Privacy Headlines
10 headlines in the database.
EDPB News · 9/23/2026
Background information Date of final decision: 21 September 2026 National case Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 6 (Lawfulness of processing), Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject) and Article 13 (Information to be provided where personal data are collected from the data subject) Decision: Administrative fine, compliance order Key words: GDPR enforcement, technology, accountability, data subjects rights Summary of the Decision Origin of the case The Irish Data Protection Commission (DPC) has announced its final decision following an inquiry into Google Ireland Limited (Google). This own-volition Inquiry was launched by the DPC, in its role as the Lead Supervisory Authority for Google, in February 2020, following receipt of complaints from several European consumer rights organisations, including BEUC, regarding Google’s processing of location data in
EDPB News · 9/22/2026
Background information Date of final decision: 1 February 2023 National case Controller: SECURITAS DIRECT, S.A. Legal Reference(s): Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject) Decision: Administrative fine, Compliance order Key words: Data subject rights Summary of the Decision Origin of the case A consumer association lodged a complaint against Securitas Direct concerning video surveillance notices that directed data subjects to a chargeable 902 telephone number to exercise their rights of access and objection. This was considered to impose a cost on data subjects and to hinder the exercise of their rights. Key Findings The use of a chargeable telephone number for the exercise of data subject rights was contrary to the GDPR requirement that such rights be exercisable free of charge and could discourage data subjects from exercising them. The availability of other free channels on the website did not remedy the i
EDPB News · 9/21/2026
Brussels, 21 September – During its latest plenary, the EDPB has adopted guidelines on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR and the final version of its guidelines on interplay between the Digital Service Act (DSA) and the GDPR . The new EDPB guidelines are a major step in further aligning how Data Protection Authorities decide whether an administrative fine should be imposed, either on its own or alongside other corrective measures. The GDPR significantly increased the corrective powers of DPAs, with fines serving as an important instrument for effective enforcement. The guidelines reaffirm our commitment to providing greater clarity and ensuring the consistent application of the GDPR across Europe. EDPB Deputy Chair, Jelena Virant Burnik Data Protection Authorities (DPAs) should follow a five-step methodology when deciding whether to impose an administrative fine: the DPA checks if the infringement can lead
EDPB News · 9/11/2026
Background information Date of final decision: 21 July 2026 National case Legal Reference(s): Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject), Article 17 (Right to erasure ‘right to be forgotten’) Decision: Administrative fine Key words: Data subject rights Summary of the Decision Origin of the case EXTIA, which specialises in IT and engineering, recruits consultants for various technical projects from its client companies. In 2024, the French Data Protection Authority (CNIL) received several complaints from former employees or candidates, relating to difficulties encountered in exercising their right to erasure or ‘right to be forgotten’. With a view to investigating these complaints, and also in the context of the Coordinated Enforcement Framework action on the ‘Right to erasure’ launched on the initiative of the European Data Protection Board in 2025, an audit of EXTIA was carried out in April 2025. It identified
EDPB News · 9/9/2026
Background information Date of final decision: 3 September 2026 National case Controller: Hôpital Privé de la Loire Legal Reference: Article 32 (Security of processing), Article 34 (Communication of a personal data breach to the data subject), Decision: Administrative fine Keywords: Cybersecurity, Personal data breaches, Health and research Summary of the Decision Origin of the case In summer 2025, an attacker managed to connect to the Computerised Patient Summary (DPI) of the Hôpital Privé de la Loire (Loire’s private hospital), which centralises all the data of the individuals under care. It thus accessed the data of 524 867 patients (some of them health data) and 202 246 persons designated as “trusted third parties”. As a result of this data breach, the French Data Protection Authority (CNIL) carried out a check that identified several failures of the Hôpital Privé de la Loire to comply with the obligations laid down in the General Data Protection Regulation (GDPR). Key findings Fai
EDPB News · 9/3/2026
