<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>klarproof — EU compliance research</title><description>Fact-based research on EU regulation: AI Act, GDPR, MiCA, DORA. Regulator profiles, fine registries, news. Sources cited.</description><link>https://klarproof.com/</link><language>en-us</language><item><title>Who is Tietosuojavaltuutettu: Finland&apos;s Data Protection Ombudsman</title><link>https://klarproof.com/regulators/finland/tietosuoja/</link><guid isPermaLink="true">https://klarproof.com/regulators/finland/tietosuoja/</guid><description>Tietosuojavaltuutetun toimisto is Finland&apos;s GDPR supervisory authority — one of the oldest in Europe (1987). What it does, how the collegial Sanctions Board works, why its head also chairs the EU&apos;s data-protection board (EDPB), and the €2.4M Posti fine that the Helsinki Administrative Court later annulled.</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>regulator</category><category>gdpr</category><category>tietosuoja</category><category>gdpr</category><category>finland</category><category>privacy</category></item><item><title>Who is the CNIL: France&apos;s data protection authority, created decades before the GDPR</title><link>https://klarproof.com/regulators/france/cnil/</link><guid isPermaLink="true">https://klarproof.com/regulators/france/cnil/</guid><description>The CNIL is France&apos;s GDPR supervisory authority — born from the 1974 SAFARI scandal and created by the 1978 Loi Informatique et Libertés, decades before the GDPR. This guide covers what it does, its 18-member college and sanctions chamber, the landmark fines from Google&apos;s first €50M to a record €325M, who runs it, and its 2024 figures — every fact sourced.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>regulator</category><category>gdpr</category><category>cnil</category><category>gdpr</category><category>france</category><category>regulator</category><category>data-protection</category></item><item><title>Who is the UODO: Poland&apos;s data regulator and one of the EU&apos;s busiest enforcers</title><link>https://klarproof.com/regulators/poland/uodo/</link><guid isPermaLink="true">https://klarproof.com/regulators/poland/uodo/</guid><description>The UODO is Poland&apos;s GDPR supervisory authority — the Personal Data Protection Office created in 2018 to replace the old GIODO inspectorate, and one of the most active fining regulators in the EU. What it does, who leads it after the 2024 change at the top, and the security-failure cases (Morele.net, Virgin Mobile) that define its enforcement. Every fact sourced.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>regulator</category><category>gdpr</category><category>uodo</category><category>gdpr</category><category>poland</category><category>regulator</category><category>data-protection</category></item><item><title>Who is the CNPD: Luxembourg&apos;s data regulator behind the €746M Amazon fine</title><link>https://klarproof.com/regulators/luxembourg/cnpd/</link><guid isPermaLink="true">https://klarproof.com/regulators/luxembourg/cnpd/</guid><description>The CNPD is Luxembourg&apos;s GDPR supervisory authority — a small national regulator that issued the second-largest GDPR fine in history, €746 million against Amazon, because so many global companies base their EU operations in the Grand Duchy. What it is, how its collège is composed after the 2025 change, and why a tiny country&apos;s regulator carries outsized weight. Every fact sourced.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>regulator</category><category>gdpr</category><category>cnpd</category><category>gdpr</category><category>luxembourg</category><category>regulator</category><category>data-protection</category><category>amazon</category></item><item><title>Who is the IMY: Sweden&apos;s data protection authority, heir to the world&apos;s first privacy law</title><link>https://klarproof.com/regulators/sweden/imy/</link><guid isPermaLink="true">https://klarproof.com/regulators/sweden/imy/</guid><description>IMY (Integritetsskyddsmyndigheten) is Sweden&apos;s GDPR supervisory authority — the modern name of Datainspektionen, founded in 1973 to enforce what is widely regarded as the world&apos;s first national data protection law. This guide covers what it does, the mandate that runs beyond the GDPR, who runs it after the 2024 leadership change, and the Google, Spotify and Klarna fines — every fact sourced.