GDPR & AI Act news for September 2026: what you shouldn't have missed
In September 2026, three topics dominated the GDPR and AI Act landscape. The CNIL has issued guidance on B2B electronic invoicing: platforms (PDPs) are considered data processors, sensitive information must be coded, and MFA is now mandatory. The LINC has published its analysis of agentic AI, focusing on traceability, persistent memory, and data minimization. The EDPB has adopted Guidelines 04/2026, which harmonize the fine calculation process into five steps. Regarding enforcement, the Irish DPC has fined Google €403M, while the CNIL has sanctioned the Hôpital Privé de la Loire (€500,000) and EXTIA (€300,000).

In September 2026, three topics dominated the GDPR and AI Act landscape. The CNIL has issued guidance on B2B electronic invoicing: platforms (PDPs) are considered data processors, sensitive information must be coded, and MFA is now mandatory. The LINC has published its analysis of agentic AI, focusing on traceability, persistent memory, and data minimization. The EDPB has adopted Guidelines 04/2026, which harmonize the fine calculation process into five steps. Regarding enforcement, the Irish DPC has fined Google €403M, while the CNIL has sanctioned the Hôpital Privé de la Loire (€500,000) and EXTIA (€300,000).
September 2026 was a busy month for legal and compliance professionals. The B2B electronic invoicing mandate came into effect, the CNIL's LINC published a breakdown of agentic AI, and the EDPB adopted a harmonized method for calculating fines. Supervisory authorities are tightening the framework around automated workflows and data governance.
Here are the three major topics of the month, key enforcement decisions, and the DPO checklist for the new season.
Electronic Invoicing and GDPR: CNIL Recommendations (September 10, 2026)
As of September 1, 2026, companies are required to receive electronic invoices. In this context, the CNIL has clarified the GDPR rules applicable to these new digital workflows.
Partner Dematerialization Platforms (PDPs) are data processors
A PDP acts as a data processor. If it reuses or analyzes invoice data for its own purposes (such as commercial scoring or statistics), it must be classified as a data controller and obtain prior consent from the client.
Sensitive invoice information must be coded
Certain sectors are subject to professional secrecy, including healthcare, law firms, and consulting. For these entities, detailed descriptions entered in free-text fields on invoices must be coded. The goal is to prevent the unlawful processing of sensitive data (Article 9 of the GDPR).
Shared accounts are being replaced by individual access with MFA
The CNIL requires the closure of generic shared accounts, such as compta@entreprise.com. These must be replaced by individual credentials associated with multi-factor authentication (MFA).
Agentic AI: The CNIL LINC analysis on the risks of autonomy (September 2, 2026)
On September 2, 2026, the CNIL's Digital Innovation Laboratory (LINC) published the analysis "Agentic AI: What are we talking about?". This work clarifies the legal classification of systems based on language models capable of chaining actions autonomously: accessing APIs, querying RAG databases, sending emails, or executing transactions.
The CNIL identifies three major challenges for compliance teams.
Action traceability and accountability
An agent can act directly on third-party applications: sending messages, modifying files, or scheduling appointments. This capability requires rigorous traceability. It allows for determining who is responsible in the event of damage or an erroneous action.
Persistent memory and the exercise of rights
Agent personalization features rely on history and long-term memory. The LINC warns that it is difficult to guarantee the exercise of rights, such as erasure or objection, regarding these persistent memories.
Massive data access and the principle of data minimization
Autonomous agents are often connected to drives, email inboxes, or RAG databases. They therefore risk processing volumes of data unrelated to the initial task, which violates the principle of data minimization (Article 5 of the GDPR).
{{newsletter}}
GDPR fines: the 5-step method from EDPB Guidelines 04/2026
The EDPB adopted Guidelines 04/2026 on September 17, 2026. They establish a harmonized 5-step reasoning process that all European authorities must apply before issuing a fine:
- Legal basis: the authority verifies that the breach falls under the infringements covered by Article 83 of the GDPR
- Accountability: it precisely identifies the legal entity responsible
- Intent: it assesses whether the breach was intentional or the result of gross negligence
- Nature and severity (Article 83.2): it analyzes the scope and duration of the infringement; the text now establishes a strong presumption of a fine unless the infringement is classified as "minor"
- Adequacy: it ensures that the sanction is effective, proportionate, and dissuasive
DPO Checklist for Fall 2026
- Validate PDP contracts (electronic invoicing): verify that the data processing agreement (Article 28 of the GDPR) prohibits the platform from reusing invoices
- Secure accounting portals: remove shared access and mandate MFA for viewing invoices
- Audit the scope of AI agents: map autonomous agents deployed internally and control their access to APIs and RAG databases
- Monitor the retention of geolocation data: ensure that automatic location history purges are actually working
FAQ - GDPR Sanctions and News for September 2026
What was the main European GDPR sanction in September 2026?
On September 21, 2026, the Irish DPC fined Google €403 million. The penalty was issued for a lack of legal basis, insufficient transparency, and excessive data retention related to geolocation tracking features.
Why did the CNIL sanction the Hôpital Privé de la Loire?
On September 3, 2026, the CNIL fined the Hôpital Privé de la Loire €500,000. A security failure (Article 32 of the GDPR) had led to a health data breach.
What sanction did the CNIL impose on EXTIA?
On September 9, 2026, the CNIL fined EXTIA €300,000. The company had repeatedly failed to comply with access and objection requests made by candidates during its recruitment process.
What happened with the injunction against Solocal Marketing Services?
On September 17, 2026, the CNIL formally closed the injunction concerning the commercial prospecting processes of Solocal Marketing Services, as the company had returned to compliance.
What does the CNIL recommend for cloud office suites like Microsoft 365 or Google Workspace?
The CNIL has published a series of practical guides on the use of cloud office suites. It reiterates that providers cannot collect telemetry and usage metadata without users' knowledge to train their internal AI models.
September 2026 at a glance
GDPR news for September 2026 reveals a clear trend: authorities are tightening their oversight of automated data flows. This affects electronic invoices transmitted via PDPs, autonomous AI agents, and cloud tools. At the same time, the EDPB's harmonized methodology is making fines more predictable and systematic. For DPOs, CIOs, and CISOs, the priority for the new season is to update sub-processing agreements, secure access points, and map out AI agents.
{{newsletter}}

