McDonald’s Hit with a €4 Million GDPR Fine: How Secure Are Your Vendors?

mcdonalds McDonald's Hit with a €4 Million GDPR Fine: How Secure Are Your Vendors? Ihr externer Datenschutzbeauftragter in Berlin | sofortdatenschutz.de

The Polish Data Protection Authority (UODO) has fined McDonald’s Poland nearly €4 million (16.9 million PLN). The reason: a chain of security failures that led to a major data breach involving employee information. This case is a textbook example of how data protection responsibility can’t simply be outsourced to third-party vendors and why fundamental GDPR … Read more

€150M Fine for SHEIN: Is Your Cookie Banner a Ticking Time Bomb?

cookie shein €150M Fine for SHEIN: Is Your Cookie Banner a Ticking Time Bomb? Ihr externer Datenschutzbeauftragter in Berlin | sofortdatenschutz.de

The French data protection authority (CNIL) has made an example of the online fashion giant SHEIN, imposing a staggering €150 million fine. The reason: a systematic and severe violation of the cookie rules under the ePrivacy Directive. The ruling, dated September 1, 2025 (Case No. SAN-2025-005), is one of the highest fines ever issued for … Read more

ECJ Rules: GDPR Fines May Be Based on Entire Corporate Group’s Turnover

28 ECJ Rules: GDPR Fines May Be Based on Entire Corporate Group’s Turnover Ihr externer Datenschutzbeauftragter in Berlin | sofortdatenschutz.de

The European Court of Justice (ECJ) has ruled on whether fines for violations of the General Data Protection Regulation (GDPR) should be based on the turnover of the specific company involved or the entire corporate group. Until now, it was unclear whether only the turnover of the individual entity responsible for the violation should be … Read more

€50 Million Fine Against ORANGE for Unauthorized Advertising and Cookie Reading

EU U.S. Data Privacy Framework 2 €50 Million Fine Against ORANGE for Unauthorized Advertising and Cookie Reading Ihr externer Datenschutzbeauftragter in Berlin | sofortdatenschutz.de

The French data protection authority CNIL announced in a recent press release that a fine of €50 million has been imposed on the telecommunications provider ORANGE. The penalty was issued due to unauthorized inbox advertising and reading of cookies despite users withdrawing consent. This decision highlights the strict stance of data protection authorities against companies … Read more