Skip to main content
ShareEmailLinkedInXWhatappsFacebook
feedback
Share

Italian DPA fines BBVA EUR 5 508 000 for failing to respect a customer’s objection to direct marketing

1 day 3 hours ago

Background information

  • Date of final decision: 3 July 2026
  • National case
  • Controller: Banco Bilbao Vizcaya Argentaria, S.A., Italian branch (BBVA)
  • Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject), Article 21 (Right to object), Article 24 (Responsibility of the controller)
  • Decision: Administrative fine, Compliance order
  • Website topics: Basic principles, Data subjects rights, Marketing

Summary of the Decision

Origin of the case  

The Italian Data Protection Authority (DPA) investigated BBVA, a multinational Spanish banking group, following a complaint from a customer who continued to receive promotional communications through the bank’s mobile app despite having objected to direct marketing.

The customer exercised his right to object through the settings provided in the BBVA app and subsequently reiterated his objection to the bank’s Customer Service. Nevertheless, promotional notifications continued for seven months, from October 2025 to May 2026.

BBVA explained that the customer’s choice had been correctly recorded but that a technical failure prevented synchronisation between its internal systems and the Customer Relationship Management unit responsible for sending commercial communications.

Key Findings

The Italian DPA found that BBVA failed to give effect to the customer’s objection correctly and in a timely manner. During the relevant period, the customer received at least ten unsolicited commercial notifications.

The DPA rejected BBVA’s argument that the customer should have used the dedicated email addresses indicated in its privacy policy. The customer had correctly exercised his right through the app and had also contacted Customer Service. Controllers must facilitate the exercise of data subject rights and cannot disregard a valid request merely because it was not submitted through a preferred channel.

The DPA also found deficiencies in BBVA’s technical and organisational measures. In particular, Customer Service provided incorrect information by telling the customer that promotional pop-up notifications in the app could not be disabled, although BBVA subsequently demonstrated that they could be stopped.

Decision

The Italian DPA found infringements of Articles 5(1)(a), 12, 21 and 24 GDPR and imposed an administrative fine of EUR 5 508 000.

The DPA ordered BBVA to adopt appropriate technical and organisational measures to facilitate the exercise of data subject rights and to ensure that requests are handled correctly and without undue delay. BBVA must also inform the DPA, within 30 days of notification of the decision, of the measures taken to comply with the order.

When determining the fine, the DPA considered that the infringement concerned one data subject, lasted seven months and involved contact data for marketing purposes. It also considered BBVA’s remedial measures as a mitigating factor and a previous relevant infringement as an aggravating factor.

For further information: 

EDPB

Italian DPA fines Emirates EUR 180 000 for infringements concerning passengers’ health data

1 day 3 hours ago

Background information

  • Date of final decision: 14 May 2026
  • National case
  • Controller: Emirates
  • Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject) and Article 13 (Information to be provided where personal data are collected from the data subject)
  • Decision: Administrative fine, Compliance order
  • Website topics: Health and research, Basic principles

Summary of the Decision

Origin of the case  

The Italian Data Protection Authority (DPA) initiated an investigation following a complaint lodged by a passenger concerning the processing of health data by Emirates in connection with assistance for passengers with disabilities or reduced mobility.

The complainant stated that Emirates had required her to complete a MEDIF (Medical Information for Fitness to Travel or Special Assistance) form, although she claimed not to fall within the categories of passengers required to do so. The form collected information concerning passengers’ health, as well as data relating to their doctor and any accompanying person. The complainant also raised concerns about the information provided regarding the processing of such data.

Key Findings

After consulting the Italian Civil Aviation Authority, the Italian DPA found that the processing of health data through the MEDIF form could be lawful where necessary to ensure safe air transport and provide appropriate assistance to passengers with disabilities or reduced mobility. Therefore, it found no infringement of Articles 5(1)(a)-(c), 6(1) and 9 GDPR concerning the lawfulness of collecting such data.

However, Emirates failed to provide sufficiently clear, complete and transparent information about the processing. Passengers could not easily determine in advance whether their condition required completion of the MEDIF form, or clearly identify relevant information such as the purposes, legal bases and retention periods.

The Italian DPA also found that the seven-year retention period applied to MEDIF data was excessive in relation to the purposes of assessing fitness to fly and providing assistance during the journey.

Decision

The Italian DPA imposed an administrative fine of EUR 180 000 on Emirates for infringements of Articles 5(1)(a), 5(1)(e), 12 and 13 GDPR.

The Italian DPA also ordered Emirates, within 30 days, to bring the processing into compliance. In particular, the company must clearly identify the categories of passengers required to complete the MEDIF form and specify which sections and fields are necessary. It must also establish appropriate retention periods for MEDIF data and delete data retained beyond the newly defined period.

In determining the fine, the Italian DPA took into account, among other factors, the limited number of passengers concerned compared with Emirates’ overall customer base, the absence of an intention to discriminate against the complainant, the corrective measures imposed and the absence of previous data protection infringements by the company.

