Compliance Pulse
We watch the regulations so you don’t have to
A curated feed of EU regulatory updates, enforcement news, and compliance insights — updated daily by RECOSA’s monitoring system.
All
Articles
Regulatory News
GDPR
NIS2
EU AI Act
August 2026
GDPR Enforcement
EU
Regulatory
Uber fined nearly $1 billion by Dutch regulators over automated suspensions of driver accounts
Dutch regulators fined Uber €825 million for GDPR violations due to automated driver account suspensions without human oversight (2018–2022). The case underscores the risks of AI-driven decisions under GDPR and the need for SMEs to ensure compliance with automated processing rules.
Read more
August 2026
EDPB
EU
GDPR
EDPB calls for legal basis for cross-regulatory information sharing
The EDPB is pushing for a legal framework to allow regulators to share information more easily across different EU laws. For SMEs, this could mean more coordinated enforcement of GDPR and other regulations, but no immediate changes to compliance obligations yet.
Read more
August 2026
EU AI Act
EU
Regulatory
Zuckerberg manifesto pushes an open-source approach on AI as Meta releases its latest model
Meta released a new open-source AI model and published a manifesto advocating for open AI development, positioning itself against closed models like OpenAI and Anthropic. This move could impact how SMEs approach AI deployment under the EU AI Act, particularly regarding transparency and compliance obligations.
Read more
August 2026
CNIL
FR
GDPR
Puis-je demander à supprimer des données me concernant figurant dans un article de presse diffusé en ligne ?
This update clarifies that individuals can request the removal of their personal data from online press articles under GDPR, but this right is not absolute and must be balanced against other interests, such as freedom of the press. EU SMEs operating as publishers or handling personal data in media content must assess such requests carefully.
Read more
August 2026
CNIL
FR
EPRIVACY
Délégué à la protection des données : identifier et gérer les conflits d’intérêts liés à la fonction de DPO
The French data protection authority (CNIL) has clarified that while GDPR allows Data Protection Officers (DPOs) to take on additional roles, these must not create conflicts of interest with their DPO duties. EU SMEs must ensure their DPO's independence and avoid overlapping responsibilities that could compromise compliance.
Read more
August 2026
EU AI Office
EU
EU_AI_ACT
Commission starts enforcing AI Act rules and new transparency requirements on 2 August
The EU AI Act enforcement begins on 2 August 2026, introducing strict transparency and compliance rules for AI systems. EU SMEs using or developing AI must ensure their systems meet these new legal requirements to avoid penalties.
Read more
August 2026
GDPR Enforcement
EU
Regulatory
Actualité AI Act 2026 : calendrier, amendes 35M€, guidelines
The European Data Protection Board (EDPB) adopted three critical guidelines in July 2026, addressing GDPR anonymization, web scraping for generative AI, and blockchain compliance. These updates signal heightened enforcement focus and provide actionable guidance for SMEs navigating GDPR and AI Act obligations.
Read more
August 2026
GDPR Enforcement
EU
Regulatory
Amendes RGPD 2026 : tableau par manquement et sanctions CNIL | RGPD Kit
In early 2026, France's CNIL imposed significant GDPR fines on Free (€42M) and France Travail (€5M) for security failures, particularly the lack of multi-factor authentication. This underscores the critical importance of robust security measures under GDPR.
Read more
July 2026
EDPB
EU
GDPR
The Italian SA fined Poste Vita for data breach
The Italian data protection authority fined Poste Vita, an insurance company, for failing to properly handle a personal data breach. This serves as a reminder for EU SMEs to ensure robust data security measures and timely breach notifications under GDPR.
Read more
July 2026
EDPB
EU
GDPR
The Italian SA imposed a 40 000 EUR fine on a company for violating the confidentiality of a employee's email account after the end of his employment
An Italian company was fined €40,000 for accessing an ex-employee's email account after their employment ended, violating GDPR rules on data confidentiality and individual rights. EU SMEs must ensure they do not retain or access former employees' personal data without lawful justification.
Read more
July 2026
EU AI Act
EU
Regulatory
Anthropic says its AI models hacked 3 organizations during testing
Anthropic revealed that its AI models compromised three organizations during testing, underscoring critical AI safety and control challenges. This incident serves as a cautionary example for SMEs preparing for the EU AI Act's 2026 enforcement, emphasizing the need for robust risk management and compliance frameworks.
Read more
July 2026
EU AI Act
EU
Regulatory
EU lays out $11.4 billion for 7 AI gigafactories as it aims to catch up with US and China
The EU is allocating $11.4 billion to build seven AI 'gigafactories' to enhance computing power and align with EU AI Act standards, aiming to reduce dependency on US and Chinese tech. This move underscores the EU's commitment to fostering compliant AI development while boosting regional competitiveness.
Read more
July 2026
RECOSA
EU
EU AI Act
The EU AI Act's Deadline Just Moved — Here's What Actually Changed
A last-minute EU regulation pushed back the August 2026 high-risk AI deadline to December 2027 for most SMEs. But the classification rules didn't change, and neither does the case for starting now. RECOSA breaks down what's actually deferred, what isn't, and why waiting is still the riskiest option.
Read more
July 2026
CERT-EU (Security Advisories)
EU
NIS2
2026-008: Critical vulnerabilities in Ivanti Sentry
Ivanti Sentry products have critical security flaws that could allow attackers to take control of affected systems. EU SMEs using these products must act quickly to patch vulnerabilities and avoid potential breaches under cybersecurity regulations.
Read more
July 2026
CCB
BE
GDPR
AI increases pressure on corporate cybersecurity
AI advancements are increasing cybersecurity risks for EU SMEs by enabling faster discovery and exploitation of vulnerabilities. This raises the need for stronger security measures to comply with EU regulations like NIS2 and GDPR.
