Compliance Pulse

We watch the regulations so you don’t have to

A curated feed of EU regulatory updates, enforcement news, and compliance insights — updated daily by RECOSA’s monitoring system.

All

Articles

Regulatory News

GDPR

NIS2

EU AI Act

July 2026

EDPB

EU

GDPR

The Italian Supervisory Authority fined a company 120 000 EUR for tracking five employees who drove company cars

An Italian company was fined €120,000 for unlawfully tracking employees using company cars without proper legal basis or transparency. This highlights the strict GDPR requirements for employee monitoring, especially regarding data processing principles and consent.

Read more

July 2026

EDPB

EU

GDPR

Italian SA fines a company for post-sick leave questionnaires

An Italian company was fined for collecting excessive health data via post-sick leave questionnaires without proper legal basis or transparency. This highlights GDPR risks for EU SMEs processing employee health data or sensitive personal information.

Read more

July 2026

CCB

BE

NIS2

NIS2: 18 April 2026 deadline – What essential entities must have in place

The NIS2 Directive sets a deadline of 18 April 2026 for essential entities in Belgium (and the EU) to comply with stricter cybersecurity requirements. SMEs classified as essential entities must ensure they meet these obligations or risk penalties.

Read more

June 2026

CNIL

FR

GDPR

Victimes de violations de données : restez vigilants face aux offres d’accompagnement

The French data protection authority (CNIL) warns individuals affected by data breaches about fraudulent emails offering assistance to remove their personal data online. EU SMEs should be aware of this scam and ensure they do not engage with unsolicited offers, as it may lead to further data risks.

Read more

June 2026

Data Protection News

EU

Regulatory

CNIL Updates Two Standards For Health Research (MR-001 and MR-003)

The French data protection authority (CNIL) has updated its Reference Methodologies MR-001 and MR-003 for health research, introducing joint controllership rules and clarifying GDPR obligations. These changes affect how organizations in the health sector must structure data processing agreements and compliance frameworks.

Read more

July 2026

CERT-EU (Security Advisories)

EU

NIS2

2026-008: Critical vulnerabilities in Ivanti Sentry

Ivanti Sentry products have critical security flaws that could allow attackers to take control of affected systems. EU SMEs using these products must act quickly to patch vulnerabilities and avoid potential breaches under cybersecurity regulations.

Read more

July 2026

CCB

BE

GDPR

AI increases pressure on corporate cybersecurity

AI advancements are increasing cybersecurity risks for EU SMEs by enabling faster discovery and exploitation of vulnerabilities. This raises the need for stronger security measures to comply with EU regulations like NIS2 and GDPR.

Read more

July 2026

CCB

BE

NIS2

NIS2: Register your organisation now

The NIS2 Directive requires EU SMEs in critical sectors to register with national authorities to enhance cybersecurity resilience. Failure to comply may result in penalties, so affected businesses must act promptly.

Read more

July 2026

CNIL

FR

EPRIVACY

La CNIL a prononcé 23 nouvelles sanctions depuis janvier au titre de la procédure simplifiée

The French data protection authority (CNIL) has issued 23 new fines since January 2026 for violations like excessive video surveillance, improper cookie use, and failure to respect individuals' rights. This signals stricter enforcement of data protection rules for EU SMEs.

Read more

July 2026

APD/GBA

BE

GDPR

Data Protection Impact Assessment

The Belgian Data Protection Authority (APD/GBA) has reminded organizations, including EU SMEs, of their obligation to conduct a Data Protection Impact Assessment (DPIA) when processing personal data that poses high risks to individuals' rights. This is a key requirement under GDPR to ensure compliance before starting such processing activities.

Read more

July 2026

APD/GBA

BE

GDPR

Data protection officer

The Belgian Data Protection Authority (APD/GBA) has reminded businesses about the legal requirement to appoint a Data Protection Officer (DPO) under GDPR if they process large-scale personal data or sensitive information. EU SMEs must check if they meet these criteria to avoid non-compliance risks.

Read more

July 2026

APD/GBA

BE

GDPR

International data transfers

The Belgian Data Protection Authority (APD/GBA) has issued new guidance on international data transfers, clarifying obligations for EU SMEs under GDPR. This affects businesses transferring personal data outside the EU/EEA, requiring compliance checks on transfer mechanisms like SCCs or adequacy decisions.

Read more

July 2026

APD/GBA

BE

GDPR

Privacy on the workfloor

The Belgian Data Protection Authority (APD/GBA) has highlighted the importance of protecting employee privacy in the workplace. EU SMEs must ensure their monitoring and data processing practices comply with GDPR when handling employee data.

Read more

July 2026

ENISA

EU

NIS2

EU incident response and cyber crisis management

The European Union Agency for Cybersecurity (ENISA) has released new guidelines on incident response and cyber crisis management. This means EU SMEs should review their cybersecurity preparedness and ensure they have plans in place to handle potential cyber incidents effectively.

Read more

July 2026

RECOSA

EU

EU AI Act

The EU AI Act's Deadline Just Moved — Here's What Actually Changed

A last-minute EU regulation pushed back the August 2026 high-risk AI deadline to December 2027 for most SMEs. But the classification rules didn't change, and neither does the case for starting now. RECOSA breaks down what's actually deferred, what isn't, and why waiting is still the riskiest option.

Read more

July 2026

APD/GBA

BE

EU_AI_ACT

“AI & Data Protection” series – The impact of artificial intelligence on privacy

This initiative by the Belgian Data Protection Authority (APD/GBA) highlights the intersection of AI and data protection, emphasizing how EU SMEs using AI must ensure compliance with privacy laws. It serves as a reminder to review AI systems for GDPR alignment, particularly regarding data processing and transparency.

Read more

July 2026

CERT-EU (Security Advisories)

EU

GDPR

2026-003: Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC

Citrix has disclosed security flaws in NetScaler ADC and Gateway that could expose sensitive data or mix up user sessions. EU SMEs using these products should update them, especially if they are exposed to the internet, to prevent potential breaches.

Read more

July 2026

CERT-EU (Security Advisories)

EU

GDPR

2026-002: Multiple Vulnerabilities in Cisco Products

EU SMEs using Cisco Catalyst SD-WAN controllers or SD-WAN Manager must immediately address critical security vulnerabilities that could allow attackers to take control of their systems. Failure to act may lead to breaches of data protection or network security obligations under EU regulations.

Read more

July 2026

CERT-EU (Security Advisories)

EU

NIS2

2026-001: Critical vulnerabilities in Ivanti EPMM

Ivanti has disclosed critical security flaws in its EPMM products that could allow attackers to take control of vulnerable systems. EU SMEs using these products must act quickly to patch or mitigate risks, as exploitation has already occurred in some cases.

Read more

RECOSA

AI-powered EU regulatory compliance for SMEs in Belgium, France, The Netherlands and across Europe.

Social media

LinkedIn

© RECOSA 2026 - Software Made in Europe for European SMEs