Laws · GDPR ·art-32-par-1 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Full text
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:
How it connects
Cited by
- Guidelines 3/2019 on processing of personal data through video devices
- Guidelines 04/2022 on the calculation of administrative fines under the GDPR
- Guidelines 07/2020 on the concepts of controller and processor in the GDPR
- Digi Távközlési Szolgáltató Kft. ('Digi') (electronic communication service provider): Insufficient technical and organisational measures to ensure information security
- Aleris Sjukvård AB: Insufficient technical and organisational measures to ensure information security
All 332
- Aleris Sjukvård AB: Insufficient technical and organisational measures to ensure information security
- Östergötland Region: Insufficient technical and organisational measures to ensure information security
- Västerbotten Region: Insufficient technical and organisational measures to ensure information security
- Sahlgrenska University Hospital: Insufficient technical and organisational measures to ensure information security
- Karolinska University Hospital of Solna: Insufficient technical and organisational measures to ensure information security
- Capio St. Göran AB: Insufficient technical and organisational measures to ensure information security
- Municipality of Indre Østfold: Insufficient technical and organisational measures to ensure information security
- Umeå University: Insufficient technical and organisational measures to ensure information security
- Virgin Mobile Polska: Insufficient technical and organisational measures to ensure information security
- Banca Transilvania SA: Insufficient technical and organisational measures to ensure information security
- Robinson Tours Ltd. (Robinson Tours Idegenforgalmi és Szolgáltató Kft.): Insufficient technical and organisational measures to ensure information security
- Next Time Media Agency Ltd. (Next Time Media Ügynökség Kft.): Insufficient technical and organisational measures to ensure information security
- ID Finance Poland Sp. z o.o.: Insufficient technical and organisational measures to ensure information security
- University College Dublin: Insufficient technical and organisational measures to ensure information security
- Azienda USL della Romagna: Non-compliance with general data processing principles
- Krajowa Szkoła Sądownictwa i Prokuratury: Insufficient technical and organisational measures to ensure information security
- Security company (name not available at the moment): Insufficient technical and organisational measures to ensure information security
- Tusla Child and Family Agency: Insufficient technical and organisational measures to ensure information security
- Registrų Centras: Insufficient technical and organisational measures to ensure information security
- Hellenic Bank: Insufficient technical and organisational measures to ensure information security
- Natural person holding the position of General Secretary for a political party in Bucharest: Insufficient technical and organisational measures to ensure information security
- Asesoría Alpi-Clúa S.L.: Non-compliance with general data processing principles
- S.C. Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security
- Ålesund Municipality: Insufficient technical and organisational measures to ensure information security
- Air Europa Lineas Aereas, SA.: Insufficient technical and organisational measures to ensure information security
- Telekom Romania Mobile Communications S.A.: Insufficient technical and organisational measures to ensure information security
- Kukimbia S.L.: Insufficient technical and organisational measures to ensure information security
- Electrotecnica Bastida S.L.: Insufficient technical and organisational measures to ensure information security
- Asker Municipality: Insufficient technical and organisational measures to ensure information security
- Private healthcare provider: Insufficient technical and organisational measures to ensure information security
- Budapest Főváros Kormányhivatala XI. kerületi Hivatalát (11th District Public Health Department of the Government Office of the Capital City Budapest): Insufficient technical and organisational measures to ensure information security
- InfoMentor ehf: Insufficient technical and organisational measures to ensure information security
- Cyfrowy Polsat S.A.: Insufficient technical and organisational measures to ensure information security
- Directorate of the Östra Skaraborg Rescue Service: Non-compliance with general data processing principles
- BRAbank ASA: Insufficient technical and organisational measures to ensure information security
- Orthodontic Clinic: Insufficient technical and organisational measures to ensure information security
- Moss municipality: Insufficient technical and organisational measures to ensure information security
- IT services company: Insufficient technical and organisational measures to ensure information security
- LUXEMBOURG DPA: Non-compliance with general data processing principles
- Mermaids: Insufficient technical and organisational measures to ensure information security
- President of the Zgierz District Court: Insufficient technical and organisational measures to ensure information security
- Høylandet Municipality: Insufficient technical and organisational measures to ensure information security
- CLUB DEPORTIVO SANSUEÑA, S.L.: Insufficient legal basis for data processing
- Insurance company: Insufficient technical and organisational measures to ensure information security
