Skip to main content
European Data Protection Board logo
Back Search Menu
Close menu

Main navigation

  • Home
  • Topics
  • Documents
  • Registers
  • Public consultations

Top navigation

  • About EDPB
  • News
  • Meetings
  • Contact
  • Guide for SMEs
EN

Select your language

  • BGбългарски
  • CSčeština
  • DAdansk
  • DEDeutsch
  • ELελληνικά
  • ESespañol
  • ETeesti
  • FIsuomi
  • FRfrançais
  • GAGaeilge
  • HRhrvatski
  • HUmagyar
  • ITitaliano
  • LTlietuvių
  • LVlatviešu
  • MTMalti
  • NLNederlands
  • PLpolski
  • PTportuguês
  • ROromână
  • SKslovenčina
  • SLslovenščina
  • SVsvenska
Close language switcher

Breadcrumb

  1. Home

Supporting GDPR consistency: EDPB launches dedicated form

Wed, 06/24/2026
Brussels, 24 June – The EDPB has launched a dedicated contact form for stakeholders to report possible inconsistencies in how the GDPR is interpreted across Europe. This initiative reflects the commitments set out in the EDPB Helsinki Statement on enhanced clarity, support and engagement, aimed at strengthening the dialogue with stakeholders and ensuring consistent GDPR enforcement across Europe. The new tool enables stakeholders to report alleged divergences between national positions, as well as between national positions and those of the EDPB. The EDPB will not respond to individual
  • Read more about Supporting GDPR consistency: EDPB launches dedicated form

EDPB gets a new look: discover the new website and brand identity

Fri, 06/12/2026
Brussels, 22 June - Since its establishment in 2018, the core mission of the EDPB has been to uphold and safeguard the right to data protection. Over the years, the EDPB has played a key role in ensuring the consistent application of the GDPR across Europe, by providing guidance on key GDPR concepts and the interaction of the GDPR with other digital laws, as well as through the adoption of consistency opinions and binding decisions. The EDPB is also committed to making GDPR compliance easier for organisations and enhancing its dialogue with stakeholders. The EDPB is glad to announce today the
  • Read more about EDPB gets a new look: discover the new website and brand identity

One-Stop-Shop case digest on right to object and right to erasure updated

Wed, 06/10/2026
Brussels, 25 June - The EDPB has published an update of the One-Stop-Shop (OSS) case digest on right to object and right to erasure. This project has been developed in the framework of the of the Support Pool of Experts programme, which aims to support cooperation among Data Protection Authorities (DPAs). Thematic one-stop-shop case digests are drafted on the basis of one-stop-shop decisions taken from the EDPB’s public register (based on Art.60 GDPR). Such case digests complement the EDPB's public register by selecting and presenting the most important decisions on a given theme and providing
  • Read more about One-Stop-Shop case digest on right to object and right to erasure updated

Coordinated Supervision Committee extends scope to include Eurodac

Wed, 06/10/2026
Brussels, 12 June – As of today, coordinated supervision of the European Union’s asylum and migration database (Eurodac) will be carried out by the Coordinated Supervision Committee (CSC). Eurodac is an information system initially designed to compare the fingerprints of asylum applicants and irregular migrants, which has evolved into a full asylum and migration management system. It plays a key role in implementing the Dublin III Regulation, which aims at determining the Member State responsible for examining an asylum application. Operational since 15 January 2003, this system is currently
  • Read more about Coordinated Supervision Committee extends scope to include Eurodac

EDPB meets with EU Commissioner McGrath and adopts common data breach notification template

Wed, 06/10/2026
Brussels, 10 June – During its latest plenary, the EDPB met with Michael McGrath, Commissioner for Democracy, Justice, the Rule of Law and Consumer Protection. In addition, the Board has adopted a common data breach notification template. The Board held a meeting with Commissioner McGrath, engaging in a fruitful discussion about common priorities and ongoing work on areas of mutual interest. The Digital Omnibus was among the key topics that shaped the discussion. The Board reiterated that, while several proposed changes have been welcomed by the Board, it is crucial not to adopt the proposed
  • Read more about EDPB meets with EU Commissioner McGrath and adopts common data breach notification template

Swedish SA: Administrative fine against Sportadmin

Fri, 06/05/2026
Background information Date of final decision: 26 January 2026 National case Controller: Sportadmin i Skandinavien AB Legal Reference(s): Article 32 (Security of processing), Article 83 (General conditions for imposing administrative fines) Decision: Administrative fine Key words: Administrative fine, Children, Data security, Hacker attack, Sensitive data Summary of the Decision Origin of the case The Swedish Supervisory Authority for Privacy Protection (IMY) has initiated an investigation of the company Sportadmin following a cyber attack in which the attacker gained access to data relating
  • Read more about Swedish SA: Administrative fine against Sportadmin

Polish SA: administrative fine of 9 625 € against Medical Centre for failure to notify a personal data breach

Fri, 06/05/2026
Background information Date of final decision: 15 October 2025 National case Legal Reference(s): Article 31 (Co-operation with the supervisory authority), Article 34 (Communication of a personal data breach to the data subject) Decision: Administrative fine, Warning Key words: Administrative fine, Cooperation with the supervisory authority, Data subject rights Summary of the Decision Origin of the case A Medical Centre dealing, inter alia, with the treatment of infertility, sent confirmation of the execution of the return transfer under the title of which the name of the genetic test was
  • Read more about Polish SA: administrative fine of 9 625 € against Medical Centre for failure to notify a personal data breach

Polish SA: administrative fine of 2 700 € against Specer sp. z o.o. for appointing chairman of the company as its DPO

Fri, 06/05/2026
Background information Date of final decision: 12 September 2025 National case Legal Reference(s): Article 38 (Position of the data protection officer) Decision: Administrative fine Key words: Administrative fine, Data protection officer Summary of the Decision Origin of the case A company whose activities are focused on the provision of medical services notified an incident with data in 2023 to the President of the Personal Data Protection Office: someone else’s documents were issued to the patient. According to the notification, the chairman of the company was also the DPO. The President of
  • Read more about Polish SA: administrative fine of 2 700 € against Specer sp. z o.o. for appointing chairman of the company as its DPO

Imposition of fine on a telecommunications company for violations of data subject’s rights

Thu, 06/04/2026
Background information Date of final decision: 11 February 2026 National case Controller: Vodafone-Panafon S.A Hellenic Telecommunications Company Legal Reference: Article 12: Transparent information, communication and modalities for the exercise of the rights of the data subject, Article 12.2: Facilitation of the exercise of the rights of the data subject, Article 12.3: Time limit for responding to a request, Article 12.4: Information to be provided where no action is taken on the request, Article 15: Right of access by the data subject, Article 18: Right to restriction of processing Decision
  • Read more about Imposition of fine on a telecommunications company for violations of data subject’s rights

Italian SA fines a company for post-sick leave questionnaires

Thu, 06/04/2026
Background information Date of final decision: 10 July 2025 National case Controller: Magna PT S.p.A. Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 6 (Lawfulness of processing), Article 9 (Processing of special categories of personal data), Article 13 (Information to be provided where personal data are collected from the data subject) Decision: Administrative fine, Definitive ban on data processing Key words: Administrative fine, Principles relating to processing of personal data, Transparency, Retention time, Lawfulness of processing, Employment
  • Read more about Italian SA fines a company for post-sick leave questionnaires

Pagination

  • Page 1
  • Page 2
  • Page 3
  • Page 4
  • Page 5
  • Page 6
  • Page 7
  • Page 8
  • Page 9
  • …
  • Next page Next ›
  • Last page Last »
Subscribe to
European Data Protection Board logo

Footer mainnavigation

  • Main menu items
    • Topics
    • Documents
    • Registers
    • Consultations
    • News
    • Meetings
  • About us menu items
    • Task and duties
    • Our members
    • EDPB Secretariat
    • Strategy and work programme
    • Legacy: Art. 29 Working Party

Footer

  • Career opportunities
  • Copyright
  • Cookies
  • General Data Protection Notice
  • Public access to documents
Coordinated Supervision Committee
The CSC ensures the coordinated supervision by data protection authorities.
CSC
Logo of Linkedin Logo of X