Moderate
Interpretation
Published
Austria · May 2, 2022
Austrian DPA rejects risk‑based approach for EU‑US data transfers, deems Google IP anonymisation insufficient
The Austrian Data Protection Authority issued a decision stating that the GDPR does not permit a risk‑based approach for transfers to insecure third countries such as the United States. It also concluded that Google’s IP anonymisation does…
Austrian Data Protection Authority · General Data Protection Regulation
Low
Enforcement
Filed
Malta · Apr 29, 2022
noyb files second complaint against C‑Planet for refusing data‑subject access to source of political data
noyb filed a second complaint with Malta's Information & Data Protection Commissioner (IDPC) demanding C‑Planet disclose the original source of illegally processed voter data. The company previously received a €65,000 fine for illegal…
Information & Data Protection Commissioner (IDPC) · General Data Protection Regulation
Moderate
Fine
In effect
Malta · Jan 20, 2022
Malta data protection commissioner fines C-Planet €65,000 for illegal voter data collection
The Malta Information & Data Protection Commissioner (IDPC) imposed a €65,000 fine on IT company C-Planet for unlawfully collecting personal data of 98% of Maltese voters, including political preferences. The IDPC found the processing…
Information & Data Protection Commissioner (IDPC) · General Data Protection Regulation
Low
Enforcement
Published
Austria · Jan 13, 2022
Austrian DSB rules EU‑US transfers to Google Analytics illegal under GDPR
The Austrian Data Protection Authority (DSB) decided that the continuous use of Google Analytics violates the GDPR following the Schrems II ruling. The DSB rejected Google's claimed technical and organisational measures as ineffective…
Austrian Data Protection Authority (Datenschutzbehörde) · California Delete Act
Low
Enforcement
Pending
Ireland · Dec 19, 2021
Facebook ignores EU Court rulings on data transfers, Irish DPC enforcement pending
noyb reports that Facebook's 86‑page Transfer Impact Assessment disregards the CJEU Schrems I and II rulings that require EU‑US data transfers to stop. The Irish Data Protection Commission has not yet issued a decision despite a complaint…
Irish Data Protection Commission · General Data Protection Regulation
Moderate
Enforcement
Filed
European Union · May 26, 2021 · effective May 25, 2018
Digital Rights alliance files legal complaints across Europe against facial recognition company Clearview AI
Noyb and other EU digital‑rights groups submitted complaints to data‑protection authorities in France, Austria, Italy, Greece and the United Kingdom to halt Clearview AI's mass facial‑recognition surveillance. The regulators have three…
EDPB · General Data Protection Regulation
Low
Enforcement
Announced
Ireland · May 21, 2021
European Parliament urges Commission to launch infringement proceedings against Ireland over GDPR enforcement
The European Parliament adopted a resolution calling on the European Commission to start infringement procedures against Ireland due to delays by the Irish Data Protection Commission in handling GDPR complaints. The resolution noted that…
European Commission · General Data Protection Regulation
Low
Enforcement
Announced
Austria · May 5, 2021
Austrian DPA may fine Google up to €6 billion for illegal EU‑US data transfers
The Austrian Data Protection Authority (DSB) has the option under the GDPR to impose a fine of up to €6 billion (4% of global turnover) on Google for continuing to transfer personal data from EU websites to the United States despite CJEU…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate
Guidance
Published
European Union · Jan 27, 2021
noyb urges stronger GDPR enforcement on European Data Protection Day
noyb highlights that despite the GDPR's strong provisions, compliance remains low and enforcement insufficient. The organization calls on data protection authorities and companies to move from paper rights to real protection, citing the…
EDPB · General Data Protection Regulation
Moderate
Enforcement
Filed
Malta · Nov 12, 2020
noyb files complaint with Maltese DPA over C-Planet voter data breach
noyb filed a complaint with the Maltese Data Protection Authority against C-Planet IT Solutions for leaking personal data of 337,384 voters, including phone numbers, dates of birth and political opinions. NGOs Daphne Foundation and…
