In the field of personal data protection, major problems often enter through a door left slightly ajar: an account that remains active after an employee leaves, a file kept out of habit or convenience, or an email opened in haste without using analytical filters before opening it.
Thank you for reading this post, don't forget to subscribe!At first glance, some may consider these to be ordinary situations, the kind that occur in almost every company. This is precisely where the most important message of the sanctions published by ANSPDCP in August 2026 lies.
Personal data protection is rarely compromised in a single moment. In essence, vulnerability is most often built gradually, through postponed checks, access rights that have not been properly reviewed, and rules that employees have not genuinely understood.
Real personal data protection within a company begins, among other things, when someone asks whether they genuinely need all the personal data contained in a spreadsheet, when a manager gives timely notice of an employee’s departure, and when the IT department limits access to what is necessary for each role.
Sometimes, it begins with an even simpler action: a colleague notices something unusual in an email and, before clicking, uses analytical filters or asks for a second opinion.
Compliance cannot be achieved solely through policies and procedures stored in a folder. It is reflected in accounts being closed on time, access rights being reviewed, data backups being maintained, and training sessions through which people genuinely understand what they should and should not do.
In this respect, the sanctions issued in August serve as a mirror, and every company can look into it before the Authority does.
Sources: ANSPDCP communications published in August 2026 (selected)
