As the EU’s AI Act reshapes compliance expectations, companies are testing whether the privacy office can absorb AI oversight without breaking the DPO’s independence.
The EU court’s C-474/24 ruling shows why context, not just labels, can decide whether an online record becomes sensitive health information.
A sanction involving Lidl and Italy’s data protection authority shows how access rights under the GDPR can be undermined by the very forms and internal channels meant to manage them.
A privacy-first age verification model keeps facial images on the handset, but the security value depends on how tightly the rest of the workflow is designed.
A multistate settlement puts genetic data protection under the microscope, with the real lesson centered on authentication, access design, and the fragility of consumer identity controls.
An updated school privacy guide puts phones, class chats, photos, recordings and AI tools under the same lens: everyday digital habits can create real compliance risk.
A FortiEndpoint update points to a broader shift in enterprise defense: the device is no longer just where threats land, but where AI use, data movement, and risk policy increasingly meet.
A Cassation ruling separates complaint handling from sanctions, clarifying that delay in one phase does not automatically erase the regulator’s power to act.
A public extortion post naming two Polish engineering firms shows why survey, LiDAR, and BIM environments are attractive targets even before any breach is independently confirmed.
The latest EDPB guidance frames anonymization as an ongoing assessment, not a one-time label, with re-identification risk, AI, and accountability now central to the privacy test.
A cryptomining incident is a reminder that a gateway built to simplify AI access can also concentrate risk across models, cloud infrastructure, and IAM data.
When privacy rules are treated as operational discipline, they can reduce legal exposure before a mistake becomes a sanction, a liability, or a reputational hit.
A ransomware-extortion listing can be a pressure tactic, a real incident, or both - and for accounting firms, the difference matters because client data is often high value.
A DragonForce ransomware claim against hive360.com is a reminder that extortion posts are signals, not proof, and that HR and payroll systems can be high-value targets even before any breach is confirmed.
A new annual report puts artificial intelligence at the center of a wider fight over personal data, fundamental rights, work, and digital sovereignty.
Italy’s privacy authority has placed artificial intelligence squarely inside the compliance discussion, especially where automated systems can affect health, work, and human oversight.
An LLM-linked extortion operation tied to a Langflow flaw shows how exposed AI workflow servers can become stepping stones toward secrets, service config, and production data.
Novant Health’s push to use AI for patient access, outreach, claims, and clinical support shows how quickly healthcare innovation turns into a question of PHI control, validation, and human oversight.
The real blind spot in data protection is often not the live database, but the copied one - the version developers and testers use when security pressure is lowest.
A €10,000 penalty is small, but the message is not: once systems are compromised, regulators look hard at whether basic security was in place before the incident.