For further information: 

EDPB

Italian DPA fines security company EUR 39 000 for violations concerning employees’ data

1 day 3 hours ago

Background information

  • Date of final decision: 6 August 2026
  • National case
  • Controller: La Patria S.p.A.
  • Legal Reference(s): Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject), Article 13 (Information to be provided where personal data are collected from the data subject) and Article 15 (Right to access by the data subject)
  • Decision: Administrative fine
  • Key words: Data subjects rights, Fines

Summary of the Decision

Origin of the case

The Italian Data Protection Authority (DPA) initiated an investigation following a complaint lodged by a former employee of La Patria S.p.A., a security and technological security company. The complainant claimed that the company had failed to respond to two requests to access documentation concerning disciplinary proceedings against him, including data collected through a GPS system installed on the company vehicle assigned to him. The employee had requested access to the documentation in order to defend himself in disciplinary proceedings which subsequently resulted in his dismissal.

Key Findings

The Garante, the Italian DPA, found that the company had failed to adequately respond to the employee’s access requests. The DPA clarified that a data subject does not need to expressly refer to the GDPR for a request to qualify as an exercise of the right of access. Furthermore, where a controller decides not to comply with a request, it must inform the data subject of the reasons and of the possibility of lodging a complaint or seeking a judicial remedy..

They also found that the company had failed to provide employees with appropriate information on the processing of geolocation data collected through GPS systems installed on company vehicles. Such data constitute personal data because the vehicle’s location can be indirectly linked to the employee driving it.

In addition, the company’s privacy notices incorrectly referred to the processing of special categories of personal data, including information concerning philosophical beliefs and sex life, although the company did not actually process such data.

Decision

The Garante imposed a total administrative fine of EUR 39 000 on La Patria S.p.A. for infringements of Articles 12, 13 and 15 GDPR. The total fine consisted of EUR 22 000 for the infringements concerning the exercise of the right of access and EUR17 000 EUR for the infringements concerning the information provided to employees.

When determining the fine, the Italian DPA took into account, among other factors, that the company had taken steps during the proceedings to bring its processing activities into compliance with the GDPR. In particular, it provided employees with appropriate information concerning the processing of geolocation data and removed incorrect references to special categories of personal data from its privacy notice.

No further corrective measures were imposed, as the infringements had ceased and the company had already taken measures to remedy the identified shortcomings.

For further information: 

EDPB

Italian DPA fines IQVIA EUR 7 000 000 for unlawful processing of patients’ health data

1 day 3 hours ago

Background information

  • Date of final decision: 23 September 2026
  • National case
  • Controller: IQVIA Solutions Italy S.r.l
  • Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 9 (Processing of special categories of personal data),  Article 13 (Information to be provided where personal data are collected from the data subject), Article 25 (Data protection by design and by default), Article 28 (Processor) and Article 35 (Data protection impact assessment)
  • Decision: Administrative fine
  • Key words: Data protection impact assessment, Health and research, Anonymisation/pseudonymisation, Privacy by design and by default, Fines, Basic principles and Controller/processor

Summary of the Decision

Origin of the case

The Italian Data Protection Authority (DPA) carried out an investigation into IQVIA Solutions Italy S.r.l., a company belonging to a multinational group active in health data analytics and clinical research. The investigation concerned a database containing health information relating to approximately one million patients of 800 general practitioners, used for studies commissioned also by pharmaceutical companies. The investigation, which followed inspections carried out in April 2025, was joined with proceedings concerning a personal data breach notified by IQVIA.

Key Findings

The Italian DPA found that the data were not anonymous, as claimed by IQVIA. A persistent identifier assigned to each patient allowed individuals to be tracked over time and, combined with detailed information including year of birth, sex, diagnoses, symptoms, prescriptions, examinations, vaccinations and location data, made it possible to single out and potentially re-identify patients using reasonably available means.

The Italian DPA found that IQVIA, as controller, processed health data without an appropriate legal basis and without providing adequate information to patients. It also failed to establish appropriate retention periods, carry out a data protection impact assessment and implement adequate security measures. The database also contained directly identifying information relating to approximately 3 370 patients, including health data for approximately 3 080 of them.

Decision

The Italian DPA imposed an administrative fine of EUR 7 000 000 on IQVIA Solutions Italy S.r.l.

If IQVIA intends to continue the processing, it must bring it into compliance with the GDPR within 120 days, including by identifying an appropriate legal basis, complying with its information obligations towards patients, carrying out a data protection impact assessment and appointing the general practitioners as processors. Alternatively, the anonymisation process must be carried out independently by the general practitioners in accordance with the safeguards specified by the Italian Authority.

In determining the amount of the fine, the Italian DPA took into account, among other factors, the large number of data subjects involved, the sensitive nature of the data, as well as mitigating factors including the suspension of data transfers by general practitioners and IQVIA’s cooperation during the proceedings.

For further information: 

EDPB

Dutch DPA fines Uber EUR 824 990 000 for unlawful automated decision-making and insufficient information on profiling

2 days ago

Background information

  • Cross-border case
  • Controller: Uber B.V
  • Legal Reference(s): Article 22 (Automated individual decision making, including profiling) and Article 13 (Information to be provided where personal data are collected from the data subject)
  • Decision: Administrative fine
  • Key words: Automated decision making, profiling and online tracking, fines

Summary of the Decision

The Autoriteit Persoonsgegevens (AP), the Dutch data protection authority, imposes a fine of EUR 824 990 000 on Uber. The reason for this is that the AP has ruled that Uber made fully automated decisions about drivers. In case of suspicions of fraud or customer reviews that were too low, drivers' accounts were automatically temporarily deactivated or, in case of persistent low customer reviews, permanently deactivated. As a result, their income was lost via Uber during the deactivation.

