nicfab
119 subscribers
15 photos
16 files
2.58K links
Canale di aggiornamento su Privacy, Data Protection, IA e Cybersecurity
Channel for updates on Privacy, Data Protection, AI, and Cybersecurity
Download Telegram
โœ‰๏ธ ๐—œ๐˜€๐—ฐ๐—ฟ๐—ถ๐˜‡๐—ถ๐—ผ๐—ป๐—ฒ ๐—ฎ๐—น๐—น๐—ฎ ๐—ก๐—ฒ๐˜„๐˜€๐—น๐—ฒ๐˜๐˜๐—ฒ๐—ฟ

Vuoi ricevere la newsletter settimanale direttamente nella tua casella email ogni martedรฌ?

๐Ÿ“ง ๐—œ๐˜€๐—ฐ๐—ฟ๐—ถ๐˜ƒ๐—ถ๐˜๐—ถ ๐—พ๐˜‚๐—ถ:
๐Ÿ‡ฎ๐Ÿ‡น https://www.nicfab.eu/it/pages/newsletter/#subscribe-now

La newsletter รจ gratuita e copre Privacy, Data Protection, AI, Cybersecurity & Tech Law con focus su sviluppi normativi europei, giurisprudenza e innovazione tecnologica.

---

โœ‰๏ธ ๐—ก๐—ฒ๐˜„๐˜€๐—น๐—ฒ๐˜๐˜๐—ฒ๐—ฟ ๐—ฆ๐˜‚๐—ฏ๐˜€๐—ฐ๐—ฟ๐—ถ๐—ฝ๐˜๐—ถ๐—ผ๐—ป

Want to receive the weekly newsletter directly in your inbox every Tuesday?

๐Ÿ“ง ๐—ฆ๐˜‚๐—ฏ๐˜€๐—ฐ๐—ฟ๐—ถ๐—ฏ๐—ฒ ๐—ต๐—ฒ๐—ฟ๐—ฒ:
๐Ÿ‡ฌ๐Ÿ‡ง https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

The newsletter is free and covers Privacy, Data Protection, AI, Cybersecurity & Tech Law with a focus on European regulatory developments, case law, and technological innovation.

#Newsletter #Subscribe #Privacy #DataProtection #AI #Cybersecurity #TechLaw
๐Ÿ“ฌ NicFab Newsletter #10 | March 3, 2026

Privacy, Data Protection, AI & Cybersecurity โ€” weekly review.

In this issue:

๐Ÿ”ด Italian DPA orders Amazon Italia to cease unlawful processing of 1,800 workers' sensitive data including medical conditions and union activities

๐Ÿ›๏ธ EDPB endorses Global Privacy Assembly statement addressing AI-generated imagery risks with 61 authorities calling for robust safeguards

๐Ÿ“Š European Parliament publishes detailed Digital Omnibus study analyzing interconnections in EU digital legislation and regulatory overlaps

โš ๏ธ CISA warns of RESURGE malware remaining dormant on Ivanti devices posing ongoing cybersecurity threats

๐ŸŸข CNIL launches PANAME project inviting professionals to test innovative GDPR audit tools specifically designed for AI models

๐Ÿ” Canadian Tire data breach affects 38 million accounts highlighting vulnerabilities in retail cybersecurity infrastructure

๐Ÿ“– AI Act Explained Part 10: Article 14 on Human Oversight requirements and the fundamental principle of human-centered AI systems

๐Ÿ‘‰ Read the full issue: https://www.nicfab.eu/en/newsletter/2026-03-03-issue-10/

๐Ÿ“ฉ Subscribe to the newsletter: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

#Privacy #GDPR #AIAct #Cybersecurity
๐Ÿ“ฌ NicFab Newsletter #11 | March 10, 2026

Privacy, Data Protection, AI & Cybersecurity โ€” weekly review.

