Articles, by our experts

Unpacking compliance, security and AI.

Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.

AI Act: Code of Practice signing — D‑41 before your AI labels

On 22 June 2026, the Commission unveiled the Code of Practice for labelling AI-generated content. Transparency duties (Art. 50) apply from 2 August 2026, with penalties for non-compliance.

CSSF — Axios compromised (31/03/2026): EDR/XDR to detect and notify under DORA

The CSSF warns about the Axios supply‑chain compromise and reminds firms to notify a major ICT incident under Circular 25/893 (DORA). Here is how an EDR/XDR stack helps detect, contain, and notify on time.

IQVIA fined €5M: pseudonymisation ≠ anonymisation

The CNIL fined IQVIA €5M over shortcomings in two health data warehouses. Key takeaway: pseudonymised data are still personal data and the GDPR applies in full.

ENISA 2026: Separate, tested backups aligned with DORA

ENISA updates its SME guide: backups separated from production, encrypted and end-to-end tested. How immutable, isolated vaults meet DORA Art. 12 and thwart ransomware.

GDPR Article 28: Belgian DPA fines SWDE — your DPA must be rock-solid

On 12 May 2026, the Belgian DPA fined SWDE €86,000, including €1,000 for lacking an Article 28-compliant DPA. Key takeaway: without a complete DPA, any outsourced processing leaves the controller non-compliant.

Novo Nordisk rejects $25M after 1.3 TB data theft

On June 16, 2026, FulcrumSec claimed to have stolen over 1 TB from Novo Nordisk and demanded $25M. The company confirmed a June 11 incident, is investigating, and did not pay.

FortiBleed: 73,932 Fortinet firewalls exposed — FIDO2 is now mandatory

FortiBleed exposed ~74,000 Fortinet firewalls/VPNs via stolen and reused credentials. Phishing-resistant MFA (FIDO2/WebAuthn) meets GDPR Article 32 and blocks initial access.

CNPD — Employee vehicle geolocation: 2 months by default, DPIA often required

CNPD clarifies: retention “2 months by default,” no tracking outside working hours if private use is allowed, and DPIA when there is regular/systematic monitoring. Measures to implement immediately.

Kodak hacked: ShinyHunters claims 2.2M records

Kodak confirms an intrusion as ShinyHunters claims 2.2M records. Here’s how RGPD-compliant DLP (Art. 32 and 44‑49) reduces exfiltration and builds evidence.

France Travail fined €5M: GDPR Article 32 moves from theory to audit

The CNIL fined France Travail €5M for breaches of GDPR Article 32: security measures identified in the DPIA but not implemented. A clear signal for Luxembourg organizations.

Foxconn hit by Nitrogen: 8 TB stolen — PAM becomes non-negotiable

On 13/05/2026, Foxconn confirmed an attack claimed by Nitrogen: 8 TB and 11M+ files stolen, with slowdowns at North American plants. A zero-trust PAM meets NIS 2 art. 21 and severs admin access that enables such attacks.

GDPR Article 28: when a vendor is a processor (AEPD SEUR/Citibox)

On 8 June 2026, the AEPD fined SEUR and Citibox for lacking a GDPR Article 28-compliant data processing agreement in a “carrier + smart lockers” setup. Contract labels are not decisive; actual processing reality prevails.

← Newer Page 12 / 22 Older →