Skip to content
Content type · 3,808 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

701–750 of 3,808 sort newestlargest fineoldest
€4.3M ING Bank Śląski: Insufficient legal basis for data processing. ⇄ 4.323.250 euro boete - Pools Nationaal Bureau voor de Bescherming van Persoonsgegevens (UODO). POLAND ·UODO ·Art. 5, 6 Personal Data Processing Accountability Aug 26, 2025
€300 Driving School: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 300 on a driving school. The controller has installed video surveillance, but failed to adequatly inform data subjects. The original fine… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Aug 26, 2025
€300 Driving School: Insufficient Compliance with Information Obligations. ⇄ Een boete van 300 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 13 Controllers Personal Data Processing Aug 26, 2025
€4.3M ING Bank Śląski: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 4,323,250 on ING Bank Śląski. The controller scanned the identity documents of every customer and potential customer without a sufficient… POLAND ·UODO ·Art. 5, 6 Controllers Personal Data Processing Aug 26, 2025
€1,800 LEIVA BUS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,800 on LEIVA BUS, S.L. The controller leaked personal data due to insufficient technical and organisational measures to ensure data… SPAIN ·AEPD ·Art. 5 Security Controllers Personal Data Aug 25, 2025
€5,400 YUNEXPRESS SPAIN, S.L.: Insufficient agreement regarding data processing. ⇄ Boete van €5.400 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). AEPD ·Art. 5, 28 ·Insufficient data processing agreement Controllers Processors Processing Aug 25, 2025
€5,400 YUNEXPRESS SPAIN, S.L.: Insufficient data processing agreement The Spanish DPA has imposed a fine of EUR 5,400 on YUNEXPRESS SPAIN, S.L. The controller used a data processor and failed to sign a sufficient data processing agreement. The… AEPD ·Art. 5, 28 ·Insufficient data processing agreement Processors Controllers Processing Aug 25, 2025
€1,800 LEIVA BUS, S.L.: Insufficient technical and organizational measures to ensure information security. ⇄ 1.800 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Aug 25, 2025
€18,000 GRUPO BONATEL SL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 18,000 on the GRUPO BONATEL SL. The controller suffered a data leak due to insufficient technical and organisational measures to ensure… SPAIN ·AEPD ·Art. 5 Security Controllers Telecommunications Aug 22, 2025
€6,000 BANCO INVERSIS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 6,000 on BANCO INVERSIS, S.A. The controller suffered a data leak due to insufficient technical and organisational measures to ensure… SPAIN ·AEPD ·Art. 5 Security Controllers Processing Agreement Aug 22, 2025
€18,000 GRUPO BONATEL SL: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van €18.000 - van de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Aug 22, 2025
€6,000 BANCO INVERSIS, S.A.: Insufficient technical and organisational measures to ensure information security. ⇄ Boete van 6.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Aug 22, 2025
€3,000 SC Elite Conta SRL: Insufficient technical and organisational measures to ensure information security The Romainian DPA has imposed a fine of EUR 3,000 on SC Elite Conta SRL. The controller failed to implement adequate technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Aug 18, 2025
€3,000 SC Elite Conta SRL: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Aug 18, 2025
€42,000 WORLD 2 MEET, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 42,000 on WORLD 2 MEET, S.L. The controller requires its guests to provide a copy of their identity card or passport for registration… SPAIN ·AEPD ·Art. 5 Controllers Processing IP Address Aug 14, 2025
€42,000 WORLD 2 MEET, S.L.: Non-compliance with the general principles of data processing. ⇄ Een boete van 42.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Processing Accountability IP Address Aug 14, 2025
€500 Sole Trader: Insufficient cooperation with supervisory authority The Slovenian DPA has imposed a fine of EUR 500 on a sole trader. The controller failed to react to a request by the DPA within the set 10-day period. SLOVENIA ·IP-RS ·Art. 31 Supervision Supervisory Authorities Controllers Aug 13, 2025
€3,000 'FLEXICREDIT' Mutual Aid House Association: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on 'FLEXICREDIT' Mutual Aid House Association. The controller failed to implement adequate technical and organisational measures… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Aug 12, 2025
€3,000 'FLEXICREDIT' Mutual Aid Cooperative: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Aug 12, 2025
€1,600 REAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,600 on the REAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESA. The controller pubilshed personal data on its website without a sufficient legal… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Aug 12, 2025
€66,000 REAL SOCIEDAD DE FUTBOL S.A.D.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 66,000 on REAL SOCIEDAD DE FUTBOL S.A.D. The controller suffered a ransomwareattack due to insufficient technical and organisational… SPAIN ·AEPD ·Art. 5, 32 Security Controllers Processing Agreement Aug 12, 2025
€4,800 GACM SEGUROS GENERALES, an insurance and reinsurance company S.A.U.: Non-compliance with the general principles of data processing. ⇄ Een boete van 4.800 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Processing Accountability Aug 12, 2025
€1,600 REAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESA: Insufficient legal basis for the processing of personal data. ⇄ 1.600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Personal Data Processing Controllers Aug 12, 2025
€4,800 GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 4,800 on GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U. The controller failed to process customer data accurately,… SPAIN ·AEPD ·Art. 5 Controllers Personal Data Processing Aug 12, 2025
€66,000 REAL SOCIEDAD DE FUTBOL S.A.D.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 66.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 32 Security Controllers Accountability Aug 12, 2025
€80,000 BIZUM, S.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 80.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 32 Security Controllers Data Breaches Aug 11, 2025