Origin of the case

Complaints from 171 French Uber drivers, submitted through the Ligue des droits de l’Homme (LDH) to the French Commission Nationale de l'Informatique et des Libertés (CNIL), led to the investigation. As Uber’s European headquarters are in the Netherlands, the case was handled by the Dutch data protection authority, the Autoriteit Persoonsgegevens (AP), under the GDPR One-Stop-Shop procedure. The case concerned incidents between 2018 and 2022.

Key Findings

According to the AP, Uber has violated the prohibition of fully automated decision-making under the General Data Protection Regulation (GDPR). The AP also found that Uber did not sufficiently inform drivers about automatic decision-making. Uber has now stopped the violations.

Decision

At the moment, the Autoriteit Persoonsgegevens (AP) imposed an administrative fine of EUR 824 990 000 on Uber for unlawful automated decision-making and insufficient information about profiling. Uber has appealed the fine, and there is no final judicial decision yet.

For further information: 

EDPB

Hellenic DPA decision on a data breach involving E.E.T.A.A. S.A. as processor for the Ministry of Social Cohesion and Family Affairs

2 days ago

Background information

  • Date of final decision: 28/07/2026
  • National case
  • Controller: Ministry of Social Cohesion and Family Affairs
  • Legal Reference(s): Article 25 (Data protection by design and by default), Article 28 (Processor), Article 32 (Security of processing), Article 33 (Notification of a personal data breach to the supervisory authority) and Article 34 (Communication of a personal data breach to the data subject)
  • Decision: Administrative fine, Compliance order, 

Summary of the Decision

Origin of the case  

The Hellenic Data Protection Authority (DPA) investigated a large-scale personal data breach affecting the information systems of the Hellenic Agency for Local Development and Local Government (E.E.T.A.A.) S.A., which were used to implement programmes of the Ministry of Social Cohesion and Family Affairs.

Key Findings

The breach affected databases containing personal data of a large number of data subjects, including identification and contact details, financial and health data. The Hellenic DPA found that the Ministry of Social Cohesion and Family Affairs, in its capacity as controller, had complied with its obligations concerning the notification of the breach to the Authority and its communication to the affected data subjects. However, the Authority found that the success of the attack was associated with E.E.T.A.A.’s continued use of outdated information systems and inadequate security measures, despite its awareness of the relevant risks. The DPA found infringements of the requirements relating to the security of processing, as well as deficiencies in compliance with the requirements of Article 28 GDPR governing the relationship between the controller and the processor.

Decision

The Hellenic DPA imposed administrative fines of EUR 200 000 on the Ministry of Social Cohesion and Family Affairs and EUR 150 000 on E.E.T.A.A. It also ordered the parties (i.e. the Ministry and E.E.T.A.A.) to enter into a data processing agreement pursuant to Article 28 GDPR and to fully implement the planned measures to strengthen the security of their information systems.

For further information: 

EDPB

Swedish DPA fines Miljödata i Karlskrona approximately EUR 160 000 for insufficient technical and organisational measures to ensure information security

2 days ago

Background information

  • Date of final decision: 22/09/2026
  • National case
  • Legal Reference(s): Article 32 (Security of processing)
  • Decision: Administrative fine
  • Website topics: Cybersecurity, personal data breaches

Summary of the Decision

Origin of the case

In August 2025, the IT service provider Miljödata was targeted in a cyberattack, during which a malicious actor gained access to a large volume of personal data and subsequently published data on the darknet. According to the company, the incident affected 2.2 million individuals. Among Miljödata’s customers affected by the attack are a majority of Sweden’s municipalities, several regions, and government agencies, as well as a large number of private companies. The compromised data included personal identity numbers, contact details, and sensitive data related to sick leave, rehabilitation, and student-related incidents in schools.

Key Findings

The review shows that the company did not maintain a sufficiently high level of technical and organizational security, given the types of personal data it processed. Miljödata failed to conduct adequate checks when installing new software and did not have automated real-time monitoring of its systems to detect intrusions or suspicious activity.

Decision

IMY, the Swedish Data Protection Authority, assesses that Miljödata acted negligently and has therefore decided to impose an administrative fine of SEK 1 800 000 (approximately EUR 160 000) for violating Article 32(1) GDPR.

For further information: 

 

EDPB

The Irish Data Protection Commission fines Google EUR 403 000 000 following Inquiry into Google’s processing of location data

2 weeks 3 days ago

Background information

  • Date of final decision: 21 September 2026
  • National case
  • Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 6 (Lawfulness of processing), Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject) and Article 13 (Information to be provided where personal data are collected from the data subject)
  • Decision: Administrative fine, compliance order
  • Key words: GDPR enforcement, technology, accountability, data subjects rights

Summary of the Decision

Origin of the case  

The Irish Data Protection Commission (DPC) has announced its final decision following an inquiry into Google Ireland Limited (Google). This own-volition Inquiry was launched by the DPC, in its role as the Lead Supervisory Authority for Google, in February 2020, following receipt of complaints from several European consumer rights organisations, including BEUC, regarding Google’s processing of location data in connection with certain services and products.

