Publications

Garrigues

ELIGE TU PAÍS / ESCOLHA O SEU PAÍS / CHOOSE YOUR COUNTRY / WYBIERZ SWÓJ KRAJ / 选择您的国家

Data Economy, Privacy and Cybersecurity Newsletter - July 2026

In this newsletter, we offer the latest updates on everything related to the data economy (technology law, technological innovations, artificial intelligence, digital law, e-Commerce), privacy (data protection and related fundamental rights), and cybersecurity (information security and the protection of the networks and systems that process it). We cover the most recent rulings from relevant authorities and agencies, key court decisions, and the most important news in this field.

Quantum computing: a new horizon for the data economy, privacy and cybersecurity

Ignacio Suárez

The advent of the quantum computing era is set to revolutionize the data economy, privacy and cybersecurity. As with all revolutions, it will bring both significant opportunities and also challenges. Although in view of its technical complexity the subject may seem remote, advances in quantum computing concern society as a whole, and professionals in particular, across all areas of the technology industry, including, of course, the legal profession.

KEEP READING >

Personal data regulation in Colombia: strengthening the enforcement regime and regulatory outlook

Adolfo Gómez y David Toro

Colombia strengthens its data protection framework: tougher penalties, new requirements for AI, fintech and cybersecurity, measures to combat identity theft, and a more proactive authority. Businesses face greater data transparency, oversight and governance obligations in 2026.

KEEP READING >

News update

  • European Data Protection Board publishes its 2025 Annual Report with a record number of total fines amounting to €1,145 million and recognizes cybersecurity as a core supervisory activity
  • AEPD records highest number of complaints in its history in the 2025 activity report
  • AEPD launches scientific journal to encourage debate on privacy, innovation and technology
  • Preliminary decision by the Commission: Meta could be breaching the DSA due to minors’ access to the platform
  • Publication of the draft law on the responsible use and governance of AI
  • AEPD issues observations on the preliminary draft AI Governance Bill to strengthen the Spanish supervisory framework
  • AEPD publishes guidelines on the use of video cameras in the homes of elderly persons to reconcile care needs and privacy
  • Report by the ECB on the proposal for a Digital Omnibus Regulation to simplify the digital legislative framework
  • AEPD publishes over 1,500 legal reports to facilitate their reuse and strengthen legal certainty
  • AEPD calls on data protection authorities to assess whether some AI systems enable third parties to access conversations
  • United States promotes federal AI framework focused on large frontier model developers
  • AEPD launches a new interactive tool for the dynamic analysis of personal data breaches
  • EDPB adopts a common data breach notification template and submits it to public consultation
  • European Commission imposes interim measures on Meta to ensure free access to WhatsApp for competing AI assistants
  • EDPB letter to the European Commission on registration requirements for international NGOs providing assistance in the Palestinian Territories
  • European Parliament and Council approve simplification measures for the AI Act and introduce a ban on AI applications that generate fake nudity
  • Joint institutional statement by the AEPD, the regional data protection authorities and the CGPJ’s Directorate for Data Protection Supervision and Oversight on strengthening the culture of privacy
  • NIS2 Cooperation Group adopts common templates for incident reporting
  • European Data Protection Board publishes its annual report on the use of external experts in the SPE program during 2025

KEEP READING >

Decisions 

  • €18 million fine imposed on an airline booking company due to misuse of traveler data for profiling and product development
  • Telecommunications operator fined more than €1 million for failing to prevent customer identity theft
  • Airline fined €650,000 for failing to ensure the confidentiality of the personal data managed by its processor following a cyberattack
  • Financial institution fined €500,000 for breaching the principles of data protection by design and by default in the operation of its customer service function
  • Fine of €250,000 resulting from a ransomware attack
  • Sports retail chain fined €120,000 for a data breach
  • AEPD confirms on reconsideration: if the processor fails to comply with the controller’s instructions, it becomes the controller
  • Penalty imposed by Italy’s national data protection authority on two entities in the postal and payment services sectors for the unlawful processing of personal data
  • Logistics company fined €16,000 for implementing a fingerprint time-clock system without a data protection impact assessment
  • Sending recordings of online meetings to third parties who did not attend must be supported by a valid legal basis
  • AEPD issues warning to a photography studio for failing to implement appropriate security measures following the theft of devices containing personal data
  • AEPD confirms that Law 25/2007 does not limit the line owner’s right of access to the call log
  • Company fined for failing to conduct an impact assessment before implementing a facial recognition-based identity verification system
  • Website advertising prostitution is fined €20,000 for lacking an effective age verification system
  • Online newspaper fined €30,000 for posting a video featuring a minor who was an assailant and a victim in a vulnerable situation
  • Courier and parcel delivery company and smart mailbox company fined for disclosing personal data without a data processing agreement
  • AEPD fines university €20,000 for requiring a copy of a national ID card to issue official degrees
  • Company fined for installing a video surveillance system with audio recording without informing employees
  • Medical center fined for improperly charging a patient for access to her medical records
  • Penalty imposed on a municipal council for publishing identifying information about an individual in an official statement
  • Penalty imposed on an autonomous community government for infringing the GDPR in the use of public employees’ electronic signatures

KEEP READING >

Judgments

  • The Supreme Court rules that the personal nature of data depends on the context and the recipient's actual ability to re-identify the individual, not on the data's intrinsic nature
  • Court sets aside penalty imposed on sports event recording company for the recording and restricted dissemination of a minor’s image
  • The National Appellate Court confirms that a data breach involving health information must be reported to the individuals affected where it poses a high risk, including in cases of joint controllership
  • Penalty confirmed against a professional association for a conflict of interest involving the data protection officer and deficiencies in disclosure
  • The National Appellate Court refuses to admit an appeal filed by a worker who sought to hold a mutual insurance company liable for denying him access to his medical records
  • The National Appellate Court confirms that the public interest does not justify the indiscriminate disclosure of personal data by a public authority
  • The National Appellate Court halves the penalty imposed on a telemarketing company for making a sales call to a number registered on the Robinson List
  • The General Court of the EU upholds the designation of Messenger (Meta) as a “gatekeeper” and sets aside that of its “marketplace” due to lack of reasoning
  • Fines are reduced for a courier company for allowing a neighbor to access personal data contained on the label of a package not delivered to the recipient
  • The GDPR applies to the storage of data regarding a police officer’s status as a suspect in his or her file, even if such data was obtained by another directorate of the same public authority during a criminal investigation
  • The National Appellate Court reduces the penalty imposed on a telecommunications operator for requiring a photograph of the recipient’s national ID card upon delivery of cell phones
  • The National Appellate Court overturns the penalty imposed on a sports federation for requiring a COVID vaccination certificate to take an exam
  • The Supreme Court dismisses an appeal by a citizen seeking compensation for a breach of confidentiality in the notification of a judgment
  • The Court of Justice of the EU clarifies when a digital service provider exercises active control over content
  • The CJEU allows courts to use personal data obtained unlawfully by a company as evidence, provided that the GDPR and the right to a fair trial are respected 

KEEP READING >