High
Data protection authority action
Decided
Italy · Oct 9, 2026 · effective Sep 23, 2026
Italian DPA fines IQVIA €7 million for unlawful processing of patients’ health data
The Italian Data Protection Authority imposed an administrative fine of EUR 7,000,000 on IQVIA Solutions Italy S.r.l. for processing health data without a legal basis, inadequate information to patients, and missing DPIA and retention…
Italian Data Protection Authority · General Data Protection Regulation
Moderate
Fine
Decided
Sweden · Oct 8, 2026
Swedish DPA fines Miljödata approx EUR 160,000 for insufficient security measures
The Swedish Data Protection Authority (IMY) imposed an administrative fine of SEK 1,800,000 (≈ EUR 160,000) on IT service provider Miljödata i Karlskrona for violating Article 32(1) GDPR. The authority found the company lacked adequate…
Swedish Data Protection Authority (IMY) · General Data Protection Regulation
High
Data protection authority action
Decided
Greece · Oct 8, 2026
Hellenic DPA fines Ministry and EETAA for data breach
The Hellenic Data Protection Authority issued a final decision on 28/07/2026 imposing administrative fines of EUR 200,000 on the Ministry of Social Cohesion and Family Affairs and EUR 150,000 on E.E.T.A.A. S.A. for security deficiencies.…
Hellenic Data Protection Authority · General Data Protection Regulation
Moderate
Enforcement
Decided
France · Oct 8, 2026
CNIL closes injunction against FRANCE TRAVAIL after compliance with data security measures
The French data protection authority (CNIL) closed the injunction issued on 22 January 2026 against FRANCE TRAVAIL, after the organization demonstrated compliance with the security measures required by Article 32 of the GDPR. The original…
CNIL · RGPD
High
Enforcement
Published
Spain · Oct 6, 2026 · effective Oct 6, 2026
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The Spanish Data Protection Agency (AEPD) sent preventive warnings (AI‑00170‑2026 and AI‑00171‑2026) to two local councils regarding planned video‑surveillance systems that use automated image analysis with AI. The agency stresses that the…
Agencia Española de Protección de Datos · Reglamento General de Protección de Datos
Moderate
Settlement
Settled
United States (federal) · Oct 2, 2026
Meta’s Muse AI Agent raises privacy, security, and child safety concerns amid past FTC consent decree
Meta launched the Muse personal AI agent in September 2026, which collects extensive personal data and can act without clear user permission. EPIC reports multiple incidents where Muse accessed messages, shared home addresses, and…
Federal Trade Commission
Low
Enforcement
In effect
EC · Oct 2, 2026
Ecuador orders security expert Ola Bini deported and bans return for 10 years
Ecuadorian immigration authorities detained free software developer Ola Bini in Quito and ordered his immediate deportation, prohibiting his return for a decade. The decision was based on a secret report alleging threats to public…
Ecuadorian immigration authorities
High
Settlement
Settled
New York · Sep 24, 2026
NY AG secures $2.3M settlement and reforms from Labcorp after data breach
The New York Attorney General, together with 43 other state AGs, secured a $2.3 million settlement and mandated security reforms from Laboratory Corporation of America (Labcorp) following a 2019 breach that exposed personal and health data…
New York Attorney General's Office
Moderate
Settlement
Settled
United States (federal) · Sep 16, 2026
Settlement codifies Meta's surveillance practices into law as states move to curb ALPR use
The EFF newsletter reports a settlement that enshrines Meta's harmful surveillance into law. It also notes that several U.S. states are introducing measures to limit the use of automated license plate reader (ALPR) networks, citing police…
Moderate
Investigation
Announced
United States (federal) · Sep 14, 2026
Police misuse ALPR data with frivolous reasons, EFF finds
EFF analysis of Flock Safety ALPR logs shows officers across the United States entering nonsensical reasons such as "LOL", "LMAO" and "idk" to access vehicle location data. The lack of warrant requirements and weak audit controls enables…
CPPA · California Delete Act
Low
Enforcement
Announced
