High
Data protection authority action
Decided
Italy · Oct 9, 2026 · effective Sep 23, 2026
Italian DPA fines IQVIA €7 million for unlawful processing of patients’ health data
The Italian Data Protection Authority imposed an administrative fine of EUR 7,000,000 on IQVIA Solutions Italy S.r.l. for processing health data without a legal basis, inadequate information to patients, and missing DPIA and retention…
Italian Data Protection Authority · General Data Protection Regulation
High
Fine
Decided
Italy · Oct 9, 2026
Italian DPA fines Emirates €180,000 for health data infringements
The Italian Data Protection Authority imposed an administrative fine of EUR 180,000 on Emirates for violations of GDPR transparency and retention requirements concerning passengers' health data. Emirates was ordered to clarify which…
Italian Data Protection Authority · General Data Protection Regulation
High
Fine
In effect
Italy · Oct 9, 2026 · effective Jul 3, 2026
Italian DPA fines BBVA €5.508 million for ignoring customer objection to direct marketing
The Italian Data Protection Authority issued an administrative fine of €5,508,000 against BBVA's Italian branch for failing to honor a customer's right to object to direct marketing. The violation lasted seven months, during which the…
Italian Data Protection Authority · General Data Protection Regulation
High
Data protection authority action
Decided
Greece · Oct 8, 2026
Hellenic DPA fines Ministry and EETAA for data breach
The Hellenic Data Protection Authority issued a final decision on 28/07/2026 imposing administrative fines of EUR 200,000 on the Ministry of Social Cohesion and Family Affairs and EUR 150,000 on E.E.T.A.A. S.A. for security deficiencies.…
Hellenic Data Protection Authority · General Data Protection Regulation
High
Fine
Published
Netherlands · Oct 8, 2026
Dutch DPA fines Uber €824.99 million for unlawful automated decision‑making
The Autoriteit Persoonsgegevens imposed an administrative fine of €824,990,000 on Uber for violating GDPR Article 22 by automatically deactivating drivers’ accounts and for failing to provide sufficient information under Article 13. The…
Autoriteit Persoonsgegevens · General Data Protection Regulation
High
Enforcement
Published
Spain · Oct 6, 2026 · effective Oct 6, 2026
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The Spanish Data Protection Agency (AEPD) sent preventive warnings (AI‑00170‑2026 and AI‑00171‑2026) to two local councils regarding planned video‑surveillance systems that use automated image analysis with AI. The agency stresses that the…
Agencia Española de Protección de Datos · Reglamento General de Protección de Datos
High
Settlement
Settled
New York · Sep 24, 2026
NY AG secures $2.3M settlement and reforms from Labcorp after data breach
The New York Attorney General, together with 43 other state AGs, secured a $2.3 million settlement and mandated security reforms from Laboratory Corporation of America (Labcorp) following a 2019 breach that exposed personal and health data…
New York Attorney General's Office
High
Fine
Decided
Ireland · Sep 23, 2026 · effective Sep 21, 2026
Irish Data Protection Commission fines Google €403 million for GDPR violations over location data
The Irish Data Protection Commission issued its final decision on 21 September 2026, imposing administrative fines of €403 million on Google Ireland Limited. The DPC found infringements of GDPR principles relating to lawfulness, fairness…
Irish Data Protection Commission · General Data Protection Regulation
High
Enforcement
Settled
United States (federal) · Sep 17, 2026
FleetCor to Pay $100M to Settle FTC Administrative Action Over Unauthorized Fuel Card Fees
The Federal Trade Commission alleged that FleetCor, now operating as Corpay, charged small‑business customers hidden fees and misrepresented savings from its fuel cards. The company agreed to pay $100 million to resolve the FTC…
Federal Trade Commission · FTC Act Section 5
High
Fine
Decided
France · Sep 11, 2026 · effective Jul 21, 2026
CNIL fines French IT firm EXTIA €300,000 for failing to honor data erasure requests
In 2024 EXTIA received 265 requests for erasure, many of which were not processed or not communicated to the requesters. The CNIL audit found breaches of Articles 12 and 17 GDPR regarding transparency and the right to erasure. The CNIL…
CNIL · General Data Protection Regulation
High
Enforcement
Decided
Ireland · Sep 3, 2026 · effective Aug 28, 2026
Data Protection Commission issues €645,000 fine and compliance orders against HSE
The Irish Data Protection Commission issued a final decision on 28 August 2026 concerning the Health Service Executive's handling of paper medical records. The DPC found physical security and integrity failures at external storage…
Data Protection Commission · General Data Protection Regulation
High
Fine
In effect
European Union · Jul 29, 2024
European data protection authorities fined Meta, Spotify, Criteo and others in 2023 for GDPR violations
In 2023, the Irish DPC ordered Meta to pay €390 million and later €1.2 billion, the Swedish DPA fined Spotify €58 million SEK, and the French CNIL fined Criteo €40 million for breaches of consent and data‑subject rights under EU law.
EDPB · General Data Protection Regulation
High
Fine
In effect
Ireland · May 24, 2024 · effective Aug 25, 2026
Irish Data Protection Commission fines HSE €645,000 for GDPR breaches over paper record storage
The Data Protection Commission (DPC) issued a final decision on 25 August 2026, fining the Health Service Executive (HSE) €645,000 for multiple GDPR infringements related to the storage and security of paper medical records. The DPC also…
Data Protection Commission (Ireland) · General Data Protection Regulation
High
Penalty
Published
European Union · Aug 23, 2023
EU data protection board draft decision imposes €390 million fine on Meta for forced consent
In December 2022, the European Data Protection Board (EDPB) published a draft decision in the “forced consent” case against Meta, finding the company's practices violated the GDPR. The decision resulted in a €390 million fine. The case…
European Data Protection Board · General Data Protection Regulation
High
Data protection authority action
Filed
Spain · Jul 27, 2023
noyb files complaint with Spanish DPA over Ryanair’s facial‑recognition verification for travel‑agent bookings
noyb lodged a complaint with Spain's Data Protection Authority (AEPD) alleging that Ryanair forces customers who book via online travel agents to undergo a facial‑recognition verification process. The complaint argues that Ryanair lacks a…
Spanish Data Protection Authority (AEPD) · General Data Protection Regulation
High
Fine
In effect
Greece · Jul 13, 2022
Greek DPA fines Clearview AI €20 million and bans biometric processing
The Greek Data Protection Authority imposed a €20 million fine on Clearview AI and prohibited the company from processing biometric data of individuals in Greece. Clearview must delete all existing facial‑recognition data of Greek citizens…
Greek Data Protection Authority · General Data Protection Regulation
High
Fine
In effect
Italy · Mar 10, 2022
Italian DPA fines Clearview AI €20 million and bans biometric processing
The Italian data protection authority imposed a €20 million fine on Clearview AI and prohibited the company from processing biometric data of individuals in Italy. Clearview must delete all existing biometric data of Italian citizens and…
Italian Data Protection Authority · General Data Protection Regulation