Italy’s new limits on phone-based offers for electricity and gas do not automatically cancel older marketing consents, leaving lawful calling dependent on how rules, exceptions, and records are interpreted.
An Italian draft decree tied to an EU platform-work directive adds rules on algorithmic transparency, human oversight, and personal-data protection, turning automated management into a compliance issue with security consequences.
The EU’s AI Omnibus is now in force, and its real effect is not just legal simplification - it pushes vendors and deployers toward a more operational model of AI security, documentation, and oversight.
A 2 million euro sanction against Lusha underscores how professional profiles, email addresses, and phone numbers can become a regulated security asset, not just a sales input.
ACN’s updated FAQs show how NIS2 supply-chain obligations are being translated from legal text into day-to-day controls for regulated organizations.
AG 421 is pushing Italy toward an operational AI oversight model, but the hardest questions still sit in the seams between human control, staff competence, and fast-changing compliance duties.
An AGCM sanction tied to clickbaiting shows how sensational headlines, page architecture, personal data, and ad monetization can move digital publishing from taste into regulatory risk.
As companies turn to algorithmic tools for reorganization, the hard question is no longer whether software can rank workers - it is whether every dismissal can still be explained, reviewed, and challenged.
As POS systems and telematic cash registers are linked more tightly, the fiscal upside is clear, but so are the questions around liability, intermediaries, privacy, competition, and merchants who act in good faith.
France’s move on social-network access for teens has revived a harder question: if the risk lives in games, chatbots, and betting too, what exactly does a single age gate solve?
Italy’s cyber environment is still under strain in early 2026, but the move to regular incident notification is beginning to shape how defenders see, sort, and answer risk.
Italy’s financial supervisor is pressing supervised institutions to treat AI as an operational risk problem, not a slow compliance exercise, as the gap between vulnerability discovery and exploitation keeps narrowing.
Privacy sanctions in the energy sector are turning automated credit scoring into a governance test, where data quality, transparency, and the right to challenge a decision matter as much as the score itself.
The European Commission has issued new guidance to help providers and users meet AI Act transparency duties, pushing AI disclosure from policy language into product and deployment practice.
The policy is simple on paper, but enforcing it means building age controls that are accurate, privacy-preserving, and hard to game.
Italy’s NIS2 debate around article 17 turns security vendors, test labs, and threat-intelligence partners into a governed information-sharing channel, not just a procurement relationship.
The EU court’s C-474/24 ruling shows why context, not just labels, can decide whether an online record becomes sensitive health information.
The move from compliance to operational capability is forcing organizations to prove they can keep working when a real crisis hits, not just when paperwork looks complete.
ANPR access through PDND is turning a once-manual administrative routine into a governed digital lookup, with efficiency gains matched by sharper demands on identity, logging, and purpose control.
The move to bring non-accredited private outpatient clinics into FSE 2.0 is chiefly a compliance-and-integration challenge, but it also raises the stakes for document integrity, selective disclosure, and privacy logging.