GDPR enforcement in 2024
318 decisions · €148.0M total fines · ← 2023 · 2025 →
| Date ↓ | Company / party | Authority | Articles | Fine |
|---|---|---|---|---|
| 2024-10-22 | IBERCAJA BANCO, S.A. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €180,000 |
| 2024-10-21 | Grue municipality Insufficient technical and organisational measures to ensure information security | 🇪🇺 Norwegian Supervisory Authority (Datatilsynet) | Art. 24Art. 32 | €20,800 |
| 2024-10-18 | VODAFONE ESPAÑA, S.A.U. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €200,000 |
| 2024-10-18 | Vilnius District Municipality Administration Insufficient technical and organisational measures to ensure information security | 🇪🇺 Lithuanian Data Protection Authority (VDAI) | Art. 5Art. 32Art. 34 | €9,000 |
| 2024-10-18 | POLAND DPA: Insufficient involvement of data protection officer Insufficient involvement of data protection officer | 🇪🇺 Polish National Personal Data Protection Office (UODO) | Art. 37 | €5,800 |
| 2024-10-17 | KUR KLINIKUM, S.L. Insufficient cooperation with supervisory authority | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 58 | €1,000 |
| 2024-10-16 | Company Lack of appointment of data protection officer | 🇪🇺 Austrian Data Protection Authority (dsb) | Art. 38 | €5,000 |
| 2024-10-16 | Your Consulting SRL Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 25Art. 32 | €3,000 |
| 2024-10-04 | ROCA & ASOCIADOS ABOGADOS Y ECONOMISTAS, S.L.P. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €5,000 |
| 2024-10-04 | Private individual Insufficient cooperation with supervisory authority | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 58 | €900 |
| 2024-10-04 | VOLTIUM CONSULTORES 2020 Insufficient cooperation with supervisory authority | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 58 | €600 |
| 2024-09-26 | TELEFÓNICA DE ESPAÑA SAU Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5 | €1,300,000 |
| 2024-09-26 | Police Service of Northern Ireland Insufficient technical and organisational measures to ensure information security | 🇪🇺 Information Commissioner (ICO) | Art. 5Art. 32 | €904,000 |
| 2024-09-26 | COSMOSPACE Non-compliance with general data processing principles | 🇪🇺 French Data Protection Authority (CNIL) | Art. 5Art. 9 | €250,000 |
| 2024-09-26 | TELEMAQUE Non-compliance with general data processing principles | 🇪🇺 French Data Protection Authority (CNIL) | Art. 5Art. 9 | €150,000 |
| 2024-09-26 | CI & DI Food s.r.l. Insufficient fulfilment of data subjects rights | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 12Art. 15 | €4,000 |
| 2024-09-23 | PPC ENERGIE MUNTENIA S.A. Insufficient fulfilment of data subjects rights | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 12Art. 17 | €2,000 |
| 2024-09-23 | Attorney Insufficient fulfilment of data subjects rights | 🇪🇺 Hellenic Data Protection Authority (HDPA) | Art. 12Art. 31 | €1,400 |
| 2024-09-23 | SERVICIOS INMOBILIARIOS Y GESTIÓN RCL-MADRID, S.L. Insufficient cooperation with supervisory authority | 🇪🇸 Spanish Data Protection Authority (aepd) | Art. 58 | €600 |
| 2024-09-17 | Constanța South Container Terminal SRL Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €3,000 |
| 2024-09-16 | Vodafone România SA Insufficient fulfilment of data subjects rights | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 12Art. 15Art. 17 | €3,000 |
| 2024-09-16 | SC Class IT Outsourcing SRL Insufficient fulfilment of data subjects rights | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 12Art. 17 | €1,000 |
| 2024-09-13 | Hospital Insufficient technical and organisational measures to ensure information security | 🇪🇺 Croatian Data Protection Authority (azop) | Art. 5Art. 6Art. 12Art. 13 | €190,000 |
| 2024-09-13 | Hotel Unknown | 🇪🇺 Croatian Data Protection Authority (azop) | €45,000 | |
| 2024-09-13 | Company Unknown | 🇪🇺 Croatian Data Protection Authority (azop) | €35,700 |