General Data Protection Regulation biggest fines

Google: US Tech Giant and the Record-High Fine Under the GDPR

As the General Data Protection Regulation came into force, companies that process personal data of EU citizens, are expected to comply with a stricter approach to data privacy and protection. US tech giant Google is not the exception.

French Data Protection Regulator (“CNIL“) fined US tech giant Google with a 50€ million fine. CNIL claims that Google failed to provide transparency and clarity in the way it informs users about the handling of their personal data. Also, Google failed to obtain specific consent and didn’t have set legal basis for personalised advertising. Read more on How Does GDPR Affect Direct Marketing and Profiling.

It is not the first fine to be issued under the GDPR. However, so far, it is the biggest one to be issued by the European regulator. 

LEARNING TIP:
Privacy by design. It is important to consider data protection and privacy aspects at the initial design stages of the product and services. Therefore, privacy and data protection should be embedded into the design, rather than trying to add it on later.
Records of processing activities: Under the GDPR, the company has an obligation to keep records of the processing activities of personal data under certain conditions and it is important for the company to have a clear understanding of what personal data is being processed and in what way.
Visibility and Transparency: Accountability, compliance and transparency are required for an effective and secure system. Thus, it is important to be clear about your system and the level of security it provides.

Find out more on GDPR fines.

Subscribe to our Newsletter

Your e-mail address is only used to send you our newsletter and information about the activities of GDPR Register. You can always use the unsubscribe link included in the mail.

Share on facebook
Share on google
Share on twitter
Share on linkedin
Share on pinterest
Share on print
Share on email

Latest Blog Posts

dpa gdpr

Data Protection Authorities (DPA)

Data Protection Authorities (DPA) Data Protection Authorities (DPA) are independent public authorities that supervise, through investigative and corrective powers, the application of the GDPR. They

Read More »

Zpracovává vaše společnost osobní údaje?


Zpracovávat vaše společnost osobní údaje fyzických osob, jako jsou:

  • Údaje zaměstnanců, zákazníků, uchazečů o zaměstnání nebo pacientů včetně:
    • Jméno nebo osobní identifikační číslo
    • Kontaktní údaje (e-mailová adresa, telefonní číslo, adresa)
    • Bankovní údaje, plat, údaje o pasu nebo jiné osobní údaje

 

Ar Jūsų įmonė renka ir tvarko fizinių asmenų asmens duomenis? 


Asmens duomenys gali būti:

  • Kliento, darbuotojo. paciento, kandidato į darbo vietą ir kt. 
    • Vardas ar asmens  numeris 
    • Kontaktinė informacija (el.pašto adresas, telefono numeris, adresas ir kt)
    • Banko sąskaitos  duomenys, atlyginimo dydis, paso duomenys ar bet kokia kita asmeninė informacija. 

Onko yrityksessäsi enemmän, kuin 250 työntekijää?


Kas teie ettevõte kogub ja töötleb isikuandmeid?


Kas teie ettevõte kogub ja töötleb füüsiliste isikutega seotud andmeid nagu näiteks:

Töötajate, klientide, tööle kandideerijate, patsientide:

  • Nimi, isikukood
  • E-posti aadress, telefoninumber, kodune aadress
  • Pangakontonumber, palgasumma, krediitkaardiandmed või mõnda muut tüüpi isiklikud andmed

Does your company collect any personal data?


Does your company collect and process any personal data of natural persons such as:

  • Employees, Customers, Job Applicants or Patients including:
    • Name or personal ID number
    • Contact details (Email address, Phone number, Address)
    • Bank details, Salary amounts, Passport details or any other personal data