calendar: requirements for Annex III high-risk systems move to 2 December 2027 for stand-alone systems and 2 August 2028 for those embedded in products already covered by sectoral legislation. 2 August nonetheless remains an operative date: the transparency obligations of Article 50 become applicable, together with the full operation of governance and penalties, with national authorities acquiring full powers.

29 jul 2026 5 min
Regelgeving
0multe dirette

Denmark: cookies are the 2026 priority, and fines are decided by a court

The Danish authority has flagged cookie consent as a supervisory priority for 2026, coordinating with the Digitaliseringsstyrelsen, which oversees the ePrivacy implementation while Datatilsynet applies the GDPR. But Denmark has a peculiarity that changes how every one of its decisions should be read: its constitutional order does not allow an administrative authority to impose punitive financial penalties. Recital 151 GDPR expressly anticipates this for Denmark and Estonia: the fine is decided by a court as a criminal penalty, following a report by the authority to the police.

28 jul 2026 4 min
Regelgeving
14 luggia' scaduta

Email tracking pixels: France has already closed its grace period, Italy's runs to October

With deliberation no. 2026-042 of 12 March 2026, made public on 14 April, the French CNIL adopted its final recommendation on email tracking pixels: for most marketing uses, prior consent is required, just as for cookies. Existing contact bases were given three months to inform recipients and allow them to object, a period that ended on 14 July 2026, with checks announced from that date. In Italy the authority reached the same conclusion with decision no. 284 of 17 April 2026, but with a longer compliance window.

26 jul 2026 4 min
Boetes
365milaclienti

Wind Tre, EUR 1.7 million: the breach started with a phone call

The Italian DPA fined Wind Tre EUR 1,715,600 (decision no. 348 of 14 May 2026, made public with the 16 July newsletter). The starting point was not a sophisticated cyberattack: people posing as support technicians convinced staff at two retail outlets to allow access to company systems. From there, identification and contact data of 365,048 customers were exfiltrated; for 41,359 of them, payment method information as well, including IBANs, postal payment slips and credit cards with partially masked numbers and expiry dates. The charges: breach of the integrity and confidentiality principle (Art. 5(1)(f)) and of security obligations (Art. 32(1)(b)).

26 jul 2026 4 min
Boetes
1,5MEUR

Cookies, France holds the line: EUR 1.5 million to American Express and the topic stays a 2026 priority

In January 2026 the CNIL fined American Express EUR 1.5 million for cookie violations, confirming that the topic remains a standalone enforcement priority alongside artificial intelligence and cybersecurity. In 2025 there had been 21 cookie decisions, totalling over EUR 475 million. The recurring charges are always the same: trackers set before consent, a reject button less visible or further away than the accept button, inadequate information.

25 jul 2026 3 min
Regelgeving
art. 15GDPR

Call centre recordings: the customer has a right to access them, and a transcript is enough

A customer had asked to access their own data contained in a recorded call with customer service. The company refused, considering the protection of the agent's confidentiality to prevail. The authority held that the request could be satisfied by providing the transcript, provided the elements identifying other people involved are redacted: given the professional context of the call and its subject, a supply contract, redaction would not have prejudiced the agent's confidentiality.

25 jul 2026 3 min
Regelgeving
3linee guida

EDPB adopts guidelines on anonymisation, web scraping for generative AI, and blockchain

At its July 2026 plenary, the European Data Protection Board adopted guidelines on anonymisation and on web scraping in the context of generative artificial intelligence, together with the final version of the guidelines on processing personal data through blockchain technologies. Three documents addressing three recurring questions: when data is truly anonymous, on what conditions data may be collected from the web to train models, and how the immutability of a chain can be reconciled with data subjects' rights.

24 jul 2026 3 min
Boetes
18MEUR

Spain: EUR 18 million to Amadeus for reusing booking data for product development

The Spanish authority fined Amadeus IT Group EUR 18 million (reduced to 14.4 with voluntary payment) for aggregating travellers' booking data into profiles for product development. The cross-border investigation found the reuse of data collected years earlier from airlines and agencies, for purposes data subjects could not reasonably expect, without an Article 14 notice and without a valid legitimate-interest balancing test.