- HIV Scotland: Insufficient technical and organisational measures to ensure information security
- IKEA ROMÂNIA SA: Insufficient technical and organisational measures to ensure information security
- S.P.E.E.H. Hidroelectrica S.A.: Insufficient technical and organisational measures to ensure information security
- MOVE Ireland: Insufficient technical and organisational measures to ensure information security
- Vodafone România SA: Insufficient technical and organisational measures to ensure information security
- Transavia: Insufficient technical and organisational measures to ensure information security
- Valoris Center S.R.L.: Insufficient technical and organisational measures to ensure information security
- UAB Prime Leasing: Insufficient technical and organisational measures to ensure information security
- Warsaw University of Technology: Insufficient technical and organisational measures to ensure information security
- Irish Teacher Council: Insufficient technical and organisational measures to ensure information security
- Uppsala regional board: Insufficient technical and organisational measures to ensure information security
- Uppsala hospital board: Insufficient technical and organisational measures to ensure information security
- IAB Europe: Insufficient legal basis for data processing
- Retail company (name not available at the moment): Insufficient technical and organisational measures to ensure information security
- Fortum Marketing and Sales Polska S.A.: Insufficient technical and organisational measures to ensure information security
- PIKA Sp. z o.o.: Insufficient technical and organisational measures to ensure information security
- Condor SA: Insufficient technical and organisational measures to ensure information security
- Dutch Foreign Ministry: Insufficient technical and organisational measures to ensure information security
- Dutch Tax and Customs Administration: Non-compliance with general data processing principles
- Lillestrøm Municipality: Insufficient technical and organisational measures to ensure information security
- MED LIFE S.A.: Insufficient technical and organisational measures to ensure information security
- Kaufland Romania SCS: Insufficient technical and organisational measures to ensure information security
- S.C. Wine Point S.R.L.: Insufficient technical and organisational measures to ensure information security
- SC Interactions Marketing SRL: Insufficient technical and organisational measures to ensure information security
- Continental Automotive Romania SRL: Insufficient technical and organisational measures to ensure information security
- Norwegian Parliament: Insufficient technical and organisational measures to ensure information security
- Company: Insufficient technical and organisational measures to ensure information security
- Telecommunications company: Insufficient technical and organisational measures to ensure information security
- JAÉN SENTIDO Y COMÚN: Insufficient technical and organisational measures to ensure information security
- ESTUDIOS EUROPEOS DE POSTGRADO Y EMPRESA, S.L.: Insufficient technical and organisational measures to ensure information security
- E Software Concept SRL: Insufficient technical and organisational measures to ensure information security
- Alpha Bank Romania SA: Insufficient technical and organisational measures to ensure information security
- Realmedia Network SA: Insufficient technical and organisational measures to ensure information security
- Banca Comercială Română SA: Insufficient technical and organisational measures to ensure information security
- Bitfactor SRL: Insufficient technical and organisational measures to ensure information security
- PUNTO BADAL-BCN S.L.: Insufficient technical and organisational measures to ensure information security
- Private individual: Insufficient technical and organisational measures to ensure information security
- Curtea Veche Publishing SRL: Insufficient technical and organisational measures to ensure information security
- Romanian Post: Insufficient technical and organisational measures to ensure information security
- BANKINTER, S.A.: Non-compliance with general data processing principles
- Mayor: Insufficient technical and organisational measures to ensure information security
- Raiffeisen Bank SA: Insufficient technical and organisational measures to ensure information security
- ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security
- Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security
- OTP LEASING ROMANIA IFN SA: Insufficient technical and organisational measures to ensure information security
- Slane Credit Union Ltd.: Insufficient technical and organisational measures to ensure information security
- Casa Rusu S.R.L.: Insufficient technical and organisational measures to ensure information security
- Kaufland Romania SCS: Insufficient technical and organisational measures to ensure information security
- Apă Canal Ilfov SA: Insufficient technical and organisational measures to ensure information security
- BRISTOL LOGISTICS SA: Insufficient technical and organisational measures to ensure information security
- VIEC Limited: Non-compliance with general data processing principles
- Dalarna Region: Insufficient technical and organisational measures to ensure information security
- PRINTAFORM Ltd.: Insufficient technical and organisational measures to ensure information security
- Medijobs Platform SRL: Insufficient technical and organisational measures to ensure information security
