Issue #13 | October 2026, Week 2
October 6, 2026Five enforcement actions this week: IQVIA, TIP TOP FOOD INDUSTRY, Zuid-Kempen school group, gambling operator and first fine under NIS2 notification rules.
Views: Read Time: 6 min.
Italian data protection authority fines IQVIA €7 million
- Jurisdiction
- Italy
- Case type
- Data protection enforcement; unlawful processing of health data, insufficient anonymization, transparency, retention and security failures
- Applicable Law
- EU General Data Protection Regulation (GDPR)
- Decision by
- Italian Data Protection Authority (Garante)
- Penalty
- €7 million
- Date
- 23 September 2026
Italy’s data protection authority Garante has fined IQVIA Solutions Italy Srl, a company that provides health care information, analytics, and consulting services, €7 million over the processing of health data belonging to around one million patients.
The company, which works with healthcare data and clinical research, created a database using information from 800 general practitioners for studies paid for by pharmaceutical companies. According to the watchdog, the information was not anonymous. Patient codes made it possible to track people over time and details like age, sex, diagnoses, medicines, tests, vaccinations, and location could also be used to identify patients.
The regulator also found that IQVIA processed health data without a proper legal basis and did not clearly explain how the data was used. The company had also failed to set clear retention periods, with some data dating back to 2001.
Other problems included the lack of a required impact assessment and insufficient security measures. The database also contained names, tax codes, addresses and contact details for more than 3,300 patients, with over 3,000 of them linked to health information.
The company was given 120 days to bring its data processing practices into compliance if it wants to continue operating. Otherwise, the data must be anonymized independently by doctors under the safeguards set by the regulator.
In a separate decision, the Garante has fined Bologna-based security company La Patria €39,000 for GDPR violations involving employee data. The case followed a former employee’s complaint after the company refused to provide GPS data from his company car, which he wanted to use in a disciplinary dispute. The authority found that the company had failed to properly respond to his access request and had not adequately informed employees about the GPS data processing. It also found inaccuracies in the company’s privacy notices.
Also, the National Institute of Metrological Research (NRIM) in Turin was fined €10,000 for illegally using its video surveillance system. The Institute had agreed with trade unions on where the cameras could be installed but later added eight cameras and changed their positions without informing employees. The cameras were activated during working hours, resulting in the unlawful collection of employees’ and visitors’ personal data.
Romania fines a food company over biometric data
- Jurisdiction
- Romania
- Case type
- Data protection enforcement; unlawful processing of employee biometric data
- Applicable Law
- GDPR, Article 9 and Article 5(1)(c)
- Decision by
- National Supervisory Authority for Personal Data Processing (ANSPDCP)
- Penalty
- RON 26,236 (approximately €5,000)
- Date
- 25 September 2026
Romania’s National Supervisory Authority for Personal Data Processing (ANSPDCP) has fined TIP TOP FOOD INDUSTRY RON 26,236 (approximately €5,000) for unlawfully processing employees’ biometric data. The penalty comes after an individual complained about how the company uses employees’ fingerprints for access control and working-time recording.
According to ANSPDCP, the company processed employees’ biometric data without a valid legal basis, breaching Article 9 of the EU General Data Protection Regulation (GDPR). The authority also found a violation of Article 5(1)(c), which establishes the principle of data minimization.
In addition to the fine, ANSPDCP ordered TIP TOP FOOD INDUSTRY to replace its fingerprint-based access control and timekeeping system with an alternative solution that can be used for the same purposes without processing biometric data.
Separately, the authority has fined call center operator GLOBAL CUSTOMER CARE SERVICES S.R.L. RON 26,294 (€5,000) following a cyber-attack that resulted in unauthorized access to the personal data, including the information belonging to employees and former employees. The company was found lacking adequate security measures required under the GDPR and was ordered to improve its IT security by implementing access monitoring and logging systems and retaining activity logs for at least 30 days.
