Skip to content

GDPR enforcement in 2020

414 decisions · €172.0M total fines · ← 2019 · 2021 →

Date ↓ Company / party Authority Articles Fine
2020-11-06 Xfera Moviles S.A.
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 31 €20,000
2020-11-05 Telefonica Moviles Espana, S.A.U.
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 6 €75,000
2020-11-03 Vodafone España, S.A.U.
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 6 €30,000
2020-10-30 Marriott International, Inc
Insufficient technical and organisational measures to ensure information security
🇪🇺 Information Commissioner (ICO) Art. 32 €20,450,000
2020-10-29 Gaypa s.r.l.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 12Art. 13 €20,000
2020-10-29 Borgo Fonte Scura s.r.l.
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 13 €4,000
2020-10-29 American College of Greece
Insufficient fulfilment of information obligations
🇪🇺 Hellenic Data Protection Authority (HDPA) Art. 12 €1,000
2020-10-28 Vodafone España, S.A.U.
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 6 €36,000
2020-10-28 Play Orenes, S.L.
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5 €4,000
2020-10-26 Conseguridad SL
Insufficient involvement of data protection officer
🇪🇺 Spanish Data Protection Authority (aepd) Art. 37 €50,000
2020-10-26 Università Campus Bio-medico di Roma (Polyclinic)
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9 €20,000
2020-10-26 Organic Natur 03 S.L.
Insufficient fulfilment of information obligations
🇪🇺 Spanish Data Protection Authority (aepd) Art. 13 €4,000
2020-10-24 Private Individual
Non-compliance with general data processing principles
🇪🇺 Data Protection Authority of Sachsen-Anhalt Art. 5Art. 32 €200
2020-10-23 Deichmann Cipőkereskedelmi Korlátolt Felelősségű Társaságnak
Insufficient fulfilment of data subjects rights
🇪🇺 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) Art. 12Art. 15Art. 18Art. 25 €54,800
2020-10-22 Cyprus Police
Insufficient technical and organisational measures to ensure information security
🇪🇺 Cypriot Data Protection Commissioner Art. 32 €6,000
2020-10-21 Vilnius City Municipality Administration
Non-compliance with general data processing principles
🇪🇺 Lithuanian Data Protection Authority (VDAI) Art. 5 €15,000
2020-10-20 Globus Score SRL
Insufficient cooperation with supervisory authority
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 58 €2,000
2020-10-19 Bank of Cyprus Public Company Ltd
Insufficient technical and organisational measures to ensure information security
🇪🇺 Cypriot Data Protection Commissioner Art. 5Art. 15Art. 32Art. 33 €15,000
2020-10-19 Grant Ideas Ltd
Insufficient legal basis for data processing
🇪🇺 Cypriot Data Protection Commissioner Art. 5Art. 6 €1,000
2020-10-19 Private Individual
Insufficient legal basis for data processing
🇪🇺 Austrian Data Protection Authority (dsb) Art. 5Art. 9 €600
2020-10-19 Private Individual
Insufficient legal basis for data processing
🇪🇺 Austrian Data Protection Authority (dsb) Art. 5Art. 6 €150
2020-10-16 British Airways
Insufficient technical and organisational measures to ensure information security
🇪🇺 Information Commissioner (ICO) Art. 5Art. 32 €22,046,000
2020-10-15 S.C. Marsorom S.R.L.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €3,000
2020-10-14 Legal Person
Insufficient fulfilment of data subjects rights
🇪🇺 Czech Data Protection Auhtority (UOOU) Art. 6Art. 12 €12,030
2020-10-09 Centro de Investigación y Estudio para la Obesidad, SL
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 6 €50,000