Moderate
Fine
In effect
France · Nov 27, 2025
CNIL fines Conde Nast €750,000 for cookie consent violations
The French data protection authority CNIL fined Conde Nast €750,000 for placing cookies on its Vanity Fair website without obtaining valid user consent. The authority also found the publisher failed to adequately inform users about the…
CNIL
Moderate
Proposed regulation
Proposed
European Union · Nov 11, 2025
Open letter warns EU Commission's Digital Omnibus draft could deregulate GDPR
Noyb, EDRi and the Irish Council for Civil Liberties sent an open letter to the European Commission criticizing a draft Digital Omnibus that would amend core GDPR provisions. The draft proposes redefining personal data, weakening data…
European Commission · General Data Protection Regulation
Moderate
Data protection authority action
Decided
Austria · Oct 9, 2025
Austrian DSB rules Microsoft 365 Education illegally tracks students and orders data deletion
The Austrian Data Protection Authority found Microsoft 365 Education used tracking cookies without consent and denied a data‑access request, violating GDPR. The DSB ordered Microsoft to delete the data, provide full access, and disclose…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate
Data protection authority action
Published
Austria · Sep 26, 2025
Austrian DSB bans KSV1870 from automated credit checks without consent
The Austrian Data Protection Authority ruled that KSV1870's fully automated credit rating was unlawful and prohibited the agency from conducting such checks without the data subject's consent. The authority also ordered KSV1870 to provide…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low
Investigation
Announced
Austria · Sep 25, 2025
noyb uncovers over 40,000 CRIF credit queries linking Austrian banks, telecoms and retailers
noyb obtained data requests from 2,440 individuals and analyzed more than 40,000 CRIF credit queries, finding that banks, telecoms and other firms provide personal address data to the credit agency. The analysis shows gender and geographic…
EDPB · General Data Protection Regulation
Moderate
Data protection authority action
Announced
Ireland · Sep 18, 2025
Former Meta lobbyist Niamh Sweeney appointed Irish DPC commissioner
Niamh Sweeney, a former senior Meta lobbyist, is set to join the Irish Data Protection Commission (DPC) as a commissioner in October. The DPC is the EU lead privacy regulator for major US tech firms. The appointment raises concerns about…
Irish Data Protection Commission · General Data Protection Regulation
Moderate
Fine
In effect
France · Sep 4, 2025
CNIL fines Google €325 million for unsolicited Gmail advertising
The French data protection authority CNIL has issued a decision siding with privacy NGO noyb and fined Google €325 million for sending unsolicited advertising emails to Gmail users without consent. The authority also ordered Google to stop…
CNIL · ePrivacy Directive
Moderate
Court ruling
Decided
Austria · Aug 18, 2025
Austrian Federal Administrative Court rules DerStandard's "pay or okay" consent model illegal
The Austrian Federal Administrative Court (BVwG) confirmed the Data Protection Authority's finding that DerStandard violated the GDPR by offering a "pay or okay" choice. The court held that the newspaper did not obtain valid, granular…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low
Enforcement
Announced
Germany · Aug 7, 2025
noyb sends cease‑and‑desist to Meta over AI training of EU users’ data
noyb commissioned a Gallup survey of 1,000 German Meta users, finding only 7% want their personal data used for AI training. Based on the results, noyb sent a cease‑and‑desist letter to Meta alleging GDPR violations and is assessing a…
EDPB · General Data Protection Regulation
Moderate
Court ruling
Decided
European Union · Jul 31, 2025
CJEU ruling C‑446/21 limits use of personal data for online advertising and repurposing publicly available data
The European Court of Justice issued ruling C‑446/21, fully backing a lawsuit against Meta's Facebook service. The court massively limits the use of personal data for online advertising and restricts the reuse of publicly available…
EDPB · General Data Protection Regulation
Moderate
Guidance
Announced
European Union · Jul 24, 2025
Report flags 'Pay or Okay' consent‑bypass systems as violating GDPR free‑consent requirement
The noyb report documents the spread of “Pay or Okay” systems across Europe, where users must pay to refuse tracking, resulting in near‑universal consent rates that breach the GDPR’s freely‑given consent standard. It cites a July 2023 CJEU…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate
Data protection authority action
Filed
Austria · Jun 26, 2025
noyb files complaint against Bumble for unlawful AI Icebreakers in Austria
noyb lodged a complaint with the Austrian Data Protection Authority alleging that Bumble's AI Icebreakers process personal data without valid consent and rely on an invalid legitimate‑interest claim. The complaint cites violations of GDPR…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low
Lawsuit filed
Filed
Germany · Jun 17, 2025
noyb sues German DPAs over inactivity on ‘Pay or OK’ GDPR complaints
noyb filed complaints in August 2021 against news sites using ‘Pay or OK’ consent mechanisms, alleging they violate the GDPR’s freely given consent requirement. After nearly four years of inaction, the North Rhine‑Westphalia and Hesse data…
EDPB · General Data Protection Regulation
Moderate
Enforcement
Announced
European Union · Jun 16, 2025
noyb warns Meta's planned WhatsApp ads may breach GDPR and DMA
noyb alleges that Meta's intention to serve ads on WhatsApp using personal data from Instagram and Facebook violates the GDPR and the EU Digital Markets Act. The organization says the proposed "Pay or Okay" model would not provide freely…
noyb · General Data Protection Regulation
Moderate
Class action
Announced
Austria · Jun 3, 2025
noyb seeks participants for potential GDPR class action against Austrian credit agency CRIF
noyb alleges that CRIF processes personal data of millions of Austrians to calculate credit scores based on age, gender and address, potentially violating the GDPR. The organization plans a scientific review and, if evidence supports it…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate
Court ruling
Decided
Germany · May 23, 2025
German Higher Regional Court denies interim injunction against Meta AI training
The Higher Regional Court of Cologne refused the interim injunction sought by Verbraucherzentrale NRW, which alleged Meta's AI training violates the GDPR by using user data without consent. The court's decision is limited to the interim…
Hamburg Data Protection Authority · General Data Protection Regulation
Low
Enforcement
Announced
Ireland · May 14, 2025
noyb sends cease and desist letter to Meta over AI training using EU personal data
noyb has issued a cease and desist letter to Meta, alleging that the company will use EU personal data from Instagram and Facebook for AI training without opt‑in consent. The letter relies on the EU Collective Redress Directive, which…
EDPB · General Data Protection Regulation
Low
Enforcement
Announced
DE-NRW · May 6, 2025
Consumer group asks Meta to stop AI training on EU user data
The Verbraucherzentrale North Rhine-Westphalia sent Meta a cease‑and‑desist letter on 30 April 2025 demanding it halt the use of Instagram and Facebook posts for AI training, citing GDPR consent requirements. Noyb supports the request…
EDPB · General Data Protection Regulation
Low
Enforcement
Filed
Austria · Apr 24, 2025
noyb files GDPR complaint against Ubisoft for forced online tracking of offline games
noyb lodged a complaint with the Austrian Data Protection Authority alleging that Ubisoft requires players to be online for single‑player games, collecting personal data such as start time, duration and quit time. The complaint argues the…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate
Court ruling
Decided
Ireland · Jan 29, 2025
EU General Court rules Irish DPC acted unlawfully for refusing to investigate noyb complaint
The EU General Court held that the Irish Data Protection Commission unlawfully refused to investigate a complaint filed by noyb. The court dismissed the DPC's claims against the European Data Protection Board. The case can now be appealed…
Irish Data Protection Commission · General Data Protection Regulation