GDPR enforcement in 2021
531 decisions · €1.3B total fines · ← 2020 · 2022 →
| Date ↓ | Company / party | Authority | Articles | Fine |
|---|---|---|---|---|
| 2021-11-23 | Vodafone España, S.A.U. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €40,000 |
| 2021-11-23 | YAY ehf. Non-compliance with general data processing principles | 🇪🇺 Icelandic data protection authority ('Persónuvernd') | Art. 5Art. 6Art. 28Art. 32 | €27,200 |
| 2021-11-23 | FUENSANTA S.L. Insufficient cooperation with supervisory authority | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 58 | €3,000 |
| 2021-11-22 | SPAIN DPA: Insufficient fulfilment of information obligations Insufficient fulfilment of information obligations | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 13 | €3,000 |
| 2021-11-22 | ANIVERSALIA NETWORKS, S.L. Insufficient fulfilment of information obligations | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 13 | €2,000 |
| 2021-11-22 | Neighborhood community Insufficient fulfilment of information obligations | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 13 | €1,000 |
| 2021-11-19 | Legal Person Insufficient fulfilment of data subjects rights | 🇪🇺 Czech Data Protection Auhtority (UOOU) | Art. 12 | €800 |
| 2021-11-15 | Vodafone España, SAU Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €40,000 |
| 2021-11-15 | Vodafone España, SAU Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €30,000 |
| 2021-11-15 | Private Individual Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5 | €1,000 |
| 2021-11-15 | Supermarket Insufficient fulfilment of information obligations | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 13 | €1,000 |
| 2021-11-14 | Vodafone România SA Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32Art. 3 | €2,900 |
| 2021-11-12 | WS WiSpear Systems Ltd Non-compliance with general data processing principles | 🇪🇺 Cypriot Data Protection Commissioner | Art. 5 | €925,000 |
| 2021-11-12 | Transavia Insufficient technical and organisational measures to ensure information security | 🇪🇺 Dutch Supervisory Authority for Data Protection (AP) | Art. 32 | €400,000 |
| 2021-11-12 | AD735 DATA MEDIA ADVERTISING S.L. Insufficient cooperation with supervisory authority | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 58 | €3,000 |
| 2021-11-12 | Company Insufficient fulfilment of information obligations | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 13 | €1,500 |
| 2021-11-11 | TIM S.p.A. Insufficient fulfilment of data subjects rights | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 15 | €150,000 |
| 2021-11-09 | LUXEMBOURG DPA: Non-compliance with general data processing principles Non-compliance with general data processing principles | 🇪🇺 National Commission for Data Protection (CNPD) | Art. 5Art. 13 | €1,500 |
| 2021-11-04 | Régie autonome des transports parisiens Non-compliance with general data processing principles | 🇪🇺 French Data Protection Authority (CNIL) | Art. 5Art. 32 | €400,000 |
| 2021-11-02 | COOPERA RC SERVICES, S.L. Insufficient fulfilment of information obligations | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 13 | €2,000 |
| 2021-11-01 | S.P.E.E.H. Hidroelectrica S.A. Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €5,000 |
| 2021-11-01 | Legal Person Insufficient fulfilment of data subjects rights | 🇪🇺 Czech Data Protection Auhtority (UOOU) | Art. 12 | €1,000 |
| 2021-11-01 | IKEA ROMÂNIA SA Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €1,000 |
| 2021-10-28 | Anfiteatro Flavio s.r.l. Insufficient fulfilment of information obligations | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 13 | €2,000 |
| 2021-10-28 | OTTO s.r.l. Insufficient fulfilment of information obligations | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 13 | €2,000 |