GDPR enforcement continues to demonstrate that privacy compliance is not simply about having the right policies on paper. Regulators increasingly expect organisations to show that controls work in practice and to produce evidence when challenged.
Recent significant GDPR fines highlight this clearly. The cases relate to cyber security, biometric data, DPIAs (data protection impact assessments), artificial intelligence and consent management. Together, they offer several practical lessons.
Wind Tre S.p.A – fine issued by the Italian Garante
In July, Italy’s data protection authority fined the telecoms operator Wind Tre €1.715 million following security deficiencies associated with attacks in which individuals posing as support personnel obtained access to company systems.
Personal data relating to more than 365,000 customers was reportedly exfiltrated.
The case is an important reminder that GDPR security obligations extend beyond firewalls and technical configurations. Identity verification, privileged access, employee awareness, third-party access and social-engineering resilience all form part of an effective control environment.
Main takeaway: Security controls should be tested against realistic attack scenarios, with clear ownership and evidence that controls are operating effectively.
Yoti Ltd – fine issued by the AEPD
In March, Spain’s data protection authority fined the UK-based digital identity company Yoti Ltd €950,000 over its processing of biometric data, citing issues including the legal basis for processing, consent and data retention.
Biometric technologies can provide convenience and stronger identity assurance, but they also introduce significant privacy risk. Because biometric information can fall within GDPR’s special-category data regime, organisations need to establish the legal basis and safeguards before deployment and not after a regulator starts asking questions.
Main takeaway: Organisations using biometric technologies should maintain a clear inventory of biometric processing, documented legal-basis assessments, retention rules and appropriate privacy controls.
FC Barcelona and BBVA – fine issued by the AEPD
In March, FC Barcelona was fined €500,000 in connection with biometric data collected during a digital census process without carrying out the required DPIA.
DPIAs can sometimes become a procedural checkbox within privacy programmes. Enforcement action demonstrates why that approach is risky.
A good DPIA creates a documented connection between a proposed activity, its privacy risks and the controls selected to mitigate those risks.
Main takeaway: Build DPIA triggers into project, procurement and technology-governance workflows so that high-risk processing cannot move into production without the appropriate assessment.
Character Technologies, Inc./Character.AI – fine issued by the Italian Garante
Another notable case involved Character Technologies, the company behind Character.AI, which received a €158,000 Italian fine in July covering a range of GDPR requirements, including transparency, accountability, EU representative, data protection by design, DPIAs and safeguards relating to minors.
For organisations adopting AI, this illustrates an increasingly important point: AI governance cannot operate separately from privacy governance.
An AI application may simultaneously create issues around personal-data processing, transparency, vulnerable users, security, vendor risk and impact assessments.
Main takeaway: Integrate AI systems into existing GRC processes rather than creating an isolated AI compliance programme. AI inventories should connect to privacy assessments, risk registers, third-party controls and evidence repositories.
Conclusions and recommendations
The above-mentioned cases involve very different organisations and technologies, but a common theme emerges.
Regulators are looking beyond policies and asking operational questions:
- Was access appropriately controlled?
- Was there a lawful basis for processing?
- Was high-risk processing assessed before deployment?
- Were privacy safeguards designed into the technology?
- Can the organisation produce reliable evidence of consent, approval and control execution?
- Was an EU representative duly appointed?
The objective should no longer be simply to demonstrate that a policy or control exists. Organisations need an auditable chain connecting regulatory obligations, risks, controls, owners, assessments, evidence, remediation. As regulatory environments become more complex, particularly around AI, biometrics and cybersecurity, maintaining that traceability will become increasingly important.
The main message from recent GDPR enforcement is that compliance must be operational, measurable and provable.
Centralising obligations, controls, assessments and evidence within a structured data privacy compliance programme can help organisations identify gaps earlier, demonstrate accountability and respond more effectively when regulators, auditors or customers ask the inevitable question “Can you prove it?”
It is never too late to conduct a gap analysis to identify strengths and weaknesses on your compliance so that you can remediate timely identified non-conformities.