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>regulator</category><category>gdpr</category><category>imy</category><category>gdpr</category><category>sweden</category><category>regulator</category><category>data-protection</category></item><item><title>Who is the ANSPDCP: Romania&apos;s data regulator that fines often but small</title><link>https://klarproof.com/regulators/romania/anspdcp/</link><guid isPermaLink="true">https://klarproof.com/regulators/romania/anspdcp/</guid><description>The ANSPDCP is Romania&apos;s GDPR supervisory authority — one of the top three EU countries by number of fines, yet with some of the smallest amounts. What it is, who leads it, and the security-breach cases (Raiffeisen, UniCredit, and the famous hotel breakfast-list fine) that define a high-volume, low-value enforcement style. Every fact sourced.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>regulator</category><category>gdpr</category><category>anspdcp</category><category>gdpr</category><category>romania</category><category>regulator</category><category>data-protection</category></item><item><title>Who is the Central Bank of Ireland: the country&apos;s financial regulator and MiCA authority</title><link>https://klarproof.com/regulators/ireland/central-bank/</link><guid isPermaLink="true">https://klarproof.com/regulators/ireland/central-bank/</guid><description>The Central Bank of Ireland is both the country&apos;s central bank and its financial regulator in one — and, under MiCA, Ireland&apos;s single national competent authority for crypto. What it does, how the 2010 reform merged central banking and supervision, who governs it, and its role under MiCA and DORA. Every fact sourced.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>regulator</category><category>mica</category><category>dora</category><category>central-bank-ireland</category><category>mica</category><category>dora</category><category>ireland</category><category>regulator</category><category>crypto</category></item><item><title>Who is the ACPR: France&apos;s prudential supervisor and stablecoin authority under MiCA</title><link>https://klarproof.com/regulators/france/acpr/</link><guid isPermaLink="true">https://klarproof.com/regulators/france/acpr/</guid><description>The ACPR is France&apos;s banking and insurance prudential supervisor, backed by the Banque de France — and, under MiCA, the authority that licenses stablecoin issuers. This guide covers what it does, its three decision-making bodies, the banks it has fined for money-laundering failures (including a €50 million penalty on La Banque Postale), who runs it, and its role under DORA — every fact sourced.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>regulator</category><category>mica</category><category>dora</category><category>acpr</category><category>mica</category><category>dora</category><category>france</category><category>regulator</category><category>stablecoins</category><category>banking</category></item><item><title>Who is the AMF: France&apos;s financial markets regulator and crypto gatekeeper under MiCA</title><link>https://klarproof.com/regulators/france/amf/</link><guid isPermaLink="true">https://klarproof.com/regulators/france/amf/</guid><description>The AMF is France&apos;s financial markets regulator — and, under MiCA, the authority that authorises crypto-asset service providers to operate in France. This guide covers what it does, its two-body structure, how it splits crypto supervision with the ACPR, who chairs it, the fines its Enforcement Committee hands down, and its role under MiCA and DORA — every fact sourced.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>regulator</category><category>mica</category><category>dora</category><category>amf</category><category>mica</category><category>dora</category><category>france</category><category>regulator</category><category>crypto</category></item><item><title>Who is the CSSF: Luxembourg&apos;s financial regulator and single MiCA authority</title><link>https://klarproof.com/regulators/luxembourg/cssf/</link><guid isPermaLink="true">https://klarproof.com/regulators/luxembourg/cssf/</guid><description>The CSSF supervises the professionals and products of Luxembourg&apos;s vast financial sector — and, under MiCA, it is the country&apos;s single competent authority for crypto, unlike France&apos;s split. What it does, its role under MiCA and DORA, and who sits on its Executive Board through a 2026 change. Every fact sourced.</description><pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate><category>regulator</category><category>mica</category><category>dora</category><category>cssf</category><category>mica</category><category>dora</category><category>luxembourg</category><category>regulator</category><category>funds</category></item><item><title>Who is the EDPS: the EU institutions&apos; own data protection supervisor</title><link>https://klarproof.com/regulators/eu/edps/</link><guid isPermaLink="true">https://klarproof.com/regulators/eu/edps/</guid><description>The European Data Protection Supervisor (EDPS) is the independent authority that watches how the EU&apos;s own institutions — the Commission, Parliament, Council, Europol and the rest — handle personal data. What it does, how it differs from the EDPB it is constantly confused with, and who runs it. Every fact sourced.