EDPB: Toward Operational Standardization of compliance.
The European Data Protection Board (EDPB) has launched a public consultation aimed at developing standardized “ready-to-use” templates. The initiative, inspired by the principles of the Helsinki Declaration, aims to simplify the application of the GDPR through the creation of official templates—that is, predefined models that provide common parameters for reporting and transparency.
The initiative addresses a structural issue in privacy: the gap between the legal obligation, expressed in general rules, and its concrete translation into documents and operational procedures. Uniform templates for the DPIA (i.e., the data protection impact assessment), notifications of data breaches (personal data breaches), notices to data subjects, processing records, and assessments of legitimate interest, in fact, help reduce inconsistencies in implementation, discrepancies in documentation, and difficulties in defending against inspections.
The standardization proposed by the EDPB makes the establishment of safeguards clearer, unifies the language used by legal, technical, and organizational functions, and promotes integrated governance of processing activities.
The template does not replace compliance, but defines the minimum framework for consistency.
The truly decisive factor remains the ability to adapt standard models to the company’s concrete reality.
It is not enough to adopt predefined documents or forms: they must be translated into the company’s own processes, roles, and operational workflows. Only when procedures on paper become actual practices integrated into daily management can we speak of true compliance.
Croatia: Bank Fined €1.5 Million for GDPR Violations in Its Mobile Banking App.
The Croatian Personal Data Protection Authority (AZOP) has imposed a fine of €1.5 million on a bank for serious GDPR violations committed through its mobile banking app, which is used by over 400,000 customers.
The decision, dated December 18, 2025, and pertaining to the Erste Bank case, concerns the indiscriminate collection of the list of apps installed on customers’ smartphones, without a valid legal basis and without adequate notice.
AZOP’s investigation was launched following a report from a customer who had noticed unusual access to data on their device. The investigation found that the bank processed the personal data of 433,922 customers, violating the principles of lawfulness, transparency, and purpose limitation set forth in the GDPR. AZOP also ordered the cessation of the unlawful practices and the adoption of corrective measures, emphasizing the seriousness of the conduct that compromised users’ privacy.
Whistleblowing: 2025 Guidelines Balancing Substantive Protections and Objective Rigor.
The year 2025 marks the end of whistleblowing as a mere formality: three rulings—by the Court of Milan, the Court of Bergamo, and the Court of Cassation—have transformed Legislative Decree 24/2023 into a substantive tool for rebalancing workplace relationships.
With Judgment No. 1680/2025, the Court of Milan applied the relative presumption of retaliation for the first time: when dismissal follows the report in time, the burden of proof shifts, and it is up to the employer to demonstrate that the termination is entirely unrelated to the report. The Court of Bergamo, in judgment no. 951/2025, awarded presumed moral damages (€25,000) to a whistleblower exposed to a hostile environment, without requiring forensic medical evaluations, thereby recognizing the existential impact of isolation.
Finally, the Court of Cassation, in judgment no. 1880/2025, reaffirmed the objective limit of protection: the prohibition on retaliatory measures does not apply when the report is used for essentially personal purposes or for claims related solely to the employment relationship. A typical example is the case of an employee who, facing dismissal for poor performance or a legitimate transfer, files a “report” based solely on internal conflicts to effectively make themselves untouchable. If the content concerns only interpersonal dynamics or unwelcome management decisions, without reporting illegal acts provided for by law or violations of the 231 Model, whistleblower protection does not apply: the objective prerequisite of defending legality is lacking.
Legislative Decree 231/2001: Requirement to Update Following Legislative Decree 211/2025.
