High
Fine
In effect
Italy · Oct 9, 2026 · effective Jul 3, 2026
Italian DPA fines BBVA €5.508 million for ignoring customer objection to direct marketing
The Italian Data Protection Authority issued an administrative fine of €5,508,000 against BBVA's Italian branch for failing to honor a customer's right to object to direct marketing. The violation lasted seven months, during which the…
Italian Data Protection Authority · General Data Protection Regulation
High
Fine
Decided
Italy · Oct 9, 2026
Italian DPA fines Emirates €180,000 for health data infringements
The Italian Data Protection Authority imposed an administrative fine of EUR 180,000 on Emirates for violations of GDPR transparency and retention requirements concerning passengers' health data. Emirates was ordered to clarify which…
Italian Data Protection Authority · General Data Protection Regulation
High
Data protection authority action
Decided
Italy · Oct 9, 2026 · effective Sep 23, 2026
Italian DPA fines IQVIA €7 million for unlawful processing of patients’ health data
The Italian Data Protection Authority imposed an administrative fine of EUR 7,000,000 on IQVIA Solutions Italy S.r.l. for processing health data without a legal basis, inadequate information to patients, and missing DPIA and retention…
Italian Data Protection Authority · General Data Protection Regulation
Moderate
Fine
In effect
Italy · Oct 9, 2026 · effective Aug 6, 2026
Italian DPA fines security firm €39,000 for employee data violations
The Italian Data Protection Authority (Garante) imposed a total administrative fine of EUR 39,000 on La Patria S.p.A. for failing to respond to employee access requests and for inadequate information about GPS‑derived geolocation data. The…
Garante – Italian Data Protection Authority · General Data Protection Regulation
Moderate
Fine
Decided
Sweden · Oct 8, 2026
Swedish DPA fines Miljödata approx EUR 160,000 for insufficient security measures
The Swedish Data Protection Authority (IMY) imposed an administrative fine of SEK 1,800,000 (≈ EUR 160,000) on IT service provider Miljödata i Karlskrona for violating Article 32(1) GDPR. The authority found the company lacked adequate…
Swedish Data Protection Authority (IMY) · General Data Protection Regulation
High
Data protection authority action
Decided
Greece · Oct 8, 2026
Hellenic DPA fines Ministry and EETAA for data breach
The Hellenic Data Protection Authority issued a final decision on 28/07/2026 imposing administrative fines of EUR 200,000 on the Ministry of Social Cohesion and Family Affairs and EUR 150,000 on E.E.T.A.A. S.A. for security deficiencies.…
Hellenic Data Protection Authority · General Data Protection Regulation
High
Fine
Published
Netherlands · Oct 8, 2026
Dutch DPA fines Uber €824.99 million for unlawful automated decision‑making
The Autoriteit Persoonsgegevens imposed an administrative fine of €824,990,000 on Uber for violating GDPR Article 22 by automatically deactivating drivers’ accounts and for failing to provide sufficient information under Article 13. The…
Autoriteit Persoonsgegevens · General Data Protection Regulation
Low
Guidance
Published
European Union · Oct 2, 2026
EDPB adopts Guidelines 04/2026 on GDPR fines and corrective powers for public consultation
The European Data Protection Board adopted Guidelines 04/2026 on the application of administrative fines and other corrective powers under the EU GDPR. The guidelines were released on September 17, 2026 for public consultation.
