As suas preferências de cookies

Orientações do CEPD · art. 7.º do RGPD

Utilizamos cookies técnicos essenciais para o funcionamento da plataforma (início de sessão, segurança, sessões). Gostaríamos de utilizar também cookies analíticos para perceber como melhorá-la.

Pode aceitar tudo, rejeitar tudo, ou escolher que categorias ativar.O seu consentimento é válido 6 meses e pode retirá-lo a qualquer momento no rodapé.

Encontra tudo na nossa política de privacidade.

Privacy and GDPR news

Curated updates: Italian DPA decisions, EDPB rulings, fines and regulatory news. Analyzed from a working DPO's perspective.

Legislação
2027e contém duas oposições, não uma

O espaço europeu de dados de saúde aplica-se dentro de pouco mais de seis meses, e as duas oposições que contém não são a mesma coisa

Não substitui o RGPD, acrescenta-se-lhe. Para quem mantém o registo de um cliente da área da saúde, as datas a anotar são quatro, não uma, e a primeira ocorre dentro de menos de sete meses.

03/09/2026Novo 7 min
Legislação
57o artigo cujo prazo acabou de terminar

A 2 de agosto expirou a obrigação de ter um ambiente de testagem nacional para a IA, e lá dentro podem tratar-se dados recolhidos para outra coisa

É o único ponto do direito da União em que a reutilização de dados pessoais para treinar um modelo está expressamente prevista. As condições são sete e têm de estar todas preenchidas em conjunto.

02/09/2026Novo 6 min
Legislação
9estudos de caso, seis de sistema e três de empresa

Os riscos psicossociais entram na campanha europeia, e o EPD tem mais que ver do que julga

A saúde mental no trabalho está a tornar-se prevenção obrigatória, não bem-estar voluntário. E o momento em que uma empresa mede o bem-estar dos seus trabalhadores é o momento em que começa a tratar dados de saúde, quase sempre sem dar por isso.

27/08/2026Novo 6 min
Coima
2milhões a quem vendia contactos nunca cedidos

Dois milhões a um data broker americano: o interesse legítimo não cobre a venda de contactos

A sociedade é norte-americana e não tem estabelecimento em Itália, mas o Regulamento aplicou-se na mesma. Além da coima, a proibição de tratar dados de pessoas que se encontram em Itália e a ordem de eliminar os recolhidos ilicitamente.

27/07/2026Novo 6 min
Legislação
3autoridades diferentes para uma só lei

Regulamento IA: quem fiscaliza o quê, e porque as «primeiras coimas» que circulam não existem

O Serviço de IA trata dos modelos de finalidade geral, as autoridades nacionais de tudo o resto, a AEPD das instituições europeias. Saber perante quem responde um cliente vem antes de saber quanto arrisca. E antes disso vem distinguir os poderes que se tornaram exercíveis dos que foram exercidos.

04/08/2026Novo 7 min
CEPD / AEPD
1balcão único para notificar violações

Um só balcão para notificar violações: o que pediram o CEPD e a AEPD sobre o pacote de cibersegurança

Notificar uma violação hoje significa escrever a várias autoridades com formatos diferentes nos mesmos três dias. O Comité e a Autoridade Europeia apoiam o balcão único e põem limites à ENISA, à certificação e à relação entre segurança e direitos fundamentais.

19/03/2026Novo 6 min
Legislação
7sites que preferiram desaparecer

Sete sites desligaram o Reino Unido em vez de protegerem os menores

O regulador britânico contou o que acontece antes das investigações formais. Postas perante a escolha entre tornar o serviço seguro ou deixarem de ser acessíveis a partir do Reino Unido, sete plataformas escolheram a segunda. É uma vitória, mas também diz como sai barato ir embora.

28/08/2026Novo 5 min
Coima
1,17 Mfichas digitalizadas, e ninguém sabia onde estavam

Um milhão e meio de histórias de adoção em suportes que ninguém sabia já onde estavam

O caso mais grave nasce da digitalização dos arquivos em papel entre 2013 e 2022: mais de 1,17 milhões de fichas, das quais 1,14 milhões sobre adotados e cerca de 30.000 sobre crianças desaparecidas, em dispositivos mal protegidos e sem qualquer registo dos seus movimentos. A entidade só deu pela falta dos suportes durante os controlos de 2024 e de 2026.

28/08/2026Novo 5 min
Coima
153,7milhões de reais, por uma idade declarada pelo próprio

No Brasil, perguntar a idade e acreditar na resposta custou 153,7 milhões de reais

Decisão de 25 de agosto de 2026. A autoridade brasileira apontou falhas no mecanismo de verificação de idade tanto no feed acessível sem cadastro como no feed com conta. Além da multa, a ordem de eliminar os dados recolhidos irregularmente e de configurar por omissão os perfis de menores de 16 anos na definição mais restritiva.

25/08/2026Novo 5 min
Coima
280.000euros por uma conta nunca confirmada

O utilizador não confirmou a conta: para a autoridade italiana não há contrato e os e-mails são ilícitos

Decisão de 18 de junho de 2026, divulgada a 29 de julho. Um cidadão recebe e-mails promocionais sem nunca ter preenchido o formulário de sócio. Da instrução resulta que quem não confirmava a criação da conta acabava na mesma nas listas: a dupla confirmação existia, mas não estava ligada a nada.

29/07/2026Novo 6 min
CEPD / AEPD
171parágrafos, e um deles fala dos seus registos

«Conservamos para fins de investigação»: o CEPD explica porque isso não é uma resposta

Em 15 de abril de 2026 o CEPD adotou em projeto as Orientações 1/2026 sobre investigação científica. A consulta pública encerrou a 25 de junho e o texto definitivo ainda não saiu. Quem preenche registos deve ler o capítulo da conservação: a finalidade de investigação, por si só, não justifica um prazo aberto.

15/04/2026Novo 7 min
Coima
26reclamações, e nenhuma coima

Declara-se o contrato e depois rejeitam-se as oposições: a Noruega mostra como os dois erros viajam juntos

A SATS pedia aos sócios uma fotografia guardada no sistema de gestão e usada na receção para verificar a identidade de quem entra. A Datatilsynet apurou que a informação indicava um fundamento errado, não explicava o direito de oposição, e que as oposições eram rejeitadas sem demonstrar razões imperiosas e legítimas. O prazo para corrigir é 11 de setembro de 2026.

26/08/2026Novo 6 min
Legislação
26o artigo que ninguém assina antes de transmitir

Quem responde pela transmissão do jogo dos sub-14? A Suécia responde à pergunta que ninguém faz

A 25 de agosto a autoridade sueca publicou orientações sobre a transmissão do desporto juvenil. Muitos clubes transmitem online os jogos das crianças, e o documento indica os fatores que decidem o que é permitido. Mas a parte que vale a pena ler é a outra: a responsabilidade quando o município é dono da instalação e o clube quer instalar as câmaras.

