{"id":12387,"date":"2025-01-28T12:24:49","date_gmt":"2025-01-28T11:24:49","guid":{"rendered":"https:\/\/stage.usercentrics.com\/?post_type=knowledge&#038;p=12387"},"modified":"2025-09-26T15:57:34","modified_gmt":"2025-09-26T13:57:34","slug":"mobile-apps-and-gdpr-violations-who-has-been-fined","status":"publish","type":"knowledge","link":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/","title":{"rendered":"Mobile apps and GDPR violations: Who has been fined?"},"content":{"rendered":"\n<p>In the years since the General Data Protection Regulation (GDPR) came into force in 2018, there have been some dramatic headlines about fines levied on companies for violating its requirements.&nbsp;<\/p>\n\n\n\n<p>For the most part these headlines have involved influential tech platforms with potentially billions of users. However, organizations of all sizes have been penalized for not adequately obtaining user consent for processing personal data, not meeting the requirements of their chosen legal basis, experiencing a data breach, or other issues.<\/p>\n\n\n\n<p>Apps developers and publishers haven\u2019t been in the news as much, even though our research showed that <a href=\"https:\/\/usercentrics-poc.psapp.devpress\/apps-report\/\">90 percent of apps available in the EU<\/a> that we looked at were not compliant with the GDPR. One exception was France\u2019s data protection authority CNIL, which <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/french-dpa-cnil-fines-voodoo-apple-distribution-millions\/\">fined Apple and Voodoo Games in 2023<\/a> for using an advertising identifier without users\u2019 consent.<\/p>\n\n\n\n<p>There have been other fines levied by data protection authorities around Europe for apps\u2019 GDPR violations. That regulation and other laws do not distinguish between websites and apps with regards to compliance requirements. We take a look at several examples to explore what happened, what the penalties were, and how to do business compliantly.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-are-the-requirements-for-legal-data-processing-under-the-gdpr\">What are the requirements for legal data processing under the GDPR?<\/h2>\n\n\n\n<p>The <a href=\"https:\/\/usercentrics-poc.psapp.devgdpr\/\">GDPR<\/a> applies to organizations that process the personal data of EU residents, whether or not the company is located in the EU. That processing could be to enable apps to function, to deliver personalized advertising, or to provide analytics data to improve performance, for example.&nbsp;<\/p>\n\n\n\n<p>Companies need to abide by \u201clawfulness of processing\u201d, i.e. meet the requirements of a relevant legal basis to justify their collection and processing of personal data.<\/p>\n\n\n\n<p><a href=\"https:\/\/gdpr.eu\/article-6-how-to-process-personal-data-legally\/\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 6 GDPR<\/a> covers these six legal bases:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>explicit, informed consent from the data subject<\/li>\n\n\n\n<li>performing a contract with the data subject<\/li>\n\n\n\n<li>compliance with a legal obligation to which the data controller is subject<\/li>\n\n\n\n<li>protecting the vital interests of the data subject or of another natural person<\/li>\n\n\n\n<li>in the public interest, or if the data controller is exercising official authority<\/li>\n\n\n\n<li>legitimate interests pursued by the controller or by a third party<\/li>\n<\/ul>\n\n\n\n<p>Consent is a common choice of legal basis, though the GDPR requires user consent to be <a href=\"https:\/\/usercentrics-poc.psapp.devknowledge-hub\/7-criteria-for-a-gdpr-compliant-consent\/\">\u201cfreely given, specific, informed and unambiguous\u201d<\/a>. As we will see, this is where a number of companies have violated the law.&nbsp;<\/p>\n\n\n\n<p>Organizations are also required to collect, store, and document users\u2019 consent choices securely, and provide important information to users about data processing, their rights, and other factors.&nbsp;<\/p>\n\n\n\n<p>Meeting these requirements on a website in a way that\u2019s clear, compliant, and user-friendly can be challenging, and managing it in apps on small mobile screens elevates the challenge, especially when companies both need to comply with GDPR requirements and need access to quality data for advertising, analytics, and other purposes.