PrivacySignal
Enforcement

Italian SA fines a company for post-sick leave questionnaires

EDPB · · EU · Enforcement

Italy's data protection authority fined Magna PT S.p.A. and issued a definitive ban on data processing after the company used questionnaires to collect information from employees returning from sick leave. The regulator found violations covering lawfulness of processing, transparency obligations, and the handling of special category health data under the GDPR.

Why this matters: When you come back from sick leave, your employer does not get to run a questionnaire about it. Health information is some of the most sensitive data there is, and GDPR treats it that way for a reason. This case is a clean example of a company treating a legal compliance exercise as a data collection opportunity. The fine matters less than the processing ban, which means Magna PT cannot keep doing this at all. Any employer using return-to-work forms should look hard at what they are actually asking and whether they have any legal ground to ask it.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Related stories

Enforcement
B Bloomberg Law News · · International

California Fines Data Broker for First Time Under Privacy Law

California has issued its first fine against a data broker under state privacy law, marking an enforcement milestone for a regulatory framework that has been on the books for years.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
New York Times — Tech · · International

Why Are So Many People Upset About Flock Cameras?

Flock Safety's license plate-reading cameras, now deployed by thousands of U.S. law enforcement agencies, have become a flashpoint for civil liberties organizations who oppose their widespread use. The cameras automatically read and log plate data, building a detailed record of vehicle movements across communities.

Who should care: Lawyers · Privacy officers · Compliance · Cybersecurity · General readers · Policy

#enforcement#surveillance#privacy Read original →
Enforcement
Data Protection Commission · · EU / Ireland

Complaint related to non-compliance with an erasure request to a prospective employer

Ireland's Data Protection Commission handled a complaint in which a job applicant requested that a prospective employer erase their personal data, and the employer failed to comply. The case reflects ongoing enforcement of individuals' right to erasure under data protection law.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#regulation#privacy Read original →
Enforcement
IAPP · · International

CalPrivacy discusses DROP enforcement, data broker fee hike

California's privacy agency discussed enforcement of the Delete Request and Opt-out Platform (DROP) program alongside a potential increase in fees charged to registered data brokers. The conversations reflect ongoing efforts to operationalize California's data broker deletion framework.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
The Record · · International

Irregular, firm behind AI hacking incidents, won't say if there were more

Irregular, the company linked to reported AI hacking incidents involving models from Anthropic, OpenAI, and Meta, has declined to say whether additional incidents occurred beyond those already known, citing an ongoing investigation.

Who should care: Lawyers · Privacy officers · Compliance · General readers · AI governance · Policy

#enforcement#ai Read original →
Enforcement
H Help Net Security · · International

What the first year of EU AI Act transparency enforcement could look like

The EU AI Act is entering its early enforcement phase, and analysts are beginning to map out what transparency requirements will actually look like in practice during the first year. Regulated entities and regulators alike are working out how obligations will be interpreted and applied.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Administrators · General readers · Policy

#enforcement#ai-governance#ai Read original →