The scope of the Inquiry concerned Google’s processing of location data in three specific features – “Web & App Activity”, “Location History” and “Location Accuracy” between the date of application of the GDPR, 25 May 2018 to 4 February 2020.

Key Findings

The decision, which was made by the Commissioners for Data Protection, finds that Google infringed the GDPR in respect of:

  • the lawfulness and fairness of its processing of location data in Web & App Activity and Location History;
  • its accountability obligations under the GDPR by failing to be able to demonstrate compliance with the lawfulness, fairness and transparency principle regarding its processing of personal data in Location Accuracy;
  • its transparency obligations in respect of all three features referred to above; and
  • its retention of location data in Web & App Activity and Location History.

Decision

The DPC has imposed administrative fines totalling EUR 403 000 000 and has ordered Google to bring its processing into compliance within 6 months.

For further information: 

EDPB

The Spanish DPA fines Securitas Direct EUR 100 000 for making the exercise of data subject rights more difficult by directing individuals to a chargeable telephone number

2 weeks 4 days ago

Background information

  • Date of final decision: 1 February 2023
  • National case
  • Controller: SECURITAS DIRECT, S.A.
  • Legal Reference(s): Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject)
  • Decision: Administrative fine, Compliance order
  • Key words: Data subject rights

Summary of the Decision

Origin of the case  

A consumer association lodged a complaint against Securitas Direct concerning video surveillance notices that directed data subjects to a chargeable 902 telephone number to exercise their rights of access and objection. This was considered to impose a cost on data subjects and to hinder the exercise of their rights.

Key Findings

The use of a chargeable telephone number for the exercise of data subject rights was contrary to the GDPR requirement that such rights be exercisable free of charge and could discourage data subjects from exercising them. The availability of other free channels on the website did not remedy the issue, as the notice specifically referred data subjects to the 902 telephone number for this purpose.

Decision

The Spanish DPA (AEPD) found an infringement of Article 12(2) GDPR, which requires controllers to facilitate the exercise by data subjects of their rights under Articles 15 to 22 GDPR. The infringement is subject to the penalties laid down in Article 83(5)(b) GDPR.

The Spanish DPA (AEPD) imposed a fine of EUR 100 000 on Securitas Direct for infringing Article 12 GDPR and ordered the company, as a corrective measure, to replace within 12 months the notices referring to the 902 telephone number in order to bring them into compliance with the GDPR.

For further information: 

EDPB

EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines

2 weeks 5 days ago

Brussels, 21 September – During its latest plenary, the EDPB has adopted guidelines on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR and the final version of its guidelines on interplay between the Digital Service Act (DSA) and the GDPR.

The new EDPB guidelines are a major step in further aligning how Data Protection Authorities decide whether an administrative fine should be imposed, either on its own or alongside other corrective measures.

The GDPR significantly increased the corrective powers of DPAs, with fines serving as an important instrument for effective enforcement. The guidelines reaffirm our commitment to providing greater clarity and ensuring the consistent application of the GDPR across Europe.

EDPB Deputy Chair, Jelena Virant Burnik

Data Protection Authorities (DPAs) should follow a five-step methodology when deciding whether to impose an administrative fine:

  1. the DPA checks if the infringement can lead to a fine, by finding support either directly in the GDPR or in national law.
  2. the DPA determines whether the party under investigation may be fined for the infringement in question. Whether the controller or the processor is liable depends on who is bound by the breached provision.
  3. the DPA assesses whether the infringement has been committed intentionally or negligently, since a culpable infringement is a condition for the imposition of a fine.
  4. the DPA assesses possible aggravating and mitigating factors. If the infringement is minor, there will generally be no fine and a reprimand may be issued instead; if it is not minor, there is a strong presumption that a fine should be imposed.
  5. the DPA assesses whether imposing an administrative fine would be effective, proportionate and dissuasive. In doing so, the DPA may consider whether, in the specific case, there is a reason to deviate from the standard approach.

The guidelines also provide an overview of the corrective powers within the remit of national DPAs and explain their purpose, scope, and how they relate to one another. Corrective measures include warnings, reprimands, orders, limitations (including bans), and the withdrawal of certification.

The Board also provides 14 practical examples illustrating how DPAs can assess the specifics of a case and decide which corrective measures should be imposed, if any.

The guidelines will be subject to public consultation until 13 November 2026, providing stakeholders with the opportunity to comment and give feedback.

Guidelines on DSA and GDPR finalised after public consultation

After public consultation, the EDPB adopted the final version of its guidelines on the interplay between the DSA and the GDPR. The guidelines support the consistent application of both legal acts, particularly where DSA provisions concern the processing of personal data by intermediary service providers and refer to concepts and definitions laid down in the GDPR.

Note to editors:

* These Guidelines replace the WP29 guidelines on the application and setting of administrative fines for the purposes of the Regulation 2016/679 and complement the previously adopted guidelines on the calculation of administrative fines under the GDPR, which rather focus on the methodology for calculating the amount of an administrative fine.

