Skip to content
Content type · 3,808 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

351–400 of 3,808 sort newestlargest fineoldest
€25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Zoetermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Zoetermeer. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€10,000 Natural Person: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 10,000 on a natural person. The controller operated a website on which identity cards containing personal data, including special… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 +6 Criminal Data Personal Data Types of Special Categories of Personal Data Jan 30, 2026
€4,200 Hungarian University of Agriculture and Life Sciences: Insufficient legal basis for data processing Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined Hungarian University of Agriculture and Life Sciences €4,200 on 2026-01-30 for:… Hungary ·NAIH ·Art. 5, 6, 13 Processing Education Public Authority Jan 30, 2026
€50,000 Università Telematica e-Campus: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Università Telematica e-Campus €50,000 on 2026-01-29 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6, 9 +1 Processing Education Public Authority Jan 29, 2026
€2,000 Federazione Nazionale Ordini Professioni Infermieristiche (FNOPI): Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Federazione Nazionale Ordini Professioni Infermieristiche (FNOPI) €2,000 on 2026-01-29 for: Insufficient legal basis for data… Italy ·Garante ·Art. 5, 6 Processing Cookies Telecommunications Jan 29, 2026
€5,000 Dr. Paolo Montemurro: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Dr. Paolo Montemurro €5,000 on 2026-01-29 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 9 Healthcare Processing Cookies Jan 29, 2026
€12,000 Ministero della Cultura: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Ministero della Cultura €12,000 on 2026-01-29 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 12 +3 Supervisory Authorities Processing Employees Jan 29, 2026
€12,000 Istituto San Giuseppe La Salle di Milano: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Istituto San Giuseppe La Salle di Milano €12,000 on 2026-01-29 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 12 +3 Supervisory Authorities Processing Education Jan 29, 2026
€10,000 Istituto tecnico industriale statale “Stanislao Cannizzaro” di Catania: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Istituto tecnico industriale statale “Stanislao Cannizzaro” di Catania €10,000 on 2026-01-29 for: Insufficient legal basis for… Italy ·Garante ·Art. 5, 6, 9 Processing Education Public Authority Jan 29, 2026
DSB Austria: disclosure of health data to court-appointed expert in legal dispute lawful The data subject was involved in a legal dispute before a civil court in which the findings of an expert opinion led to the dismissal of the case. The expert opinion concerned the… DSB-D124.0850/25 ·Art. 9 Healthcare Health Data Types of Special Categories of Personal Data Jan 28, 2026
€565,000 Sportadmin i Skandinavien AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 565,500 on Sportadmin i Skandinavien AB. The controller suffered a sucessfull cyber attack, resulting in personal and special category… SWEDEN ·IMY ·Art. 32 Security Personal Data Controllers Jan 26, 2026
€5M FRANCE TRAVAIL: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 5,000,000 on FRANCE TRAVAIL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures,… CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Jan 22, 2026
€4,850 Slovenia DPA: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined an unnamed party €4,850 on 2026-01-20 for: Insufficient technical and organisational measures to ensure… IP-RS ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Security Supervisory Authorities Supervision Jan 20, 2026
€1,200 Dental Clinic: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,200 on a dental clinic. The controller used video surveillance in its clinic for security purposes, including a camera in the doctor's… SPAIN ·AEPD ·Art. 5 Controllers Processing Security Jan 19, 2026
€15,000 Continental Automotive Products SRL: Insufficient technical and organisational measures to ensure information security. ⇄ Boete van €15.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 32 Security Processing Personal Data Jan 19, 2026
€15,000 Continental Automotive Products SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Continental Automotive Products SRL. The controller failed to implement adequate technical and organisational measures,… ROMANIA ·ANSPDCP ·Art. 5, 32 Controllers Security Processing Jan 19, 2026
€25,500 DSB · 2025-1.049.138 The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted… Austria ·Art. 5, 6, 12 +1 Legitimate Interest Personal Data Retention Period Jan 19, 2026