25/08/2026Novo 5 min
Legislação
24meses para além dos quais um incidente já não se usa

A pontuação com que lhe recusam o crédito pode ser pedida, e tem de ser explicada

A 19 de agosto a CNIL traduziu para o público a sua recomendação de maio de 2026 sobre a avaliação da solvabilidade. Lá dentro estão três números e um princípio que dizem respeito a quem faz scoring: vinte e quatro meses para os incidentes passados, seis meses para os dados de um pedido recusado, e um direito de acesso à pontuação que não se despacha invocando o segredo comercial.

19/08/2026Novo 6 min
Tech & IA
0palavras-passe roubadas, e é esse o problema

Roubados os dados fiscais franceses, e nenhuma senha: é isso que torna o caso perigoso

A 14 de agosto o ministério da Economia francês comunicou que o sistema de informação da administração fiscal tinha sofrido uma violação de dados: um terceiro conseguiu consultar e extrair informação de particulares e empresas. Os identificadores e as palavras-passe não parecem afetados — e é precisamente por isso que o risco não é o acesso às contas mas o phishing construído sobre dados fiscais verdadeiros.

18/08/2026Novo 5 min
Legislação
2critérios do CEPD e a AIPD torna-se obrigatória

Na escola os rastreadores publicitários são proibidos, e não é uma questão de consentimento

A 24 de agosto a CNIL publicou as regras para os espaços digitais de trabalho usados nas escolas. O que decide não é a proteção dos menores mas um princípio de direito administrativo: a neutralidade do serviço público de educação inclui a neutralidade comercial, pelo que os rastreadores para fins publicitários ou de definição de perfis são em princípio proibidos. Se a ferramenta os tiver, o responsável tem de os desativar.

24/08/2026Novo 6 min
Legislação
2documentos sobre a mesma matéria, com uma regra diferente

Mesma ferramenta, mesmo dia, regra diferente: porque na universidade os rastreadores não são proibidos

A 24 de agosto a CNIL publicou dois textos sobre a mesma matéria, um para a escola e outro para a universidade. Quem lê só o primeiro e o aplica ao segundo erra num ponto preciso: na escola os rastreadores publicitários são «em princípio proibidos», no ensino superior a CNIL «recomenda privilegiar» ferramentas que não os usem. O resto — fundamento de licitude, AIPD, garantias do subcontratante, transferências — coincide.

24/08/2026Novo 5 min
Coima
825 mln €a segunda coima mais alta de sempre

Oitocentos e vinte e cinco milhões por um algoritmo que desativava contas sem ninguém olhar

É a segunda coima mais alta alguma vez aplicada ao abrigo do RGPD, atrás apenas dos 1,2 mil milhões da Meta. Não trata de uma transferência de dados nem de uma violação de segurança: trata do artigo 22.º, a norma sobre decisões automatizadas que quase ninguém documenta por parecer coisa de grandes plataformas. Diz respeito, na verdade, a quem quer que deixe um software decidir algo que pesa na vida de uma pessoa.

24/08/2026Novo 5 min
Coima
64 mln złcontra 14 no ano anterior

A Polónia quadruplicou as coimas num ano, e as três mais altas de sempre são todas de 2025

Durante anos a Polónia foi tida como um mercado de baixo risco sancionatório. Esse pressuposto deixou de valer: em doze meses o total passou de catorze para mais de sessenta e quatro milhões de zlótis, e as três coimas mais altas da história do país têm todas o mesmo ano. Se acompanha um cliente com filial, fornecedor ou centro de serviços na Polónia, o cálculo do risco mudou.

24/08/2026Novo 4 min
Legislação
77áreas documentais

Setenta e sete gavetas: o que um EPD arquiva de facto, e porque trinta e uma não chegavam

Fizemos uma pergunta simples a quem usa a plataforma: quando chega um pedido da autoridade, que papéis tira? A resposta continha quarenta e seis categorias sem gaveta própria, que iam todas parar a «Outros documentos». Acrescentámo-las. Depois foi preciso refazer a página, porque setenta e sete quadrados cinzentos em grelha são piores do que trinta e um.

24/08/2026Novo 6 min
Plataforma
29destinos alcancaveis escrevendo uma palavra

O risco avalia-se dentro do registo, e cada funcionalidade está a uma palavra de distância

Uma EPD experimentou a plataforma durante alguns dias e escreveu que faltavam o registo de violações, a avaliação do risco, o carregamento de documentos e os preços. Três das quatro já lá estavam. Não as encontrou porque ficam dentro da ficha do cliente, e o menu não as mostra. Daí dois acrescentos: a avaliação do risco, que realmente faltava no registo, e uma barra de pesquisa que responde a «violação», «72 horas» ou «art. 33.º» dizendo também onde está o que procura.

23/08/2026Novo 5 min
Plataforma
35medidas do art. 32.º no catálogo

As medidas de segurança já não se reescrevem à mão

O reparo veio de uma EPD durante o período de experiência gratuito: «nas medidas de segurança só posso escrever». Tinha razão. As medidas escolhem-se agora num catálogo dividido em nove grupos, continuam a poder ser completadas à mão, e o programa destaca as pertinentes olhando para as categorias de dados e para as transferências. Mudam também as categorias de dados, com um segundo nível descritivo, e o país de destino, que deixa de ser um campo livre.

22/08/2026Novo 4 min
Plataforma
611regras legais, nove ordenamentos

Durante quanto tempo se conservam os dados: 611 regras, nove ordenamentos e um método

A limitação da conservação é o princípio que pior se demonstra numa verificação, porque a resposta muda para cada categoria de dados e cada país. A plataforma integra 611 regras já escritas. Mas o essencial não é o número: de 232 regras portuguesas apenas 99 têm uma duração exprimível por um número, e 95 são declaradas «referência corrente» em vez de «verificado». Dizê-lo é mais útil do que escondê-lo.

22/08/2026Novo 5 min
Coima
80pedidos de acesso recusados

O cliente vai à falência, o fornecedor fica sozinho com os dados: e passa a ser responsável pelo tratamento

Uma cadeia de lojas vai à falência. Os ex-trabalhadores precisam dos seus registos de horas para documentar salários em atraso, mas o único que os detém é o fornecedor do software de registo de tempos, que responde não poder comunicar nada a ninguém — «nem sequer aos próprios titulares» — porque o contrato com o responsável terminou. A autoridade norueguesa decidiu o contrário: quando fica só você a decidir sobre os dados, o responsável é você.

21/08/2026Novo 4 min
Jurisprudência
200 €pela perda de controlo

Dados reais dos trabalhadores no software em teste: quanto vale a perda de controlo

Testar um novo sistema de gestão de pessoal com dados reais não é proibido: proibido é transferir mais campos do que o teste exige. O Tribunal Federal do Trabalho alemão condenou um empregador a duzentos euros por ter carregado salário, morada particular, número de identificação fiscal e estado civil apesar de ter acordado com a comissão de trabalhadores uma lista de nove campos. E confirmou que o atraso na resposta a um pedido de acesso não é, por si só, um dano.