EDPB

Failure to respect the rights of individuals: The CNIL fined EXTIA EUR 300 000

4 weeks 1 day ago

Background information

  • Date of final decision: 21 July 2026
  • National case
  • Legal Reference(s): Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject), Article 17 (Right to erasure ‘right to be forgotten’)
  • Decision: Administrative fine
  • Key words: Data subject rights

Summary of the Decision

Origin of the case  

EXTIA, which specialises in IT and engineering, recruits consultants for various technical projects from its client companies. 

In 2024, the French Data Protection Authority (CNIL) received several complaints from former employees or candidates, relating to difficulties encountered in exercising their right to erasure or ‘right to be forgotten’. With a view to investigating these complaints, and also in the context of the Coordinated Enforcement Framework action on the ‘Right to erasure’ launched on the initiative of the European Data Protection Board in 2025, an audit of EXTIA was carried out in April 2025. It identified breaches of several obligations under the GDPR regarding transparency and respect for individuals’ rights.

Of the 265 requests for erasure received by the company in 2024, the majority of which came from candidates and, occasionally, former employees, more than three quarters had not been dealt with or had not been dealt with satisfactorily.

Key Findings

Failure to process erasure requests (Articles 12 and 17 GDPR)

The CNIL’s restricted committee – the body responsible for issuing sanctions –  noted that 12 requests for erasure received by the company in 2024 had not been processed. It considered that that failure had adversely affected the rights of those persons, including the right to retain control over their data.

Failure to inform individuals of the action taken on their request for erasure (Article 12 GDPR)

The CNIL’s restricted committee considered that the company had failed to fulfil its obligation to inform the persons who had requested the erasure of their data. It noted that 166 persons who had made a request for erasure in 2024 had not been informed of the action taken on that request. Another 27 people had received this information late (outside the legal one-month deadline), with delays of up to several months.

Decision

Consequently, the restricted committee imposed a fine of EUR 300 000 on EXTIA, taking into account the infringement of essential principles relating to the rights of individuals, the number of persons concerned and the fact that EXTIA had already been reminded of its obligations on two occasions.

For further information: 

EDPB

Health data breach: the CNIL fined Hôpital Privé de la Loire EUR 500 000

1 month ago

Background information

  • Date of final decision: 3 September 2026
  • National case
  • Controller: Hôpital Privé de la Loire
  • Legal Reference: Article 32 (Security of processing), Article 34 (Communication of a personal data breach to the data subject), 
  • Decision: Administrative fine
  • Keywords: Cybersecurity, Personal data breaches, Health and research

Summary of the Decision

Origin of the case

In summer 2025, an attacker managed to connect to the Computerised Patient Summary (DPI) of the Hôpital Privé de la Loire (Loire’s private hospital), which centralises all the data of the individuals under care. It thus accessed the data of 524 867 patients (some of them health data) and 202 246 persons designated as “trusted third parties”. As a result of this data breach, the French Data Protection Authority (CNIL) carried out a check that identified several failures of the Hôpital Privé de la Loire to comply with the obligations laid down in the General Data Protection Regulation (GDPR).

Key findings

  • Failure to ensure the security of personal data (Article 32 GDPR)
    The authentication procedure to connect to the hospital’s e-Health Patient Summary, used by users outside the hospital, in particular doctors not affiliated with the hospital, was not sufficiently robust, due to the lack of VPNs and multifactor authentication means. The attacker took advantage of this vulnerability to access the data. Moreover, the access control policy was inadequate: it did not take account of the concept of care team, so that only professionals actually involved in the care of a patient had access to the information covered by medical confidentiality. This lack of access limitation allowed the attacker, using the credentials of a single user account, to access the data of all hospital patients. Finally, the hospital had not taken measures to detect suspicious activity within the e-Health Patient Summary in real time or in the very short term, and to trigger an alert mechanism if necessary. In those circumstances, the attacker was able to explore the hospital’s e-Health Patient Summary for several days and extract a very large volume of data, without that abnormal activity being detected. This vulnerability has contributed to exacerbating the scale of the data breach.
  • Failure to inform data subjects about the data breach (Article 34 GDPR)
    Finally, the restricted committee found that only the patients of the Hôpital Privé de la Loire concerned by the data breach had been informed, but that no direct information had been provided to the 202 246 individuals designated by patients as trusted third parties, even though their personal data had also been stolen by the attacker.

Decision

The restricted committee – the body of the CNIL responsible for issuing sanctions – imposed a fine of EUR 500 000 on the Hôpital Privé de la Loire, taking into account, inter alia, the lack of awareness of essential security principles, the number of persons concerned, the nature of the data compromised and its financial capacities.

Further information:

EDPB

Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE)

1 month 1 week ago

Background information

  • Date of final decision: 28 August 2026
  • National case
  • Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 32 (Security of processing), Article 33 (Notification of a personal data breach to the supervisory authority), Article 34 (Communication of a personal data breach to the data subject)
  • Decision: Administrative fine, Compliance order, Communication order personal data breach
  • Key words: GDPR enforcement, Data subjects rights, Fines, Health and research

Summary of the Decision

Origin of the case  

This Inquiry commenced on 24 May 2024 as a result of two personal data breaches notified to the Data Protection Commission (DPC) in October 2023 and November 2023.

