High
Fine
In effect
Italy · Oct 9, 2026 · effective Jul 3, 2026
Italian DPA fines BBVA €5.508 million for ignoring customer objection to direct marketing
The Italian Data Protection Authority issued an administrative fine of €5,508,000 against BBVA's Italian branch for failing to honor a customer's right to object to direct marketing. The violation lasted seven months, during which the…
Italian Data Protection Authority · General Data Protection Regulation
High
Fine
Decided
Italy · Oct 9, 2026
Italian DPA fines Emirates €180,000 for health data infringements
The Italian Data Protection Authority imposed an administrative fine of EUR 180,000 on Emirates for violations of GDPR transparency and retention requirements concerning passengers' health data. Emirates was ordered to clarify which…
Italian Data Protection Authority · General Data Protection Regulation
High
Data protection authority action
Decided
Italy · Oct 9, 2026 · effective Sep 23, 2026
Italian DPA fines IQVIA €7 million for unlawful processing of patients’ health data
The Italian Data Protection Authority imposed an administrative fine of EUR 7,000,000 on IQVIA Solutions Italy S.r.l. for processing health data without a legal basis, inadequate information to patients, and missing DPIA and retention…
Italian Data Protection Authority · General Data Protection Regulation
Moderate
Guidance
Published
France · Oct 9, 2026
CNIL hosts 2nd Rencontres Informatique & Libertés on connected glasses and data‑sanctions
The French data‑protection authority CNIL held its second Rencontres Informatique & Libertés on 29 September 2026, featuring panels on the privacy impact of connected glasses and the role of sanctions under the GDPR. The event gathered…
CNIL · RGPD
Moderate
Fine
In effect
Italy · Oct 9, 2026 · effective Aug 6, 2026
Italian DPA fines security firm €39,000 for employee data violations
The Italian Data Protection Authority (Garante) imposed a total administrative fine of EUR 39,000 on La Patria S.p.A. for failing to respond to employee access requests and for inadequate information about GPS‑derived geolocation data. The…
Garante – Italian Data Protection Authority · General Data Protection Regulation
Moderate
Guidance
Announced
European Union · Oct 9, 2026
Commission holds special meeting of Scientific Panel on frontier AI safety and risks
The European Commission convened a special meeting of the Scientific Panel on AI, which includes 60 independent experts. The panel advises the EU AI Office and national authorities on systemic risks, model classification, evaluation…
European Commission · EU AI Act
Moderate
Fine
Decided
Sweden · Oct 8, 2026
Swedish DPA fines Miljödata approx EUR 160,000 for insufficient security measures
The Swedish Data Protection Authority (IMY) imposed an administrative fine of SEK 1,800,000 (≈ EUR 160,000) on IT service provider Miljödata i Karlskrona for violating Article 32(1) GDPR. The authority found the company lacked adequate…
Swedish Data Protection Authority (IMY) · General Data Protection Regulation
High
Data protection authority action
Decided
Greece · Oct 8, 2026
Hellenic DPA fines Ministry and EETAA for data breach
The Hellenic Data Protection Authority issued a final decision on 28/07/2026 imposing administrative fines of EUR 200,000 on the Ministry of Social Cohesion and Family Affairs and EUR 150,000 on E.E.T.A.A. S.A. for security deficiencies.…
Hellenic Data Protection Authority · General Data Protection Regulation
Moderate
Proposed regulation
Proposed
France · Oct 8, 2026
CNIL examines draft deliberation authorizing BIG DATA SANTE to process personal data for anonymized medical research (ONCOVAL)
During its plenary session on 8 October 2026, the CNIL will consider a draft deliberation that would permit BIG DATA SANTE (Octopize Mimethik Data) to carry out automated processing of personal data to create anonymised datasets for…
Commission nationale de l'informatique et des libertés (CNIL) · Law of 6 January 1978
Moderate
Enforcement
Decided
France · Oct 8, 2026
CNIL closes injunction against FRANCE TRAVAIL after compliance with data security measures
The French data protection authority (CNIL) closed the injunction issued on 22 January 2026 against FRANCE TRAVAIL, after the organization demonstrated compliance with the security measures required by Article 32 of the GDPR. The original…
