2 February 2024
… request, hence the Company breached Article 12(3) of GDPR when they failed to meet the Complainant’s erasure … right to erasure according to Article 17(1)(b) of GDPR. The Company also failed to meet the requirements of … database, so the Company breached Article 25(1) of GDPR. Decision The Authority established that the Company …
22 January 2024
… order to verify the compliance with the provisions of the GDPR, and more precisely concerning the legal basis of the … that the data controller violated article 13.1.e) of the GDPR (no information about the recipients of the personal … the CNPD identified a violation of article 24.1 of the GDPR (responsibility of the data controller), as personal …
… mechanism to promote consistent application of the GDPR by European supervisory authorities: Opinions We can … issue opinions on any matter of general application of the GDPR, or any issue having an effect in more than one member … we may adopt a binding decision . Binding decisions The GDPR creates a dispute resolution system, allowing us to …
26 January 2023
… of legality, fairness and transparency (Art. 5(1)(a) of GDPR), consent of the data subject (Art. 7(2) of GDPR), direct marketing (Art. 81(1) of ECL) Decision: The … was upheld, infringements of Art. 5(1)(a) and Art. 7(2) of GDPR and Art. 81(1) ECL Summary of the Decision Origin …
20 August 2020
… the e-Privacy Directive forms lex specialis vis-à-vis the GDPR (as lex generalis), as stated in article 95 GDPR, the provisions with regard to consent of the GDPR remain applicable as preconditions for lawful …
7 December 2023
… can therefore be lawful only if it has a legal basis under GDPR Article 6(1). Where the processing also involves … the controller must have a legal basis under Article 6(1) GDPR or the processing must also comply with one of the situations set out in Article 9(2) GDPR. The reply of the Company to the request of access …
23 January 2024
… Key Findings The French SA found several breaches of the GDPR regarding: Warehouse stock and order management: … with the principle of data minimisation (Article 5.1.c GDPR). Failure to ensure lawful processing (Article 6 GDPR) by using three indicators which are illegal: the "Stow …
16 June 2022
… on certification as a tool for transfers . Art. 46(2)(f) GDPR introduces approved certification mechanisms as a new … tool for transfers - a new transfer tool introduced by the GDPR. The guidelines provide guidance on how this tool can … a dispute resolution decision on the basis of Art. 65 GDPR . The binding decision seeks to address the lack of …
29 March 2023
… Legal Reference: Data minimisation (article 5.1.c of the GDPR), Contractual framework between the controller and processors (article 28.3 of the GDPR), Inform and collect user consent before writing and … French Data Protection Act) Decision: Infringement of the GDPR, Infringement of the French Data Protection Act, …
14 April 2021
… Guidelines on the application of Article 65(1)(a) GDPR, Guidelines on the targeting of social media users and … UK adequacy decisions . Opinion 14/2021 is based on the GDPR and assesses both general data protection aspects and … draft adequacy decision. This assessment is based on the GDPR Adequacy Referential WP254 . Opinion 15/2021 is based …
25 November 2020
… decision to specify certain viewpoints, the primacy of the GDPR as EU law resulted in the decision that a priori analysed potential breaches of the GDPR. Decision of the Litigation Chamber The litigation … were not processed in a lawful way under article 6.1.f. GDPR, as there were legitimate interests for the defendants …
29 March 2021
… investigation under the General Data Protection Regulation (GDPR), in February 2021 imposed a fine for improper … for infringements of Article 32(1) (b) and (c) of the GDPR, namely failure to ensure the ongoing integrity, … to the risk, infringement of Article 32(1)(b)(c) of the GDPR, and also taking into account the factors listed in …
8 September 2021
… Legal Reference: Data retention period (Article 5.1.e GDPR), Information (Articles 13 & 14 GDPR) Decision: Fine … had failed to comply with articles 5-1-e, 13 and 14 of the GDPR. Decision Breach of Article 5-1-e of the GDPR The …
26 September 2018
… an important tool for the consistent application of the GDPR across the EU. DPIA is a process to help identify and … the types of processing which could require a DPIA, the GDPR calls for the national supervisory authorities to … and challenges of consistency in practice. The GDPR does not require full harmonisation or an 'EU list', …
10 November 2020
… first dispute resolution decision on the basis of Art. 65 GDPR. The binding decision seeks to address the dispute … draft decision with the CSAs in accordance with Art. 60 (3) GDPR. The CSAs then had four weeks to submit their RROs. … others, the CSAs issued RROs on the infringements of the GDPR identified by the LSA, the role of Twitter …
1 March 2023
… case Legal references: Article 83 (1), (2), (4) (a) GDPR (General conditions for imposing administrative fines), Article 57 (1) (a) and (h) GDPR, Article 58 (2) (e) and (i) GDPR, Article 33 (1) GDPR (Notification of a personal data …
1 July 2025
… found CDETB: Infringed Articles 5(1)(f), 32(1) and 32(2) GDPR by failing to implement appropriate technical and … the appropriate level of security, Infringed Article 33(1) GDPR by failing to notify the DPC of the breach without undue delay, Infringed Article 34(1) GDPR by failing to notify the affected data subjects of the …
30 June 2022
… (Articles 44 and 46). Decision: infringement of the GDPR; order to comply; order to suspend data flows to U.S.; … data transfers despite their being in violation of the GDPR. Key Findings: The Italian SA found that Caffeina … be transferred to the U.S. in violation of Chapter V of the GDPR, since the measures adopted by Google to supplement the …
7 December 2023
… adopted an order imposing a temporary ban under Art. 66 (1) GDPR on Meta IE and Facebook Norway AS (“Facebook Norway”) … EDPB concluded that there are ongoing infringements of the GDPR and there is an urgent need to act in light of the … found that there was an ongoing infringement of art. 6 (1) GDPR because of the inappropriate use of the legal bases of …
… Tools The principle of accountability under the GDPR requires that organisations put in place appropriate … to put in place a structured approach to their GDPR compliance efforts. These codes, prepared by business associations, of conduct operationalise GDPR obligations. The codes are approved by data protection …