PrivacySignal

Search & browse the archive

The full corpus — beyond today's front page.

Reset

47 results · page 2 of 2

GDPR / Intl
EDPB · · EU

One-Stop-Shop case digest on right to object and right to erasure updated

The European Data Protection Board has released an updated case digest compiling significant One-Stop-Shop decisions related to individuals' rights to object and to erasure under GDPR, drawn from its public register and developed through its inter-DPA cooperation program.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
Enforcement
iapp.org · · International

GDPR EU representative enforcement continues

EU data protection authorities are continuing to enforce GDPR requirements around the designation of local representatives for non-EU companies doing business in Europe. The trend signals that regulators are treating this structural compliance obligation as a live enforcement priority, not a paper formality.

Who should care: Lawyers · Privacy officers · Compliance · AI governance

#enforcement#gdpr Read original →
Enforcement
EDPB · · EU

Supporting GDPR consistency: EDPB launches dedicated form

The European Data Protection Board has introduced a dedicated online form allowing stakeholders to flag discrepancies in how GDPR is interpreted or enforced across EU member states, including gaps between national supervisory authorities and EDPB positions. The initiative stems from commitments made in the EDPB's Helsinki Statement on clarity and engagement.

Who should care: Lawyers · Privacy officers · Compliance · AI governance

#enforcement#gdpr Read original →
GDPR / Intl
noyb (None of Your Business) · · EU

EU Member States (and Google) suddenly want to keep cookie banners!

The European Commission proposed replacing cookie consent banners with automated browser-based signals as part of its Digital Omnibus simplification package. However, Google and several EU member states, including Germany and France, have pushed back against the change, apparently preferring the current banner system.

Who should care: Lawyers · Privacy officers · AI governance · Compliance · General readers · Policy

#gdpr#regulation#privacy Read original →
GDPR / Intl
EDPB · · EU

EDPB gets a new look: discover the new website and brand identity

The European Data Protection Board has launched a redesigned website and updated brand identity, marking a communications refresh for the EU body responsible for consistent GDPR enforcement and guidance across member states since 2018.

Who should care: Lawyers · Privacy officers · AI governance · Compliance · General readers · Policy

#gdpr#regulation#privacy Read original →
News
IAPP · · International

Are businesses ready for the UK's new data protection complaints regime?

The UK is introducing a revised data protection complaints regime that will change how individuals can raise grievances and how businesses must respond. The shift puts new procedural and compliance pressure on organisations handling personal data under UK GDPR.

Who should care: General readers · Privacy officers · Policy

Enforcement
Inside Privacy (Covington) · · International

Amadeus IT Group Receives GDPR Fine

Spain's data protection authority fined Amadeus IT Group €18 million for GDPR violations tied to its Global Distribution System, which powers booking and travel data infrastructure used across the global travel industry. Amadeus voluntarily paid the fine, receiving a 20% reduction for doing so.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · General readers · Policy

#enforcement#gdpr#privacy Read original →
GDPR / Intl
E EPIC – Electronic Privacy Information Center · · International

Council of the EU Must Prevent GDPR Changes From Eroding Privacy Rights, EPIC, Coalition Urge

EPIC and a coalition of privacy advocates have urged the Council of the European Union to block proposed changes to GDPR that they say would weaken existing privacy protections. The groups are pushing EU member states to resist modifications they believe would roll back rights the regulation was designed to guarantee.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
Enforcement
EDPB · · EU

Italian SA fines a company for post-sick leave questionnaires

Italy's data protection authority fined Magna PT S.p.A. and issued a definitive ban on data processing after the company used questionnaires to collect information from employees returning from sick leave. The regulator found violations covering lawfulness of processing, transparency obligations, and the handling of special category health data under the GDPR.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Enforcement
EDPB · · EU

The Italian Supervisory Authority fined a company 120 000 EUR for tracking five employees who drove company cars

Italy's data protection authority fined Pioneer Hi-Bred Italia Sementi s.r.l. €120,000 for unlawfully tracking five employees via GPS systems in company vehicles, finding violations of GDPR principles on lawful processing, transparency, and data subject information obligations.