21/08/2026Novo 5 min
Legislação
2 dic 2027il nuovo termine per l'alto rischio

O 2 de agosto não desapareceu: estreitou-se

Quem leu apenas o título — «o regulamento da IA foi adiado» — está a trabalhar com informação errada. A data de 2 de agosto de 2026 não desapareceu: mudou de conteúdo. O que ficou abrange muito mais clientes do que aquilo que se moveu.

19/08/2026Novo 5 min
Tech & IA
4i momenti in cui si decide

A autoridade neerlandesa publica uma autoavaliação para a IA generativa

Faltava algo para dar ao cliente que diz «ativámos a IA no programa de gestão». A autoridade neerlandesa publicou uma autoavaliação sobre sistemas de IA generativa: quatro momentos, e em cada um uma decisão que tem de ficar documentada.

18/08/2026Novo 4 min
Legislação
133.000le PMI raggiunte dalla catena

A NIS2 é lei nos Países Baixos, e sem período de transição

A Cyberbeveiligingswet entrou em vigor a 15 de agosto de 2026. O número que conta não é oito mil: são cento e trinta e três mil, as PME neerlandesas que a lei alcança não por estarem no âmbito, mas por fornecerem quem lá está.

15/08/2026Novo 5 min
Tech & IA
1 su 4le violazioni con IA

As notificações de violações já ultrapassaram todo o ano de 2025

Os dados do primeiro semestre de 2026 dizem duas coisas distintas. A primeira é que o número de pessoas notificadas é dominado por pouquíssimos incidentes enormes. A segunda, mais incómoda para quem avalia o risco, é que a IA aparece numa violação em cada quatro.

14/08/2026Novo 4 min
Legislação
3le vie per chiudere il conflitto

O EPD que decide não pode fiscalizar-se a si próprio

Em 10 de agosto de 2026 a CNIL colocou por escrito como se identifica e como se resolve um conflito de interesses do encarregado de proteção de dados. O critério é um só: se nas restantes funções o EPD determina as finalidades e os meios de um tratamento, não pode depois fiscalizá-lo. Ninguém pode ser juiz em causa própria.

10/08/2026Novo 5 min
Jurisprudência
7i criteri di bilanciamento CEDU

Não se apaga o artigo, apaga-se o nome

Em 5 de agosto de 2026 a autoridade francesa esclareceu os contornos de um direito que é exercido com frequência e mal compreendido. Perante um órgão de imprensa mantêm-se aplicáveis a oposição e o apagamento, não o acesso nem a retificação. E a recusa tem de ser fundamentada em concreto: seis fórmulas genéricas são indicadas como inadmissíveis.

05/08/2026Novo 4 min
CEPD / AEPD
12-14gli articoli sotto esame

Em 2026 todas as autoridades europeias olham para a mesma coisa: as informações de privacidade

Todos os anos o CEPD escolhe um tema e todas as autoridades nacionais verificam-no em conjunto, no mesmo período, com questionários e inspeções. Para 2026 o tema é a transparência: como os responsáveis informam as pessoas sobre o que acontece aos seus dados. Estão em foco o art. 13.º, quando os dados vêm do titular, e o art. 14.º, quando vêm de outra origem. A autoridade checa já inscreveu o tema no seu plano de inspeções.

10/08/2026Novo 6 min
Legislação

A CNPD escreve onde vai olhar até 2029

A 24 de julho de 2026 a CNPD aprovou o Plano Plurianual de Atividades para o triénio 2027-2029 e o Plano de Atividades para 2027. É o tipo de documento que quase ninguém lê e que diz, com anos de antecedência, onde a supervisão se vai concentrar: formação digital, vulnerabilidade digital, capacitação para o DSA, competências em IA e neurodados.

24/07/2026Novo 4 min
Coima
4,3milioni EUR

Portugal: a maior coima de sempre ensina uma coisa só. Verificar o subcontratante é um dever substantivo, não um formulário a assinar

Com a Deliberação/2022/1072 a CNPD aplicou ao INE uma coima única de 4,3 milhões de euros por cinco contraordenações praticadas no âmbito da operação censitária de 2021. A mais instrutiva não é a dos dados de saúde e religião: é que o INE, apesar de existir um escritório da empresa em Lisboa, contratou com a sociedade sediada nos EUA, aceitando o foro da Califórnia e o trânsito dos dados por duzentos servidores, com cláusulas contratuais-tipo e nenhuma medida complementar.

12/12/2022Novo 7 min
Jurisprudência
3condizioni cumulative del test

O interesse legítimo não é a base jurídica de recurso

No processo C-621/22 o Tribunal de Justiça decidiu que um interesse comercial pode constituir um interesse legítimo nos termos do artigo 6.º, n.º 1, alínea f). Muitos leram apenas essa linha. O resto do acórdão lembra que as condições continuam a ser três e cumulativas, e que a terceira - a ponderação com as expectativas razoáveis do titular - é aquela em que o caso concreto se perdeu. Para o EPD a consequência é prática: o interesse legítimo só existe se estiver escrito nalgum lado.

12/08/2026 6 min
Jurisprudência
3elementi da provare, cumulativi

A indemnização por violação do RGPD: o que tem de provar quem reclama

As coimas das autoridades fazem manchetes; as acções cíveis fazem a facturação dos advogados. Desde 2023 o Tribunal de Justiça esclareceu que a indemnização do artigo 82.º exige três elementos cumulativos - violação, dano e nexo de causalidade - sem qualquer limiar de gravidade. E decidiu que o receio fundado de que os dados tenham caído em mãos erradas já é dano não patrimonial. Para o responsável muda o terreno de jogo: já não a gravidade, mas a prova das medidas adoptadas.

11/08/2026 7 min
CEPD / AEPD
28 agotermine per candidarsi

Concorrência e proteção de dados: o CEPD abre a mesa, e há um prazo

Depois do DSA e antes do DMA e do regulamento da IA, a quarta peça do mosaico regulatório europeu trata da relação entre concorrência e proteção de dados. Não é um tema teórico: toca nos dados como ativo de mercado, nas concentrações e na posição de quem trata dados porque domina um mercado. O CEPD e a Comissão pedem contributos antes de escrever, e desta vez o prazo está próximo.

