Retningslinjer fra Personvernrådet · art. 7 GDPR
Vi bruker tekniske informasjonskapsler som er nødvendige for at plattformen skal fungere (innlogging, sikkerhet, økter). Vi ønsker også å bruke analytiske informasjonskapsler for å forstå hvordan vi kan forbedre den.
Du kan godta alt, avvise alt, eller velge hvilke kategorier som skal være på.Samtykket ditt er gyldig i 6 måneder, og du kan når som helst trekke det tilbake fra bunnteksten.
Du finner alt i vår personvernerklæring.
Curated updates: Italian DPA decisions, EDPB rulings, fines and regulatory news. Analyzed from a working DPO's perspective.
Den erstatter ikke personvernforordningen, den kommer i tillegg. For den som fører protokollen til en helsekunde er det fire datoer å merke seg, ikke én, og den første faller om mindre enn sju måneder.
Det er det eneste stedet i EU-retten der gjenbruk av personopplysninger til å trene en modell er uttrykkelig regulert. Vilkårene er sju, og alle må være oppfylt samtidig.
Psykisk helse på jobben er i ferd med å bli pliktig forebygging, ikke frivillig velferd. Og i det øyeblikket en virksomhet måler de ansattes velvære, begynner den å behandle helseopplysninger — som regel uten å merke det.
Selskapet er amerikansk og har ingen etablering i Italia; forordningen gjaldt likevel. I tillegg til gebyret: forbud mot å behandle opplysninger om personer som befinner seg i Italia, og pålegg om å slette det som er ulovlig innsamlet.
KI-kontoret tar modellene til allmenne formål, nasjonale myndigheter alt annet, EDPS EU-institusjonene. Å vite hvem en kunde svarer til kommer før å vite hva han risikerer. Og enda før det kommer å skille fullmakter som ble utøvbare fra fullmakter som er utøvd.
Å melde et brudd i dag betyr å skrive til flere myndigheter i ulike formater innenfor de samme tre dagene. Rådet og Datatilsynet støtter ett felles kontaktpunkt, og setter grenser for ENISA, for sertifisering og for forholdet mellom sikkerhet og grunnleggende rettigheter.
Det britiske tilsynet fortalte hva som skjer før de formelle undersøkelsene. Stilt overfor valget mellom å sikre tjenesten eller ikke lenger være tilgjengelig fra Storbritannia, valgte sju plattformer det andre. Det er en seier, men det sier også hvor billig det er å gå.
Det alvorligste tilfellet stammer fra digitaliseringen av papirarkivene mellom 2013 og 2022: over 1,17 millioner mapper, hvorav 1,14 millioner om adopterte og rundt 30 000 om savnede barn, på dårlig sikrede enheter og uten noen form for sporing. Etaten oppdaget at mediene manglet først under kontroller i 2024 og 2026.
Vedtak av 25. august 2026. Den brasilianske myndigheten fant mangler ved aldersverifiseringen både i strømmen som er åpen uten registrering og i den med konto. I tillegg til gebyret: pålegg om å slette ulovlig innsamlede opplysninger og å sette profiler under 16 til den mest restriktive innstillingen som standard.
Vedtak av 18. juni 2026, offentliggjort 29. juli. En borger mottar reklame-e-poster uten noen gang å ha fylt ut medlemsskjemaet. Undersøkelsen viser at de som ikke bekreftet kontoopprettelsen likevel havnet i listene: dobbel bekreftelse fantes, men var ikke koblet til noe.
15. april 2026 vedtok EDPB utkastet til retningslinjer 1/2026 om vitenskapelig forskning. Den offentlige høringen ble avsluttet 25. juni, og den endelige teksten foreligger ennå ikke. Den som fører protokoller bør lese kapittelet om lagring: forskningsformålet alene begrunner ingen åpen frist.
SATS krevde at medlemmene hadde et bilde som lagres i medlemssystemet og brukes i resepsjonen for å kontrollere identiteten til dem som kommer inn. Datatilsynet fant at informasjonen oppga feil behandlingsgrunnlag, ikke forklarte retten til å protestere, og at innsigelser ble avvist uten å påvise tvingende berettigede grunner. Fristen for å rette opp er 11. september 2026.
25. august publiserte det svenske tilsynet veiledning om strømming av ungdomsidrett. Mange klubber sender barnekamper på nett, og veiledningen peker på faktorene som avgjør hva som er tillatt. Men den delen det er verdt å lese, er den andre: ansvaret når kommunen eier anlegget og klubben vil sette opp kameraene.