&nbsp;<\/p>\n\n\n<div id=\"uc-cta_69ebaad641e4c\" class=\"uc-cta uc-cta--button uc-cta--size-7 uc-cta--primary uc-ctx--blue\">\n    <div class=\"uc-cta__inner container\">\n        <div class=\"uc-cta__content\">\n                                        <div class=\"uc-cta__heading no-default-margin\">What is mobile app consent and how can you obtain it from more users?<\/div>\n                                        <div class=\"uc-cta__description\">\n                    <p>The GDPR consent for data processing from app users the same as for website visitors. We have important tips to get consent that\u2019s privacy-compliant and user-friendly.<\/p>\n                <\/div>\n                                                                    <\/div>\n                            <div class=\"uc-cta__section\">\n                                        <a id=\"b94127ec-4481-41f9-837e-7935784072c2\" class=\"uc-button uc-button-size-m uc-button-contained  no-default-link-decoration\" href=\"\/knowledge-hub\/best-practices-for-mobile-app-consent\/\" target=\"\"><span>Learn more<\/span><\/a>                                    <\/div>\n            <\/div>\n<\/div>\n    <script type=\"module\">\n        new Uc_Cta(document.getElementById(\"uc-cta_69ebaad641e4c\"));\n    <\/script>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-who-is-responsible-for-gdpr-enforcement\">Who is responsible for GDPR enforcement?<\/h2>\n\n\n\n<p>GDPR enforcement is a collective effort across several authorities within the EU and is mainly in the hands of national Data Protection Authorities (DPA) within each EU member state. These supervisory authorities, established under <a href=\"https:\/\/gdpr.eu\/article-51-supervisory-authority-monitoring-application-of-regulation\/\" target=\"_blank\" rel=\"noreferrer noopener\">Chapter 6 GDPR<\/a>, are independent public authorities.&nbsp;<\/p>\n\n\n\n<p>They have the power to handle complaints, investigate compliance, and issue fines or other penalties for established violations. DPAs also issue guidelines and provide resources on GDPR compliance.<\/p>\n\n\n\n<p>These groups work together to ensure that the GDPR\u2019s requirements are consistently applied across the EU, and are supported by the <a href=\"https:\/\/commission.europa.eu\/law\/law-topic\/data-protection\/rules-business-and-organisations\/enforcement-and-sanctions\/enforcement\/what-european-data-protection-board-edpb_en\" target=\"_blank\" rel=\"noreferrer noopener\">European Data Protection Board (EDPB)<\/a>, which increases collaboration and cooperation among DPAs and advises on key matters of data privacy and protection.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-are-the-fines-and-penalties-for-gdpr-violations\">What are the fines and penalties for GDPR violations?<\/h2>\n\n\n\n<p>Some data privacy laws around the world provide a \u201ccure period\u201d if an organization has been found to have violated the law. This enables them to correct the issue and ensure it won\u2019t happen again while avoiding fines and other penalties.<\/p>\n\n\n\n<p>The GDPR does not require provision of a cure period, though arrangements are at the discretion of EU member countries\u2019 data protection authorities. GDPR enforcement is handled at a national level, and countries can also add their own specific data privacy and protection requirements.<\/p>\n\n\n\n<p><a href=\"https:\/\/gdpr.eu\/article-83-conditions-for-imposing-administrative-fines\/\" target=\"_blank\" rel=\"noreferrer noopener\">Art. 83 GDPR<\/a> covers penalties for violations. These include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>warnings or reprimands<\/li>\n\n\n\n<li>temporary or permanently imposed restrictions on data processing<\/li>\n\n\n\n<li>ordering the erasure of personal data<\/li>\n\n\n\n<li>suspending international data transfers to third countries<\/li>\n\n\n\n<li>imposing administrative fines<\/li>\n\n\n\n<li>imposing criminal penalties<\/li>\n<\/ul>\n\n\n\n<p>Administrative fines are probably the most well known GDPR penalty and what tends to make the headlines. There are two levels of administrative fines, depending on severity of the infraction.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-tier-one-administrative-fines\">Tier one administrative fines<\/h3>\n\n\n\n<p>The first tier of GDPR fines are most commonly used for first time or less severe infractions. They can be up to EUR 10 million or two percent of global annual revenue for the preceding financial year, whichever is higher.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-tier-two-administration-fines\">Tier two administration fines<\/h3>\n\n\n\n<p>The second tier GDPR fines are generally for repeat violators or more severe infractions. They can be up to EUR 20 million or four percent of global annual revenue for the preceding financial year, whichever is higher.