Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
Coca‑Cola/Fairlife: ransomware, production halt and data theft
Coca‑Cola confirms data theft following a ransomware attack against Fairlife. U.S. production was suspended mid‑July; the Anubis group claims up to 1 TB of data.
CSSF 26/906: strengthened governance and risk — an ISO 27001 ISMS to evidence NIS 2
CSSF 26/906 tightens governance and risk for payment/e-money institutions, with compliance due by 30 June 2026. A certified ISO 27001 ISMS operationalizes these requirements and NIS 2 Article 21.
CNPD: recording private meetings — legitimate interest only under conditions
CNPD finds consent rarely valid in meetings and allows legitimate interest only after a strict necessity and balancing test. Recordings must be deleted as soon as minutes are approved.
Garante vs Lusha: €2M fine for data brokering without legal basis
Italy’s Garante fined Lusha €2,000,000 for collecting/selling professional contacts without a legal basis and adequate information. A strong signal for the use of data enrichment tools in the EU.
CNIL: New Guidelines on Tracking Pixels in Emails
The CNIL releases guidelines and FAQs to regulate tracking pixels in emails, affecting companies using tracking tools. A key priority for DPOs and CISOs across Europe.
Pope Francis: Data Breach Exposes 700,000 Users of Official Prayer App
The Vatican's official prayer app suffered a major data breach, exposing personal information of over 700,000 users. A security flaw in the code allowed unauthorized access to sensitive data, highlighting risks associated with poorly secured mobile applications.
UL: €98,000 for late notification — what Article 33 really requires
Ireland’s DPC fined the University of Limerick for three late GDPR notifications. Here is how to meet Article 33 and notify the CNPD within 72 hours, with documented timing and solid content.
Wind Tre: €1.715M for unprotected APIs and poor key management
Italy’s DPA fined Wind Tre €1,715,600 for security gaps: weak certificate/key management and APIs lacking basic controls, leading to data exfiltration affecting 365,048 customers (41,359 with payment data).
CSSF 26/904: stronger ICT evidence — inventory/CMDB becomes essential
CSSF Circular 26/904 tightens investment firms’ self‑assessment by requiring concrete evidence on ICT organization. An automated inventory and a relational CMDB are the most reliable way to demonstrate effective control.
C‑97/23 P — Binding decisions of the EDPB are challengeable
The CJEU allows direct actions against an EDPB binding decision (WhatsApp v EDPB, 10/02/2026). Bottom line: intra‑group data sharing must be documented and defensible before the EU courts.
Secureholiday (Ctoutvert): 41,577 Dutch campers affected
Ctoutvert (Secureholiday) confirms a breach affecting 41,577 Dutch campers. No IBANs or cards leaked, but emails, phone numbers and stay dates exposed and used for targeted fraud.
CNIL fines Free/Free Mobile €42M and why to move to FIDO2 MFA
CNIL fined Free and Free Mobile €42M for insufficient security, including weak VPN authentication. Deploying FIDO2/WebAuthn MFA concretely meets GDPR Article 32 and reduces risk.