Skip to content

Article 5 GDPR — enforcement

Cited in 1,715 decisions · €1.8B total fines · median €10,000 · top authority: 🇪🇺Spanish Data Protection Authority (aepd) (541)

Date ↓ Company / party Authority Articles Fine
2025-09-25 SERVACE S.L.
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 6 €840
2025-09-18 SAMARITAINE SAS
Non-compliance with general data processing principles
🇪🇺 French Data Protection Authority (CNIL) Art. 5Art. 33Art. 38 €100,000
2025-09-18 SAMARITAINE SAS
Non-compliance with general data processing principles
🇪🇺 French Data Protection Authority (CNIL) Art. 5Art. 33Art. 38 €100,000
2025-09-17 SERVICIOS FINANCIEROS CARREFOUR, E.F.C.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5 €1,500,000
2025-09-17 SERVICIOS FINANCIEROS CARREFOUR, E.F.C.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5 €1,500,000
2025-09-11 Comune di Nichelino
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 12Art. 16 €18,000
2025-09-11 Comune di Nichelino
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 12Art. 16 €18,000
2025-09-11 Ministry of the Interior - Department of Firefighters, Public Rescue, and Civil Defense - Provincial Command of Florence
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9 €12,000
2025-09-11 Casa di Cura Città di Roma
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 25Art. 32 €12,000
2025-09-11 Casa di Cura Città di Roma
Insufficient technical and organisational measures to ensure information security
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 9Art. 25Art. 32 €12,000
2025-09-11 Ministry of the Interior - Department of Firefighters, Public Rescue, and Civil Defense - Provincial Command of Florence
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9 €12,000
2025-09-11 Migliarino San Rossore Massaciuccoli Regional Park Authority
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 20 €8,000
2025-09-11 Migliarino San Rossore Massaciuccoli Regional Park Authority
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 20 €8,000
2025-09-11 Company
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 13 €6,000
2025-09-11 Municipality of Buccino
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 13 €6,000
2025-09-11 Company
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 13 €6,000
2025-09-11 Municipality of Buccino
Insufficient legal basis for data processing
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 9Art. 13 €6,000
2025-09-11 Giada FM S.r.l.
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 12Art. 15 €1,000
2025-09-11 Giada FM S.r.l.
Insufficient fulfilment of data subjects rights
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 12Art. 15 €1,000
2025-09-08 S-Pankki Oyj
Insufficient technical and organisational measures to ensure information security
🇪🇺 Deputy Data Protection Ombudsman Art. 5Art. 25Art. 32 €1,800,000
2025-09-08 S-Pankki Oyj
Insufficient technical and organisational measures to ensure information security
🇪🇺 Deputy Data Protection Ombudsman Art. 5Art. 25Art. 32 €1,800,000
2025-09-05 Bakery Chain
Non-compliance with general data processing principles
🇪🇺 Austrian Data Protection Authority (dsb) Art. 5Art. 6 €33,500
2025-09-05 Bakery Chain
Non-compliance with general data processing principles
🇪🇺 Austrian Data Protection Authority (dsb) Art. 5Art. 6 €33,500
2025-09-04 Sociedad de Gestión de Activos Procedentes de la Reestructuración Bancaria S.A.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 28 €180,000
2025-09-04 Sociedad de Gestión de Activos Procedentes de la Reestructuración Bancaria S.A.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 28 €180,000