Skip to content
Content type · 933 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Italy · €20,000 Garante per la protezione dei dati personali (Italy) - 471/2026 Facts — The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Personal Data Fairness & Transparency Criminal Data Jul 18, 2026
Spain · €200,000 AEPD (Spain) - PS-00020-2025 Facts — Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware… DPIA Privacy Impact Assessment Security Jul 16, 2026
Italy · €50,000 Garante per la protezione dei dati personali (Italy) - 10128005 Facts — The Calabrian Regional Agency for Agricultural Development (the controller) implemented a remote work policy that required employees to use a time-tracking application… DPIA Monitoring Personal Data Jul 16, 2026
Spain AEPD (Spain) - EXP202102529 Facts — A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as… Consent Healthcare Health Data Jul 16, 2026
Spain · €140 AEPD (Spain) - EXP202310345 Facts — On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Telecommunications Personal Data Controllers Jul 13, 2026
Slovenia · €1,198 IP (Slovenia) - 0609-36/2026/7 Facts — A company (the controller) operates an online store. An employee of the controller used a pirated and unlicensed software when creating the website. This software… Integrity and Confidentiality Principle Security Data Breaches Jul 8, 2026
Romania · €26,172 ANSPDCP (Romania) - 02/07/2026 Facts — The Romanian DPA (ANSPDCP) launched an investigation into a bank, Banca Transilvania S.A. (the controller), following a data subject’s complaint. The data subject claimed… Integrity and Confidentiality Principle Data Breaches Security Jul 3, 2026
Sweden IMY (Sweden) - IMY-2024-2904 Facts — The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the… Personal Data Controllers International Transfer Jul 3, 2026
Italy · €158,000 Garante per la protezione dei dati personali (Italy) - 487/2026 Facts — Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows… Personal Data Processing Artificial Intelligence Jul 3, 2026
Island Persónuvernd (Island) - 2025010358 Facts — The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… Monitoring Cloud Computing Integrity and Confidentiality Principle Jul 1, 2026
Lithuania · €450,000 VDAI (Lithuania) - 3R-1143 Facts — Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and… Security Data Breaches Access Controls Jun 19, 2026
ANSPDCP · €2,000 SSG SELECT SOLUTIONS S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined SSG Select Solutions S.R.L. €2,000 for failing to implement adequate technical and… Security Supervisory Authorities Personal Data Jun 15, 2026
Poland · €2,760 UODO (Poland) - DKN.5131.34.2023 Facts — An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account… Data Breaches Notification Obligation Right of Access Jun 13, 2026
ANSPDCP · €5,000 Națională Poșta Română: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Națională Poșta Română €5,000 on 2026-06-12 for: Insufficient technical and organisational… Security Personal Data Supervisory Authorities Jun 12, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Notification Obligation Data Breaches Healthcare Jun 11, 2026
UODO · €23,540 Minister of Justice: Insufficient technical and organisational measures to ensure information security Polish National Personal Data Protection Office (UODO) fined Minister of Justice €23,540 on 2026-06-02 for: Insufficient technical and organisational measures to ensure… Security Personal Data Public Sector Jun 2, 2026
ANSPDCP · €12,000 Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Unicredit Bank SA €12,000 on 2026-05-29 for: Insufficient technical and organisational… Security Personal Data Supervisory Authorities May 29, 2026
Italy · €700 Garante per la protezione dei dati personali (Italy) - 385/2026 Facts — A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was… Personal Data Healthcare Retention Period May 28, 2026
Italy · €55,000 Garante per la protezione dei dati personali (Italy) - 419/2026 Facts — The data controller for the case is a government body called the Agency for Digital Italy (AgID). AgID is tasked with driving the adoption of digital technologies in both… Processing Controllers Personal Data May 28, 2026
Italy · €6,000 Garante per la protezione dei dati personali (Italy) - 382/2026 Facts — A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller). The data subject was employed by the Ligurian Social and… DPIA Privacy by Design Privacy by Default May 28, 2026
Poland · €26,711 UODO (Poland) - DKE.561.4.2026 Facts — The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance… Video Surveillance Accountability Monitoring May 22, 2026
NAIH · €1,400 Elektronikus Egészségügyi Szolgáltatási Tér: Insufficient technical and organisational measures to ensure information security Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined Elektronikus Egészségügyi Szolgáltatási Tér €1,400 on 2026-05-20 for: Insufficient… Healthcare Security May 20, 2026
Poland · €33,700 UODO (Poland) - DKN.5131.27.2023 Facts — A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and… Personal Data Controllers Data Breaches May 19, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Security Risk Management System Accountability May 8, 2026
ICO · €1,112,100 South Staffordshire Plc: Insufficient technical and organisational measures to ensure information security Information Commissioner (ICO) fined South Staffordshire Plc €1,112,100 on 2026-05-07 for: Insufficient technical and organisational measures to ensure information security. Security May 7, 2026
Slovenia · €2,802 IP (Slovenia) - 0609-42/2026/7 Facts — A processor was contracted by a company (the controller) to maintain an online store, fix errors, and provide support. This included ensuring that the controller had… Security Controllers Encryption May 1, 2026
