Skip to content

Enforcement Tracker

3,481 GDPR enforcement decisions from 51 countries, updated daily.

Total fines · last 12 months
€1.3B
+878% vs previous year
Decisions · last 12 months
543
45 per month avg
Largest · last 90 days
€6.6M
Most active authority
112 decisions · SPAIN

Monthly fine totals · last 12 months

AugSepOctNovDecJanFebMarAprMayJunJul
Date ↓ Company / party Authority Articles Fine
2025-11-20 LastPass UK Ltd
Insufficient technical and organisational measures to ensure information security
🇪🇺 Information Commissioner (ICO) Art. 5Art. 32 €1,400,000
2025-11-20 LES PUBLICATIONS CONDE NAST
Non-compliance with general data processing principles
🇪🇺 French Data Protection Authority (CNIL) Art. 82 €750,000
2025-11-20 LES PUBLICATIONS CONDE NAST
Non-compliance with general data processing principles
🇪🇺 French Data Protection Authority (CNIL) Art. 82 €750,000
2025-11-19 STRATESYS TECHNOLOGY SOLUTIONS, S.L.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5 €60,000
2025-11-19 STRATESYS TECHNOLOGY SOLUTIONS, S.L.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5 €60,000
2025-11-19 Greencorp S.R.L.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €3,000
2025-11-19 Greencorp S.R.L.
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €3,000
2025-11-19 ASOCIACIÓN NACIONAL DE TASADORES Y PERITOS JUDICIALES INFORMÁTICOS
Insufficient fulfilment of data subjects rights
🇪🇺 Spanish Data Protection Authority (aepd) Art. 13Art. 17 €2,000
2025-11-19 ASOCIACIÓN NACIONAL DE TASADORES Y PERITOS JUDICIALES INFORMÁTICOS
Insufficient fulfilment of data subjects rights
🇪🇺 Spanish Data Protection Authority (aepd) Art. 13Art. 17 €2,000
2025-11-19 SOBLADA RESTAURACIÓN, S.L.
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 13 €800
2025-11-19 SOBLADA RESTAURACIÓN, S.L.
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5Art. 13 €800
2025-11-18 Journalist
Insufficient legal basis for data processing
🇪🇺 Austrian Data Protection Authority (dsb) Art. 5Art. 6 €80
2025-11-18 Journalist
Insufficient legal basis for data processing
🇪🇺 Austrian Data Protection Authority (dsb) Art. 5Art. 6 €80
2025-11-17 PGS SOFA & CO SRL
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €8,000
2025-11-17 PGS SOFA & CO SRL
Insufficient technical and organisational measures to ensure information security
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 32 €8,000
2025-11-15 Powiatowego Inspektora Sanitarnego w Policach
Insufficient technical and organisational measures to ensure information security
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 5Art. 24Art. 25Art. 32 €4,750
2025-11-15 Powiatowego Inspektora Sanitarnego w Policach
Insufficient technical and organisational measures to ensure information security
🇪🇺 Polish National Personal Data Protection Office (UODO) Art. 5Art. 24Art. 25Art. 32 €4,750
2025-11-14 AXARQUIA VELEZ DENTAL, S.L.
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5 €2,400
2025-11-14 AXARQUIA VELEZ DENTAL, S.L.
Non-compliance with general data processing principles
🇪🇺 Spanish Data Protection Authority (aepd) Art. 5 €2,400
2025-11-13 Quarantadue S.r.l.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5 €40,000
2025-11-13 Quarantadue S.r.l.
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5 €40,000
2025-11-13 Comune di Orte
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 12Art. 13 €6,000
2025-11-13 Comune di Orte
Non-compliance with general data processing principles
🇪🇺 Italian Data Protection Authority (Garante) Art. 5Art. 6Art. 12Art. 13 €6,000
2025-11-12 Fan Courier Express S.R.L.
Insufficient fulfilment of data subjects rights
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 5Art. 6Art. 12Art. 15 €4,000
2025-11-12 Fan Courier Express S.R.L.
Insufficient fulfilment of data subjects rights
🇪🇺 Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) Art. 5Art. 6Art. 12Art. 15 €4,000