Skip to content

Article 25 GDPR — enforcement

Cited in 206 decisions · €920.8M total fines · median €50,000 · top authority: 🇪🇺Italian Data Protection Authority (Garante) (69)

Date ↓ Company / party Authority Articles Fine
2025-04-29 MA Immobiliare S.r.l.s.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 7Art. 12 €40,000
2025-04-29 Versilmagra Immobiliare di Robertelli Davide & C. S.a.s.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 7Art. 12 €2,000
2025-04-29 Versilmagra Immobiliare di Robertelli Davide & C. S.a.s.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 7Art. 12 €2,000
2025-04-22 Company
Non-compliance with general data processing principles
🇪🇺 Belgian Data Protection Authority (APD) Art. 5Art. 6Art. 12Art. 14 €20,000
2025-04-22 Company
Non-compliance with general data processing principles
🇪🇺 Belgian Data Protection Authority (APD) Art. 5Art. 6Art. 12Art. 14 €20,000
2025-04-10 Luka Inc.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 12Art. 13 €5,000,000
2025-04-10 Luka Inc.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 12Art. 13 €5,000,000
2025-04-10 Acea Energia S.p.A.
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 7Art. 13 €3,000,000
2025-04-10 Acea Energia S.p.A.
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 7Art. 13 €3,000,000
2025-04-10 Immobiliare Valdalpone S.r.l.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 7Art. 12 €15,000
2025-04-10 Immobiliare Valdalpone S.r.l.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 7Art. 12 €15,000
2025-04-10 Undici S.r.l.s.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 7Art. 12 €8,000
2025-04-10 Undici S.r.l.s.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 7Art. 12 €8,000
2025-03-24 Hospital
Non-compliance with general data processing principles
🇪🇺 Croatian Data Protection Authority (azop) Art. 13Art. 14Art. 25Art. 28 €4,000
2025-03-24 Hospital
Non-compliance with general data processing principles
🇪🇺 Croatian Data Protection Authority (azop) Art. 13Art. 14Art. 25Art. 28 €4,000
2025-03-13 Azienda regionale per lo sviluppo e per i servizi in agricoltura (ARSAC)
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 13Art. 25 €50,000
2025-02-05 ORANGE ESPAGNE, S.A.U.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Spanish Data Protection Authority (aepd) Art. 6Art. 25 €1,200,000
2025-02-05 FARMEC SA
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 25Art. 32 €5,000
2025-02-03 Unicredit Bank SA
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 25 €15,000
2025-01-31 S.P.E.E.H. HIDROELECTRICA S.A
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 25 €15,000
2025-01-16 Realmaps S.r.l.
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 7Art. 12 €100,000
2025-01-10 National Bank of Greece S.A
Insufficient technical and organisational measures to ensure information security
🇬🇷 Hellenic Data Protection Authority (HDPA) Art. 5Art. 15Art. 25Art. 32 €120,000
2024-12-17 Sambla Group Oy
Insufficient technical and organisational measures to ensure information security
🇪🇺 Deputy Data Protection Ombudsman Art. 5Art. 25Art. 32 €950,000
2024-12-12 CAIXABANK, S.A.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 25 €3,500,000
2024-12-10 GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS
Insufficient technical and organisational measures to ensure information security
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 25Art. 32Art. 35 €4,000,000