- Company: Insufficient technical and organisational measures to ensure information security
- Centric Health Ltd.: Non-compliance with general data processing principles
- A&G Couriers Limited T/A Fastway Couriers (Ireland): Insufficient technical and organisational measures to ensure information security
- Finopro IFN SA: Insufficient technical and organisational measures to ensure information security
- Integral Collection SRL: Insufficient technical and organisational measures to ensure information security
- Partidul Uniunea Salvați România: Insufficient technical and organisational measures to ensure information security
- Tinmar Energy SA: Insufficient technical and organisational measures to ensure information security
- Centrul Medical dr. Furtună Dan: Insufficient technical and organisational measures to ensure information security
- Med Life S.A.: Insufficient technical and organisational measures to ensure information security
- Szczecin-Centrum District Court: Insufficient technical and organisational measures to ensure information security
- Private individual: Non-compliance with general data processing principles
- Bank of Ireland 365: Insufficient technical and organisational measures to ensure information security
- Logistics company: Insufficient technical and organisational measures to ensure information security
- Physician: Insufficient technical and organisational measures to ensure information security
- Covid-19 test center: Insufficient technical and organisational measures to ensure information security
- Dutch Social Insurance Institution (SVB): Insufficient technical and organisational measures to ensure information security
- Skåne region: Insufficient technical and organisational measures to ensure information security
- Company: Insufficient technical and organisational measures to ensure information security
- Debt collection agency: Insufficient technical and organisational measures to ensure information security
- Epic Ltd.: Insufficient legal basis for data processing
- NAGA Markets Europe Ltd: Insufficient technical and organisational measures to ensure information security
- Political party: Insufficient technical and organisational measures to ensure information security
- Bulgarian Post EAD: Insufficient technical and organisational measures to ensure information security
- MALTA DPA: Insufficient technical and organisational measures to ensure information security
- MALTA DPA: Insufficient technical and organisational measures to ensure information security
- MALTA DPA: Insufficient technical and organisational measures to ensure information security
- MALTA DPA: Insufficient technical and organisational measures to ensure information security
- MALTA DPA: Insufficient technical and organisational measures to ensure information security
- MALTA DPA: Insufficient technical and organisational measures to ensure information security
- NN Pensii Societate de Administrare a unui Fond de Pensii Administrat Privat S.A.: Insufficient technical and organisational measures to ensure information security
- NN Asigurări de Viață S.A.: Insufficient technical and organisational measures to ensure information security
- AUTOMOBILE BAVARIA SRL: Insufficient technical and organisational measures to ensure information security
- Sports betting operator: Insufficient legal basis for data processing
- TIM S.p.A.: Insufficient legal basis for data processing
- Artima S.A.: Insufficient technical and organisational measures to ensure information security
- Municipality: Insufficient technical and organisational measures to ensure information security
- MALTA DPA: Non-compliance with general data processing principles
- Farmacia Ardealul SRL: Insufficient technical and organisational measures to ensure information security
- Municipality: Insufficient technical and organisational measures to ensure information security
- Benetton Group S.r.l.: Non-compliance with general data processing principles
- Heilsuveru: Insufficient technical and organisational measures to ensure information security
- CaixaBank, S.A.: Insufficient technical and organisational measures to ensure information security
- Private individual: Non-compliance with general data processing principles
- Company: Insufficient technical and organisational measures to ensure information security
- ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security
- Company: Non-compliance with general data processing principles
- Trygg-Hansa: Non-compliance with general data processing principles
- Rinascente S.p.A.: Non-compliance with general data processing principles
- Digi Telecommunications and Services Ltd.: Insufficient technical and organisational measures to ensure information security
- RESTART ENERGY ONE S.A.: Insufficient technical and organisational measures to ensure information security
- Hotel: Insufficient legal basis for data processing
- Debt collection company: Insufficient legal basis for data processing
- Cez Vânzare S.A.: Insufficient technical and organisational measures to ensure information security
- Company: Insufficient technical and organisational measures to ensure information security
- Mensajero SRL: Insufficient technical and organisational measures to ensure information security
- Indcap AB: Insufficient technical and organisational measures to ensure information security
- Rompetrol Downstream SRL: Insufficient technical and organisational measures to ensure information security
- Norwegian Labor and Welfare Administration: Insufficient technical and organisational measures to ensure information security