Who should care: Lawyers · Privacy officers · Compliance · Cybersecurity · General readers · Policy

#enforcement#regulation#surveillance#privacy Read original →
Enforcement
EDPB · · EU

Imposition of fine on a telecommunications company for violations of data subject’s rights

Greece's data protection authority fined Vodafone-Panafon in February 2026 for failing to properly handle a customer's data rights requests. The violations covered multiple GDPR obligations, including timely responses, the right of access, and the right to restrict processing.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#privacy Read original →
Breach
EDPB · · EU

The Italian SA fined Poste Vita for data breach

Italy's data protection authority issued an administrative fine against insurance firm Poste Vita S.p.A. following a customer complaint alleging unauthorized disclosure of personal data. The regulator found violations of GDPR principles governing data processing and breach-notification obligations.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

#breach#enforcement#privacy Read original →
Enforcement
EDPB · · EU

The Italian SA imposed a 40 000 EUR fine on a company for violating the confidentiality of a employee's email account after the end of his employment

Italy's data protection authority fined LTL S.p.A. €40,000 for accessing a former employee's work email account after his employment ended, breaching GDPR principles on lawful processing, transparency, and the individual's right to access his own data.

Who should care: Lawyers · Privacy officers · Compliance · General readers · Policy

#enforcement#regulation#privacy Read original →
GDPR / Intl
IAPP · · International

GDPR certification goes global, simplifying data transfers and compliance

A GDPR certification mechanism is expanding to cover international data transfers, offering organizations a recognized compliance path across borders. The move is intended to reduce the friction companies face when moving personal data between jurisdictions under Europe's data protection framework.

Who should care: Lawyers · Privacy officers · AI governance · Compliance

#gdpr#regulation Read original →
GDPR / Intl
IAPP · · International

When withdrawal cannot be effectively exercised: Rethinking consent validity under the GDPR

A legal analysis published by the IAPP examines situations under GDPR where individuals nominally retain the right to withdraw consent but face practical barriers that render that right ineffective, raising questions about whether such consent should be considered legally valid in the first place.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
GDPR / Intl
noyb (None of Your Business) · · EU

noyb success: ORF.at must correct misleading cookie banner

Austria's Federal Administrative Court has upheld a ruling requiring public broadcaster ORF to redesign its cookie consent banner so that the accept and reject buttons are visually equal. The decision, which follows a successful complaint by privacy group noyb, addresses ORF's practice of highlighting the 'Accept' button in color, which the court agreed could push users into unintended consent.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

#gdpr#surveillance#privacy Read original →
GDPR / Intl
noyb (None of Your Business) · · EU

LinkedIn locks your GDPR rights behind a paywall

LinkedIn tracks who views user profiles but restricts access to that data behind a paid Premium subscription. Privacy researchers argue this violates Article 15 of GDPR, which gives people the right to access personal data held about them, regardless of whether a company also sells it as a product feature.

Who should care: Lawyers · Privacy officers · AI governance · Cybersecurity · General readers · Policy

#gdpr#surveillance#privacy Read original →
GDPR / Intl
noyb (None of Your Business) · · EU

Digital Omnibus reality check: 83.5% of access requests not properly answered

A new analysis by privacy advocacy group noyb found that over eight years of sending GDPR data access requests to companies, only 16.5% received a satisfactory response. More than half of replies were incomplete, and nearly 30% of companies did not respond at all.

Who should care: Lawyers · Privacy officers · AI governance · General readers · Policy

#gdpr#privacy Read original →
GDPR / Intl
OECD AI Policy Observatory · · International

Rethinking AI data: From scraping to sustainable and ethical data sharing

The OECD's VIADUCT initiative examines growing tensions in AI training data acquisition, questioning the sustainability of web scraping and exploring alternatives centered on ethical data-sharing frameworks that account for copyright, GDPR compliance, and equitable access.

Who should care: Lawyers · Privacy officers · AI governance · Administrators · General readers · Policy

#gdpr#ai-governance#ai Read original →
GDPR / Intl
EDPS · · EU

High-Level Debate: “From Omnibus to Opportunity: Driving Data Protection and Innovation”

On June 8, 2026, the EDPS, Germany's BfDI, and Bavaria's BayLfD will co-host a high-level debate examining the European Commission's Omnibus proposals and their potential effects on GDPR and the wider EU digital regulatory landscape.

Who should care: Lawyers · Privacy officers · AI governance · Compliance · General readers · Policy

#gdpr#regulation#privacy Read original →
Enforcement
noyb (None of Your Business) · · EU

Conseil d'État upholds Criteo's €40M GDPR fine

France's highest administrative court has upheld a €40 million GDPR fine against ad-tracking company Criteo, originally imposed by the CNIL. The regulator found that Criteo could not demonstrate it had obtained valid consent from users and had failed to respect data subject rights.

Who should care: Lawyers · Privacy officers · Compliance · AI governance · Cybersecurity · General readers · Policy

#enforcement#gdpr#surveillance#privacy Read original →
← Prev Page 2 of 2