European Data Protection Board · General Data Protection Regulation
High
Fine
Decided
Ireland · Sep 23, 2026 · effective Sep 21, 2026
Irish Data Protection Commission fines Google €403 million for GDPR violations over location data
The Irish Data Protection Commission issued its final decision on 21 September 2026, imposing administrative fines of €403 million on Google Ireland Limited. The DPC found infringements of GDPR principles relating to lawfulness, fairness…
Irish Data Protection Commission · General Data Protection Regulation
Moderate
Fine
Decided
Spain · Sep 22, 2026 · effective Feb 1, 2023 · deadline Feb 1, 2024
Spanish DPA fines Securitas Direct €100,000 for charging phone line for data subject rights
The Spanish Data Protection Agency (AEPD) issued a final decision on 1 February 2023 finding Securitas Direct in breach of GDPR Article 12(2) by directing data subjects to a chargeable 902 telephone number to exercise their rights. The…
Spanish Data Protection Agency (AEPD) · General Data Protection Regulation
Moderate
Proposed regulation
Proposed
European Union · Sep 21, 2026
EU proposes Article 88c/88bis to allow unrestricted AI use of personal data
A leaked Irish Presidency document proposes that personal data used "in the context of AI" be automatically lawful, removing consent requirements. The draft Article 88c (now 88bis) would permit AI companies to process any personal data for…
European Commission · General Data Protection Regulation
Moderate
Guidance
Published
KE · Sep 16, 2026
Kenya publishes new guidance on cross‑border data transfers
On 8 September 2026 Kenya’s Office of the Data Protection Commissioner released detailed Guidance Notes on cross‑border data transfers. The guidance clarifies Kenya’s transfer framework, adds operational detail, and highlights differences…
Office of the Data Protection Commissioner (ODPC) · General Data Protection Regulation
High
Fine
Decided
France · Sep 11, 2026 · effective Jul 21, 2026
CNIL fines French IT firm EXTIA €300,000 for failing to honor data erasure requests
In 2024 EXTIA received 265 requests for erasure, many of which were not processed or not communicated to the requesters. The CNIL audit found breaches of Articles 12 and 17 GDPR regarding transparency and the right to erasure. The CNIL…
CNIL · General Data Protection Regulation
Moderate
Fine
Announced
Netherlands · Sep 10, 2026
Dutch DPA fines Uber €824,990,000 for automated decisions affecting drivers
On August 21, 2026, the Dutch Data Protection Authority announced it had fined Uber €824,990,000 for breaching the EU GDPR rules on solely automated decision‑making. The fine targets Uber's use of automated systems that affect driver…
Dutch Data Protection Authority · General Data Protection Regulation
High
Enforcement
Decided
Ireland · Sep 3, 2026 · effective Aug 28, 2026
Data Protection Commission issues €645,000 fine and compliance orders against HSE
The Irish Data Protection Commission issued a final decision on 28 August 2026 concerning the Health Service Executive's handling of paper medical records. The DPC found physical security and integrity failures at external storage…
Data Protection Commission · General Data Protection Regulation
Moderate
Proposed regulation
Announced
France · Sep 3, 2026
CNIL agenda includes review of draft decrees on automated personal data processing and authorizations for health data studies
The CNIL plenary session agenda for 3 September 2026 lists examinations of draft deliberations on a decree modifying decree n° 2023‑935 for the SISPoPP system, a draft decree on the API‑PNR France system, and authorizations for RCTs, IQVIA…
Commission nationale de l'informatique et des libertés (CNIL) · General Data Protection Regulation
Moderate
Court ruling
Decided
Austria · Sep 1, 2026
Austrian Supreme Court rules CRIF’s use of address‑publisher data for credit scoring violates GDPR purpose limitation
The Austrian Supreme Court (OGH) held that credit reference agencies may not collect personal data from address publishers that process the data for marketing purposes, confirming a GDPR purpose‑limitation breach. The ruling supports…
EDPB · General Data Protection Regulation
Low
Enforcement
Announced
Germany · Aug 26, 2026 · effective Aug 26, 2026
noyb sends cease‑and‑desist letter to SCHUFA over alleged ‘shadow database’ GDPR violations