30/07/2026 6 min
CEPD / AEPD
10 lug 2027quando si potra' condividere

Branqueamento de capitais e privacidade: o CEPD e a AMLA escrevem juntos as regras da partilha

A 1 de Julho de 2026 o CEPD e a Autoridade europeia antibranqueamento anunciaram orientações conjuntas sobre um ponto que nenhum dos dois podia resolver sozinho: como podem bancos, profissionais e autoridades trocar informação sobre suspeitas sem construir listas de suspeitos fora de controlo. A faculdade aplica-se a partir de 10 de Julho de 2027 e a consulta pública é esperada na primeira metade desse ano. Quem assessora entidades obrigadas tem um ano para se preparar.

01/07/2026 6 min
CEPD / AEPD
16-17luglio 2026

CEPD a partir de Dublin: é precisa uma base jurídica para que as autoridades troquem informações entre setores diferentes

O número e a complexidade das reclamações aumentam, em parte devido ao maior uso da IA, e as autoridades dizem abertamente que os recursos não chegam. As soluções em cima da mesa: operações conjuntas, partilha de recursos entre autoridades e o futuro regulamento processual.

17/07/2026 6 min
CEPD / AEPD
65art. GDPR

CEPD, decisão vinculativa 1/2026: uma reclamação sobre cookies não se arquiva dizendo que o titular abusa dela

A autoridade principal queria encerrar o caso alegando abuso dos artigos 77.º e 80.º, n.º 1. A autoridade austríaca opôs-se e o CEPD deu-lhe razão: nem o elemento objetivo nem o subjetivo do abuso estavam demonstrados. A reclamação volta atrás e tem de ser decidida quanto ao mérito.

14/07/2026 7 min
Legislação
3condizioni

Controlo dos trabalhadores: a CNIL lembra que as condições são três e têm de ser cumpridas todas. A proporcionalidade é apenas a primeira

A 9 de Julho de 2026 a CNIL atualizou a sua página sobre o controlo da atividade do pessoal. O conteúdo parece revisão, mas há um ponto que na prática se subestima continuamente: as condições são três, são cumulativas, e duas das três nada têm a ver com o grau de intrusão do instrumento.

09/07/2026 6 min
Legislação
71%lo vuole

71% of DPOs want the AI Act in their remit. 27% say they know it. 85% have never had AI training

On 3 July 2026 the French labour ministry, the AFCDP and the CNIL published the fifth edition of the DPO Profession Observatory, carried out by the Afpa. The easy reading is that DPOs are becoming the AI point of contact. The useful reading is different: between those who want the AI Act in their remit and those who say they know it there is a 44-point gap, and the AI Act never mentions the DPO at all.

03/07/2026 6 min
Jurisprudência
13milioni EUR

Austria: the Supreme Administrative Court cuts the fine from 18 to 13 million. But the part to read is where it says a compliance programme excuses nothing

On 24 June 2026 the Austrian Verwaltungsgerichtshof closed proceedings pending since 2019, reducing to EUR 13 million the fine for processing 'party affinities' calculated for around 2.2 million people. The headlines will be about the discount. For a DPO what matters is the rest: the Court says that punishing a legal person requires no act by its management bodies, that having resources to take advice raises the bar rather than lowering it, and that the charges on the DPIA and the record of processing fall away by absorption - not because those documents were correct.

24/06/2026 7 min
Coima
2.126.075persone

Sweden: SEK 6 million for an SQL injection. The hardest part is not the fine, it is that the risk had been sitting in their own risk register since 2021

On 26 January 2026 the Swedish authority fined Sportadmin i Skandinavien AB SEK 6,000,000 for breaching Article 32(1). The platform handles memberships, invoicing and websites for sports clubs: the 16 January 2025 attack exposed the data of 2,126,075 people, mostly children, including allergies and disabilities. But the passage worth reading twice is another one: since 2021 the company had identified the risk of SQL injection in its own annual reviews, and IMY cites exactly that to establish gross negligence.

26/01/2026 8 min
Legislação
5priorita' 2026

Netherlands: who supervises the AI Act, and where they will start. Prohibited practices and AI literacy, not high-risk systems

The Dutch government has designated the Autoriteit Persoonsgegevens and the Rijksinspectie Digitale Infrastructuur as coordinating national supervisors for the AI Act. The 2026 work agenda lists five priorities: overarching system supervision, transparency and explainability, frameworks and standards, testing for bias and fairness against discrimination, and AI literacy. The first formal enforcement actions are expected during 2026, starting with organisations using prohibited practices or demonstrably neglecting the AI literacy obligation.

01/08/2026 5 min
Coima
23sanzioni in 6 mesi

France: 23 fines in six months under the simplified procedure. Small amounts, new target

In the review published on 6 July 2026 the CNIL counts 23 new fines adopted since January under its simplified procedure, totalling EUR 133,750. Three infringements recur: excessive video surveillance, non-compliant cookie banners, and failure to respond to access and erasure requests. One example of the kind of target: EUR 7,500 against a company operating public toilet facilities, on 2 April.

06/07/2026 5 min
Coima
5milioni EUR

France: EUR 5 million for IQVIA. The pharmacy software kept sending the data even when the patient had said no

On 26 May 2026 the CNIL's restricted committee fined IQVIA Operations France EUR 5 million. The company runs two health data warehouses for third-party studies: LRX, authorised in 2018 and fed by around 14,000 pharmacies, and EMR, authorised in 2021 and fed by several thousand doctors. Among the findings, the most instructive: the practice management software used in pharmacies transmitted customer data to IQVIA even where the customer had objected.

26/05/2026 7 min
Jurisprudência
792.639EUR confermati

Finland: the Supreme Administrative Court upholds the fine on Verkkokauppa.com. The failing: never having defined how long to keep the data

On 12 June 2026 the Korkein hallinto-oikeus, Finland's Supreme Administrative Court, dismissed Verkkokauppa.com's appeal against the penalty imposed by the Finnish Data Protection Ombudsman's sanctions board (decision KHO 12.6.2026/1604). The original amount was EUR 856,000, reduced by the Administrative Court to EUR 792,639 on the basis of the company's most recent turnover. The finding does not concern a data breach: it concerns the fact that the company had never defined retention periods for customer account data.

12/06/2026 6 min
Coima
749firmatari esposti

Poland: a municipality fined not for publishing the data of 749 petition signatories, but for never reporting it

On 25 May 2026 the President of the UODO fined the mayor of Myslenice PLN 7,700. An un-anonymised petition had been published in the municipality's Public Information Bulletin: names, surnames, home addresses and signature specimens of 749 people. The core of the decision is not the publication, which the municipality corrected by replacing the file: it is that the breach was never notified to the authority, not even after the authority asked.

25/05/2026 6 min
Jurisprudência
600.000EUR annullati

Netherlands: the Council of State confirms the annulment of the EUR 600,000 fine for Enschede's wifi tracking

On 29 July 2026 the Administrative Jurisdiction Division of the Raad van State dismissed the appeal of the Autoriteit Persoonsgegevens against the municipality of Enschede, upholding the February 2024 judgment of the Overijssel District Court. The EUR 600,000 fine, imposed in March 2021 for counting city-centre visitors through sensors capturing the MAC addresses of wifi-enabled devices, remains annulled. The reason is not that the tracking was lawful: it is that the authority did not sufficiently demonstrate that the MAC addresses collected qualified as personal data and that processing of personal data had therefore taken place.

