Article 25 GDPR — enforcement
Cited in 206 decisions · €920.8M total fines · median €50,000 · top authority: 🇪🇺Italian Data Protection Authority (Garante) (69)
| Date ↓ | Company / party | Authority | Articles | Fine |
|---|---|---|---|---|
| 2025-04-29 | MA Immobiliare S.r.l.s. Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 7Art. 12 | €40,000 |
| 2025-04-29 | Versilmagra Immobiliare di Robertelli Davide & C. S.a.s. Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 7Art. 12 | €2,000 |
| 2025-04-29 | Versilmagra Immobiliare di Robertelli Davide & C. S.a.s. Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 7Art. 12 | €2,000 |
| 2025-04-22 | Company Non-compliance with general data processing principles | 🇪🇺 Belgian Data Protection Authority (APD) | Art. 5Art. 6Art. 12Art. 14 | €20,000 |
| 2025-04-22 | Company Non-compliance with general data processing principles | 🇪🇺 Belgian Data Protection Authority (APD) | Art. 5Art. 6Art. 12Art. 14 | €20,000 |
| 2025-04-10 | Luka Inc. Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 12Art. 13 | €5,000,000 |
| 2025-04-10 | Luka Inc. Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 12Art. 13 | €5,000,000 |
| 2025-04-10 | Acea Energia S.p.A. Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 7Art. 13 | €3,000,000 |
| 2025-04-10 | Acea Energia S.p.A. Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 7Art. 13 | €3,000,000 |
| 2025-04-10 | Immobiliare Valdalpone S.r.l. Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 7Art. 12 | €15,000 |
| 2025-04-10 | Immobiliare Valdalpone S.r.l. Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 7Art. 12 | €15,000 |
| 2025-04-10 | Undici S.r.l.s. Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 7Art. 12 | €8,000 |
| 2025-04-10 | Undici S.r.l.s. Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 7Art. 12 | €8,000 |
| 2025-03-24 | Hospital Non-compliance with general data processing principles | 🇪🇺 Croatian Data Protection Authority (azop) | Art. 13Art. 14Art. 25Art. 28 | €4,000 |
| 2025-03-24 | Hospital Non-compliance with general data processing principles | 🇪🇺 Croatian Data Protection Authority (azop) | Art. 13Art. 14Art. 25Art. 28 | €4,000 |
| 2025-03-13 | Azienda regionale per lo sviluppo e per i servizi in agricoltura (ARSAC) Non-compliance with general data processing principles | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 13Art. 25 | €50,000 |
| 2025-02-05 | ORANGE ESPAGNE, S.A.U. Insufficient technical and organisational measures to ensure information security | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 6Art. 25 | €1,200,000 |
| 2025-02-05 | FARMEC SA Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 25Art. 32 | €5,000 |
| 2025-02-03 | Unicredit Bank SA Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 25 | €15,000 |
| 2025-01-31 | S.P.E.E.H. HIDROELECTRICA S.A Insufficient technical and organisational measures to ensure information security | 🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 25 | €15,000 |
| 2025-01-16 | Realmaps S.r.l. Insufficient legal basis for data processing | 🇪🇺 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 7Art. 12 | €100,000 |
| 2025-01-10 | National Bank of Greece S.A Insufficient technical and organisational measures to ensure information security | 🇬🇷 Hellenic Data Protection Authority (HDPA) | Art. 5Art. 15Art. 25Art. 32 | €120,000 |
| 2024-12-17 | Sambla Group Oy Insufficient technical and organisational measures to ensure information security | 🇪🇺 Deputy Data Protection Ombudsman | Art. 5Art. 25Art. 32 | €950,000 |
| 2024-12-12 | CAIXABANK, S.A. Insufficient technical and organisational measures to ensure information security | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 25 | €3,500,000 |
| 2024-12-10 | GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS Insufficient technical and organisational measures to ensure information security | 🇪🇺 Spanish Data Protection Authority (aepd) | Art. 5Art. 25Art. 32Art. 35 | €4,000,000 |