Article 32 GDPR — enforcement
Cited in 827 decisions · €200.5B total fines · median €17,300 · top authority: 🇪🇺Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) (175)
| Date ↓ | Company / party | Authority | Articles | Fine |
|---|---|---|---|---|
| 2026-10-01 | Garante per la protezione dei dati personali (Italy) - 10297167 | 🇮🇹 Garante per la protezione dei dati personali (Italy) | Art. 51Art. 5Art. 121Art. 12 | €10,000 |
| 2026-09-23 | AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight | 🇪🇸 AEPD (Spain) | Art. 51Art. 5Art. 28Art. 32 | €750,000 |
| 2026-09-22 | IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M | 🇸🇪 IMY (Sweden) | Art. 321Art. 32 | €1,800,000 |
| 2026-09-16 | AEPD sanctions Iberdrola Clientes for improper identity verification and unauthorized | 🇪🇸 AEPD (Spain) | Art. 24Art. 32Art. 321Art. 582 | €1,000,000 |
| 2026-09-16 | ANSPDCP (Romania) - Fine against Homelux SRL | 🇷🇴 ANSPDCP (Romania) | Art. 321Art. 32Art. 322 | €108,570 |
| 2026-09-16 | Italian DPA probes University Health Agency Friuli over EHR access and missing logs | 🇮🇹 Garante per la protezione dei dati personali (Italy) | Art. 51Art. 5Art. 51Art. 51 | €24,000 |
| 2026-09-16 | Italian DPA: Municipality of Rieti breached GDPR by publishing 31,000 taxpayers' waste | 🇮🇹 Garante per la protezione dei dati personali (Italy) | Art. 51Art. 5Art. 51Art. 51 | €6,000 |
| 2026-09-08 | ANSPDCP (Romania) - Fine against GEROCOSSEN S.R.L. | 🇷🇴 ANSPDCP (Romania) | Art. 321Art. 32Art. 322 | €26,236 |
| 2026-09-03 | Friuli Centrale University Health Authority Insufficient technical and organisational measures to ensure information security | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 9Art. 25Art. 32 | €24,000 |
| 2026-09-01 | Slovenian DPA fines controller €5,320 for leaving employee personal data documents | 🇸🇮 IP (Slovenia) | Art. 51Art. 5Art. 32 | €5,320 |
| 2026-08-28 | GEROCOSSEN S.R.L. Insufficient technical and organisational measures to ensure information security | 🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €5,000 |
| 2026-08-21 | ANSPDCP (Romania) - Fine against Poliserv JG (PJG) SRL | 🇷🇴 ANSPDCP (Romania) | Art. 321Art. 32Art. 322 | €15,728 |
| 2026-08-19 | Poliserv JG (PJG) SRL Insufficient technical and organisational measures to ensure information security | 🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €3,000 |
| 2026-08-19 | HDPA: Hellenic Open University found to have met breach notification duties after | 🇬🇷 HDPA (Greece) | Art. 32Art. 33Art. 34Art. 582 | — |
| 2026-08-18 | ANSPDCP (Romania) - AMATO BESTSELLER S.R.L. | 🇷🇴 ANSPDCP (Romania) | Art. 51Art. 5Art. 9Art. 324 | €285,395 |
| 2026-08-07 | ICO (UK) - ACRO Criminal Records Office | 🇬🇧 ICO (UK) | Art. 32 | — |
| 2026-08-06 | AMATO BESTSELLER S.R.L Non-compliance with general data processing principles | 🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32Art. 14Art. 5Art. 9 | €45,000 |
| 2026-07-31 | HOMELUX S.R.L Non-compliance with general data processing principles | 🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €15,000 |
| 2026-07-29 | ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026 | 🇷🇴 ANSPDCP (Romania) | Art. 251Art. 25Art. 321Art. 32 | €523,900 |
| 2026-07-28 | HDPA (Greece) - 15/2026 | 🇬🇷 HDPA (Greece) | Art. 51Art. 5Art. 283Art. 28 | €200,000,150,000 |
| 2026-07-23 | Garante per la protezione dei dati personali (Italy) - 556/2026 | 🇮🇹 Garante per la protezione dei dati personali (Italy) | Art. 52Art. 5Art. 24Art. 28 | €9,516,000 |
| 2026-07-23 | TIM S.p.A. Non-compliance with general data processing principles | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 7Art. 15 | €9,516,000 |
| 2026-07-21 | Hôpital privé de la Loire Insufficient technical and organisational measures to ensure information security | 🇫🇷 French Data Protection Authority (CNIL) | Art. 32Art. 34 | €500,000 |
| 2026-07-17 | Orange Romania SA Insufficient technical and organisational measures to ensure information security | 🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 25Art. 32 | €100,000 |
| 2026-07-14 | NIER Ingeriegna S.p.A. SB Insufficient technical and organisational measures to ensure information security | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 32 | €120,000 |
1–25 of 827 next →