29/07/2026 6 min
Coima
10.145PLN al responsabile

Poland: WhatsApp in the sales network brings a fine for the processor, and a reprimand for the controller that never vetted it

On 22 June 2026 the President of the UODO, Miroslaw Wroblewski, closed the proceedings opened after a breach notification by Energa-Obrot: reprimands for the controller and the processors, and an administrative fine of PLN 10,145 for one of the processors. At the root of it, the use of WhatsApp by sales representatives of a door-to-door network during the pandemic: on a former agent's private phone there were scans and photographs of customer contracts, in group conversations, for many months.

22/06/2026 7 min
Coima
277.500EUR

Ireland: EUR 277,500 for Permanent TSB over a contact centre that could be fooled, and for reporting late

On 8 May 2026 the Irish Data Protection Commission closed its inquiry into a series of personal data breaches at Permanent TSB, first notified in May 2022. Malicious actors, holding certain customer information, called the Open24 contact centre posing as customers, gained access to accounts and amended account details. Some customers lost money. The authority issued a reprimand and fines totalling EUR 277,500.

08/05/2026 6 min
Legislação
3priorita'

The Dutch authority names its 2026-2028 priorities: mass surveillance, artificial intelligence, digital resilience

The Autoriteit Persoonsgegevens has set three strategic priorities for 2026-2028: mass surveillance, artificial intelligence and digital resilience. In its 2026 annual plan the authority states that it is allocating more capacity to AI and algorithms and will concentrate on large-scale systems with significant societal impact, without distinguishing between the public and private sectors. For anyone with clients in the Netherlands, or considering that market, it is the most useful piece of information of the year - and it costs nothing.

01/08/2026 6 min
Legislação
2autorita'

Netherlands and Poland: two authorities that raised the bar in 2026

The Dutch Autoriteit Persoonsgegevens has increased its budget and headcount and has named transparency, tracking and cookies among its 2026 supervisory priorities, with an approach that is openly less advisory and more enforcement-driven. In Poland the President of the UODO has shifted attention towards small and medium enterprises, a segment until recently little touched by inspections. For anyone with clients in those countries, or considering it, these are two signals that change the cost-benefit balance of compliance.

30/07/2026 4 min
Coima
460keuro

Piaggio fined 460,000 euro: 112 company emails read, backups kept for five years after termination

The Italian data protection authority has fined Piaggio & C. Spa 460,000 euro over the way the company managed employee email accounts. The investigation, opened after complaints by two former employees, established that 112 emails had been acquired during the employment relationship, some dating from roughly two years before any suspicion arose, made possible by backups retained for the whole duration of employment and up to five years after termination. Alongside the fine, the authority banned the company from accessing the data it had collected.

29/07/2026 7 min
Legislação
5settori

AI Act in Italy: the data protection authority becomes market surveillance authority for high-risk systems in justice, borders and democratic processes

The Italian data protection authority has issued a favourable opinion on the draft legislative decree implementing the AI Act in Italy. The decree sets out national governance and designates the authority as market surveillance authority for high-risk AI systems used in the areas most sensitive for fundamental rights: justice, law enforcement, immigration, border management and democratic processes. Among the conditions attached, one concerns any organisation: extending the ban on decisions based solely on automated systems to assessments affecting the employment relationship.

29/07/2026 6 min
Autoridade italiana
12keuro

Misconfigured document register: 12,000 euro fine for the Metropolitan City of Sassari

Following a data breach notification and a complaint, the Italian data protection authority fined the Metropolitan City of Sassari for misconfiguring its electronic document register, making documents containing personal data accessible to staff who, given their role and duties, were not authorised to process them. The fine is 12,000 euro, but the principle applies to every public body and every company running a document management system: filing is not a neutral activity, and a default of total visibility breaches the principles of integrity and confidentiality.

29/07/2026 6 min
Legislação
2 agoma non tutto

AI Act, 2 August: what actually applies and what has been postponed to 2027

For two years 2 August 2026 was presented as the day obligations for high-risk AI systems would start. The Digital Omnibus package changed that calendar: requirements for Annex III high-risk systems move to 2 December 2027 for stand-alone systems and 2 August 2028 for those embedded in products already covered by sectoral legislation. 2 August nonetheless remains an operative date: the transparency obligations of Article 50 become applicable, together with the full operation of governance and penalties, with national authorities acquiring full powers.

29/07/2026 5 min
Legislação
0multe dirette

Denmark: cookies are the 2026 priority, and fines are decided by a court

The Danish authority has flagged cookie consent as a supervisory priority for 2026, coordinating with the Digitaliseringsstyrelsen, which oversees the ePrivacy implementation while Datatilsynet applies the GDPR. But Denmark has a peculiarity that changes how every one of its decisions should be read: its constitutional order does not allow an administrative authority to impose punitive financial penalties. Recital 151 GDPR expressly anticipates this for Denmark and Estonia: the fine is decided by a court as a criminal penalty, following a report by the authority to the police.

28/07/2026 4 min
Legislação
14 luggia' scaduta

Email tracking pixels: France has already closed its grace period, Italy's runs to October

With deliberation no. 2026-042 of 12 March 2026, made public on 14 April, the French CNIL adopted its final recommendation on email tracking pixels: for most marketing uses, prior consent is required, just as for cookies. Existing contact bases were given three months to inform recipients and allow them to object, a period that ended on 14 July 2026, with checks announced from that date. In Italy the authority reached the same conclusion with decision no. 284 of 17 April 2026, but with a longer compliance window.

26/07/2026 4 min
Coima
365milaclienti

Wind Tre, EUR 1.7 million: the breach started with a phone call

The Italian DPA fined Wind Tre EUR 1,715,600 (decision no. 348 of 14 May 2026, made public with the 16 July newsletter). The starting point was not a sophisticated cyberattack: people posing as support technicians convinced staff at two retail outlets to allow access to company systems. From there, identification and contact data of 365,048 customers were exfiltrated; for 41,359 of them, payment method information as well, including IBANs, postal payment slips and credit cards with partially masked numbers and expiry dates. The charges: breach of the integrity and confidentiality principle (Art. 5(1)(f)) and of security obligations (Art. 32(1)(b)).

26/07/2026 4 min
Coima
1,5MEUR

Cookies, France holds the line: EUR 1.5 million to American Express and the topic stays a 2026 priority

In January 2026 the CNIL fined American Express EUR 1.5 million for cookie violations, confirming that the topic remains a standalone enforcement priority alongside artificial intelligence and cybersecurity. In 2025 there had been 21 cookie decisions, totalling over EUR 475 million. The recurring charges are always the same: trackers set before consent, a reject button less visible or further away than the accept button, inadequate information.

