GDPR enforcement in 2022
603 decisions · €519.9M total fines · ← 2021 · 2023 →
| Date ↓ | Company / party | Authority | Articles | Fine |
|---|---|---|---|---|
| 2022-11-25 | ALPA 57 PRODUCCIONES, S.L. Insufficient cooperation with supervisory authority | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 58 | €1,800 |
| 2022-11-24 | Areti spa Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 12Art. 15Art. 24 | €1,000,000 |
| 2022-11-24 | ÉLECTRICITÉ DE FRANCE Insufficient fulfilment of data subjects rights | 🇪🇺 French Data Protection Authority (CNIL) | Art. 7Art. 12Art. 13Art. 14 | €600,000 |
| 2022-11-24 | Società Lombarda Sport s.r.l. Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 9 | €4,000 |
| 2022-11-24 | Ordine dei Medici Chirurghi e degli Odontoiatri della Provincia di Cagliari Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 2 | €3,000 |
| 2022-11-24 | Medicover S.R.L. Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €1,000 |
| 2022-11-24 | STS Di Prisinzano s.r.l Insufficient fulfilment of information obligations | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 13 | €1,000 |
| 2022-11-24 | Private individual Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 9Art. 32 | €1,000 |
| 2022-11-21 | ING Bank NV Amsterdam Sucursala București Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €20,000 |
| 2022-11-21 | Private individual Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5 | €300 |
| 2022-11-18 | Homeowners Association Bld. Pipera 1-2E Insufficient cooperation with supervisory authority | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 58 | €300 |
| 2022-11-16 | Raiffeisen Bank SA Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 25Art. 32 | €28,000 |
| 2022-11-15 | BANKINTER, S.A. Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 32 | €80,000 |
| 2022-11-15 | News service Insufficient legal basis for data processing | 🇪🇺 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) | Art. 6Art. 7Art. 12 | €5,200 |
| 2022-11-11 | Banco Bilbao Vizcaya Argentaria S.L. Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 32 | €48,000 |
| 2022-11-11 | XASTRE DO PETO, S.L. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6Art. 13Art. 21 | €3,600 |
| 2022-11-10 | DISCORD INC. Non-compliance with general data processing principles | 🇪🇺 French Data Protection Authority (CNIL) | Art. 5Art. 13Art. 25Art. 32 | €800,000 |
| 2022-11-10 | Vodafone Italia S.p.A. Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 7Art. 12 | €500,000 |
| 2022-11-10 | Azienda Usl Valle d'Aosta Insufficient technical and organisational measures to ensure information security | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 9Art. 25Art. 32 | €40,000 |
| 2022-11-10 | Sportitalia Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 9Art. 13Art. 30 | €20,000 |
| 2022-11-10 | Poliambulatorio Radiologico 'il Sorriso' S.r.l. Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 13Art. 37 | €15,000 |
| 2022-11-10 | I-Model s.r.l. Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 6Art. 17 | €10,000 |
| 2022-11-10 | Conservatorio di Musica S. Cecilia di Roma Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 38Art. 2 | €6,000 |
| 2022-11-10 | Cisterna di Latina municipality Insufficient fulfilment of data subjects rights | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 12Art. 37 | €5,000 |
| 2022-11-10 | Cisterna di Latina Municipality Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 12Art. 37 | €5,000 |