Skip to content
Content type · 1,530 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Italy · €20,000 Garante per la protezione dei dati personali (Italy) - 471/2026 Facts — The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Personal Data Fairness & Transparency Right to be Forgotten Jul 18, 2026
Italy · €16,000 Garante per la protezione dei dati personali (Italy) - 10192784 Facts — The data subject, a professional registered with the OPI of Pisa, discovered while consulting the Public Register of Professionals online that the database included the… Personal Data Retention Period Controllers Jul 16, 2026
Spain AEPD (Spain) - E/03783/2020 Facts — The Directorate for National Security of the Ministry of Interior issued guidelines for the police forces to monitor news and social networks to spot fake news and… Social Media Monitoring Personal Data Jul 15, 2026
Spain · €140 AEPD (Spain) - EXP202310345 Facts — On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Telecommunications Accountability Personal Data Jul 13, 2026
Romania · €26,172 ANSPDCP (Romania) - 02/07/2026 Facts — The Romanian DPA (ANSPDCP) launched an investigation into a bank, Banca Transilvania S.A. (the controller), following a data subject’s complaint. The data subject claimed… Integrity and Confidentiality Principle Data Breaches Personal Data Jul 3, 2026
Lithuania · €450,000 VDAI (Lithuania) - 3R-1143 Facts — Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and… Security Data Breaches Access Controls Jun 19, 2026
Poland · €2,760 UODO (Poland) - DKN.5131.34.2023 Facts — An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account… Data Breaches Notification Obligation Security Jun 13, 2026
Italy · €55,000 Garante per la protezione dei dati personali (Italy) - 419/2026 Facts — The data controller for the case is a government body called the Agency for Digital Italy (AgID). AgID is tasked with driving the adoption of digital technologies in both… Controllers Processing Personal Data May 28, 2026
Poland · €33,700 UODO (Poland) - DKN.5131.27.2023 Facts — A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and… Personal Data Controllers Data Breaches May 19, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Risk Management System Security Infringement Reporting May 8, 2026
€6,600 Utility Company: Insufficient legal basis for data processing Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Utility Company €6,600 on 2026-04-15 for: Insufficient legal basis for data processing. IP Address Processing Supervision Apr 15, 2026
Spain · €150,000 AEPD (Spain) - EXP202306354 (PS/00312/2024) Facts — The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party… Personal Data Integrity and Confidentiality Principle Controllers Feb 11, 2026
ANSPDCP · €20,000 Tensa Art Design S.A: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 20,000 onTensa Art Design S.A.The DPA began investigating the controller's data processing activities, but the controller failed to… Supervisory Authorities Controllers Supervision Feb 5, 2026
ICO · €284,450 MediaLab.AI, Inc.: Insufficient legal basis for data processing The UK DPA has imposed a fine of GBP 247,590 (EUR 284,450) on MediaLab.AI, Inc.The controller of the image-sharing and hosting platform Imgur failed to implement age verification.… Minors Controllers Consent Feb 5, 2026
AP · €25,000 Municipality of Eindhoven: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Eindhoven. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Controllers Feb 3, 2026
AP · €25,000 Municipality of Veenendaal: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Controllers Feb 3, 2026
AP · €25,000 Municipality of Ede: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Ede. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Public Authority Controllers Feb 3, 2026
AP · €25,000 Municipality of Zoetermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Zoetermeer. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Public Authority Health Data Feb 3, 2026
AP · €25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… Political Opinions Health Data Public Authority Feb 3, 2026
ANSPDCP · €1,000 Alliance for the Union of Romanians (AUR) Party: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on the Alliance for the Union of Romanians (AUR) Party. The controller failed to react adequately to a data subject's request to… Personal Data Controllers Processing Agreement Feb 3, 2026
AP · €25,000 Municipality of Delft: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Delft. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Public Authority Health Data Feb 3, 2026
AP · €25,000 Municipality of Tilburg: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Tilburg. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Public Authority Feb 3, 2026
AP · €25,000 Municipality of Huizen: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Huizen. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Controllers Feb 3, 2026
AP · €25,000 Municipality of Gooise Meren: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Gooise Meren. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Public Authority Feb 3, 2026
AP · €25,000 Municipality of Hilversum: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Hilversum. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Public Authority Feb 3, 2026
ANSPDCP · €15,000 Continental Automotive Products SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Continental Automotive Products SRL. The controller failed to implement adequate technical and organisational measures,… Security Controllers Processing Agreement Jan 19, 2026
Italy · €1,500 Garante per la protezione dei dati personali (Italy) - 10214411 Facts — The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of… Video Surveillance Controllers Fairness & Transparency Jan 16, 2026
ANSPDCP · €8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PREMIER RESTAURANTS ROMANIA SRL. The controller failed to implement adequate technical and organisational measures, resulting… Security Controllers Processing Agreement Jan 13, 2026
