Skip to content

Article 32 GDPR — enforcement

Cited in 827 decisions · €200.5B total fines · median €17,300 · top authority: 🇪🇺Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) (175)

Date ↓ Company / party Authority Articles Fine
2026-03-12 Hanako s.r.l.
Insufficient technical and organisational measures to ensure information security
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 13Art. 32 €2,000
2026-03-04 Slovenian DPA: Controller breached Art. 32, 15 and 34 GDPR over data breach and access 🇸🇮 IP (Slovenia) Art. 13Art. 15Art. 17Art. 32 —
2026-02-26 Dedalus Italia S.p.A.
Insufficient technical and organisational measures to ensure information security
🇮🇹 Italian Data Protection Authority (Garante) Art. 32 €32,000
2026-02-19 Your Consulting SRL
Insufficient technical and organisational measures to ensure information security
🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 25Art. 32 €3,000
2026-02-16 Slovenia DPA: Insufficient technical and organisational measures to ensure information security
Insufficient technical and organisational measures to ensure information security
🇸🇮 Slovenian Supervisory Authority (Informacijski pooblaščenec) Art. 32 €5,500
2026-02-05 DPD Polska sp. z o.o.
Insufficient data processing agreement
🇵🇱 Polish National Personal Data Protection Office (UODO) Art. 5Art. 24Art. 29Art. 32 €2,682,000
2026-02-04 GENPACT ROMANIA SRL
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €10,000
2026-02-03 FREE TECHNOLOGIES EXCOM, S.L.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Spanish Data Protection Authority (aepd) Art. 32 €10,000
2026-01-26 Sportadmin i Skandinavien AB
Insufficient technical and organisational measures to ensure information security
🇪🇺 Data Protection Authority of Sweden (Integritetsskyddsmyndigheten) Art. 32 €565,000
2026-01-22 FRANCE TRAVAIL
Insufficient technical and organisational measures to ensure information security
🇪🇺 French Data Protection Authority (CNIL) Art. 32 €5,000,000
2026-01-19 Continental Automotive Products SRL
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 5Art. 32 €15,000
2026-01-19 Continental Automotive Products SRL
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 5Art. 32 €15,000
2026-01-13 AEPD fines bank €500,000 for losing customer documents via courier service (Art. 32) 🇪🇸 Agencia Española de Protección de Datos Art. 32 €500,000
2026-01-13 PREMIER RESTAURANTS ROMANIA SRL
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 28Art. 32 €8,000
2026-01-13 PREMIER RESTAURANTS ROMANIA SRL
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 28Art. 32 €8,000
2026-01-08 FREE MOBILE
Insufficient technical and organisational measures to ensure information security
🇪🇺 French Data Protection Authority (CNIL) Art. 5Art. 32 €27,000,000
2026-01-08 FREE MOBILE
Insufficient technical and organisational measures to ensure information security
🇪🇺 French Data Protection Authority (CNIL) Art. 5Art. 32 €27,000,000
2026-01-08 FREE
Insufficient technical and organisational measures to ensure information security
🇪🇺 French Data Protection Authority (CNIL) Art. 32Art. 34 €15,000,000
2026-01-08 FREE
Insufficient technical and organisational measures to ensure information security
🇪🇺 French Data Protection Authority (CNIL) Art. 32Art. 34 €15,000,000
2025-12-31 ONE WAY PRIVATE COMPANY
Non-compliance with general data processing principles
🇪🇺 Hellenic Data Protection Authority (HDPA) Art. 5Art. 6Art. 7Art. 29 €80,000
2025-12-31 SIGMA & KAPPA IMPORTING SOCIÉTÉ ANONYME
Insufficient technical and organisational measures to ensure information security
🇪🇺 Hellenic Data Protection Authority (HDPA) Art. 32 €10,000
2025-12-31 Thessaloniki–Thessaly Gas Supply Company S.A.
Insufficient data processing agreement
🇪🇺 Hellenic Data Protection Authority (HDPA) Art. 28Art. 32 €10,000
2025-12-31 REVMA PLUS Retail S.A.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Hellenic Data Protection Authority (HDPA) Art. 32 €5,000
2025-12-30 Company
Non-compliance with general data processing principles
🇪🇺 French Data Protection Authority (CNIL) Art. 6Art. 13Art. 32Art. 35 €3,500,000
2025-12-30 Social Insurance Agency
Insufficient technical and organisational measures to ensure information security
🇪🇺 Slovak Data Protection Office Art. 32 €50,000