In July 2026, the NGO noyb issued a cease‑and‑desist letter to German credit agency SCHUFA demanding it stop storing data beyond retention periods and provide full historical data under Article 15 GDPR. The organization warned it will seek…
EDPB · General Data Protection Regulation
Moderate
Proposed bill
Announced
European Union · Aug 6, 2026
EU proposes Cloud and AI Development Act (CADA) to boost AI and cloud sovereignty
The European Commission released the Cloud and AI Development Act (CADA) proposal in June 2026, aiming to enhance EU competitiveness in AI and cloud technologies. The draft sets up Cloud and AI Leadership Initiatives, national AI…
European Commission · General Data Protection Regulation
Moderate
Proposed regulation
Announced
European Union · Jul 30, 2026
EDPB announces stakeholder event on upcoming data protection and competition law guidelines
The European Data Protection Board and the European Commission will hold a remote stakeholder event on 15 October 2026 to discuss upcoming guidelines on the interplay between data protection and competition law. The event aims to gather…
European Data Protection Board (EDPB) · General Data Protection Regulation
Low
Enforcement
Filed
Austria · Jul 30, 2026
noyb files GDPR complaint against dict.cc over 1,741‑partner consent banner
noyb lodged a complaint with the Austrian Data Protection Authority alleging that dict.cc’s cookie banner forces users to consent to tracking by 1,741 partner companies with a single click, violating GDPR consent requirements. The…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate
Guidance
Announced
European Union · Jul 23, 2026
EDPB announces stakeholder event on upcoming data protection and competition law guidelines (15 Oct 2026)
The European Data Protection Board and the European Commission will hold a remote stakeholder event on 15 October 2026 to discuss upcoming guidelines on the interplay between competition law and data protection. The event invites…
European Data Protection Board · General Data Protection Regulation
Moderate
Guidance
Announced
European Union · Jul 17, 2026
EDPB calls for legal basis for cross‑regulatory information sharing
The European Data Protection Board urged the European Commission to create a clear legal basis for regulators to share information across competences. It highlighted the need for stronger legislation to enable confidential information…
European Data Protection Board · General Data Protection Regulation
Moderate
Interpretation
Published
Belgium · Jul 14, 2026 · effective May 28, 2026
EDPB orders Belgian DPA to assess NOYB cookie banner complaint on merits
The European Data Protection Board issued a binding decision on 28 May 2026 requiring the Belgian DPA to evaluate a NOYB complaint about VRT's cookie banners on the merits rather than dismiss it on procedural grounds. The decision found no…
European Data Protection Board · General Data Protection Regulation
Moderate
Court ruling
Decided
United States (federal) · Jun 29, 2026
US Supreme Court decision undermines EU‑US Data Privacy Framework
The US Supreme Court ruled in Trump v. Slaughter that the FTC cannot be an independent agency. The decision calls into question the independence requirement for the EU‑US Data Privacy Framework, effectively collapsing the adequacy…
EDPB · General Data Protection Regulation
Moderate
Proposed regulation
Proposed
European Union · Jun 23, 2026
EU Council scrapes Article 88b proposal to replace cookie banners with automated signal
The European Commission proposed adding Article 88b to the GDPR to replace cookie banners with an automated consent signal. On 18 June, the Council’s position paper removed the article, keeping the existing cookie banner regime. The change…
European Commission · General Data Protection Regulation
Low
Enforcement
Filed
Austria · Jun 9, 2026
noyb files injunction against Austrian credit agency CRIF over GDPR violations
noyb, a state‑approved qualified entity, filed an injunction against CRIF to stop its alleged unlawful collection and scoring of personal data under the GDPR. The filing also suspends the limitation period and prepares a subsequent class…
EDPB · General Data Protection Regulation
Low
Investigation
Filed
Norway (EEA) · Jun 3, 2026
Norwegian Consumer Council and noyb file complaint against Schibsted over “Pay or Okay” tracking scheme
The Norwegian Consumer Council and privacy NGO noyb have lodged a joint complaint with the Norwegian Data Protection Authority against Schibsted for its “Pay or Okay” system that forces users to pay to refuse tracking. The complaint argues…
Norwegian Data Protection Authority · General Data Protection Regulation
Low
Court ruling
Decided
Austria · May 21, 2026
Austrian Federal Administrative Court orders ORF to redesign cookie banner for equal consent options
The Federal Administrative Court (BVwG) upheld the Austrian Data Protection Authority's 2024 decision that ORF.at's cookie banner violates the GDPR. The court ruled that the ‘Accept’ button must not be highlighted in colour and that…
EDPB · General Data Protection Regulation
Low
Enforcement
Filed
Austria · May 5, 2026
LinkedIn blocks GDPR access to profile visitor data behind paywall, noyb files complaint in Austria
LinkedIn requires users to pay to view who has visited their profile, despite the data being personal under the GDPR. noyb argues the data must be provided free of charge under Article 15 and has lodged a complaint with the Austrian Data…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate
Lawsuit filed
Filed
Germany · Apr 30, 2026
noyb files lawsuit against Hamburg DPA over inaction on PimEyes biometric data case
noyb has filed a lawsuit against the Hamburg Data Protection Authority, alleging that the authority has failed to act on illegal biometric data processing by PimEyes. The DPA considers PimEyes' facial recognition practices illegal but…
Hamburg Data Protection Authority · General Data Protection Regulation
Moderate
Proposed regulation
Proposed
European Union · Apr 16, 2026
EU Digital Omnibus proposal aims to limit GDPR right of access amid 83.5% non‑compliance
The European Commission’s Digital Omnibus proposal would restrict the GDPR right of access to “data protection purposes”, citing alleged abuse. NOYB’s analysis shows that 83.5% of access requests were not properly answered, with only 16.5%…
European Commission · General Data Protection Regulation
Moderate
Fine
In effect
France · Mar 13, 2026
French court upholds €40M GDPR fine against Criteo
The French Data Protection Authority (CNIL) fined Criteo €40 million for GDPR violations, including lack of valid consent, transparency, and failures to honor erasure and access rights. In March 2026, the Conseil d’État rejected Criteo’s…
CNIL · General Data Protection Regulation
Moderate
Proposed regulation
Published
European Union · Mar 5, 2026
EU Commission's Digital Omnibus proposal to limit GDPR Right of Access faces criticism from DPOs
The European Commission has published a Digital Omnibus proposal that would narrow the definition of personal data, restrict the Right of Access and allow broader AI training. A survey by noyb shows data protection officers consider the…
European Commission · General Data Protection Regulation
Moderate
Lawsuit filed
Filed
European Union · Jan 28, 2026
noyb debunks 5 GDPR misconceptions on Data Protection Day
The article clarifies that the GDPR does not mandate cookie banners, that DPAs rarely impose fines, and that companies must obtain explicit consent for tracking. It also explains the limited scope of the right of access and counters claims…
EDPB · General Data Protection Regulation
Low
Lawsuit filed
Filed
Germany · Jan 28, 2026
noyb files lawsuit against Hamburg DPA over Pay or Okay case involving SPIEGEL
In 2024, privacy advocacy group noyb sued the Hamburg Data Protection Authority concerning a Pay or Okay implementation dispute with the German news magazine SPIEGEL. The case highlights concerns about DPA impartiality and enforcement…
Hamburg Data Protection Authority · General Data Protection Regulation
Moderate
Data protection authority action
Decided
Austria · Jan 27, 2026
Austrian DSB orders Microsoft to stop tracking school children with cookies
The Austrian Data Protection Authority ruled that Microsoft illegally installed tracking cookies on a pupil's device without consent. The authority ordered Microsoft to cease the use of those cookies within four weeks. The decision follows…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low
Investigation
Announced
Austria · Jan 20, 2026
noyb investigation reveals Austrian credit agency CRIF uses public registers for mass address data collection
noyb’s investigation of CRIF shows that most address data comes from brokers who scrape public registers, violating GDPR purpose‑limitation. The Austrian DSB has already ruled that further processing for advertising breaches the GDPR.