ANSPDCP · €2,500 BLUE PROJECTS INDUSTRIES S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined BLUE PROJECTS INDUSTRIES S.R.L. €2,500 on 2026-04-30 for: Insufficient technical and… Security Supervisory Authorities Personal Data Apr 30, 2026
aepd · €300,000 KONECTA BTO, S.L.: Insufficient technical and organisational measures to ensure information security Spanish Data Protection Authority (aepd) fined KONECTA BTO, S.L. €300,000 on 2026-04-22 for: Insufficient technical and organisational measures to ensure information security. Security Supervisory Authorities Apr 22, 2026
aepd · €400,000 CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined Caixabank, S.A. €400,000 for failing to implement sufficient technical and organizational measures to ensure information… Privacy by Default Security Privacy by Design Apr 15, 2026
Poland · €2,415 UODO (Poland) - DKN.5131.7.2022 Facts — An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a… Data Breaches Processors Notification Obligation Apr 13, 2026
ANSPDCP · €2,500 BLUE PROJECTS S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined BLUE PROJECTS S.R.L. €2,500 on 2026-04-03 for: Insufficient technical and organisational… Security Personal Data Supervisory Authorities Apr 3, 2026
€13,491 Legal Person: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Legal Person €13,491 on 2026-03-27 for: Insufficient technical and organisational measures to ensure information… Security Supervision IP Address Mar 27, 2026
Garante · €31,800,000 Intesa Sanpaolo S.p.A.: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) fined Intesa Sanpaolo S.p.A. €31,800,000 on 2026-03-26 for: Insufficient technical and organisational measures to ensure information… Security Insurance Supervisory Authorities Mar 26, 2026
ANSPDCP · €125,000 RENAULT COMMERCIAL ROUMANIE S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined RENAULT COMMERCIAL ROUMANIE S.R.L. €125,000 on 2026-03-25 for: Insufficient technical and… Security Personal Data Supervisory Authorities Mar 25, 2026
ANSPDCP · €4,000 ING Bank NV Amsterdam – Sucursala București S.A.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined ING Bank NV Amsterdam – Sucursala București S.A. €4,000 on 2026-03-23 for: Insufficient… Security Supervisory Authorities Personal Data Mar 23, 2026
aepd · €150,000 ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L. €150,000 for failing to implement sufficient technical and organizational measures to… Integrity and Confidentiality Principle Security Personal Data Mar 20, 2026
Garante · €2,000 Liceo Scientifico Morgagni di Roma: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) fined Liceo Scientifico Morgagni di Roma €2,000 on 2026-03-12 for: Insufficient technical and organisational measures to ensure… Security Education Public Sector Mar 12, 2026
Garante · €40,000 INPS – Istituto nazionale previdenza sociale: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) fined INPS – Istituto nazionale previdenza sociale €40,000 on 2026-03-12 for: Insufficient technical and organisational measures to… Security Education Public Authority Mar 12, 2026
Garante · €2,000 Hanako s.r.l.: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) fined Hanako s.r.l. €2,000 on 2026-03-12 for: Insufficient technical and organisational measures to ensure information security. Security Supervisory Authorities Healthcare Mar 12, 2026
aepd · €650,000 IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA: Insufficient technical and organisational measures to ensure information security Spanish Data Protection Authority (aepd) fined IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA €650,000 on 2026-03-11 for: Insufficient technical and organisational measures to… Security Supervisory Authorities Mar 11, 2026
Garante · €32,000 Dedalus Italia S.p.A.: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) fined Dedalus Italia S.p.A. €32,000 on 2026-02-26 for: Insufficient technical and organisational measures to ensure information… Security Telecommunications Supervisory Authorities Feb 26, 2026
ANSPDCP · €3,000 Your Consulting SRL: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Your Consulting SRL €3,000 on 2026-02-19 for: Insufficient technical and organisational… Security Personal Data Supervisory Authorities Feb 19, 2026
€5,500 Slovenia DPA: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined an unnamed party €5,500 on 2026-02-16 for: Insufficient technical and organisational measures to ensure… Security Supervisory Authorities Supervision Feb 16, 2026
Spain · €150,000 AEPD (Spain) - EXP202306354 (PS/00312/2024) Facts — The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party… Personal Data Integrity and Confidentiality Principle Controllers Feb 11, 2026
ANSPDCP · €10,000 GENPACT ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational… Access Controls Security Processing Agreement Feb 4, 2026
AP · €25,000 Municipality of Gooise Meren: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Gooise Meren. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Public Authority Feb 3, 2026
AP · €25,000 Municipality of Delft: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Delft. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Public Authority Health Data Feb 3, 2026
aepd · €10,000 FREE TECHNOLOGIES EXCOM, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 10,000 on FREE TECHNOLOGIES EXCOM, S.L. The controller had reset user passwords and communicated the new passwords to the clients via… Encryption Integrity and Confidentiality Principle Security Feb 3, 2026
AP · €25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… Political Opinions Health Data Controllers Feb 3, 2026
AP · €25,000 Municipality of Tilburg: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Tilburg. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Controllers Public Authority Feb 3, 2026