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>regulator</category><category>gdpr</category><category>edps</category><category>gdpr</category><category>eu</category><category>eudpr</category><category>privacy</category></item><item><title>Who is the BfDI: Germany&apos;s federal data protection commissioner</title><link>https://klarproof.com/regulators/germany/bfdi/</link><guid isPermaLink="true">https://klarproof.com/regulators/germany/bfdi/</guid><description>The BfDI is Germany&apos;s federal data-protection regulator — but it supervises only federal bodies and the telecom and postal sector. The rest is handled by 16 state authorities. What the BfDI does, how Germany&apos;s two-tier system works, and who runs it. Every fact sourced.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>regulator</category><category>gdpr</category><category>bfdi</category><category>gdpr</category><category>germany</category><category>privacy</category><category>bdsg</category></item><item><title>Who is the BNetzA: Germany&apos;s AI Act market-surveillance authority</title><link>https://klarproof.com/regulators/germany/bnetza/</link><guid isPermaLink="true">https://klarproof.com/regulators/germany/bnetza/</guid><description>Germany chose its Federal Network Agency (Bundesnetzagentur, BNetzA) — the regulator that runs the power grid and telecoms — as its lead AI Act authority, not its data-protection commissioner. What the BNetzA is, the AI role set out in the draft KI-MIG law, and who runs it. Every fact sourced.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>regulator</category><category>ai-act</category><category>bnetza</category><category>ai-act</category><category>germany</category><category>market-surveillance</category><category>regulation</category></item><item><title>Who is BaFin: Germany&apos;s financial regulator under MiCA and DORA</title><link>https://klarproof.com/regulators/germany/bafin/</link><guid isPermaLink="true">https://klarproof.com/regulators/germany/bafin/</guid><description>BaFin is Germany&apos;s integrated financial supervisor — banks, insurers, securities — and the national authority that licenses crypto firms under MiCA and supervises financial-sector IT resilience under DORA. Germany leads the EU in authorised crypto providers. What BaFin does and who runs it, every fact sourced.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>regulator</category><category>mica</category><category>dora</category><category>bafin</category><category>mica</category><category>dora</category><category>germany</category><category>crypto</category><category>casp</category></item><item><title>Who is the AP: the Netherlands&apos; data protection authority and algorithm watchdog</title><link>https://klarproof.com/regulators/netherlands/ap/</link><guid isPermaLink="true">https://klarproof.com/regulators/netherlands/ap/</guid><description>The Autoriteit Persoonsgegevens is the Netherlands&apos; GDPR supervisory authority — the regulator that fined Uber €290 million and Clearview AI €30.5 million, and, unusually, also the country&apos;s coordinating supervisor for algorithms and AI. What it does, how it is run, and who chairs it through the 2026 leadership change — every fact sourced.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>regulator</category><category>gdpr</category><category>ap</category><category>gdpr</category><category>netherlands</category><category>regulator</category><category>algorithms</category><category>data-protection</category></item><item><title>DORA CTPP register: the 19 critical ICT providers under direct EU oversight</title><link>https://klarproof.com/enforcement/dora-ctpp-register/</link><guid isPermaLink="true">https://klarproof.com/enforcement/dora-ctpp-register/</guid><description>On 18 November 2025 the EU designated its first Critical ICT Third-Party Providers (CTPPs) under DORA — 19 tech firms, from the hyperscale clouds to SAP and Bloomberg, now overseen directly by EU regulators. The full list, what designation means, and the powers behind it — sourced to the official ESA document.