Austrian Data Protection Authority · General Data Protection Regulation
Moderate
Court ruling
Decided
Austria · Dec 18, 2025 · deadline Dec 31, 2025
Austrian Supreme Court orders Meta to give users full data access within 14 days
The Austrian Supreme Court ruled that Meta must provide a complete copy of all personal data to any user request within 14 days, including source, recipient and purpose information. The court also required Meta to obtain explicit opt‑in…
EDPB · General Data Protection Regulation
Low
Enforcement
Filed
Austria · Dec 17, 2025
noyb files complaints against TikTok, AppsFlyer and Grindr with Austrian DSB over unlawful tracking
noyb has lodged two complaints with Austria's data protection authority alleging that TikTok tracks users across other apps and fails to provide a complete copy of personal data. The complaints also target AppsFlyer and Grindr for sharing…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate
Guidance
Announced
European Union · Dec 10, 2025
EU‑US data transfers face imminent risk as US legal changes could undermine TAFPF and SCCs
The blog notes that most EU‑US transfers rely on the Transatlantic Data Privacy Framework (TAFPF) or Standard Contract Clauses (SCCs), which depend on fragile US laws and executive orders. It warns that upcoming US Supreme Court decisions…
EDPB · General Data Protection Regulation
Moderate
Proposed regulation
Proposed
European Union · Nov 22, 2025
EU Commission proposes Digital Omnibus package with new personal data definition and research exemption
The European Commission has released the Digital Omnibus proposal, introducing a narrower definition of personal data (Art. 4(1)), a broader research exemption (Arts. 4(38), 5(1)(b), 13, 89), and new AI‑related rules (Arts. 9(2)(k), 9(5)…
European Commission · General Data Protection Regulation
Moderate
Proposed regulation
Proposed
European Union · Nov 11, 2025
Open letter warns EU Commission's Digital Omnibus draft could deregulate GDPR
Noyb, EDRi and the Irish Council for Civil Liberties sent an open letter to the European Commission criticizing a draft Digital Omnibus that would amend core GDPR provisions. The draft proposes redefining personal data, weakening data…
European Commission · General Data Protection Regulation
Moderate
Enforcement
Filed
Austria · Oct 28, 2025
noyb files criminal complaint against Clearview AI in Austria
noyb filed a criminal complaint with Austrian public prosecutors against Clearview AI and its managers for alleged GDPR violations. The complaint relies on Article 84 GDPR and Austria's § 63 Data Protection Act, which allow criminal…
Austrian public prosecutors · General Data Protection Regulation
Moderate
Data protection authority action
Decided
Austria · Oct 9, 2025
Austrian DSB rules Microsoft 365 Education illegally tracks students and orders data deletion
The Austrian Data Protection Authority found Microsoft 365 Education used tracking cookies without consent and denied a data‑access request, violating GDPR. The DSB ordered Microsoft to delete the data, provide full access, and disclose…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low
Enforcement
Filed
Lithuania · Sep 29, 2025
noyb files complaint with Lithuanian DPA against Whitebridge AI for unlawful data processing
noyb has lodged a complaint with Lithuania's data protection authority alleging that Whitebridge AI unlawfully scrapes and sells AI‑generated reputation reports containing personal and sensitive data. The complaint cites violations of…
Lithuanian Data Protection Authority · General Data Protection Regulation
Moderate
Data protection authority action
Published
Austria · Sep 26, 2025
Austrian DSB bans KSV1870 from automated credit checks without consent
The Austrian Data Protection Authority ruled that KSV1870's fully automated credit rating was unlawful and prohibited the agency from conducting such checks without the data subject's consent. The authority also ordered KSV1870 to provide…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low
Investigation
Announced
Austria · Sep 25, 2025
noyb uncovers over 40,000 CRIF credit queries linking Austrian banks, telecoms and retailers
noyb obtained data requests from 2,440 individuals and analyzed more than 40,000 CRIF credit queries, finding that banks, telecoms and other firms provide personal address data to the credit agency. The analysis shows gender and geographic…
EDPB · General Data Protection Regulation
Moderate
Data protection authority action
Announced
Ireland · Sep 18, 2025
Former Meta lobbyist Niamh Sweeney appointed Irish DPC commissioner
Niamh Sweeney, a former senior Meta lobbyist, is set to join the Irish Data Protection Commission (DPC) as a commissioner in October. The DPC is the EU lead privacy regulator for major US tech firms. The appointment raises concerns about…