19. august oversatte det franske tilsynet sin anbefaling fra mai 2026 om vurdering av betalingsevne til allmennheten. Der står tre tall og ett prinsipp som angår alle som driver med scoring: tjuefire måneder for tidligere hendelser, seks måneder for opplysningene i en avslått søknad, og en innsynsrett i poengsummen som ikke lar seg avfeie med henvisning til forretningshemmeligheter.
14. august opplyste det franske finansdepartementet at skatteetatens informasjonssystem var rammet av et brudd på personopplysningssikkerheten: en tredjepart kunne se og hente ut opplysninger om privatpersoner og virksomheter. Brukernavn og passord ser ikke ut til å være berørt — og nettopp derfor ligger risikoen ikke i kontoovertakelse, men i phishing bygget på ekte skatteopplysninger.
24. august publiserte CNIL reglene for de digitale arbeidsrommene som brukes i skolen. Det avgjørende er ikke vernet av mindreårige, men et forvaltningsrettslig prinsipp: nøytraliteten i den offentlige utdanningstjenesten omfatter kommersiell nøytralitet, slik at sporere til reklame- eller profileringsformål i utgangspunktet er forbudt. Har verktøyet dem, må den behandlingsansvarlige slå dem av.
24. august publiserte CNIL to tekster om samme emne, én for skolen og én for universitetet. Den som bare leser den første og bruker den på den andre, tar feil på ett bestemt punkt: i skolen er reklamesporere «i utgangspunktet forbudt», i høyere utdanning «anbefaler» CNIL å foretrekke verktøy uten dem. Resten — behandlingsgrunnlag, vurdering av personvernkonsekvenser, databehandlerens garantier, overføringer — er sammenfallende.
Det er det nest høyeste gebyret som noen gang er ilagt etter personvernforordningen, bare bak Metas 1,2 milliarder. Saken gjelder verken overføring av opplysninger eller et sikkerhetsbrudd: den gjelder artikkel 22, regelen om automatiserte avgjørelser som nesten ingen dokumenterer fordi den ser ut som et problem for store plattformer. I virkeligheten gjelder den alle som lar programvare avgjøre noe som veier tungt i et menneskes liv.
I mange år ble Polen regnet som et marked med lav risiko for sanksjoner. Den forutsetningen holder ikke lenger: på tolv måneder gikk summen fra fjorten til over sekstifire millioner zloty, og de tre høyeste gebyrene i landets historie bærer alle samme årstall. Følger du en kunde med filial, leverandør eller servicesenter i Polen, er risikoregnestykket endret.
Vi stilte brukerne et enkelt spørsmål: når et krav fra tilsynet kommer, hvilke papirer henter du fram? Svaret inneholdt førtiseks kategorier uten egen skuff, som alle havnet i «Andre dokumenter». Vi har lagt dem til. Deretter måtte siden bygges på nytt, for syttisju grå fliser i et rutenett er verre enn trettién.
Et personvernombud prøvde plattformen i noen dager og skrev at avviksprotokollen, risikovurderingen, dokumentopplastingen og prisene manglet. Tre av de fire fantes allerede. Hun fant dem ikke fordi de ligger inne i klientmappen, og menyen viser dem ikke. Derav to tillegg: risikovurderingen, som faktisk manglet i protokollen, og et søkefelt som svarer på «avvik», «72 timer» eller «art. 33» og også sier hvor det du leter etter ligger.
Tilbakemeldingen kom fra et personvernombud i den gratis prøveperioden: «under sikkerhetstiltak kan jeg bare skrive». Hun hadde rett. Tiltak velges nå fra en katalog i ni grupper, kan fortsatt utfylles for hånd, og programmet løfter fram de relevante ved å se på opplysningskategoriene og overføringene. Opplysningskategoriene får også et beskrivende andre nivå, og mottakerlandet er ikke lenger et fritt felt.
Lagringsbegrensning er prinsippet som er vanskeligst å dokumentere under en gjennomgang, fordi svaret endrer seg for hver kategori opplysninger og hvert land. Plattformen inneholder 611 ferdigskrevne regler. Men poenget er ikke tallet: av 232 portugisiske regler har bare 99 en varighet som kan uttrykkes med et tall, og 95 er oppgitt som «løpende referanse» i stedet for «verifisert». Å si det er mer nyttig enn å skjule det.