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>enforcement</category><category>dora</category><category>dora</category><category>ctpp</category><category>ict</category><category>oversight</category><category>eu</category><category>cloud</category><category>registry</category></item><item><title>MiCA and stablecoins: how USDT left the EU and authorised coins took over</title><link>https://klarproof.com/enforcement/mica-stablecoins-usdt-delisting/</link><guid isPermaLink="true">https://klarproof.com/enforcement/mica-stablecoins-usdt-delisting/</guid><description>MiCA&apos;s most visible real-world effect: by early 2025 the EU&apos;s licensed exchanges had removed Tether (USDT) for EEA users, while Circle&apos;s MiCA-authorised USDC and EURC moved in. The delisting timeline, why it happened, and how the EBA&apos;s &apos;significant token&apos; test works — sourced to the regulators and editorial press.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>enforcement</category><category>mica</category><category>mica</category><category>stablecoin</category><category>usdt</category><category>usdc</category><category>eba</category><category>enforcement</category><category>registry</category></item><item><title>Big Tech GDPR fines: the largest data-protection penalties in EU history</title><link>https://klarproof.com/enforcement/big-tech-gdpr-fines/</link><guid isPermaLink="true">https://klarproof.com/enforcement/big-tech-gdpr-fines/</guid><description>A registry of the biggest GDPR fines ever issued — Meta €1.2 billion, Amazon €746 million, TikTok €530 million, Uber €290 million and more. Who was fined, how much, for what, why almost all of them come out of Ireland, and which ones courts have already overturned — every amount sourced to the regulator or the binding EU decision behind it.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>enforcement</category><category>gdpr</category><category>gdpr</category><category>big-tech</category><category>fines</category><category>enforcement</category><category>meta</category><category>tiktok</category><category>data-transfers</category></item><item><title>AEPD fines: inside the EU&apos;s busiest data-protection enforcer</title><link>https://klarproof.com/enforcement/aepd-fines/</link><guid isPermaLink="true">https://klarproof.com/enforcement/aepd-fines/</guid><description>A registry of the largest fines from Spain&apos;s AEPD — Google €10M, Vodafone €8.15M, CaixaBank €6M, BBVA €5M and more — and why Spain matters less for the size of any single fine than for sheer volume: it issues a larger share of the EU&apos;s GDPR fines than any other country. Who was fined, for what, and why banks and telcos dominate the list. Every amount sourced.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>enforcement</category><category>gdpr</category><category>gdpr</category><category>aepd</category><category>spain</category><category>fines</category><category>enforcement</category><category>banks</category><category>telecoms</category></item><item><title>CNIL fines: the EU&apos;s cookie-enforcement powerhouse, case by case</title><link>https://klarproof.com/enforcement/cnil-fines/</link><guid isPermaLink="true">https://klarproof.com/enforcement/cnil-fines/</guid><description>A registry of the biggest fines issued by France&apos;s CNIL — Google €150M and €100M, Facebook €60M, Microsoft €60M, Orange €50M, Criteo €40M and more. Why most of them are about cookies rather than the GDPR, why the CNIL can fine Big Tech directly when Ireland normally would, and which fines France&apos;s top court has upheld — every amount sourced to the regulator.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>enforcement</category><category>gdpr</category><category>gdpr</category><category>cnil</category><category>france</category><category>cookies</category><category>fines</category><category>enforcement</category><category>eprivacy</category></item><item><title>DPC fines: Europe&apos;s most powerful — and most criticised — data regulator</title><link>https://klarproof.com/enforcement/dpc-fines/</link><guid isPermaLink="true">https://klarproof.com/enforcement/dpc-fines/</guid><description>A registry of fines from Ireland&apos;s DPC — the lead regulator for most of Big Tech, which imposed over €652 million in a single year, yet is accused of going easy on the platforms and being forced higher by the EU. The Big Tech mega-fines, the modest domestic Irish cases (Tusla, Bank of Ireland), and the bottleneck criticism — every fact sourced.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>enforcement</category><category>gdpr</category><category>gdpr</category><category>dpc</category><category>ireland</category><category>big-tech</category><category>fines</category><category>enforcement</category><category>one-stop-shop</category></item><item><title>Garante fines: Italy&apos;s war on telemarketing — and on management by algorithm</title><link>https://klarproof.com/enforcement/garante-fines/</link><guid isPermaLink="true">https://klarproof.com/enforcement/garante-fines/</guid><description>A registry of the largest GDPR fines from Italy&apos;s Garante — Enel Energia €79.1M and €26.5M, TIM €27.8M, Wind Tre €16.7M, Vodafone €12.25M — plus the pioneering gig-economy cases against Foodinho and Deliveroo. Why Italy&apos;s enforcement is dominated by unsolicited marketing calls and worker-management algorithms, and what each company did. Every amount sourced to the regulator.