New Jersey · Sep 11, 2026
Cameras capture alleged vandal in Morristown SafetyStick pilot
EPIC senior counsel Jeramie D. Scott said the community should be informed before any surveillance technology is deployed. Cameras in the Morristown SafetyStick pilot captured an alleged camera vandal. Scott warned that surveillance can be…
High
Fine
Decided
France · Sep 11, 2026 · effective Jul 21, 2026
CNIL fines French IT firm EXTIA €300,000 for failing to honor data erasure requests
In 2024 EXTIA received 265 requests for erasure, many of which were not processed or not communicated to the requesters. The CNIL audit found breaches of Articles 12 and 17 GDPR regarding transparency and the right to erasure. The CNIL…
CNIL · General Data Protection Regulation
Moderate
Enforcement
Announced
Spain · Sep 9, 2026
AEPD opens investigation into Ministry of Interior report listing journalists and political leanings
The Spanish Data Protection Agency announced it will launch a formal, ex officio investigation into a Ministry of Interior communication office report that includes journalists' names and alleged political ideologies. The probe will…
Agencia Española de Protección de Datos · Reglamento General de Protección de Datos (RGPD)
High
Enforcement
Decided
Ireland · Sep 3, 2026 · effective Aug 28, 2026
Data Protection Commission issues €645,000 fine and compliance orders against HSE
The Irish Data Protection Commission issued a final decision on 28 August 2026 concerning the Health Service Executive's handling of paper medical records. The DPC found physical security and integrity failures at external storage…
Data Protection Commission · General Data Protection Regulation
Moderate
Settlement
Announced
United States (federal) · Sep 1, 2026
Meta to implement age‑verification framework under $17 B settlement with 52 U.S. states
Meta has agreed to a $17 billion settlement with 52 state attorneys general that mandates age‑assurance technology for its platforms. The settlement requires Meta to apply age‑verification methods within one year, classify users into 18+…
state attorneys general · Children's Online Privacy Protection Act
Moderate
Settlement
Settled
United States (federal) · Aug 26, 2026
EFF says Meta settlement expands data collection and limits youth rights
The settlement reduces young users' access to Meta products and limits their ability to exercise free expression and community participation. It requires age assurance on every product, leading to the collection of additional personal…
Low
Enforcement
Announced
EU-GB · Aug 21, 2026
EFF and civil groups urge Nottinghamshire Police to halt live facial recognition rollout
The Electronic Frontier Foundation and several civil‑society organisations wrote to Nottinghamshire Police in the UK demanding an immediate stop to the proposed roll‑out of live facial recognition (LFR). The letter cites concerns about…
Low
Enforcement
Announced
United States (federal) · Aug 19, 2026
Tech firms privately resist ICE subpoenas seeking user data
ICE has sent hundreds of subpoenas to large technology companies for subscriber information. Meta and Reddit have privately pushed back, questioning statutory authority and objecting to requests tied to protected activity. In some cases…
U.S. Immigration and Customs Enforcement · 19 U.S.C. §1509
Moderate
Data protection authority action
Decided
Ireland · Jul 16, 2025
DPC issues final decision reprimanding Children’s Health Ireland for GDPR security breaches
The Irish Data Protection Commission concluded that Children’s Health Ireland (CHI) at Tallaght University Hospital breached GDPR security and confidentiality obligations. CHI was reprimanded and ordered to bring its processing into…
Data Protection Commission (Ireland) · General Data Protection Regulation
Low
Enforcement
Filed
DE-NRW · Feb 12, 2025
noyb files complaint against WetterOnline for refusing GDPR access request
WetterOnline shares precise location data with more than 300 third‑party advertising companies and rejected a data‑subject access request, citing a "disproportionate effort". noyb filed a complaint with the North Rhine‑Westphalia data…
Data protection authority of North Rhine-Westphalia · General Data Protection Regulation