Skip to content
Content type · 1,878 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Italy · €20,000 Garante per la protezione dei dati personali (Italy) - 471/2026 Facts — The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Personal Data Fairness & Transparency Criminal Data Jul 18, 2026
Spain AEPD (Spain) - EXP202103746 Facts — A complaint is filed against the controller for having six surveillance cameras facing public highway and private spaces without authorisation. In addition to the claim,… Video Surveillance Retention Period Monitoring Jul 17, 2026
Spain AEPD (Spain) - EXP202102529 Facts — A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as… Consent Healthcare Health Data Jul 16, 2026
Italy · €50,000 Garante per la protezione dei dati personali (Italy) - 10128005 Facts — The Calabrian Regional Agency for Agricultural Development (the controller) implemented a remote work policy that required employees to use a time-tracking application… DPIA Monitoring Personal Data Jul 16, 2026
Spain · €200,000 AEPD (Spain) - PS-00020-2025 Facts — Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware… DPIA Privacy Impact Assessment Data Breaches Jul 16, 2026
Italy · €16,000 Garante per la protezione dei dati personali (Italy) - 10192784 Facts — The data subject, a professional registered with the OPI of Pisa, discovered while consulting the Public Register of Professionals online that the database included the… Personal Data Retention Period Processing Jul 16, 2026
Spain · €140 AEPD (Spain) - EXP202310345 Facts — On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Telecommunications Accountability Personal Data Jul 13, 2026
Romania · €57,839 ANSPDCP (Romania) - Fine against Ascendex Technology SRL Facts — The Romanian DPA (ANSPDCP) launched an investigation into the cryptocurrency exchange platform Ascendex Technology SRL (the controller). The DPA was notified by the French… Supervisory Authorities Controllers Personal Data Jul 9, 2026
Slovenia · €1,198 IP (Slovenia) - 0609-36/2026/7 Facts — A company (the controller) operates an online store. An employee of the controller used a pirated and unlicensed software when creating the website. This software… Integrity and Confidentiality Principle Data Breaches Security Jul 8, 2026
Italy · €158,000 Garante per la protezione dei dati personali (Italy) - 487/2026 Facts — Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows… Processing Artificial Intelligence Personal Data Jul 3, 2026
Romania · €26,172 ANSPDCP (Romania) - 02/07/2026 Facts — The Romanian DPA (ANSPDCP) launched an investigation into a bank, Banca Transilvania S.A. (the controller), following a data subject’s complaint. The data subject claimed… Data Breaches Integrity and Confidentiality Principle Security Jul 3, 2026
Sweden IMY (Sweden) - IMY-2024-2904 Facts — The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the… Personal Data Controllers Supervisory Authorities Jul 3, 2026
Island Persónuvernd (Island) - 2025010358 Facts — The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… Monitoring Integrity and Confidentiality Principle Cloud Computing Jul 1, 2026
Lithuania · €450,000 VDAI (Lithuania) - 3R-1143 Facts — Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and… Security Data Breaches Access Controls Jun 19, 2026
Poland · €2,760 UODO (Poland) - DKN.5131.34.2023 Facts — An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account… Data Breaches Notification Obligation Right of Access Jun 13, 2026
Italy · €55,000 Garante per la protezione dei dati personali (Italy) - 419/2026 Facts — The data controller for the case is a government body called the Agency for Digital Italy (AgID). AgID is tasked with driving the adoption of digital technologies in both… Personal Data Controllers Processing May 28, 2026
Italy · €6,000 Garante per la protezione dei dati personali (Italy) - 382/2026 Facts — A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller). The data subject was employed by the Ligurian Social and… DPIA Privacy by Design Privacy by Default May 28, 2026
Italy · €700 Garante per la protezione dei dati personali (Italy) - 385/2026 Facts — A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was… Personal Data Healthcare Retention Period May 28, 2026
Poland · €26,711 UODO (Poland) - DKE.561.4.2026 Facts — The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance… Fairness & Transparency Video Surveillance Accountability May 22, 2026
UK · €300 ICO (UK) - KRA Consultancy Ltd Facts — The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related… Direct Marketing Telecommunications Marketing May 20, 2026
Poland · €33,700 UODO (Poland) - DKN.5131.27.2023 Facts — A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and… Personal Data Controllers Accountability May 19, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Risk Management System Data Breaches Encryption May 8, 2026
Slovenia · €2,802 IP (Slovenia) - 0609-42/2026/7 Facts — A processor was contracted by a company (the controller) to maintain an online store, fix errors, and provide support. This included ensuring that the controller had… Controllers Security Encryption May 1, 2026
Estonia · €1,000 AKI (Estonia) - No. 2.1-1/24/397-890-38 Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had… Controllers Processors Data Controller Apr 16, 2026
Poland · €2,415 UODO (Poland) - DKN.5131.7.2022 Facts — An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a… Data Breaches Notification Obligation Processors Apr 13, 2026