- Veranda Obor S.A.: Insufficient technical and organisational measures to ensure information security
- Polish Minister of Health: Insufficient technical and organisational measures to ensure information security
- Disciplinary officer: Insufficient technical and organisational measures to ensure information security
- TECHNINK LEB SRL: Insufficient technical and organisational measures to ensure information security
- VESTA CEU ROMÂNIA SRL.: Insufficient technical and organisational measures to ensure information security
- UniCredit S.p.a.: Insufficient technical and organisational measures to ensure information security
- EURO MINI STORAGE ROMANIA SRL: Insufficient technical and organisational measures to ensure information security
- Daycare center: Insufficient technical and organisational measures to ensure information security
- ALPHA BANK ROMANIA SA.: Insufficient technical and organisational measures to ensure information security
- Physician: Insufficient technical and organisational measures to ensure information security
- IRIDEX GROUP SALUBRIZARE SRL: Insufficient technical and organisational measures to ensure information security
- MEDICOVER SRL: Insufficient technical and organisational measures to ensure information security
- CENTRUL MEDICAL UNIREA SRL: Insufficient technical and organisational measures to ensure information security
- Central Young Men’s Christian Association: Insufficient technical and organisational measures to ensure information security
- Res-Gastro M. Gaweł Sp. k.: Insufficient technical and organisational measures to ensure information security
- PILLOW HOTELS, S.L.: Non-compliance with general data processing principles
- Committee: Insufficient technical and organisational measures to ensure information security
- Rețele Electrice Muntenia SA.: Insufficient technical and organisational measures to ensure information security
- Rețele Electrice Dobrogea SA: Insufficient technical and organisational measures to ensure information security
- Avanza Bank AB: Insufficient technical and organisational measures to ensure information security
- Company: Insufficient technical and organisational measures to ensure information security
- Apoteket AB.: Insufficient technical and organisational measures to ensure information security
- Apohem AB: Insufficient technical and organisational measures to ensure information security
- Constanța South Container Terminal SRL: Insufficient technical and organisational measures to ensure information security
- Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security
- Healthcare facility: Insufficient technical and organisational measures to ensure information security
- Your Consulting SRL: Insufficient technical and organisational measures to ensure information security
- Ana Hotels SRL: Insufficient technical and organisational measures to ensure information security
- Grue municipality: Insufficient technical and organisational measures to ensure information security
- POLAND DPA: Insufficient technical and organisational measures to ensure information security
- POLAND DPA: Insufficient technical and organisational measures to ensure information security
- Hospital: Insufficient technical and organisational measures to ensure information security
- Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security
- DELIVERY SOLUTIONS S.A.: Insufficient technical and organisational measures to ensure information security
- Softehnica S.R.L.: Insufficient technical and organisational measures to ensure information security
- Sambla Group Oy: Insufficient technical and organisational measures to ensure information security
- Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles
- ATRIUM LEX SFC: Insufficient fulfilment of information obligations
- Police Service of Northern Ireland: Insufficient technical and organisational measures to ensure information security
- Advanced Computer Software Group Ltd: Insufficient technical and organisational measures to ensure information security
- DPP Law Ltd.: Insufficient technical and organisational measures to ensure information security
- Polskie Radio Szczecin: Insufficient technical and organisational measures to ensure information security
- Employment Service under the Ministry of Social Security and Labor of the Republic of Lithuania: Insufficient technical and organisational measures to ensure information security
- Vilnius District Municipality Administration: Insufficient technical and organisational measures to ensure information security
- Diskrimineringsombudsmannen: Insufficient technical and organisational measures to ensure information security
- Hospital: Insufficient technical and organisational measures to ensure information security
- Yliopiston Apteekin: Non-compliance with general data processing principles
- Ordine degli psicologi della Lombardia: Insufficient technical and organisational measures to ensure information security
- Realmaps S.r.l.: Insufficient legal basis for data processing
- Accounting Audit SRL: Insufficient technical and organisational measures to ensure information security
- City of Dublin Education and Training Board: Insufficient technical and organisational measures to ensure information security
- V&M Contab & Management SRL: Insufficient technical and organisational measures to ensure information security
- FARMEC SA: Insufficient technical and organisational measures to ensure information security