Irish Data Protection Commission · General Data Protection Regulation
Low
Enforcement
Announced
Austria · Sep 18, 2025
NGOs file EU Commission complaint over Austrian DPA budget cuts
The Austrian Data Protection Authority (DSB) announced further restrictions due to significant budget cuts. NGOs epicenter.works and noyb plan to file a complaint with the European Commission alleging violation of Article 52(4) GDPR. The…
European Commission · General Data Protection Regulation
Moderate
Data protection authority action
Decided
Austria · Aug 29, 2025
Austrian DPA orders YouTube to comply with GDPR Article 15 access request
The Austrian Data Protection Authority issued a decision ordering YouTube (Google) to provide the complainant with full access to his personal data, including purpose, storage periods, recipients and tracking cookies, under Article 15…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate
Court ruling
Decided
Austria · Aug 18, 2025
Austrian Federal Administrative Court rules DerStandard's "pay or okay" consent model illegal
The Austrian Federal Administrative Court (BVwG) confirmed the Data Protection Authority's finding that DerStandard violated the GDPR by offering a "pay or okay" choice. The court held that the newspaper did not obtain valid, granular…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low
Enforcement
Announced
Germany · Aug 7, 2025
noyb sends cease‑and‑desist to Meta over AI training of EU users’ data
noyb commissioned a Gallup survey of 1,000 German Meta users, finding only 7% want their personal data used for AI training. Based on the results, noyb sent a cease‑and‑desist letter to Meta alleging GDPR violations and is assessing a…
EDPB · General Data Protection Regulation
Moderate
Court ruling
Decided
European Union · Jul 31, 2025
CJEU ruling C‑446/21 limits use of personal data for online advertising and repurposing publicly available data
The European Court of Justice issued ruling C‑446/21, fully backing a lawsuit against Meta's Facebook service. The court massively limits the use of personal data for online advertising and restricts the reuse of publicly available…
EDPB · General Data Protection Regulation
Moderate
Guidance
Announced
European Union · Jul 24, 2025
Report flags 'Pay or Okay' consent‑bypass systems as violating GDPR free‑consent requirement
The noyb report documents the spread of “Pay or Okay” systems across Europe, where users must pay to refuse tracking, resulting in near‑universal consent rates that breach the GDPR’s freely‑given consent standard. It cites a July 2023 CJEU…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate
Enforcement
Filed
European Union · Jul 17, 2025
noyb files GDPR complaints against TikTok, AliExpress and WeChat for denying data access
noyb has lodged complaints with the data protection authorities in Belgium, Greece and the Netherlands alleging that TikTok, AliExpress and WeChat violated Articles 12 and 15 of the GDPR by failing to provide full data access. The…
Data Protection Authorities (Belgium, Greece, Netherlands) · General Data Protection Regulation
Moderate
Data protection authority action
Decided
Ireland · Jul 16, 2025
DPC issues final decision reprimanding Children’s Health Ireland for GDPR security breaches
The Irish Data Protection Commission concluded that Children’s Health Ireland (CHI) at Tallaght University Hospital breached GDPR security and confidentiality obligations. CHI was reprimanded and ordered to bring its processing into…
Data Protection Commission (Ireland) · General Data Protection Regulation
Moderate
Data protection authority action
Filed
Austria · Jun 26, 2025
noyb files complaint against Bumble for unlawful AI Icebreakers in Austria
noyb lodged a complaint with the Austrian Data Protection Authority alleging that Bumble's AI Icebreakers process personal data without valid consent and rely on an invalid legitimate‑interest claim. The complaint cites violations of GDPR…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low
Lawsuit filed
Filed
Germany · Jun 17, 2025
noyb sues German DPAs over inactivity on ‘Pay or OK’ GDPR complaints
noyb filed complaints in August 2021 against news sites using ‘Pay or OK’ consent mechanisms, alleging they violate the GDPR’s freely given consent requirement. After nearly four years of inaction, the North Rhine‑Westphalia and Hesse data…
EDPB · General Data Protection Regulation
Moderate
Enforcement
Announced
European Union · Jun 16, 2025
noyb warns Meta's planned WhatsApp ads may breach GDPR and DMA
noyb alleges that Meta's intention to serve ads on WhatsApp using personal data from Instagram and Facebook violates the GDPR and the EU Digital Markets Act. The organization says the proposed "Pay or Okay" model would not provide freely…
noyb · General Data Protection Regulation