General Data Protection Regulation
GDPREU-wide data protection law governing the processing of personal data of individuals in the EU/EEA. Sets strict requirements for consent, data subject rights, breach notification, and cross-border transfers.
Jurisdiction
European Union
Jurisdiction Type
supranational
Effective Date
5/25/2018
Enforcing Authority
National Data Protection Authorities (DPAs)
Maximum Fine
Up to €20M or 4% of annual global turnover
Fines Under This Regulation
1,990
Total Fine Amount (USD)
$4.8B
Privacy Topics
consentdata_subject_rightsbreach_notificationcross_border_transferdpoprivacy_by_designchildren
Key Articles
| Article | Description |
|---|---|
| Art. 5 | Principles of processing |
| Art. 6 | Lawful basis |
| Art. 7 | Conditions for consent |
| Art. 9 | Special categories |
| Art. 15 | Right of access |
| Art. 17 | Right to erasure |
| Art. 20 | Data portability |
| Art. 25 | Data protection by design |
| Art. 32 | Security of processing |
| Art. 33 | Breach notification to authority |
| Art. 35 | Data protection impact assessment |
| Art. 83 | Fines and penalties |
| Art. 12-14 | Transparency and information |
| Art. 44-49 | International transfers |
Fines Under GDPR
| Date | Company | Authority | Amount (USD) | Type |
|---|---|---|---|---|
| -- | Unknwon | Slovak Data Protection Office | -- | Failure to implement sufficient measures to ensure information security |
| -- | Vodafone Espana | Spanish Data Protection Authority (AEPD) | $5,400 | Failure to comply with processing principles |
| -- | Unknown | Slovak Data Protection Office | -- | Non-compliance with lawful basis for data processing |
| -- | Gestion De Cobros Yo Cobro SL | Spanish Data Protection Authority (AEPD) | $64,800 | Non-compliance with lawful basis for data processing |
| -- | Unknown | Slovak Data Protection Office | -- | <a href="https://www.privacy-regulation.eu/en/32.htm">Art. 32 GDPR</a> |
| -- | Vodafone Espana | Spanish Data Protection Authority (AEPD) | $29,160 | Non-compliance with subjects' rights protection safeguards |
| -- | Unknown | Data Protection Authority of Hamburg | $540 | Non-compliance with lawful basis for data processing |
| -- | ENDESA | Spanish Data Protection Authority (AEPD) | $64,800 | Non-compliance with lawful basis for data processing |
| -- | Unknown | Data Protection Authority of Saarland | -- | Non-compliance with lawful basis for data processing |
| -- | Restaurant | Spanish Data Protection Authority (AEPD) | $12,960 | Non-compliance with lawful basis for data processing |
| -- | Unknown | Slovak Data Protection Office | -- | Non-compliance with subjects' rights protection safeguards |
| -- | Unknown | Slovak Data Protection Office | -- | Failure to implement sufficient measures to ensure information security |
| -- | UniCredit Bank | Czech Data Protection Authority (UOOU) | $3,391 | Non-compliance with lawful basis for data processing |
| -- | Alza.cz a.s. | Czech Data Protection Authority (UOOU) | $635 | Non-compliance with lawful basis for data processing |
| -- | Individual entrepreneur | Czech Data Protection Authority (UOOU) | $1,058 | Failure to implement sufficient measures to ensure information security |
| -- | Edison Energia S.p.A. | Italian Data Protection Authority (Garante) | $5,292,000 | Failure to comply with data processing principles |
| -- | Hamburger Volksbank eG | Data Protection Authority of Hamburg | -- | Non-compliance with lawful basis for data processing |
| -- | Unknown | Data Protection Authority of Brandenburg | $54,000 | Non-compliance with subjects' rights protection safeguards |
| -- | Unknown | Data Protection Authority of Liechtenstein | $4,428 | Unknown |
| -- | Ikea Romania SA | Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | $1,080 | Failure to implement sufficient measures to ensure information security |
| -- | Piraeus Bank | Hellenic Data Protection Authority (HDPA) | $10,800 | Failure to comply with data processing principles |
| -- | ALBERTO FORTE COMPSITE, S.L. | Spanish Data Protection Authority (AEPD) | $12,960 | Failure to implement sufficient measures to ensure information security |
| -- | Mercadona S.A. | Spanish Data Protection Authority (AEPD) | $18,360 | Non-compliance with lawful basis for data processing |
| 2026-02-01 | NL Municipalities (x10) | Netherlands AP | $270,000 | consent |
| 2025-09-01 | SHEIN | France CNIL | $162,000,000 | consent |
Showing 1 - 25 of 1,990 results
Page 1 of 80