25/07/2026 3 min
Legislação
art. 15GDPR

Call centre recordings: the customer has a right to access them, and a transcript is enough

A customer had asked to access their own data contained in a recorded call with customer service. The company refused, considering the protection of the agent's confidentiality to prevail. The authority held that the request could be satisfied by providing the transcript, provided the elements identifying other people involved are redacted: given the professional context of the call and its subject, a supply contract, redaction would not have prejudiced the agent's confidentiality.

25/07/2026 3 min
Legislação
3linee guida

EDPB adopts guidelines on anonymisation, web scraping for generative AI, and blockchain

At its July 2026 plenary, the European Data Protection Board adopted guidelines on anonymisation and on web scraping in the context of generative artificial intelligence, together with the final version of the guidelines on processing personal data through blockchain technologies. Three documents addressing three recurring questions: when data is truly anonymous, on what conditions data may be collected from the web to train models, and how the immutability of a chain can be reconciled with data subjects' rights.

24/07/2026 3 min
Coima
18MEUR

Spain: EUR 18 million to Amadeus for reusing booking data for product development

The Spanish authority fined Amadeus IT Group EUR 18 million (reduced to 14.4 with voluntary payment) for aggregating travellers' booking data into profiles for product development. The cross-border investigation found the reuse of data collected years earlier from airlines and agencies, for purposes data subjects could not reasonably expect, without an Article 14 notice and without a valid legitimate-interest balancing test.

23/07/2026 4 min
Coima
6Miscritti

Norway: loyalty programme under scrutiny, more than six million members involved

The Norwegian authority concluded proceedings opened after an audit of the Nordic entities of a retail group, finding several breaches relating to its loyalty programme: invalid consent, new processing purposes introduced without assessment, insufficient legitimate-interest balancing, and failure to answer data subject requests within the deadline. More than six million members across the Nordic region were affected.

22/07/2026 3 min
Coima
3provvedimenti

Credit scoring in utilities: the Italian DPA hits the whole chain with three decisions in one day

With three decisions adopted in the same session on 3 July 2026, the Italian DPA targeted the credit-scoring chain applied to energy supply contracts: Experian Italia, Hera Comm and Cerved. The charges are similar and paint a clear picture: deficient notices, breaches of minimisation and storage limitation, privacy by design and by default disregarded, inadequate responses to access requests and poorly governed Article 28 relationships along the chain.

21/07/2026 4 min
Legislação
art. 21d.lgs. 24/23

Whistleblowing: without consulting the unions, the procedure is not compliant

A preliminary requirement that almost everyone overlooks is back in the spotlight: Article 4 of Legislative Decree 24/2023 requires internal reporting channels to be activated after hearing worker representatives or trade unions. The ANAC guidelines clarify that failing to do so makes the procedure non-compliant and may trigger a sanction under Article 21. It also applies to substantial updates, not just first activation.

20/07/2026 3 min
Coima
1,7MEUR

Data breach: Italian DPA fines Wind Tre EUR 1.7 million after exfiltration of 365,000 customers' data

In its 16 July 2026 newsletter the Italian DPA announced a EUR 1.7 million fine to telecom operator Wind Tre following a data breach with exfiltration of roughly 365,000 customers' data. The case confirms the authority's line on large operators: the incident itself is not the fault - the fault lies in security measures inadequate to the risk (Art. 32) and in how the breach was handled. In the same newsletter: two debt-collection companies fined (EUR 50k and 30k) and the customer's right to access the audio of their own support calls (Enel case).

17/07/2026 3 min
Coima
158KEUR

Character.AI fined EUR 158,000: minors, late DPIA and missing EU representative

With a decision of 3 July 2026 (announced 9 July) the Italian DPA fined Character Technologies Inc., the US company behind Character.AI, EUR 158,000: deficient privacy notice (Arts. 12-14), a DPIA prepared late relative to the service launch, late designation of the EU representative (Art. 27) and shortcomings in minor protection and age verification. Beyond the fine, corrective measures within 120 days: working age verification, an effective cooling-off period against re-registration by blocked minors, minors' profiles private by default.

16/07/2026 4 min
Autoridade italiana
2/2genitori

Children's photos on social media: both parents must consent

In its 17 June 2026 newsletter the Italian DPA restated a principle that matters well beyond family disputes: publishing photos of minor children on social media requires the consent of BOTH parents. In case of disagreement, the child's protection prevails. For the DPO it is an operational criterion affecting schools, nurseries, sports clubs, parishes and companies publishing images of minors for promotional purposes.

15/07/2026 3 min
Autoridade italiana
STOPcopie

Italian DPA to hoteliers: do not keep copies of guests' ID documents

In a notice addressed to the hospitality sector, the Italian DPA reiterated that hoteliers may not keep copies of guests' identity documents: the legal duty (Art. 109 of the Italian public-security code) is to identify the guest and transmit the data to the police via the Alloggiati Web portal - after that, document copies must be destroyed or deleted. A widespread habit becomes a concrete sanction risk.

14/07/2026 3 min
Legislação
EDPBconsultazione

Data breach: EDPB puts a new EU-wide notification template up for consultation

The EDPB has opened a public consultation on a new harmonised data-breach notification template, designed to align the information requested by authorities across Member States. For DPOs it is operational news: the content of the Art. 33 notification is becoming standardised, and anyone with a structured internal procedure (facts, categories, risk assessment, measures) will find the work already done.

13/07/2026 3 min
Coima
563KEUR

Enel Energia fined EUR 563,000: the 'administrative' call that turns into a sales pitch

With decision no. 170/2026 the Italian DPA fined Enel Energia EUR 563,052: during purely administrative contacts (supply paperwork, takeover confirmations), including via third parties, commercial offers were made without a valid legal basis - even to customers on the opt-out register or who had expressly refused marketing consent. Also challenged: a re-contact mechanism based on opt-out (an SMS with 90 seconds to refuse) and partner vetting - one agency was contracted two months after being sanctioned by the DPA for marketing.

09/07/2026 4 min
Coima
55KEUR

Italy's DPA fines AgID: EUR 55,000 to the Agency for Digital Italy over transparency and privacy by design

With injunction order no. 419 of 28 May 2026 the Italian DPA declared unlawful certain personal data processing carried out by AgID - the Agency for Digital Italy, with a EUR 55,000 fine and publication of the decision on the authority's website. The breaches concern lawfulness, fairness and purpose limitation (Art. 5), information duties towards data subjects (Arts. 12 and 14) and data protection by design (Art. 25).

