Skip to content
Content type · 539 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 539 sort newestlargest fineoldest
€5,000 Italian DPA: Municipality of Aprilia unlawfully disclosed whistleblower data to employer The data subject, an employee of a municipal agency, sent a certified email to the Municipality of Aprilia (the controller), requesting a meeting with its Extraordinary Commission… Italy ·Garante ·Art. 5, 6 Public Authority Supervisory Authorities Personal Data Sep 30, 2026
€30,000 Garante: Bologna University Hospital rightly refused erasure of recruitment ranking data The DPA received a complaint from a data subject, regarding the ranking list published as part of a recruitment procedure at the Bologna University Hospital IRCCS (the… Italy ·Art. 5, 6, 9 Personal Data Retention Period Healthcare Sep 29, 2026
Persónuvernd: Icelandic Farmers’ Association breached GDPR by disclosing owner data to The DPA received a complaint from a data subject, after the Icelandic Farmers’ Association operating a database, disclosed her personal data without consent to the company… 2025010358 ·Iceland ·Art. 5, 14 Legitimate Interest Personal Data Fairness & Transparency Sep 23, 2026
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Data Breaches Notification Obligation Controllers Sep 22, 2026
Icelandic DPA: City of Reykjavik cannot request bank statements from NPA disabled service The DPA received a request from a the NPA Centre, the service manager of services for disabled people with long-term care needs, asking whether the Social Services Department of… 2025020567 ·Iceland ·Persónuvernd Supervisory Authorities Public Authority Personal Data Sep 17, 2026
€140 AEPD fines DIGI Telecom for issuing duplicate SIM to impersonator without consent On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Spain ·Art. 5, 6, 83 Consent Integrity and Confidentiality Principle Personal Data Sep 16, 2026
€20,000 AEPD fines El Español for publishing video of minor assailant without anonymization El León de El Español Publicaciones, S.A., the controller, operates the Spanish digital newspaper „El Español“. It published an article concerning an assault and embedded a video… Spain ·Art. 5, 25, 58 Anonymization Privacy by Design & Default Privacy by Default Sep 16, 2026
€6,000 Italian DPA: Municipality of Rieti breached GDPR by publishing 31,000 taxpayers' waste The Municipality of Rieti (the controller) published its administrative acts on its official notice board and in the "Transparent Administration" section of its website. A… Italy ·Garante ·Art. 5, 12, 24 +3 Public Authority Supervisory Authorities Integrity and Confidentiality Principle
AEPD: Data subject entitled to identity of professionals who accessed medical records Suspecting unauthorised access to his medical records, a public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide a log copy of… pd-00055-2026 ·Spain ·Art. 5, 12, 15 +2 Personal Data Healthcare Right of Access Sep 15, 2026
HDPA investigates Greek Infrastructure Ministry for SMS sent without consent or The DPA started an investigation, after receiving 83 complaints from data subjects, against the Ministry of Infrastructure and Transportation (the controller). Particularly,… 17/2026 ·Greece ·Art. 5, 14 Consent Right to Object Personal Data Sep 15, 2026
€3,150 APDCAT: Public body violated GDPR by disclosing audio recording to four extra recipients On 22 January 2025, an employee and trade union representative of a public-sector organisation, the data subject, emailed the DPO requesting access to and a copy of a recording of… Spain ·Art. 5, 6, 12 +1 Personal Data Right of Access Integrity and Confidentiality Principle Sep 15, 2026
€10,000 Italian DPA finds Ministry of Education's disclosure of disciplinary dismissal excessive The data subject, an employee of the Ministry of Education and Merit (the controller), filed a complaint with the DPA after the controller notified various administrative branches… Italy ·Garante ·Art. 5, 6 Supervisory Authorities Personal Data Retention Period Sep 9, 2026
€10,000 Garante · 551/2026 The Bologna University Hospital IRCCS (the controller), published on its website a pdf list containing the names and the eligibility status of candidates to an income-based… Italy ·Art. 5, 6, 9 Personal Data Types of Special Categories of Personal Data Integrity and Confidentiality Principle
€2,000 AEPD · ps-00256-2025 After receiving an in-person visit at her address, a data subject received a letter from a third party concerning a plot of land. The third party asked the data subject to… Spain ·Art. 6 Personal Data Recipient Legitimate Interest Sep 8, 2026
Finnish DPA orders Espoo to ensure pupil data protection in Google learning tools In April 2018, the DPA received a complaint stating that the city of Espoo (the controller) was using Google's digital learning tools in a school without obtaining consent from… TSV/40/2018 ·Finland ·Tietosuojavaltuutettu Supervisory Authorities Controllers Retention Period Sep 4, 2026
€8,000 Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) found that Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento (A.S.I.S.) unlawfully installed video… Italy ·Garante ·Art. 5, 6, 12 +1 Retention Period Storage Limitation Personal Data Sep 3, 2026