<\/p>\n\n\n\n<p>The smallest GDPR fines have been \u201cthree-digit amounts\u201d. To date, as of early 2025, the largest GDPR fine has been levied on Meta, parent company of Facebook, Instagram, and WhatsApp, for EUR 1.2 billion.<\/p>\n\n\n<div id=\"uc-cta_69ebaad642a3b\" class=\"uc-cta uc-cta--button uc-cta--size-7 uc-cta--primary uc-ctx--blue\">\n    <div class=\"uc-cta__inner container\">\n        <div class=\"uc-cta__content\">\n                                        <div class=\"uc-cta__heading no-default-margin\">Get the ultimate guide to apps privacy<\/div>\n                                        <div class=\"uc-cta__description\">\n                    <p>Find out how user consent and privacy compliance influence apps, and how the Usercentrics consent management SDK can help with your automation and monetization.<\/p>\n                <\/div>\n                                                                    <\/div>\n                            <div class=\"uc-cta__section\">\n                                        <a id=\"e4cd37f5-380f-4ec2-a175-4dfb426dd508\" class=\"uc-button uc-button-size-m uc-button-contained  no-default-link-decoration\" href=\"\/knowledge-hub\/ultimate-guide-to-app-privacy\/\" target=\"\"><span>Learn more<\/span><\/a>                                    <\/div>\n            <\/div>\n<\/div>\n    <script type=\"module\">\n        new Uc_Cta(document.getElementById(\"uc-cta_69ebaad642a3b\"));\n    <\/script>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-gdpr-fines-for-app-publishers\">GDPR fines for app publishers<\/h2>\n\n\n\n<p>Over the past several years, data protection authorities around the world have increasingly turned their attention to mobile apps privacy compliance. The California Attorney General announced <a href=\"https:\/\/oag.ca.gov\/news\/press-releases\/ahead-data-privacy-day-attorney-general-bonta-focuses-mobile-applications%E2%80%99\" target=\"_blank\" rel=\"noreferrer noopener\">increased focus on mobile apps compliance<\/a> in 2023. In September 2024, France\u2019s CNIL published <a href=\"https:\/\/www.cnil.fr\/en\/mobile-applications-cnil-publishes-its-recommendations-better-privacy-protection\" target=\"_blank\" rel=\"noreferrer noopener\">recommendations to enable better privacy compliance in apps<\/a>, with increased enforcement beginning in 2025.<\/p>\n\n\n\n<p>Let\u2019s look at some notable enforcement actions that European DPAs have levied on prominent mobile apps and platforms.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-norwegian-data-protection-authority-datatilsynet-vs-grindr\">Norwegian Data Protection Authority Datatilsynet vs. Grindr<\/h3>\n\n\n\n<p>Norway\u2019s Datatilsynet <a href=\"https:\/\/www.datatilsynet.no\/en\/regulations-and-tools\/regulations\/avgjorelser-fra-datatilsynet\/2021\/gebyr-til-grindr\/\" target=\"_blank\" rel=\"noreferrer noopener\">fined social networking and online dating app Grindr<\/a> approximately EUR 6.5 million in 2021 for disclosing user data to third parties for behavioral advertising without a legal basis. The data shared included:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GPS location<\/li>\n\n\n\n<li>IP address<\/li>\n\n\n\n<li>Advertising ID<\/li>\n\n\n\n<li>Age<\/li>\n\n\n\n<li>Gender<\/li>\n\n\n\n<li>Status as a Grindr user<\/li>\n<\/ul>\n\n\n\n<p>The DPA also considered that use of Grindr is sensitive personal information, as it strongly indicates the user\u2019s sexual orientation or preferences, which would merit additional protections under the law.<\/p>\n\n\n\n<p>The Norwegian Consumer Council filed a complaint against Grindr in 2020. The company claimed to have collected valid consent information from users to enable sharing their personal data with advertising partners.&nbsp;<\/p>\n\n\n\n<p>However, the consents were not valid as users did not have consent choices \u2014 e.g. to opt out of sharing data with third parties for advertising \u2014 and had to accept the privacy policy in its entirety to be able to use the app. Additionally, users were not properly notified about the app\u2019s sharing of personal data. Both of these issues violated the GDPR\u2019s requirements.