Skip to content

GDPR enforcement in 2024

318 decisions · €148.0M total fines · ← 2023 · 2025 →

Date ↓ Company / party Authority Articles Fine
2024-09-12 Sky Italia S.r.l.
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 130 €842,062
2024-09-12 CEGEDIM SANTÉ
Non-compliance with general data processing principles
🇪🇺 French Data Protection Authority (CNIL) Art. 5Art. 66 €800,000
2024-09-12 Top Quality Corporation s.r.l.s.
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 12Art. 15 €5,000
2024-09-12 Private individual
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6 €400
2024-09-11 KVIKU SPAIN, S.L
Insufficient cooperation with supervisory authority
🇪🇺 Spanish Data Protection Authority (aepd) Art. 58 €600
2024-09-06 Eidskog municipality
Insufficient legal basis for data processing
🇪🇺 Norwegian Supervisory Authority (Datatilsynet) Art. 6 €20,900
2024-09-05 PLAY FUL KIDS, S.L.
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 6 €3,000
2024-09-04 University of Agder
Insufficient technical and organisational measures to ensure information security
🇪🇺 Norwegian Supervisory Authority (Datatilsynet) Art. 32Art. 24 €12,700
2024-09-04 Senira Limited
Insufficient cooperation with supervisory authority
🇪🇺 Cypriot Data Protection Commissioner Art. 31 €3,000
2024-09-02 National Prosecutor's Office
Insufficient legal basis for data processing
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 6Art. 9Art. 33Art. 34 €19,800
2024-08-30 POLAND DPA: Insufficient cooperation with supervisory authority
Insufficient cooperation with supervisory authority
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 31Art. 58 €4,500
2024-08-29 Apoteket AB.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) Art. 32 €3,200,000
2024-08-29 Apohem AB
Insufficient technical and organisational measures to ensure information security
🇪🇺 Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) Art. 32 €698,000
2024-08-22 SANTANDER CONSUMER FINANCE, S.A.
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 6 €50,000
2024-08-20 mBank
Insufficient fulfilment of data breach notification obligations
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 34 €940,000
2024-08-20 Ana Hotels SRL
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €8,000
2024-08-16 IKEA
Insufficient legal basis for data processing
🇪🇺 Austrian Data Protection Authority (dsb) Art. 5Art. 6 €1,500,000
2024-08-16 Company
Unknown
🇪🇺 Austrian Data Protection Authority (dsb) €1,500,000
2024-08-14 Municipality of Vejen
Insufficient technical and organisational measures to ensure information security
🇪🇺 Danish Data Protection Authority (Datatilsynet) €26,800
2024-08-12 UNIQLO EUROPE, LTD, SUCURSAL EN ESPAÑA
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 32 €270,000
2024-08-06 LOCAL VERTICALS, S.L.
Insufficient fulfilment of information obligations
🇪🇺 Spanish Data Protection Authority (aepd) Art. 13 €10,000
2024-08-06 Private individual
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 6 €2,000
2024-08-06 Private individual
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 6 €1,000
2024-08-06 BEST ELAN ONLINE SRL
Insufficient cooperation with supervisory authority
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 58 €1,000
2024-07-22 Municipality of Korou
Insufficient involvement of data protection officer
🇪🇺 French Data Protection Authority (CNIL) Art. 31Art. 37 €6,900