In this issue:

๐Ÿ›๏ธ Italian DPA monitors "Forest Family" case, emphasizing heightened protection standards for minors exposed to media attention

๐Ÿ“Š EDPB publishes comprehensive data brokers market study with methodology for identifying entities and analyzing business models

๐ŸŸข CNIL closes injunction against KASPR following compliance efforts after โ‚ฌ240,000 fine for LinkedIn data scraping violations

โš ๏ธ Cisco Catalyst SD-WAN vulnerabilities now widely exploited with CVSS 9.8 flaws added to CISA KEV catalog

๐Ÿ” UK ICO investigates Meta's Smart Glasses after privacy breach reports and data harvesting concerns

๐Ÿ“ˆ EU Member States prepare to roll out European Digital Identity Wallets this year with new privacy implications

๐Ÿ”ด Cognizant TriZetto breach exposes health data of 3.4 million patients in latest healthcare cybersecurity incident

๐Ÿ“– AI Act Explained Part 11: Article 15 requirements for accuracy, robustness and cybersecurity integration from design phase

๐Ÿ‘‰ Read the full issue: https://www.nicfab.eu/en/newsletter/2026-03-10-issue-11/

๐Ÿ“ฉ Subscribe to the newsletter: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

#Privacy #GDPR #AIAct #Cybersecurity
๐Ÿ“ฌ NicFab Newsletter #12 | March 17, 2026

Privacy, Data Protection, AI & Cybersecurity โ€” weekly review.

In this issue:

๐Ÿ”ด Intesa Sanpaolo fined โ‚ฌ17.6 million for unlawful profiling of 2.4 million customers transferred to digital subsidiary Isybank

๐Ÿ”ด Acea Energia sanctioned โ‚ฌ2 million for over 1,200 fraudulent door-to-door contracts activated without customer knowledge

๐Ÿ›๏ธ EDPB and EDPS publish joint opinion supporting European Biotech Act while requesting specific safeguards for health data

๐Ÿ“Š European Commission launches TraceMap, new AI platform for food safety using artificial intelligence to detect fraud and contamination

๐Ÿ” CNIL issues new recommendations for web filtering proxy servers balancing corporate cybersecurity with GDPR compliance

โš ๏ธ Operation Synergia III targets international cybercrime while SocksEscort botnet dismantled with 369,000 compromised IPs

๐Ÿ“ˆ EU moves toward banning AI nudification apps following high-profile cases and growing regulatory concerns

๐Ÿ“– AI Act Explained Part 12 covers Article 16 obligations for high-risk AI system providers including technical documentation requirements

๐Ÿ‘‰ Read the full issue: https://www.nicfab.eu/en/newsletter/2026-03-17-issue-12/

๐Ÿ“ฉ Subscribe to the newsletter: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

#Privacy #GDPR #AIAct #Cybersecurity
๐Ÿ“ฉ NicFab Newsletter #13 โ€” March 24, 2026

Issue #13 of the bilingual (IT/EN) newsletter on privacy, data protection, AI regulation and cybersecurity is now available.

This week:
๐Ÿ”น Rome Court annuls the โ‚ฌ15M fine against OpenAI
๐Ÿ”น EDPB launches CEF 2026 on transparency (25 DPAs)
๐Ÿ”น Chat Control โ€” no deal between Parliament and Council
๐Ÿ”น EDPB-EDPS Joint Opinion on Cybersecurity Act 2 & NIS2
๐Ÿ”น EU AI Act delay approved
๐Ÿ”น EU sanctions Chinese and Iranian entities for cyberattacks

๐ŸŽ™๏ธ NEW: Podcast launches today โ€” Legal Prompting, Episode #1
๐Ÿ”– AI Act in a Nutshell โ€“ Part 13: Article 17

๐Ÿ“– https://www.nicfab.eu/en/newsletter-issues/2026-03-24-issue-13/
๐Ÿ“ฉ Subscribe โ†’ https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

#Privacy #GDPR #AIAct #Cybersecurity #EDPB #NicFab #LegalPrompting #Podcast
The European Parliament has published a briefing on the ethical dimensions of AI in classrooms (PE 784.573, March 2026), authored by Prof. Wayne Holmes for the CULT Committee.

The document is strong on the ethical-philosophical plane. But the real challenge lies elsewhere: we don't need more principles โ€” we need operational connections between the principles already formulated, binding rules (GDPR, AI Act) and European competence frameworks (DigComp 3.0, eCF 4.0).