DSB · 2026-0.043.390 Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop… 2026-0.043.390 ·Austria ·Art. 5, 12, 13 Personal Data IP Address Fairness & Transparency Jan 16, 2026
€1,500 10214411 The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of security… Italy ·Garante ·Art. 5, 6, 13 +2 Fairness & Transparency Controllers Transparency Jan 16, 2026
€21,650 Timegrip AS: Insufficient fulfilment of data subjects rights The Norwegian DPA has imposed a fine of EUR 21,650 on Timegrip AS. The controller had been tracking the working hours of employees at a company that went bankrupt. A former… NORWAY ·Datatilsynet (NO) ·Art. 15 Personal Data Controllers Supervisory Authorities Jan 16, 2026
GBP 120,000 ICO (UK) - Allay Claims Ltd Allay Claims Ltd (the controller) sent over 4 million direct marketing text messages to individuals promoting a different entity’s services. The DPA received over 48,000… United Kingdom Direct Marketing Telecommunications Consent Jan 15, 2026
€1M CNIL fines data processor €1,000,000 for unlawful retention, purpose conflict, and no ROPA The data protection authority (DPA) has imposed a fine of 1 million euros on a data processor for failing to delete user personal data, processing that data for purposes that… France Processors Controllers Processing Jan 13, 2026
€500,000 AEPD fines bank €500,000 for losing customer documents via courier service (Art. 32) Facts: The data protection authority (DPA) has fined a bank €500,000 after documents belonging to a customer were lost during delivery by a courier service. The authority ruled… Spain ·Art. 32 Controllers Security Personal Data Jan 13, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PREMIER RESTAURANTS ROMANIA SRL. The controller failed to implement adequate technical and organisational measures, resulting… ANSPDCP ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Controllers Security Supervisory Authorities Jan 13, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organizational measures to ensure information security. ⇄ 8.000 euro boete - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Security Processing Supervisory Authorities Jan 13, 2026
CNIL: fairness of procedure adequate, sharing internal reports with complainant violates Art. 6 ECHR ⇄ Permanent link: "Regarding the fairness of the procedure:" "Regarding the fairness of the procedure:" In the first instance, the data protection authority (DPA) rejected the… SAN-2025-015 ·Frankrijk Supervisory Authorities Processing Agreement Jan 13, 2026
€200 Medical Student: Insufficient legal basis for data processing The Austrian Data Protection Authority (dsb) fined a medical student €200 for processing personal data without a sufficient legal basis under GDPR Article 6(1)(f) and Article… Austria ·DSB ·Art. 6, 9 Legitimate Interest Types of Special Categories of Personal Data Personal Data Jan 12, 2026
DSB: Art. 15 GDPR access right does not extend to full documents with third-party data The data protection authority (DPA) has determined that, according to Article 15 of the GDPR, an individual has the right to access personal data relating to them, but this right… 2025-0.395.497 ·Austria ·Art. 15 Right of Access Personal Data Supervisory Authorities Jan 12, 2026
€200 A medical student (the controller) worked as a ward attendant at a hospital Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the nursing staff immediately when necessary. While assigned to a patient with… 2026-0.016.479 ·Austria ·DSB Legitimate Interest Personal Data Integrity and Confidentiality Principle Jan 12, 2026
€1.7M CNIL fines data processor €1.7M for misconfigured disability-records software causing The data protection authority (DPA) has imposed a fine of €1,700,000 on a data processor that had incorrectly configured a software program. This program processed files related… France Controllers Processors Processing Jan 12, 2026
€500 VOX ESPAÑA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500 on VOX ESPAÑA. The controller, a political party, posted a picture of of a receipt on its Facebook page. The picture of the recipt… SPAIN ·AEPD ·Art. 6 Personal Data Controllers IP Address Jan 10, 2026
€8,000 KVIKU SPAIN, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 8,000 on KVIKU SPAIN, S.L.The controller requires customers to send a photo of themselves holding their ID card when verifying their… AEPD ·Art. 5 ·Non-compliance with general data processing principles Retention Period Controllers Processing Jan 10, 2026
€18,500 Komendanta Miejskiego Policji w Krakowie: Non-compliance with general data processing principles The Polish DPA has imposd a fine of EUR 18,500 on the Komendanta Miejskiego Policji w Krakowie. The controller published personal data, including health data, of a data subject… POLAND ·UODO ·Non-compliance with general data processing principles Personal Data Education Public Authority Jan 9, 2026