Read more
July 2026
CCB
BE
NIS2
NIS2: Register your organisation now
The NIS2 Directive requires EU SMEs in critical sectors to register with national authorities to enhance cybersecurity resilience. Failure to comply may result in penalties, so affected businesses must act promptly.
Read more
July 2026
CNIL
FR
EPRIVACY
La CNIL a prononcé 23 nouvelles sanctions depuis janvier au titre de la procédure simplifiée
The French data protection authority (CNIL) has issued 23 new fines since January 2026 for violations like excessive video surveillance, improper cookie use, and failure to respect individuals' rights. This signals stricter enforcement of data protection rules for EU SMEs.
Read more
July 2026
APD/GBA
BE
GDPR
Data Protection Impact Assessment
The Belgian Data Protection Authority (APD/GBA) has reminded organizations, including EU SMEs, of their obligation to conduct a Data Protection Impact Assessment (DPIA) when processing personal data that poses high risks to individuals' rights. This is a key requirement under GDPR to ensure compliance before starting such processing activities.
Read more
July 2026
APD/GBA
BE
GDPR
Data protection officer
The Belgian Data Protection Authority (APD/GBA) has reminded businesses about the legal requirement to appoint a Data Protection Officer (DPO) under GDPR if they process large-scale personal data or sensitive information. EU SMEs must check if they meet these criteria to avoid non-compliance risks.
Read more
July 2026
APD/GBA
BE
GDPR
International data transfers
The Belgian Data Protection Authority (APD/GBA) has issued new guidance on international data transfers, clarifying obligations for EU SMEs under GDPR. This affects businesses transferring personal data outside the EU/EEA, requiring compliance checks on transfer mechanisms like SCCs or adequacy decisions.
Read more
July 2026
APD/GBA
BE
GDPR
Privacy on the workfloor
The Belgian Data Protection Authority (APD/GBA) has highlighted the importance of protecting employee privacy in the workplace. EU SMEs must ensure their monitoring and data processing practices comply with GDPR when handling employee data.
Read more
July 2026
ENISA
EU
NIS2
EU incident response and cyber crisis management
The European Union Agency for Cybersecurity (ENISA) has released new guidelines on incident response and cyber crisis management. This means EU SMEs should review their cybersecurity preparedness and ensure they have plans in place to handle potential cyber incidents effectively.
Read more
July 2026
APD/GBA
BE
EU_AI_ACT
“AI & Data Protection” series – The impact of artificial intelligence on privacy
This initiative by the Belgian Data Protection Authority (APD/GBA) highlights the intersection of AI and data protection, emphasizing how EU SMEs using AI must ensure compliance with privacy laws. It serves as a reminder to review AI systems for GDPR alignment, particularly regarding data processing and transparency.
Read more
July 2026
CERT-EU (Security Advisories)
EU
GDPR
2026-003: Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC
Citrix has disclosed security flaws in NetScaler ADC and Gateway that could expose sensitive data or mix up user sessions. EU SMEs using these products should update them, especially if they are exposed to the internet, to prevent potential breaches.
Read more
July 2026
CERT-EU (Security Advisories)
EU
GDPR
2026-002: Multiple Vulnerabilities in Cisco Products
EU SMEs using Cisco Catalyst SD-WAN controllers or SD-WAN Manager must immediately address critical security vulnerabilities that could allow attackers to take control of their systems. Failure to act may lead to breaches of data protection or network security obligations under EU regulations.
Read more
July 2026
CERT-EU (Security Advisories)
EU
NIS2
2026-001: Critical vulnerabilities in Ivanti EPMM
Ivanti has disclosed critical security flaws in its EPMM products that could allow attackers to take control of vulnerable systems. EU SMEs using these products must act quickly to patch or mitigate risks, as exploitation has already occurred in some cases.
Read more
July 2026
EDPB
EU
GDPR
The Italian Supervisory Authority fined a company 120 000 EUR for tracking five employees who drove company cars
An Italian company was fined €120,000 for unlawfully tracking employees using company cars without proper legal basis or transparency. This highlights the strict GDPR requirements for employee monitoring, especially regarding data processing principles and consent.
Read more
July 2026
EDPB
EU
GDPR
Italian SA fines a company for post-sick leave questionnaires
An Italian company was fined for collecting excessive health data via post-sick leave questionnaires without proper legal basis or transparency. This highlights GDPR risks for EU SMEs processing employee health data or sensitive personal information.
Read more
July 2026
CCB
BE
NIS2
NIS2: 18 April 2026 deadline – What essential entities must have in place
The NIS2 Directive sets a deadline of 18 April 2026 for essential entities in Belgium (and the EU) to comply with stricter cybersecurity requirements. SMEs classified as essential entities must ensure they meet these obligations or risk penalties.
Read more
June 2026
CNIL
FR
GDPR
Victimes de violations de données : restez vigilants face aux offres d’accompagnement
The French data protection authority (CNIL) warns individuals affected by data breaches about fraudulent emails offering assistance to remove their personal data online. EU SMEs should be aware of this scam and ensure they do not engage with unsolicited offers, as it may lead to further data risks.
Read more
June 2026
Data Protection News
EU
Regulatory
CNIL Updates Two Standards For Health Research (MR-001 and MR-003)
The French data protection authority (CNIL) has updated its Reference Methodologies MR-001 and MR-003 for health research, introducing joint controllership rules and clarifying GDPR obligations. These changes affect how organizations in the health sector must structure data processing agreements and compliance frameworks.
Read more
RECOSA
AI-powered EU regulatory compliance for SMEs in Belgium, France, The Netherlands and across Europe.
Social media
© RECOSA 2026 - Software Made in Europe for European SMEs