23 jul 2026 4 min
Boetes
6Miscritti

Norway: loyalty programme under scrutiny, more than six million members involved

The Norwegian authority concluded proceedings opened after an audit of the Nordic entities of a retail group, finding several breaches relating to its loyalty programme: invalid consent, new processing purposes introduced without assessment, insufficient legitimate-interest balancing, and failure to answer data subject requests within the deadline. More than six million members across the Nordic region were affected.

22 jul 2026 3 min
Boetes
3provvedimenti

Credit scoring in utilities: the Italian DPA hits the whole chain with three decisions in one day

With three decisions adopted in the same session on 3 July 2026, the Italian DPA targeted the credit-scoring chain applied to energy supply contracts: Experian Italia, Hera Comm and Cerved. The charges are similar and paint a clear picture: deficient notices, breaches of minimisation and storage limitation, privacy by design and by default disregarded, inadequate responses to access requests and poorly governed Article 28 relationships along the chain.

21 jul 2026 4 min
Regelgeving
art. 21d.lgs. 24/23

Whistleblowing: without consulting the unions, the procedure is not compliant

A preliminary requirement that almost everyone overlooks is back in the spotlight: Article 4 of Legislative Decree 24/2023 requires internal reporting channels to be activated after hearing worker representatives or trade unions. The ANAC guidelines clarify that failing to do so makes the procedure non-compliant and may trigger a sanction under Article 21. It also applies to substantial updates, not just first activation.

20 jul 2026 3 min
Boetes
1,7MEUR

Data breach: Italian DPA fines Wind Tre EUR 1.7 million after exfiltration of 365,000 customers' data

In its 16 July 2026 newsletter the Italian DPA announced a EUR 1.7 million fine to telecom operator Wind Tre following a data breach with exfiltration of roughly 365,000 customers' data. The case confirms the authority's line on large operators: the incident itself is not the fault - the fault lies in security measures inadequate to the risk (Art. 32) and in how the breach was handled. In the same newsletter: two debt-collection companies fined (EUR 50k and 30k) and the customer's right to access the audio of their own support calls (Enel case).

17 jul 2026 3 min
Boetes
158KEUR

Character.AI fined EUR 158,000: minors, late DPIA and missing EU representative

With a decision of 3 July 2026 (announced 9 July) the Italian DPA fined Character Technologies Inc., the US company behind Character.AI, EUR 158,000: deficient privacy notice (Arts. 12-14), a DPIA prepared late relative to the service launch, late designation of the EU representative (Art. 27) and shortcomings in minor protection and age verification. Beyond the fine, corrective measures within 120 days: working age verification, an effective cooling-off period against re-registration by blocked minors, minors' profiles private by default.

16 jul 2026 4 min
Italiaanse toezichthouder
2/2genitori

Children's photos on social media: both parents must consent

In its 17 June 2026 newsletter the Italian DPA restated a principle that matters well beyond family disputes: publishing photos of minor children on social media requires the consent of BOTH parents. In case of disagreement, the child's protection prevails. For the DPO it is an operational criterion affecting schools, nurseries, sports clubs, parishes and companies publishing images of minors for promotional purposes.

15 jul 2026 3 min
Italiaanse toezichthouder
STOPcopie

Italian DPA to hoteliers: do not keep copies of guests' ID documents

In a notice addressed to the hospitality sector, the Italian DPA reiterated that hoteliers may not keep copies of guests' identity documents: the legal duty (Art. 109 of the Italian public-security code) is to identify the guest and transmit the data to the police via the Alloggiati Web portal - after that, document copies must be destroyed or deleted. A widespread habit becomes a concrete sanction risk.