UODO · €18,500 Commandant van de Stedelijke Politie van Krakau: Niet-naleving van de algemene principes voor gegevensverwerking. 18.500 euro boete - Poolse nationale autoriteit voor de bescherming van persoonlijke gegevens (UODO). Health Data Personal Data Processing NL Jan 9, 2026
UODO · €18,500 Komendanta Miejskiego Policji w Krakowie: Non-compliance with general data processing principles The Polish DPA has imposd a fine of EUR 18,500 on the Komendanta Miejskiego Policji w Krakowie. The controller published personal data, including health data, of a data subject… Personal Data Health Data Healthcare Jan 9, 2026
CNIL · €15,000,000 FREE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 15,000,000 on FREE. The controller suffered a data breach due to insufficient technical and organisational measures. This was caused by… Data Breaches Access Controls Security Jan 8, 2026
CNIL · €15,000,000 ONVOLDRAAGLIJK: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. De Franse autoriteit voor gegevensbescherming (CNIL) heeft FREE een boete van 15.000.000 euro opgelegd. Het bedrijf heeft een datalek geleden als gevolg van onvoldoende technische… Security Data Breaches Notification Obligation NL Jan 8, 2026
CNIL · €27,000,000 FREE MOBILE: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 27 miljoen euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). Security Data Breaches Access Controls NL Jan 8, 2026
ANSPDCP · €2,000 Money Seeds S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Money Seeds S.R.L. The controller failed to fulfil a data subject's request to exercise their rights. Personal Data Controllers Processing Agreement Jan 8, 2026
CNIL · €27,000,000 FREE MOBILE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 27,000,000 on FREE MOBILE. The controller suffered a data breach due to insufficient technical and organisational measures. This was… Data Breaches Access Controls Telecommunications Jan 8, 2026
UODO · €232,379 Polish Postal Service: Lack of appointment of data protection officer The Polish DPA has imposed a fine of EUR 232,379 on the Polish Postal Service. The controller appointed a person as DPO who also held a managerial position with authority over… Supervisory Authorities Public Sector Public Authority Jan 2, 2026
HDPA · €5,000 REVMA PLUS Retail S.A.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 5,000 on REVMA PLUS Retail S.A.. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… Controllers Processors Security Dec 31, 2025
HDPA · €10,000 Thessaloniki–Thessaly Gas Supply Company S.A.: Insufficient data processing agreement The Greek DPA has imposed a fine of EUR 10,000 on Thessaloniki–Thessaly Gas Supply Company S.A. The controller, an energy provider, used external processors for direct marketing… Processing Agreement Controllers Processors Dec 31, 2025
CNIL · €3,500,000 Company: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 3,500,000 on a company. The controller operated a loyalty program in France and 16 other EU countries, using customer data obtained… DPIA Processing Agreement Controllers Dec 30, 2025
SLOVAKIA DPA: Insufficient fulfilment of data subjects rights A Data Controller failed to comply with data subject´s request to access his/her personal data processed by audio recordings. Slovak Data Protection Office Controllers Personal Data Data Controller Dec 30, 2025
azop · €20,000 Telecommunications company: Insufficient legal basis for data processing The Croatian DPA (azop) has imposed a fine of EUR 20,000 on a telecommunications company. A data subject had filed a complaint with the DPA claiming that the company was still… Accuracy Personal Data Telecommunications Dec 30, 2025
UOOU · €3,140 UniCredit Bank Czech Republic and Slovakia, a.s.: Insufficient legal basis for data processing The bank established a personal bank account for a data subject without his consent or knowledge. The bank supposedly had his personal data available because the subject had… Personal Data Consent Insurance Dec 30, 2025
UOOU · €980 Individual entrepreneur - no further details published: Insufficient technical and organisational measures to ensure information security The operator of an online game was exposed to several DDoS attacks which caused the malfunctioning of the servers. The attacker blackmailed the operator stating that the attacks… Security Law Enforcement Personal Data Dec 30, 2025
aepd · €12,000 Madrileña Red de Gas: Insufficient technical and organisational measures to ensure information security The gas company did not have appropriate measures in place to verify the identity of the data subject. The person who filed the complaint alleges that the company e-mailed his… Security Personal Data Law Enforcement Dec 30, 2025
aepd · €10,000 Ikea Ibérica: Insufficient legal basis for data processing The company installed cookies on an end users terminal device without prior consent of the data subject. Cookies Consent Personal Data Dec 30, 2025
aepd · €60,000 Debt collecting agancy (GESTIÓN DE COBROS, YO COBRO SL): Insufficient legal basis for data processing After the claimant did alledgedly not pay back a microcredit to an online credit agany, the claim was assigned to the debt collecting agancy. Subsequently, the latter startet… Insurance Processing Supervisory Authorities Dec 30, 2025
ANSPDCP · €10,000 Roumasport S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on Roumasport S.R.L The controller failed to implement adequate technical and organisational measures, resulting in multiple… Security Law Enforcement Processing Agreement Dec 30, 2025
aepd · €1,600 NAROBESA INV, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,600 on NAROBESA INV, S.L. The controller failed to react to requests made by the DPA. The original fine of EUR 2,000 was reduced to EUR… Supervisory Authorities Supervision Controllers Dec 29, 2025
aepd · €600 4USPORT INSTALACIONES DEPORTIVAS, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 300 on 4USPORT INSTALACIONES DEPORTIVAS, S.L. The controller failed to react to requests made by the DPA. Supervisory Authorities Supervision Controllers Dec 20, 2025
aepd · €300 SPAIN DPA: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 300 on an unkonwn person/entity. The controller failed to react to requests made by the DPA. Supervisory Authorities Supervision Law Enforcement Dec 20, 2025