Skip to content
Content type · 3,808 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

901–950 of 3,808 sort newestlargest fineoldest
€5,000 Maravet S.R.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data May 19, 2025
€1,000 Homeowners' Association: Failure to Comply with the Principle of Confidentiality ⇄ Boete van €1.000 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Processing Accountability Professional Secrecy May 19, 2025
€1,000 Home Owner Association: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 1,000 on a home owner association. The HOA displayed the personal data of debtors in the entrance hall of a building, which infringed on the… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Processing May 19, 2025
€200,000 ASNEF-EQUIFAX, a company providing creditworthiness information, lacks a sufficient legal basis for data processing. ⇄ Een boete van 200.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6, 17 Controllers Personal Data Right to be Forgotten May 19, 2025
€5,000 Maravet S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Maravet S.R.L. The controller did not implement sufficient technical and organisational measures to ensure information… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 19, 2025
€200,000 ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 200,000 on ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L. The controller obtained personal data from a third party… SPAIN ·AEPD ·Art. 6, 17 Controllers Personal Data Insurance May 19, 2025
€30,000 ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.: Non-compliance with the general principles for data processing. ⇄ Boete van 30.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Personal Data Processing May 16, 2025
€5,000 ACCOUNTING & AUDIT CONSULTING SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on ACCOUNTING & AUDIT CONSULTING SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 16, 2025
€5,000 ACCOUNTING & AUDIT CONSULTING SRL: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data May 16, 2025
€30,000 ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 30,000 on ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A. The controller published a video of a violent incident, which contained the… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Identification May 16, 2025
€80,000 CALOGA: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 80,000 on CALOGA. The controller is a company obtaining data from data brokers to use those for marketing purposes. The DPA found multiple… FRANCE ·CNIL ·Art. 5, 6 Controllers Processing IP Address May 15, 2025
€900,000 SOLOCAL MARKETING SERVICES: Insufficient legal basis for data processing. ⇄ 900.000 euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 6, 7 Consent Controllers Processing May 15, 2025
€900,000 SOLOCAL MARKETING SERVICES: Insufficient legal basis for data processing The French DPA imposed a fine of EUR 900,000 on SOLOCAL MARKETING SERVICES. The controller, a company that also engages in direct marketing activities for its clients, ist using… FRANCE ·CNIL ·Art. 6, 7 Consent Controllers Personal Data May 15, 2025
€80,000 CALOGA: Non-compliance with general principles of data processing. ⇄ Een boete van 80.000 euro - van de Franse Autoriteit voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 5, 6 Controllers Processing Accountability May 15, 2025
€16,000 Sole Trader: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 16,000 on a sole trader. The controller rented out apartments to tenants and installed video surveillance inside them. SLOVENIA ·IP-RS ·Art. 5, 6 Controllers Processing Video Surveillance May 14, 2025
€2,000 CVA TAX & FINANCE S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 CVA TAX & FINANCE S.R.L. The controller did not implement sufficient technical and organisational measures to ensure information… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 14, 2025
€2,000 CVA TAX & FINANCE S.R.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data May 14, 2025
€2,000 Romoffice Construct Holding Ag SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 Romoffice Construct Holding Ag SRL. The controller processed personal data without a sufficient legal basis. ROMANIA ·ANSPDCP ·Art. 5, 6 Controllers Personal Data Processing May 13, 2025
€100,000 PLATAFORMA CABANILLAS SA.: Violation of the general principles for data processing. ⇄ Een boete van 100.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Processing Accountability IP Address May 13, 2025
€2,000 Romoffice Construct Holding Ag SRL: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6 Processing Personal Data Controllers May 13, 2025
€100,000 PLATAFORMA CABANILLAS SA.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 100,000 on PLATAFORMA CABANILLAS SA. The controller is requesting criminal record certificates from potential employees before inviting them… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing May 13, 2025
€2,000 CV PRO CONSULT S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on CV PRO CONSULT S.R.L. The controller did not implement sufficient technical and organisational measures to ensure information… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 12, 2025
€2,000 CV PRO CONSULT S.R.L.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data May 12, 2025
€6,600 Owner of a Pharmacy Office: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the owner of a pharmacy office. The controller processed data of residents of two geriatric centers without a sufficient legal basis. The… SPAIN ·AEPD ·Art. 6, 14, 32 Controllers Encryption Personal Data May 9, 2025
€6,600 Owner of a pharmacy: Non-compliance with general principles for data processing. ⇄ Boete van 6.600 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6, 14, 32 Health Data Controllers Processing May 9, 2025
€5,000 ROUMASPORT SRL: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6 Processing Personal Data Controllers May 9, 2025
