Skip to content
Content type · 3,808 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

201–250 of 3,808 sort newestlargest fineoldest
€1,500 Francesco Gagliardi: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) found Francesco Gagliardi, operating as a sole proprietorship, in violation of Articles 5(1)(a) and 14 of the GDPR and Article 130… Italy ·Garante ·Art. 5, 14 Legitimate Interest Personal Data Lawful Basis May 14, 2026
€1,000 Danta di Cadore Hunting Reserve: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined the Danta di Cadore Hunting Reserve €1,000 for failing to adequately fulfill its information obligations regarding the… Italy ·Garante ·Art. 5, 6, 13 Personal Data Processing Supervisory Authorities May 14, 2026
€100,000 Energia Sostenibile S.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Energia Sostenibile S.r.l. €100,000 for violations of multiple GDPR provisions, including Articles 5, 6, 7, 12, 13, 15, 24,… Italy ·Garante ·Art. 5, 6, 7 +5 Controllers Processors Supervision May 14, 2026
€43,000 Lidl Italia S.r.l.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) fined Lidl Italia S.r.l. €43,000 for insufficient fulfillment of data subjects' rights under Articles 5, 12, 15, and 18 of the… Italy ·Garante ·Art. 5, 12, 15 +1 Supervisory Authorities Transparency May 14, 2026
€8,000 Municipality of Ventasso: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Municipality of Ventasso €8,000 for violating the general data processing principles under Articles 5, 6, and 9 of the… Italy ·Garante ·Art. 5, 6, 9 Types of Special Categories of Personal Data Personal Data Public Authority May 14, 2026
HDPA · 12/2026 The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Greece ·Art. 23 Right of Access Criminal Data Personal Data May 13, 2026
€120,000 Isabel SA: Insufficient fulfilment of data subjects rights Belgian Data Protection Authority (APD) fined Isabel SA €120,000 on 2026-05-12 for: Insufficient fulfilment of data subjects rights. Belgium ·APD/GBA ·Art. 5, 12, 13 +2 Personal Data Supervisory Authorities Insurance May 12, 2026
€86,000 Société Wallonne des Eaux: Insufficient legal basis for data processing Belgian Data Protection Authority (APD) fined Société Wallonne des Eaux €86,000 on 2026-05-12 for: Insufficient legal basis for data processing. Belgium ·APD/GBA ·Art. 5, 12, 13 +1 Supervisory Authorities Processing Education May 12, 2026
HUF 15M NAIH-450-7-2026 The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Fairness & Transparency Transparency Personal Data May 12, 2026
€42,052 Operator of an online marketplace: Insufficient fulfilment of information obligations The Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined an online marketplace operator €42,052 for failing to adequately fulfill its… Hungary ·NAIH ·Art. 5, 12, 13 Transparency Personal Data May 12, 2026
€177,000 Technology Company: Insufficient legal basis for data processing Belgian Data Protection Authority (APD) fined Technology Company €177,000 on 2026-05-12 for: Insufficient legal basis for data processing. Belgium ·APD/GBA ·Art. 5, 6, 12 +1 Processing Supervisory Authorities Employees May 12, 2026
€4,920 Law Firm: Insufficient fulfilment of data subjects rights Belgian Data Protection Authority (APD) fined Law Firm €4,920 on 2026-05-08 for: Insufficient fulfilment of data subjects rights. Belgium ·APD/GBA ·Art. 5, 12, 13 +2 Personal Data Supervisory Authorities Insurance May 8, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·DPC ·Art. 5, 32, 33 Integrity and Confidentiality Principle Data Breaches Notification Obligation May 8, 2026
€1.1M South Staffordshire Plc: Insufficient technical and organisational measures to ensure information security Information Commissioner (ICO) fined South Staffordshire Plc €1,112,100 on 2026-05-07 for: Insufficient technical and organisational measures to ensure information security. United Kingdom ·ICO ·Art. 5, 32 Security May 7, 2026
The data subject was a technician employed by the controller The controller used weekly handwritten service sheets as a system for recording working time. These sheets contained the technician’s working hours, journeys, services performed… 97/2026 ·Belgium ·APD/GBA Personal Data Right of Access Controllers May 6, 2026
€2,802 IP-RS · 0609-42/2026/7 A processor was contracted by a company (the controller) to maintain an online store, fix errors, and provide support. This included ensuring that the controller had installed the… Slovenia ·Art. 32 Controllers Processors Security May 1, 2026