08/07/2026 3 min
Art. 5
AI Act
Coima

Italy's DPA halts stress and emotion monitoring at work: not even in aggregate form

With decision no. 342 of 2026, the Italian DPA reaffirmed that data on employees' health or psychological journey cannot be made accessible to the employer, not even in aggregate form. The case closes the loop with the AI Act, which expressly prohibits AI systems that infer people's emotions in the workplace (Art. 5): organisational wellbeing cannot turn into emotional surveillance.

06/07/2026 4 min
8
mesi
Coima

Trenitalia tells customers about a data breach eight months after the attack: an Art. 34 lesson

In July 2026 Trenitalia informed its customers of a data breach suffered roughly eight months earlier. Beyond the outcome, the case is a textbook lesson on the difference between notifying the authority within 72 hours (Art. 33) and communicating to data subjects 'without undue delay' when the risk to their rights is high (Art. 34): eight months are hard to justify, and in the meantime the persons affected could not protect themselves.

04/07/2026 3 min
Autoridade italiana
37,7MEUR

Italian DPA annual report: collected fines +54.5%, almost 7 data breaches notified per day, AI at the centre

On 2 July 2026 the Italian DPA presented its 2025 activity report to Parliament: 807 collegial decisions, 506 corrective and sanctioning measures, over EUR 37.7 million in fines collected (+54.5% on 2024), 2,415 data breaches notified (+10%), 130 inspections. AI takes centre stage: from DeepSeek to deepfakes, from facial recognition at the airport to worker surveillance.

02/07/2026 4 min
1,5M
cittadini
Coima

SPID under scrutiny: Lepida fined, data of 1.5 million citizens viewable 'out of mere curiosity'

With a decision of 29 April 2026, the Italian DPA fined Lepida (EUR 100,000), one of Italy's main SPID identity providers: over 7,000 counter operators could view data and download copies of ID documents and health cards of more than 1.5 million citizens, even with no operational need. The DPA found accesses 'out of mere curiosity' and documents left stored on operators' workstations after identification.

01/07/2026 4 min
AI Act
update
Legislação

Digital Omnibus: EU Council approves changes to the AI Act. What it means if you are preparing

On 29 June 2026 the EU Council approved the proposed regulation that streamlines and simplifies certain AI rules, amending the AI Act (the 'Digital Omnibus' package). Negotiations with Parliament continue: until final adoption, the current AI Act text remains the reference, including the August 2026 transparency deadlines.

29/06/2026 3 min
Coima
180kEUR

Italy's DPA fines Emirates EUR 180,000: passenger health data kept for 7 years and an unclear notice

The Italian DPA fined Emirates EUR 180,000 over the handling of reduced-mobility passengers' health data. The case started from a complaint by a passenger asked to fill in a medical form despite not being in the categories required to do so. The key point for DPOs: the collection itself was lawful, but the authority faulted an inadequate notice and excessive retention (7 years).

17/06/2026 4 min
Art. 5
GDPR
Coima

Loyalty-card data used to fire an employee: Italy's DPA says no. A lesson on purpose limitation

With decision no. 311 of 29 April 2026, the Italian DPA found unlawful the employer's use of data collected through the loyalty card to support an employee's dismissal. That data had been collected to run the loyalty programme, not to monitor or discipline staff. The point for DPOs: having a piece of data does not mean you can use it for any purpose.

15/06/2026 4 min
Legislação
12-14artt.

EDPB 2026: the EU coordinated action targets transparency (Art. 12-14). What to check in privacy notices

For 2026 the EDPB chose TRANSPARENCY as the topic of its coordinated enforcement action: authorities will examine how organisations inform data subjects under Art. 12-14. In short: clear, complete, verifiable notices. A good moment to review your clients' documents.

12/06/2026 5 min
Coima
7,1mld EUR

GDPR fines top EUR 7.1 billion: enforcement accelerates and SMEs are not exempt

Cumulative GDPR fines have passed EUR 7.1 billion across 1,400+ decisions. Enforcement is accelerating, not plateauing. And contrary to a common myth, SMEs do get fined: smaller amounts, same proportional severity.

12/06/2026 5 min
5M
EUR
Coima

France fines IQVIA EUR 5M: pseudonymisation does not take you out of the GDPR

In France the authority (CNIL) fined IQVIA EUR 5 million, clarifying a point many confuse: pseudonymising data - even health data - is not the same as anonymising it. Pseudonymised data remains personal data and must be handled with all the safeguards of the Regulation, including the enhanced ones in Art. 9.

10/06/2026 3 min
Legislação
15MEUR

Rome Court annuls the Garante's EUR 15M fine against OpenAI: the one-stop-shop decides

The Rome Court annulled the EUR 15M fine the Italian Garante imposed on OpenAI in 2024. The judge does not rule on the merits (legal basis, notice, age verification): it upholds the jurisdiction argument. For cross-border processing the one-stop-shop and lead authority govern.

10/06/2026 6 min
Legislação
6ambiti

The Garante's 2026 inspection plan: six areas and how to be ready

The Italian Garante set its 2026 inspection areas, backed by the Finance Police tech-fraud unit. Topics include data breaches in public databases and abusive access. Those who document self-assessment and lesson learning get treated differently.

10/06/2026 5 min
Coima
5MEUR

France: CNIL fines France Travail EUR 5 million - 36.8 million data subjects and a social-engineering attack

The CNIL fined France Travail (formerly Pole Emploi) EUR 5 million after a breach exposing the data of around 36.8 million people. Attackers used social engineering against partner advisers' accounts. The lesson: having security plans is not enough, they must actually be implemented.

09/06/2026 6 min
Coima
1,7MEUR

France: EUR 1.7 million to Nexpublica - health and disability data accessible to other users through long-known flaws

The CNIL fined software vendor Nexpublica EUR 1.7 million: its PCRM tool, used by social services, exposed sensitive documents (including disability data) to other users. The flaws were known from prior audits but left open. A textbook case for anyone processing health data.

09/06/2026 6 min
Coima
10MEUR

Spain: AEPD fines Aena EUR 10 million for biometric boarding without adequate DPIA

The Spanish Data Protection Agency fined Aena over EUR 10 million for launching its biometric boarding programme without completing an adequate DPIA. Not a data breach: a failure of preventive accountability.

25/05/2026 8 min
Coima
290MEUR

Netherlands: the EUR 290 million Uber fine and the Dutch Authority's new priorities for 2026

The Autoriteit Persoonsgegevens confirmed the EUR 290 million fine against Uber for unlawful transfers to the US. Meanwhile the Authority sets three strategic priorities for the next two years every DPO should know.

22/05/2026 7 min
Coima
85kEUR

Data breach: Italy's DPA fines The European House - Ambrosetti EUR 85,000 over plaintext passwords and late notification

The Italian DPA fined The European House - Ambrosetti spa EUR 85,000 following a 2024 data breach affecting 61,670 people. The attack, via a technical vulnerability, led to the exfiltration of names, emails, usernames and passwords. The point for DPOs: the breach was notified to the regulator within 72 hours, but data subjects were informed only after two months and after the authority stepped in.