En butikkjede går konkurs. De tidligere ansatte trenger sine egne timelister for å dokumentere ubetalt lønn, men den eneste som har dem er leverandøren av timeføringssystemet. Svaret er at selskapet ikke kan utlevere noe til noen – «ikke engang til de registrerte selv» – fordi avtalen med den behandlingsansvarlige er avsluttet. Datatilsynet konkluderte motsatt: er du den eneste som bestemmer over dataene, er du behandlingsansvarlig.
Å teste et nytt personalsystem med ekte data er ikke forbudt – å overføre flere felt enn testen trenger, er det. Den tyske arbeidsretten dømte en arbeidsgiver til å betale to hundre euro fordi lønn, privatadresse, skattenummer og sivilstand ble lastet opp, selv om partene hadde avtalt en liste på ni felt med de ansattes representanter. Og retten bekreftet at en forsinket innsynsbesvarelse ikke i seg selv er en skade.
Den som bare leste overskriften — «KI-forordningen utsettes» — arbeider på feil grunnlag. Datoen 2. august 2026 forsvant ikke: den endret innhold. Det som ble stående gjelder langt flere klienter enn det som ble utsatt.
Det manglet noe å gi til klienten som sier «vi har slått på KI-en i fagsystemet». Det nederlandske tilsynet har publisert en egenvurdering av generative KI-systemer: fire øyeblikk, og i hvert av dem en beslutning som må dokumenteres.
The Cyberbeveiligingswet entered into force on 15 August 2026. The number that matters is not eight thousand: it is one hundred and thirty-three thousand — the Dutch SMEs the law reaches not because they are in scope, but because they supply someone who is.
The first-half 2026 figures say two different things. The first is that the number of people notified is dominated by very few enormous incidents. The second, less comfortable for anyone assessing risk, is that AI appears in one breach in four.
On 10 August 2026 the CNIL set out in writing how to identify and resolve a conflict of interest affecting the DPO. The test is single: if in their other duties the DPO determines the purposes and means of a processing operation, they cannot then supervise it. No one can be judge and party.
On 5 August 2026 the CNIL clarified the boundaries of a right that is often exercised and widely misunderstood. Against a press organisation, objection and erasure remain available; access and rectification do not. And a refusal must be reasoned concretely: six generic formulas are named as inadmissible.
Each year the EDPB picks a topic and every national authority checks it together, in the same period, through questionnaires and inspections. For 2026 the topic is transparency: how controllers tell people what happens to their data. In scope are Article 13, where data comes from the data subject, and Article 14, where it comes from elsewhere. The Czech authority has already written the theme into its inspection plan.
On 24 July 2026 the Portuguese authority approved its multiannual plan for 2027-2029 and its 2027 activity plan. It is the kind of document almost nobody reads and which says, years in advance, where supervision will concentrate: digital training, digital vulnerability, regulatory capacity for the DSA, AI competences and neurodata.
By Decision 2022/1072 the Portuguese CNPD imposed a single fine of EUR 4.3 million on INE for five infringements committed during the 2021 census. The most instructive is not the one about health and religious data: it is that INE, although the supplier had an office in Lisbon, contracted with the US-based company, accepting California jurisdiction and the routing of data across two hundred servers, with standard contractual clauses and no supplementary measures.
In Case C-621/22 the Court of Justice held that a commercial interest can constitute a legitimate interest under Article 6(1)(f). Many people read only that line. The rest of the judgment recalls that the conditions remain three and cumulative, and that the third - the balancing against the data subject's reasonable expectations - is where the case at hand was lost. For the DPO the consequence is practical: legitimate interest exists only if it is written down somewhere.
Regulatory fines make the headlines; civil claims pay the lawyers. Since 2023 the Court of Justice has held that compensation under Article 82 requires three cumulative elements - infringement, damage, causal link - with no threshold of seriousness. It has also held that a well-founded fear that your data has fallen into the wrong hands is already non-material damage. For the controller this moves the battleground: not the gravity of the harm, but proof of the measures in place.
After the DSA and before the DMA and the AI Act, the fourth piece of the European regulatory mosaic concerns the relationship between competition and data protection. This is not theoretical: it touches data as a market asset, mergers, and the position of those who process data because they dominate a market. The EDPB and the Commission are asking for input before they write, and this time the deadline is close.
On 1 July 2026 the EDPB and the European Anti-Money Laundering Authority announced joint guidelines on a question neither could solve alone: how banks, professionals and authorities can share information about suspicions without building unchecked lists of suspects. The possibility applies from 10 July 2027 and the public consultation is expected in the first half of that year. Anyone advising obliged entities has a year to prepare.
