Low
Lawsuit filed
Filed
Austria · Dec 4, 2023
noyb sues CRIF and AZ Direct for illegal secret data processing in Austria
noyb filed a lawsuit in the Vienna Regional Court on behalf of seven individuals alleging that CRIF GmbH and address trader AZ Direct secretly trade personal data of millions of Austrians for credit scoring. The Austrian Data Protection…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate
Enforcement
Filed
European Union · Nov 16, 2023
noyb files complaint with EDPS over EU Commission’s political micro‑targeting ads on X
noyb lodged a complaint with the European Data Protection Supervisor alleging the EU Commission used unlawful micro‑targeting on X to promote its chat‑control proposal. The ads targeted users based on political views and religious beliefs…
European Data Protection Supervisor (EDPS) · General Data Protection Regulation
Low
Court ruling
Decided
Austria · Oct 9, 2023
Austrian court orders streaming service DAZN to comply with GDPR access request after 5 years
The Austrian Federal Administrative Court ruled on 6 September 2023 that DAZN must provide the missing information requested under the GDPR right of access. DAZN complied with the court order on 13 September 2023, completing the request…
Austrian Data Protection Authority · General Data Protection Regulation
Moderate
Fine
Decided
Norway (EEA) · Sep 29, 2023
Norwegian Privacy Appeals Board upholds €5.8 million fine against Grindr
The Norwegian Privacy Appeals Board confirmed the Norwegian Data Protection Authority's fine of NOK 65 million against the dating app Grindr for sharing sensitive personal data with third parties. The fine, approximately €5.8 million…
Norwegian Data Protection Authority · General Data Protection Regulation
Low
Enforcement
Decided
DE-NI · Jul 14, 2023
German DPA declares heise.de "Pay or Okay" cookie banner illegal
The Lower Saxony Data Protection Authority (LfD) ruled that the "Pay or Okay" model used by heise.de in 2021 violates GDPR because it does not provide specific consent for each purpose. The authority issued a reprimand, noting that…
Data Protection Authority of Lower Saxony (LfD) · General Data Protection Regulation
Moderate
Proposed regulation
Proposed
European Union · Jul 4, 2023
EU Commission proposes GDPR Procedures Regulation that may limit citizens' procedural rights
The European Commission has issued a proposal to create a GDPR Procedures Regulation to address cooperation gaps among DPAs. Critics say the draft strips citizens of procedural rights and gives companies extensive participation rights. The…
European Commission · General Data Protection Regulation
Moderate
Amendment
Passed
Ireland · Jun 28, 2023
Ireland passes amendment to Data Protection Act allowing DPC to declare GDPR cases confidential
The Irish government has passed an amendment to the Data Protection Act, creating Section 26A which permits the Data Protection Commission to declare documents relating to pending GDPR procedures confidential and criminalise their…
Irish Data Protection Commission (DPC) · General Data Protection Regulation
Moderate
Amendment
Proposed
Ireland · Jun 26, 2023
Irish Parliament debates amendment to criminalise reporting on DPC procedures
A last‑minute amendment (Section 26A) was added to the Courts and Civil Law (Miscellaneous Provisions) Bill 2022 that would allow the Irish Data Protection Commissioner to declare its procedures confidential and make reporting on them a…
Irish Data Protection Commissioner · General Data Protection Regulation
Moderate
Amendment
Pending
Ireland · Jun 26, 2023
Irish government adds Section 26A to Data Protection Act, criminalising reporting on DPC procedures
A last‑minute amendment (Section 26A) was inserted into the Courts and Civil Law (Miscellaneous Provisions) Bill 2022, allowing the Irish Data Protection Commissioner to declare most of its procedures confidential. The amendment would make…
Irish Data Protection Commissioner (DPC) · General Data Protection Regulation
Moderate
Enforcement
Filed
Belgium · Jun 23, 2023
noyb files complaint against TeleSign for unlawful profiling of mobile users
noyb filed a complaint with the Belgian Data Protection Authority alleging that TeleSign receives phone data from BICS and creates reputation scores without consent, violating the GDPR. The complaint cites the use of AI-generated trust…
Belgian Data Protection Authority · General Data Protection Regulation
