๐ธ๐ช Sweden: breathalyser tests
Retention & Minimisation, Legal basis | 30/06/2025
๐ณ๏ธ๐ซง When daily breath tests sink GDPR compliance: the WÅAB case (Sweden)

Regulator: IMY (Swedish DPA)Source: IMY-2024-1520, 18 June 2025

๐ The facts...
Read more
๐ซ๐ท Penalty amounts
Tools & Documentation | 26/06/2025
โ๏ธ 1. CNIL Penalties๐ No obligation to reveal how fines are calculated“The CNIL must state the legal and factual grounds for a sanction, but it is not...
Read more
๐ฎ๐น OPT-OUT / Penalty
Data Subject Rights | 26/06/2025
๐ฎ๐น Italy - ๐ Estate agency penalised for unwanted calls ๐ A reminder: a single complaint can trigger an inspection!

Regulator: Il Garante (GPDP) Sour...
Read more
โ Delay in processing requests for access rights
Data Subject Rights | 26/06/2025
๐ When emails sent to the DPO are identified as SPAM!

Regulator: CNPD, Luxembourg Source: Deliberation no. 1FR/2025 of 6 January 2025

๐ฆ Response tim...
Read more
๐ฆ Penalty: vulnerabilities identified by unpatched pentests
Cybersecurity | 26/06/2025
๐จ Spain, a French supermarket chain sanctioned: For failing to correct all the flaws identified by the pentests.

Regulator : AEPD Source : ps-00128-2...
Read more
Video surveillance: Use without authorization
Biometrics & Video Surveillance, Confidentiality & Security | 05/05/2025
Source : PS 0345-2024

๐ฏ Context: A supermarket customer complains about a refund error. An employee shows her the CCTV footage captured on her mobil...
Read more
๐ฃ A lack of confidentiality
Confidentiality & Security | 28/04/2025
๐ Confidentiality broken in an internal investigation protocol = €120,000 fine.

Source: PS 0505-2024 The Spanish regulator, AEPD has fined a company...
Read more
๐ฆ Bank and Access
Confidentiality & Security | 08/04/2025
Source : PS/00477/2023

· A bank allowed unauthorized access to a joint bank account by a third party (the mother of one of the holders), withou...
Read more
๐ Data Deletion Not Effectively Implemented
Legal basis | 08/04/2025
๐ Data Blocking and Deletion : Breach of Article 32 of the LOPDGDD Source :PS-00176-2024 The AEPD imposed a €20,000 fine (reduced to €16,000 for e...
Read more
๐Cookies and Commercial Prospecting ๐ซ๐ท
Cookies & Trackers | 04/04/2025
๐ฑ๐ช €50 Million Fine for a French Telecom Operator ๐ฑ๐ช

On November 14, 2024, the CNIL imposed a €50 million fine on a French telecom operator for displ...
Read more
๐ซ๐ฎ Costly negligence and security
Confidentiality & Security | 30/03/2025
๐ Personal data & security A loan comparator ๐
On December 17, 2024, the Finnish Data Protection Authority fined a loan comparator €950,000 for secu...
Read more
๐ข GDPR & Rental
Retention & Minimisation, Confidentiality & Security | 30/03/2025
โ No ID documents via WhatsApp or Email

When a rental company requests ID documents via WhatsApp — including that of a minor!

Source: PS 00175-2023S...
Read more