Skip to content
Content type · 3,808 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

751–800 of 3,808 sort newestlargest fineoldest
€10,000 SATI S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on SATI S.p.A. Information about the reasons for employees' absences was displayed on boards and in emails, which were accessible… ITALY ·Garante ·Art. 5, 9 Controllers Processing Employees Jul 23, 2025
€10,000 Order of Nursing Professions of Viterbo: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on the Order of Nursing Professions of Viterbo. The controller suffered a data leak due to insufficient technical and… ITALY ·Garante ·Art. 5, 32 Security Controllers Education Jul 23, 2025
€10,000 SATI S.p.A.: Non-compliance with the general principles for data processing. ⇄ Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9 Controllers Processing Accountability Jul 23, 2025
€10,000 Order of Nurses of Viterbo: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 32 Security Controllers Accountability Jul 23, 2025
€5,000 Agricola International SA: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Jul 23, 2025
€320,000 HEP-Toplinarstvo: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined HEP-Toplinarstvo €320,000 on 2025-07-22 for: Insufficient technical and organisational measures to ensure information security. Croatia ·AZOP ·Art. 31, 32 Security Supervisory Authorities Human Resources Jul 22, 2025
€2,200 Legal Entity: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 2,200 on a legal entity. An employee of the company forwarded health data to a lawyer without sufficient grounds. The company was fined… SLOVENIA ·IP-RS ·Art. 6, 9 Healthcare Types of Special Categories of Personal Data Processing Jul 22, 2025
€50,000 Information and Communication Company: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined Information and Communication Company €50,000 on 2025-07-22 for: Insufficient technical and organisational measures to ensure… Croatia ·AZOP ·Art. 32 Security Human Resources Supervisory Authorities Jul 22, 2025
€4M McDonald’s Polska Sp. z o.o.: Non-compliance with general principles for data processing. ⇄ Een boete van 3.955.000 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 28 +1 Controllers Security Processing Jul 21, 2025
€9,000 Hestia Publishers & Booksellers, I. D. Kollaros & Co. S.A.: Insufficient technical and organisational measures to ensure information security. ⇄ Boete van €9.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 25, 32 +2 Security Pseudonymization Controllers Jul 21, 2025
€43,000 24/7 Communication Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 43,000 on 24/7 Communication Sp. z o.o. The fined entity acted as the data processor for McDonald’s Polska Sp. z o.o. (see ETid: 2757).… POLAND ·UODO ·Art. 5, 25, 38 Controllers Processors Retention Period Jul 21, 2025
€4M McDonald’s Polska Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed a fine of EUR 3,955,000 on McDonald’s Polska Sp. z o.o. The controller used a third party processor (see ETid: 2758) for the purpose of managing work… POLAND ·UODO ·Art. 5, 25, 28 +1 Controllers Processors Security Jul 21, 2025
€9,000 Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 9,000 on Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A. The controller disclosed the identity of an anonymous author by… GREECE ·HDPA ·Art. 5, 25, 32 +2 Pseudonymization Security Controllers Jul 21, 2025
€43,000 24/7 Communication Sp. z o.o.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 43.000 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 38 Security Controllers Processors Jul 21, 2025
€1,000 CLUB BALONCESTO TELDE: Insufficient legal basis for the processing of data. ⇄ 1.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6 Consent Controllers Processing Jul 18, 2025
€1,100 ADMINISTRACIONES BENIPON, S.L.: Insufficient fulfilment of data breach notification obligations The Spanish DPA has imposed a fine of EUR 1,100 on ADMINISTRACIONES BENIPON, S.L. The processor failed to notify the controller of a data breach and also used a sub-processor… SPAIN ·AEPD ·Art. 28, 33 Notification Obligation Data Breaches Processors Jul 18, 2025
€1,000 CLUB BALONCESTO TELDE: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,000 on the club BALONCESTO TELDE. The controller published an image of a minor without the consent of the minors representative. SPAIN ·AEPD ·Art. 6 Controllers Consent Minors Jul 18, 2025
€1,100 ADMINISTRACIONES BENIPON, S.L.: Failure to comply with the obligations regarding the notification of personal data breaches. ⇄ 1.100 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 28, 33 Controllers Processing Processors Jul 18, 2025
€1,200 TRUEBA SPORT S.L.: Insufficient technical and organizational measures to ensure information security. ⇄ 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 13 Security Controllers Accountability Jul 17, 2025
€1,200 TRUEBA SPORT S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,200 on TRUEBA SPORT S.L. The controller disclosed personal data due to an human error. The controller also failed to include a privacy… SPAIN ·AEPD ·Art. 5, 13 Personal Data Controllers Supervisory Authorities Jul 17, 2025
€200,000 ENDESA ENERGIA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 200,000 on ENDESA ENERGIA, S.A.U. The controller mistakenly linked two unrelated parties, resulting in a third party having its energy… SPAIN ·AEPD ·Art. 5 Controllers Processing IP Address Jul 17, 2025
€200,000 ENDESA ENERGIA, S.A.U.: Violation of the general principles of data processing. ⇄ Een boete van 200.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Processing Accountability Jul 17, 2025
€180,000 TRIVE CREDIT SPAIN, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 180,000 on TRIVE CREDITSPAIN, S.L. The controller failed to adequatly comply with a order from the DPA. The original fine of EUR 225,000… AEPD ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Jul 16, 2025
€4,000 Georgescu Călin: Inadequate compliance with data subjects' rights (regarding their personal data). ⇄ Een boete van 4.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Processing Supervisory Authorities Jul 16, 2025
