Content type · 3,808 documents in this view · 3,813 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filter by Topic Supervisory Authorities 3589 Processing 2636 Personal Data 2395 Controllers 2018 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
€3,000 Zougla TZI-AP, an anonymous mass media conglomerate: Insufficient legal basis for the processing of personal data. ⇄ Boete van €3.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE · ·Art. 5, 31 Jul 4, 2025
€3,000 Zougla TZI-AP Anonymous Mass Media Company: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 3,000 on Zougla TZI-AP Anonymous Media Company. The controller, who operates a news website, published an article revealing the personal… GREECE · ·Art. 5, 31 Jul 4, 2025
€6,000 CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 6,000 on CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U. The controller processed personal data in order to conclude a contract. But the… SPAIN · ·Art. 5 Jul 4, 2025
€101,000 Croatian Insurance Bureau: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined Croatian Insurance Bureau €101,000 on 2025-07-02 for: Insufficient technical and organisational measures to ensure information… Croatia · ·Art. 5, 32 Jul 2, 2025
€900 ARCONADA 1932, S.L.: Insufficient cooperation with the supervisory authority. ⇄ 900 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN · ·Art. 58 Jul 2, 2025
€900 ARCONADA 1932, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA imposed a fine of EUR 900 on ARCONADA 1932, S.L. The controller did not react adequatly to communication from the DPA. The original fine of EUR 1,500 was reduced… SPAIN · ·Art. 58 Jul 2, 2025
€175,000 FAVORIT SPORTSKA KLADIONICA d.o.o.: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined FAVORIT SPORTSKA KLADIONICA d.o.o. €175,000 on 2025-07-02 for: Insufficient technical and organisational measures to ensure… Croatia · ·Art. 5 Jul 2, 2025
€15,600 Children's Hospital of the L. Zamenhof University in Białystok: Insufficient technical and organizational measures to ensure information security. ⇄ 15.600 euro boete - Poolse nationale instantie voor de bescherming van persoonlijke gegevens (UODO). POLAND · ·Art. 5, 32 Jun 30, 2025
€15,600 L. Zamenhof University Children's Clinical Hospital in Białystok: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 15,600 on the L. Zamenhof University Children's Clinical Hospital in Białystok. The controller did not implement sufficient technical and… POLAND · ·Art. 5, 32 Jun 30, 2025
€96,000 SIDECU, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 96,000 on SIDECU, S.A. The controller introduced facial recognistion system as the only access method to their facilities, without offering… SPAIN · ·Art. 9, 13, 35 Jun 26, 2025
€3,000 SC Piramida Trade Invest SRL: Non-compliance with the general principles of data processing. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 5, 6, 12 +4 Jun 26, 2025
€96,000 SIDECU, S.A.: Non-compliance with the general principles for data processing. ⇄ Een boete van 96.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN · ·Art. 9, 13, 35 Jun 26, 2025
€3,000 SC Piramida Trade Invest SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 3,000 on SC Piramida Trade Invest SRL. The controller processed personal data without a sufficient legal basis and without sufficient… ROMANIA · ·Art. 5, 6, 12 +4 Jun 26, 2025
€3,000 Selgros Cash & Carry SRL: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 32 Jun 26, 2025
€3,000 SC Tremend Software Consulting SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on SC Tremend Software Consulting SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA · ·Art. 32 Jun 26, 2025
€25,000 Alliance for the Union of Romanians Party: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 25,000 on the Alliance for the Union of Romanians Party. The controller did not implement adeqaute technical and organisational measures… ROMANIA · ·Art. 5, 6, 25 +1 Jun 26, 2025
€3,000 Selgros Cash & Carry SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Selgros Cash & Carry SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA · ·Art. 32 Jun 26, 2025
€25,000 Party "Alliance for the Union of Romanians": Non-compliance with the general principles of data processing. ⇄ Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 5, 6, 25 +1 Jun 26, 2025
€3,000 SC Tremend Software Consulting SRL: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 32 Jun 26, 2025
€40,000 KARAMBELAS KONSTANTINOS & CO. E.E.: Insufficient Technical and Organizational Measures for Data Security ⇄ Boete van 40.000 euro - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE · ·Art. 29, 32 Jun 25, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 550,000 on Vodafone – PANAFON A.E.E.T. The controller failed to implement sufficient technical and organisational measures to ensure data… GREECE · ·Art. 5, 28 Jun 25, 2025
€40,000 KARAMBELAS KONSTANTINOS & CO. E.E.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 40,000 on KARAMBELAS KONSTANTINOS & CO. E.E. The processor, which was processing data for a telecommunications provider (ETid: 2878),… GREECE · ·Art. 29, 32 Jun 25, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 550.000 euro - Hellenic Data Protection Authority (HDPA). GREECE · ·Art. 5, 28 Jun 25, 2025
€20,725 Birthlink: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 18,000 (EUR 20,725) on Birthlink. The controller, a scottish registered charity, failed to implement sufficient technical and organisational… UNITED KINGDOM · ·Art. 5, 32, 33 Jun 24, 2025
