News

🌸🌼🌺 Pre-checked box: small checkbox, big risk!

Regulated Sectors | 08/12/2025

💸 Interflora fined over €3.1M for… a pre-checked box The DGCCRF (via the Rhône DDPP) has just imposed an administrative fine of €3,166,380 on Interfl...

Read more

🍪 Cookies without consent

Cookies & Trackers | 08/12/2025

💥 €750,000 fine for Condé Nast Regulator: CNILSource: SAN 2025-010 of 20 November 2025 The CNIL has just fined Condé Nast, the famous publisher of Va...

Read more

🇫🇷 Cookies set without consent

Cookies & Trackers | 08/12/2025

💸 €1.5 million fine for American Express Regulator: CNILSource: SAN-2025-011 of 27 November 2025 On 27 November 2025, the CNIL fined American Express...

Read more

🔁 Authentication issue

Confidentiality & Security | 06/11/2025

🇫🇮🔐 Finland – Banking Sector: when 47 minutes cost €865,000Personal data breach following a change in authentication software settings 📌 Key facts: ❗...

Read more

🇮🇹🛑 Passports: massive data theft

Cybersecurity, Confidentiality & Security | 10/09/2025

📂🚫 Data leak: high-res passport scans stolen from multiple Italian hotels!!!🛂 What to do if you stayed in Italy this summer? Between June and August ...

Read more

Cookies: Council of State

Cookies & Trackers | 10/09/2025

💥 Cookies: the post office wins in the Council of State Some cookies are exempt from consent! Reminder: The La Poste / Digiposte case before the Coun...

Read more

🚨 Cloud & sovereignty

Data Transfers, Confidentiality & Security | 10/09/2025

⚠️ANSSI sets the record straightSenate report of 8 July 2025 Sources: official Senate minutes (hearing of V. Strubel), SecNumCloud v3.2 framework (AN...

Read more

👉 Non-compliant practices

Cookies & Trackers, Legal basis | 10/09/2025

🛡️ CNIL: €325M for Google & €150M for SHEIN — Enforcement on cookies & consent Regulator: CNILDecision, Google: SAN 2025-004Decision, SHEIN: SAN 2025...

Read more

🇪🇸 🚫 🔀 No misuse of purpose

Legal basis | 10/09/2025

🚨 ❌ AEPD – No illegal data repurposing: €1,200 penalty after acknowledgment of responsibility Regulator: AEPDDecision: PS-00181-2025, 2025-09-01 An ...

Read more

📚 TOS update

Data Transfers, Legal basis | 18/07/2025

🚚📦 WeTransfer: when a simple TOS update raises an GDPR tsunami On 15 July, WeTransfer discreetly slipped the following statement into its new TOS: ‘W...

Read more

Poland: erroneous risk analysis

Cybersecurity, Regulated Sectors | 18/07/2025

🔗 Cybersecurity ≠ Protection of rights & freedoms: the error that costs Białystok paediatric hospital fined PLN 66,500 / ~€15,000 🇵🇱 UODO sanction :...

Read more

🔒 HR & Facebook

Legal basis | 18/07/2025

HR teams: stop mining employees’ Facebook posts. 🔎 Autostrade per l’Italia fined €420,000 for… “screening” an employee’s Facebook 🇮🇹 Regulator: GPDP ...

Read more

Explore all our areas of expertise:

]]>