Training and teaching
-

Records of processing and SMEs: the simplification of Article 30(5) GDPR seen by the EDPB and EDPS
Extending the exemption from the obligation to keep a record of processing activities to organisations with fewer than 750 employees: this is the Commission’s proposal on which the EDPB and the EDPS pronounced in Joint Opinion 01/2025. Favour for the lightening, but with a warning: the register is not just an obligation, it is a…
-

EHDS: the European Health Data Space between primary use, secondary use and prohibited uses
Regulation (EU) 2025/327 establishes the European Health Data Space: the first common European sectoral data space, with staggered application from 26 March 2027. Interoperable health records for care, access bodies for research, and a catalogue of expressly prohibited uses. The essential coordinates of a regulation set to reshape European digital health. With Regulation (EU) 2025/327…
-

Facial recognition in Italian cities: the moratorium extended to 2027 and the AI Act’s limits
After Trento, the Garante scrutinised Rome’s metro and Turin’s “intelligent” cameras. Meanwhile, the Italian moratorium on the use of facial recognition in public places has been extended to 31 December 2027, and the AI Act has set directly applicable prohibitions, from the scraping of facial images to real-time remote biometric identification. The updated map of…
-

The EDPB DPIA template: towards a harmonised impact assessment across the European Economic Area
On 14 April 2026 the EDPB adopted a template for data-protection impact assessments, put out for public consultation until 9 June 2026: predefined fields, an explanatory document and the ambition to become the single model — or the “meta-template” — of the authorities across the entire EEA. What changes, in practice, for controllers and DPOs?…
-

ISO/IEC 42005 and the impact assessment of AI systems: a compass between FRIA and DPIA
Published in May 2025, ISO/IEC 42005 offers organisations guidance for assessing the impact of AI systems on individuals, groups and society. A voluntary tool that sits in an ecosystem crowded with mandatory assessments: the FRIA of Article 27 of the AI Act and the DPIA of Article 35 of the GDPR. How do these three…
-

EN 18286: the quality-management system for Article 17 of the AI Act nears publication
It is the most awaited European standard of the AI Act construction site: EN 18286 on the quality-management system for the Regulation’s regulatory purposes. Public enquiry closed, formal vote concluded in June 2026, publication imminent. But for the presumption of conformity a further step will still be needed: citation in the Official Journal of the…
-

NIS 2, DORA and the Cyber Resilience Act: how to find your way when perimeters overlap
Three European acts, three regulatory logics, one goal: digital resilience. But for those who fall within several perimeters — from a bank to a software vendor — the question is concrete: which discipline prevails? The answer lies in the coordination clauses: Article 4 of NIS 2, the lex specialis of DORA and the complementarity of…
-

GPAI models and the Code of Practice: the voluntary route to Chapter V compliance under the AI Act
Since 2 August 2025 the obligations of Chapter V of the AI Act apply to providers of general-purpose AI models. The General-Purpose AI Code of Practice, delivered to the Commission on 10 July 2025 and signed by over twenty providers, is its voluntary implementing tool: three chapters, from transparency to copyright to the safety and…
-

ISO 45001 and climate change: when occupational health and safety meets the climate
With Amendment 1:2024 “Climate action changes”, climate change entered ISO 45001 expressly — the standard on occupational health and safety management systems, transposed in Italy as UNI EN ISO 45001:2023+A1 in October 2024. And with Accredia Technical Circular 24/2026 the conformity of work equipment became a condition for issuing and maintaining certificates. What does this…
-

ISO 14001:2026, environmental management steps up: what certified organisations need to know
In April 2026 the new edition of ISO 14001 was published, the world’s reference standard for environmental management systems, transposed in Italian as UNI EN ISO 14001 (April 2026 edition), replacing the 2015 version as integrated by the 2024 climate Amendment. Not a revolution, but a targeted update: life cycle, climate, leadership and transparency. And…