€120,000 UNIÓN DE CRÉDITO PARA LA FINANCIACIÓN MOBILIARIA E INMOBILIARIA EFC: Insufficient legal basis for data processing The Spanish DPA imposed a fine on UNIÓN DE CRÉDITO PARA LA FINANCIACIÓN MOBILIARIA E INMOBILIARIA EFCD. The controller forwarded customerdata to a credit information system… SPAIN ·AEPD ·Art. 6 Controllers Insurance Supervisory Authorities May 9, 2025
€5,000 ROUMASPORT SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 5,000 on ROUMASPORT SRL. The controller accessed surveillance cameras to monitor its employees without a sufficient legal basis. The… ROMANIA ·ANSPDCP ·Art. 5, 6 Controllers Processing Personal Data May 9, 2025
€120,000 CREDIT UNION FOR FINANCING OF MOVABLE AND IMMOVABLE PROPERTY EFC: Insufficient legal basis for the processing of data. ⇄ Een boete van 120.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6 Controllers Processing Insurance May 9, 2025
€6,600 Owner of a Pharmacy Office: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the owner of a pharmacy office. The controller processed data of residents of geriatric centers without a sufficient legal basis. The… SPAIN ·AEPD ·Art. 6, 14, 32 Controllers Encryption Personal Data May 8, 2025
€6,600 Owner of a Pharmacy: Violation of the General Principles of Data Processing. ⇄ Een boete van 6.600 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6, 14, 32 Health Data Controllers Processing May 8, 2025
€530M TikTok Technology Limited: Insufficient legal basis for data processing The Irish DPA (DPC) has fined TikTok EUR 530 million. In its decision, the DPC found, that TikTok infringed Art. 13 (1) f) GDPR and Art. 46 (1) GDPR due to the unlawful transfer… DPC ·Art. 13, 46 Processing Agreement International Transfer Personal Data May 2, 2025
€7,000 Company: Non-compliance with general principles for data processing. ⇄ Boete van €7.000 - Nationale Commissie voor de Bescherming van Persoonsgegevens (CNPD). LUXEMBOURG ·CNPD (LU) ·Art. 30 Personal Data Processing IP Address Apr 30, 2025
€7,000 Company: Non-compliance with general data processing principles The DPA of Luxembourg has issued a fine of EUR 7,000 on a company. The controller failed to maintain complete records of its processing activities. LUXEMBOURG ·CNPD (LU) ·Art. 30 Processing Controllers Supervisory Authorities Apr 30, 2025
€40,000 Municipality of Bologna: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 40,000 on the Municipality of Bologna. The controller used a data processor (Cooperativa Sociale Quadrifoglio | ETid: 2274) to process… ITALY ·Garante ·Art. 5, 6, 9 Controllers Security Healthcare Apr 29, 2025
€2,000 Versilmagra Immobiliare di Robertelli Davide & C. S.a.s.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2,000 on Versilmagra Immobiliare di Robertelli Davide & C. S.a.s. The controller obtained personal data of potential customers by… ITALY ·Garante ·Art. 5, 6, 7 +7 Direct Marketing Personal Data Controllers Apr 29, 2025
€1,200 Municipality of San Francesco al Campo: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1,200 on the Municipality of San Francesco al Campo. The controller published the personal data of employees on its website, thereby… ITALY ·Garante ·Art. 5 Retention Period Personal Data Controllers Apr 29, 2025
€40,000 MA Immobiliare S.r.l.s.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on MA Immobiliare S.r.l.s. The controller obtained personal data of potential customers by Realmaps S.r.l., which obtained the… ITALY ·Garante ·Art. 5, 6, 7 +6 Personal Data Controllers Marketing Apr 29, 2025
€2,000 Tirrenia Hospital S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 2,000 on Tirrenia Hospital S.r.l. The controller failed to respond to a data access request from a data subject. ITALY ·Garante ·Art. 12, 15 Right of Access Personal Data Controllers Apr 29, 2025
€100,000 Energia Verde S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Energia Verde S.p.A. The controller had been active in direct marketing activities. The controller processed data without a… ITALY ·Garante ·Art. 5, 6, 7 +13 Direct Marketing Controllers Processors Apr 29, 2025
€20,000 Cooperativa Sociale Quadrifoglio: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio. The entity that was fined, acting as a data processor, forwarded files containing the… ITALY ·Garante ·Art. 28, 32 Processors Controllers Security Apr 29, 2025
€30,000 Lombardy Order of Psychologists: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 30.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 32 Security Controllers Accountability Apr 29, 2025
€20,000 Cooperativa Sociale Quadrifoglio: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 20.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 28, 32 Security Processors Controllers Apr 29, 2025
€40,000 MA Immobiliare S.r.l.s.: Non-compliance with the general principles for data processing. ⇄ Een boete van 40.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +6 Marketing Controllers Processing Apr 29, 2025
€40,000 Municipality of Bologna: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 40.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 Security Controllers Health Data Apr 29, 2025
€50,000 Lombardy Region: Insufficient legal basis for data processing. ⇄ Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 25 +3 Controllers Processing Processors Apr 29, 2025
€30,000 Ordine degli psicologi della Lombardia: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 30,000 on Ordine degli psicologi della Lombardia. The controller suffered a data breach due to insufficient technical and organisational… ITALY ·Garante ·Art. 5, 32 Security Controllers Data Breaches Apr 29, 2025
€100,000 Energia Verde S.p.A.: Non-compliance with the general principles of data processing. ⇄ Een boete van 100.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +13 Security Controllers Direct Marketing Apr 29, 2025
€50,000 Regione Lombardia: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 50,000 on the Regione Lombardia. The controller tracked its employees' browser activities, including private ones, without a sufficient legal… ITALY ·Garante ·Art. 5, 6, 25 +3 Controllers Supervisory Authorities Processing Apr 29, 2025