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-italian-data-protection-authority-garante-vs-clubhouse\">Italian Data Protection Authority Garante vs. Clubhouse<\/h3>\n\n\n\n<p>In December 2022, <a href=\"https:\/\/iapp.org\/news\/b\/the-garante-fines-clubhouse-owner-2m-euros\" target=\"_blank\" rel=\"noreferrer noopener\">Italian DPA Garante fined social audio chat app Clubhouse<\/a> EUR 2 million for multiple GDPR infractions:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Lack of transparency about the use of users\u2019 personal data and information about connections among users<\/li>\n\n\n\n<li>Storage and sharing or user-generated audio without users\u2019 consent<\/li>\n\n\n\n<li>Indefinite retention periods for recordings<\/li>\n\n\n\n<li>Not identifying an accurate legal basis prior to profiling users and sharing their account information<\/li>\n<\/ul>\n\n\n\n<p>Clubhouse was also required to adopt measures to comply with the GDPR, in addition to being prohibited from further processing of personal data for marketing or profiling purposes without obtaining informed and explicit user consent.<\/p>\n\n\n\n<p>Clubhouse is owned by Alpha Exploration, which is a US company with no EU presence, however, Clubhouse services were available to users in the EU, making the app subject to GDPR compliance.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-irish-data-protection-commission-vs-whatsapp\">Irish Data Protection Commission vs. WhatsApp<\/h3>\n\n\n\n<p>Ireland\u2019s Data Protection Commission <a href=\"https:\/\/www.dataprotection.ie\/en\/news-media\/data-protection-commission-announces-conclusion-inquiry-whatsapp\" target=\"_blank\" rel=\"noreferrer noopener\">fined instant messaging and VoIP service WhatsApp<\/a> EUR 5.5 million in 2023. As noted earlier, WhatsApp\u2019s parent company is US-based Meta, which also owns Facebook and Instagram, among other platforms and services.&nbsp;<\/p>\n\n\n\n<p>WhatsApp Ireland was given six months from when the decision was handed down to bring their data processing operations into compliance with the GDPR.<\/p>\n\n\n\n<p>In advance of the GDPR coming into effect on May 25, 2018, WhatsApp Ireland updated its Terms of Service, forcing users to click \u201cagree and continue \u201c to accept the new terms to be able to access the app.&nbsp;<\/p>\n\n\n\n<p>Users were forced to accept the terms in whole and consent to processing of their personal data for security and service improvement purposes. They had no granular consent options. Declining the terms prevented users from accessing the app\u2019s services entirely. The initial complaint was filed by a German WhatsApp user.<\/p>\n\n\n\n<p>WhatsApp also didn\u2019t provide users with adequate information about the legal basis for data processing, preventing clear understanding of how their personal data was being used or shared, or for what purposes.&nbsp;<\/p>\n\n\n\n<p>WhatsApp had considered users\u2019 acceptance of the updated Terms of Service to be entering into a contract with the company. Fulfilling a contract is an acceptable legal basis under the GDPR, and the company took the position that processing users\u2019 personal data for delivering its services was necessary to perform that contract.&nbsp;<\/p>\n\n\n\n<p>The complaint, however, argued that by requiring users\u2019 acceptance of the updated Terms of Service, the company was forcing user consent, and thus consent was their legal basis, not contract fulfillment. However, the conditions of the consent invalidated it under the GDPR, as it was not adequately informed or voluntary.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-usercentrics-helps-you-stay-gdpr-compliant-and-growing-monetization\">Usercentrics helps you stay GDPR-compliant and growing monetization<\/h2>\n\n\n\n<p>Increased GDPR enforcement for apps compliance and ever more savvy users mean that it\u2019s not worth risking trying to get around data privacy requirements. Especially since there are robust, user-friendly tools like <a href=\"https:\/\/usercentrics-poc.psapp.devin-app-sdk\/\">Usercentrics App CMP<\/a> that streamline consent management. Collect consent compliantly on your apps and get the data you need to grow your monetization, without getting in your users\u2019 way.&nbsp;<\/p>\n\n\n\n<p>Usercentrics delivers an SDK that enables fast setup. Access over 2,200 pre-built legal templates for your data processing services, and use the App Scanner to seamlessly detect and integrate your vendors, SSPs, and SDKs. Our expert team is also here for you every step of the way with expert guidance and detailed documentation.<\/p>\n\n\n\n<p>Learn more about how Usercentrics can help grow your business. Check out our case study with Homa Games and how they achieved a 10% increase in Ad LTV with user consent and achieved and maintained privacy compliance.