Skip to content

Article 32 GDPR — enforcement

Cited in 827 decisions · €200.5B total fines · median €17,300 · top authority: 🇪🇺Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) (175)

Date ↓ Company / party Authority Articles Fine
2026-05-29 Unicredit Bank SA
Insufficient technical and organisational measures to ensure information security
🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32Art. 33 €12,000
2026-05-25 UODO (Poland) - DKN.5131.5.2025 🇵🇱 UODO (Poland) Art. 241Art. 24Art. 251Art. 25 €21,000
2026-05-25 District Governor of Lubartów
Insufficient technical and organisational measures to ensure information security
🇵🇱 Polish National Personal Data Protection Office (UODO) Art. 5Art. 25Art. 28Art. 32 €4,958
2026-05-25 Land-surveying office
Insufficient technical and organisational measures to ensure information security
🇵🇱 Polish National Personal Data Protection Office (UODO) Art. 28Art. 32 €2,951
2026-05-19 UODO (Poland) - DKN.5131.27.2023 🇵🇱 UODO (Poland) Art. 51Art. 5Art. 52Art. 241 €33,700
2026-05-14 Monaldi-Cotugno-CTO
Non-compliance with general data processing principles
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 13Art. 25 €15,000
2026-05-08 Permanent TSB
Insufficient technical and organisational measures to ensure information security
🇮🇪 Data Protection Authority of Ireland Art. 5Art. 32Art. 33 €277,500
2026-05-07 South Staffordshire Plc
Insufficient technical and organisational measures to ensure information security
🇬🇧 Information Commissioner (ICO) Art. 5Art. 32 €1,112,100
2026-05-01 IP (Slovenia) - 0609-42/2026/7 🇸🇮 IP (Slovenia) Art. 32 €2,802
2026-04-30 Permanent TSB plc
Insufficient technical and organisational measures to ensure information security
🇮🇪 Data Protection Authority of Ireland Art. 5Art. 32Art. 33 €277,500
2026-04-30 BLUE PROJECTS INDUSTRIES S.R.L.
Insufficient technical and organisational measures to ensure information security
🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €2,500
2026-04-29 Lepida S.c.p.A.
Non-compliance with general data processing principles
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 13Art. 25Art. 32 €100,000
2026-04-29 Matera Local Health Authority
Insufficient technical and organisational measures to ensure information security
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 32 €8,600
2026-04-17 Poste Italiane S.p.a.
Non-compliance with general data processing principles
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 13Art. 25 €6,624,000
2026-04-17 Postepay S.p.a.
Non-compliance with general data processing principles
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 13Art. 25 €5,877,000
2026-04-17 Business Owner
Insufficient legal basis for data processing
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 13Art. 32 €2,000
2026-04-13 Sole trader
Insufficient technical and organisational measures to ensure information security
🇵🇱 Polish National Personal Data Protection Office (UODO) Art. 32Art. 28 €2,415
2026-04-13 Sub Agent
Insufficient technical and organisational measures to ensure information security
🇵🇱 Polish National Personal Data Protection Office (UODO) Art. 28Art. 32 €2,415
2026-04-13 UODO reprimands electricity seller for Art. 5, 24, 25, 28, 32 GDPR violations over 🇵🇱 UODO (Poland) Art. 51Art. 5Art. 52Art. 241 €2,415
2026-04-03 BLUE PROJECTS S.R.L.
Insufficient technical and organisational measures to ensure information security
🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €2,500
2026-03-27 Legal Person
Insufficient technical and organisational measures to ensure information security
🇸🇮 Slovenian Supervisory Authority (Informacijski pooblaščenec) Art. 32 €13,491
2026-03-26 Intesa Sanpaolo S.p.A.
Insufficient technical and organisational measures to ensure information security
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 24Art. 32Art. 34 €31,800,000
2026-03-25 RENAULT COMMERCIAL ROUMANIE S.R.L.
Insufficient technical and organisational measures to ensure information security
🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 28Art. 32 €125,000
2026-03-23 ING Bank NV Amsterdam – Sucursala București S.A.
Insufficient technical and organisational measures to ensure information security
🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €4,000
2026-03-12 Hanako s.r.l.
Insufficient technical and organisational measures to ensure information security
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 13Art. 32 €2,000