High
Fine
Decided
Italy · Oct 9, 2026
Italian DPA fines Emirates €180,000 for health data infringements
The Italian Data Protection Authority imposed an administrative fine of EUR 180,000 on Emirates for violations of GDPR transparency and retention requirements concerning passengers' health data. Emirates was ordered to clarify which…
Italian Data Protection Authority · General Data Protection Regulation
Moderate
Enforcement
Decided
France · Oct 8, 2026
CNIL closes injunction against FRANCE TRAVAIL after compliance with data security measures
The French data protection authority (CNIL) closed the injunction issued on 22 January 2026 against FRANCE TRAVAIL, after the organization demonstrated compliance with the security measures required by Article 32 of the GDPR. The original…
CNIL · RGPD
High
Enforcement
Published
Spain · Oct 6, 2026 · effective Oct 6, 2026
AEPD issues warnings to two Spanish municipalities over AI‑enabled video surveillance projects
The Spanish Data Protection Agency (AEPD) sent preventive warnings (AI‑00170‑2026 and AI‑00171‑2026) to two local councils regarding planned video‑surveillance systems that use automated image analysis with AI. The agency stresses that the…
Agencia Española de Protección de Datos · Reglamento General de Protección de Datos
Moderate
Settlement
Settled
United States (federal) · Oct 2, 2026
Meta’s Muse AI Agent raises privacy, security, and child safety concerns amid past FTC consent decree
Meta launched the Muse personal AI agent in September 2026, which collects extensive personal data and can act without clear user permission. EPIC reports multiple incidents where Muse accessed messages, shared home addresses, and…
Federal Trade Commission
High
Settlement
Settled
New York · Sep 24, 2026
NY AG secures $2.3M settlement and reforms from Labcorp after data breach
The New York Attorney General, together with 43 other state AGs, secured a $2.3 million settlement and mandated security reforms from Laboratory Corporation of America (Labcorp) following a 2019 breach that exposed personal and health data…
New York Attorney General's Office
Moderate
Enforcement
Published
Spain · Sep 23, 2026
Spanish Data Protection Agency issues warning to company over AI-driven resume screening
On 23 September 2026 the AEPD sent a formal warning to a company planning to use an AI tool for analysing CVs and assigning scores. The agency stresses that data protection must be built in from the start, including DPIA for high‑risk…
Agencia Española de Protección de Datos (AEPD) · Reglamento General de Protección de Datos (RGPD)
High
Fine
Decided
Ireland · Sep 23, 2026 · effective Sep 21, 2026
Irish Data Protection Commission fines Google €403 million for GDPR violations over location data
The Irish Data Protection Commission issued its final decision on 21 September 2026, imposing administrative fines of €403 million on Google Ireland Limited. The DPC found infringements of GDPR principles relating to lawfulness, fairness…
Irish Data Protection Commission · General Data Protection Regulation
Low
Enforcement
Announced
Germany · Sep 10, 2026
noyb to file injunction against SCHUFA over shadow database
noyb sent a cease-and-desist letter to SCHUFA demanding the removal of its shadow database. SCHUFA's deadline to comply has expired and the agency has rejected the allegations. noyb announced it will now file an injunction and invites…
Moderate
Enforcement
Announced
Spain · Sep 9, 2026
AEPD opens investigation into Ministry of Interior report listing journalists and political leanings
The Spanish Data Protection Agency announced it will launch a formal, ex officio investigation into a Ministry of Interior communication office report that includes journalists' names and alleged political ideologies. The probe will…
Agencia Española de Protección de Datos · Reglamento General de Protección de Datos (RGPD)
High
Enforcement
Decided
Ireland · Sep 3, 2026 · effective Aug 28, 2026
Data Protection Commission issues €645,000 fine and compliance orders against HSE
The Irish Data Protection Commission issued a final decision on 28 August 2026 concerning the Health Service Executive's handling of paper medical records. The DPC found physical security and integrity failures at external storage…
Data Protection Commission · General Data Protection Regulation
Moderate
Settlement
Announced
United States (federal) · Sep 1, 2026
Meta to implement age‑verification framework under $17 B settlement with 52 U.S. states
Meta has agreed to a $17 billion settlement with 52 state attorneys general that mandates age‑assurance technology for its platforms. The settlement requires Meta to apply age‑verification methods within one year, classify users into 18+…
state attorneys general · Children's Online Privacy Protection Act
Moderate
Settlement
Settled
United States (federal) · Aug 26, 2026
EFF says Meta settlement expands data collection and limits youth rights
The settlement reduces young users' access to Meta products and limits their ability to exercise free expression and community participation. It requires age assurance on every product, leading to the collection of additional personal…
Low
Enforcement
Announced
Germany · Aug 26, 2026 · effective Aug 26, 2026
noyb sends cease‑and‑desist letter to SCHUFA over alleged ‘shadow database’ GDPR violations
In July 2026, the NGO noyb issued a cease‑and‑desist letter to German credit agency SCHUFA demanding it stop storing data beyond retention periods and provide full historical data under Article 15 GDPR. The organization warned it will seek…
EDPB · General Data Protection Regulation
Low
Enforcement
Filed
Austria · Jun 9, 2026
noyb files injunction against Austrian credit agency CRIF over GDPR violations
noyb, a state‑approved qualified entity, filed an injunction against CRIF to stop its alleged unlawful collection and scoring of personal data under the GDPR. The filing also suspends the limitation period and prepares a subsequent class…
EDPB · General Data Protection Regulation
Low
Investigation
Announced
Austria · Jan 20, 2026
noyb investigation reveals Austrian credit agency CRIF uses public registers for mass address data collection
noyb’s investigation of CRIF shows that most address data comes from brokers who scrape public registers, violating GDPR purpose‑limitation. The Austrian DSB has already ruled that further processing for advertising breaches the GDPR.
Austrian Data Protection Authority · General Data Protection Regulation
Low
Enforcement
Filed
Austria · Dec 17, 2025
noyb files complaints against TikTok, AppsFlyer and Grindr with Austrian DSB over unlawful tracking
noyb has lodged two complaints with Austria's data protection authority alleging that TikTok tracks users across other apps and fails to provide a complete copy of personal data. The complaints also target AppsFlyer and Grindr for sharing…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Moderate
Data protection authority action
Decided
Austria · Oct 9, 2025
Austrian DSB rules Microsoft 365 Education illegally tracks students and orders data deletion
The Austrian Data Protection Authority found Microsoft 365 Education used tracking cookies without consent and denied a data‑access request, violating GDPR. The DSB ordered Microsoft to delete the data, provide full access, and disclose…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation
Low
Investigation
Announced
Austria · Sep 25, 2025
noyb uncovers over 40,000 CRIF credit queries linking Austrian banks, telecoms and retailers
noyb obtained data requests from 2,440 individuals and analyzed more than 40,000 CRIF credit queries, finding that banks, telecoms and other firms provide personal address data to the credit agency. The analysis shows gender and geographic…
EDPB · General Data Protection Regulation
Low
Enforcement
Announced
Ireland · May 14, 2025
noyb sends cease and desist letter to Meta over AI training using EU personal data
noyb has issued a cease and desist letter to Meta, alleging that the company will use EU personal data from Instagram and Facebook for AI training without opt‑in consent. The letter relies on the EU Collective Redress Directive, which…
EDPB · General Data Protection Regulation
Low
Enforcement
Filed
Austria · Apr 24, 2025
noyb files GDPR complaint against Ubisoft for forced online tracking of offline games
noyb lodged a complaint with the Austrian Data Protection Authority alleging that Ubisoft requires players to be online for single‑player games, collecting personal data such as start time, duration and quit time. The complaint argues the…
Austrian Data Protection Authority (DSB) · General Data Protection Regulation