CNIL · RGPD
High
Fine
Published
Netherlands · Oct 8, 2026
Dutch DPA fines Uber €824.99 million for unlawful automated decision‑making
The Autoriteit Persoonsgegevens imposed an administrative fine of €824,990,000 on Uber for violating GDPR Article 22 by automatically deactivating drivers’ accounts and for failing to provide sufficient information under Article 13. The…
Autoriteit Persoonsgegevens · General Data Protection Regulation
Moderate
Guidance
Published
Spain · Oct 8, 2026
AEPD publishes second issue of scientific journal “Privacy, Innovation and Technology”
The Spanish Data Protection Agency released the second issue of its scientific journal PIT, dedicated to the 10th anniversary of the GDPR. The monograph examines proactive responsibility, the right to explanation in automated decisions…
Agencia Española de Protección de Datos (AEPD) · Reglamento General de Protección de Datos (RGPD)
Moderate
Proposed regulation
Announced
European Union · Oct 6, 2026
Commission registers European Citizens' Initiative for sovereign European AI domains
The European Commission has officially registered a European Citizens' Initiative that calls for the creation of sovereign European AI domains. The initiative seeks to shape future EU policy on artificial intelligence and digital…
European Commission
High
Enforcement
Published
Spain · Oct 6, 2026 · effective Oct 6, 2026
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The Spanish Data Protection Agency (AEPD) sent preventive warnings (AI‑00170‑2026 and AI‑00171‑2026) to two local councils regarding planned video‑surveillance systems that use automated image analysis with AI. The agency stresses that the…
Agencia Española de Protección de Datos · Reglamento General de Protección de Datos
Low
Guidance
Published
European Union · Oct 2, 2026
EDPB adopts Guidelines 04/2026 on GDPR fines and corrective powers for public consultation
The European Data Protection Board adopted Guidelines 04/2026 on the application of administrative fines and other corrective powers under the EU GDPR. The guidelines were released on September 17, 2026 for public consultation.
European Data Protection Board · General Data Protection Regulation
Moderate
Proposed regulation
Proposed
European Union · Oct 2, 2026
Commission seeks feedback on proposed EU Kids Act
The European Commission is gathering feedback on the proposed EU Kids Act, which aims to improve online safety for children with measures such as a social‑media delay, safety‑by‑design rules, privacy‑preserving age assurance, and…
European Commission · EU Kids Act
Moderate
Guidance
Published
France · Oct 2, 2026
CNIL explains when data‑breach victims can claim compensation under the GDPR
The CNIL outlines that individuals can seek damages only if a GDPR breach caused a real material or moral injury, and they can prove a causal link. Compensation is awarded by a judge, not the CNIL, and the regulator may only impose…
CNIL · RGPD
High
Guidance
Published
France · Oct 1, 2026 · effective Oct 1, 2026
CNIL and Cybermalveillance.gouv.fr release guide for individuals on personal data breach response
The French data protection authority (CNIL) and Cybermalveillance.gouv.fr have published a practical support document titled “Violation de données personnelles, que faire en 3 étapes clés ?”. The guide provides a three‑step checklist for…
CNIL
Moderate
Proposed regulation
Announced
France · Oct 1, 2026
CNIL to examine draft decree on student violence questionnaire and automated vehicle sound monitoring
The CNIL plenary session on 1 October 2026 will examine a draft decree authorising personal data processing for a "Questionnaire violences sexistes et sexuelles" in schools. It will also review draft orders on sound radars and an automated…
Commission nationale de l'informatique et des libertés (CNIL) · règlement intérieur de la CNIL
Moderate
Enforcement
Announced
Bulgaria · Oct 1, 2026
European Commission sends formal notice to Bulgaria for non‑compliance with the Digital Services Act
The Commission issued a formal notice (INFR(2024)2241) to Bulgaria for failing to fully comply with the DSA, specifically for not designating and empowering the required Digital Services Coordinators. Bulgaria has two months to respond…
European Commission · Digital Services Act
Moderate