21/05/2026 4 min
CEPD / AEPD
25DPA

EDPB CEF 2026: 25 European DPAs verify transparency of privacy notices

The European Data Protection Board has launched the 2026 coordinated action on transparency and information obligations. 25 national DPAs (including the Italian Garante) are already contacting controllers in various sectors. What to expect and how to prepare.

20/05/2026 9 min
Autoridade italiana
1 lug 2026deadline

Italian DPA cracks down on WhatsApp and Telegram in public administration: ban on operational communications with citizens from July 1, 2026

The Italian DPA (Garante) issued a general provision banning Italian public administrations from using WhatsApp, Telegram, Messenger and other commercial messaging apps for operational communications with citizens. Banned also for requesting documents, certificates or personal data. PAs must use institutional channels (PEC, portals, SPID-auth) by July 1, 2026. Fines up to 100,000 EUR.

19/05/2026 9 min
Tech & IA
1ain UE

Spain: AEPD publishes Europe's first guidance on agentic AI and data protection

The Spanish Data Protection Agency is the first European Authority to publish elaborate guidance on agentic AI. It explains the concept, the vulnerabilities in processing personal data and mitigation measures for controllers and processors.

18/05/2026 7 min
Coima
45MEUR

Vodafone Germany fined EUR 45 million: the Art. 28 GDPR lesson on processor controls

The German Federal Commissioner for Data Protection (BfDI) imposed a total fine of EUR 45 million on Vodafone GmbH: 15M for Art. 28 violation (processor oversight) and 30M for Art. 32 (security). A decision that redefines accountability expectations on processors.

15/05/2026 8 min
Legislação
18settori essenziali

NIS2 and GDPR: how to orchestrate them operationally after Italian Decree 138/2024. The DPO checklist for the NIS Operator

After the NIS2 transposition with Legislative Decree 138/2024, Italian companies qualified as 'essential entities' or 'important entities' must coordinate NIS2 obligations (cyber security, 24h incident reporting) with GDPR obligations (72h data breach). The DPO is not the NIS Coordinator but must interface: risk of double sanctions if not properly orchestrated.

15/05/2026 11 min
CEPD / AEPD
12raccomandazioni

EDPB publishes guidelines on public DPO profiles: transparency, accountability and data subject rights

The EDPB clarifies how to process the professional data of DPOs exposed publicly on online directories: legal basis, purposes, data subject rights and platform responsibilities.

12/05/2026 8 min
Tech & IA
Aug 2026

AI Act August 2026: high-risk systems deadline. Mandatory DPIA for enterprise LLMs

The EU AI Act enters its critical phase: August 2026 triggers obligations for high-risk systems. The Italian Garante has already anticipated enforcement with the EUR 5M fine to Luka (Replika). What DPOs must do now.

08/05/2026 10 min
Legislação
Art. 26AI Act

AI Act and DPO: how the DPO role changes with deployer obligations entering into force in August 2026

In less than 3 months, the AI Act sections dedicated to deployers (users) of high-risk AI systems enter into force. The DPO becomes a key interlocutor for impact assessment, data subject information and monitoring.

08/05/2026 10 min
Autoridade italiana

Corporate email post-termination: Italian DPA fines ITAS Mutua

The Italian Data Protection Authority addresses the management of corporate emails after employment termination. ITAS Mutua sanctioned for undocumented access and retention beyond necessary.

07/05/2026 5 min
Jurisprudência
530MEUR

TikTok vs Irish DPC: Supreme Court suspends 530 million euro fine

The Irish Supreme Court confirms the suspension of the record 530M EUR fine imposed by the DPC on TikTok for EEA data transfer to China. The case exposes the structural problem of enforcement timing against big tech.

30/04/2026 6 min
Legislação
6mesi

Email tracking pixels: new Italian DPA Guidelines

On April 17, 2026, the Italian DPA adopted Guidelines on tracking pixels in emails. For DPOs: 6 months to align privacy notices, consent flows, and privacy-by-design techniques.

17/04/2026 5 min
Coima
31.8MEUR

Intesa Sanpaolo: 31.8M euro fine from the Italian DPA

The Italian Data Protection Authority fines Intesa Sanpaolo for a data breach affecting 2.4 million customers. Late notification and incomplete information among the key issues.

26/03/2026 4 min
Jurisprudência
15MEUR

Rome Court annuls 15M euro fine against OpenAI

The Rome Court annuls the fine that the Italian DPA had imposed on OpenAI for the ChatGPT case. A decision that redefines the scope of GDPR enforcement on generative AI models.

20/03/2026 4 min
Coima
500KEUR

Enel Energia fined over 500,000 euros: telemarketing without consent

The Italian DPA fines Enel Energia for promotional calls to subjects who had not provided consent or had registered their number in the public opposition register.

12/03/2026 3 min
Jurisprudência
120giorni

Italian Supreme Court 984/2026: the DPA 120-day deadline is final

With its January 17, 2026 ruling, the Italian Supreme Court confirms that the 120-day deadline for concluding the DPA's enforcement proceedings is final. A relevant decision for those handling privacy litigation.

18/02/2026 3 min
CEPD / AEPD

EDPB: DPOs are under-resourced and disconnected from top management

EDPB publishes the results of the coordinated enforcement action: insufficient resources, lack of access to top management, conflict of interest risk. A snapshot that also concerns Italian external DPOs.

17/02/2026 4 min
Jurisprudência

France's Conseil d'Etat: the line between anonymization and pseudonymization narrows

France's State Council confirms CNIL's approach on pseudonymized health data. A ruling that redefines the practical scope of GDPR anonymization and impacts all data analytics projects.

13/02/2026 5 min
CEPD / AEPD

EDPS strengthens DPO independence: new binding rules

The European Data Protection Supervisor (EDPS) adopts new binding rules to protect DPO independence within Union institutions. A signal strengthening the role.

13/02/2026 3 min
CEPD / AEPD
96h

Digital Omnibus: EDPB and EDPS call for simplification without setbacks

EDPB and EDPS publish the joint opinion on the EU Commission's Digital Omnibus package. Positive measures on data breach and DPIA, but strong opposition to the revision of the personal data definition.

11/02/2026 5 min
Autoridade italiana
40ispezioni

Italian DPA 2026 inspection plan: data breach, whistleblowing, AI in schools

The Italian DPA published its inspection activities plan for January-June 2026. Sectors at risk: banking data breaches, health dossiers, energy telemarketing, and AI in schools.

29/01/2026 3 min
Coima
42MEUR

CNIL fines Free Mobile and Free 42 million euros: 24 million customer data breach

The French Authority separately fines Free Mobile (27M) and Free (15M) for a breach that exposed 24 million subscribers in October 2024. A decision that clarifies the scope of Art. 34 GDPR.

13/01/2026 7 min