GDPR Has Imposed Fines to Date
At the end of 2019, it should be noted that momentum in fines for violations of the GDPR has increased. Since the introduction of the GDPR in May 2018, the number of reports of data protection breaches has increased massively and some reports have resulted in significant fines.
GDPR Fines in 2019
In 2019, we saw a significantly higher rate of increase in the number of GDPR-Fines.
In January 2019, Google was fined 50 million euros by the French data protection authority, the CNIL, for violating EU data protection regulations.
In March 2019, the Danish Data Protection Authority imposed a fine of 1.2 million DKK on a taxi company, and the Polish Regulatory Authority imposed a fine of 220,000 euros for illegal data collection.
In April, the National Regulatory Authority Romania imposed a fine of 146,000 USD on Unicredit Bank S.A. for failing to implement appropriate technical and organizational measures at its local subsidiary.
In May 2019, the Lithuanian state data protection authority imposed a fine on MisterTango UAB. Fine in the amount of EUR 61,500.
In June 2019, Spain imposed a fine of 250,000 euros on the soccer league La Liga Based on its monitoring of soccer matches for piracy and its investigation into France, the real estate company Sergic was fined 400,000 euros for allowing access to its websites without user authentication.
In July 2019, some of the largest fines since the introduction of the GDPR imposed.
The UK's Information Commissioner's Office (ICO) has fined British Airways £183.4 million (£230 million) and Marriott Hotels £99.2 million (£124 million) for breaches of data protection regulations. The sanctions were the two largest imposed to date under the GDPR were imposed.
Also in July, the Netherlands imposed a fine of 460,000 euros on a Dutch hospital for lax controls over patient records. In addition, France’s CNIL imposed a fine of 180,000 euros on the company ACTIVE INSURANCES for failing to adequately protect the data of its website users.
In August 2019, a Polish retailer was fined 645,000 euros for "insufficient organizational and technical guarantees" due to the GDPR.
Also in August, a Swedish school district was penalized for using facial recognition during roll call in classrooms.
GDPR Fines in 2018
Just a few months after the GDPR took effect, the Portuguese Regulatory Authority ("CNPD") imposed a fine of EUR 400,000 on a hospital on July 17, 2018 for a violation of the GDPR.
When, in October 2018, the Austrian Data Protection Authority (DSB) imposed a fine of 4,800 euros on a small business for the unlawful installation of a CCTV camera that also recorded the public space in front of the business, it became clear for the first time that even small businesses are affected.
In November 2018, a German social media platform called Knuddels.de was fined 20,000 euros, after a data breach exposed the personal data of 330,000 users, including their passwords and email addresses. The low amount of the fine was primarily due to the company’s cooperative approach and massive investments in the Data protection by those responsible.
GDPR Fines Gain Momentum in the Third Quarter
On October 16, 2019, the joint body of the German data protection authorities, the Data protection conference (DSK), has published the model according to which it will GDPR wants to charge fines.
October also saw the first Fine of several million dollars in Germany when the Berlin Commissioner for Data Protection and Freedom of Information announced that Deutsche Wohnen AG would have to pay a fine of 14.5 million euros for failing to provide an adequate Fire Suppression Plan for the tenant information records.
On October 25, the Spanish data protection authority fined Vodafone Spain 35,000 euros for inadequate Legal basis imposed for data processing.
On October 31, the Netherlands imposed a fine of 900,000 euros on the Dutch employee insurance agency UWV for inadequate security on its online employee portal.
In October 2019, Facebook agreed to pay the fine announced by the ICO in July 2018 in relation to the Cambridge Analytica data breaches in 2015. As the measure was introduced before the GDPR the maximum possible fine the ICO could levy was £500,000. If the breaches had occurred after May 2018, the potential fine could have been significantly higher - up to 4% of Facebook's annual turnover.
In November, the Romanian National Regulatory Authority for the Processing personal data fines against four companies:
- 2,500 EUR in fines against the royal president for rejecting a request for access to personal data pursuant to Article 15 of the GDPR and for disclosing personal data without the consent of the data subjects.
- A fine of 80,000 euros against ING Bank N.V. Bucharest for failing to implement appropriate technical and organizational measures for an automated data processing system in connection with the processing of card transactions involving 225,525 customers.
- A courier service company has been fined 11,000 euros for failing to implement appropriate technical and organizational measures, which led to the loss of and unauthorized access to personal data affecting approximately 1,100 people.
- 2,000 EUR against BNP Paribas Personal Finance S.A. for failing to comply with a request for erasure within the time limit set by the GDPR.
In November, the Spanish Data Protection Agency (AEPD) imposed fines on a number of companies:
- A 1,500-euro fine imposed on Cerrajero Online for collecting personal data without a sufficient legal basis.
- 900 Euro Fine to TOTO TECNICOS24H S.L. for the collection of personal data without a sufficient legal basis.
- 3,000 euros Fine to the General Confederation of Labor for the disclosure of personal data in a mailing without Consent.
- 30,000 euros Fine Telefonica SA again for non-compliance with the general principles of data processing.
- Xfera Moviles SA was fined 60,000 euros for failing to implement technical and organizational measures (TOMs) to ensure information security.
- Corporación Radiotelevisión Española was also fined 60,000 euros for failing to implement technical and organizational measures (TOMs) to ensure information security.
The Belgian Data Protection Authority (APD) imposed a fine of 5,000 euros on a city council member and a mayor for sending out campaign mailings without a sufficient legal basis.
In November, the French CNIL imposed the second-highest fine—500,000 euros—on Futura Internationale for unsolicited calls, after several complainants received unsolicited calls even though they had explicitly informed the caller—both directly and by mail—that they did not wish to receive such calls, had failed to implement proper data transfer mechanisms, and had not cooperated with the CNIL.
In December, a series of fines and penalties were imposed, including one by the Spanish Data Protection Agency, which fined Ikea Iberica €10,000 for installing Cookies on your customers' mobile devices without their prior consent.
On December 3, the German data protection authority imposed a fine of 105,000 euros on a hospital for several breaches of the GDPR in connection with a patient mix-up during the patient's admission. This revealed structural technical and organizational deficits in the hospital's patient management.
On December 4, the Romanian Data Protection Authority imposed a fine of 20,000 euros on an airline for failing to take appropriate measures to ensure that every natural person working under its supervision, personal data processed in accordance with your instructions under the GDPR.
On December 9, the Federal Commissioner for Data Protection and Freedom of Information (BfDI), Ulrich Kelber, published a Fine 9.5 million against the telecommunications service provider 1&1 Telecom GmbH (1&1) for allegedly failing to adequately protect its customer data.
Delayed Decisions
Ireland's data protection supervisory authority, the Data Protection Commission (DPC), was due to announce in December whether WhatsApp had violated the GDPR by not informing its users clearly enough about how it uses their personal data. The decision is now expected to be available in January 2020.
In summary, it can be said that, looking back on the fines imposed to date, it is clear that GDPR has gained some momentum this year. With thousands of complaints in recent months, 2020 promises to be a very interesting year in terms of GDPR-With regard to fines.
Are you concerned about compliance with the GDPR-Guidelines? It's not too late yet.
Contact us today to find out how you can ensure your operations comply with data protection regulations in 2020.