In both cases, individuals gained unauthorised access to paper records stored and retained in both St. Loman’s Hospital (Mullingar, County Westmeath) and St Conal’s Hospital (Letterkenny, County Donegal). Both locations are former disused psychiatric hospitals.Videos uploaded to social media by intruders highlighted that medical records were stored and retained in both facilities.

Key Findings

The Data Protection Commission (DPC) has announced its final decision following an inquiry into the HSE’s processing of personal data contained in paper records, which are stored and retained in the HSE’s external storage facilities. The DPC’s findings identified data protection failings concerning the physical conditions of HSE document storage facilities and the integrity of the documents held within those facilities.

Decision

The DPC issued fines totalling  EUR 645 000, a reprimand and made a number of compliance orders. 

For further information: Data Protection Commission announces Final Decision following Inquiry into the Health Service Executive (HSE) 

EDPB

Stakeholder event on guidelines on the interplay between data protection and competition law: agenda now available

2 months 1 week ago

Brussels, 30 July – The EDPB and the European Commission organise a remote stakeholder event in the context of their joint work on upcoming guidelines on the interplay between competition and data protection. The event will take place on 15 October 2026 and is an opportunity for stakeholders to inform and support the ongoing work on this topic.

The event reflects the EDPB’s commitment to stakeholder engagement and cross-regulatory cooperation, as outlined in the Helsinki statement and in the EDPB Strategy 2024-2027.

Who can participate?

The EDPB and the European Commission welcome participation from individuals and organisations with relevant expertise in the topic of the event.

How to take part?

The call is now closed.

Agenda

Click here to see the agenda.

Overview of key topics

Please find here the overview of topics and questions for the EDPB–EC Stakeholder Event on GDPR & Competition Law.

Further background reading

 

EDPB

Stakeholder event on guidelines on the interplay between data protection and competition law: save the date

2 months 2 weeks ago

Brussels, 23 July – The EDPB and the European Commission organise a remote stakeholder event in the context of their joint work on upcoming guidelines on the interplay between competition and data protection. The event will take place on 15 October 2026 and is an opportunity for stakeholders to inform and support the ongoing work on this topic.

The event reflects the EDPB’s commitment to stakeholder engagement and cross-regulatory cooperation, as outlined in the Helsinki statement and in the EDPB Strategy 2024-2027.

Join the event to have your say

This is your chance to contribute directly to an evolving and highly relevant policy area. A call for expression of interest to participate in the stakeholder event will be launched in the following weeks. More details about the date and format of the event will be available soon on the EDPB and European Commission’s websites.
 

EDPB

EDPB calls for legal basis for cross-regulatory information sharing

2 months 3 weeks ago

Dublin, 17 July– At a high-level meeting in Dublin on 16 and 17 July 2026, the European Data Protection Board (EDPB) called for a clear legal basis for the sharing of information among regulators with different competences. The Board also discussed how to further expand efforts to support a consistent application of the General Data Protection Regulation (GDPR), including through more intense cooperation between Data Protection Authorities (DPAs).

A clear legal basis for efficient cross-regulatory cooperation

The Board underlines the growing need in the current regulatory environment for effective cooperation between regulators operating in adjacent areas of competence under EU law.

The EDPB calls upon the European Commission to propose a legal basis for cross-regulatory information sharing. This should enable regulators to exchange information, including confidential information, relevant to enforcement within their respective areas of competence.

First-hand experience of cooperating with other EU digital regulators at both national and EU level has highlighted the need for stronger legislation to facilitate more effective cross-regulatory cooperation, including enhanced information sharing. This will help remove barriers to cooperation and help improve enforcement outcomes and cross-regulatory coherence.

EDPB Chair, Anu Talus

Strengthening consistency and boosting efficient enforcement

The EDPB recalls the significant progress on cross-border enforcement, as also mentioned in the second European Commission report on the GDPR.

At the same time, DPAs are facing a considerable rise in the number and complexity of complaints, among others as a result of the increased use of AI. This is placing additional strain on already stretched resources limiting all DPAs’ ability to perform all their tasks and exercise their powers under the GDPR efficiently.

DPAs underlined the need to find practical and, where necessary, legislative solutions to address these challenges, to ensure the efficient enforcement of the GDPR, especially in cases where a large number of people is affected.

To further boost cross-border enforcement, the Board discussed practical solutions and how to pool resources to further deepen cooperation between DPAs, including the possibility for complaint-receiving authorities to make resources available to lead supervisory authorities, where useful. In addition, the DPAs will organise a series of workshops on enforcement procedures and to exchange information on national practices, also in the context of implementing the upcoming Procedural Regulation.

Greater use of joint operations will help DPAs pool resources and carry out their enforcement actions with greater efficiency. Through information sharing and joint operations, DPAs will support consistent and effective enforcement, better protect individuals and provide greater regulatory clarity and certainty for industry. In addition, in the context of the upcoming Procedural Regulation, which codifies many DPAs’ existing practices, exchanges of information on national practices will be crucial.