In my latest article, I analyse the briefing from the perspective of a data protection lawyer, focusing on:

โ€” The false dichotomy between ethics and law
โ€” Children as rights-bearing subjects, not objects of optimisation
โ€” The "flipped AI divide" as a matter of substantive equality
โ€” The CEN-CENELEC JTC 21 standard on professional AI ethicists
โ€” The role of DigComp 3.0 and eCF 4.0 in bridging the principles-to-practice gap

Full article: https://www.nicfab.eu/en/posts/ai-ethics-classrooms-ep/

Stay updated on AI, privacy and digital rights โ€” subscribe to the newsletter: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

#AIAct #GDPR #AIethics #Education #DigComp #eCF #EuropeanParliament #DigitalRights #Privacy #ArtificialIntelligence
๐Ÿ“ฌ NicFab Newsletter #27 | 30 June 2026

The Council gives the final green light to the Digital Omnibus on AI (29 June): high-risk deadlines pushed to 2 December 2027 / 2 August 2028 and a new ban on non-consensual sexual deepfakes and AI-generated CSAM from 2 December 2026.

Also in this issue:
- G7 data protection authorities in Paris: minors, age verification, agentic AI
- Commission: AWS & Azure heading for first DMA cloud gatekeeper status
- New Case Law section: eight ECtHR rulings under Art. 8
- AI Act in a Nutshell: Article 31 on notified bodies
- Cybersecurity: Cisco Unified CM, Windchill, Lantronix/UniFi, Signal backup keys

๐Ÿ“– Read: https://www.nicfab.eu/en/newsletter-issues/2026-06-30-issue-27/
โœ‰๏ธ Subscribe: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

#Privacy #GDPR #AIAct #Cybersecurity
๐Ÿ“ฌ NicFab Newsletter #34 | August 18, 2026

Privacy, Data Protection, AI & Cybersecurity โ€” weekly review.

In this issue:

๐Ÿ›๏ธ The European Commission launches D-TECT, the EU industrial forum on drone and counter-drone technology: expressions of interest open, inaugural meeting on 11 November 2026

๐ŸŸข CNIL publishes operational guidance on DPO conflicts of interest: senior management and HR roles incompatible as a rule, and the DPO-CISO combination put under scrutiny

๐Ÿ“Š Australia's under-16 social media ban becomes an exported regulatory model, but eSafety finds most 10-15 year-olds still online due to inadequate age verification

๐Ÿ“ˆ Apple Intelligence registered by China's CAC with an Alibaba-built model, while the DMA standoff in Europe delays Siri AI โ€” same company, two very different strategies

โš ๏ธ Prompt injection hidden in a court filing, Ghostjacking via security logs, and OpenAI's GPT-5.6-Cyber lowering safeguards on exploit development: agentic AI risks are becoming concrete

๐Ÿ”ด Operation Klonen siphons โ‚ฌ30 million from Commerzbank through a supplier, while ShinyHunters expose 1.6 million RingCentral accounts and SafePal data goes up for sale

๐Ÿ” Coordinated attacks on U.S. water utilities with Iranian attribution suspicions, and a Polish combined heat and power plant breached through a private APN

๐Ÿ“– AI Act Explained โ€“ Part 34: Article 38 and the coordination of notified bodies, the sectoral group, and the exchange of knowledge between notifying authorities

๐Ÿ‘‰ Read the full issue: https://www.nicfab.eu/en/newsletter-issues/2026-08-18-issue-34/?utm_campaign=telegram-issue-34

๐Ÿ“ฉ Subscribe to the newsletter: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

#Privacy #GDPR #AIAct #Cybersecurity
๐Ÿ“ฌ NicFab Newsletter #35 | August 25, 2026

Privacy, Data Protection, AI & Cybersecurity โ€” weekly review.

In this issue:

๐Ÿ›๏ธ The European Commission tenders a EUR 400,000 empirical study on how marketplace design shapes user behaviour under DSA Articles 16, 30(7) and 31

๐Ÿ“– EDPS Opinion 17/2026 on the revision of Regulation 2018/1725 sent to Council delegations, ahead of the Working Party meeting on 4 September

๐ŸŸข CNIL publishes a citizens' guide on credit refusals: no "right to credit", but transparency, bias mitigation and explainability duties apply to AI scoring models

๐Ÿ”ด Brussels changes gear on Big Tech: EUR 890 million in DMA fines against Google for self-preferencing and Play Store restrictions, bringing total DMA penalties to EUR 1.6 billion

๐Ÿ“ˆ Apple reshapes App Store terms for EU developers from 1 October 2026: commission down to 26%, Core Technology Fee replaced by a 5% Core Technology Commission

โš ๏ธ Cybersecurity week: GitLab CVE-2026-19478 exploited within hours, unauthenticated RCE in Zimbra already in KEV, and 14 trojanized npm packages delivering RedC2 4.0