14 jul 2026 3 min
Regelgeving
EDPBconsultazione

Data breach: EDPB puts a new EU-wide notification template up for consultation

The EDPB has opened a public consultation on a new harmonised data-breach notification template, designed to align the information requested by authorities across Member States. For DPOs it is operational news: the content of the Art. 33 notification is becoming standardised, and anyone with a structured internal procedure (facts, categories, risk assessment, measures) will find the work already done.

13 jul 2026 3 min
Boetes
563KEUR

Enel Energia fined EUR 563,000: the 'administrative' call that turns into a sales pitch

With decision no. 170/2026 the Italian DPA fined Enel Energia EUR 563,052: during purely administrative contacts (supply paperwork, takeover confirmations), including via third parties, commercial offers were made without a valid legal basis - even to customers on the opt-out register or who had expressly refused marketing consent. Also challenged: a re-contact mechanism based on opt-out (an SMS with 90 seconds to refuse) and partner vetting - one agency was contracted two months after being sanctioned by the DPA for marketing.

09 jul 2026 4 min
Boetes
55KEUR

Italy's DPA fines AgID: EUR 55,000 to the Agency for Digital Italy over transparency and privacy by design

With injunction order no. 419 of 28 May 2026 the Italian DPA declared unlawful certain personal data processing carried out by AgID - the Agency for Digital Italy, with a EUR 55,000 fine and publication of the decision on the authority's website. The breaches concern lawfulness, fairness and purpose limitation (Art. 5), information duties towards data subjects (Arts. 12 and 14) and data protection by design (Art. 25).

08 jul 2026 3 min
Art. 5
AI Act
Boetes

Italy's DPA halts stress and emotion monitoring at work: not even in aggregate form

With decision no. 342 of 2026, the Italian DPA reaffirmed that data on employees' health or psychological journey cannot be made accessible to the employer, not even in aggregate form. The case closes the loop with the AI Act, which expressly prohibits AI systems that infer people's emotions in the workplace (Art. 5): organisational wellbeing cannot turn into emotional surveillance.

06 jul 2026 4 min
8
mesi
Boetes

Trenitalia tells customers about a data breach eight months after the attack: an Art. 34 lesson

In July 2026 Trenitalia informed its customers of a data breach suffered roughly eight months earlier. Beyond the outcome, the case is a textbook lesson on the difference between notifying the authority within 72 hours (Art. 33) and communicating to data subjects 'without undue delay' when the risk to their rights is high (Art. 34): eight months are hard to justify, and in the meantime the persons affected could not protect themselves.

04 jul 2026 3 min
Italiaanse toezichthouder
37,7MEUR

Italian DPA annual report: collected fines +54.5%, almost 7 data breaches notified per day, AI at the centre

On 2 July 2026 the Italian DPA presented its 2025 activity report to Parliament: 807 collegial decisions, 506 corrective and sanctioning measures, over EUR 37.7 million in fines collected (+54.5% on 2024), 2,415 data breaches notified (+10%), 130 inspections. AI takes centre stage: from DeepSeek to deepfakes, from facial recognition at the airport to worker surveillance.

02 jul 2026 4 min
1,5M
cittadini
Boetes

SPID under scrutiny: Lepida fined, data of 1.5 million citizens viewable 'out of mere curiosity'

With a decision of 29 April 2026, the Italian DPA fined Lepida (EUR 100,000), one of Italy's main SPID identity providers: over 7,000 counter operators could view data and download copies of ID documents and health cards of more than 1.5 million citizens, even with no operational need. The DPA found accesses 'out of mere curiosity' and documents left stored on operators' workstations after identification.

01 jul 2026 4 min
AI Act
update
Regelgeving

Digital Omnibus: EU Council approves changes to the AI Act. What it means if you are preparing

On 29 June 2026 the EU Council approved the proposed regulation that streamlines and simplifies certain AI rules, amending the AI Act (the 'Digital Omnibus' package). Negotiations with Parliament continue: until final adoption, the current AI Act text remains the reference, including the August 2026 transparency deadlines.