Between late 2025 and early 2026, the regulations governing corporate liability under Legislative Decree 231/2001 underwent a significant strengthening, requiring companies to promptly update their organizational, management, and control models. Legislative Decree No. 211 of December 30, 2025, effective as of January 24, 2026, introduced the new Article 25-octies.2 into the list of predicate offenses, dedicated to violations of European Union restrictive measures, transposing Directive (EU) 2024/1226. Conduct such as making funds or economic resources available to sanctioned entities, failing to freeze assets, carrying out prohibited commercial transactions, the import/export of prohibited goods, the provision of restricted services, and the violation of reporting obligations related to European sanctions regimes now fall within the scope of 231 risk. As of January 2026, therefore, international sanctions, export controls, frozen assets, and counterparty checks no longer concern only commercial, banking, or customs compliance, but constitute a full-fledged 231 risk, requiring enhanced controls over customers, suppliers, beneficial owners, cross-border payments, authorizations, exports, and relations with “sensitive” countries. Of particular note is the new sanctions system: for specific violations, monetary penalties are no longer calculated using the traditional quota system, but as a percentage of the entity’s total annual revenue (generally between 1% and 5%), with fixed thresholds of up to 40 million euros when revenue cannot be determined. This makes a substantial update of the 231 Models essential, including a detailed mapping of EU sanction risks, enhanced due diligence procedures on counterparties, and continuous control mechanisms throughout the entire operational chain.
Cybersecurity: The weakest link is still the password.
Today, cybersecurity fails not only in the face of sophisticated attacks, but above all due to human predictability. Even the most advanced infrastructure becomes vulnerable if access is protected by weak or easily guessed credentials.
The password is not a technical detail, but a front-line legal and organizational safeguard, also relevant for the purposes of Article 32 of the GDPR. Proper names, dates of birth, trivial sequences such as “123456,” or references easily reconstructed from social networks remain among the most exploited keys in attacks today, facilitating system intrusions, identity theft, and corporate compromises.
Added to this is the evolution of phishing, enhanced by artificial intelligence: emails and messages with impeccable language and credible context, even deepfake voices and videos capable of imitating colleagues and executives.
The risk no longer concerns only the individual user, but the operational continuity of businesses, organizations, and critical infrastructure.
This is why cybersecurity cannot remain the domain of specialists alone: it is a culture of prevention, continuous training, robust password policies, multi-factor authentication, and daily vigilance for warning signs.
The real question is not whether we are connected, but whether we are truly prepared to protect what we entrust to the digital realm.
Digital Omnibus: Regulatory Simplification or a Redefinition of Digital Rights in the EU?
On November 19, 2025, the European Commission officially presented the proposal for the “Digital Omnibus” regulation, a legislative package aimed at simplifying, harmonizing, and making the European Union’s complex framework of digital rules more consistent. The proposal, currently under review by the European Parliament and the Council, has a cross-cutting impact on several key pieces of legislation, including the GDPR, the ePrivacy Directive, the Data Act, the NIS2 Directive, and the AI Act, with the stated goal of reducing regulatory overlap, compliance costs, and uncertainty regarding application for businesses and public administrations.
The Digital Omnibus comprises at least two main proposals:
■ Digital Omnibus Regulation Proposal — technical provisions to amend and streamline digital regulations, with impacts on the GDPR, ePrivacy, Data Governance, Data Act, NIS2, and other acts.
■ Digital Omnibus on AI Regulation Proposal — more specific measures designed to refine the AI Act and coordinate it with the rest of the digital regulatory framework.
Key Issues and Critical Points in Personal Data Regulation
Among the most significant and critical aspects of the Digital Omnibus proposal is the issue of the definition of “personal data”. The initiative aims to redefine and contextualize this concept for the purposes of the GDPR, introducing criteria that are more functional and tied to the concrete context of identifying the data subject, emphasizing “means reasonably likely to be used.” Such an approach, if adopted, could affect the subjective scope of application of the GDPR, influencing the classification of certain information as protected personal data.
The proposal also addresses certain specific obligations, particularly regarding automated decision-making and cookie management, with the aim of reducing administrative burdens and simplifying compliance. However, these changes raise interpretative doubts, especially regarding the preservation of the protection standards enshrined in the Charter of Fundamental Rights of the European Union.
