Skip to content

Article 9 GDPR — enforcement

Cited in 233 decisions · €44.1M total fines · median €15,000 · top authority: 🇪🇺Italian Data Protection Authority (Garante) (121)

Date ↓ Company / party Authority Articles Fine
2023-06-27 eCommerce 2020 ApS
Insufficient legal basis for data processing
🇪🇺 Icelandic data protection authority ('Persónuvernd') Art. 5Art. 6Art. 8Art. 9 €51,000
2023-06-27 Almennri innheimtu ehf
Insufficient legal basis for data processing
🇪🇺 Icelandic data protection authority ('Persónuvernd') Art. 5Art. 6Art. 8Art. 9 €24,000
2023-06-16 Irish Departement of Health
Non-compliance with general data processing principles
🇪🇺 Data Protection Authority of Ireland Art. 5Art. 6Art. 9 €22,500
2023-06-08 KG COM
Non-compliance with general data processing principles
🇪🇺 French Data Protection Authority (CNIL) Art. 5Art. 6Art. 9Art. 12 €150,000
2023-06-07 Azienda Tutela della Salute della Sardegna
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 2 €5,000
2023-06-01 Ew Business Machines S.p.A.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 13Art. 114 €20,000
2023-06-01 Azienda Usl Toscana Sud Est.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 25Art. 2 €20,000
2023-06-01 Thin Srl
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 13 €15,000
2023-06-01 Camedi s.r.l.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 32 €10,000
2023-04-27 Roma Capitale
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 28Art. 29 €176,000
2023-04-27 Ufficio Scolastico Regionale per la Puglia, Ufficio VI - Ambito Territoriale di Lecce
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 2 €15,000
2023-04-14 Citynews S.p.A.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9 €15,000
2023-04-13 Azienda socio sanitaria locale n. 3 di Nuoro
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 2 €13,000
2023-04-13 Comune di Cogollo del Cengio
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 2 €3,000
2023-04-04 Real Federación Española de Tenis de Mesa
Insufficient fulfilment of information obligations
🇪🇺 Spanish Data Protection Authority (aepd) Art. 9 €10,000
2023-03-23 Azienda socio-sanitaria locale n. 1 di Sassari
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 32 €4,000
2023-03-02 Azienda sanitaria locale di Bari
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 25 €50,000
2023-02-06 I&S Limited Kft
Non-compliance with general data processing principles
🇪🇺 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) Art. 5Art. 6Art. 9Art. 13 €80,500
2023-01-31 Dentist
Insufficient legal basis for data processing
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 6Art. 9 €1,000
2023-01-26 Azienda ULSS n.5 Polesana
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 32 €5,000
2023-01-16 Thomas International Systems, S.A.
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 9 €40,000
2023-01-11 Ufficio Scolastico Regionale per la Lombardia, Ufficio IV - Ambito Territoriale di Brescia
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 2 €6,000
2023-01-11 Azienda Ospedale-Università Padova
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9 €5,000
2023-01-09 Praktiškas UAB
Insufficient legal basis for data processing
🇪🇺 Lithuanian Data Protection Authority (VDAI) Art. 5Art. 9Art. 13Art. 30 €6,000
2023-01-01 Company
Insufficient technical and organisational measures to ensure information security
🇪🇺 Data Protection Authority of Hamburg Art. 9Art. 32 €75,000