Skip to content

Article 12 GDPR — enforcement

Cited in 425 decisions · €1.2B total fines · median €10,000 · top authority: 🇪🇺Italian Data Protection Authority (Garante) (155)

Date ↓ Company / party Authority Articles Fine
2022-11-10 Vodafone Italia S.p.A.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 7Art. 12 €500,000
2022-11-10 Cisterna di Latina Municipality
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 12Art. 37 €5,000
2022-11-10 Cisterna di Latina municipality
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 12Art. 37 €5,000
2022-11-03 Burwebs S.L.
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 12Art. 13Art. 25 €75,000
2022-11-02 Portuguese National Statistical Institute
Non-compliance with general data processing principles
🇪🇺 Portuguese Data Protection Authority (CNPD) Art. 5Art. 9Art. 12Art. 13 €4,300,000
2022-10-31 TECHPUMP SOLUTIONS S.L.
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 6Art. 8Art. 12 €525,000
2022-10-20 Douglas Italia S.p.a.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 7Art. 12 €1,400,000
2022-10-20 Comune di Salento
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 12Art. 13 €12,000
2022-10-17 Clearview Al Inc.
Insufficient fulfilment of data subjects rights
🇪🇺 French Data Protection Authority (CNIL) Art. 6Art. 12Art. 15Art. 17 €20,000,000
2022-10-06 Alpha Exploration
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 7Art. 12 €2,000,000
2022-10-06 Codess Sociale, Soc. Coop. sociale.
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 12Art. 17 €10,000
2022-10-06 Poste Italiane S.p.a.
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 12 €10,000
2022-10-06 Associazione Rescue Drones Network ODV
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 12Art. 15 €3,000
2022-10-05 Bank
Insufficient legal basis for data processing
🇪🇺 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) Art. 5Art. 6Art. 12 €72,500
2022-09-26 TV2 Média Csoport Zrt.
Non-compliance with general data processing principles
🇪🇺 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) Art. 5Art. 6Art. 12Art. 13 €26,700
2022-09-25 Health insurance provider
Non-compliance with general data processing principles
🇪🇺 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) Art. 5Art. 12Art. 31 €1,200
2022-09-22 Gas station
Insufficient fulfilment of data subjects rights
🇪🇺 Hellenic Data Protection Authority (HDPA) Art. 12Art. 14 €3,000
2022-09-15 Lazio Region
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 12 €100,000
2022-09-15 FCA Italy S.p.A.
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 12Art. 15 €40,000
2022-09-15 Bper Banca S.p.A.
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 12 €10,000
2022-09-12 Coin dealer
Non-compliance with general data processing principles
🇪🇺 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) Art. 5Art. 6Art. 7Art. 12 €80,700
2022-09-09 School
Non-compliance with general data processing principles
🇪🇺 Hellenic Data Protection Authority (HDPA) Art. 5Art. 6Art. 12Art. 13 €15,000
2022-09-05 Meta Platforms, Inc.
Non-compliance with general data processing principles
🇪🇺 Data Protection Authority of Ireland Art. 5Art. 6Art. 12Art. 24 €405,000,000
2022-08-19 ACCOR SA
Insufficient fulfilment of data subjects rights
🇪🇺 French Data Protection Authority (CNIL) Art. 12Art. 13Art. 15Art. 21 €600,000
2022-08-19 Medical laboratory
Insufficient technical and organisational measures to ensure information security
🇪🇺 Belgian Data Protection Authority (APD) Art. 5Art. 12Art. 13Art. 14 €20,000