GDPR enforcement in 2023
558 decisions · €457.1M total fines · ← 2022 · 2024 →
| Date ↓ | Company / party | Authority | Articles | Fine |
|---|---|---|---|---|
| 2023-09-18 | SAF LOGISTICS Non-compliance with general data processing principles | 🇪🇺 French Data Protection Authority (CNIL) | Art. 5Art. 9Art. 10Art. 31 | €200,000 |
| 2023-09-18 | NN Asigurări de Viață S.A. Insufficient fulfilment of data subjects rights | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 21 | €1,000 |
| 2023-09-14 | GFB One s.r.l. Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 13Art. 157 | €90,000 |
| 2023-09-14 | Intesa Sanpaolo Spa Insufficient fulfilment of data subjects rights | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 15 | €42,000 |
| 2023-09-14 | Betting company Insufficient legal basis for data processing | 🇪🇺 Croatian Data Protection Authority (azop) | Art. 6Art. 7Art. 13 | €30,000 |
| 2023-09-14 | Betting company Insufficient legal basis for data processing | 🇪🇺 Croatian Data Protection Authority (azop) | Art. 6Art. 7Art. 13 | €20,000 |
| 2023-09-14 | Shardana Working Soc. Coop. a r.l. Insufficient fulfilment of data subjects rights | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 12Art. 15 | €20,000 |
| 2023-09-14 | Azienda Sanitaria dell'Alto Adige - Suedtiroler Sanitaetsbetrieb Insufficient fulfilment of data subjects rights | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 12 | €10,000 |
| 2023-09-14 | San Severo municipality Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 2 | €10,000 |
| 2023-09-14 | Nimbus s.r.l. Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 9Art. 13 | €5,000 |
| 2023-09-13 | Zagreb Holding d.o.o. Insufficient fulfilment of information obligations | 🇪🇺 Croatian Data Protection Authority (azop) | Art. 13Art. 25 | €25,000 |
| 2023-09-11 | Suomen Yritysrekisteri Insufficient fulfilment of data subjects rights | 🇪🇺 Deputy Data Protection Ombudsman | Art. 12Art. 15 | €23,000 |
| 2023-09-07 | SUMINISTRADOR IBÉRICO DE ENERGÍA, S.L. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €70,000 |
| 2023-09-06 | University of Iceland Insufficient fulfilment of information obligations | 🇪🇺 Icelandic data protection authority ('Persónuvernd') | Art. 5Art. 12Art. 13 | €10,300 |
| 2023-09-05 | Vodafone España, S.A.U. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €80,000 |
| 2023-09-04 | Company Insufficient fulfilment of data subjects rights | 🇪🇺 Deputy Data Protection Ombudsman | Art. 12Art. 15 | €1,600 |
| 2023-09-01 | TikTok Limited Non-compliance with general data processing principles | 🇪🇺 Data Protection Authority of Ireland | Art. 5Art. 12Art. 13Art. 24 | €345,000,000 |
| 2023-09-01 | Private individual Insufficient fulfilment of information obligations | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 13 | €300 |
| 2023-08-31 | Robin Srl Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 137Art. 139Art. 6 | €25,000 |
| 2023-08-31 | Bar association Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 2 | €20,000 |
| 2023-08-31 | Mednow Medical Center di Giugni Marco Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 9Art. 12Art. 15 | €10,000 |
| 2023-08-31 | RCS Mediagroup Spa Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 2Art. 137Art. 139 | €10,000 |
| 2023-08-31 | Legal Person Insufficient fulfilment of data subjects rights | 🇪🇺 Czech Data Protection Auhtority (UOOU) | Art. 12 | €1,600 |
| 2023-08-30 | GENERAL LOGISTICS SYSTEMS SPAIN, S.A. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €140,000 |
| 2023-08-30 | POLAND DPA: Insufficient cooperation with supervisory authority Insufficient cooperation with supervisory authority | 🇪🇺 Polish National Personal Data Protection Office (UODO) | Art. 58 | €13,000 |