- Omniasig Vienna Insurance Group S.A.: Insufficient technical and organisational measures to ensure information security
- BEKO ROMANIA SA: Insufficient technical and organisational measures to ensure information security
- WEBRASOFT SRL: Insufficient technical and organisational measures to ensure information security
- Automobilus International S.R.L.: Insufficient technical and organisational measures to ensure information security
- NTT DATA ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security
- BINBOX GLOBAL SERVICES S.R.L.: Insufficient technical and organisational measures to ensure information security
- NEW GAMBLING SOLUTIONS S.R.L.: Insufficient technical and organisational measures to ensure information security
- United Business Solutions SRL: Insufficient technical and organisational measures to ensure information security
- CV PRO CONSULT S.R.L.: Insufficient technical and organisational measures to ensure information security
- CVA TAX & FINANCE S.R.L.: Insufficient technical and organisational measures to ensure information security
- ACCOUNTING & AUDIT CONSULTING SRL: Insufficient technical and organisational measures to ensure information security
- Maravet S.R.L.: Insufficient technical and organisational measures to ensure information security
- AG-BROKER ASIGURARE S.R.L.: Insufficient technical and organisational measures to ensure information security
- SC Piramida Trade Invest SRL: Non-compliance with general data processing principles
- Alliance for the Union of Romanians Party: Non-compliance with general data processing principles
- Selgros Cash & Carry SRL: Insufficient technical and organisational measures to ensure information security
- SC Tremend Software Consulting SRL: Insufficient technical and organisational measures to ensure information security
- Agricola International SA: Insufficient technical and organisational measures to ensure information security
- Company: Non-compliance with general data processing principles
- Panek SA: Insufficient technical and organisational measures to ensure information security
- Non-Public Health Care Institution: Insufficient technical and organisational measures to ensure information security
- Birthlink: Insufficient technical and organisational measures to ensure information security
- Cooperativa Sociale Quadrifoglio: Insufficient technical and organisational measures to ensure information security
- Sligo County Council: Non-compliance with general data processing principles
- Maynooth University: Insufficient technical and organisational measures to ensure information security
- SC Elite Conta SRL: Insufficient technical and organisational measures to ensure information security
- La Fântâna S.R.L.: Insufficient technical and organisational measures to ensure information security
- Order of Nursing Professions of Viterbo: Insufficient technical and organisational measures to ensure information security
- Unita Turism Holding S.A.: Insufficient technical and organisational measures to ensure information security
- S-Pankki Oyj: Insufficient technical and organisational measures to ensure information security
- S.C. PRIMONET RO S.R.L.: Insufficient technical and organisational measures to ensure information security
- EON ENERGIE ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security
- Vellea Home SRL: Insufficient technical and organisational measures to ensure information security
- CAPITA PLC: Insufficient technical and organisational measures to ensure information security
- CAPITA PENSION SOLUTIONS LIMITED: Insufficient technical and organisational measures to ensure information security
- PRIME TRANSACTION SA: Insufficient technical and organisational measures to ensure information security
- S.P.E.E.H. HIDROELECTRICA SA: Insufficient technical and organisational measures to ensure information security
- Aktia Pankki Oyj: Insufficient technical and organisational measures to ensure information security
- Klass Wagen S.R.L.: Insufficient technical and organisational measures to ensure information security
- Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A.: Insufficient technical and organisational measures to ensure information security
- PGS SOFA & CO SRL: Insufficient technical and organisational measures to ensure information security
- Greencorp S.R.L.: Insufficient technical and organisational measures to ensure information security
- Nițu A. Cleopatra – Expert Accountant: Insufficient technical and organisational measures to ensure information security
- LastPass UK Ltd: Insufficient technical and organisational measures to ensure information security
- hier
- EDPB Annual Report 2024
- Joint Guidelines on the Interplay between the Digital Markets Act and the General Data Protection Regulation
- Meta Platforms and Others v Bundeskartellamt
- VB v Natsionalna agentsia za prihodite
- Powiatowego Inspektora Sanitarnego w Policach: Insufficient technical and organisational measures to ensure information security
- Roumasport S.R.L: Insufficient technical and organisational measures to ensure information security
- PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organisational measures to ensure information security
- Continental Automotive Products SRL: Insufficient technical and organisational measures to ensure information security
- Legal Entity: Insufficient technical and organisational measures to ensure information security
- Sportadmin i Skandinavien AB: Insufficient technical and organisational measures to ensure information security
- GENPACT ROMANIA SRL: Insufficient technical and organisational measures to ensure information security