29 jun 2026 3 min
Boetes
180kEUR

Italy's DPA fines Emirates EUR 180,000: passenger health data kept for 7 years and an unclear notice

The Italian DPA fined Emirates EUR 180,000 over the handling of reduced-mobility passengers' health data. The case started from a complaint by a passenger asked to fill in a medical form despite not being in the categories required to do so. The key point for DPOs: the collection itself was lawful, but the authority faulted an inadequate notice and excessive retention (7 years).

17 jun 2026 4 min
Art. 5
GDPR
Boetes

Loyalty-card data used to fire an employee: Italy's DPA says no. A lesson on purpose limitation

With decision no. 311 of 29 April 2026, the Italian DPA found unlawful the employer's use of data collected through the loyalty card to support an employee's dismissal. That data had been collected to run the loyalty programme, not to monitor or discipline staff. The point for DPOs: having a piece of data does not mean you can use it for any purpose.

15 jun 2026 4 min
Regelgeving
12-14artt.

EDPB 2026: the EU coordinated action targets transparency (Art. 12-14). What to check in privacy notices

For 2026 the EDPB chose TRANSPARENCY as the topic of its coordinated enforcement action: authorities will examine how organisations inform data subjects under Art. 12-14. In short: clear, complete, verifiable notices. A good moment to review your clients' documents.

12 jun 2026 5 min
Boetes
7,1mld EUR

GDPR fines top EUR 7.1 billion: enforcement accelerates and SMEs are not exempt

Cumulative GDPR fines have passed EUR 7.1 billion across 1,400+ decisions. Enforcement is accelerating, not plateauing. And contrary to a common myth, SMEs do get fined: smaller amounts, same proportional severity.

12 jun 2026 5 min
5M
EUR
Boetes

France fines IQVIA EUR 5M: pseudonymisation does not take you out of the GDPR

In France the authority (CNIL) fined IQVIA EUR 5 million, clarifying a point many confuse: pseudonymising data - even health data - is not the same as anonymising it. Pseudonymised data remains personal data and must be handled with all the safeguards of the Regulation, including the enhanced ones in Art. 9.

10 jun 2026 3 min
Regelgeving
15MEUR

Rome Court annuls the Garante's EUR 15M fine against OpenAI: the one-stop-shop decides

The Rome Court annulled the EUR 15M fine the Italian Garante imposed on OpenAI in 2024. The judge does not rule on the merits (legal basis, notice, age verification): it upholds the jurisdiction argument. For cross-border processing the one-stop-shop and lead authority govern.

10 jun 2026 6 min
Regelgeving
6ambiti

The Garante's 2026 inspection plan: six areas and how to be ready

The Italian Garante set its 2026 inspection areas, backed by the Finance Police tech-fraud unit. Topics include data breaches in public databases and abusive access. Those who document self-assessment and lesson learning get treated differently.

10 jun 2026 5 min
Boetes
5MEUR

France: CNIL fines France Travail EUR 5 million - 36.8 million data subjects and a social-engineering attack

The CNIL fined France Travail (formerly Pole Emploi) EUR 5 million after a breach exposing the data of around 36.8 million people. Attackers used social engineering against partner advisers' accounts. The lesson: having security plans is not enough, they must actually be implemented.

09 jun 2026 6 min
Boetes
1,7MEUR

France: EUR 1.7 million to Nexpublica - health and disability data accessible to other users through long-known flaws

The CNIL fined software vendor Nexpublica EUR 1.7 million: its PCRM tool, used by social services, exposed sensitive documents (including disability data) to other users. The flaws were known from prior audits but left open. A textbook case for anyone processing health data.

09 jun 2026 6 min
Boetes
10MEUR

Spain: AEPD fines Aena EUR 10 million for biometric boarding without adequate DPIA

The Spanish Data Protection Agency fined Aena over EUR 10 million for launching its biometric boarding programme without completing an adequate DPIA. Not a data breach: a failure of preventive accountability.