Proposed regulation
Proposed
European Union · Oct 1, 2026
EU Commission proposes KIDS Act to ban social‑media access for under‑13s and set minimum account age of 15
The European Commission has presented the EU KIDS Act, which would prohibit social‑media platforms from providing services to children under 13 and require a minimum age of 15 for users to open their own accounts. The proposal shifts the…
European Commission · EU KIDS Act
Moderate
Guidance
Announced
France · Sep 28, 2026
CNIL to host AIR 2026 event on political communication ethics and election manipulation on 16 Nov 2026
The French data‑protection authority CNIL will hold a public debate on 16 November 2026 about the ethical challenges of digital political communication and foreign interference. The programme will examine voter consent, data‑minimisation…
CNIL · RGPD
Moderate
Guidance
Published
Ireland · Sep 28, 2026
Data Protection Commission releases AI Insights Report covering 2021‑2025 supervision
The Irish Data Protection Commission published a report on its supervision of AI products and services from 2021 to 2025, noting a rise in AI engagements and improvements in lawful basis, transparency and data‑minimisation. The report…
Data Protection Commission
Moderate
Guidance
Published
European Union · Sep 28, 2026
ENISA launches podcast series on Frontier AI and publishes guidance note on cybersecurity in the Frontier AI era
ENISA announced a new podcast series to discuss the latest cybersecurity developments, with the first episode focusing on Frontier AI. In July 2026 the agency also published a note providing recommendations for national authorities and EU…
ENISA
Moderate
FRAMEWORK UPDATE
Published
European Union · Sep 28, 2026
EU Commission releases two reports on generative AI and digital education impacts
The European Commission published two reports examining the implications of generative AI for education and the state of digital transformation in European schools. The findings will inform the Commission's work on the Union of Skills and…
European Commission
High
Interpretation
Published
European Union · Sep 28, 2026
Commission designates ChatGPT, Reddit, Roblox as VLOPs/VLOSE under the Digital Services Act
The European Commission has designated ChatGPT as a Very Large Online Search Engine and Reddit and Roblox as Very Large Online Platforms under the DSA, citing each service’s reach of at least 45 million EU monthly users. The designated…
European Commission · Digital Services Act
Low
Enforcement
Decided
France · Sep 24, 2026 · effective Sep 17, 2026
CNIL closes injunction against SOLOCAL MARKETING SERVICES
The French data protection authority CNIL closed the injunction it issued on 15 May 2025 after the company demonstrated measures to verify the validity of consent obtained by its data‑broker partners. The original sanction included a…
CNIL · code des postes et des communications électroniques (CPCE)
Moderate
Proposed regulation
Proposed
France · Sep 24, 2026
CNIL examines draft decree creating SI-Mandoline personal data system for protection of adults
The CNIL plenary session on 24 September 2026 will examine a draft decree establishing the personal data processing system "Système d’information de la protection juridique des majeurs" (SI-Mandoline). It will also consider a draft decree…
Commission nationale de l'informatique et des libertés (CNIL) · code de commerce
Moderate
Enforcement
Published
Spain · Sep 23, 2026
Spanish Data Protection Agency issues warning to company over AI-driven resume screening
On 23 September 2026 the AEPD sent a formal warning to a company planning to use an AI tool for analysing CVs and assigning scores. The agency stresses that data protection must be built in from the start, including DPIA for high‑risk…
Agencia Española de Protección de Datos (AEPD) · Reglamento General de Protección de Datos (RGPD)
Low
Proposed regulation
Proposed
European Union · Sep 23, 2026
European Commission proposes EU KIDS Act to strengthen online child protections
On September 17, 2026, the European Commission published a proposal for the EU KIDS Act. The draft legislation aims to enhance protections for children using online services. It is part of the Commission's broader effort to safeguard…
European Commission · EU KIDS Act
Moderate
Guidance
Published
European Union · Sep 23, 2026