The number and complexity of complaints are rising, partly because of increased use of AI, and authorities say openly that resources are not enough. The solutions on the table: joint operations, pooling resources between authorities, and the upcoming Procedural Regulation.
The lead authority wanted to close the case claiming abuse of Art. 77 and Art. 80(1). The Austrian DPA objected and the EDPB agreed: neither the objective nor the subjective component of abuse was demonstrated. The complaint goes back and must be assessed on the merits.
On 9 July 2026 the CNIL updated its page on monitoring staff activity. The content looks like revision, but there is one point that practice keeps underrating: the conditions are three, they are cumulative, and two of the three have nothing to do with how intrusive the tool is.
On 3 July 2026 the French labour ministry, the AFCDP and the CNIL published the fifth edition of the DPO Profession Observatory, carried out by the Afpa. The easy reading is that DPOs are becoming the AI point of contact. The useful reading is different: between those who want the AI Act in their remit and those who say they know it there is a 44-point gap, and the AI Act never mentions the DPO at all.
On 24 June 2026 the Austrian Verwaltungsgerichtshof closed proceedings pending since 2019, reducing to EUR 13 million the fine for processing 'party affinities' calculated for around 2.2 million people. The headlines will be about the discount. For a DPO what matters is the rest: the Court says that punishing a legal person requires no act by its management bodies, that having resources to take advice raises the bar rather than lowering it, and that the charges on the DPIA and the record of processing fall away by absorption - not because those documents were correct.
On 26 January 2026 the Swedish authority fined Sportadmin i Skandinavien AB SEK 6,000,000 for breaching Article 32(1). The platform handles memberships, invoicing and websites for sports clubs: the 16 January 2025 attack exposed the data of 2,126,075 people, mostly children, including allergies and disabilities. But the passage worth reading twice is another one: since 2021 the company had identified the risk of SQL injection in its own annual reviews, and IMY cites exactly that to establish gross negligence.
The Dutch government has designated the Autoriteit Persoonsgegevens and the Rijksinspectie Digitale Infrastructuur as coordinating national supervisors for the AI Act. The 2026 work agenda lists five priorities: overarching system supervision, transparency and explainability, frameworks and standards, testing for bias and fairness against discrimination, and AI literacy. The first formal enforcement actions are expected during 2026, starting with organisations using prohibited practices or demonstrably neglecting the AI literacy obligation.
In the review published on 6 July 2026 the CNIL counts 23 new fines adopted since January under its simplified procedure, totalling EUR 133,750. Three infringements recur: excessive video surveillance, non-compliant cookie banners, and failure to respond to access and erasure requests. One example of the kind of target: EUR 7,500 against a company operating public toilet facilities, on 2 April.
On 26 May 2026 the CNIL's restricted committee fined IQVIA Operations France EUR 5 million. The company runs two health data warehouses for third-party studies: LRX, authorised in 2018 and fed by around 14,000 pharmacies, and EMR, authorised in 2021 and fed by several thousand doctors. Among the findings, the most instructive: the practice management software used in pharmacies transmitted customer data to IQVIA even where the customer had objected.
On 12 June 2026 the Korkein hallinto-oikeus, Finland's Supreme Administrative Court, dismissed Verkkokauppa.com's appeal against the penalty imposed by the Finnish Data Protection Ombudsman's sanctions board (decision KHO 12.6.2026/1604). The original amount was EUR 856,000, reduced by the Administrative Court to EUR 792,639 on the basis of the company's most recent turnover. The finding does not concern a data breach: it concerns the fact that the company had never defined retention periods for customer account data.
On 25 May 2026 the President of the UODO fined the mayor of Myslenice PLN 7,700. An un-anonymised petition had been published in the municipality's Public Information Bulletin: names, surnames, home addresses and signature specimens of 749 people. The core of the decision is not the publication, which the municipality corrected by replacing the file: it is that the breach was never notified to the authority, not even after the authority asked.
On 29 July 2026 the Administrative Jurisdiction Division of the Raad van State dismissed the appeal of the Autoriteit Persoonsgegevens against the municipality of Enschede, upholding the February 2024 judgment of the Overijssel District Court. The EUR 600,000 fine, imposed in March 2021 for counting city-centre visitors through sensors capturing the MAC addresses of wifi-enabled devices, remains annulled. The reason is not that the tracking was lawful: it is that the authority did not sufficiently demonstrate that the MAC addresses collected qualified as personal data and that processing of personal data had therefore taken place.
