📬 NicFab Newsletter #39 | 22 settembre 2026
Privacy, Data Protection, AI e Cybersecurity — la rassegna settimanale.
In questo numero:
🏛️ EDPB, 123ª plenaria del 17 settembre: linee guida su rapporto DSA–GDPR, interazione AI Act–protezione dati e uso delle sanzioni pecuniarie rispetto agli altri poteri correttivi
🔴 Garante privacy: comunicati su 24.000 euro all'Azienda sanitaria universitaria Friuli centrale per accessi indebiti al dossier sanitario e 8.000 euro ad ASIS Trento per le telecamere negli spogliatoi della piscina
🟢 Commissione europea, COM(2026) 680: l'approccio UE alla sicurezza online dei minori con cinque nuove iniziative annunciate, dal Digital Fairness Act alla revisione della direttiva AVMS
⚠️ Stato dell'Unione: von der Leyen richiama i rischi dei modelli di frontiera capaci di auto-migliorarsi e l'aumento delle capacità offensive informatiche
🏛️ Parlamento europeo: approvazione dell'accordo UE–Svizzera sui dati PNR e risoluzione sull'impatto dei social media e dell'ambiente online sui giovani
🔍 AEPD: registrata la prima notifica di violazione relativa a un attacco eseguito tramite un agente di intelligenza artificiale
📈 Primo IPCEI dedicato all'intelligenza artificiale con la partecipazione di 19 Stati membri, mentre l'AI Board si riunisce per la nona volta su incidenti e vigilanza
📖 AI Act in Pillole — Parte 39: articolo 43 e valutazione della conformità, tra controllo interno, organismi notificati e modifiche sostanziali
👉 Leggi il numero completo: https://www.nicfab.eu/it/newsletter-issues/2026-09-22-issue-39/?utm_source=telegram&utm_medium=organic-social&utm_campaign=issue-39
📩 Iscriviti alla newsletter: https://www.nicfab.eu/it/pages/newsletter/#iscriviti-ora
#Privacy #GDPR #AIAct #Cybersecurity
Privacy, Data Protection, AI e Cybersecurity — la rassegna settimanale.
In questo numero:
🏛️ EDPB, 123ª plenaria del 17 settembre: linee guida su rapporto DSA–GDPR, interazione AI Act–protezione dati e uso delle sanzioni pecuniarie rispetto agli altri poteri correttivi
🔴 Garante privacy: comunicati su 24.000 euro all'Azienda sanitaria universitaria Friuli centrale per accessi indebiti al dossier sanitario e 8.000 euro ad ASIS Trento per le telecamere negli spogliatoi della piscina
🟢 Commissione europea, COM(2026) 680: l'approccio UE alla sicurezza online dei minori con cinque nuove iniziative annunciate, dal Digital Fairness Act alla revisione della direttiva AVMS
⚠️ Stato dell'Unione: von der Leyen richiama i rischi dei modelli di frontiera capaci di auto-migliorarsi e l'aumento delle capacità offensive informatiche
🏛️ Parlamento europeo: approvazione dell'accordo UE–Svizzera sui dati PNR e risoluzione sull'impatto dei social media e dell'ambiente online sui giovani
🔍 AEPD: registrata la prima notifica di violazione relativa a un attacco eseguito tramite un agente di intelligenza artificiale
📈 Primo IPCEI dedicato all'intelligenza artificiale con la partecipazione di 19 Stati membri, mentre l'AI Board si riunisce per la nona volta su incidenti e vigilanza
📖 AI Act in Pillole — Parte 39: articolo 43 e valutazione della conformità, tra controllo interno, organismi notificati e modifiche sostanziali
👉 Leggi il numero completo: https://www.nicfab.eu/it/newsletter-issues/2026-09-22-issue-39/?utm_source=telegram&utm_medium=organic-social&utm_campaign=issue-39
📩 Iscriviti alla newsletter: https://www.nicfab.eu/it/pages/newsletter/#iscriviti-ora
#Privacy #GDPR #AIAct #Cybersecurity
NicFab Blog — Privacy, GDPR & Intelligenza Artificiale
Newsletter #39 - 22 settembre 2026
NicFab Newsletter #39 — 22 settembre 2026. Weekly review on privacy, data protection, AI regulation, cybersecurity and digital rights.
📬 NicFab Newsletter #39 | September 22, 2026
Privacy, Data Protection, AI & Cybersecurity — weekly review.
