Skip to content

Article 32 GDPR — enforcement

Cited in 827 decisions · €200.5B total fines · median €17,300 · top authority: 🇪🇺Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) (175)

Date ↓ Company / party Authority Articles Fine
2022-07-12 FREE SUN ENERGY S.L.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 32 €6,000
2022-07-07 E Software Concept SRL
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32Art. 58 €4,000
2022-06-30 Continental Automotive Romania SRL
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 24Art. 32 €2,000
2022-06-20 SC Interactions Marketing SRL
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €1,000
2022-06-15 S.C. Wine Point S.R.L.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €3,000
2022-06-09 Tavistock & Portman NHS Foundation Trust
Insufficient technical and organisational measures to ensure information security
🇪🇺 Information Commissioner (ICO) Art. 5Art. 32 €91,000
2022-06-03 Kaufland Romania SCS
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 29Art. 32 €2,000
2022-05-26 Azienda sanitaria universitaria Friuli Centrale
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 25Art. 32 €70,000
2022-05-26 Azienda sanitaria universitaria Friuli Occidentale
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 25Art. 32 €50,000
2022-05-24 MED LIFE S.A.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €5,000
2022-05-22 Azienda Socio Sanitaria Territoriale Dei Sette Laghi
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 32 €7,000
2022-05-12 Civilstyrelsen
Insufficient technical and organisational measures to ensure information security
🇪🇺 Danish Data Protection Authority (Datatilsynet) Art. 32Art. 33 €13,400
2022-05-12 LORIS FUEL SHOP SRL
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 29Art. 32 €1,000
2022-05-04 Bulgarian Post EAD
Insufficient technical and organisational measures to ensure information security
🇪🇺 Bulgarian Commission for Personal Data Protection (KZLD) Art. 32 €500,000
2022-05-03 City of Reykjavík
Insufficient legal basis for data processing
🇪🇺 Icelandic data protection authority ('Persónuvernd') Art. 5Art. 6Art. 32 €36,000
2022-04-28 Istituto Nazionale Assicurazione Infortuni sul Lavoro
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 32 €50,000
2022-04-26 ASST di Lodi
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 32 €1,000
2022-04-22 Political party
Insufficient technical and organisational measures to ensure information security
🇪🇺 Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) Art. 5Art. 32 €8,000
2022-04-15 DEDALUS BIOLOGIE
Insufficient technical and organisational measures to ensure information security
🇪🇺 French Data Protection Authority (CNIL) Art. 28Art. 29Art. 32 €1,500,000
2022-04-11 BASER COMERCIALIZADORA DE REFERENCIA, S.A.
Insufficient legal basis for data processing
🇪🇺 Spanish Data Protection Authority (aepd) Art. 6Art. 32 €150,000
2022-04-07 Dutch Tax and Customs Administration
Non-compliance with general data processing principles
🇪🇺 Dutch Supervisory Authority for Data Protection (AP) Art. 5Art. 6Art. 32Art. 35 €3,700,000
2022-04-07 Azienda ospedaliera di Perugia
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 13Art. 14Art. 25 €40,000
2022-04-07 Tecnomed Trento s.r.l.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 13Art. 29Art. 32 €10,000
2022-04-05 Bank of Ireland
Insufficient technical and organisational measures to ensure information security
🇪🇺 Data Protection Authority of Ireland Art. 32Art. 33Art. 34 €463,000
2022-03-28 Condor SA
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €2,000