On 22 June 2026 the President of the UODO, Miroslaw Wroblewski, closed the proceedings opened after a breach notification by Energa-Obrot: reprimands for the controller and the processors, and an administrative fine of PLN 10,145 for one of the processors. At the root of it, the use of WhatsApp by sales representatives of a door-to-door network during the pandemic: on a former agent's private phone there were scans and photographs of customer contracts, in group conversations, for many months.
On 8 May 2026 the Irish Data Protection Commission closed its inquiry into a series of personal data breaches at Permanent TSB, first notified in May 2022. Malicious actors, holding certain customer information, called the Open24 contact centre posing as customers, gained access to accounts and amended account details. Some customers lost money. The authority issued a reprimand and fines totalling EUR 277,500.
The Autoriteit Persoonsgegevens has set three strategic priorities for 2026-2028: mass surveillance, artificial intelligence and digital resilience. In its 2026 annual plan the authority states that it is allocating more capacity to AI and algorithms and will concentrate on large-scale systems with significant societal impact, without distinguishing between the public and private sectors. For anyone with clients in the Netherlands, or considering that market, it is the most useful piece of information of the year - and it costs nothing.
The Dutch Autoriteit Persoonsgegevens has increased its budget and headcount and has named transparency, tracking and cookies among its 2026 supervisory priorities, with an approach that is openly less advisory and more enforcement-driven. In Poland the President of the UODO has shifted attention towards small and medium enterprises, a segment until recently little touched by inspections. For anyone with clients in those countries, or considering it, these are two signals that change the cost-benefit balance of compliance.
The Italian data protection authority has fined Piaggio & C. Spa 460,000 euro over the way the company managed employee email accounts. The investigation, opened after complaints by two former employees, established that 112 emails had been acquired during the employment relationship, some dating from roughly two years before any suspicion arose, made possible by backups retained for the whole duration of employment and up to five years after termination. Alongside the fine, the authority banned the company from accessing the data it had collected.
The Italian data protection authority has issued a favourable opinion on the draft legislative decree implementing the AI Act in Italy. The decree sets out national governance and designates the authority as market surveillance authority for high-risk AI systems used in the areas most sensitive for fundamental rights: justice, law enforcement, immigration, border management and democratic processes. Among the conditions attached, one concerns any organisation: extending the ban on decisions based solely on automated systems to assessments affecting the employment relationship.
Following a data breach notification and a complaint, the Italian data protection authority fined the Metropolitan City of Sassari for misconfiguring its electronic document register, making documents containing personal data accessible to staff who, given their role and duties, were not authorised to process them. The fine is 12,000 euro, but the principle applies to every public body and every company running a document management system: filing is not a neutral activity, and a default of total visibility breaches the principles of integrity and confidentiality.
For two years 2 August 2026 was presented as the day obligations for high-risk AI systems would start. The Digital Omnibus package changed that calendar: requirements for Annex III high-risk systems move to 2 December 2027 for stand-alone systems and 2 August 2028 for those embedded in products already covered by sectoral legislation. 2 August nonetheless remains an operative date: the transparency obligations of Article 50 become applicable, together with the full operation of governance and penalties, with national authorities acquiring full powers.
The Danish authority has flagged cookie consent as a supervisory priority for 2026, coordinating with the Digitaliseringsstyrelsen, which oversees the ePrivacy implementation while Datatilsynet applies the GDPR. But Denmark has a peculiarity that changes how every one of its decisions should be read: its constitutional order does not allow an administrative authority to impose punitive financial penalties. Recital 151 GDPR expressly anticipates this for Denmark and Estonia: the fine is decided by a court as a criminal penalty, following a report by the authority to the police.
With deliberation no. 2026-042 of 12 March 2026, made public on 14 April, the French CNIL adopted its final recommendation on email tracking pixels: for most marketing uses, prior consent is required, just as for cookies. Existing contact bases were given three months to inform recipients and allow them to object, a period that ended on 14 July 2026, with checks announced from that date. In Italy the authority reached the same conclusion with decision no. 284 of 17 April 2026, but with a longer compliance window.
The Italian DPA fined Wind Tre EUR 1,715,600 (decision no. 348 of 14 May 2026, made public with the 16 July newsletter). The starting point was not a sophisticated cyberattack: people posing as support technicians convinced staff at two retail outlets to allow access to company systems. From there, identification and contact data of 365,048 customers were exfiltrated; for 41,359 of them, payment method information as well, including IBANs, postal payment slips and credit cards with partially masked numbers and expiry dates. The charges: breach of the integrity and confidentiality principle (Art. 5(1)(f)) and of security obligations (Art. 32(1)(b)).