Des Hogan, Chairperson and Commissioner for Data Protection, Ireland

The Board noted that consistency depends on a broad range of actors and actions, going sometimes beyond the reach of the EDPB, for example when related to national legislation and case law. The EDPB members therefore committed to expanding its dialogue with other actors across the data protection ecosystem, in order to support greater consistency of the GDPR’s application.

Finally, the EDPB also took stock of the actions taken following the 2025 Helsinki Statement on enhanced clarity, support and engagement, from improved speed and quality of its guidance, the adoption of cross-regulatory guidance to making available templates and strengthening stakeholder engagement. The EDPB committed to continue to build on it.

EDPB

EDPB requires Belgian DPA to handle the merits of NOYB cookie banner complaint

2 months 3 weeks ago

Brussels, 14 July–The EDPB has published its binding decision of 28 May 2026 under Art.65(1)(a) GDPR*. The decision concerns a dispute submitted by the Belgian Data Protection Authority (DPA) about a complaint against Vlaamse Radio-en Televisieomroeporganisatie (VRT) – a public broadcasting company based in Belgium.

The complaint was lodged with the Austrian DPA by the Austrian-based NGO Noyb on behalf of an individual. It concerns the use of cookie banners on the website of VRT.

The Belgian DPA, acting as Lead Supervisory Authority (LSA), submitted a draft decision proposing to dismiss the complaint on the basis of an alleged abuse of Art.77 GDPR and Art. 80(1) GDPR. The Austrian DPA, Concerned Supervisory Authority (CSA), objected, arguing that the LSA should not have dismissed the complaint on procedural grounds and should have instead issued a decision on the merits.

The Belgian DPA decided not to follow the objection and submitted the case to the EDPB. 

Outcome of the EDPB decision

The EDPB considered the Austrian DPA’s objection relevant and reasoned within the meaning of Art.4(24) GDPR and the EDPB Guidelines on the concept of relevant and reasoned objection and assessed it on the merits. 

The EDPB found that, based on the information available and in line with the CJEU’s test for alleged abuse, the complainant did not abuse their rights under Art.77 and Art.80(1) GDPR. This is because the objective and subjective components needed to prove such abuse were not demonstrated. 

Therefore, the EDPB instructed the LSA not to dismiss the complaint, but to assess it instead on its merits and to submit a new draft decision to the CSAs under Art.60(3) GDPR.

Note to editors:
*Art.65(1)(a) GDPR is a dispute resolution mechanism meant to ensure the correct and consistent application of the GDPR in cross-border cases, addressing disagreements that have arisen between the LSA and the CSAs in a given case.

EDPB

EDPB sheds light on anonymisation and web scraping for generative AI and adopts final version of guidelines on blockchain

3 months ago

Brussels, 8 July– During its latest plenary, the EDPB has adopted guidelines on anonymisation and guidelines on web scraping in the context of generative AI. In addition, the Board has adopted the final version of its guidelines on the processing of personal data through blockchain technologies.

Understanding anonymous data

The new EDPB guidelines bring clarity to the notion of anonymous data, taking also into account the ruling of the Court of Justice of the EU in the case C-413/23 P EDPS v SRB of 4 September 2025 and other CJEU jurisprudence.

The guidelines mark a significant milestone in clarifying the notion of anonymous data, establishing clear standards that facilitate the use of data while protecting individuals' fundamental rights.

In developing these guidelines, we incorporated valuable input from our stakeholder event, showing, once more, our strong commitment to collaborative dialogue as outlined in the EDPB Helsinki statement.

EDPB Chair, Anu Talus

Data is anonymous if it does not relate to an identified or identifiable natural person. Whether this is the case may vary from one entity to another.

Information can relate to an individual because of its content, purpose, or effect. The existence of such a link may not be immediately obvious and could require further analysis.

An individual is considered 'identified or identifiable' if they can be distinguished from others in a specific context using means reasonably likely to be used in a way that makes it possible to treat them differently. Whether the means are reasonably likely to be used will depend on the relevant entity’s perspective and should be assessed in light of all objective factors.

The guidelines also provide a practical framework for organisations to determine if anonymisation is successful. The framework can be applied in two ways: either by assessing differences in capabilities between those who might identify the individual (‘contextual approach’) or for simplicity’s sake by not taking such differences into account (‘simplified approach’), if a controller chooses to do so. The contextual approach reflects the full nuances of the legal standard for anonymisation. The simplified approach can go beyond the legal standard and may lead an anonymising controller to treat data as though it is not anonymous even if it would actually be so for some relevant entities, but this approach can be more convenient, and provide greater confidence that data is actually anonymous.

The framework uses 3 criteria to test if data is anonymous: 1) no record isolation, 2) no linkage, and 3) no inference. If all 3 criteria are met, the data can be safely considered anonymous. If any of these criteria are not satisfied, further analysis should be done to determine if the data may be considered anonymous.

The guidelines will be subject to public consultation until 30 October 2026, providing stakeholders with the opportunity to comment and provide feedback.

Clarifying data protection implications of web scraping for AI development

Web scraping is a large-scale automated data extraction process that often operates without individuals being aware, and which may pose significant risks to the protection of their personal data. In its guidelines on web scraping in the context of generative AI*, the Board clarifies various aspects of the GDPR compliance of web scraping, including the legal basis for such activities and the conditions under which special categories of data can be processed in this context.

