PrivacySignal
Enforcement

The Spanish DPA fines Securitas Direct EUR 100 000 for making the exercise of data subject rights more difficult by directing individuals to a chargeable telephone number

EDPB · · EU · Enforcement

Spain's data protection authority fined Securitas Direct €100,000 after the security company directed people to a paid-rate phone number to exercise their data access and objection rights. The case began with a complaint from a consumer association over video surveillance notices that made using those rights more expensive than they should be.

Why this matters: Data protection law gives people the right to see what companies hold on them and to say stop. Those rights are empty if companies make them cost money to use. Securitas Direct ran a video surveillance business and pointed people to a chargeable number when they tried to exercise basic rights. That is not a technicality. It is a wall designed to discourage people from asking questions. Regulators exist to notice that. A €100,000 fine sends a clear signal that access rights need to be genuinely free to use, not just technically available.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Cybersecurity · General readers · Policy

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Analysis

All analysis →

Weekly Editorial Analysis from Experts and Editors

Deep Signal · Part I of III

The Algorithm Said So

Federal rulemakers are deciding what to do when artificial intelligence produces the kind of conclusion that once required an expert. They disagree about how to regulate it. They also disagree about whether the problem has arrived.

· 10 min read Read →

Related stories

Enforcement
EDPB · · EU

Italian DPA fines Emirates EUR 180 000 for infringements concerning passengers’ health data

Italy's data protection authority fined Emirates €180,000 following an investigation into how the airline handled passengers' health data. The ruling cited violations of GDPR principles on lawful processing, transparent communication, and disclosure obligations at the point of data collection.

Who should care: Lawyers · Privacy officers · Compliance · Healthcare professionals · AI governance · General readers · Policy

#enforcement#healthcare#gdpr#regulation#privacy Read original →
Enforcement
The Record · · International

ASOS: Hackers tricked way into employee account before sending rogue push notification

ASOS confirmed a breach in which attackers used social engineering to access an employee account, then sent unauthorized push notifications. The incident exposed some customer personal information, including names and contact details, along with non-personal account data.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
EDPB · · EU

Swedish DPA fines Miljödata i Karlskrona approximately EUR 160 000 for insufficient technical and organisational measures to ensure information security

Sweden's data protection authority fined IT service provider Miljödata i Karlskrona roughly EUR 160,000 after a 2025 cyberattack exposed personal data belonging to 2.2 million individuals, with the stolen data later published on the darknet. The fine was issued under Article 32 of the GDPR for inadequate technical and organisational security measures.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#privacy Read original →
Enforcement
EDPB · · EU

Dutch DPA fines Uber EUR 824 990 000 for unlawful automated decision-making and insufficient information on profiling

The Dutch Data Protection Authority has fined Uber approximately 825 million euros for violating GDPR rules on automated decision-making and failing to properly inform drivers about how profiling data was used against them.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Administrators · Cybersecurity · General readers · Policy

#enforcement#gdpr#ai-governance#surveillance#privacy Read original →
Enforcement
Y Yahoo · · International

Lawsuit claims facial recognition program led to wrongful arrest

A lawsuit alleges that a facial recognition program identified the wrong person, leading to a wrongful arrest. The case adds to a growing record of people facing serious legal consequences because of misidentification by automated systems.

Who should care: Lawyers · Privacy officers · Compliance · Cybersecurity · General readers · Policy

#enforcement#surveillance#privacy Read original →
Enforcement
The Guardian — Tech · · International

Police routinely failing to investigate ‘revenge porn’, research reveals

Research drawing on accounts from 100 people in England and Wales found that police frequently dismiss or fail to act on reports of intimate images shared without consent. Lawyers have filed a super-complaint to push authorities to treat image-based abuse as the serious criminal offense it legally is.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →