Skip to main content
European Data Protection Board logo
Back Search Menu
Close menu

Main navigation

  • Home
  • Topics
  • Documents
  • Registers
  • Public consultations

Top navigation

  • About EDPB
  • News
  • Meetings
  • Contact
  • Guide for SMEs
EN

Select your language

  • BGбългарски
  • CSčeština
  • DAdansk
  • DEDeutsch
  • ELελληνικά
  • ESespañol
  • ETeesti
  • FIsuomi
  • FRfrançais
  • GAGaeilge
  • HRhrvatski
  • HUmagyar
  • ITitaliano
  • LTlietuvių
  • LVlatviešu
  • MTMalti
  • NLNederlands
  • PLpolski
  • PTportuguês
  • ROromână
  • SKslovenčina
  • SLslovenščina
  • SVsvenska
Close language switcher

Breadcrumb

  1. Home

French SA: Cookies placed without consent: SHEIN fined 150 000 000 EUR by the CNIL

Thu, 09/04/2025
Background information Date of final decision: September 1st, 2025 National case Controller: INFINITE STYLES SERVICES CO. LIMITED Legal Reference: The French Data Protection Act (Article 82): failure to obtain user consent before placing cookies; incomplete information banners, insufficient second-level information, inadequate mechanisms for refusing and withdrawing consent Decision: Infringement of the French Data Protection Act, Administrative fine Key words: Cookies Summary of the Decision Origin of the case In August 2023, the French supervisory authority (CNIL) carried out an inspection
  • Read more about French SA: Cookies placed without consent: SHEIN fined 150 000 000 EUR by the CNIL

Greek SA: Imposition of fine on association for transmission of sensitive data, failure to facilitate right of access and lack of cooperation with the SA

Tue, 08/12/2025
Background information Date of final decision: 24 June 2025 National case Controller: Association “Shield of David” Legal Reference(s): GDPR: Article 5. Principles relating to processing of personal data GDPR: Article 12: Transparent information, communication and modalities for the exercise of the rights of the data subject GDPR: Article 13: Information to be provided where personal data is collected from the data subject GDPR: Article 15: Right of access by the data subject GDPR: Article 24: Responsibility of the controller GDPR: Article 31 Cooperation with the Supervisory Authority Decision
  • Read more about Greek SA: Imposition of fine on association for transmission of sensitive data, failure to facilitate right of access and lack of cooperation with the SA

Swedish SA: Administrative fine against two companies in the SL Group

Thu, 07/17/2025
Background information Date of final decision: 18 June 2025 National case Controller: the SL Group Legal Reference (s): Article 6 (Lawfulness of processing), Article 9 (Processing of special categories of personal data), Article 83 (General conditions for imposing administrative fines) Decision: Administrative fine Key words: Personal data breach, Sensitive data, Administrative fine, Data retention, Retention time Summary of the Decision Origin of the case The Swedish Supervisory Authority (SA), IMY has reviewed two complaints from employees that had been subject to sobriety tests during their
  • Read more about Swedish SA: Administrative fine against two companies in the SL Group

Biometrics for attendance recording. The Italian SA fines a high school

Tue, 07/15/2025
Background information Date of final decision: 27 March 2025 National case Controller: Istituto di Istruzione Superiore “P. Galluppi” Tropea Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 6 (Lawfulness of processing), Article 9 (Processing of special categories of personal data) Decision: Administrative fine Key words: Administrative fine, Consent, Lawfulness of processing, Biometrics, Public administration Summary of the Decision Origin of the case Following a complaint, the Italian Supervisory Authority (SA) - Garante found out that a high school
  • Read more about Biometrics for attendance recording. The Italian SA fines a high school

The Italian SA imposes fines of 420 000 EUR on Autostrade per l’Italia spa

Tue, 07/15/2025
Background information Date of final decision: 21 May 2025 National case Controller: Autostrade per l’Italia spa Legal Reference(s): Article 5 (Principles relating to processing of personal data), Article 6 (Lawfulness of processing), Article 88 Decision: Administrative fine Key words: Administrative fine, Consent, Lawfulness of processing, Unsolicited communication Summary of the Decision Origin of the case The Italian Supervisory Authority (SA) - Garante action followed the complaint of an employee who had reported the company's use of content extracted from her Facebook profile and private
  • Read more about The Italian SA imposes fines of 420 000 EUR on Autostrade per l’Italia spa

Swedish SA: Administrative fine against the Equality Ombudsman when personal data was collected via a web form

Tue, 07/15/2025
Background information Date of final decision: 23 April 2025 National case Controller: the Equality Ombudsman (DO) Legal Reference (s): Article 32 (Security of processing), Article 83 (General conditions for imposing administrative fines) Decision: administrative fine Key words: administrative fine, data security, restriction of processing, personal data breach, public administration, sensitive data Summary of the Decision Origin of the case The Equality Ombudsman (DO), the Swedish agency to promote equal rights and opportunities and to combat discrimination, has reported a personal data
  • Read more about Swedish SA: Administrative fine against the Equality Ombudsman when personal data was collected via a web form

Targeted modifications of the GDPR: EDPB & EDPS welcome simplification of record keeping obligations and request further clarifications

Wed, 07/09/2025
Brussels, 9 July 2025 - The European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) issued today a Joint Opinion on the European Commission’s Proposal for a Regulation amending certain regulations, including the GDPR. The Proposal, part of the fourth simplification Omnibus, aims to simplify EU rules and reduce administrative burden, extending certain mitigating measures available for small and medium sized enterprises (SMEs) to small mid-cap enterprises (SMCs), and includes further simplification measures. The Proposal aims to modify Art.30 (5) GDPR, providing a
  • Read more about Targeted modifications of the GDPR: EDPB & EDPS welcome simplification of record keeping obligations and request further clarifications

Irish Supervisory Authority fines TikTok €530 million and orders corrective measures following Inquiry into transfers of EEA User Data to China

Fri, 07/04/2025
Background information Date of final decision: 2 May 2025 Cross-border LSA: Ireland CSAs: all SAs Controller: TikTok Technology Limited Legal Reference (s): Article 13 (Information to be provided where personal data are collected from the data subject), Article 46 (Transfers by way of appropriate safeguards) Decision: Administrative fine, Compliance order Key words: Administrative fine, Social media, Transparency Summary of the Decision Origin of the case The Irish Supervisory Authority (SA) announced its final decision following an Inquiry into TikTok Technology Limited (“TikTok”). The
  • Read more about Irish Supervisory Authority fines TikTok €530 million and orders corrective measures following Inquiry into transfers of EEA User Data to China

The Helsinki Statement on enhanced clarity, support and engagement

Thu, 07/03/2025
A fundamental rights approach to innovation and competitiveness Helsinki, 3 July 2025 – At a high-level meeting in Helsinki on 1–2 July 2025, the European Data Protection Board (EDPB) adopted a landmark Statement on enhanced clarity, support and engagement. The Statement outlines new initiatives to make GDPR compliance easier, in particular for micro, small and medium organisations, strengthen consistency and boost cross-regulatory cooperation. EDPB Chair Anu Talus said: “The EDPB aims to ensure that compliance with the GDPR can be more easily achieved. By placing fundamental rights into the
  • Read more about The Helsinki Statement on enhanced clarity, support and engagement

Irish SA announces conclusion of investigation into use of facial matching technology in connection with the Public Services Card by the Irish Department of Social Protection

Wed, 07/02/2025
Background information Date of final decision: 12 June 2025 National case Controller: Department of Social Protection’s (DSP) Legal Reference (s): Article 5 (Principles relating to processing of personal data), Article 6 (Lawfulness of processing), Article 9 (Processing of special categories of personal data), Article 13 (Information to be provided where personal data are collected from the data subject), Article 35 (Data protection impact assessment) Decision: Administrative fine, Compliance order and Reprimand Key words: Lawfulness of processing, Sensitive data, Biometrics Summary of the
  • Read more about Irish SA announces conclusion of investigation into use of facial matching technology in connection with the Public Services Card by the Irish Department of Social Protection

Pagination

  • First page « First
  • Previous page ‹ Previous
  • …
  • Page 17
  • Page 18
  • Page 19
  • Page 20
  • Page 21
  • Page 22
  • Page 23
  • Page 24
  • Page 25
  • …
  • Next page Next ›
  • Last page Last »
Subscribe to
European Data Protection Board logo

Footer mainnavigation

  • Main menu items
    • Topics
    • Documents
    • Registers
    • Consultations
    • News
    • Meetings
  • About us menu items
    • Task and duties
    • Our members
    • EDPB Secretariat
    • Strategy and work programme
    • Legacy: Art. 29 Working Party

Footer

  • Career opportunities
  • Copyright
  • Cookies
  • General Data Protection Notice
  • Public access to documents
Coordinated Supervision Committee
The CSC ensures the coordinated supervision by data protection authorities.
CSC
Logo of Linkedin Logo of X
×

We use cookies

When you visit our website, if you give your consent, we will use cookies to allow us to collect data for aggregated statistics to improve our services and remember your choice for future visits.
If you don't want this, we will only use cookies to remember your choice for future visits (i.e., essential cookies).
If you don't select any of the two options, no cookies will be deployed, but the banner will re-appear every time you enter our website.
More information on cookies and data protection.