€80,000 BIZUM, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 80,000 on BIZUM, S.L. The controller failed to implement sufficient technical and organisational measures to ensure data security,… SPAIN ·AEPD ·Art. 32 Security Controllers Data Breaches Aug 11, 2025
DSB · 2025-0.626.844 The data subject requested access to their personal data from a video streaming service (controller) established in the US. The controller provided access to certain personal data… 2025-0.626.844 ·Austria ·Art. 12, 15 Aug 7, 2025
€6,200 Media Company: Insufficient cooperation with supervisory authority The Austrian DPA has imposed a fine of EUR 6,200 on a media company. The controller failed to comply with an order from the DPA to implement an adequate cookie banner. AUSTRIA ·DSB ·Art. 58 Supervisory Authorities Supervision Controllers Aug 6, 2025
€6,200 Media company: Insufficient cooperation with the supervisory authority. ⇄ Boete van 6.200 euro - Oostenrijkse Autoriteit voor Gegevensbescherming (dsb). AUSTRIA ·DSB ·Art. 58 Supervisory Authorities Supervision Telecommunications Aug 6, 2025
€1,000 Order of Biochemists, Biologists and Chemists in the Romanian Healthcare System: Insufficient Compliance with Data Subjects' Rights. ⇄ 1.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Processing Supervisory Authorities Aug 5, 2025
€1,000 Order of Biochemists, Biologists and Chemists in the Romanian Health System: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on the Order of Biochemists, Biologists and Chemists in the Romanian Health System. The controller failed to adequatly respond to… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Aug 5, 2025
€25,000 Bank of Cyprus Public Company Limited: Insufficient technical and organisational measures to ensure information security Cypriot Data Protection Commissioner fined Bank of Cyprus Public Company Limited €25,000 on 2025-08-05 for: Insufficient technical and organisational measures to ensure… Cyprus DPA ·Art. 5, 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Insurance Aug 5, 2025
€10,000 Comune di Venezia: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on the Comune di Venezia. The controller implemented a tourist tax, which includes exceptions for certain groups of visitors. When… ITALY ·Garante ·Art. 5, 6, 25 +1 Controllers Processing Education Aug 4, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Non-compliance with the general principles for data processing. ⇄ Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor gegevensbescherming (Garante). ITALY ·Garante ·Art. 5 Controllers Processing Health Data Aug 4, 2025
€80,000 Ospedaliero-Universitaria Careggi: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 80,000 on the Ospedaliero-Universitaria Careggi. The controller, a university hospital, used software that allowed medical personnel to… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Controllers Security Aug 4, 2025
€7,700 Not a healthcare institution: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van €7.700 - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 32 Security Controllers Healthcare Aug 4, 2025
€230 Police Officer: Insufficient legal basis for data processing The UK DPA has imposed a fine of £ 200 (EUR 230) on a police officer. The controller forwarded sensitive and restricted personal data that he had obtained in the course of his… UNITED KINGDOM ·ICO ·Insufficient legal basis for data processing Education Public Authority Personal Data Aug 4, 2025
€230 Police officer: Insufficient legal basis for data processing. ⇄ Een boete van 230 euro - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Insufficient legal basis for data processing Education Public Authority Processing Aug 4, 2025
€80,000 Careggi University Hospital: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9, 25 +1 Security Health Data Healthcare Aug 4, 2025
€10,000 Municipality of Venice: Non-compliance with the general principles of data processing. ⇄ Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 25 +1 Controllers Processing Public Authority Aug 4, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2,000 on Linea Stampalibera Società Cooperativa r.I. The controller, who operates a news site, has disclosed too much personal… ITALY ·Garante ·Art. 5 Retention Period Controllers Processing Aug 4, 2025
€7,700 Non-Public Health Care Institution: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 7,700 on a non-public health care institution. The controller offered home visits by doctors as part of its services. For this purpose,… POLAND ·UODO ·Art. 5, 25, 32 Controllers Security Personal Data Aug 4, 2025
€11,614 Legal Entity: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 11,614 on a legal entity. The controller did not delete the email address of a former employee, but rather continued to receive and… SLOVENIA ·IP-RS ·Art. 5, 6 Controllers Processing Supervisory Authorities Jul 29, 2025
€4,400 Entrepreneur: Insufficient cooperation with supervisory authority The Polish DPA has imposed a fine of EUR 4,400 on an Entrepreneur. The controller failed to adequatly react to a request from the DPA. POLAND ·UODO ·Art. 58 Supervisory Authorities Supervision Controllers Jul 28, 2025
€4,400 Entrepreneur: Insufficient cooperation with the supervisory authority. ⇄ 4.400 euro boete - Pools Nationaal Bureau voor de Bescherming van Persoonsgegevens (UODO). POLAND ·UODO ·Art. 58 Personal Data Controllers Supervisory Authorities Jul 28, 2025
€5,020 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 5,020 on a legal entity. The controller had developed an application that allowed the exchange of personal data, but failed to… SLOVENIA ·IP-RS ·Art. 32 Security Controllers Personal Data Jul 25, 2025
€5,810 Legal Entity: Insufficient data processing agreement The Slovenian DPA has imposed a fine of EUR 5,810 on a legal entity. The controller employed a person authorised to perform clerical work. However, this person used a data… SLOVENIA ·IP-RS ·Art. 28 Processors Controllers Processing Jul 25, 2025
€26,400 Debt Collector: Insufficient fulfilment of data subjects rights The Hungarian DPA has imposed a fine of EUR 26,400 on a debt collector. The controller processed the personal data of a natural person, specifically data relating to a consumer… HUNGARY ·NAIH ·Art. 6, 17 Personal Data Controllers Insurance Jul 24, 2025
€10,000 SATI S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on SATI S.p.A. Information about the reasons for employees' absences was displayed on boards and in emails, which were accessible… ITALY ·Garante ·Art. 5, 9 Controllers Processing Employees Jul 23, 2025