Zuid-Kempen school group faces a €1,000 GDPR fine
- Jurisdiction
- Belgium / European Union
- Case type
- Data protection litigation; applicability of GDPR administrative fines to a privately operated, publicly funded organization
- Applicable Law
- GDPR, Article 83(7), and relevant Belgian data protection legislation
- Decision by
- Advocate General Manuel Campos Sánchez-Bordona, Court of Justice of the European Union; original fine imposed by the Belgian Data Protection Authority
- Penalty
- €1,000, reduced from €2,000
- Date
- 10 September 2026
A Belgian school group could face a €1,000 GDPR fine after an adviser to the Court of Justice of the European Union said privately run, government-funded schools are not protected from such penalties.
The case began in 2019, when a father complained after his child’s school sent pupils an online survey about their well-being without informing parents beforehand. He said the school had not obtained consent, had collected more data than necessary and had not properly explained how the data would be used.
Belgium’s Data Protection Authority later found four GDPR violations and initially imposed a €2,000 fine on Onderwijsgroep Zusters der Christelijke Scholen Zuid-Kempen VZW, known as OZCS. The fine was later reduced to €1,000.
OZCS argued that Belgian law protects public authorities from data protection fines. It said that, because its schools receive public funding and provide a public service, it should receive the same protection. But Advocate General Manuel Campos Sánchez-Bordona disagreed in an opinion issued on 10 September 2026. He said the Belgian rule cannot prevent a fine against a privately run organization simply because it provides publicly subsidized education.
The dispute has moved through Belgian courts several times. Belgium’s Court of Cassation eventually asked the EU court in Luxembourg to clarify the law. The case C-458/25 concerns whether privately operated organizations carrying out public-interest work can be fined under the GDPR. The Advocate General’s opinion is not a final ruling. The Court of Justice will make the final decision.
Croatia fines gambling operator €2.59M for GDPR violations
- Jurisdiction
- Croatia
- Case type
- Data protection enforcement; unlawful biometric processing, invalid consent, excessive data collection and transparency failures
- Applicable Law
- EU General Data Protection Regulation (GDPR)
- Decision by
- Croatian Personal Data Protection Agency (AZOP)
- Penalty
- €2.59 million
- Date
- 2 October 2026
Croatia’s data protection authority has fined an unnamed gambling operator €2.59 million for multiple violations of the General Data Protection Regulation (GDPR), including the unlawful processing of biometric data and failures to obtain valid consent.
The investigation found that the operator offered players the option of identifying themselves through an RFID chip or fingerprints, in addition to identification by ID card. Although the operator said it collected two fingerprints, authorities found that four fingerprints were collected and used for biometric identification.
The authority ruled that collecting four fingerprints was excessive for the purpose of identifying players. The operator argued that additional fingerprints were needed as a backup if a player’s skin was damaged, but the authority found that it had not proved why such a volume of biometric data was necessary.
The authority also found that consent for biometric processing was not valid. Consent statements combined different processing purposes, meaning players could not make separate choices about optional biometric processing.
In addition, registration documents provided incomplete and inconsistent information about the purposes and legal bases for processing personal data. The authority said players were not given sufficiently clear information about how their data, including fingerprints, were being used.
Romanian DNSC issues first fine under NIS2 notification rules
- Jurisdiction
- Romania
- Case type
- Cybersecurity / NIS2 regulatory enforcement; failure to comply with mandatory entity-registration notification
- Applicable Law
- Emergency Government Ordinance No. 155/2024, Article 18(2) and Article 60(1)(o)
- Decision by
- National Directorate for Cyber Security (DNSC)
- Penalty
- RON 50,000 (approximately €9,350)
- Date
- 29 September 2026
Romania’s National Directorate for Cyber Security (DNSC) has fined an institution within the central public administration 50,000 lei (about €9,350) for failing to comply with a notification deadline under the country’s NIS2 cybersecurity framework.
The sanction was issued on September 29, 2026. DNSC did not disclose the name of the institution.
According to DNSC, the institution failed to meet the notification requirement set out in Article 18(2) of Emergency Government Ordinance No. 155/2024. The provision requires entities falling within the scope of the legislation to notify DNSC for registration as essential or important entities.
The failure constitutes a contravention under Article 60(1)(o) of the same ordinance. DNSC said this was the first sanction it had imposed for failure to comply with this notification obligation.
Disclaimer: The information in this blog is provided from open and governmental sources. We respectfully remind our readers about the presumption of innocence. The information herein is provided for educational purposes only and does not constitute legal opinion or advice.