Maltese Data Protection Authority · General Data Protection Regulation
Moderate
Court ruling
Decided
Ireland · Oct 12, 2020
Irish High Court grants judicial review to stop Facebook EU-US data transfers
The Irish High Court granted leave for a judicial review filed by privacy group noyb against the Irish Data Protection Commission (DPC) to compel a decision on Facebook's EU‑US data transfers. The action seeks to enforce the European Court…
Irish Data Protection Commission · Standard Contractual Clauses
Moderate
Court ruling
Announced
Ireland · Sep 14, 2020
Irish High Court grants Facebook leave to file Judicial Review, stays DPC EU‑US data‑flow investigation
The Irish High Court granted Facebook leave to bring a Judicial Review (Case No 2020/617 JR) and ordered a stay of the Data Protection Commission's ex officio investigation into Facebook's EU‑US data transfers. The DPC may resume the…
Data Protection Commission (DPC) · Standard Contractual Clauses
Moderate
Enforcement
Filed
European Union · Aug 17, 2020
101 GDPR complaints filed against EU companies for US data transfers to Google and Facebook
Noyb has filed 101 complaints in all 30 EU and EEA member states alleging that European companies continue to forward visitor data to Google and Facebook in the US. The complaints cite the CJEU ruling that the EU‑US Privacy Shield is…
Data Protection Authorities · Standard Contractual Clauses
High
Guidance
Published
European Union · Jul 24, 2020 · effective Jul 16, 2020
noyb provides step-by-step guide for EU users to stop US data transfers after Schrems II
The document outlines how data subjects can exercise GDPR rights to learn about and halt transfers of their personal data to the United States following the CJEU Schrems II judgment. It provides sample request letters for information…
European Commission · Standard Contractual Clauses
Moderate
Guidance
Published
European Union · Jul 20, 2020
noyb releases guidance for EU companies on Schrems II data‑transfer obligations
The guidance explains steps EU controllers should take after the CJEU Schrems II judgment, including reviewing data flows, stopping transfers that rely on the invalidated Privacy Shield, and notifying DPAs when using SCCs after a negative…
EDPB · General Data Protection Regulation
Moderate
Court ruling
Decided
European Union · Jul 16, 2020
CJEU invalidates EU‑US Privacy Shield and bars use of SCCs for Facebook
The Court of Justice of the European Union ruled that the EU‑US Privacy Shield is invalid because US surveillance laws conflict with EU fundamental rights. It also held that Standard Contractual Clauses cannot be used by Facebook and…
European Commission · Standard Contractual Clauses
Moderate
Court ruling
Decided
European Union · Jul 12, 2020
CJEU judgment limits EU‑US data outsourcing, confirms 'necessary' transfers exempt
The Court of Justice of the EU ruled that "necessary" transfers of personal data to the US are not affected by the case, while voluntary outsourcing of processing to US providers may violate the GDPR. The judgment confirms the invalidity…
European Commission · Standard Contractual Clauses
Low
Class action
Announced
Malta · May 27, 2020
Massive political data leak in Malta prompts class action
A database of 337,384 Maltese voters' personal information, including political affiliation, was publicly accessible for at least a year after being stored by C‑Planet IT Solutions in an open directory. The leak violates GDPR provisions on…
Maltese Data Protection Authority · General Data Protection Regulation
Low
Guidance
Published
Austria · Apr 21, 2020
First European Corona contact tracing app in Austria reviewed by noyb, epicenter.works and SBA Research
The Austrian Red Cross released a contact tracing app on March 25th, which uses a hybrid central‑server and local storage model. NGOs and security researchers reviewed the app and identified privacy weaknesses, recommending a switch to a…
Moderate
Guidance
Published
European Union · Apr 9, 2020
noyb releases ad‑hoc guidance on GDPR compliance for COVID‑19 data processing
noyb published an ad‑hoc paper outlining how the GDPR permits processing personal data to combat the coronavirus pandemic. The paper cites Articles 6(1)(d) and 9(2)(i) as legal bases and stresses the need for privacy‑by‑design, data…
EDPB · General Data Protection Regulation