<\/p>\n\n\n<div id=\"uc-cta_69ebaad64395a\" class=\"uc-cta uc-cta--button uc-cta--size-7 uc-cta--primary uc-ctx--blue\">\n    <div class=\"uc-cta__inner container\">\n        <div class=\"uc-cta__content\">\n                                        <div class=\"uc-cta__heading no-default-margin\">Usercentrics App CMP helps you achieve privacy and monetize faster<\/div>\n                                        <div class=\"uc-cta__description\">\n                    <p>Start your no-risk free trial of our Google-certified CMP today. Learn how to simplify mobile app consent to drive performance and growth.<\/p>\n                <\/div>\n                                                                    <\/div>\n                            <div class=\"uc-cta__section\">\n                                        <a id=\"c8113fe7-3e50-40a9-ab46-e42bae7efe5c\" class=\"uc-button uc-button-size-m uc-button-contained  no-default-link-decoration\" href=\"\/in-app-sdk\/\" target=\"\"><span>Start trial <\/span><\/a>                                    <\/div>\n            <\/div>\n<\/div>\n    <script type=\"module\">\n        new Uc_Cta(document.getElementById(\"uc-cta_69ebaad64395a\"));\n    <\/script>\n","protected":false},"excerpt":{"rendered":"<p>The GDPR applies to data processing on apps just as much as for websites. But to date apps\u2019 privacy compliance has often been low. This is changing with increased enforcement and user-friendly consent management tools. We look at GDPR apps compliance and some notable fines for violations.<\/p>\n","protected":false},"featured_media":13222,"template":"","meta":{"_acf_changed":false,"editor_notices":[],"footnotes":""},"tags":[],"magazine_issue":[],"magazine_tag":[],"resource_tag":[63,11,13],"class_list":["post-12387","knowledge","type-knowledge","status-publish","has-post-thumbnail","hentry","resource_tag-legal-news","resource_tag-apps","resource_tag-regulations"],"acf":[],"yoast_head":"<title>Mobile Apps and GDPR Violations: Who Has Been Fined?<\/title>\n<meta name=\"description\" content=\"GDPR enforcement for mobile apps and games is increasing in the EU. Learn about violations, penalties, apps privacy compliance requirements, and more.\" \/>\n<meta name=\"robots\" content=\"noindex, follow\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Mobile Apps and GDPR Violations: Who Has Been Fined?\" \/>\n<meta property=\"og:description\" content=\"GDPR enforcement for mobile apps and games is increasing in the EU. Learn about violations, penalties, apps privacy compliance requirements, and more.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/\" \/>\n<meta property=\"og:site_name\" content=\"Usercentrics - US\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/usercentrics\" \/>\n<meta property=\"article:modified_time\" content=\"2025-09-26T13:57:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2025\/01\/uc_some_mobile_apps_gdpr_012625_1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Mobile apps and GDPR violations: Who has been fined?\" \/>\n<meta name=\"twitter:site\" content=\"@usercentrics\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/\",\"url\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/\",\"name\":\"Mobile Apps and GDPR Violations: Who Has Been Fined?\",\"isPartOf\":{\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2025\/01\/Mobile-apps-and-GDPR-violations-min.jpg\",\"datePublished\":\"2025-01-28T11:24:49+00:00\",\"dateModified\":\"2025-09-26T13:57:34+00:00\",\"description\":\"GDPR enforcement for mobile apps and games is increasing in the EU. Learn about violations, penalties, apps privacy compliance requirements, and more.\",\"breadcrumb\":{\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/\"}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/#primaryimage\",\"url\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2025\/01\/Mobile-apps-and-GDPR-violations-min.jpg\",\"contentUrl\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2025\/01\/Mobile-apps-and-GDPR-violations-min.jpg\",\"width\":1000,\"height\":1000,\"caption\":\"Man with a mobile phone\",\"copyrightNotice\":\"\u00a9 Copyright 2026 Usercentrics GmbH\",\"creator\":{\"@type\":\"Organization\",\"name\":\"Usercentrics GmbH\"},\"creditText\":\"Image: Usercentrics GmbH\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Resources\",\"item\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/resources\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Blog\",\"item\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Mobile apps and GDPR violations: Who has been fined?