Skip to main content
European Data Protection Board logo
Back Search Menu
Close menu

Main navigation

  • Home
  • Topics
  • Documents
  • Registers
  • Public consultations

Top navigation

  • About EDPB
  • News
  • Meetings
  • Contact
  • Guide for SMEs
EN

Select your language

  • BGбългарски
  • CSčeština
  • DAdansk
  • DEDeutsch
  • ELελληνικά
  • ESespañol
  • ETeesti
  • FIsuomi
  • FRfrançais
  • GAGaeilge
  • HRhrvatski
  • HUmagyar
  • ITitaliano
  • LTlietuvių
  • LVlatviešu
  • MTMalti
  • NLNederlands
  • PLpolski
  • PTportuguês
  • ROromână
  • SKslovenčina
  • SLslovenščina
  • SVsvenska
Close language switcher

Breadcrumb

  1. Home

The Italian SA imposed a 40 000 EUR fine on a company for violating the confidentiality of a employee's email account after the end of his employment

Thu, 04/06/2026
Background information Date of final decision: 18 December 2025 National case Controller: LTL S.p.A. Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject), Article 15 (Right to access by the data subject) Decision: Administrative fine, Compliance order, Erasure order or Add here your free text for the decision Key words: Administrative fine, Principles relating to processing of personal data, Transparency, Right of access, Employment, Data subject
  • Read more about The Italian SA imposed a 40 000 EUR fine on a company for violating the confidentiality of a employee's email account after the end of his employment

The Italian SA fined Poste Vita for data breach

Thu, 04/06/2026
Background information Date of final decision: 10 July 2025 National case Controller: Poste Vita s.p.a. Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 33 (Notification of a personal data breach to the supervisory authority) Decision: Administrative fine Key words: Administrative fine, Clients, Data security, Insurance, Personal data breach Summary of the Decision Origin of the case The investigation was initiated following a complaint from an insurance company (Poste Vita) customer who complained about the unlawful disclosure of personal data to an
  • Read more about The Italian SA fined Poste Vita for data breach

The Italian Supervisory Authority has fined Verisure Italia for unlawful processing of personal data for direct marketing purposes

Thu, 04/06/2026
Background information Date of final decision: 27 November 2025 National case Controller: Verisure Italia srl Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 7 (Conditions for consent), Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject), Article 13 (Information to be provided where personal data are collected from the data subject), Article 21 (Right to object) Decision: Administrative fine, Compliance order, Erasure order Key words: Administrative fine, Principles relating to
  • Read more about The Italian Supervisory Authority has fined Verisure Italia for unlawful processing of personal data for direct marketing purposes

Inadequate security measures: Italian Supervisory Authority sanctions Aimag

Thu, 28/05/2026
Background information Date of final decision: 27 November 2025 National case Controller: Aimag Spa Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 7 (Conditions for consent), Article 12 (Transparent information, communication and modalities for the exercise of the rights of the data subject), Article 13 (Information to be provided where personal data are collected from the data subject), Article 21 (Right to object) Decision: administrative fine, compliance order, erasure order Key words: administrative fine, principles relating to processing of
  • Read more about Inadequate security measures: Italian Supervisory Authority sanctions Aimag

Norwegian Supervisory Authority fines company for failure to provide access to information

Thu, 28/05/2026
Background information Date of final decision: 16 January 2026 Cross-border case and CSAs: Sweden, Denmark, Spain Controller: Timegrip AS Legal Reference(s): Article 15 (Right to access by the data subject) Decision: administrative fine Key words: administrative fine, data subject rights, right of access, definition of controller, data processing agreement Summary of the Decision Origin of the case The case concerns a retail chain that went bankrupt where the employees needed to document the hours they had worked. The company Timegrip had been the data processor for the retail chain until its
  • Read more about Norwegian Supervisory Authority fines company for failure to provide access to information

Polish SA: administrative fine of 4 935 € for bailiff for failure to notify a personal data breach without undue delay

Thu, 28/05/2026
Background information Date of final decision: 23 October 2025 National case Legal Reference(s): Article 31 (Co-operation with the supervisory authority), Article 33 (Notification of a personal data breach to the supervisory authority), Article 34 (Communication of a personal data breach to the data subject) Decision: administrative fine, communication order personal data breach Key words: administrative fine, cooperation with the supervisory authority, data subject rights Summary of the Decision Origin of the case The bailiff, by mistake, sent a letter of attachment of earnings to the wrong
  • Read more about Polish SA: administrative fine of 4 935 € for bailiff for failure to notify a personal data breach without undue delay

Enhancing compliance and consistency: EDPB adopts DPIA template

Tue, 19/05/2026
Brussels, 14 April - In line with the EDPB’s Helsinki Statement to make GDPR compliance easier and strengthen consistency across Europe, the EDPB has adopted a template for Data Protection Impact Assessments (DPIA). The template will help organisations structure, harmonise and evidence their DPIA reporting processes. The template is complemented by an explainer document providing concise explanations for completing this template effectively, by breaking down key concepts in a simple language and addressing possible questions and knowledge gaps controllers might have. A DPIA is a process
  • Read more about Enhancing compliance and consistency: EDPB adopts DPIA template

EDPB conference on cross-regulatory cooperation: what we learned

Tue, 19/05/2026
Brussels, 23 March - On 17 March 2026, the EDPB conference “Cross-regulatory interplay and cooperation in the EU: a data protection perspective” took place in Brussels. The event showcased high-level discussions, featuring contributions from representatives of key EU institutions, European Data Protection Authorities, academia and industry. Key takeaways from the panel discussions Throughout the day, three panels were held, focusing on 1) data protection and competition, 2) the Digital Markets Act (DMA) and the GDPR, and 3) the Digital Services Act (DSA) and the GDPR. During the first panel
  • Read more about EDPB conference on cross-regulatory cooperation: what we learned

EDPB and EDPS support strengthening EU’s cybersecurity and easing compliance while protecting individuals’ personal data

Tue, 19/05/2026
Brussels, 19 March 2026 – The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) have adopted a Joint Opinion on the European Commission’s proposal for a Cybersecurity Act 2 (CSA2) and the proposal on amendments to the Network and Information Security 2 (NIS2) Directive. On 20 January 2026, the Commission published a cybersecurity package proposal to further strengthen cybersecurity in Europe while making compliance with cybersecurity laws easier for organisations. In their joint opinion, issued at the request of the Commission*, the EDPB and the EDPS
  • Read more about EDPB and EDPS support strengthening EU’s cybersecurity and easing compliance while protecting individuals’ personal data

EDPB brings clarity to data processing for scientific research, speeds up the finalisation of the anonymisation guidelines and approves first European data protection seal as a tool for transfers

Wed, 13/05/2026
Brussels, 16 April – During its latest plenary, the EDPB has adopted Guidelines on processing of personal data for scientific research purposes. In addition, the Board has created a team to speed up the finalisation of the guidelines on anonymisation. The EDPB has also adopted two opinions on the two sets of the Europrivacy certification criteria for approval as European Data Protection Seals, one of which to be used as a tool for transfers. Many areas of scientific research rely on the processing of individuals’ personal data, and this has driven significant scientific breakthroughs that
  • Read more about EDPB brings clarity to data processing for scientific research, speeds up the finalisation of the anonymisation guidelines and approves first European data protection seal as a tool for transfers

Pagination

  • First page « First
  • Previous page ‹ Previous
  • Page 1
  • Page 2
  • Page 3
  • Page 4
  • Page 5
  • Page 6
  • Page 7
  • Page 8
  • Page 9
  • …
  • Next page Next ›
  • Last page Last »
Subscribe to
European Data Protection Board logo

Footer mainnavigation

  • Main menu items
    • Topics
    • Documents
    • Registers
    • Consultations
    • News
    • Meetings
  • About us menu items
    • Task and duties
    • Our members
    • EDPB Secretariat
    • Strategy and work programme
    • Legacy: Art. 29 Working Party

Footer

  • Career opportunities
  • Copyright
  • Cookies
  • General Data Protection Notice
  • Public access to documents
Coordinated Supervision Committee
The CSC ensures the coordinated supervision by data protection authorities.
CSC
Logo of Linkedin Logo of X
×

We use cookies

When you visit our website, if you give your consent, we will use cookies to allow us to collect data for aggregated statistics to improve our services and remember your choice for future visits.
If you don't want this, we will only use cookies to remember your choice for future visits (i.e., essential cookies).
If you don't select any of the two options, no cookies will be deployed, but the banner will re-appear every time you enter our website.
More information on cookies and data protection.