€4,000 Georgescu Călin: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine on the politican Georgescu Călin. The controller failed to inform data subjects on his website regarding the processing of their data and how… ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervisory Authorities Jul 16, 2025
€5,400 SUNERIS, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5,400 on SUNERIS, S.A. The controller processed scans of ID cards and passports of their guests, infringing the principle of data… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Jul 16, 2025
€180,000 TRIVE CREDIT SPAIN, S.L.: Insufficient cooperation with the supervisory authority. ⇄ Een boete van 180.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). AEPD ·Art. 58 ·Insufficient cooperation with supervisory authority Controllers Supervisory Authorities Supervision Jul 16, 2025
€5,400 SUNERIS, S.A.: Non-compliance with the general principles of data processing. ⇄ Boete van €5.400 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Processing Accountability IP Address Jul 16, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 32.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 32 Security Controllers Personal Data Jul 11, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on VALORA PREVENCIÓN, S.L.U. The controller, a company offering occupational health and safety services, failed to implement… SPAIN ·AEPD ·Art. 5, 32 Controllers Security Personal Data Jul 11, 2025
€20,000 NN Greek Single-Member Insurance Company Anonymous: Insufficient compliance with data subject rights. ⇄ Boete van 20.000 euro - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 15 Personal Data Controllers Supervisory Authorities Jul 11, 2025
€20,000 NN Greek Single-Member Anonymous Life Insurance Company: Insufficient fulfilment of data subjects rights The Greek DPA has imposed a fine of EUR 20,000 on NN Greek Single-Member Anonymous Life Insurance Company. The controller failed to provide the data subject with the personal data… GREECE ·HDPA ·Art. 15 Right of Access Personal Data Controllers Jul 11, 2025
€2,000 PAVLOS BIKOS SOLE PROPRIETORSHIP DENTAL PRIVATE CAPITAL COMPANY: Insufficient cooperation with supervisory authority The Greek DPA has imposed a fine of EUR 2,000 on PAVLOS BIKOS SOLE PROPRIETORSHIP DENTAL PRIVATE CAPITAL COMPANY. The fined party was a data processor in case ETid: 2880. During… GREECE ·HDPA ·Art. 31 Supervisory Authorities Supervision Processors Jul 11, 2025
€4,000 Istituto Comprensivo 2 C.D. “G. Modugno” S.M. “G. Galilei” di Monopoli: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 4,000 on Istituto Comprensivo 2 C.D. “G. Modugno” S.M. “G. Galilei” di Monopoli. The controller published a list with the name of pupils… ITALY ·Garante ·Art. 5, 6, 9 Controllers Processing Education Jul 10, 2025
€80,000 Poste Vita S.p.a.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 33 Security Controllers Personal Data Jul 10, 2025
€4,000 Istituto Comprensivo 2 C.D. “G. Modugno” S.M. “G. Galilei” in Monopoli: Insufficient Legal Basis for Data Processing. ⇄ Een boete van 4.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 Types of Special Categories of Personal Data Controllers Processing Jul 10, 2025
€8,000 University of Cassino and Southern Lazio: Non-compliance with general principles of data processing. ⇄ Een boete van 8.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +2 Right to be Forgotten Controllers Processing Jul 10, 2025
€50,000 Magna PT S.p.A.: Insufficient legal basis for the processing of data. ⇄ Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Retention Period Jul 10, 2025
€8,000 Università degli Studi di Cassino e del Lazio Meridionale: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 8,000 on Università degli Studi di Cassino e del Lazio Meridionale. The controller failed to delete a former employee's email address… ITALY ·Garante ·Art. 5, 6, 12 +2 Controllers Supervisory Authorities Processing Jul 10, 2025
€50,000 Magna PT S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine on Magna PT S.p.A. Employees of the controllers were subjected to 'return to work interviews' after returning from an absence due to illness or… ITALY ·Garante ·Art. 5, 6, 9 +2 Retention Period Controllers Storage Limitation Jul 10, 2025
€80,000 Poste Vita S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine on Poste Vita S.p.a. The controller failed to implement adequate technical and organisational measures to ensure data security. This resulted in… ITALY ·Garante ·Art. 5, 33 Security Personal Data Controllers Jul 10, 2025
€10,000 Childcare "La Combricola Dei Birichini Di Betty": Non-compliance with the general principles of data processing. ⇄ Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +5 Marketing Controllers Processing Jul 10, 2025
€10,000 Nursery School “La Combricola Dei Birichini Di Betty”: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on the Nursery School “La Combricola Dei Birichini Di Betty”. The controller only accepted new children if their parents agreed… ITALY ·Garante ·Art. 5, 6, 7 +5 Controllers Public Authority Supervisory Authorities Jul 10, 2025
€100,000 Banco Bilbao Vizcaya Argentaria SA: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Banco Bilbao Vizcaya Argentaria SA €100,000 on 2025-07-10 for: Insufficient fulfilment of data subjects rights. Italy ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Insurance Jul 10, 2025
€3,000 Comune di Conversano: Lack of appointment of data protection officer The Italian DPA has imposed a fine of EUR 3,000 on the Comune di Conversano. The controller failed to correctly appoint a DPA. ITALY ·Garante ·Art. 37 Supervisory Authorities Public Authority Controllers Jul 10, 2025
€3,000 Municipality of Conversano: Failure to appoint a data protection officer. ⇄ Een boete van 3.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 37 Public Authority Supervisory Authorities Controllers Jul 10, 2025
€3,000 Zougla TZI-AP, an anonymous mass media conglomerate: Insufficient legal basis for the processing of personal data. ⇄ Boete van €3.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 31 Personal Data Processing Controllers Jul 4, 2025