- UODO fines accounting firm €2,760 for email breach security failures
- UODO reprimands electricity seller for Art. 5, 24, 25, 28, 32 GDPR violations over
- Your Consulting SRL: Insufficient technical and organisational measures to ensure information security
- University of Limerick: Insufficient technical and organisational measures to ensure information security
- ING Bank NV Amsterdam – Sucursala București S.A.: Insufficient technical and organisational measures to ensure information security
- RENAULT COMMERCIAL ROUMANIE S.R.L.: Insufficient technical and organisational measures to ensure information security
- Chief Constable of the Police Service of Scotland: Insufficient technical and organisational measures to ensure information security
- Information and Communication Company: Insufficient technical and organisational measures to ensure information security
- BLUE PROJECTS S.R.L.: Insufficient technical and organisational measures to ensure information security
- BLUE PROJECTS INDUSTRIES S.R.L.: Insufficient technical and organisational measures to ensure information security
- Permanent TSB: Insufficient technical and organisational measures to ensure information security
- South Staffordshire Plc: Insufficient technical and organisational measures to ensure information security
- Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security
- Națională Poșta Română: Insufficient technical and organisational measures to ensure information security
- ANSPDCP (Romania) - 02/07/2026
- If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation
- SSG SELECT SOLUTIONS S.R.L: Insufficient technical and organisational measures to ensure information security
- Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security
- UODO (Poland) - DKN.5131.27.2023
- Persónuvernd (Island) - 2025010358
- SG Nürnberg: MOVEit zero-day cyberattack via processor did not breach Art. 32 GDPR
- DPC (Ireland) reprimands Kildare County Council over surveillance tech and CCTV compliance
- EDPB Annual Report 2025
- Opinion 22/2024 on certain obligations following from the reliance on processor(s) and sub-processor(s)
- EDPB Annual Report 2023
- Opinion 7/2024 on the draft decision of the German North Rhine Westphalia Supervisory Authority regarding the EU Cloud Service Data Protection (Auditor) certification criteria
- EDPB-EDPS Joint Opinion 02/2023 on the Proposal for a Regulation of the European Parliament and of the Council on the establishment of the digital euro
- EDPB Annual Report 2022
- EDPB Annual Report 2021
- EDPB-EDPS Joint Opinion 2/2022 on the Proposal of the European Parliament and of the Council on harmonised rules on fair access to and use of data (Data Act)
- Opinion 18/2021 on the draft Standard Contractual Clauses submitted by the LT SA (Article 28(8) GDPR)
- EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)
- Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak
- Opinion 14/2019 on the draft Standard Contractual Clauses submitted by the DK SA (Article 28(8) GDPR)
- Court upholds €50,000 fine on Sociálna poisťovňa for sending sensitive data by ordinary
- X v Russmedia Digital SRL and Inform Media Press SRL
- ZQ v Medizinischer Dienst der Krankenversicherung Nordrhein, Körperschaft des öffentlichen Rechts
- UODO reprimands hospital for inadequate processor oversight and email security failures
- UODO (Poland) - DKN.5131.5.2025
- VG Stuttgart orders deletion of SIS alert for refusal of entry under Art. 17 GDPR
- Sub Agent: Insufficient technical and organisational measures to ensure information security
- HDPA: Hellenic Open University found to have met breach notification duties after
- ICO (UK) - ACRO Criminal Records Office
- HDPA (Greece) - 15/2026
- Altex Romania S.R.L: Insufficient technical and organisational measures to ensure information security
- Banca Transilvania S.A.: Insufficient technical and organisational measures to ensure information security
- InMedica UAB: Insufficient technical and organisational measures to ensure information security
- Permanent TSB plc: Insufficient technical and organisational measures to ensure information security
- Orange Romania SA: Insufficient technical and organisational measures to ensure information security
- HOMELUX S.R.L: Non-compliance with general data processing principles
- AEPD: CaixaBank requested excessive inheritance documentation from heirs
- Cypriot court backs DPA fines of €40,000 each on football clubs and €25,000 on processor
- Hôpital privé de la Loire: Insufficient technical and organisational measures to ensure information security
- AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight
- Sole trader providing accounting and tax advisory services: Insufficient technical and organisational measures to ensure information security
- Guidelines 04/2026 on the application of the power to impose administrative fines in relation to other corrective powers under the GDPR
- IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M
- District Governor of Lubartów: Insufficient technical and organisational measures to ensure information security
- Land-surveying office: Insufficient technical and organisational measures to ensure information security
- Sole trader: Insufficient technical and organisational measures to ensure information security
- Poliserv JG (PJG) SRL: Insufficient technical and organisational measures to ensure information security
- GEROCOSSEN S.R.L.: Insufficient technical and organisational measures to ensure information security