Unpacking compliance, security and AI.
Our DPOs and CISOs regularly share their take on regulatory and technical news here: new CNPD guidelines, notable sanctions, incident lessons learned, evolutions on the AI Act, NIS 2 and DORA. To go beyond the press release.
170 articles found · #rgpd
CEVA Logistics: data leak at supplier — Bol and De Bijenkorf customers warned
On August 6, 2026, Bol and De Bijenkorf warned customers that a possible data leak at CEVA Logistics may have exposed names, addresses and phone numbers. The Dutch DPA was notified on August 3; no payments or passwords are implicated so far.
Forg365: a PhaaS targets Microsoft 365 via device code — IAM for NIS 2 and GDPR
On July 9, 2026, ZeroBEC revealed Forg365, a PhaaS combining device‑code and AiTM against Microsoft 365, with public IOCs. Here’s how concrete IAM governance fulfills NIS 2 Art. 21 and GDPR Art. 32.
Foxconn: 8 TB stolen — a DLP to meet GDPR (May 2026)
After the “Nitrogen” attack on Foxconn (~8 TB, 11M files), here’s how a design‑centric DLP meets GDPR Articles 32 and 44‑49 and prevents exfiltration without halting production.
GDPR Article 32: a small Italian fine, big obligations
On 29/04/2026, the Italian Garante imposed an €8,600 fine for security failures (Arts. 5 and 32 GDPR), including non‑compliant password storage. In Luxembourg, proving proportionality and state of the art remains decisive.
AI Act: mandatory transparency from August 2 — act now
The AI Act’s transparency rules (Art. 50) have applied since August 2, 2026. Chatbots, deepfakes and AI-generated content must now be disclosed — including by deployers in Luxembourg.
LastPass (ICO, 20/11/2025): £1.23M for an exfiltrated backup
The UK ICO fined LastPass UK Ltd £1,228,283 after a backup repository was exfiltrated. Why to move to immutable, isolated backups (DORA Art. 12) and how to evidence compliance.
Web scraping to train AI: ICO opens, EDPB tightens
The ICO considers legitimate interests a practicable basis for AI training via web scraping, subject to strict tests and transparency. The EDPB narrows this, stressing Article 14 notice and the constraints of Article 9.
Council of State upholds CNIL authorisation for HDH: cloud impact and proof of compliance
On 20/03/2026, France’s Council of State upheld CNIL’s authorisation for the Health Data Hub hosted on Azure in France. Key takeaway: use CSPM to evidence compliance with GDPR, NIS 2 and CSSF 22/806.
Workplace video surveillance: Garante fine and lessons for Luxembourg
Italy’s Garante fined a shop €2,000 for video surveillance without notice or labor authorization. In Luxembourg, L.261‑1, two‑layer notice and short retention are mandatory.
PNLD: 135,000 police and partner contacts published on the dark web
The UK’s Police National Legal Database (PNLD) confirmed 1.9 GB of data was posted online: 114,000 PNLD subscribers and 21,000 “Ask the Police” users. The attack, claimed by ExfilSquad, was detected on July 26, 2026.
French Council of State — Beaucaire: Authentication Bar Raised
The French Council of State upheld CNIL’s warning over weak passwords. Here’s how to move to phishing‑resistant MFA (FIDO2/WebAuthn) compliant with GDPR Article 32 — and prove it.
Amazon vs CNPD (12/03/2026): fine annulled, fine methodology reset
On 12 March 2026, Luxembourg’s Administrative Court annulled Amazon’s €746m fine while upholding core findings. Key takeaway: apply CJEU (Deutsche Wohnen/Nacionalinis) and robustly justify the GDPR fine methodology.