In January 2026 the CNIL fined American Express EUR 1.5 million for cookie violations, confirming that the topic remains a standalone enforcement priority alongside artificial intelligence and cybersecurity. In 2025 there had been 21 cookie decisions, totalling over EUR 475 million. The recurring charges are always the same: trackers set before consent, a reject button less visible or further away than the accept button, inadequate information.
A customer had asked to access their own data contained in a recorded call with customer service. The company refused, considering the protection of the agent's confidentiality to prevail. The authority held that the request could be satisfied by providing the transcript, provided the elements identifying other people involved are redacted: given the professional context of the call and its subject, a supply contract, redaction would not have prejudiced the agent's confidentiality.
At its July 2026 plenary, the European Data Protection Board adopted guidelines on anonymisation and on web scraping in the context of generative artificial intelligence, together with the final version of the guidelines on processing personal data through blockchain technologies. Three documents addressing three recurring questions: when data is truly anonymous, on what conditions data may be collected from the web to train models, and how the immutability of a chain can be reconciled with data subjects' rights.
The Spanish authority fined Amadeus IT Group EUR 18 million (reduced to 14.4 with voluntary payment) for aggregating travellers' booking data into profiles for product development. The cross-border investigation found the reuse of data collected years earlier from airlines and agencies, for purposes data subjects could not reasonably expect, without an Article 14 notice and without a valid legitimate-interest balancing test.
The Norwegian authority concluded proceedings opened after an audit of the Nordic entities of a retail group, finding several breaches relating to its loyalty programme: invalid consent, new processing purposes introduced without assessment, insufficient legitimate-interest balancing, and failure to answer data subject requests within the deadline. More than six million members across the Nordic region were affected.
With three decisions adopted in the same session on 3 July 2026, the Italian DPA targeted the credit-scoring chain applied to energy supply contracts: Experian Italia, Hera Comm and Cerved. The charges are similar and paint a clear picture: deficient notices, breaches of minimisation and storage limitation, privacy by design and by default disregarded, inadequate responses to access requests and poorly governed Article 28 relationships along the chain.
A preliminary requirement that almost everyone overlooks is back in the spotlight: Article 4 of Legislative Decree 24/2023 requires internal reporting channels to be activated after hearing worker representatives or trade unions. The ANAC guidelines clarify that failing to do so makes the procedure non-compliant and may trigger a sanction under Article 21. It also applies to substantial updates, not just first activation.
In its 16 July 2026 newsletter the Italian DPA announced a EUR 1.7 million fine to telecom operator Wind Tre following a data breach with exfiltration of roughly 365,000 customers' data. The case confirms the authority's line on large operators: the incident itself is not the fault - the fault lies in security measures inadequate to the risk (Art. 32) and in how the breach was handled. In the same newsletter: two debt-collection companies fined (EUR 50k and 30k) and the customer's right to access the audio of their own support calls (Enel case).
With a decision of 3 July 2026 (announced 9 July) the Italian DPA fined Character Technologies Inc., the US company behind Character.AI, EUR 158,000: deficient privacy notice (Arts. 12-14), a DPIA prepared late relative to the service launch, late designation of the EU representative (Art. 27) and shortcomings in minor protection and age verification. Beyond the fine, corrective measures within 120 days: working age verification, an effective cooling-off period against re-registration by blocked minors, minors' profiles private by default.
In its 17 June 2026 newsletter the Italian DPA restated a principle that matters well beyond family disputes: publishing photos of minor children on social media requires the consent of BOTH parents. In case of disagreement, the child's protection prevails. For the DPO it is an operational criterion affecting schools, nurseries, sports clubs, parishes and companies publishing images of minors for promotional purposes.
In a notice addressed to the hospitality sector, the Italian DPA reiterated that hoteliers may not keep copies of guests' identity documents: the legal duty (Art. 109 of the Italian public-security code) is to identify the guest and transmit the data to the police via the Alloggiati Web portal - after that, document copies must be destroyed or deleted. A widespread habit becomes a concrete sanction risk.
The EDPB has opened a public consultation on a new harmonised data-breach notification template, designed to align the information requested by authorities across Member States. For DPOs it is operational news: the content of the Art. 33 notification is becoming standardised, and anyone with a structured internal procedure (facts, categories, risk assessment, measures) will find the work already done.
With decision no. 170/2026 the Italian DPA fined Enel Energia EUR 563,052: during purely administrative contacts (supply paperwork, takeover confirmations), including via third parties, commercial offers were made without a valid legal basis - even to customers on the opt-out register or who had expressly refused marketing consent. Also challenged: a re-contact mechanism based on opt-out (an SMS with 90 seconds to refuse) and partner vetting - one agency was contracted two months after being sanctioned by the DPA for marketing.