Moderate
Fine
In effect
France · Jun 22, 2023
French CNIL fines Criteo €40 million for GDPR violations
The French Data Protection Authority (CNIL) fined Criteo €40 million for violating the GDPR, including lack of valid consent, transparency, and failure to respect the right to erasure and access. The enforcement followed complaints filed…
CNIL · General Data Protection Regulation
Moderate
Fine
In effect
Sweden · Jun 13, 2023
Swedish Data Protection Authority fines Spotify €5 million for GDPR access violations
The Swedish Data Protection Authority (IMY) imposed a fine of 58 million Swedish crowns (≈ €5 million) on Spotify for not fully complying with users' right of access under the GDPR. The authority ordered Spotify to provide the complete set…
Swedish Data Protection Authority (IMY) · General Data Protection Regulation
Low
Enforcement
Filed
European Union · Jun 1, 2023
Credit agency CRIF systematically withholds data from consumers, noyb files complaint
noyb has filed a complaint with the data protection authority alleging that CRIF violates GDPR Article 15 by providing incomplete access to personal data. The complaint cites systematic withholding of source information and limited…
EDPB · General Data Protection Regulation
Moderate
Data protection authority action
Announced
Malta · May 17, 2023
Maltese DPA orders C-PLANET to disclose data source within 20 days or face fine
The Maltese Data Protection Authority (IDPC) ordered IT company C-PLANET to provide details on the source of personal data collected on voters within 20 days. Failure to comply will result in a proportionate and dissuasive fine under the…
Maltese Data Protection Authority (IDPC) · General Data Protection Regulation
Moderate
Court ruling
Decided
Austria · Mar 17, 2023
Austrian Federal Administrative Court allows mobile providers to refuse access requests for location data without proof of exclusive use
The Austrian Federal Administrative Court (BVwG) ruled that A1 Telekom Austria may deny a data subject's request for traffic and location data unless the subject can prove exclusive use of the phone. The court deemed location data…
EDPB · General Data Protection Regulation
Moderate
Guidance
Published
European Union · Jan 24, 2023
EDPB releases draft report on minimum requirements for cookie consent banners
The European Data Protection Board's task force issued a draft report outlining unlawful cookie banner practices under EU law. It sets a minimum threshold for consent banners, including the need for a visible reject option and prohibition…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate
Enforcement
Published
Ireland · Jan 11, 2023
Irish DPC fines Meta €60m for unlawful processing and €150m for transparency breaches
The Irish Data Protection Commission (DPC) issued a final decision imposing a €150 million fine on Facebook for transparency failures and a €60 million fine on Meta for lacking a legal basis to process personal data. The decision also…
Irish Data Protection Commission · General Data Protection Regulation
Moderate
Enforcement
Announced
European Union · Jan 4, 2023
EU EDPB bans Meta from using personal data for personalized ads, imposes €390 million fine
The European Data Protection Board (EDPB) decided that Meta (Facebook and Instagram) may not use personal data for personalized advertising and must obtain opt‑in consent. The decision also imposes a total fine of €390 million on Meta.…
European Data Protection Board (EDPB) · General Data Protection Regulation
Moderate
Fine
In effect
Ireland · Jan 4, 2023 · effective Jan 4, 2023
EU data protection board fines Meta €390 million and bans personalized ads
The European Data Protection Board, following the Irish Data Protection Commission, ruled that Meta's use of personal data for personalized advertising violated the GDPR and imposed a €390 million fine. Meta must obtain opt‑in consent and…
European Data Protection Board · General Data Protection Regulation
Low
Court ruling
Decided
Sweden · Nov 9, 2022
Swedish court rules IMY must investigate GDPR complaints and grant complainants party status
The Stockholm administrative court held that a complainant under Article 77 GDPR can request a decision from the Swedish Data Protection Authority (IMY) after six months and that Swedish law does not deny party status. The court ordered…
Swedish Data Protection Authority (IMY) · General Data Protection Regulation