EDPB adopts guidelines on GDPR fines and DSA interaction (17 Sep 2026)
On 17 September 2026 the European Data Protection Board adopted guidelines on the use of administrative fines by data protection authorities and finalised guidance on the interaction between the Digital Services Act (DSA) and the GDPR. The…
European Data Protection Board (EDPB) · Digital Services Act
High
Fine
Decided
Ireland · Sep 23, 2026 · effective Sep 21, 2026
Irish Data Protection Commission fines Google €403 million for GDPR violations over location data
The Irish Data Protection Commission issued its final decision on 21 September 2026, imposing administrative fines of €403 million on Google Ireland Limited. The DPC found infringements of GDPR principles relating to lawfulness, fairness…
Irish Data Protection Commission · General Data Protection Regulation
Moderate
Guidance
Published
European Union · Sep 23, 2026
EU Commission hosts fifth roundtable on Digital Services Act implementation
On 23 September 2026 the European Commission held an online roundtable with about 60 civil society organisations and researchers to discuss the implementation of the Digital Services Act. The discussion focused on systemic risks…
European Commission · Digital Services Act
Low
Interpretation
Published
EU-GB · Sep 22, 2026
London faces privacy pushback against smart glasses, EPIC warns
The article reports growing public concern in London over smart glasses that can record video. EPIC's AI and Human Rights director Calli Shroeder says solving privacy problems will be difficult and warns of fear of being left behind in the…
Moderate
Fine
Decided
Spain · Sep 22, 2026 · effective Feb 1, 2023 · deadline Feb 1, 2024
Spanish DPA fines Securitas Direct €100,000 for charging phone line for data subject rights
The Spanish Data Protection Agency (AEPD) issued a final decision on 1 February 2023 finding Securitas Direct in breach of GDPR Article 12(2) by directing data subjects to a chargeable 902 telephone number to exercise their rights. The…
Spanish Data Protection Agency (AEPD) · General Data Protection Regulation
Moderate
Guidance
Published
European Union · Sep 22, 2026 · effective Sep 22, 2026
ENISA releases 2026 Threat Landscape report highlighting AI-enabled cyber threats and supply‑chain risks
ENISA's 2026 Threat Landscape report analyses incidents from 1 January to 31 December 2025, noting a rise in ransomware, AI‑driven malicious activity, and supply‑chain attacks. The report finds public administration to be the most targeted…
ENISA · NIS2 Directive
Moderate
Proposed regulation
Proposed
European Union · Sep 21, 2026
EU Commission proposes KIDS Act to impose age‑based restrictions and safety‑by‑design for children online
On September 17, 2026 the European Commission published a proposal for a new EU KIDS Act that would ban users under 15 from creating accounts on certain social networking and video‑sharing services, with limited exceptions. The draft…
European Commission · Digital Services Act
Moderate
Proposed regulation
Proposed
European Union · Sep 21, 2026
EU proposes Article 88c/88bis to allow unrestricted AI use of personal data
A leaked Irish Presidency document proposes that personal data used "in the context of AI" be automatically lawful, removing consent requirements. The draft Article 88c (now 88bis) would permit AI companies to process any personal data for…
European Commission · General Data Protection Regulation
Moderate
Proposed regulation
Announced
France · Sep 17, 2026
CNIL plenary agenda includes draft decrees on prison camera use, Apple ATT, and data collection in real‑estate rentals
The CNIL plenary session of 17 September 2026 will discuss a draft decree on the use of on‑board cameras by prison surveillance staff, a draft decree amending the 2019 decree that implements the French data protection law, and a…
Commission nationale de l'informatique et des libertés (CNIL) · décret n° 2019-536 du 29 mai 2019
Moderate
Guidance
Published
France · Sep 17, 2026
CNIL outlines its status, organization and sanction powers
The CNIL, created by the 1978 Loi Informatique et Libertés, is an independent administrative authority composed of a college of 18 members. Its restricted board can impose fines up to €20 million or 4 % of global annual turnover under the…
CNIL · loi Informatique et Libertés