€1,790 Mayor of the City and Municipality of Myślenice: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined the Mayor of the City and Municipality of Myślenice €1,790 for insufficient fulfilment of personal data breach notification obligations under Article… Poland ·UODO ·Art. 33 Notification Obligation Data Breaches Supervisory Authorities Apr 30, 2026
HUF 10M NAIH-4462-5-2026 The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Personal Data Fairness & Transparency Accountability Apr 30, 2026
€27,319 Operator of an online shop for alcoholic beverages: Insufficient fulfilment of information obligations The Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined the operator of an online shop for alcoholic beverages €27,319 for failing to… Hungary ·NAIH ·Art. 5, 12, 13 Transparency Processing Apr 30, 2026
€2,500 BLUE PROJECTS INDUSTRIES S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined BLUE PROJECTS INDUSTRIES S.R.L. €2,500 on 2026-04-30 for: Insufficient technical and… Romania ·ANSPDCP ·Art. 32 Security Personal Data Supervision Apr 30, 2026
€277,500 Permanent TSB plc: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Permanent TSB plc €277,500 for failing to implement sufficient technical and organisational measures to ensure information security,… Ireland ·DPC ·Art. 5, 32, 33 Notification Obligation Data Breaches Supervision Apr 30, 2026
€100,000 Lepida S.c.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Lepida S.c.p.A. €100,000 for violating general data processing principles under the GDPR. The enforcement action addressed… Italy ·Garante ·Art. 5, 13, 25 +1 Retention Period Storage Limitation Security Apr 29, 2026
€5,000 Dr. Guzzo: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Dr. Guzzo €5,000 for processing personal data without a sufficient legal basis. The violation concerned healthcare data and… Italy ·Garante ·Art. 5, 9 Retention Period Controllers Healthcare Apr 29, 2026
€15,000 Nouva Corrente S.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Nouva Corrente S.r.l. €15,000 for non-compliance with general data processing principles under the GDPR. The enforcement… Italy ·Garante ·Art. 1, 2, 5 +3 Personal Data Supervision Consent Apr 29, 2026
€8,600 Matera Local Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the Matera Local Health Authority €8,600 for failing to implement sufficient technical and organizational measures to ensure… Italy ·Garante ·Art. 5, 32 Security Personal Data Supervision Apr 29, 2026
€12,000 Ministry of Justice: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Ministry of Justice €12,000 for insufficient legal basis for personal data processing. The enforcement action, decided on… Italy ·Garante ·Art. 5, 6, 9 Fairness & Transparency Personal Data Healthcare Apr 29, 2026
€34,000 Pianeta S.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Pianeta S.r.l. €34,000 for violations of multiple GDPR provisions, including Article 5(1)(a) and (b) on general data… Italy ·Garante ·Art. 5, 6, 12 +5 Personal Data Processing Transparency Apr 29, 2026
€4,000 Montelibretti State Comprehensive School: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Montelibretti State Comprehensive School €4,000 for lacking a sufficient legal basis for its data processing activities. The… Italy ·Garante ·Art. 5, 6, 9 Personal Data Healthcare Processing Apr 29, 2026
€6,000 GATIGOS, S.L.: Insufficient cooperation with supervisory authority Spanish Data Protection Authority (aepd) fined GATIGOS, S.L. €6,000 on 2026-04-28 for: Insufficient cooperation with supervisory authority. Spain ·AEPD ·Art. 58 Supervision Supervisory Authorities Apr 28, 2026
€1,800 RESIDENCIAL ETXE-LAN, S.L.: Insufficient cooperation with supervisory authority Spanish Data Protection Authority (aepd) fined RESIDENCIAL ETXE-LAN, S.L. €1,800 on 2026-04-28 for: Insufficient cooperation with supervisory authority. Spain ·AEPD ·Art. 58 Supervisory Authorities Supervision Apr 28, 2026
€240 Posada del León de Oro: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) fined Posada del León de Oro €240 on 2026-04-28 for: Non-compliance with general data processing principles. Spain ·AEPD ·Art. 5, 13 Supervisory Authorities Processing IP Address Apr 28, 2026
€35,000 Crowd Entertainment Ltd: Insufficient legal basis for data processing Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Crowd Entertainment Ltd €35,000 on 2026-04-28 for: Insufficient legal basis for data… Romania ·ANSPDCP ·Art. 5 Personal Data Processing Supervisory Authorities Apr 28, 2026
€1,000 Non-Profit Foundation: Insufficient cooperation with supervisory authority Belgian Data Protection Authority (APD) fined Non-Profit Foundation €1,000 on 2026-04-28 for: Insufficient cooperation with supervisory authority. Belgium ·APD/GBA ·Art. 31 Supervisory Authorities Supervision Apr 28, 2026
