GDPR enforcement in 2020
414 decisions · €172.0M total fines · ← 2019 · 2021 →
| Date ↓ | Company / party | Authority | Articles | Fine |
|---|---|---|---|---|
| 2020-11-06 | Xfera Moviles S.A. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 31 | €20,000 |
| 2020-11-05 | Telefonica Moviles Espana, S.A.U. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 6 | €75,000 |
| 2020-11-03 | Vodafone España, S.A.U. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 6 | €30,000 |
| 2020-10-30 | Marriott International, Inc Insufficient technical and organisational measures to ensure information security | 🇪🇺 Information Commissioner (ICO) | Art. 32 | €20,450,000 |
| 2020-10-29 | Gaypa s.r.l. Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 12Art. 13 | €20,000 |
| 2020-10-29 | Borgo Fonte Scura s.r.l. Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 13 | €4,000 |
| 2020-10-29 | American College of Greece Insufficient fulfilment of information obligations | 🇪🇺 Hellenic Data Protection Authority (HDPA) | Art. 12 | €1,000 |
| 2020-10-28 | Vodafone España, S.A.U. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 6 | €36,000 |
| 2020-10-28 | Play Orenes, S.L. Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5 | €4,000 |
| 2020-10-26 | Conseguridad SL Insufficient involvement of data protection officer | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 37 | €50,000 |
| 2020-10-26 | Università Campus Bio-medico di Roma (Polyclinic) Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 9 | €20,000 |
| 2020-10-26 | Organic Natur 03 S.L. Insufficient fulfilment of information obligations | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 13 | €4,000 |
| 2020-10-24 | Private Individual Non-compliance with general data processing principles | 🇪🇺 Data Protection Authority of Sachsen-Anhalt | Art. 5Art. 32 | €200 |
| 2020-10-23 | Deichmann Cipőkereskedelmi Korlátolt Felelősségű Társaságnak Insufficient fulfilment of data subjects rights | 🇪🇺 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) | Art. 12Art. 15Art. 18Art. 25 | €54,800 |
| 2020-10-22 | Cyprus Police Insufficient technical and organisational measures to ensure information security | 🇪🇺 Cypriot Data Protection Commissioner | Art. 32 | €6,000 |
| 2020-10-21 | Vilnius City Municipality Administration Non-compliance with general data processing principles | 🇪🇺 Lithuanian Data Protection Authority (VDAI) | Art. 5 | €15,000 |
| 2020-10-20 | Globus Score SRL Insufficient cooperation with supervisory authority | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 58 | €2,000 |
| 2020-10-19 | Bank of Cyprus Public Company Ltd Insufficient technical and organisational measures to ensure information security | 🇪🇺 Cypriot Data Protection Commissioner | Art. 5Art. 15Art. 32Art. 33 | €15,000 |
| 2020-10-19 | Grant Ideas Ltd Insufficient legal basis for data processing | 🇪🇺 Cypriot Data Protection Commissioner | Art. 5Art. 6 | €1,000 |
| 2020-10-19 | Private Individual Insufficient legal basis for data processing | 🇪🇺 Austrian Data Protection Authority (dsb) | Art. 5Art. 9 | €600 |
| 2020-10-19 | Private Individual Insufficient legal basis for data processing | 🇪🇺 Austrian Data Protection Authority (dsb) | Art. 5Art. 6 | €150 |
| 2020-10-16 | British Airways Insufficient technical and organisational measures to ensure information security | 🇪🇺 Information Commissioner (ICO) | Art. 5Art. 32 | €22,046,000 |
| 2020-10-15 | S.C. Marsorom S.R.L. Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €3,000 |
| 2020-10-14 | Legal Person Insufficient fulfilment of data subjects rights | 🇪🇺 Czech Data Protection Auhtority (UOOU) | Art. 6Art. 12 | €12,030 |
| 2020-10-09 | Centro de Investigación y Estudio para la Obesidad, SL Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 6 | €50,000 |