With injunction order no. 419 of 28 May 2026 the Italian DPA declared unlawful certain personal data processing carried out by AgID - the Agency for Digital Italy, with a EUR 55,000 fine and publication of the decision on the authority's website. The breaches concern lawfulness, fairness and purpose limitation (Art. 5), information duties towards data subjects (Arts. 12 and 14) and data protection by design (Art. 25).
With decision no. 342 of 2026, the Italian DPA reaffirmed that data on employees' health or psychological journey cannot be made accessible to the employer, not even in aggregate form. The case closes the loop with the AI Act, which expressly prohibits AI systems that infer people's emotions in the workplace (Art. 5): organisational wellbeing cannot turn into emotional surveillance.
In July 2026 Trenitalia informed its customers of a data breach suffered roughly eight months earlier. Beyond the outcome, the case is a textbook lesson on the difference between notifying the authority within 72 hours (Art. 33) and communicating to data subjects 'without undue delay' when the risk to their rights is high (Art. 34): eight months are hard to justify, and in the meantime the persons affected could not protect themselves.
On 2 July 2026 the Italian DPA presented its 2025 activity report to Parliament: 807 collegial decisions, 506 corrective and sanctioning measures, over EUR 37.7 million in fines collected (+54.5% on 2024), 2,415 data breaches notified (+10%), 130 inspections. AI takes centre stage: from DeepSeek to deepfakes, from facial recognition at the airport to worker surveillance.
With a decision of 29 April 2026, the Italian DPA fined Lepida (EUR 100,000), one of Italy's main SPID identity providers: over 7,000 counter operators could view data and download copies of ID documents and health cards of more than 1.5 million citizens, even with no operational need. The DPA found accesses 'out of mere curiosity' and documents left stored on operators' workstations after identification.
On 29 June 2026 the EU Council approved the proposed regulation that streamlines and simplifies certain AI rules, amending the AI Act (the 'Digital Omnibus' package). Negotiations with Parliament continue: until final adoption, the current AI Act text remains the reference, including the August 2026 transparency deadlines.
The Italian DPA fined Emirates EUR 180,000 over the handling of reduced-mobility passengers' health data. The case started from a complaint by a passenger asked to fill in a medical form despite not being in the categories required to do so. The key point for DPOs: the collection itself was lawful, but the authority faulted an inadequate notice and excessive retention (7 years).
With decision no. 311 of 29 April 2026, the Italian DPA found unlawful the employer's use of data collected through the loyalty card to support an employee's dismissal. That data had been collected to run the loyalty programme, not to monitor or discipline staff. The point for DPOs: having a piece of data does not mean you can use it for any purpose.
For 2026 the EDPB chose TRANSPARENCY as the topic of its coordinated enforcement action: authorities will examine how organisations inform data subjects under Art. 12-14. In short: clear, complete, verifiable notices. A good moment to review your clients' documents.
Cumulative GDPR fines have passed EUR 7.1 billion across 1,400+ decisions. Enforcement is accelerating, not plateauing. And contrary to a common myth, SMEs do get fined: smaller amounts, same proportional severity.
In France the authority (CNIL) fined IQVIA EUR 5 million, clarifying a point many confuse: pseudonymising data - even health data - is not the same as anonymising it. Pseudonymised data remains personal data and must be handled with all the safeguards of the Regulation, including the enhanced ones in Art. 9.
The Rome Court annulled the EUR 15M fine the Italian Garante imposed on OpenAI in 2024. The judge does not rule on the merits (legal basis, notice, age verification): it upholds the jurisdiction argument. For cross-border processing the one-stop-shop and lead authority govern.
The Italian Garante set its 2026 inspection areas, backed by the Finance Police tech-fraud unit. Topics include data breaches in public databases and abusive access. Those who document self-assessment and lesson learning get treated differently.
The CNIL fined France Travail (formerly Pole Emploi) EUR 5 million after a breach exposing the data of around 36.8 million people. Attackers used social engineering against partner advisers' accounts. The lesson: having security plans is not enough, they must actually be implemented.
The CNIL fined software vendor Nexpublica EUR 1.7 million: its PCRM tool, used by social services, exposed sensitive documents (including disability data) to other users. The flaws were known from prior audits but left open. A textbook case for anyone processing health data.
