Skip to content

GDPR enforcement in 2021

531 decisions · €1.3B total fines · ← 2020 · 2022 →

Date ↓ Company / party Authority Articles Fine
2021-11-23 Vodafone España, S.A.U.
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 6 €40,000
2021-11-23 YAY ehf.
Non-compliance with general data processing principles
🇪🇺 Icelandic data protection authority ('Persónuvernd') Art. 5Art. 6Art. 28Art. 32 €27,200
2021-11-23 FUENSANTA S.L.
Insufficient cooperation with supervisory authority
🇪🇺 Spanish Data Protection Authority (aepd) Art. 58 €3,000
2021-11-22 SPAIN DPA: Insufficient fulfilment of information obligations
Insufficient fulfilment of information obligations
🇪🇺 Spanish Data Protection Authority (aepd) Art. 13 €3,000
2021-11-22 ANIVERSALIA NETWORKS, S.L.
Insufficient fulfilment of information obligations
🇪🇺 Spanish Data Protection Authority (aepd) Art. 13 €2,000
2021-11-22 Neighborhood community
Insufficient fulfilment of information obligations
🇪🇺 Spanish Data Protection Authority (aepd) Art. 13 €1,000
2021-11-19 Legal Person
Insufficient fulfilment of data subjects rights
🇪🇺 Czech Data Protection Auhtority (UOOU) Art. 12 €800
2021-11-15 Vodafone España, SAU
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 6 €40,000
2021-11-15 Vodafone España, SAU
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 6 €30,000
2021-11-15 Private Individual
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5 €1,000
2021-11-15 Supermarket
Insufficient fulfilment of information obligations
🇪🇺 Spanish Data Protection Authority (aepd) Art. 13 €1,000
2021-11-14 Vodafone România SA
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32Art. 3 €2,900
2021-11-12 WS WiSpear Systems Ltd
Non-compliance with general data processing principles
🇪🇺 Cypriot Data Protection Commissioner Art. 5 €925,000
2021-11-12 Transavia
Insufficient technical and organisational measures to ensure information security
🇪🇺 Dutch Supervisory Authority for Data Protection (AP) Art. 32 €400,000
2021-11-12 AD735 DATA MEDIA ADVERTISING S.L.
Insufficient cooperation with supervisory authority
🇪🇺 Spanish Data Protection Authority (aepd) Art. 58 €3,000
2021-11-12 Company
Insufficient fulfilment of information obligations
🇪🇺 Spanish Data Protection Authority (aepd) Art. 13 €1,500
2021-11-11 TIM S.p.A.
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 15 €150,000
2021-11-09 LUXEMBOURG DPA: Non-compliance with general data processing principles
Non-compliance with general data processing principles
🇪🇺 National Commission for Data Protection (CNPD) Art. 5Art. 13 €1,500
2021-11-04 Régie autonome des transports parisiens
Non-compliance with general data processing principles
🇪🇺 French Data Protection Authority (CNIL) Art. 5Art. 32 €400,000
2021-11-02 COOPERA RC SERVICES, S.L.
Insufficient fulfilment of information obligations
🇪🇺 Spanish Data Protection Authority (aepd) Art. 13 €2,000
2021-11-01 S.P.E.E.H. Hidroelectrica S.A.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €5,000
2021-11-01 Legal Person
Insufficient fulfilment of data subjects rights
🇪🇺 Czech Data Protection Auhtority (UOOU) Art. 12 €1,000
2021-11-01 IKEA ROMÂNIA SA
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €1,000
2021-10-28 Anfiteatro Flavio s.r.l.
Insufficient fulfilment of information obligations
🇪🇺 Italian Data Protection Authority (Garante) Art. 13 €2,000
2021-10-28 OTTO s.r.l.
Insufficient fulfilment of information obligations
🇪🇺 Italian Data Protection Authority (Garante) Art. 13 €2,000