In this issue:
🏛️ EDPB 123rd plenary of 17 September: agenda on DSA–GDPR guidelines, AI Act and data protection interplay, and the use of administrative fines alongside other corrective powers
📖 AI Act in a Nutshell, Part 39: Article 43 on conformity assessment — the two routes for Annex III biometric systems, internal control, and substantial modifications
🔴 Garante Privacy Italy: EUR 24,000 fine to the Friuli Centrale health authority for unlawful access to electronic patient records, and EUR 8,000 to ASIS Trento over cameras in swimming pool changing rooms
🏛️ European Commission Communication COM(2026) 680: the EU approach to children's online safety, with five announced initiatives including a Digital Fairness Act and AVMS revision
⚠️ AEPD reports its first notification of a cyberattack executed through an AI agent
📈 European Parliament adopts the resolution on the impact of social media on young people (T10-0313/2026) and consents to the EU–Switzerland PNR agreement
🟢 First AI IPCEI brings together 19 Member States; AI Board holds its ninth meeting on frontier-model incidents, conformity assessments and cyber preparedness
🔍 CJEU, AG Spielmann Opinion in Groupe Canal+ (C-317/25): validity of consent for marketing to 3.9 million people and the CNIL's EUR 600,000 fine
👉 Read the full issue: https://www.nicfab.eu/en/newsletter-issues/2026-09-22-issue-39/?utm_source=telegram&utm_medium=organic-social&utm_campaign=issue-39
📩 Subscribe to the newsletter: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now
#Privacy #GDPR #AIAct #Cybersecurity
Privacy, Data Protection, AI & Cybersecurity — weekly review.
In this issue:
🏛️ EDPB 123rd plenary of 17 September: agenda on DSA–GDPR guidelines, AI Act and data protection interplay, and the use of administrative fines alongside other corrective powers
📖 AI Act in a Nutshell, Part 39: Article 43 on conformity assessment — the two routes for Annex III biometric systems, internal control, and substantial modifications
🔴 Garante Privacy Italy: EUR 24,000 fine to the Friuli Centrale health authority for unlawful access to electronic patient records, and EUR 8,000 to ASIS Trento over cameras in swimming pool changing rooms
🏛️ European Commission Communication COM(2026) 680: the EU approach to children's online safety, with five announced initiatives including a Digital Fairness Act and AVMS revision
⚠️ AEPD reports its first notification of a cyberattack executed through an AI agent
📈 European Parliament adopts the resolution on the impact of social media on young people (T10-0313/2026) and consents to the EU–Switzerland PNR agreement
🟢 First AI IPCEI brings together 19 Member States; AI Board holds its ninth meeting on frontier-model incidents, conformity assessments and cyber preparedness
🔍 CJEU, AG Spielmann Opinion in Groupe Canal+ (C-317/25): validity of consent for marketing to 3.9 million people and the CNIL's EUR 600,000 fine
👉 Read the full issue: https://www.nicfab.eu/en/newsletter-issues/2026-09-22-issue-39/?utm_source=telegram&utm_medium=organic-social&utm_campaign=issue-39
📩 Subscribe to the newsletter: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now
#Privacy #GDPR #AIAct #Cybersecurity
NicFab Blog — Privacy, GDPR & Artificial Intelligence
Newsletter #39 - 22 September 2026
NicFab Newsletter #39 — 22 September 2026. Weekly review on privacy, data protection, AI regulation, cybersecurity and digital rights.
Daily Digest | 22 September 2026
Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective pow...
EDPB publications
https://www.edpb.europa.eu/documents/guideline/guidelines-042026-on-the-application-of-the-power-to-impose-administrative_en
EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines
European Data Protection Board
https://www.edpb.europa.eu/news/edpb-harmonises-fining-methodology-and-adopts-final-dsa-gdpr-guidelines_en
CELEX:52026SC0681: COMMISSION STAFF WORKING DOCUMENT Analysis of impacts Accompanying the document Proposal for a Reg...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CELEX:52026SC0681
Registro nazionale diabete: ok del Garante privacy
Garante Protezione dei dati personali - news
https://www.gpdp.it/garante/doc.jsp?ID=10298308
Google Hit With $463 Million Fine for EU Location Data Rule Breach
SecurityWeek RSS Feed
https://www.securityweek.com/google-hit-with-463-million-fine-for-eu-location-data-rule-breach/
#Privacy #AI #Cybersecurity #DailyDigest
Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective pow...