The package has sparked a wide-ranging debate: some fear a weakening of the GDPR’s safeguards, while others, on the contrary, see an opportunity for a more coherent and certain digital framework. The proposal is still under review by the European Parliament and the Council and remains subject to significant changes.
EDPB: Recommendations for More Privacy-Friendly Online Shopping.
The European Data Protection Board (EDPB), at its plenary session on December 4, 2025, adopted Recommendations for the creation of user accounts on e-commerce websites. The goal is to make online shopping more respectful of users’ privacy by allowing transactions to be carried out without the need to register, favoring a “guest” mode. Registration may be mandatory only in specific cases, such as subscriptions or exclusive offers. These guidelines aim to reduce the collection and processing of personal data, in line with the GDPR’s principles of data protection by design and by default.
The EDPB has also launched a preliminary discussion on the “Digital Omnibus” proposal, expressing concern over the proposed change to the definition of personal data, which could go beyond the case law of the Court of Justice of the EU and undermine the fundamental right to data protection. This change, in fact, risks weakening the protection of data subjects and reducing transparency and accountability of companies in the management of personal data.
United Kingdom: ICO fines British password manager £1.2 million for a data breach.
The UK’s Information Commissioner’s Office (ICO), in a decision dated December 11, 2025, imposed a fine of £1.2 million (approximately €1.375 million) on a British company that provides password management services for a serious data breach that occurred in 2022.
The case involves two separate incidents which, combined, allowed a hacker to access the company’s backup database and steal personal information from up to 1.6 million customers, including names, email addresses, phone numbers, and stored website URLs.
Although the “zero-knowledge” encryption system prevented the decryption of passwords, the failure to implement adequate security measures left personal data exposed. The unauthorized access was made possible by the compromise first of the company’s laptop and then of an employee’s personal device, which contained the decryption key. The breach was deemed severe due to its scope, the categories of data involved, and the failure to adopt sufficiently adequate security controls.
Spain: AEPD fines a Spanish company €1.56 million for a data breach.
The Agencia Española de Protección de Datos (AEPD) imposed, by decision no. EXP202401683 of October 22, 2025, a fine of €1.56 million on a Spanish company that sells sporting goods, for a serious breach of personal data security.
The case involved a data breach of significant scope, affecting approximately 6.4 million people, including customers and employees, residing in Spain, France, Italy, the Netherlands, and Portugal. The cyberattack led to the compromise of identifying data (first name, last name, tax ID), contact information (address, phone number, email), financial data, and health data, with particular relevance to employee data, including that related to health and disability.
The notification of the breach to the data subjects was deemed late and incomplete in relation to the obligations set forth in Article 34 of EU Regulation 2016/679 (GDPR), which requires timely and clear notification in the event of a data breach posing a risk to the rights and freedoms of data subjects. The breach was also considered serious due to the failure to adopt adequate technical and organizational security measures, as well as the cross-border impact and the categories of data involved, which amplified the risk of abuse and harm to the individuals concerned.
WhatsApp: Appeal to the Court of Justice of the European Union to Challenge the €225 Million Fine
WhatsApp Ireland Ltd has filed an appeal with the Court of Justice of the European Union (CJEU) against the €225 million (approximately $236 million) fine for alleged violations of privacy regulations.
The fine was initially imposed by the Irish Data Protection Commission (DPC) due to WhatsApp’s lack of transparency regarding data transfers to Facebook, its parent company.
The investigation conducted by the Irish Data Protection Commission revealed that WhatsApp had not provided users with sufficient information about data transfers.
The EDPB decided to increase the fine to €225 million and ordered WhatsApp to remedy the violations within three months.
Meta, WhatsApp’s parent company, is currently under pressure across the EU, facing numerous data protection-related fines.
In Ireland, the data protection authority has already issued significant fines to Meta in recent years, including a record fine of €1.2 billion in May 2024. Additionally, a recent ruling by the German Supreme Court has paved the way for compensation claims by users for data breaches involving Facebook.