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>enforcement</category><category>gdpr</category><category>gdpr</category><category>garante</category><category>italy</category><category>telemarketing</category><category>fines</category><category>enforcement</category><category>gig-economy</category></item><item><title>Germany&apos;s AI Act law (KI-MIG) reaches government draft</title><link>https://klarproof.com/news/germany-ai-act-implementation-ki-mig/</link><guid isPermaLink="true">https://klarproof.com/news/germany-ai-act-implementation-ki-mig/</guid><description>Germany&apos;s Federal Cabinet adopted the government draft of its AI Act implementation law on 10 February 2026. It names the Federal Network Agency (BNetzA) as the main market-surveillance authority — but it is not yet enacted.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>news</category><category>ai-act</category><category>ai-act</category><category>germany</category><category>bnetza</category><category>enforcement</category><category>regulation</category></item><item><title>François-Louis Michaud takes over as EBA Chair</title><link>https://klarproof.com/news/eba-new-chair-michaud/</link><guid isPermaLink="true">https://klarproof.com/news/eba-new-chair-michaud/</guid><description>François-Louis Michaud became Chair of the European Banking Authority on 16 April 2026, succeeding José Manuel Campa. The EBA supervises significant stablecoin issuers under MiCA and is one of the three ESAs under DORA.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>news</category><category>mica</category><category>mica</category><category>dora</category><category>eba</category><category>eu</category><category>stablecoin</category><category>leadership</category></item><item><title>Rome court annuls the Garante&apos;s €15M GDPR fine against OpenAI</title><link>https://klarproof.com/news/openai-fine-annulled-rome-court/</link><guid isPermaLink="true">https://klarproof.com/news/openai-fine-annulled-rome-court/</guid><description>Italy&apos;s Tribunale di Roma has overturned, in full, the €15 million fine the Garante imposed on OpenAI over ChatGPT in December 2024 — the first major European generative-AI penalty to fall in court.</description><pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate><category>news</category><category>gdpr</category><category>gdpr</category><category>openai</category><category>garante</category><category>italy</category><category>ai</category><category>court</category></item><item><title>Who is the EBA: the EU&apos;s banking authority — and supervisor of the biggest stablecoins</title><link>https://klarproof.com/regulators/eu/eba/</link><guid isPermaLink="true">https://klarproof.com/regulators/eu/eba/</guid><description>The European Banking Authority writes the EU&apos;s banking rulebook and, under MiCA, is the body that directly supervises the largest &apos;significant&apos; stablecoins — the one part of crypto licensing that is centralised at EU level, not national. What it does, how it differs from ESMA, who runs it after the 2026 leadership change, and its role under DORA — every fact sourced.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><category>regulator</category><category>mica</category><category>dora</category><category>eba</category><category>mica</category><category>dora</category><category>eu</category><category>crypto</category><category>stablecoins</category><category>regulator</category></item><item><title>Who is EIOPA: the EU&apos;s insurance and pensions authority — and the third DORA ESA</title><link>https://klarproof.com/regulators/eu/eiopa/</link><guid isPermaLink="true">https://klarproof.com/regulators/eu/eiopa/</guid><description>The European Insurance and Occupational Pensions Authority is the EU&apos;s supervisor for insurance and occupational pensions. It has no crypto or MiCA role at all — it matters to this site for one reason: it is the third of the three ESAs that jointly run DORA. What it does, how it differs from EBA and ESMA, and who runs it — every fact sourced.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><category>regulator</category><category>dora</category><category>eiopa</category><category>dora</category><category>eu</category><category>insurance</category><category>pensions</category><category>regulator</category></item><item><title>Who is the European AI Office: the EU&apos;s enforcer for GPT-class AI models</title><link>https://klarproof.com/regulators/eu/ai-office/</link><guid isPermaLink="true">https://klarproof.com/regulators/eu/ai-office/</guid><description>The European AI Office is the body that polices general-purpose AI — the GPT/Claude/Gemini-class models — directly from Brussels. What it does, the structural detail most coverage skips (it is not an independent agency — it is a department inside the European Commission), who runs it, and where it stops and national authorities take over — every fact sourced.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><category>regulator</category><category>ai-act</category><category>ai-office</category><category>ai-act</category><category>eu</category><category>gpai</category><category>regulator</category><category>european-commission</category></item><item><title>Who is ESMA: the EU&apos;s securities-markets and crypto rule-maker</title><link>https://klarproof.com/regulators/eu/esma/</link><guid isPermaLink="true">https://klarproof.com/regulators/eu/esma/</guid><description>The European Securities and Markets Authority is the EU body that writes the technical rulebook for MiCA crypto and is one of the three authorities overseeing DORA. What it does, what it deliberately does NOT do (it does not licence or fine crypto firms — national regulators do), who runs it, and where it sits next to EBA — every fact sourced.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><category>regulator</category><category>mica</category><category>dora</category><category>esma</category><category>mica</category><category>dora</category><category>eu</category><category>crypto</category><category>regulator</category></item><item><title>Who is the Garante: Italy&apos;s data protection authority that took on ChatGPT</title><link>https://klarproof.com/regulators/italy/garante/</link><guid isPermaLink="true">https://klarproof.com/regulators/italy/garante/</guid><description>The Garante per la protezione dei dati personali is Italy&apos;s GDPR supervisory authority — and the regulator that made global headlines by temporarily blocking ChatGPT. What it does, how its four-member Collegio is structured, why the first big AI fines in Europe are Italian, and who runs it after the January 2026 mandate change — every fact sourced.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><category>regulator</category><category>gdpr</category><category>garante</category><category>gdpr</category><category>italy</category><category>regulator</category><category>ai</category><category>data-protection</category></item><item><title>Who is the DPC: Ireland&apos;s data regulator that polices most of Big Tech</title><link>https://klarproof.com/regulators/ireland/dpc/</link><guid isPermaLink="true">https://klarproof.com/regulators/ireland/dpc/</guid><description>The Data Protection Commission is Ireland&apos;s GDPR supervisory authority — and, because Meta, Google, Apple, TikTok, X and LinkedIn run their EU operations from Ireland, the lead regulator for most of Big Tech across the whole EU under the one-stop-shop. What it does, why one national authority carries EU-wide weight, and who runs it after the move from one Commissioner to a three-person Commission — every fact sourced.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><category>regulator</category><category>gdpr</category><category>dpc</category><category>gdpr</category><category>ireland</category><category>regulator</category><category>big-tech</category><category>one-stop-shop</category></item><item><title>Who is AESIA: Spain&apos;s AI supervisory authority</title><link>https://klarproof.com/regulators/spain/aesia/</link><guid isPermaLink="true">https://klarproof.com/regulators/spain/aesia/</guid><description>AESIA is the EU&apos;s first dedicated national AI agency — Spain&apos;s authority for supervising and, where needed, sanctioning AI systems under the AI Act. What it does, the key detail that it is not an independent authority (unlike a data-protection DPA), who runs it, and where it sits — every fact sourced.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><category>regulator</category><category>ai-act</category><category>aesia</category><category>ai-act</category><category>spain</category><category>regulator</category><category>ai-supervision</category></item><item><title>Who is the AEPD: Spain&apos;s data protection authority — the EU&apos;s busiest fining regulator</title><link>https://klarproof.com/regulators/spain/aepd/</link><guid isPermaLink="true">https://klarproof.com/regulators/spain/aepd/</guid><description>The Agencia Española de Protección de Datos is Spain&apos;s GDPR supervisory authority — and, by number of fines, the most prolific data-protection enforcer in the EU. What it does, why it is not the same body as Spain&apos;s AI authority AESIA, the 2025 leadership change under a new selection model, and who runs it — every fact sourced.