EDPB publications
https://www.edpb.europa.eu/documents/guideline/guidelines-042026-on-the-application-of-the-power-to-impose-administrative_en
EDPB harmonises fining methodology and adopts final DSA-GDPR guidelines
European Data Protection Board
https://www.edpb.europa.eu/news/edpb-harmonises-fining-methodology-and-adopts-final-dsa-gdpr-guidelines_en
CELEX:52026SC0681: COMMISSION STAFF WORKING DOCUMENT Analysis of impacts Accompanying the document Proposal for a Reg...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CELEX:52026SC0681
Registro nazionale diabete: ok del Garante privacy
Garante Protezione dei dati personali - news
https://www.gpdp.it/garante/doc.jsp?ID=10298308
Google Hit With $463 Million Fine for EU Location Data Rule Breach
SecurityWeek RSS Feed
https://www.securityweek.com/google-hit-with-463-million-fine-for-eu-location-data-rule-breach/
#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 23 September 2026
Google Fined €403 Million Over GDPR Violations Tied to Location Data
The Hacker News
https://thehackernews.com/2026/09/google-fined-403-million-over-gdpr.html
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
BleepingComputer
https://www.bleepingcomputer.com/news/security/sweden-fines-milj-data-183-000-over-breach-affecting-22-million/
CELEX:52026DC0491: REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL on the implementation and im...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CELEX:52026DC0491
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
The Hacker News
https://thehackernews.com/2026/09/check-point-warns-of-management-server.html
Microsoft Disrupts EvilTokens Device Code Phishing Service
Dark Reading
https://www.darkreading.com/identity-access-management-security/microsoft-disrupts-eviltokens-device-code-phishing-service
#Privacy #AI #Cybersecurity #DailyDigest
Google Fined €403 Million Over GDPR Violations Tied to Location Data
The Hacker News
https://thehackernews.com/2026/09/google-fined-403-million-over-gdpr.html
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
BleepingComputer
https://www.bleepingcomputer.com/news/security/sweden-fines-milj-data-183-000-over-breach-affecting-22-million/
CELEX:52026DC0491: REPORT FROM THE COMMISSION TO THE EUROPEAN PARLIAMENT AND THE COUNCIL on the implementation and im...
EUR-Lex | AI Act | EN
https://eur-lex.europa.eu/legal-content/AUTO/?uri=CELEX:52026DC0491
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
The Hacker News
https://thehackernews.com/2026/09/check-point-warns-of-management-server.html
Microsoft Disrupts EvilTokens Device Code Phishing Service
Dark Reading
https://www.darkreading.com/identity-access-management-security/microsoft-disrupts-eviltokens-device-code-phishing-service
#Privacy #AI #Cybersecurity #DailyDigest
Daily Digest | 24 September 2026
The Irish Data Protection Commission fines Google 403 000 000 EUR following Inquiry into Google’s processing of locat...
EDPB News
https://www.edpb.europa.eu/news/the-irish-data-protection-commission-fines-google-403-000-000-eur-following-inquiry_en
Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
SecurityWeek RSS Feed
https://www.securityweek.com/critical-f5-big-ip-vulnerability-exploited-as-zero-day/
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
The Hacker News
https://thehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.html
Ryuk ransomware member sentenced to 24 months in prison
BleepingComputer
https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-sentenced-to-24-months-in-prison/
Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
Dark Reading
https://www.darkreading.com/threat-intelligence/attackers-manipulate-ai-chatbots-mass-disinformation-phishing-campaign
#Privacy #AI #Cybersecurity #DailyDigest
The Irish Data Protection Commission fines Google 403 000 000 EUR following Inquiry into Google’s processing of locat...
EDPB News
https://www.edpb.europa.eu/news/the-irish-data-protection-commission-fines-google-403-000-000-eur-following-inquiry_en
Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
SecurityWeek RSS Feed
https://www.securityweek.com/critical-f5-big-ip-vulnerability-exploited-as-zero-day/
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
The Hacker News
https://thehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.html
Ryuk ransomware member sentenced to 24 months in prison
BleepingComputer
https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-sentenced-to-24-months-in-prison/
Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
Dark Reading
https://www.darkreading.com/threat-intelligence/attackers-manipulate-ai-chatbots-mass-disinformation-phishing-campaign
#Privacy #AI #Cybersecurity #DailyDigest