GDPR enforcement in 2021
531 decisions · €1.3B total fines · ← 2020 · 2022 →
| Date ↓ | Company / party | Authority | Articles | Fine |
|---|---|---|---|---|
| 2021-09-16 | Bocconi University Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 9Art. 13 | €200,000 |
| 2021-09-16 | Favrskov municipality Insufficient technical and organisational measures to ensure information security | 🇪🇺 Danish Data Protection Authority (Datatilsynet) | Art. 32 | €10,000 |
| 2021-09-16 | La Prima S.r.l. Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 24Art. 25 | €5,000 |
| 2021-09-16 | Comune di Montalbano Jonico Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 9Art. 2 | €5,000 |
| 2021-09-16 | Ciechi Ardizzone Gioeni di Catania Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 12Art. 13Art. 35 | €5,000 |
| 2021-09-16 | Frigorifica Botana S.L. Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5 | €4,000 |
| 2021-09-16 | Farpa s.r.l. Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 13Art. 88Art. 114 | €1,000 |
| 2021-09-15 | Société nouvelle de l’annuaire français Insufficient fulfilment of data subjects rights | 🇪🇺 French Data Protection Authority (CNIL) | Art. 16Art. 17Art. 30Art. 31 | €3,000 |
| 2021-09-14 | Vodafone España, S.A.U. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €56,000 |
| 2021-09-14 | Vodafone España, S.A.U. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €56,000 |
| 2021-09-14 | Vodafone España, S.A.U. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €56,000 |
| 2021-09-14 | Vodafone España, S.A.U. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €56,000 |
| 2021-09-14 | Vodafone España, S.A.U. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €40,000 |
| 2021-09-13 | Website operator Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6Art. 13 | €9,000 |
| 2021-09-13 | GESTIONES AUTO LOW COST S. L. Insufficient fulfilment of information obligations | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 13 | €1,000 |
| 2021-09-13 | Hairdressing salon Insufficient fulfilment of information obligations | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 13 | €1,000 |
| 2021-09-08 | Midtjylland Region Insufficient technical and organisational measures to ensure information security | 🇪🇺 Danish Data Protection Authority (Datatilsynet) | Art. 32 | €53,800 |
| 2021-09-07 | Vodafone Ireland Limited Insufficient fulfilment of data subjects rights | 🇪🇺 Data Protection Authority of Ireland | Art. 21 | €1,400 |
| 2021-09-06 | AC Omonia Insufficient technical and organisational measures to ensure information security | 🇪🇺 Cypriot Data Protection Commissioner | Art. 32 | €40,000 |
| 2021-09-06 | APOEL FC Insufficient technical and organisational measures to ensure information security | 🇪🇺 Cypriot Data Protection Commissioner | Art. 32 | €40,000 |
| 2021-09-06 | Hellenic Technical Enterprises Ltd. Insufficient technical and organisational measures to ensure information security | 🇪🇺 Cypriot Data Protection Commissioner | Art. 32 | €25,000 |
| 2021-09-04 | AMPUDIA DIAZ, S.L. Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 13 | €1,500 |
| 2021-09-03 | Rhodes Municipal Transport Company Insufficient fulfilment of data subjects rights | 🇪🇺 Hellenic Data Protection Authority (HDPA) | Art. 5Art. 12Art. 15 | €8,000 |
| 2021-09-02 | WhatsApp Ireland Ltd. Insufficient fulfilment of information obligations | 🇪🇺 Data Protection Authority of Ireland | Art. 5Art. 12Art. 13Art. 14 | €225,000,000 |
| 2021-09-02 | Automecanica Jerez, S.L. Insufficient technical and organisational measures to ensure information security | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 32Art. 21 | €4,000 |