Article 32 GDPR — enforcement
Cited in 827 decisions · €200.5B total fines · median €17,300 · top authority: 🇪🇺Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) (175)
| Date ↓ | Company / party | Authority | Articles | Fine |
|---|---|---|---|---|
| 2026-05-29 | Unicredit Bank SA Insufficient technical and organisational measures to ensure information security | 🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32Art. 33 | €12,000 |
| 2026-05-25 | UODO (Poland) - DKN.5131.5.2025 | 🇵🇱 UODO (Poland) | Art. 241Art. 24Art. 251Art. 25 | €21,000 |
| 2026-05-25 | District Governor of Lubartów Insufficient technical and organisational measures to ensure information security | 🇵🇱 Polish National Personal Data Protection Office (UODO) | Art. 5Art. 25Art. 28Art. 32 | €4,958 |
| 2026-05-25 | Land-surveying office Insufficient technical and organisational measures to ensure information security | 🇵🇱 Polish National Personal Data Protection Office (UODO) | Art. 28Art. 32 | €2,951 |
| 2026-05-19 | UODO (Poland) - DKN.5131.27.2023 | 🇵🇱 UODO (Poland) | Art. 51Art. 5Art. 52Art. 241 | €33,700 |
| 2026-05-14 | Monaldi-Cotugno-CTO Non-compliance with general data processing principles | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 9Art. 13Art. 25 | €15,000 |
| 2026-05-08 | Permanent TSB Insufficient technical and organisational measures to ensure information security | 🇮🇪 Data Protection Authority of Ireland | Art. 5Art. 32Art. 33 | €277,500 |
| 2026-05-07 | South Staffordshire Plc Insufficient technical and organisational measures to ensure information security | 🇬🇧 Information Commissioner (ICO) | Art. 5Art. 32 | €1,112,100 |
| 2026-05-01 | IP (Slovenia) - 0609-42/2026/7 | 🇸🇮 IP (Slovenia) | Art. 32 | €2,802 |
| 2026-04-30 | Permanent TSB plc Insufficient technical and organisational measures to ensure information security | 🇮🇪 Data Protection Authority of Ireland | Art. 5Art. 32Art. 33 | €277,500 |
| 2026-04-30 | BLUE PROJECTS INDUSTRIES S.R.L. Insufficient technical and organisational measures to ensure information security | 🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €2,500 |
| 2026-04-29 | Lepida S.c.p.A. Non-compliance with general data processing principles | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 13Art. 25Art. 32 | €100,000 |
| 2026-04-29 | Matera Local Health Authority Insufficient technical and organisational measures to ensure information security | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 32 | €8,600 |
| 2026-04-17 | Poste Italiane S.p.a. Non-compliance with general data processing principles | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 13Art. 25 | €6,624,000 |
| 2026-04-17 | Postepay S.p.a. Non-compliance with general data processing principles | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 6Art. 13Art. 25 | €5,877,000 |
| 2026-04-17 | Business Owner Insufficient legal basis for data processing | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 13Art. 32 | €2,000 |
| 2026-04-13 | Sole trader Insufficient technical and organisational measures to ensure information security | 🇵🇱 Polish National Personal Data Protection Office (UODO) | Art. 32Art. 28 | €2,415 |
| 2026-04-13 | Sub Agent Insufficient technical and organisational measures to ensure information security | 🇵🇱 Polish National Personal Data Protection Office (UODO) | Art. 28Art. 32 | €2,415 |
| 2026-04-13 | UODO reprimands electricity seller for Art. 5, 24, 25, 28, 32 GDPR violations over | 🇵🇱 UODO (Poland) | Art. 51Art. 5Art. 52Art. 241 | €2,415 |
| 2026-04-03 | BLUE PROJECTS S.R.L. Insufficient technical and organisational measures to ensure information security | 🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €2,500 |
| 2026-03-27 | Legal Person Insufficient technical and organisational measures to ensure information security | 🇸🇮 Slovenian Supervisory Authority (Informacijski pooblaščenec) | Art. 32 | €13,491 |
| 2026-03-26 | Intesa Sanpaolo S.p.A. Insufficient technical and organisational measures to ensure information security | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 24Art. 32Art. 34 | €31,800,000 |
| 2026-03-25 | RENAULT COMMERCIAL ROUMANIE S.R.L. Insufficient technical and organisational measures to ensure information security | 🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 28Art. 32 | €125,000 |
| 2026-03-23 | ING Bank NV Amsterdam – Sucursala București S.A. Insufficient technical and organisational measures to ensure information security | 🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) | Art. 32 | €4,000 |
| 2026-03-12 | Hanako s.r.l. Insufficient technical and organisational measures to ensure information security | 🇮🇹 Italian Data Protection Authority (Garante) | Art. 5Art. 13Art. 32 | €2,000 |