The controller, an Austrian registered association, operates a therapy centre for psychosomatic illnesses The data subject was a patient of the controller. On 28 July 2025, the data subject sent an access request by email under Article 15 GDPR, asking for full information on all… DSB-D124.2437/25 ·Austria ·DSB Right of Access Personal Data Controllers Jan 9, 2026
€18,500 Commander of the Municipal Police of Krakow: Failure to Comply with General Data Protection Principles ⇄ 18.500 euro boete - Poolse nationale autoriteit voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Non-compliance with general data processing principles Law Enforcement Health Data Education Jan 9, 2026
€15M FREE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 15,000,000 on FREE. The controller suffered a data breach due to insufficient technical and organisational measures. This was caused by… FRANCE ·CNIL ·Art. 32, 34 Data Breaches Security Controllers Jan 8, 2026
€2,000 Money Seeds S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. ⇄ The Romanian supervisory authority ANSPDCP has imposed a fine of 2,000 euros on Money Seeds S.R.L., a financial and consultancy company, for failing to honor a data subject's… ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervision Jan 8, 2026
€2,000 Money Seeds S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Money Seeds S.R.L. The controller failed to fulfil a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervisory Authorities Jan 8, 2026
€27M FREE MOBILE: Insufficient technical and organizational measures to ensure information security. ⇄ 27 miljoen euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 5, 32 Security Controllers Personal Data Jan 8, 2026
€27M FREE MOBILE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 27,000,000 on FREE MOBILE. The controller suffered a data breach due to insufficient technical and organisational measures. This was… FRANCE ·CNIL ·Art. 5, 32 Personal Data Controllers Security Jan 8, 2026
€10,000 Headquarter of a Fire Brigade: Insufficient legal basis for data processing The Greek DPA has imposed a fine of EUR 10,000 on a Fire Brigade Head Quarter. The controller had stored health data of an employee which had been in relation with her sick leave.… GREECE ·HDPA ·Art. 5 Controllers Processing Health Data Jan 8, 2026
€15M UNACCEPTABLE: Insufficient technical and organizational measures to ensure information security. ⇄ The French data protection authority (CNIL) has imposed a fine of €15,000,000 on FREE. The company suffered a data breach as a result of insufficient technical and organizational… FRANCE ·CNIL ·Art. 32, 34 Security Data Breaches Notification Obligation Jan 8, 2026
Decision No. 3R-1700. Facts: The data protection authority (DPA) ruled that a gambling operator had lawfully transferred data to a processor for the purpose of sending invitations to sporting events,… 3R-1700 ·Lithuania ·VDAI Personal Data Fairness & Transparency Processors Jan 7, 2026
€400,000 AEPD fines two telecom providers €400,000 and €300,000 for SIM card fraud Facts: The Data Protection Authority has fined a telecommunications company €400,000 for unlawfully changing the ownership of a mobile phone subscription and issuing a dual SIM… Spain ·Art. 6 Telecommunications IP Address Identification Jan 7, 2026
AEPD: fines of €400,000 and €300,000 for telecom providers in SIM card fraud ⇄ Facts: The Data Protection Authority has imposed a fine of 400,000 euros on a telephone company for unlawfully changing the ownership of a mobile phone subscription and issuing a… EXP202306073 ·Spanje Telecommunications Personal Data Supervisory Authorities Jan 7, 2026
VDAI (Lithuania) - Decision no. 3R-1700. ⇄ Facts: The Data Protection Authority (DPA) ruled that a gambling provider had lawfully transferred data to a processor for the purpose of sending invitations to sporting events,… 3R-1700 ·Litouwen Controllers Fairness & Transparency Personal Data Jan 7, 2026
DSB: complaint against Austrian media company dismissed, but cookie banner instruction issued ⇄ An Austrian media company (the controller) that published local news operated a website that collected personal data from visitors using cookies and a cookie consent banner. The… 2025-0.276.820 ·Oostenrijk Cookies Personal Data Right to be Forgotten Jan 7, 2026
€6,820 Austrian media company fined €6,820 for failing to comply with order to fix cookie banner An Austrian media company has been fined €6,820 by the Data Protection Authority because it failed to implement a binding instruction to modify the cookie banner on its website.… Austria ·DSB ·Art. 58 Right to be Forgotten Supervisory Authorities Cookies Jan 7, 2026
€5,000 Sole Trader: Non-compliance with general data processing principles Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Sole Trader €5,000 on 2026-01-06 for: Non-compliance with general data processing principles. Slovenia ·IP-RS ·Art. 5 Processing Supervision IP Address Jan 6, 2026