25 mei 2026 8 min
Boetes
290MEUR

Netherlands: the EUR 290 million Uber fine and the Dutch Authority's new priorities for 2026

The Autoriteit Persoonsgegevens confirmed the EUR 290 million fine against Uber for unlawful transfers to the US. Meanwhile the Authority sets three strategic priorities for the next two years every DPO should know.

22 mei 2026 7 min
Boetes
85kEUR

Data breach: Italy's DPA fines The European House - Ambrosetti EUR 85,000 over plaintext passwords and late notification

The Italian DPA fined The European House - Ambrosetti spa EUR 85,000 following a 2024 data breach affecting 61,670 people. The attack, via a technical vulnerability, led to the exfiltration of names, emails, usernames and passwords. The point for DPOs: the breach was notified to the regulator within 72 hours, but data subjects were informed only after two months and after the authority stepped in.

21 mei 2026 4 min
EDPB / EDPS
25DPA

EDPB CEF 2026: 25 European DPAs verify transparency of privacy notices

The European Data Protection Board has launched the 2026 coordinated action on transparency and information obligations. 25 national DPAs (including the Italian Garante) are already contacting controllers in various sectors. What to expect and how to prepare.

20 mei 2026 9 min
Italiaanse toezichthouder
1 lug 2026deadline

Italian DPA cracks down on WhatsApp and Telegram in public administration: ban on operational communications with citizens from July 1, 2026

The Italian DPA (Garante) issued a general provision banning Italian public administrations from using WhatsApp, Telegram, Messenger and other commercial messaging apps for operational communications with citizens. Banned also for requesting documents, certificates or personal data. PAs must use institutional channels (PEC, portals, SPID-auth) by July 1, 2026. Fines up to 100,000 EUR.

19 mei 2026 9 min
Tech & AI
1ain UE

Spain: AEPD publishes Europe's first guidance on agentic AI and data protection

The Spanish Data Protection Agency is the first European Authority to publish elaborate guidance on agentic AI. It explains the concept, the vulnerabilities in processing personal data and mitigation measures for controllers and processors.

18 mei 2026 7 min
Boetes
45MEUR

Vodafone Germany fined EUR 45 million: the Art. 28 GDPR lesson on processor controls

The German Federal Commissioner for Data Protection (BfDI) imposed a total fine of EUR 45 million on Vodafone GmbH: 15M for Art. 28 violation (processor oversight) and 30M for Art. 32 (security). A decision that redefines accountability expectations on processors.

15 mei 2026 8 min
Regelgeving
18settori essenziali

NIS2 and GDPR: how to orchestrate them operationally after Italian Decree 138/2024. The DPO checklist for the NIS Operator

After the NIS2 transposition with Legislative Decree 138/2024, Italian companies qualified as 'essential entities' or 'important entities' must coordinate NIS2 obligations (cyber security, 24h incident reporting) with GDPR obligations (72h data breach). The DPO is not the NIS Coordinator but must interface: risk of double sanctions if not properly orchestrated.

15 mei 2026 11 min
EDPB / EDPS
12raccomandazioni

EDPB publishes guidelines on public DPO profiles: transparency, accountability and data subject rights

The EDPB clarifies how to process the professional data of DPOs exposed publicly on online directories: legal basis, purposes, data subject rights and platform responsibilities.

12 mei 2026 8 min
Tech & AI
Aug 2026

AI Act August 2026: high-risk systems deadline. Mandatory DPIA for enterprise LLMs

The EU AI Act enters its critical phase: August 2026 triggers obligations for high-risk systems. The Italian Garante has already anticipated enforcement with the EUR 5M fine to Luka (Replika). What DPOs must do now.

08 mei 2026 10 min
Regelgeving
Art. 26AI Act

AI Act and DPO: how the DPO role changes with deployer obligations entering into force in August 2026

In less than 3 months, the AI Act sections dedicated to deployers (users) of high-risk AI systems enter into force. The DPO becomes a key interlocutor for impact assessment, data subject information and monitoring.

