High
Fine
Published
Netherlands · Oct 8, 2026
Dutch DPA fines Uber €824.99 million for unlawful automated decision‑making
The Autoriteit Persoonsgegevens imposed an administrative fine of €824,990,000 on Uber for violating GDPR Article 22 by automatically deactivating drivers’ accounts and for failing to provide sufficient information under Article 13. The…
Autoriteit Persoonsgegevens · General Data Protection Regulation
High
Enforcement
Published
Spain · Oct 6, 2026 · effective Oct 6, 2026
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The Spanish Data Protection Agency (AEPD) sent preventive warnings (AI‑00170‑2026 and AI‑00171‑2026) to two local councils regarding planned video‑surveillance systems that use automated image analysis with AI. The agency stresses that the…
Agencia Española de Protección de Datos · Reglamento General de Protección de Datos
Moderate
Settlement
Settled
United States (federal) · Oct 2, 2026
Meta’s Muse AI Agent raises privacy, security, and child safety concerns amid past FTC consent decree
Meta launched the Muse personal AI agent in September 2026, which collects extensive personal data and can act without clear user permission. EPIC reports multiple incidents where Muse accessed messages, shared home addresses, and…
Federal Trade Commission
Low
Investigation
Announced
United States (federal) · Sep 24, 2026
Senate Judiciary Subcommittee holds hearing on Flock Safety AI surveillance network
The Senate Judiciary Committee’s Subcommittee on Crime and Counterterrorism conducted a hearing on Flock Safety’s nationwide AI surveillance system. Experts highlighted the extensive data collection, facial tracking, and cybersecurity…
Moderate
Enforcement
Published
Spain · Sep 23, 2026
Spanish Data Protection Agency issues warning to company over AI-driven resume screening
On 23 September 2026 the AEPD sent a formal warning to a company planning to use an AI tool for analysing CVs and assigning scores. The agency stresses that data protection must be built in from the start, including DPIA for high‑risk…
Agencia Española de Protección de Datos (AEPD) · Reglamento General de Protección de Datos (RGPD)
High
Fine
Decided
Ireland · Sep 23, 2026 · effective Sep 21, 2026
Irish Data Protection Commission fines Google €403 million for GDPR violations over location data
The Irish Data Protection Commission issued its final decision on 21 September 2026, imposing administrative fines of €403 million on Google Ireland Limited. The DPC found infringements of GDPR principles relating to lawfulness, fairness…
Irish Data Protection Commission · General Data Protection Regulation
Moderate
Investigation
Announced
United States (federal) · Sep 14, 2026
Police misuse ALPR data with frivolous reasons, EFF finds
EFF analysis of Flock Safety ALPR logs shows officers across the United States entering nonsensical reasons such as "LOL", "LMAO" and "idk" to access vehicle location data. The lack of warrant requirements and weak audit controls enables…
CPPA · California Delete Act
Low
Enforcement
Announced
Germany · Sep 10, 2026
noyb to file injunction against SCHUFA over shadow database
noyb sent a cease-and-desist letter to SCHUFA demanding the removal of its shadow database. SCHUFA's deadline to comply has expired and the agency has rejected the allegations. noyb announced it will now file an injunction and invites…
Low
Enforcement
Announced
Germany · Aug 26, 2026 · effective Aug 26, 2026
noyb sends cease‑and‑desist letter to SCHUFA over alleged ‘shadow database’ GDPR violations
In July 2026, the NGO noyb issued a cease‑and‑desist letter to German credit agency SCHUFA demanding it stop storing data beyond retention periods and provide full historical data under Article 15 GDPR. The organization warned it will seek…
EDPB · General Data Protection Regulation
Low
Investigation
Announced
Global · Aug 19, 2026
EFF report finds mobile ad libraries may leak user location data
EFF released a new report highlighting how mobile ad libraries can cause apps to unintentionally expose users' location information. The investigation notes that this leakage can reveal intimate details about individuals and be exploited…
Low
Enforcement
Filed
Austria · Jul 30, 2026
