GDPR enforcement in 2022
603 decisions · €519.9M total fines · ← 2021 · 2023 →
| Date ↓ | Company / party | Authority | Articles | Fine |
|---|---|---|---|---|
| 2022-09-21 | Curtea Veche Publishing SRL Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €5,000 |
| 2022-09-21 | Surveyor Insufficient legal basis for data processing | 🇪🇺 Data Protection Authority of Baden-Wuerttemberg | Art. 6 | €5,000 |
| 2022-09-20 | Company Insufficient involvement of data protection officer | 🇪🇺 Data Protection Authority of Berlin | Art. 38 | €525,000 |
| 2022-09-20 | Union Sindical Obrera Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €1,800 |
| 2022-09-19 | Banca Comercială Română SA Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 25Art. 32 | €2,000 |
| 2022-09-16 | SOPHIE ET VOILA, S.L Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €10,000 |
| 2022-09-16 | MARIELI GABRIELA, S.L. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €3,000 |
| 2022-09-16 | Agent of the real estate agency BARCELONA DREAM HOUSE AGENCY Insufficient fulfilment of information obligations | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 13 | €2,000 |
| 2022-09-16 | Private individual Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5 | €480 |
| 2022-09-15 | Lazio Region Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 9Art. 12 | €100,000 |
| 2022-09-15 | FCA Italy S.p.A. Insufficient fulfilment of data subjects rights | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 12Art. 15 | €40,000 |
| 2022-09-15 | Bper Banca S.p.A. Insufficient fulfilment of data subjects rights | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 12 | €10,000 |
| 2022-09-15 | Thiene municipality Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 2 | €3,000 |
| 2022-09-15 | Immobiliare Riscostruzione Meloria s.r.l. Insufficient fulfilment of information obligations | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 13 | €2,000 |
| 2022-09-13 | GIE INFOGREFFE Insufficient technical and organisational measures to ensure information security | 🇪🇺 French Data Protection Authority (CNIL) | Art. 5Art. 32 | €250,000 |
| 2022-09-13 | Private individual Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5 | €2,000 |
| 2022-09-13 | Private individual Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5 | €300 |
| 2022-09-12 | Coin dealer Non-compliance with general data processing principles | 🇪🇺 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) | Art. 5Art. 6Art. 7Art. 12 | €80,700 |
| 2022-09-12 | Hørsholm municipality Insufficient technical and organisational measures to ensure information security | 🇪🇺 Danish Data Protection Authority (Datatilsynet) | Art. 32 | €6,700 |
| 2022-09-09 | School Non-compliance with general data processing principles | 🇪🇺 Hellenic Data Protection Authority (HDPA) | Art. 5Art. 6Art. 12Art. 13 | €15,000 |
| 2022-09-09 | SC Raiffeisen Bank SA Non-compliance with general data processing principles | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 5 | €2,000 |
| 2022-09-09 | Private individual Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5 | €300 |
| 2022-09-09 | EURO DONER KEBAB Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 13 | €180 |
| 2022-09-08 | Realmedia Network SA Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €8,000 |
| 2022-09-07 | Sułkowice Cultural Center Insufficient data processing agreement | 🇪🇺 Polish National Personal Data Protection Office (UODO) | Art. 28 | €530 |