Get tomorrow's brief in your inbox
Today: European data protection authorities issued three separate GDPR enforcement actions totaling €593,052 in fines for marketing violations and data accuracy failures. The SEC's new Cyber and Emerging Technologies Unit signals continued focus on AI-related fraud despite reduced whistleblower awards in FY 2025. Section 230 litigation over social media platform design features continues to challenge the content versus design distinction.
Spain Fines Energy Supplier €30,000 for Unauthorized Provider Switch (AEPD - EXP202306737)
Spain's DPA fined GAOLANIA SERVICIOS €30,000 after the energy supplier changed a customer's electricity provider without consent by relying on an incorrect CUPS identifier provided by a third party. The controller processed the wrong individual's personal data without a legal basis under Article 6(1) GDPR and violated the accuracy principle under Article 5(1)(d) GDPR by failing to verify the identifier before processing. The DPA emphasized that controllers cannot rely solely on information provided by third parties and must verify personal data accuracy before processing.
Belgium Warns Two Government Agencies for Access Request Delays
Belgium's DPA warned the Walloon Public Service and the Economic, Social and Environmental Council after both agencies failed to respond within the legal time limit to access requests from a hunter whose personal data appeared in a published opinion. The Department violated Article 12(3) and Article 15 GDPR by failing to respond in time. The Council separately violated Article 12(3) GDPR, Article 15 GDPR for access request delays, and Article 12(4) and Article 17 GDPR by refusing an erasure request on incorrect legal grounds and responding after the legal deadline. The DPA found the Council could not rely on legitimate interest under Article 6(1)(f) GDPR as a legal basis, constituting a potential violation of Article 5(1)(a) GDPR.
Italy Fines Enel Energia €563,052 for Marketing Violations (Garante - 10233396)
Italy's DPA fined Enel Energia, the country's largest energy provider, €563,052 for conducting marketing activities during customer care calls without consent, failing to oversee processor operations, and allowing unlawful marketing calls by third parties. The DPA held that customer care calls are lawful under Article 6(1)(b) GDPR without consent, but controllers may only provide marketing information during such calls if the recipient previously consented to direct marketing or requested the information. Enel's SMS notification system for documenting consent was insufficient. The company also failed to ensure processors registered phone numbers in Italy's national marketing operator register and failed to audit a processor that had been previously sanctioned by the DPA, violating Articles 5, 24, and 28 GDPR.
SEC Focuses on AI Fraud Through New Cyber and Emerging Technologies Unit
The SEC created the Cyber and Emerging Technologies Unit (CETU) in February 2025 to target fraud involving artificial intelligence and machine learning. The Division of Examinations' FY2026 priorities specifically identify registrants' use of AI technologies and trading algorithms, focusing on the accuracy of AI-related representations and the adequacy of policies, procedures, and supervision. Despite awarding only $60 million to whistleblowers in FY 2025 (a steep decline from previous years), the SEC Office of the Whistleblower continues to process AI-related complaints. Whistleblowers who provide original, timely, and credible information leading to successful enforcement actions remain eligible for awards ranging from 10 to 30 percent of monetary sanctions exceeding $1 million.
Section 230 Design Versus Content Debate Continues in Instagram Litigation
Trial courts in California and New Mexico ruled that Section 230 immunity does not apply to claims about social media platform design features like infinite scroll, autoplay, and algorithmic recommendations, distinguishing between "product design" and "content" issues. Plaintiffs argue that Instagram's design creates addiction and mental health harm, particularly for children, regardless of content. The courts accepted arguments that design features like infinite scroll, autoplay, algorithmic recommendations, and notification systems constitute separate grounds for liability distinct from user-generated content. Both cases proceeded to trial after courts rejected Section 230 defenses.
Verify third-party data before processing. The Spanish AEPD decision makes clear that controllers bear responsibility for data accuracy even when relying on information from third parties. Implement verification steps for customer identifiers, account numbers, and contact information before processing account changes or service switches.
Enforce strict GDPR response deadlines. Belgium's warning to two government agencies highlights the one-month response requirement under Article 12(3) GDPR for access and erasure requests. Review internal procedures to ensure compliance teams can meet this deadline and document proper legal grounds when refusing erasure requests under Article 17(3) GDPR.
Separate customer service from marketing. Italy's €563,052 fine against Enel Energia establishes that customer care calls under Article 6(1)(b) GDPR cannot include marketing content without separate consent. Train customer service teams to distinguish between service interactions and marketing, and obtain explicit consent before transitioning to marketing during customer care calls.
Implement AI governance and whistleblower protections. The SEC's Cyber and Emerging Technologies Unit and FY2026 examination priorities signal continued scrutiny of AI representations and governance. Financial services firms should document AI policies, audit AI-related public statements for accuracy, and establish internal channels for AI and cybersecurity concerns to reduce whistleblower activity.
Monitor Section 230 design liability developments. The distinction between platform design features and content moderation continues to evolve in litigation. Companies offering social media platforms or algorithmic recommendation systems should track these cases and consider whether design features like autoplay, infinite scroll, or notification systems create liability exposure separate from user-generated content immunity under Section 230.