noyb files GDPR complaint against dict.cc over 1,741‑partner consent banner
noyb lodged a complaint with the Austrian Data Protection Authority alleging that dict.cc’s cookie banner forces users to consent to tracking by 1,741 partner companies with a single click, violating GDPR consent requirements. The…
Austrian Data Protection Authority · General Data Protection Regulation
Low
Enforcement
Filed
Austria · Jun 9, 2026
noyb files injunction against Austrian credit agency CRIF over GDPR violations
noyb, a state‑approved qualified entity, filed an injunction against CRIF to stop its alleged unlawful collection and scoring of personal data under the GDPR. The filing also suspends the limitation period and prepares a subsequent class…
EDPB · General Data Protection Regulation
Low
Investigation
Filed
Norway (EEA) · Jun 3, 2026
Norwegian Consumer Council and noyb file complaint against Schibsted over “Pay or Okay” tracking scheme
The Norwegian Consumer Council and privacy NGO noyb have lodged a joint complaint with the Norwegian Data Protection Authority against Schibsted for its “Pay or Okay” system that forces users to pay to refuse tracking. The complaint argues…
Norwegian Data Protection Authority · General Data Protection Regulation
Low
Enforcement
Filed
Austria · May 5, 2026
LinkedIn blocks GDPR access to profile visitor data behind paywall, noyb files complaint in Austria
LinkedIn requires users to pay to view who has visited their profile, despite the data being personal under the GDPR. noyb argues the data must be provided free of charge under Article 15 and has lodged a complaint with the Austrian Data…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate
Fine
In effect
France · Mar 13, 2026
French court upholds €40M GDPR fine against Criteo
The French Data Protection Authority (CNIL) fined Criteo €40 million for GDPR violations, including lack of valid consent, transparency, and failures to honor erasure and access rights. In March 2026, the Conseil d’État rejected Criteo’s…
CNIL · General Data Protection Regulation
Moderate
Data protection authority action
Decided
Austria · Jan 27, 2026
Austrian DSB orders Microsoft to stop tracking school children with cookies
The Austrian Data Protection Authority ruled that Microsoft illegally installed tracking cookies on a pupil's device without consent. The authority ordered Microsoft to cease the use of those cookies within four weeks. The decision follows…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low
Investigation
Announced
Austria · Jan 20, 2026
noyb investigation reveals Austrian credit agency CRIF uses public registers for mass address data collection
noyb’s investigation of CRIF shows that most address data comes from brokers who scrape public registers, violating GDPR purpose‑limitation. The Austrian DSB has already ruled that further processing for advertising breaches the GDPR.
Austrian Data Protection Authority · General Data Protection Regulation
Low
Enforcement
Filed
Austria · Dec 17, 2025
noyb files complaints against TikTok, AppsFlyer and Grindr with Austrian DSB over unlawful tracking
noyb has lodged two complaints with Austria's data protection authority alleging that TikTok tracks users across other apps and fails to provide a complete copy of personal data. The complaints also target AppsFlyer and Grindr for sharing…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate
Enforcement
Filed
Austria · Oct 28, 2025
noyb files criminal complaint against Clearview AI in Austria
noyb filed a criminal complaint with Austrian public prosecutors against Clearview AI and its managers for alleged GDPR violations. The complaint relies on Article 84 GDPR and Austria's § 63 Data Protection Act, which allow criminal…
Austrian public prosecutors · General Data Protection Regulation
Moderate
Data protection authority action
Decided
Austria · Oct 9, 2025
Austrian DSB rules Microsoft 365 Education illegally tracks students and orders data deletion
The Austrian Data Protection Authority found Microsoft 365 Education used tracking cookies without consent and denied a data‑access request, violating GDPR. The DSB ordered Microsoft to delete the data, provide full access, and disclose…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation