Skip to content

Article 34 GDPR — enforcement

Cited in 68 decisions · €84.0M total fines · median €26,350 · top authority: 🇪🇺Polish National Personal Data Protection Office (UODO) (24)

Date ↓ Company / party Authority Articles Fine
2026-09-16 Italian DPA: Municipality of Rieti breached GDPR by publishing 31,000 taxpayers' waste 🇮🇹 Garante per la protezione dei dati personali (Italy) Art. 51Art. 5Art. 51Art. 51 €6,000
2026-08-19 HDPA: Hellenic Open University found to have met breach notification duties after 🇬🇷 HDPA (Greece) Art. 32Art. 33Art. 34Art. 582 —
2026-07-21 Hôpital privé de la Loire
Insufficient technical and organisational measures to ensure information security
🇫🇷 French Data Protection Authority (CNIL) Art. 32Art. 34 €500,000
2026-07-14 Municipality of Rieti
Non-compliance with general data processing principles
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 12Art. 24Art. 25 €6,000
2026-06-18 Altex Romania S.R.L
Insufficient technical and organisational measures to ensure information security
🇷🇴 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32Art. 33Art. 34 €10,000
2026-06-11 Midlands Regional Hospital Tullamore, County Offaly
Insufficient technical and organisational measures to ensure information security
🇮🇪 Data Protection Authority of Ireland Art. 5Art. 28Art. 30Art. 32 €300,000
2026-05-19 UODO (Poland) - DKN.5131.27.2023 🇵🇱 UODO (Poland) Art. 51Art. 5Art. 52Art. 241 €33,700
2026-03-26 Intesa Sanpaolo S.p.A.
Insufficient technical and organisational measures to ensure information security
🇮🇹 Italian Data Protection Authority (Garante) Art. 5Art. 24Art. 32Art. 34 €31,800,000
2026-03-04 Slovenian DPA: Controller breached Art. 32, 15 and 34 GDPR over data breach and access 🇸🇮 IP (Slovenia) Art. 13Art. 15Art. 17Art. 32 —
2026-02-10 Fundację Lumus
Non-compliance with general data processing principles
🇵🇱 Polish National Personal Data Protection Office (UODO) Art. 33Art. 34Art. 37Art. 38 €5,220
2026-01-08 FREE
Insufficient technical and organisational measures to ensure information security
🇪🇺 French Data Protection Authority (CNIL) Art. 32Art. 34 €15,000,000
2026-01-08 FREE
Insufficient technical and organisational measures to ensure information security
🇪🇺 French Data Protection Authority (CNIL) Art. 32Art. 34 €15,000,000
2025-12-10 University of Limerick
Insufficient technical and organisational measures to ensure information security
🇮🇪 Data Protection Authority of Ireland Art. 5Art. 30Art. 32Art. 33 €98,000
2025-11-28 SPRINTER MEGACENTROS DEL DEPORTE, S.L.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 34 €1,560,000
2025-11-28 SPRINTER MEGACENTROS DEL DEPORTE, S.L.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 34 €1,560,000
2025-10-23 Court Bailiff
Insufficient fulfilment of data breach notification obligations
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 33Art. 34 €5,000
2025-10-23 Court Bailiff
Insufficient fulfilment of data breach notification obligations
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 33Art. 34 €5,000
2025-07-21 Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Hellenic Data Protection Authority (HDPA) Art. 5Art. 25Art. 32Art. 33 €9,000
2025-07-21 Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Hellenic Data Protection Authority (HDPA) Art. 5Art. 25Art. 32Art. 33 €9,000
2025-06-23 City of Dublin Education and Training Board
Insufficient technical and organisational measures to ensure information security
🇪🇺 Data Protection Authority of Ireland Art. 5Art. 32Art. 33Art. 34 €125,000
2025-06-23 City of Dublin Education and Training Board
Insufficient technical and organisational measures to ensure information security
🇪🇺 Data Protection Authority of Ireland Art. 5Art. 32Art. 33Art. 34 €125,000
2025-03-24 Hospital
Insufficient technical and organisational measures to ensure information security
🇪🇺 Croatian Data Protection Authority (azop) Art. 13Art. 32Art. 33Art. 34 €3,000
2025-03-14 CENTROS COMERCIALES CARREFOUR, S.A.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 32Art. 34 €3,200,000
2025-01-10 National Bank of Greece S.A
Insufficient technical and organisational measures to ensure information security
🇬🇷 Hellenic Data Protection Authority (HDPA) Art. 5Art. 15Art. 25Art. 32 €120,000
2024-11-26 Hospital
Insufficient fulfilment of data breach notification obligations
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 33Art. 34 €6,900