Spain · €150,000 AEPD (Spain) - EXP202306354 (PS/00312/2024) Facts — The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party… Personal Data Integrity and Confidentiality Principle Controllers Feb 11, 2026
aepd · €1,800 Landlord: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,800 on a Landlord. The landlord used video surveillance in rental apartments without having a sufficient legal basis. The original fine… Video Surveillance Controllers Processing Agreement Feb 6, 2026
ANSPDCP · €20,000 Tensa Art Design S.A: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 20,000 onTensa Art Design S.A.The DPA began investigating the controller's data processing activities, but the controller failed to… Supervisory Authorities Supervision Controllers Feb 5, 2026
ICO · €284,450 MediaLab.AI, Inc.: Insufficient legal basis for data processing The UK DPA has imposed a fine of GBP 247,590 (EUR 284,450) on MediaLab.AI, Inc.The controller of the image-sharing and hosting platform Imgur failed to implement age verification.… Minors Controllers Consent Feb 5, 2026
ANSPDCP · €10,000 GENPACT ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational… Access Controls Security Controllers Feb 4, 2026
AP · €25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… Political Opinions Health Data Controllers Feb 3, 2026
AP · €25,000 Municipality of Eindhoven: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Eindhoven. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Public Authority Feb 3, 2026
AP · €25,000 Municipality of Veenendaal: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Controllers Feb 3, 2026
AP · €25,000 Municipality of Delft: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Delft. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Public Authority Feb 3, 2026
aepd · €10,000 FREE TECHNOLOGIES EXCOM, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 10,000 on FREE TECHNOLOGIES EXCOM, S.L. The controller had reset user passwords and communicated the new passwords to the clients via… Encryption Integrity and Confidentiality Principle Security Feb 3, 2026
ANSPDCP · €1,000 Alliance for the Union of Romanians (AUR) Party: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on the Alliance for the Union of Romanians (AUR) Party. The controller failed to react adequately to a data subject's request to… Personal Data Controllers Processing Agreement Feb 3, 2026
AP · €25,000 Municipality of Tilburg: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Tilburg. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Controllers Public Authority Feb 3, 2026
AP · €25,000 Municipality of Gooise Meren: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Gooise Meren. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Public Authority Health Data Feb 3, 2026
AP · €25,000 Municipality of Hilversum: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Hilversum. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Public Authority Feb 3, 2026
AP · €25,000 Municipality of Ede: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Ede. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Public Authority Controllers Feb 3, 2026
AP · €25,000 Municipality of Huizen: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Huizen. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Controllers Feb 3, 2026
AP · €25,000 Municipality of Zoetermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Zoetermeer. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Public Authority Health Data Feb 3, 2026
ANSPDCP · €10,000 Natural Person: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 10,000 on a natural person. The controller operated a website on which identity cards containing personal data, including special… Criminal Data Personal Data Controllers Jan 30, 2026
€565,000 Sportadmin i Skandinavien AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 565,500 on Sportadmin i Skandinavien AB. The controller suffered a sucessfull cyber attack, resulting in personal and special category… Security Health Data Healthcare Jan 26, 2026
CNIL · €5,000,000 FRANCE TRAVAIL: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 5,000,000 on FRANCE TRAVAIL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures,… Security Health Data Public Sector Jan 22, 2026
ANSPDCP · €15,000 Continental Automotive Products SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Continental Automotive Products SRL. The controller failed to implement adequate technical and organisational measures,… Security Law Enforcement Processing Agreement Jan 19, 2026
aepd · €1,200 Dental Clinic: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,200 on a dental clinic. The controller used video surveillance in its clinic for security purposes, including a camera in the doctor's… Video Surveillance Controllers IP Address Jan 19, 2026
ANSPDCP · €15,000 Continental Automotive Products SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van €15.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). Security Controllers Accountability NL Jan 19, 2026
Datatilsynet · €21,650 Timegrip AS: Insufficient fulfilment of data subjects rights The Norwegian DPA has imposed a fine of EUR 21,650 on Timegrip AS. The controller had been tracking the working hours of employees at a company that went bankrupt. A former… Controllers Personal Data Employees Jan 16, 2026
Italy · €1,500 Garante per la protezione dei dati personali (Italy) - 10214411 Facts — The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of… Video Surveillance Fairness & Transparency Controllers Jan 16, 2026