€7,000 General Hospital of the University of Larissa: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 7,000 on the General Hospital of the University of Larissa. The controller failed to adequately fulfil the rights of data subjects. It… GREECE · ·Art. 5, 14, 15 Jun 24, 2025
€10,000 Shield of David - K.I.D.A.F.: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Shield of David - K.I.D.A.F. The controller, a day care centre for people with autism, has legally installed video… GREECE · ·Art. 5, 12, 13 +3 Jun 24, 2025
€10,000 Shield of David - K.I.D.A.F.: Non-compliance with general principles of data processing. ⇄ Boete van €10.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE · ·Art. 5, 12, 13 +3 Jun 24, 2025
€20,725 Birthlink: Insufficient technical and organisational measures to ensure information security. ⇄ Boete van €20.725 - Informatiecommissaris (ICO). UNITED KINGDOM · ·Art. 5, 32, 33 Jun 24, 2025
€7,000 General Hospital of the University of Larissa: Inadequate compliance with data subjects' rights. ⇄ Een boete van €7.000 - Hellenic Data Protection Authority (HDPA). GREECE · ·Art. 5, 14, 15 Jun 24, 2025
€4,000 Vodafone Romania S.A.: Insufficient technical and organizational measures to ensure information security. ⇄ 4.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Jun 23, 2025
€50,000 Piraeus Bank S.A.: Insufficient legal basis for data processing. ⇄ Een boete van 50.000 euro - Hellenic Data Protection Authority (HDPA). GREECE · ·Art. 5, 6 Jun 23, 2025
€3,500 Municipal Social Assistance Centre in Aleksandrów: Insufficient Technical and Organisational Measures to Ensure Information Security. ⇄ Een boete van 3.500 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND · ·Art. 32 Jun 23, 2025
€125,000 City of Dublin Education and Training Board: Insufficient technical and organizational measures to ensure information security. ⇄ 125.000 euro boete - Ierse Autoriteit voor Gegevensbescherming. IRELAND · ·Art. 5, 32, 33 +1 Jun 23, 2025
€50,000 Piraeus Bank S.A.: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 50,000 on Piraeus Bank S.A.The controller has processed personal data even though the data subject rightfully opposed the the data… GREECE · ·Art. 5, 6 Jun 23, 2025
€4,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 4,000 on Vodafone Romania S.A. The controller failed to implement sufficient technical and organisational measures to ensure data… ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Jun 23, 2025
€125,000 City of Dublin Education and Training Board: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 125,000 on the City of Dublin Education and Training Board. The controller suffered a data breach due to insufficient technical and… IRELAND · ·Art. 5, 32, 33 +1 Jun 23, 2025
€3,500 Municipal Social Welfare Center Aleksandrów: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 3,500 on the Municipal Social Welfare Center in Aleksandrów. The controller did not implement sufficient technical and organisational… POLAND · ·Art. 32 Jun 23, 2025
€42,000 IBERCAJA BANCO, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 42,000 on IBERCAJA BANCO, S.A. During a bank transfer, the controller transmitted more data then necessary to the recipient of the payment.… SPAIN · ·Art. 5 Jun 20, 2025
€24,000 COLEGIO VIRGEN DE EUROPA, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 24,000 on COLEGIO VIRGEN DE EUROPA, S.L. An employee of the controller, a school, took pictures of minor pupils without a sufficient legal… SPAIN · ·Art. 5, 6, 13 Jun 20, 2025
€42,000 IBERCAJA BANCO, S.A.: Violation of the general principles of data processing. ⇄ Een boete van 42.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN · ·Art. 5 Jun 20, 2025
€24,000 COLEGIO VIRGEN DE EUROPA, S.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 24.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN · ·Art. 5, 6, 13 Jun 20, 2025
€1,000 SC Diamir SRL: Violation of the general principles of data processing. ⇄ Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 6, 58 Jun 19, 2025
€1,000 SC Diamir SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 1,000 on SC Diamir SRL. The controller failed to properly cooperate with the supervisory authority and also disclosed personal data to… ROMANIA · ·Art. 6, 58 Jun 19, 2025
€6,800 AB Storstockholms Lokaltrafik: Insufficient legal basis for data processing. ⇄ 6.800 euro boete - De Zweedse Autoriteit voor Gegevensbescherming (Integritetsskyddsmyndigheten). SWEDEN · ·Art. 6, 9 Jun 18, 2025
€6,800 Waxholms Ångfartygs AB: Insufficient legal basis for the processing of personal data. ⇄ 6.800 euro boete - De Zweedse Autoriteit voor Gegevensbescherming (Integritetsskyddsmyndigheten). SWEDEN · ·Art. 6, 9 Jun 18, 2025
€200 Dincă Viorel George: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 200 on a private individual. The controller failed to react to communication from the supervisory authority. ROMANIA · ·Art. 58 Jun 18, 2025
€200 Dincă Viorel George: Insufficient cooperation with the supervisory authority. ⇄ Een boete van 200 euro - De Roemeense nationale toezichthouder op de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 58 Jun 18, 2025
€6,800 Waxholms Ångfartygs AB: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 6,800 on Waxholms Ångfartygs AB. The controller, a public transportation company, requires employees operating a ferry to take a… SWEDEN · ·Art. 6, 9 Jun 18, 2025
€6,800 AB Storstockholms Lokaltrafik: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 6,800 on AB Storstockholms Lokaltrafik. The controller, a public transportation company, requires employees operating a ferry to take a… SWEDEN · ·Art. 6, 9 Jun 18, 2025
Decision on objection AS Watson - Kruidvat ⇄ Jun 17, 2025