GDPR enforcement in 2025
718 decisions · €1.2B total fines · ← 2024 · 2026 →
| Date ↓ | Company / party | Authority | Articles | Fine |
|---|---|---|---|---|
| 2025-10-23 | Comune di Avola Lack of appointment of data protection officer | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 37 | €2,000 |
| 2025-10-23 | Mayor of the Municipality of Calvi Risorta Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 9 | €1,000 |
| 2025-10-23 | Mayor of the Municipality of Calvi Risorta Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 9 | €1,000 |
| 2025-10-22 | SENDING TRANSPORTE Y COMUNICACIÓN, S.A. Insufficient data processing agreement | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 28 | €80,000 |
| 2025-10-22 | SENDING TRANSPORTE Y COMUNICACIÓN, S.A. Insufficient data processing agreement | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 28 | €80,000 |
| 2025-10-22 | Agency for Control of Outstanding Debts S.R.L. Insufficient fulfilment of data subjects rights | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 12Art. 15 | €2,000 |
| 2025-10-22 | Agency for Control of Outstanding Debts S.R.L. Insufficient fulfilment of data subjects rights | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 12Art. 15 | €2,000 |
| 2025-10-20 | S.P.E.E.H. HIDROELECTRICA SA Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €5,000 |
| 2025-10-20 | S.P.E.E.H. HIDROELECTRICA SA Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €5,000 |
| 2025-10-16 | Experian Nederland B.V. Insufficient legal basis for data processing | 🇪🇺 Dutch Supervisory Authority for Data Protection (AP) | Art. 5Art. 6Art. 12Art. 14 | €2,700,000 |
| 2025-10-16 | Experian Nederland B.V. Insufficient legal basis for data processing | 🇪🇺 Dutch Supervisory Authority for Data Protection (AP) | Art. 5Art. 6Art. 12Art. 14 | €2,700,000 |
| 2025-10-16 | PRIME TRANSACTION SA Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €2,000 |
| 2025-10-16 | PRIME TRANSACTION SA Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €2,000 |
| 2025-10-15 | CAPITA PLC Insufficient technical and organisational measures to ensure information security | 🇪🇺 Information Commissioner (ICO) | Art. 5Art. 32 | €9,180,000 |
| 2025-10-15 | CAPITA PLC Insufficient technical and organisational measures to ensure information security | 🇪🇺 Information Commissioner (ICO) | Art. 5Art. 32 | €9,180,000 |
| 2025-10-15 | CAPITA PENSION SOLUTIONS LIMITED Insufficient technical and organisational measures to ensure information security | 🇪🇺 Information Commissioner (ICO) | Art. 32 | €6,880,000 |
| 2025-10-15 | CAPITA PENSION SOLUTIONS LIMITED Insufficient technical and organisational measures to ensure information security | 🇪🇺 Information Commissioner (ICO) | Art. 32 | €6,880,000 |
| 2025-10-13 | Vellea Home SRL Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €5,000 |
| 2025-10-13 | Vellea Home SRL Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €5,000 |
| 2025-10-09 | EON ENERGIE ROMANIA S.A. Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €25,000 |
| 2025-10-09 | EON ENERGIE ROMANIA S.A. Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €25,000 |
| 2025-10-09 | Order of Nursing Professions of Pisa Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6 | €16,000 |
| 2025-10-09 | Order of Nursing Professions of Pisa Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6 | €16,000 |
| 2025-10-09 | Municipality of Moschato–Tavros Insufficient legal basis for data processing | 🇪🇺 Hellenic Data Protection Authority (HDPA) | Art. 5Art. 12Art. 13Art. 25 | €10,000 |
| 2025-10-09 | Municipality of Moschato–Tavros Insufficient legal basis for data processing | 🇪🇺 Hellenic Data Protection Authority (HDPA) | Art. 5Art. 12Art. 13Art. 25 | €10,000 |