Skip to content

GDPR enforcement in 2023

558 decisions · €457.1M total fines · ← 2022 · 2024 →

Date ↓ Company / party Authority Articles Fine
2023-09-18 SAF LOGISTICS
Non-compliance with general data processing principles
🇪🇺 French Data Protection Authority (CNIL) Art. 5Art. 9Art. 10Art. 31 €200,000
2023-09-18 NN Asigurări de Viață S.A.
Insufficient fulfilment of data subjects rights
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 21 €1,000
2023-09-14 GFB One s.r.l.
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 13Art. 157 €90,000
2023-09-14 Intesa Sanpaolo Spa
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 15 €42,000
2023-09-14 Betting company
Insufficient legal basis for data processing
🇪🇺 Croatian Data Protection Authority (azop) Art. 6Art. 7Art. 13 €30,000
2023-09-14 Betting company
Insufficient legal basis for data processing
🇪🇺 Croatian Data Protection Authority (azop) Art. 6Art. 7Art. 13 €20,000
2023-09-14 Shardana Working Soc. Coop. a r.l.
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 12Art. 15 €20,000
2023-09-14 Azienda Sanitaria dell'Alto Adige - Suedtiroler Sanitaetsbetrieb
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 12 €10,000
2023-09-14 San Severo municipality
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 2 €10,000
2023-09-14 Nimbus s.r.l.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 13 €5,000
2023-09-13 Zagreb Holding d.o.o.
Insufficient fulfilment of information obligations
🇪🇺 Croatian Data Protection Authority (azop) Art. 13Art. 25 €25,000
2023-09-11 Suomen Yritysrekisteri
Insufficient fulfilment of data subjects rights
🇪🇺 Deputy Data Protection Ombudsman Art. 12Art. 15 €23,000
2023-09-07 SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L.
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 6 €70,000
2023-09-06 University of Iceland
Insufficient fulfilment of information obligations
🇪🇺 Icelandic data protection authority ('Persónuvernd') Art. 5Art. 12Art. 13 €10,300
2023-09-05 Vodafone España, S.A.U.
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 6 €80,000
2023-09-04 Company
Insufficient fulfilment of data subjects rights
🇪🇺 Deputy Data Protection Ombudsman Art. 12Art. 15 €1,600
2023-09-01 TikTok Limited
Non-compliance with general data processing principles
🇪🇺 Data Protection Authority of Ireland Art. 5Art. 12Art. 13Art. 24 €345,000,000
2023-09-01 Private individual
Insufficient fulfilment of information obligations
🇪🇺 Spanish Data Protection Authority (aepd) Art. 13 €300
2023-08-31 Robin Srl
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 137Art. 139Art. 6 €25,000
2023-08-31 Bar association
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 2 €20,000
2023-08-31 Mednow Medical Center di Giugni Marco
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 12Art. 15 €10,000
2023-08-31 RCS Mediagroup Spa
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 2Art. 137Art. 139 €10,000
2023-08-31 Legal Person
Insufficient fulfilment of data subjects rights
🇪🇺 Czech Data Protection Auhtority (UOOU) Art. 12 €1,600
2023-08-30 GENERAL LOGISTICS SYSTEMS SPAIN, S.A.
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 6 €140,000
2023-08-30 POLAND DPA: Insufficient cooperation with supervisory authority
Insufficient cooperation with supervisory authority
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 58 €13,000