Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
AI Act: Code of Practice signing — D‑41 before your AI labels
On 22 June 2026, the Commission unveiled the Code of Practice for labelling AI-generated content. Transparency duties (Art. 50) apply from 2 August 2026, with penalties for non-compliance.
CSSF — Axios compromised (31/03/2026): EDR/XDR to detect and notify under DORA
The CSSF warns about the Axios supply‑chain compromise and reminds firms to notify a major ICT incident under Circular 25/893 (DORA). Here is how an EDR/XDR stack helps detect, contain, and notify on time.
IQVIA fined €5M: pseudonymisation ≠ anonymisation
The CNIL fined IQVIA €5M over shortcomings in two health data warehouses. Key takeaway: pseudonymised data are still personal data and the GDPR applies in full.
ENISA 2026: Separate, tested backups aligned with DORA
ENISA updates its SME guide: backups separated from production, encrypted and end-to-end tested. How immutable, isolated vaults meet DORA Art. 12 and thwart ransomware.
GDPR Article 28: Belgian DPA fines SWDE — your DPA must be rock-solid
On 12 May 2026, the Belgian DPA fined SWDE €86,000, including €1,000 for lacking an Article 28-compliant DPA. Key takeaway: without a complete DPA, any outsourced processing leaves the controller non-compliant.
Novo Nordisk rejects $25M after 1.3 TB data theft
On June 16, 2026, FulcrumSec claimed to have stolen over 1 TB from Novo Nordisk and demanded $25M. The company confirmed a June 11 incident, is investigating, and did not pay.
FortiBleed: 73,932 Fortinet firewalls exposed — FIDO2 is now mandatory
FortiBleed exposed ~74,000 Fortinet firewalls/VPNs via stolen and reused credentials. Phishing-resistant MFA (FIDO2/WebAuthn) meets GDPR Article 32 and blocks initial access.
CNPD — Employee vehicle geolocation: 2 months by default, DPIA often required
CNPD clarifies: retention “2 months by default,” no tracking outside working hours if private use is allowed, and DPIA when there is regular/systematic monitoring. Measures to implement immediately.
Kodak hacked: ShinyHunters claims 2.2M records
Kodak confirms an intrusion as ShinyHunters claims 2.2M records. Here’s how RGPD-compliant DLP (Art. 32 and 44‑49) reduces exfiltration and builds evidence.
France Travail fined €5M: GDPR Article 32 moves from theory to audit
The CNIL fined France Travail €5M for breaches of GDPR Article 32: security measures identified in the DPIA but not implemented. A clear signal for Luxembourg organizations.
Foxconn hit by Nitrogen: 8 TB stolen — PAM becomes non-negotiable
On 13/05/2026, Foxconn confirmed an attack claimed by Nitrogen: 8 TB and 11M+ files stolen, with slowdowns at North American plants. A zero-trust PAM meets NIS 2 art. 21 and severs admin access that enables such attacks.
GDPR Article 28: when a vendor is a processor (AEPD SEUR/Citibox)
On 8 June 2026, the AEPD fined SEUR and Citibox for lacking a GDPR Article 28-compliant data processing agreement in a “carrier + smart lockers” setup. Contract labels are not decisive; actual processing reality prevails.