Skip to content

Article 9 GDPR — enforcement

Cited in 233 decisions · €44.1M total fines · median €15,000 · top authority: 🇪🇺Italian Data Protection Authority (Garante) (121)

Date ↓ Company / party Authority Articles Fine
2025-06-18 AB Storstockholms Lokaltrafik
Insufficient legal basis for data processing
🇪🇺 Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) Art. 6Art. 9 €6,800
2025-06-12 Departement of Social Security
Insufficient legal basis for data processing
🇪🇺 Data Protection Authority of Ireland Art. 5Art. 6Art. 9Art. 13 €550,000
2025-06-12 Departement of Social Security
Insufficient legal basis for data processing
🇪🇺 Data Protection Authority of Ireland Art. 5Art. 6Art. 9Art. 13 €550,000
2025-05-21 Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9 €7,000
2025-05-21 Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9 €7,000
2025-04-29 Municipality of Bologna
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9 €40,000
2025-04-29 Municipality of Bologna
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9 €40,000
2025-04-24 ULPIA TRAJANA ALAMEDA S.L.
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 9 €1,500
2025-04-24 ULPIA TRAJANA ALAMEDA S.L.
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 9 €1,500
2025-03-27 Istituto di Istruzione Superiore 'P. Galluppi' Tropea
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9 €4,000
2025-03-27 Istituto di Istruzione Superiore 'P. Galluppi' Tropea
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9 €4,000
2025-03-24 Chief Commander of the Police
Insufficient legal basis for data processing
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 6Art. 9 €17,600
2025-02-17 Primary Health Care in the Capital Area
Insufficient legal basis for data processing
🇪🇺 Icelandic data protection authority ('Persónuvernd') Art. 5Art. 6Art. 9 €34,300
2025-02-17 Meedea Construct Prest SRL
Insufficient legal basis for data processing
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 5Art. 6Art. 9 €2,000
2025-01-16 San Pio Hospital in Benevento
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9 €6,000
2024-12-12 Physician
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 2 €20,000
2024-11-13 Foodinho Srl
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 12 €5,000,000
2024-09-26 COSMOSPACE
Non-compliance with general data processing principles
🇪🇺 French Data Protection Authority (CNIL) Art. 5Art. 9 €250,000
2024-09-26 TELEMAQUE
Non-compliance with general data processing principles
🇪🇺 French Data Protection Authority (CNIL) Art. 5Art. 9 €150,000
2024-09-02 National Prosecutor's Office
Insufficient legal basis for data processing
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 6Art. 9Art. 33Art. 34 €19,800
2024-07-05 Clinic owner
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 6Art. 9 €10,000
2024-06-06 Cappello Giovanni & Figli s.r.l.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 13 €120,000
2024-06-06 Covid 19 Test Lab
Insufficient technical and organisational measures to ensure information security
🇪🇺 Austrian Data Protection Authority (dsb) Art. 9Art. 5Art. 28Art. 32 €100,000
2024-06-06 Comune di Ustica
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 37 €500
2024-05-31 GSMA Limited
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 6Art. 9Art. 14 €600,000