GDPR enforcement in 2022
603 decisions · €519.9M total fines · ← 2021 · 2023 →
| Date ↓ | Company / party | Authority | Articles | Fine |
|---|---|---|---|---|
| 2022-10-06 | Alpha Exploration Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 7Art. 12 | €2,000,000 |
| 2022-10-06 | Veneto region Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 2 | €100,000 |
| 2022-10-06 | Servizio Idrico Integrato S.c.p.a. Insufficient technical and organisational measures to ensure information security | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 32 | €15,000 |
| 2022-10-06 | Poste Italiane S.p.a. Insufficient fulfilment of data subjects rights | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 12 | €10,000 |
| 2022-10-06 | Codess Sociale, Soc. Coop. sociale. Insufficient fulfilment of data subjects rights | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 12Art. 17 | €10,000 |
| 2022-10-06 | Associazione Rescue Drones Network ODV Insufficient fulfilment of data subjects rights | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 12Art. 15 | €3,000 |
| 2022-10-05 | Bank Insufficient legal basis for data processing | 🇪🇺 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) | Art. 5Art. 6Art. 12 | €72,500 |
| 2022-10-04 | Easylife Ltd. Insufficient legal basis for data processing | 🇪🇺 Information Commissioner (ICO) | Art. 5Art. 6Art. 9Art. 13 | €1,547,000 |
| 2022-10-04 | Club Náutico el Estacio Insufficient technical and organisational measures to ensure information security | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 32 | €6,000 |
| 2022-10-04 | Homeowners Association Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 13 | €600 |
| 2022-10-03 | NATIONAL BANK OF GREECE S.A. Insufficient fulfilment of information obligations | 🇪🇺 Hellenic Data Protection Authority (HDPA) | Art. 13 | €20,000 |
| 2022-10-03 | EUROBANK ERGASIAS S.A. Insufficient fulfilment of information obligations | 🇪🇺 Hellenic Data Protection Authority (HDPA) | Art. 13 | €20,000 |
| 2022-10-03 | ALFA BANK S.A. Insufficient fulfilment of information obligations | 🇪🇺 Hellenic Data Protection Authority (HDPA) | Art. 13 | €20,000 |
| 2022-10-03 | PIRAEUS BANK S.A. Insufficient fulfilment of information obligations | 🇪🇺 Hellenic Data Protection Authority (HDPA) | Art. 13 | €20,000 |
| 2022-10-03 | Website operator Non-compliance with general data processing principles | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 5Art. 6 | €150 |
| 2022-09-28 | BAYARD REVISTAS, S.A. Insufficient technical and organisational measures to ensure information security | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 32Art. 33 | €31,200 |
| 2022-09-28 | CLUB NATACIO LLEIDA Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5 | €720 |
| 2022-09-28 | Y OTRO MAS C.B. Insufficient fulfilment of information obligations | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 13 | €180 |
| 2022-09-26 | TV2 Média Csoport Zrt. Non-compliance with general data processing principles | 🇪🇺 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) | Art. 5Art. 6Art. 12Art. 13 | €26,700 |
| 2022-09-25 | Health insurance provider Non-compliance with general data processing principles | 🇪🇺 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) | Art. 5Art. 12Art. 31 | €1,200 |
| 2022-09-23 | Private individual Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 13 | €3,000 |
| 2022-09-23 | URBANO DIVERTIA, S.L. Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5 | €1,200 |
| 2022-09-22 | Gas station Insufficient fulfilment of data subjects rights | 🇪🇺 Hellenic Data Protection Authority (HDPA) | Art. 12Art. 14 | €3,000 |
| 2022-09-22 | Bitfactor SRL Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 25Art. 32 | €2,000 |
| 2022-09-21 | Property development company Insufficient legal basis for data processing | 🇪🇺 Data Protection Authority of Baden-Wuerttemberg | Art. 6Art. 14 | €50,000 |