GDPR enforcement in 2021
531 decisions · €1.3B total fines · ← 2020 · 2022 →
| Date ↓ | Company / party | Authority | Articles | Fine |
|---|---|---|---|---|
| 2021-10-06 | Facebook Ireland Limited Insufficient fulfilment of information obligations | 🇪🇺 Data Protection Authority of Ireland | Art. 5Art. 12Art. 13 | — |
| 2021-10-05 | CLUB DEPORTIVO SANSUEÑA, S.L. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 6Art. 32 | €4,000 |
| 2021-10-04 | CALDERERIA Y SOLDADURA DE ESTRUCTURAS METALICAS, S.L. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €5,000 |
| 2021-10-04 | PREMIUMMEDIA ΠΑΡΑΓΩΓΗ ΟΠΤΙΚΟ-ΑΚΟΥΣΤΙΚΩΝ ΕΡΓΩΝ ΙΔΙΩΤΙΚΗ ΚΕΦΑΛΑΙΟΥΧΙΚΗ ΕΤΑΙΡΙΑ Insufficient fulfilment of data subjects rights | 🇪🇺 Hellenic Data Protection Authority (HDPA) | Art. 21Art. 25 | €5,000 |
| 2021-10-04 | Store owner Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5 | €2,000 |
| 2021-10-04 | Store owner Insufficient fulfilment of information obligations | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 13 | €1,000 |
| 2021-09-29 | Danish Cancer Society Insufficient technical and organisational measures to ensure information security | 🇪🇺 Danish Data Protection Authority (Datatilsynet) | Art. 32 | €107,000 |
| 2021-09-29 | Territorial Administration of the Government of Genoa Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 2 | €11,000 |
| 2021-09-29 | ACONCAGUA JUEGOS S.A. Insufficient involvement of data protection officer | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 37 | €10,000 |
| 2021-09-29 | CYNGASA, S.L. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €5,000 |
| 2021-09-29 | Physician Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 9 | €2,000 |
| 2021-09-28 | Austrian Post Insufficient fulfilment of data subjects rights | 🇪🇺 Austrian Data Protection Authority (dsb) | Art. 12 | €9,500,000 |
| 2021-09-28 | Address Broker Insufficient fulfilment of data subjects rights | 🇪🇺 Austrian Data Protection Authority (dsb) | Art. 12 | €500,000 |
| 2021-09-28 | Bar owner Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5 | €3,000 |
| 2021-09-27 | Ferde AS Non-compliance with general data processing principles | 🇪🇺 Norwegian Supervisory Authority (Datatilsynet) | Art. 5Art. 28Art. 32Art. 44 | €496,000 |
| 2021-09-24 | Vattenfall Europe Sales GmbH Insufficient data processing agreement | 🇪🇺 Data Protection Authority of Hamburg | Art. 12Art. 13 | €900,000 |
| 2021-09-24 | SPAIN DPA: Insufficient fulfilment of information obligations Insufficient fulfilment of information obligations | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 13 | €3,000 |
| 2021-09-21 | Ultra-Technology AS Insufficient legal basis for data processing | 🇪🇺 Norwegian Supervisory Authority (Datatilsynet) | Art. 6 | €12,500 |
| 2021-09-21 | Istituto Comprensivo - IC Cosenza III “V. Negroni” Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 9Art. 2 | €2,000 |
| 2021-09-20 | ST. OLAVS HOSPITAL HF Insufficient technical and organisational measures to ensure information security | 🇪🇺 Norwegian Supervisory Authority (Datatilsynet) | Art. 32 | €75,600 |
| 2021-09-20 | Høylandet Municipality Insufficient technical and organisational measures to ensure information security | 🇪🇺 Norwegian Supervisory Authority (Datatilsynet) | Art. 32 | €40,200 |
| 2021-09-20 | CEDICO, CENTRO DE DIAGNÓSTICO POR LA IMÁGEN, S.L. Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5 | €18,000 |
| 2021-09-17 | Syddanmark Region Insufficient technical and organisational measures to ensure information security | 🇪🇺 Danish Data Protection Authority (Datatilsynet) | Art. 32 | €67,200 |
| 2021-09-17 | Mediterranean Hospital of Cyprus Insufficient cooperation with supervisory authority | 🇪🇺 Cypriot Data Protection Commissioner | Art. 31Art. 58 | €10,000 |
| 2021-09-16 | Sky Italia S.r.l. Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 7Art. 12 | €3,296,326 |