Background information Date of final decision: 28 August 2026 National case Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 32 (Security of processing), Article 33 (Notification of a personal data breach to the supervisory authority), Article 34 (Communication of a personal data breach to the data subject) Decision: Administrative fine, Compliance order, Communication order personal data breach Key words: GDPR enforcement, Data subjects rights, Fines, Health and research Summary of the Decision Origin of the case This Inquiry commenced on 24 May 2024 as a result of two personal data breaches notified to the Data Protection Commission (DPC) in October 2023 and November 2023. In both cases, individuals gained unauthorised access to paper records stored and retained in both St. Loman’s Hospital (Mullingar, County Westmeath) and St Conal’s Hospital (Letterkenny, County Donegal). Both locations are former disused psychiatric hospitals.Videos uploa
EDPB News · 7/30/2026
Brussels, 30 July – The EDPB and the European Commission organise a remote stakeholder event in the context of their joint work on upcoming guidelines on the interplay between competition and data protection . The event will take place on 15 October 2026 and is an opportunity for stakeholders to inform and support the ongoing work on this topic. The event reflects the EDPB’s commitment to stakeholder engagement and cross-regulatory cooperation, as outlined in the Helsinki statement and in the EDPB Strategy 2024-2027 . Who can participate? The EDPB and the European Commission welcome participation from individuals and organisations with relevant expertise in the topic of the event. How to take part? The call is now closed. Overview of key topics Please find here the overview of topics and questions for the EDPB–EC Stakeholder Event on GDPR & Competition Law . Further background reading Position paper on Interplay between data protection and competition law OECD - The intersection betwee
EDPB News · 7/23/2026
Brussels, 23 July – The EDPB and the European Commission organise a remote stakeholder event in the context of their joint work on upcoming guidelines on the interplay between competition and data protection . The event will take place on 15 October 2026 and is an opportunity for stakeholders to inform and support the ongoing work on this topic. The event reflects the EDPB’s commitment to stakeholder engagement and cross-regulatory cooperation, as outlined in the Helsinki statement and in the EDPB Strategy 2024-2027 . Join the event to have your say This is your chance to contribute directly to an evolving and highly relevant policy area. A call for expression of interest to participate in the stakeholder event will be launched in the following weeks. More details about the date and format of the event will be available soon on the EDPB and European Commission’s websites.
EDPB News · 7/17/2026
Dublin, 17 July– At a high-level meeting in Dublin on 16 and 17 July 2026, the European Data Protection Board (EDPB) called for a clear legal basis for the sharing of information among regulators with different competences. The Board also discussed how to further expand efforts to support a consistent application of the General Data Protection Regulation (GDPR), including through more intense cooperation between Data Protection Authorities (DPAs). A clear legal basis for efficient cross-regulatory cooperation The Board underlines the growing need in the current regulatory environment for effective cooperation between regulators operating in adjacent areas of competence under EU law. The EDPB calls upon the European Commission to propose a legal basis for cross-regulatory information sharing . This should enable regulators to exchange information, including confidential information, relevant to enforcement within their respective areas of competence. First-hand experience of cooperating
EDPB News · 7/14/2026
Brussels, 14 July–The EDPB has published its binding decision of 28 May 2026 under Art.65(1)(a) GDPR*. The decision concerns a dispute submitted by the Belgian Data Protection Authority (DPA) about a complaint against Vlaamse Radio-en Televisieomroeporganisatie (VRT) – a public broadcasting company based in Belgium. The complaint was lodged with the Austrian DPA by the Austrian-based NGO Noyb on behalf of an individual. It concerns the use of cookie banners on the website of VRT . The Belgian DPA, acting as Lead Supervisory Authority (LSA), submitted a draft decision proposing to dismiss the complaint on the basis of an alleged abuse of Art.77 GDPR and Art. 80(1) GDPR. The Austrian DPA, Concerned Supervisory Authority (CSA), objected, arguing that the LSA should not have dismissed the complaint on procedural grounds and should have instead issued a decision on the merits. The Belgian DPA decided not to follow the objection and submitted the case to the EDPB. Outcome of the EDPB decisio
Showing 1 - 10 of 10 results