Moderate
Fine
In effect
Italy · Oct 9, 2026 · effective Aug 6, 2026
Italian DPA fines security firm €39,000 for employee data violations
The Italian Data Protection Authority (Garante) imposed a total administrative fine of EUR 39,000 on La Patria S.p.A. for failing to respond to employee access requests and for inadequate information about GPS‑derived geolocation data. The…
Garante – Italian Data Protection Authority · General Data Protection Regulation
Moderate
Fine
Decided
Sweden · Oct 8, 2026
Swedish DPA fines Miljödata approx EUR 160,000 for insufficient security measures
The Swedish Data Protection Authority (IMY) imposed an administrative fine of SEK 1,800,000 (≈ EUR 160,000) on IT service provider Miljödata i Karlskrona for violating Article 32(1) GDPR. The authority found the company lacked adequate…
Swedish Data Protection Authority (IMY) · General Data Protection Regulation
Moderate
Enforcement
Decided
France · Oct 8, 2026
CNIL closes injunction against FRANCE TRAVAIL after compliance with data security measures
The French data protection authority (CNIL) closed the injunction issued on 22 January 2026 against FRANCE TRAVAIL, after the organization demonstrated compliance with the security measures required by Article 32 of the GDPR. The original…
CNIL · RGPD
Moderate
Settlement
Settled
United States (federal) · Oct 2, 2026
Meta’s Muse AI Agent raises privacy, security, and child safety concerns amid past FTC consent decree
Meta launched the Muse personal AI agent in September 2026, which collects extensive personal data and can act without clear user permission. EPIC reports multiple incidents where Muse accessed messages, shared home addresses, and…
Federal Trade Commission
Moderate
Enforcement
Announced
Bulgaria · Oct 1, 2026
European Commission sends formal notice to Bulgaria for non‑compliance with the Digital Services Act
The Commission issued a formal notice (INFR(2024)2241) to Bulgaria for failing to fully comply with the DSA, specifically for not designating and empowering the required Digital Services Coordinators. Bulgaria has two months to respond…
European Commission · Digital Services Act
Moderate
Enforcement
Published
Spain · Sep 23, 2026
Spanish Data Protection Agency issues warning to company over AI-driven resume screening
On 23 September 2026 the AEPD sent a formal warning to a company planning to use an AI tool for analysing CVs and assigning scores. The agency stresses that data protection must be built in from the start, including DPIA for high‑risk…
Agencia Española de Protección de Datos (AEPD) · Reglamento General de Protección de Datos (RGPD)
Moderate
Fine
Decided
Spain · Sep 22, 2026 · effective Feb 1, 2023 · deadline Feb 1, 2024
Spanish DPA fines Securitas Direct €100,000 for charging phone line for data subject rights
The Spanish Data Protection Agency (AEPD) issued a final decision on 1 February 2023 finding Securitas Direct in breach of GDPR Article 12(2) by directing data subjects to a chargeable 902 telephone number to exercise their rights. The…
Spanish Data Protection Agency (AEPD) · General Data Protection Regulation
Moderate
Settlement
Settled
United States (federal) · Sep 17, 2026
FTC Announces Additional Payments to Consumers Under Amazon Prime Settlement
The FTC announced that under a revised order in the Amazon Prime settlement, the maximum consumer refund increased from $51 to $200. The change allows more consumers to qualify for payments. The announcement was released on September 17…
Federal Trade Commission
Moderate
Settlement
Settled
United States (federal) · Sep 16, 2026
Settlement codifies Meta's surveillance practices into law as states move to curb ALPR use
The EFF newsletter reports a settlement that enshrines Meta's harmful surveillance into law. It also notes that several U.S. states are introducing measures to limit the use of automated license plate reader (ALPR) networks, citing police…
Moderate
Investigation
Announced
United States (federal) · Sep 14, 2026
Police misuse ALPR data with frivolous reasons, EFF finds
EFF analysis of Flock Safety ALPR logs shows officers across the United States entering nonsensical reasons such as "LOL", "LMAO" and "idk" to access vehicle location data. The lack of warrant requirements and weak audit controls enables…
CPPA · California Delete Act