Skip to content

GDPR enforcement in 2026

156 decisions · €267.1M total fines · ← 2025

Date ↓ Company / party Authority Articles Fine
2026-03-13 RAMÓN GRAU, S.L.
Insufficient legal basis for data processing
🇪🇸 Spanish Data Protection Authority (aepd) Art. 6Art. 13 €18,000
2026-03-13 CENTRO MEDICO REY FERNANDO, S.L.P.
Insufficient fulfilment of data subjects rights
🇪🇸 Spanish Data Protection Authority (aepd) Art. 12 €600
2026-03-13 SERVICIOS INMOBILIARIOS Y GESTIÓN RCL MADRID, S.L.
Insufficient cooperation with supervisory authority
🇪🇸 Spanish Data Protection Authority (aepd) Art. 58 €600
2026-03-13 Housing Association
Insufficient cooperation with supervisory authority
🇪🇸 Spanish Data Protection Authority (aepd) Art. 58 €450
2026-03-12 Enel Energia S.p.A.
Insufficient legal basis for data processing
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 7Art. 24 €563,052
2026-03-12 ITAS Mutua
Insufficient fulfilment of data subjects rights
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 12Art. 13Art. 15 €50,000
2026-03-12 INPS – Istituto nazionale previdenza sociale
Insufficient technical and organisational measures to ensure information security
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 10 €40,000
2026-03-12 La7 S.p.A.
Non-compliance with general data processing principles
🇮🇹 Italian Data Protection Authority (Garante) Art. 5 €40,000
2026-03-12 Comune di Sutri
Insufficient legal basis for data processing
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 6 €2,000
2026-03-12 Liceo Scientifico Morgagni di Roma
Insufficient technical and organisational measures to ensure information security
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 32 €2,000
2026-03-12 Hanako s.r.l.
Insufficient technical and organisational measures to ensure information security
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 13Art. 32 €2,000
2026-03-12 Barber Shop
Insufficient fulfilment of information obligations
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 13 €800
2026-03-11 IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA
Insufficient technical and organisational measures to ensure information security
🇪🇸 Spanish Data Protection Authority (aepd) Art. 5 €650,000
2026-03-10 CUMACA MOTOR, S.L.
Insufficient legal basis for data processing
🇪🇸 Spanish Data Protection Authority (aepd) Art. 5 €6,000
2026-03-05 Altex Romania S.R.L.
Insufficient cooperation with supervisory authority
🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 58 €8,000
2026-03-04 ARES CAPITAL, S.A.
Insufficient legal basis for data processing
🇪🇸 Spanish Data Protection Authority (aepd) Art. 5Art. 6Art. 13 €200,000
2026-03-02 HIGHCLIFFE ESTATES MARBELLA, S.L.
Insufficient legal basis for data processing
🇪🇸 Spanish Data Protection Authority (aepd) Art. 6 €8,500
2026-03-02 Suomen Numerokeskus Oy
Insufficient fulfilment of data subjects rights
🇫🇮 Deputy Data Protection Ombudsman Art. 15 €5,000
2026-03-02 MALAGASUITE SHOWROOM, S.L.
Insufficient fulfilment of data subjects rights
🇪🇸 Spanish Data Protection Authority (aepd) Art. 13 €2,000
2026-03-02 ORNITOLÓGICA DE ANDALUCÍA FOA
Non-compliance with general data processing principles
🇪🇸 Spanish Data Protection Authority (aepd) Art. 5 €900
2026-03-01 HOLY MARY CATHOLIC SCHOOL, S.L.
Insufficient legal basis for data processing
🇪🇸 Spanish Data Protection Authority (aepd) Art. 5Art. 6Art. 35 €12,000
2026-03-01 Spain DPA: Non-compliance with general data processing principles
Non-compliance with general data processing principles
🇪🇸 Spanish Data Protection Authority (aepd) Art. 5 €1,000
2026-02-26 Dedalus Italia S.p.A.
Insufficient technical and organisational measures to ensure information security
🇮🇹 Italian Data Protection Authority (Garante) Art. 32 €32,000
2026-02-26 S.M. Trattamento Acqua di XX
Insufficient legal basis for data processing
🇮🇹 Italian Data Protection Authority (Garante) Art. 4Art. 5Art. 6Art. 7 €30,000
2026-02-26 Flamel S.r.l.
Non-compliance with general data processing principles
🇮🇹 Italian Data Protection Authority (Garante) Art. 8Art. 11Art. 25Art. 39 €15,000