Data protection and GDPR
-

Biometric data and dignity: why a lost fingerprint cannot be replaced
On 26 February 2026 the Italian Data Protection Authority (Garante) fined an employer that recorded attendance by means of its employees’ fingerprints, reiterating that “the legal framework in force does not permit the processing of employees’ biometric data for the purpose of recording attendance at work” (Garante). It is the same principle affirmed in February…
-

EU KIDS Act: gradual access to social media and the reversal of the burden of proof
On 17 September 2026 the European Commission adopted the proposed EU KIDS Act: a Union wide minimum age for autonomous social media accounts, safety by design obligations, age assurance and a reversed burden of proof.
-

Informing is not the same as ensuring understanding: comprehensibility as a condition of transparency
There is a provision of Law No 132 of 23 September 2025 that almost always goes unnoticed and which, in our view, carries greater weight than many declarations of principle. Article 4(4) provides that a minor who has reached the age of fourteen may give consent to the processing of data connected with the use…
-

Automated deactivations and Article 22 of Regulation (EU) 2016/679: the fine imposed on Uber and the algorithmic management of work
In August 2026 the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), in cooperation with the French data protection authority (CNIL), imposed on Uber B.V. and Uber Technologies Inc. a fine of EUR 824,990,000 for having taken automated individual decisions in respect of the platform’s drivers (CNIL). It is the third fine arising from the same collective…
-

When the law meets the digital giants: the Meta settlement, minors and the frontier of artificial intelligence agents
What happens when the law meets the digital giants? I discussed this on “Un Giorno Speciale” on Radio Radio, as a guest of Alessio De Paolis. The starting point was the settlement with which Meta closed, in the United States, the lawsuit brought by twenty-nine States over the impact of social media on minors. From…
-

Data on people who are not under investigation: the EDPS on the Europol and Eurojust package
Between 10 and 11 August 2026 the European Data Protection Supervisor adopted four Opinions on the legislative package that the European Commission presented on 24 June 2026 to strengthen Europol and Eurojust and to overhaul the cross-border gathering of evidence. The press releases came out between 12 and 14 August, in the middle of the…
-

Italy implements the AI Act: who supervises, what it costs and where the workplace ban stops
On 4 August 2026 the Italian Council of Ministers gave final approval to the two legislative decrees that align Italian law with Regulation (EU) 2024/1689, under the delegation contained in Article 24 of Law no. 132 of 23 September 2025. The first decree covers the use of artificial intelligence in policing and the related civil…
-

A satirical deepfake is still data processing: the Garante, the Mentana case and disclaimers that fall short
The Italian data protection authority, the Garante per la protezione dei dati personali, has issued a warning to R.T.I. Reti Televisive Italiane, the broadcaster behind the show Striscia la Notizia, over segments in which the image and voice of journalist Enrico Mentana had been manipulated using artificial intelligence. The decision, adopted on 23 July 2026…
-

A score decides the supply: the Garante and the right to know the score
Four companies fined a total of 7.72 million euro because an automated system decided, on the basis of a reliability score, whether or not to activate an electricity and gas supply; and the customers who were turned down could not find out how that score had been built. In its press release of 21 July…
-

Making regulators talk to one another: the EDPB calls for a legal basis to share information
Meeting in Dublin on 16 and 17 July 2026, Europe’s data protection authorities put a clear request to the European Commission: give the Union a legal basis that lets authorities with different remits share information, including confidential information, in order to enforce their respective rules. The request, made by the European Data Protection Board (EDPB)…