๐Ÿ” AI security under pressure: Grok exfiltrating user data via encrypted instructions, Copilot disclosing the secret parameter used to attack it, and OpenAI pausing frontier RL training

๐Ÿ“Š TikTok pays USD 400 million for COPPA violations while the FTC prepares limits on surveillance pricing

๐Ÿ‘‰ Read the full issue: https://www.nicfab.eu/en/newsletter-issues/2026-08-25-issue-35/?utm_source=telegram&utm_medium=organic-social&utm_campaign=issue-35

๐Ÿ“ฉ Subscribe to the newsletter: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

#Privacy #GDPR #AIAct #Cybersecurity
๐Ÿ“ฌ NicFab Newsletter #36 | September 1, 2026

Privacy, Data Protection, AI & Cybersecurity โ€” weekly review.

In this issue:

๐Ÿ”ด Uber fined โ‚ฌ824.99 million by the Dutch DPA, in cooperation with the CNIL, for automated driver account deactivations under Article 22 GDPR

๐Ÿ›๏ธ Council of Europe Framework Convention on AI: the European Parliament's consent published in the Official Journal, paving the way for the Council's conclusion

๐Ÿ“– AI Act Explained โ€“ Part 36: Article 40 on harmonized standards, the presumption of conformity and the Commission's standardization requests

โš–๏ธ ePrivacy derogation and child abuse: March amendments published in the OJ, but the framework in force is now Regulation (EU) 2026/1881, which excludes end-to-end encrypted communications

๐ŸŸข Copyright and generative AI: Parliament calls for transparency on training data, sector-based collective licensing and machine-readable opt-out tools

๐Ÿ” DMA and Apple's new terms: the Commission accepts the changes while Poland asks Brussels to fine Meta โ‚ฌ250 million over scam ads

โš ๏ธ McKesson confirms breach with ShinyHunters claiming 284 million records, while Berlin refuses to pay ransom after the attack on its administrative network

๐Ÿ“Š Union Customs Code: the Council's first-reading position introduces the EU Customs Data Hub and a new European Customs Authority

๐Ÿ‘‰ Read the full issue: https://www.nicfab.eu/en/newsletter-issues/2026-09-01-issue-36/?utm_source=telegram&utm_medium=organic-social&utm_campaign=issue-36

๐Ÿ“ฉ Subscribe to the newsletter: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

#Privacy #GDPR #AIAct #Cybersecurity
๐Ÿ“ฌ NicFab Newsletter #38 | September 15, 2026

Privacy, Data Protection, AI & Cybersecurity โ€” weekly review.

In this issue:

๐Ÿ”ด CNIL fines EXTIA EUR 300,000: over three-quarters of 265 erasure requests received in 2024 went unhandled or mishandled (Articles 12 and 17 GDPR)

๐Ÿ›๏ธ Data Act: the "access by design" obligation under Article 3(1) applies to connected products placed on the market after 12 September 2026

๐Ÿ“– AI Act Explained, Part 38: Article 42 and the presumption of conformity linked to training data, cybersecurity certification and the new ground added by Regulation (EU) 2026/1744

๐ŸŸข Neuro-AI: the European Group on Ethics calls for protection of neurodata and inferences, plus governance of collection and reuse infrastructures

๐Ÿ”ด Garante Privacy fines BBVA Italia EUR 5.5 million for unwanted in-app marketing, and EUR 24,000 the Friuli Centrale health authority over health records

โš ๏ธ Cyber Resilience Act: the 24-hour reporting clock has been running since 11 September, as APT29 and ShinyHunters weaponise AI models for malware and credential theft

๐Ÿ” ICO investigates Police Scotland over its handling of subject access requests

๐Ÿ›๏ธ Council Working Party on Data Protection: 17 September agenda on international data flows and the review of Regulation (EU) 2018/1725

๐Ÿ“Š Research corner: membership inference and privacy auditing, differential privacy in clinical settings, split learning and attacks on LLM agents

๐Ÿ‘‰ Read the full issue: https://www.nicfab.eu/en/newsletter-issues/2026-09-15-issue-38/?utm_source=telegram&utm_medium=organic-social&utm_campaign=issue-38

๐Ÿ“ฉ Subscribe to the newsletter: https://www.nicfab.eu/en/pages/newsletter/#subscribe-now

#Privacy #GDPR #AIAct #Cybersecurity