The GDPR applies to web scraping when it includes personal data processing operations, such as collection, storage, organisation and retrieval.

When relying on web scraping, particular attention needs to be paid to the purpose limitation principle, and to the transparency principle. However, depending on how the data processing is precisely designed, the controller might not have to inform individuals personally if this proves to be impossible or require excessive effort.

The EDPB recommends scraping data only from reliable sources, recording the timestamp, and validating the data before using them in AI training to ensure compliance with the accuracy principle. The guidelines also advise on measures the controller should implement to comply with the data minimisation principle.

Building on the EDPB Opinion on AI models, the guidelines provide further clarifications and examples on the use of the legitimate interest legal basis in the specific context of web scraping for AI training.

Finally, the EDPB recalls that processing special categories of personal data is in principle prohibited. If web scraping involves such data, both a lawful basis under Art. 6 of GDPR and an exception under Art. 9(2) of the GDPR are required. The EDPB suggests that the Court ruling in GC & Others (C-136/17) may be relevant for incidental or residual collection of special categories of personal data, provided the controller acts within the ”framework of their responsibilities, powers, and capabilities” and implements appropriate technical and organisational measures to prevent the collection and dissemination of such data. The Board emphasises that there is no general exemption from the requirements of Art. 9 GDPR and each case must be assessed individually to determine whether the Court’s reasoning applies.

The guidelines will be subject to public consultation until 30 October 2026, providing stakeholders with the opportunity to comment and provide feedback

Blockchains guidelines finalised after public consultation

Following public consultation, the EDPB has adopted the final version of its guidelines on blockchain technologies. The guidelines help organisations using blockchain technologies to comply with the GDPR. The EDPB explains how blockchains work, assessing the different possible architectures and their implications for the processing of personal data.

In line with the Helsinki statement’s objective to strengthen the dialogue with stakeholders, the Board has also released a report on the outcome of the dedicated public consultation, as well as a track changes version of the guidelines.

Note to editors: 
*Generative AI is a technology aiming to create new content by learning patterns from existing data. It uses specialised machine learning models designed to produce a wide and general variety of outputs such as text, image or audio.

EDPB

EDPB and AMLA to develop Joint Guidelines on partnerships for information sharing

3 months 1 week ago

Brussels/Frankfurt, 1 July – The EDPB and the Anti-Money Laundering Authority (AMLA) are working together to bring greater clarity to a question of growing importance for industry and authorities alike: how to share information to fight financial crime while protecting personal data.

Why information sharing matters

The fight against financial crime depends on cooperation, and information sharing can help detect and prevent money laundering and terrorist financing. Art. 75 of the AML Regulation makes this possible, allowing companies and professionals covered by anti-money laundering rules to share information with each other and with public authorities, within clear limits. The new information sharing possibility will apply from 10 July 2027. To provide clarity on this possibility, the EDPB and AMLA will work together on the development of Joint Guidelines.  

Clearer rules for industry and authorities

Sharing information of this kind means processing personal data, which is why data protection safeguards are essential. The Joint Guidelines, developed by the EDPB and AMLA, will set out in practical terms how partnerships can be built so that effective information sharing and the protection of personal data go hand in hand. This will give everyone involved, from companies and supervisors to FIUs and data protection authorities, more clarity on how to set up successful partnerships.

Share your perspective

Input from industry and stakeholders will be essential to the success of this work. The EDPB and AMLA will hold an event later this year to gather early views on the elements that would benefit from clarification in the Joint Guidelines. In addition, the EDPB and AMLA are planning to launch a public consultation on the draft Guidelines in the first half of 2027. A joint drafting team with members from both the EDPB and AMLA will lead the work. Further details on the scope and content of the Guidelines will be shared as the work progresses.

EDPB

One-Stop-Shop case digest on right to object and right to erasure updated

3 months 2 weeks ago

Brussels, 25 June - The EDPB has published an update of the One-Stop-Shop (OSS) case digest on right to object and right to erasure. This project has been developed in the framework of the of the Support Pool of Experts programme, which aims to support cooperation among Data Protection Authorities (DPAs).

Thematic one-stop-shop case digests are drafted on the basis of one-stop-shop decisions taken from the EDPB’s public register (based on Art.60 GDPR). Such case digests complement the EDPB's public register by selecting and presenting the most important decisions on a given theme and providing aggregate results of relevant decisions on this theme.

The one-stop-shop thematic case digest on the right to object and right to erasure offers insights into how DPAs analyse the internal processes implemented within organisations to comply with these rights. It also lists the most frequent infringements and gives an overview of which corrective measures have been issued. Cases cover for example the exercise of the right to object to direct marketing or the wish of individuals to erase their account or online data profile.

Since the original case digest was finalised, DPAs have adopted hundreds of new OSS decisions on the rights to object and to erasure. The initial case digest has been revised to reflect these developments.

Background

The Support Pool of Experts (SPE) is a key initiative of the EDPB, which is part of the EDPB 2024-2027 Strategy.

The main objective of this programme is to help European DPAs increase their capacity to supervise and enforce data protection rules by developing common tools and giving them access to a wide pool of experts.

EDPB