Knowledge Base → Enforcement → ⚖️ Enforcement & Case Law
⚖️ Enforcement & Case Law
DPA decisions, fines and court/CJEU rulings. The daily digest LEADS with these; this page organises them by ROOT CAUSE (adapted from the user’s dpaactions taxonomy) for inspection-readiness. Living record: see the daily archive and per-country folders.
Root-cause lenses
- Consent / cookies & tracking — invalid banners, cookies before consent, dark patterns → Website Privacy (e.g. SHEIN €150M, Google €150M, Amazon).
- Mobile app / SDK / advertising-ID — tracking without consent → Mobile App Privacy (e.g. Voodoo €3M, Apple €8M).
- Data breach & security failures — unencrypted email, unsecured FTP/storage, missing security testing, weak TOMs.
- Transparency & information — missing or inadequate notices (Arts 12–14; EDPB 2026 coordinated action).
- International transfers — unlawful/unassessed transfers → International Transfers · China CBDT.
- Data-subject rights — access/erasure failures (e.g. BAG Art.15 ruling).
- Profiling / scoring — credit-reference & data-broker models (e.g. CRIF, Schufa).
- Health data — → US Health Privacy / HIPAA (US) · Digital Health & DiGA (EU/CH).
🆕 Recent additions (auto)
(enforcement items also appear in the daily archive and country/topic pages)
Curated taxonomy; the living record is the daily archive + per-country/topic folders.