Skip to content

Article 9 GDPR — enforcement

Cited in 233 decisions · €44.1M total fines · median €15,000 · top authority: 🇪🇺Italian Data Protection Authority (Garante) (121)

Date ↓ Company / party Authority Articles Fine
2025-12-04 Roverbella Comprehensive School
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9 €1,000
2025-12-04 'Principe Umberto di Savoia' State Scientific and Linguistic High School
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 13 €1,000
2025-11-21 IDCQ HOSPITALES Y SANIDAD, S.L.U.
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 6Art. 9Art. 25 €1,200,000
2025-10-23 Mayor of the Municipality of Calvi Risorta
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9 €1,000
2025-10-23 Mayor of the Municipality of Calvi Risorta
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9 €1,000
2025-09-11 Ministry of the Interior - Department of Firefighters, Public Rescue, and Civil Defense - Provincial Command of Florence
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9 €12,000
2025-09-11 Ministry of the Interior - Department of Firefighters, Public Rescue, and Civil Defense - Provincial Command of Florence
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9 €12,000
2025-09-11 Casa di Cura Città di Roma
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 25Art. 32 €12,000
2025-09-11 Casa di Cura Città di Roma
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 25Art. 32 €12,000
2025-09-11 Municipality of Buccino
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 13 €6,000
2025-09-11 Municipality of Buccino
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 13 €6,000
2025-08-04 Ospedaliero-Universitaria Careggi
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 25Art. 32 €80,000
2025-08-04 Ospedaliero-Universitaria Careggi
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 25Art. 32 €80,000
2025-07-23 SATI S.p.A.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9 €10,000
2025-07-23 SATI S.p.A.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9 €10,000
2025-07-22 Legal Entity
Insufficient legal basis for data processing
🇪🇺 Slovenian Supervisory Authority (Informacijski pooblaščenec) Art. 6Art. 9 €2,200
2025-07-10 Magna PT S.p.A.
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 13 €50,000
2025-07-10 Magna PT S.p.A.
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 13 €50,000
2025-07-10 Istituto Comprensivo 2 C.D. “G. Modugno” S.M. “G. Galilei” di Monopoli
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9 €4,000
2025-07-10 Istituto Comprensivo 2 C.D. “G. Modugno” S.M. “G. Galilei” di Monopoli
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9 €4,000
2025-06-26 SIDECU, S.A.
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 9Art. 13Art. 35 €96,000
2025-06-26 SIDECU, S.A.
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 9Art. 13Art. 35 €96,000
2025-06-18 Waxholms Ångfartygs AB
Insufficient legal basis for data processing
🇪🇺 Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) Art. 6Art. 9 €6,800
2025-06-18 Waxholms Ångfartygs AB
Insufficient legal basis for data processing
🇪🇺 Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) Art. 6Art. 9 €6,800
2025-06-18 AB Storstockholms Lokaltrafik
Insufficient legal basis for data processing
🇪🇺 Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) Art. 6Art. 9 €6,800