The Spanish Data Protection Agency fined Aena over EUR 10 million for launching its biometric boarding programme without completing an adequate DPIA. Not a data breach: a failure of preventive accountability.
The Autoriteit Persoonsgegevens confirmed the EUR 290 million fine against Uber for unlawful transfers to the US. Meanwhile the Authority sets three strategic priorities for the next two years every DPO should know.
The Italian DPA fined The European House - Ambrosetti spa EUR 85,000 following a 2024 data breach affecting 61,670 people. The attack, via a technical vulnerability, led to the exfiltration of names, emails, usernames and passwords. The point for DPOs: the breach was notified to the regulator within 72 hours, but data subjects were informed only after two months and after the authority stepped in.
The European Data Protection Board has launched the 2026 coordinated action on transparency and information obligations. 25 national DPAs (including the Italian Garante) are already contacting controllers in various sectors. What to expect and how to prepare.
The Italian DPA (Garante) issued a general provision banning Italian public administrations from using WhatsApp, Telegram, Messenger and other commercial messaging apps for operational communications with citizens. Banned also for requesting documents, certificates or personal data. PAs must use institutional channels (PEC, portals, SPID-auth) by July 1, 2026. Fines up to 100,000 EUR.
The Spanish Data Protection Agency is the first European Authority to publish elaborate guidance on agentic AI. It explains the concept, the vulnerabilities in processing personal data and mitigation measures for controllers and processors.
The German Federal Commissioner for Data Protection (BfDI) imposed a total fine of EUR 45 million on Vodafone GmbH: 15M for Art. 28 violation (processor oversight) and 30M for Art. 32 (security). A decision that redefines accountability expectations on processors.
After the NIS2 transposition with Legislative Decree 138/2024, Italian companies qualified as 'essential entities' or 'important entities' must coordinate NIS2 obligations (cyber security, 24h incident reporting) with GDPR obligations (72h data breach). The DPO is not the NIS Coordinator but must interface: risk of double sanctions if not properly orchestrated.
The EDPB clarifies how to process the professional data of DPOs exposed publicly on online directories: legal basis, purposes, data subject rights and platform responsibilities.
The EU AI Act enters its critical phase: August 2026 triggers obligations for high-risk systems. The Italian Garante has already anticipated enforcement with the EUR 5M fine to Luka (Replika). What DPOs must do now.
In less than 3 months, the AI Act sections dedicated to deployers (users) of high-risk AI systems enter into force. The DPO becomes a key interlocutor for impact assessment, data subject information and monitoring.
The Italian Data Protection Authority addresses the management of corporate emails after employment termination. ITAS Mutua sanctioned for undocumented access and retention beyond necessary.
The Irish Supreme Court confirms the suspension of the record 530M EUR fine imposed by the DPC on TikTok for EEA data transfer to China. The case exposes the structural problem of enforcement timing against big tech.
On April 17, 2026, the Italian DPA adopted Guidelines on tracking pixels in emails. For DPOs: 6 months to align privacy notices, consent flows, and privacy-by-design techniques.
The Italian Data Protection Authority fines Intesa Sanpaolo for a data breach affecting 2.4 million customers. Late notification and incomplete information among the key issues.
The Rome Court annuls the fine that the Italian DPA had imposed on OpenAI for the ChatGPT case. A decision that redefines the scope of GDPR enforcement on generative AI models.
The Italian DPA fines Enel Energia for promotional calls to subjects who had not provided consent or had registered their number in the public opposition register.
With its January 17, 2026 ruling, the Italian Supreme Court confirms that the 120-day deadline for concluding the DPA's enforcement proceedings is final. A relevant decision for those handling privacy litigation.
EDPB publishes the results of the coordinated enforcement action: insufficient resources, lack of access to top management, conflict of interest risk. A snapshot that also concerns Italian external DPOs.
France's State Council confirms CNIL's approach on pseudonymized health data. A ruling that redefines the practical scope of GDPR anonymization and impacts all data analytics projects.
The European Data Protection Supervisor (EDPS) adopts new binding rules to protect DPO independence within Union institutions. A signal strengthening the role.
EDPB and EDPS publish the joint opinion on the EU Commission's Digital Omnibus package. Positive measures on data breach and DPIA, but strong opposition to the revision of the personal data definition.
The Italian DPA published its inspection activities plan for January-June 2026. Sectors at risk: banking data breaches, health dossiers, energy telemarketing, and AI in schools.
The French Authority separately fines Free Mobile (27M) and Free (15M) for a breach that exposed 24 million subscribers in October 2024. A decision that clarifies the scope of Art. 34 GDPR.