filtercookiee logofiltercookiee All posts
regulation August 4, 2026 8 min read

GDPR Fines: Solar Firms & Menstruation Apps Face Privacy Scrutiny

New GDPR fines are hitting companies from solar installers to menstruation apps. Discover who's next in the privacy spotlight and what it means for your data.

The drumbeat of GDPR enforcement is growing louder, and this week, it's hitting some surprisingly diverse sectors. From solar energy firms to apps designed to track personal health, companies are learning that data privacy is not a niche concern but a fundamental operational requirement. The latest headlines highlight a solar firm losing a GDPR fight over customer background checks and a warning to menstruation apps about potential probes from data protection authorities. This surge in scrutiny around GDPR fines privacy rulings underscores a critical shift in how personal data is handled across industries.

When Solar Panels Meet Privacy Panels

PPC Land reports a solar firm recently lost a GDPR dispute related to its practice of running Schufa credit checks on customers even before site visits. While credit checks are a standard part of many transactions, the timing and scope of these checks are under increasing fire from data protection authorities. In this case, the firm’s proactive — some might say premature — data collection practices tripped a wire. It’s a stark reminder that data collection must be justifiable, proportionate, and strictly adhere to GDPR principles, particularly around the legal basis for processing.

This isn't just about large-scale data breaches; it's about the day-to-day operations of businesses and their routine interactions with customer data. Companies must be able to demonstrate why they need certain information, when they need it, and how they protect it. Ignorance, it seems, is no longer an excuse when it comes to GDPR compliance.

Period Tracking Apps: A New Front in Data Privacy Battles

Meanwhile, the Dutch data protection authority, Autoriteit Persoonsgegevens (AP), has issued a warning to menstruation apps, signaling a potential probe into their data handling practices. These apps, often used daily by millions, collect highly sensitive personal health information. While they offer convenience and insight, the commercialization and sharing of this data have long been a privacy flashpoint.

  • Sensitive Data: Menstruation apps collect intimate health details, which fall under 'special categories of personal data' in GDPR, requiring higher levels of protection and explicit consent.
  • Third-Party Sharing: Many apps, sometimes without users' full awareness, share data with advertisers, researchers, or other third parties.
  • Anonymization Claims: Even when data is ostensibly 'anonymized,' re-identification remains a concern, especially with rich datasets.

The AP's warning serves as a global signal to developers of health and wellness apps: if your business model relies on collecting and processing sensitive personal data, you will be scrutinized. Users implicitly trust these apps with their most personal details, and that trust comes with significant data protection responsibilities.

Why it matters: GDPR Fines Privacy Enforcement is Broadening

The takeaway from these recent developments is clear: GDPR enforcement is expanding beyond the usual suspects like tech giants and social media platforms. It's now reaching into seemingly unrelated sectors, holding all companies accountable for their data practices. Lexology's recent update on key compliance developments (July 20-31) further solidifies this trend, indicating a continuous and evolving regulatory landscape.

This broadening scope means that every business, regardless of size or industry, must have a robust understanding of its data processing activities and ensure compliance. The fines for non-compliance can be substantial, but perhaps more damaging is the erosion of consumer trust and reputational harm.

At FilterCookiee, we empower you to see exactly what data is being tracked on the sites you visit. Our browser extension helps you identify insecure cookies, detect hidden trackers, and understand sneaky permissions, giving you transparency in an increasingly opaque digital world. Don't just hope for privacy; actively demand it. Learn more and get ahead of the curve with more privacy news.

FAQ

What type of data is considered 'sensitive' under GDPR?

Sensitive data, or 'special categories of personal data,' includes information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for identification, health data, and data concerning a person's sex life or sexual orientation. This data requires explicit consent for processing.

Can I be fined for collecting too much data, even if I don't misuse it?

Yes, under GDPR's data minimization principle, you should only collect data that is adequate, relevant, and limited to what is necessary for the purpose for which it's processed. Collecting excessive data, even if not misused, can lead to fines because it violates this fundamental principle.

How can I check if an app or website is handling my data responsibly?

While it's difficult to know definitively, you can start by reading privacy policies, checking app permissions before installing, and using tools like FilterCookiee to inspect trackers and cookies. Look for clear consent mechanisms and transparency regarding data sharing practices.

What you can do

  1. Read Privacy Policies (Seriously): While often long, try to skim for sections on data sharing, retention, and your rights.
  2. Scrutinize App Permissions: Before installing an app, review the permissions it requests. Does a flashlight app really need access to your contacts or location?
  3. Use Privacy-Focused Tools: Employ browser extensions like FilterCookiee to block trackers, inspect cookies, and understand a website's data collection habits in real-time.
  4. Exercise Your Data Rights: Remember you have the right to access, rectify, and erase your personal data under GDPR. Don't hesitate to contact companies to exercise these rights.
  5. Be Wary of 'Free' Services: If a service is free, there's a high chance your data is the product. Understand the trade-off before handing over sensitive information.
#gdpr fines privacy#data protection#privacy regulation#menstruation apps#solar firm#sensitive data#compliance