Skip to content

Article 32 GDPR — enforcement

Cited in 827 decisions · €200.5B total fines · median €17,300 · top authority: 🇪🇺Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) (175)

Date ↓ Company / party Authority Articles Fine
2026-10-01 Garante per la protezione dei dati personali (Italy) - 10297167 🇮🇹 Garante per la protezione dei dati personali (Italy) Art. 51Art. 5Art. 121Art. 12 €10,000
2026-09-23 AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight 🇪🇸 AEPD (Spain) Art. 51Art. 5Art. 28Art. 32 €750,000
2026-09-22 IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M 🇸🇪 IMY (Sweden) Art. 321Art. 32 €1,800,000
2026-09-16 AEPD sanctions Iberdrola Clientes for improper identity verification and unauthorized 🇪🇸 AEPD (Spain) Art. 24Art. 32Art. 321Art. 582 €1,000,000
2026-09-16 ANSPDCP (Romania) - Fine against Homelux SRL 🇷🇴 ANSPDCP (Romania) Art. 321Art. 32Art. 322 €108,570
2026-09-16 Italian DPA probes University Health Agency Friuli over EHR access and missing logs 🇮🇹 Garante per la protezione dei dati personali (Italy) Art. 51Art. 5Art. 51Art. 51 €24,000
2026-09-16 Italian DPA: Municipality of Rieti breached GDPR by publishing 31,000 taxpayers' waste 🇮🇹 Garante per la protezione dei dati personali (Italy) Art. 51Art. 5Art. 51Art. 51 €6,000
2026-09-08 ANSPDCP (Romania) - Fine against GEROCOSSEN S.R.L. 🇷🇴 ANSPDCP (Romania) Art. 321Art. 32Art. 322 €26,236
2026-09-03 Friuli Centrale University Health Authority
Insufficient technical and organisational measures to ensure information security
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 25Art. 32 €24,000
2026-09-01 Slovenian DPA fines controller €5,320 for leaving employee personal data documents 🇸🇮 IP (Slovenia) Art. 51Art. 5Art. 32 €5,320
2026-08-28 GEROCOSSEN S.R.L.
Insufficient technical and organisational measures to ensure information security
🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €5,000
2026-08-21 ANSPDCP (Romania) - Fine against Poliserv JG (PJG) SRL 🇷🇴 ANSPDCP (Romania) Art. 321Art. 32Art. 322 €15,728
2026-08-19 Poliserv JG (PJG) SRL
Insufficient technical and organisational measures to ensure information security
🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €3,000
2026-08-19 HDPA: Hellenic Open University found to have met breach notification duties after 🇬🇷 HDPA (Greece) Art. 32Art. 33Art. 34Art. 582 —
2026-08-18 ANSPDCP (Romania) - AMATO BESTSELLER S.R.L. 🇷🇴 ANSPDCP (Romania) Art. 51Art. 5Art. 9Art. 324 €285,395
2026-08-07 ICO (UK) - ACRO Criminal Records Office 🇬🇧 ICO (UK) Art. 32 —
2026-08-06 AMATO BESTSELLER S.R.L
Non-compliance with general data processing principles
🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32Art. 14Art. 5Art. 9 €45,000
2026-07-31 HOMELUX S.R.L
Non-compliance with general data processing principles
🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €15,000
2026-07-29 ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026 🇷🇴 ANSPDCP (Romania) Art. 251Art. 25Art. 321Art. 32 €523,900
2026-07-28 HDPA (Greece) - 15/2026 🇬🇷 HDPA (Greece) Art. 51Art. 5Art. 283Art. 28 €200,000,150,000
2026-07-23 Garante per la protezione dei dati personali (Italy) - 556/2026 🇮🇹 Garante per la protezione dei dati personali (Italy) Art. 52Art. 5Art. 24Art. 28 €9,516,000
2026-07-23 TIM S.p.A.
Non-compliance with general data processing principles
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 7Art. 15 €9,516,000
2026-07-21 Hôpital privé de la Loire
Insufficient technical and organisational measures to ensure information security
🇫🇷 French Data Protection Authority (CNIL) Art. 32Art. 34 €500,000
2026-07-17 Orange Romania SA
Insufficient technical and organisational measures to ensure information security
🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 25Art. 32 €100,000
2026-07-14 NIER Ingeriegna S.p.A. SB
Insufficient technical and organisational measures to ensure information security
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 32 €120,000