08 mei 2026 10 min
Italiaanse toezichthouder

Corporate email post-termination: Italian DPA fines ITAS Mutua

The Italian Data Protection Authority addresses the management of corporate emails after employment termination. ITAS Mutua sanctioned for undocumented access and retention beyond necessary.

07 mei 2026 5 min
Rechtspraak
530MEUR

TikTok vs Irish DPC: Supreme Court suspends 530 million euro fine

The Irish Supreme Court confirms the suspension of the record 530M EUR fine imposed by the DPC on TikTok for EEA data transfer to China. The case exposes the structural problem of enforcement timing against big tech.

30 apr 2026 6 min
Regelgeving
6mesi

Email tracking pixels: new Italian DPA Guidelines

On April 17, 2026, the Italian DPA adopted Guidelines on tracking pixels in emails. For DPOs: 6 months to align privacy notices, consent flows, and privacy-by-design techniques.

17 apr 2026 5 min
Boetes
31.8MEUR

Intesa Sanpaolo: 31.8M euro fine from the Italian DPA

The Italian Data Protection Authority fines Intesa Sanpaolo for a data breach affecting 2.4 million customers. Late notification and incomplete information among the key issues.

26 mrt 2026 4 min
Rechtspraak
15MEUR

Rome Court annuls 15M euro fine against OpenAI

The Rome Court annuls the fine that the Italian DPA had imposed on OpenAI for the ChatGPT case. A decision that redefines the scope of GDPR enforcement on generative AI models.

20 mrt 2026 4 min
Boetes
500KEUR

Enel Energia fined over 500,000 euros: telemarketing without consent

The Italian DPA fines Enel Energia for promotional calls to subjects who had not provided consent or had registered their number in the public opposition register.

12 mrt 2026 3 min
Rechtspraak
120giorni

Italian Supreme Court 984/2026: the DPA 120-day deadline is final

With its January 17, 2026 ruling, the Italian Supreme Court confirms that the 120-day deadline for concluding the DPA's enforcement proceedings is final. A relevant decision for those handling privacy litigation.

18 feb 2026 3 min
EDPB / EDPS

EDPB: DPOs are under-resourced and disconnected from top management

EDPB publishes the results of the coordinated enforcement action: insufficient resources, lack of access to top management, conflict of interest risk. A snapshot that also concerns Italian external DPOs.

17 feb 2026 4 min
Rechtspraak

France's Conseil d'Etat: the line between anonymization and pseudonymization narrows

France's State Council confirms CNIL's approach on pseudonymized health data. A ruling that redefines the practical scope of GDPR anonymization and impacts all data analytics projects.

13 feb 2026 5 min
EDPB / EDPS

EDPS strengthens DPO independence: new binding rules

The European Data Protection Supervisor (EDPS) adopts new binding rules to protect DPO independence within Union institutions. A signal strengthening the role.

13 feb 2026 3 min
EDPB / EDPS
96h

Digital Omnibus: EDPB and EDPS call for simplification without setbacks

EDPB and EDPS publish the joint opinion on the EU Commission's Digital Omnibus package. Positive measures on data breach and DPIA, but strong opposition to the revision of the personal data definition.

11 feb 2026 5 min
Italiaanse toezichthouder
40ispezioni

Italian DPA 2026 inspection plan: data breach, whistleblowing, AI in schools

The Italian DPA published its inspection activities plan for January-June 2026. Sectors at risk: banking data breaches, health dossiers, energy telemarketing, and AI in schools.

29 jan 2026 3 min
Boetes
42MEUR

CNIL fines Free Mobile and Free 42 million euros: 24 million customer data breach

The French Authority separately fines Free Mobile (27M) and Free (15M) for a breach that exposed 24 million subscribers in October 2024. A decision that clarifies the scope of Art. 34 GDPR.

13 jan 2026 7 min