€4,000 SIPHONE 2020, S.L.: Insufficient legal basis for data processing Spanish Data Protection Authority (aepd) fined SIPHONE 2020, S.L. €4,000 on 2026-04-28 for: Insufficient legal basis for data processing. Spain ·AEPD ·Art. 6, 13 Supervisory Authorities IP Address Employees Apr 28, 2026
€8,500 Accountancy Firm: Insufficient legal basis for data processing Belgian Data Protection Authority (APD) fined Accountancy Firm €8,500 on 2026-04-23 for: Insufficient legal basis for data processing. Belgium ·APD/GBA ·Art. 5, 6, 12 +1 Processing Supervisory Authorities Employees Apr 23, 2026
€300,000 KONECTA BTO, S.L.: Insufficient technical and organisational measures to ensure information security Spanish Data Protection Authority (aepd) fined KONECTA BTO, S.L. €300,000 on 2026-04-22 for: Insufficient technical and organisational measures to ensure information security. Spain ·AEPD ·Art. 5 Security Supervisory Authorities Apr 22, 2026
€2,000 Io e te s.r.l.s.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Io e te s.r.l.s. €2,000 on 2026-04-17 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 13, 88 Supervisory Authorities Processing Apr 17, 2026
€6.6M Poste Italiane S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Poste Italiane S.p.a. €6,624,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 13 +4 Supervisory Authorities Processing IP Address Apr 17, 2026
€5.9M Postepay S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Postepay S.p.a. €5,877,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 13 +4 Supervisory Authorities Processing IP Address Apr 17, 2026
€6,000 Comune di Campo Calabro: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Comune di Campo Calabro €6,000 on 2026-04-17 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6 Processing Employees Supervisory Authorities Apr 17, 2026
€2,000 Business Owner: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Business Owner €2,000 on 2026-04-17 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 13, 32 Processing Supervisory Authorities Apr 17, 2026
€5,000 Framos Italia s.r.l.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Framos Italia s.r.l. €5,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 12 +3 Processing Supervisory Authorities Employees Apr 17, 2026
OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only… No. 2.1-1/24/397-890-38 ·Estonia ·AKI Controllers Processors Privacy by Design & Default Apr 16, 2026
€400,000 CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined Caixabank, S.A. €400,000 for failing to implement sufficient technical and organizational measures to ensure information… Spain ·AEPD ·Art. 5, 25 Privacy by Design & Default Privacy by Default Privacy by Design Apr 15, 2026
€6,600 Utility Company: Insufficient legal basis for data processing Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Utility Company €6,600 on 2026-04-15 for: Insufficient legal basis for data processing. Slovenia ·IP-RS ·Art. 5 Processing Supervision IP Address Apr 15, 2026
€2,415 Sub Agent: Insufficient technical and organisational measures to ensure information security The Polish National Personal Data Protection Office (UODO) fined Sub Agent €2,415 for failing to implement sufficient technical and organizational measures to ensure information… Poland ·UODO ·Art. 28, 32 Security Personal Data Apr 13, 2026
€2,415 UODO reprimands electricity seller for Art. 5, 24, 25, 28, 32 GDPR violations over An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone… Poland ·Art. 5, 24, 25 +2 Processors Integrity and Confidentiality Principle Controllers Apr 13, 2026
€2,415 Sole trader: Insufficient technical and organisational measures to ensure information security The Polish National Personal Data Protection Office (UODO) fined a sole trader operating in the industry and commerce sector €2,415 for failing to implement sufficient technical… Poland ·UODO ·Art. 28, 32 Processors Controllers Personal Data Apr 13, 2026
€2,350 Housing Associaction: Insufficient fulfilment of data breach notification obligations Polish National Personal Data Protection Office (UODO) fined Housing Associaction €2,350 on 2026-04-07 for: Insufficient fulfilment of data breach notification obligations. Poland ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Apr 7, 2026
€2,500 BLUE PROJECTS S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined BLUE PROJECTS S.R.L. €2,500 on 2026-04-03 for: Insufficient technical and organisational… Romania ·ANSPDCP ·Art. 32 Security Personal Data Supervision Apr 3, 2026