๐ฎ๐น๐ Passports: massive data theft
Cybersecurity, Confidentiality & Security | 10/09/2025
๐๐ซ Data leak: high-res passport scans stolen from multiple Italian hotels!!!๐ What to do if you stayed in Italy this summer?

Between June and August ...
Read more
Cookies: Council of State
Cookies & Trackers | 10/09/2025
๐ฅ Cookies: the post office wins in the Council of State Some cookies are exempt from consent!

Reminder: The La Poste / Digiposte case before the Coun...
Read more
๐จ Cloud & sovereignty
Data Transfers, Confidentiality & Security | 10/09/2025
โ ๏ธANSSI sets the record straightSenate report of 8 July 2025

Sources: official Senate minutes (hearing of V. Strubel), SecNumCloud v3.2 framework (AN...
Read more
๐ Non-compliant practices
Cookies & Trackers, Legal basis | 10/09/2025
๐ก๏ธ CNIL: €325M for Google & €150M for SHEIN — Enforcement on cookies & consent

Regulator: CNILDecision, Google: SAN 2025-004Decision, SHEIN: SAN 2025...
Read more
๐ช๐ธ ๐ซ ๐ No misuse of purpose
Legal basis | 10/09/2025
๐จ โ AEPD – No illegal data repurposing: €1,200 penalty after acknowledgment of responsibility

Regulator: AEPDDecision: PS-00181-2025, 2025-09-01 An ...
Read more
๐ HR & Facebook
Legal basis | 18/07/2025
HR teams: stop mining employees’ Facebook posts. ๐ Autostrade per l’Italia fined €420,000 for… “screening” an employee’s Facebook ๐ฎ๐น

Regulator: GPDP ...
Read more
Poland: erroneous risk analysis
Cybersecurity, Regulated Sectors | 18/07/2025
๐ Cybersecurity ≠ Protection of rights & freedoms: the error that costs Białystok paediatric hospital fined PLN 66,500 / ~€15,000 ๐ต๐ฑ

UODO sanction :...
Read more
๐ TOS update
Data Transfers, Legal basis | 18/07/2025
๐๐ฆ WeTransfer: when a simple TOS update raises an GDPR tsunami

On 15 July, WeTransfer discreetly slipped the following statement into its new TOS: ‘W...
Read more
โ ๏ธ Access request not handled in time!
Data Subject Rights, Regulated Sectors | 18/07/2025

















๐จ๐ฎ๐น Hard Drive Failure + Ignored Access Request = €2,000 Fine for Tirrenia Hospital Srl ๐๐พ

Regulator: GPDP (Italian DPA)Decision: 1...
Read more
๐ข Spain, excessive data collection!
Data Subject Rights, Retention & Minimisation, Legal basis | 08/07/2025
๐ข Do you work in the hotel industry ๐ช๐ธ? Is your privacy policy really up to date?

๐๏ธ If you go to a hotel in Spain ๐ช๐ธ Expect to fill in a form with 4...
Read more
๐ธ๐ช Sweden: breathalyser tests
Retention & Minimisation, Legal basis | 30/06/2025
๐ณ๏ธ๐ซง When daily breath tests sink GDPR compliance: the WÅAB case (Sweden)

Regulator: IMY (Swedish DPA)Source: IMY-2024-1520, 18 June 2025

๐ The facts...
Read more
๐ซ๐ท Penalty amounts
Tools & Documentation | 26/06/2025
โ๏ธ 1. CNIL Penalties๐ No obligation to reveal how fines are calculated“The CNIL must state the legal and factual grounds for a sanction, but it is not...
Read more