GDPR enforcement in 2026
403 decisions · €202.4B total fines · ← 2025
| Date ↓ | Company / party | Authority | Articles | Fine |
|---|---|---|---|---|
| 2026-07-03 | Giuliano Isontina University Health Authority Insufficient technical and organisational measures to ensure information security | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 9Art. 25Art. 32 | €10,000 |
| 2026-07-03 | Municipality of San Genesio and Uniti Insufficient legal basis for data processing | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 9 | €2,000 |
| 2026-07-03 | Municipality of Villaputzu Insufficient legal basis for data processing | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 6 | €2,000 |
| 2026-07-03 | IMY (Sweden) - IMY-2024-2904 | 🇸🇪 IMY (Sweden) | Art. 13 | — |
| 2026-07-02 | Banca Transilvania S.A. Insufficient technical and organisational measures to ensure information security | 🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €5,000 |
| 2026-07-01 | Ascendex Technology SRL Insufficient fulfilment of data subjects rights | 🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 12Art. 17 | €11,000 |
| 2026-07-01 | Persónuvernd (Island) - 2025010358 | 🇮🇸 Persónuvernd (Island) | Art. 51Art. 5Art. 52Art. 321 | — |
| 2026-06-24 | Persónuvernd (Iceland) - 2025010364 | 🇮🇸 Persónuvernd (Iceland) | Art. 51Art. 5Art. 51Art. 51 | — |
| 2026-06-19 | VDAI fines medical company €450,000 for inadequate security measures in data breaches | 🇱🇹 VDAI (Lithuania) | Art. 51Art. 5Art. 241Art. 24 | €450,000 |
| 2026-06-19 | InMedica UAB Insufficient technical and organisational measures to ensure information security | 🇱🇹 Lithuanian Data Protection Authority (VDAI) | Art. 24Art. 32Art. 5 | €450,000 |
| 2026-06-19 | Estonian DPA: website republishing public authority documents independently liable under | 🇪🇪 AKI (Estonia) | Art. 52Art. 5Art. 61Art. 6 | — |
| 2026-06-18 | Garante per la protezione dei dati personali (Italy) - 476/2026 | 🇮🇹 Garante per la protezione dei dati personali (Italy) | Art. 123Art. 12Art. 17Art. 6 | €460,000 |
| 2026-06-18 | Acquirente Unico S.p.A. Insufficient fulfilment of data subjects rights | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 12Art. 16Art. 28 | €90,000 |
| 2026-06-18 | Enna Provincial Health Authority Non-compliance with general data processing principles | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 10Art. 12 | €20,000 |
| 2026-06-18 | Altex Romania S.R.L Insufficient technical and organisational measures to ensure information security | 🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32Art. 33Art. 34 | €10,000 |
| 2026-06-18 | Docplanner Italy S.r.l. Insufficient technical and organisational measures to ensure information security | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 32 | €10,000 |
| 2026-06-18 | Garante per la protezione dei dati personali (Italy) - 462/2026 | 🇮🇹 Garante per la protezione dei dati personali (Italy) | Art. 21Art. 2Art. 41Art. 4 | €6,600 |
| 2026-06-18 | Cosmint S.p.A. Non-compliance with general data processing principles | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 13 | €6,600 |
| 2026-06-18 | Garante per la protezione dei dati personali (Italy) - 457/2026 | 🇮🇹 Garante per la protezione dei dati personali (Italy) | Art. 51Art. 5Art. 51Art. 61 | €5,000 |
| 2026-06-18 | Edizioni Grandangolo di Giuseppe Castaldo Non-compliance with general data processing principles | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 12Art. 13Art. 24 | €2,075 |
| 2026-06-16 | SILVANERGIA 2022, S.L. Insufficient legal basis for data processing | 🇪🇸 Spanish Data Protection Authority (aepd) | Art. 6 | €3,000 |
| 2026-06-16 | Dormeo Home SRL Insufficient fulfilment of data subjects rights | 🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 6Art. 21 | €1,000 |
| 2026-06-15 | SSG SELECT SOLUTIONS S.R.L Insufficient technical and organisational measures to ensure information security | 🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 29Art. 32 | €2,000 |
| 2026-06-13 | Sole trader providing accounting and tax advisory services Insufficient technical and organisational measures to ensure information security | 🇵🇱 Polish National Personal Data Protection Office (UODO) | Art. 5Art. 25Art. 32 | €2,760 |
| 2026-06-13 | UODO fines accounting firm €2,760 for email breach security failures | 🇵🇱 UODO (Poland) | Art. 51Art. 5Art. 52Art. 241 | €2,760 |