\",\"item\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/#website\",\"url\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/\",\"name\":\"Usercentrics - US\",\"description\":\"Consent Management Platform (CMP) Usercentrics\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/usercentrics-poc.psapp.dev\/us\/?s={search_term_string}\"}}],\"inLanguage\":\"en-US\"}]}<\/script>","yoast_head_json":{"title":"Mobile Apps and GDPR Violations: Who Has Been Fined?","description":"GDPR enforcement for mobile apps and games is increasing in the EU. Learn about violations, penalties, apps privacy compliance requirements, and more.","robots":{"index":"noindex","follow":"follow"},"og_locale":"en_US","og_type":"article","og_title":"Mobile Apps and GDPR Violations: Who Has Been Fined?","og_description":"GDPR enforcement for mobile apps and games is increasing in the EU. Learn about violations, penalties, apps privacy compliance requirements, and more.","og_url":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/","og_site_name":"Usercentrics - US","article_publisher":"https:\/\/www.facebook.com\/usercentrics","article_modified_time":"2025-09-26T13:57:34+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2025\/01\/uc_some_mobile_apps_gdpr_012625_1.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_title":"Mobile apps and GDPR violations: Who has been fined?","twitter_site":"@usercentrics","twitter_misc":{"Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/","url":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/","name":"Mobile Apps and GDPR Violations: Who Has Been Fined?","isPartOf":{"@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/#website"},"primaryImageOfPage":{"@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/#primaryimage"},"image":{"@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/#primaryimage"},"thumbnailUrl":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2025\/01\/Mobile-apps-and-GDPR-violations-min.jpg","datePublished":"2025-01-28T11:24:49+00:00","dateModified":"2025-09-26T13:57:34+00:00","description":"GDPR enforcement for mobile apps and games is increasing in the EU. Learn about violations, penalties, apps privacy compliance requirements, and more.","breadcrumb":{"@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/"}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/#primaryimage","url":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2025\/01\/Mobile-apps-and-GDPR-violations-min.jpg","contentUrl":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-content\/uploads\/sites\/7\/2025\/01\/Mobile-apps-and-GDPR-violations-min.jpg","width":1000,"height":1000,"caption":"Man with a mobile phone","copyrightNotice":"\u00a9 Copyright 2026 Usercentrics GmbH","creator":{"@type":"Organization","name":"Usercentrics GmbH"},"creditText":"Image: Usercentrics GmbH"},{"@type":"BreadcrumbList","@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Resources","item":"https:\/\/usercentrics-poc.psapp.dev\/us\/resources\/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/"},{"@type":"ListItem","position":3,"name":"Mobile apps and GDPR violations: Who has been fined?","item":"https:\/\/usercentrics-poc.psapp.dev\/us\/knowledge-hub\/mobile-apps-and-gdpr-violations-who-has-been-fined\/"}]},{"@type":"WebSite","@id":"https:\/\/usercentrics-poc.psapp.dev\/us\/#website","url":"https:\/\/usercentrics-poc.psapp.dev\/us\/","name":"Usercentrics - US","description":"Consent Management Platform (CMP) Usercentrics","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/usercentrics-poc.psapp.dev\/us\/?s={search_term_string}"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/knowledge\/12387","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/knowledge"}],"about":[{"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/types\/knowledge"}],"version-history":[{"count":0,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/knowledge\/12387\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/media\/13222"}],"wp:attachment":[{"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/media?parent=12387"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/tags?post=12387"},{"taxonomy":"magazine_issue","embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/magazine_issue?post=12387"},{"taxonomy":"magazine_tag","embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/magazine_tag?post=12387"},{"taxonomy":"resource_tag","embeddable":true,"href":"https:\/\/usercentrics-poc.psapp.dev\/us\/wp-json\/wp\/v2\/resource_tag?post=12387"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}