Skip to content

GDPR enforcement in 2025

718 decisions · €1.2B total fines · ← 2024 · 2026 →

Date ↓ Company / party Authority Articles Fine
2025-11-06 Aena, S.M.E., S.A.
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 35 €10,043,002
2025-11-06 Aena, S.M.E., S.A.
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 35 €10,043,002
2025-11-05 ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓN
Insufficient cooperation with supervisory authority
🇪🇺 Spanish Data Protection Authority (aepd) Art. 58 €750
2025-11-05 ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓN
Insufficient cooperation with supervisory authority
🇪🇺 Spanish Data Protection Authority (aepd) Art. 58 €750
2025-11-01 Municipality of Kyustendil
Insufficient legal basis for data processing
🇧🇬 Bulgarian Commission for Personal Data Protection (KZLD) €2,556
2025-10-28 SIA 'ZZ Dats'
Insufficient technical and organisational measures to ensure information security
🇪🇺 Data State Inspectorate (DSI) Art. 32 €300,000
2025-10-28 SIA 'ZZ Dats'
Insufficient technical and organisational measures to ensure information security
🇪🇺 Data State Inspectorate (DSI) Art. 32 €300,000
2025-10-28 APARELLS ORTOPEDICS CURTO, S.L
Insufficient fulfilment of data subjects rights
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5 €6,000
2025-10-28 APARELLS ORTOPEDICS CURTO, S.L
Insufficient fulfilment of data subjects rights
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5 €6,000
2025-10-27 Gynecological Center
Insufficient fulfilment of data breach notification obligations
🇪🇺 Polish National Personal Data Protection Office (UODO) €9,450
2025-10-27 Gynecological Center
Insufficient fulfilment of data breach notification obligations
🇪🇺 Polish National Personal Data Protection Office (UODO) €9,450
2025-10-27 Shop Owner
Insufficient legal basis for data processing
🇦🇹 Austrian Data Protection Authority (dsb) Art. 5Art. 6 €1,500
2025-10-23 Aktia Pankki Oyj
Insufficient technical and organisational measures to ensure information security
🇪🇺 Deputy Data Protection Ombudsman Art. 5Art. 25Art. 32 €865,000
2025-10-23 Aktia Pankki Oyj
Insufficient technical and organisational measures to ensure information security
🇪🇺 Deputy Data Protection Ombudsman Art. 5Art. 25Art. 32 €865,000
2025-10-23 Multimedia News Società Cooperativa
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 12 €20,000
2025-10-23 Multimedia News Società Cooperativa
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 12 €20,000
2025-10-23 Ordine degli Avvocati di Latina
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 10 €15,000
2025-10-23 Comune di Curtarolo
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 12Art. 13 €15,000
2025-10-23 Comune di Curtarolo
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 12Art. 13 €15,000
2025-10-23 Ordine degli Avvocati di Latina
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 10 €15,000
2025-10-23 Court Bailiff
Insufficient fulfilment of data breach notification obligations
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 33Art. 34 €5,000
2025-10-23 Court Bailiff
Insufficient fulfilment of data breach notification obligations
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 33Art. 34 €5,000
2025-10-23 'Statista Aldo Moro' Higher Education Institute in Fara Sabina
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 37 €4,000
2025-10-23 'Statista Aldo Moro' Higher Education Institute in Fara Sabina
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 37 €4,000
2025-10-23 Comune di Avola
Lack of appointment of data protection officer
🇪🇺 Italian Data Protection Authority (Garante) Art. 37 €2,000