GDPR enforcement in 2024
318 decisions · €148.0M total fines · ← 2023 · 2025 →
| Date ↓ | Company / party | Authority | Articles | Fine |
|---|---|---|---|---|
| 2024-09-12 | Sky Italia S.r.l. Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 130 | €842,062 |
| 2024-09-12 | CEGEDIM SANTÉ Non-compliance with general data processing principles | 🇪🇺 French Data Protection Authority (CNIL) | Art. 5Art. 66 | €800,000 |
| 2024-09-12 | Top Quality Corporation s.r.l.s. Insufficient fulfilment of data subjects rights | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 12Art. 15 | €5,000 |
| 2024-09-12 | Private individual Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6 | €400 |
| 2024-09-11 | KVIKU SPAIN, S.L Insufficient cooperation with supervisory authority | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 58 | €600 |
| 2024-09-06 | Eidskog municipality Insufficient legal basis for data processing | 🇪🇺 Norwegian Supervisory Authority (Datatilsynet) | Art. 6 | €20,900 |
| 2024-09-05 | PLAY FUL KIDS, S.L. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €3,000 |
| 2024-09-04 | University of Agder Insufficient technical and organisational measures to ensure information security | 🇪🇺 Norwegian Supervisory Authority (Datatilsynet) | Art. 32Art. 24 | €12,700 |
| 2024-09-04 | Senira Limited Insufficient cooperation with supervisory authority | 🇪🇺 Cypriot Data Protection Commissioner | Art. 31 | €3,000 |
| 2024-09-02 | National Prosecutor's Office Insufficient legal basis for data processing | 🇪🇺 Polish National Personal Data Protection Office (UODO) | Art. 6Art. 9Art. 33Art. 34 | €19,800 |
| 2024-08-30 | POLAND DPA: Insufficient cooperation with supervisory authority Insufficient cooperation with supervisory authority | 🇪🇺 Polish National Personal Data Protection Office (UODO) | Art. 31Art. 58 | €4,500 |
| 2024-08-29 | Apoteket AB. Insufficient technical and organisational measures to ensure information security | 🇪🇺 Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) | Art. 32 | €3,200,000 |
| 2024-08-29 | Apohem AB Insufficient technical and organisational measures to ensure information security | 🇪🇺 Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) | Art. 32 | €698,000 |
| 2024-08-22 | SANTANDER CONSUMER FINANCE, S.A. Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €50,000 |
| 2024-08-20 | mBank Insufficient fulfilment of data breach notification obligations | 🇪🇺 Polish National Personal Data Protection Office (UODO) | Art. 34 | €940,000 |
| 2024-08-20 | Ana Hotels SRL Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €8,000 |
| 2024-08-16 | IKEA Insufficient legal basis for data processing | 🇪🇺 Austrian Data Protection Authority (dsb) | Art. 5Art. 6 | €1,500,000 |
| 2024-08-16 | Company Unknown | 🇪🇺 Austrian Data Protection Authority (dsb) | €1,500,000 | |
| 2024-08-14 | Municipality of Vejen Insufficient technical and organisational measures to ensure information security | 🇪🇺 Danish Data Protection Authority (Datatilsynet) | €26,800 | |
| 2024-08-12 | UNIQLO EUROPE, LTD, SUCURSAL EN ESPAÑA Non-compliance with general data processing principles | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 32 | €270,000 |
| 2024-08-06 | LOCAL VERTICALS, S.L. Insufficient fulfilment of information obligations | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 13 | €10,000 |
| 2024-08-06 | Private individual Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €2,000 |
| 2024-08-06 | Private individual Insufficient legal basis for data processing | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6 | €1,000 |
| 2024-08-06 | BEST ELAN ONLINE SRL Insufficient cooperation with supervisory authority | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 58 | €1,000 |
| 2024-07-22 | Municipality of Korou Insufficient involvement of data protection officer | 🇪🇺 French Data Protection Authority (CNIL) | Art. 31Art. 37 | €6,900 |