Skip to content

Article 35 GDPR — enforcement

Cited in 88 decisions · €509.0M total fines · median €55,000 · top authority: 🇪🇺Italian Data Protection Authority (Garante) (31)

Date ↓ Company / party Authority Articles Fine
2022-12-15 Azienda Universitaria Giuliano Isontina
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 14Art. 35 €55,000
2022-11-10 DISCORD INC.
Non-compliance with general data processing principles
🇪🇺 French Data Protection Authority (CNIL) Art. 5Art. 13Art. 25Art. 32 €800,000
2022-11-02 Portuguese National Statistical Institute
Non-compliance with general data processing principles
🇪🇺 Portuguese Data Protection Authority (CNPD) Art. 5Art. 9Art. 12Art. 13 €4,300,000
2022-10-06 Alpha Exploration
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 7Art. 12 €2,000,000
2022-09-05 Meta Platforms, Inc.
Non-compliance with general data processing principles
🇪🇺 Data Protection Authority of Ireland Art. 5Art. 6Art. 12Art. 24 €405,000,000
2022-08-19 Medical laboratory
Insufficient technical and organisational measures to ensure information security
🇪🇺 Belgian Data Protection Authority (APD) Art. 5Art. 12Art. 13Art. 14 €20,000
2022-07-26 Volkswagen
Insufficient fulfilment of information obligations
🇪🇺 Data Protection Authority of Niedersachsen Art. 13Art. 28Art. 30Art. 35 €1,100,000
2022-05-18 Clearview Al Inc.
Non-compliance with general data processing principles
🇪🇺 Information Commissioner (ICO) Art. 5Art. 6Art. 9Art. 14 €9,000,000
2022-04-28 Tarento municipality
Insufficient fulfilment of information obligations
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 12Art. 13Art. 14 €150,000
2022-04-07 Dutch Tax and Customs Administration
Non-compliance with general data processing principles
🇪🇺 Dutch Supervisory Authority for Data Protection (AP) Art. 5Art. 6Art. 32Art. 35 €3,700,000
2022-04-07 Azienda ospedaliera di Perugia
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 13Art. 14Art. 25 €40,000
2022-04-04 Brussels Airport Zaventem
Insufficient legal basis for data processing
🇪🇺 Belgian Data Protection Authority (APD) Art. 5Art. 6Art. 9Art. 12 €200,000
2022-04-04 Brussels Airport Charleroi
Insufficient legal basis for data processing
🇪🇺 Belgian Data Protection Authority (APD) Art. 5Art. 6Art. 9Art. 12 €100,000
2022-01-27 Cosmote Mobile Telecommunications S.A.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Hellenic Data Protection Authority (HDPA) Art. 5Art. 13Art. 14Art. 25 €6,000,000
2022-01-27 EU DisinfoLab
Non-compliance with general data processing principles
🇪🇺 Belgian Data Protection Authority (APD) Art. 5Art. 6Art. 9Art. 12 €2,800
2022-01-13 Azienda sanitaria unica regionale Marche
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 32Art. 35 €14,000
2021-12-21 Lisbon City Council
Insufficient legal basis for data processing
🇪🇺 Portuguese Data Protection Authority (CNPD) Art. 5Art. 6Art. 9Art. 13 €1,250,000
2021-10-26 SERVICIOS LOGÍSTICOS MARTORELL SIGLO XXI, S.L.
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 35 €16,000
2021-09-16 Bocconi University
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 13 €200,000
2021-09-16 Ciechi Ardizzone Gioeni di Catania
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 12Art. 13Art. 35 €5,000
2021-07-26 Mercadona S.A.
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 6Art. 9Art. 12 €2,520,000
2021-07-22 Deliveroo Italy s.r.l.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 13Art. 22Art. 25 €2,500,000
2021-06-21 UAB VS FITNESS
Non-compliance with general data processing principles
🇪🇺 Lithuanian Data Protection Authority (VDAI) Art. 5Art. 9Art. 13Art. 30 €20,000
2021-06-10 Foodinho s.r.l.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 13Art. 22Art. 25 €2,600,000
2021-05-13 Comune di Bolzano
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 13 €84,000