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><category>regulator</category><category>gdpr</category><category>aepd</category><category>gdpr</category><category>spain</category><category>regulator</category><category>data-protection</category></item><item><title>Garante AI fines: Italy&apos;s GDPR enforcement against generative AI</title><link>https://klarproof.com/enforcement/garante-ai-fines/</link><guid isPermaLink="true">https://klarproof.com/enforcement/garante-ai-fines/</guid><description>A registry of the Italian data protection authority&apos;s enforcement against generative-AI services: €15M on OpenAI for ChatGPT (later annulled by a Rome court) and €5M on Luka for Replika. What was violated, the exact articles, and the fate of each decision — every fact sourced to the regulator, the court record and editorial press.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><category>enforcement</category><category>gdpr</category><category>ai-act</category><category>gdpr</category><category>garante</category><category>italy</category><category>ai</category><category>openai</category><category>replika</category><category>fines</category></item><item><title>Clearview AI fines: how four EU regulators hit one US facial-recognition firm</title><link>https://klarproof.com/enforcement/clearview-ai-fines/</link><guid isPermaLink="true">https://klarproof.com/enforcement/clearview-ai-fines/</guid><description>A registry of the GDPR fines imposed on Clearview AI by EU data protection authorities — Italy, Greece, France and the Netherlands — for scraping billions of faces without a legal basis. The exact amounts, articles and orders, why the company has paid none of them, and how the UK route diverged. Every fact sourced to the regulator.</description><pubDate>Sun, 17 May 2026 00:00:00 GMT</pubDate><category>enforcement</category><category>gdpr</category><category>ai-act</category><category>gdpr</category><category>clearview</category><category>facial-recognition</category><category>biometric</category><category>ai</category><category>enforcement</category><category>fines</category></item><item><title>Who is AKI: Estonia&apos;s data protection authority</title><link>https://klarproof.com/regulators/estonia/aki/</link><guid isPermaLink="true">https://klarproof.com/regulators/estonia/aki/</guid><description>AKI is Andmekaitse Inspektsioon, Estonia&apos;s GDPR supervisory authority. What it does, who runs it, how to file a complaint, and how it went from issuing €280 fines to a €3,000,000 fine in 2025.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><category>regulator</category><category>gdpr</category><category>aki</category><category>gdpr</category><category>estonia</category><category>privacy</category></item><item><title>Who is the EDPB: the EU&apos;s data protection coordinator</title><link>https://klarproof.com/regulators/eu/edpb/</link><guid isPermaLink="true">https://klarproof.com/regulators/eu/edpb/</guid><description>The European Data Protection Board is the EU-wide body that coordinates national data-protection regulators (DPAs) and resolves cross-border GDPR disputes. What it does, how the one-stop-shop mechanism works, who leads it, and what binding decisions look like.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><category>regulator</category><category>gdpr</category><category>edpb</category><category>gdpr</category><category>eu</category><category>one-stop-shop</category><category>privacy</category></item><item><title>AKI fines: every known enforcement case of Estonia&apos;s Data Protection Inspectorate</title><link>https://klarproof.com/enforcement/aki-fines/</link><guid isPermaLink="true">https://klarproof.com/enforcement/aki-fines/</guid><description>A complete public registry of fines issued by the Estonian Data Protection Inspectorate — from token misdemeanour fines of a few dozen euros on individuals up to €3 million against the Apotheka pharmacy chain. What was violated, which decisions were overturned in court, and why Estonia is the EU&apos;s most lenient GDPR jurisdiction — and is right now ceasing to be one.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><category>enforcement</category><category>gdpr</category><category>gdpr</category><category>aki</category><category>estonia</category><category>fines</category><category>privacy</category></item></channel></rss>