AEPD: Canals City Council breached Art. 5(1)(f) GDPR by discarding exam papers unshredded The DPA became aware that examination papers from an employment-training programme managed by Canals City Council, the controller, had been found next to waste containers in a… PS-00506-2026 ·Spain ·Art. 5 Integrity and Confidentiality Principle Data Breaches Notification Obligation Sep 2, 2026
Datatilsynet authorises AC Horsens facial recognition at matches under conditions AC Horsens (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial recognition… 09-07-2026 ·Denmark ·Datatilsynet (DK) DPIA Access Controls Prior Consultation
09-07-2026 (Lyngby Boldklub) Lyngby Boldklub (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial… 09-07-2026 ·Denmark ·Datatilsynet (DK) DPIA Access Controls Prior Consultation
09-07-2026 (Lyngby Boldklub) Lyngby Boldklub (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial… 09-07-2026 ·Denmark ·Datatilsynet (DK) DPIA Access Controls Prior Consultation Sep 1, 2026
DSB: Retailer must grant full access and delete data after third-party fraud order A retailer (controller) sent a notebook to the address of a data subject after having received an order to that address. However, the data subject has never placed the order and… DSB-D124.2016/23 ·Austria ·Art. 6, 13, 14 +2 Personal Data Right of Access Right to be Forgotten Aug 26, 2026
Datatilsynet reprimands Danish Tax Administration for access request delays (2019-2024) In November 2024 the DPA started an investigation against the Danish Tax Administration (‘the controller’) for their processing time of access requests. 30 September 2025 the DPA… 2024-432-0039 ·Denmark ·Datatilsynet (DK) Right of Access Personal Data Supervisory Authorities
HDPA orders TEIRESIAS S.A. to ensure data accuracy under Art. 5(1)(d) GDPR 29 January 2023, the data subject requested TEIRESIAS S.A. (‘the controller’) to delete an entry registered in their database, and to correct the “erroneous financial data”… 4/2026 ·Greece ·Art. 5 Accuracy Personal Data Right to Restriction
Finnish DPA examines anti-doping organization's GDPR compliance over public suspension An athlete (the data subject) gave a doping sample containing a low concentration of a banned substance in August 2020. The national anti-doping organisation (the controller)… TSV/179/2021 ·Finland ·Tietosuojavaltuutettu Supervisory Authorities Personal Data Retention Period Aug 4, 2026
€200,000M 15/2026 The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information… Greece ·HDPA ·Art. 5, 28, 32 Controllers Data Breaches Integrity and Confidentiality Principle Jul 28, 2026
€10,000 Monza and Brianza Local Education Authority: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Monza and Brianza Local Education Authority €10,000 for failing to establish a sufficient legal basis for data processing… Italy ·Garante ·Art. 5, 6 Personal Data Public Authority Supervision Jul 23, 2026
€8,000 Municipality of Terralba: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of Terralba €8,000 for processing personal data without a sufficient legal basis. The Garante found that the… Italy ·Garante ·Art. 5, 6, 24 +2 Processing Personal Data Public Authority Jul 23, 2026
€2,000 Ancel Keys Comprehensive School Castelnuovo Cilento: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Ancel Keys Comprehensive School Castelnuovo Cilento €2,000 for processing personal data without a sufficient legal basis,… Italy ·Garante ·Art. 5, 6, 9 Personal Data Public Authority Supervisory Authorities Jul 23, 2026
€30,000 Emiglia-Romagna Regional Employment Agency: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Emiglia-Romagna Regional Employment Agency €30,000 for violations of Articles 5, 6, and 9 of the GDPR concerning an… Italy ·Garante ·Art. 5, 6, 9 Legitimate Interest Personal Data Processing Jul 23, 2026
€500,000 Hôpital privé de la Loire: Insufficient technical and organisational measures to ensure information security The French Data Protection Authority (CNIL) sanctioned Hôpital Privé de la Loire, a Ramsay Santé group hospital, following a June 2025 personal data breach in which an attacker… France ·CNIL ·Art. 32, 34 Data Breaches Notification Obligation Healthcare Jul 21, 2026
€300,000 CNIL fines EXTIA for failing to properly handle job applicant erasure requests EXTIA, the controller, is a French consulting company specialising in IT and engineering services. As part of its recruitment activities, the controller processed personal data of… France ·Art. 12, 17 Right to be Forgotten Personal Data Right to Restriction Jul 21, 2026
€12,000 Garante · 10254256 The data subject was an employee at a detention facility run by the Italian Ministry of Justice (the controller). Following an assessment by the occupational health physician, who… Italy ·Art. 4, 5, 6 +2 Personal Data Health Data Types of Special Categories of Personal Data
€20,000 Garante · 471/2026 The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Italy ·Art. 5, 6, 10 +1 Personal Data Retention Period Criminal Data Jul 18, 2026
APDCAT sanctions Madremanya City Council for inadequate redaction of sensitive data in On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing… PS-0036/2026 ·Spain ·Art. 5, 31 Integrity and Confidentiality Principle Personal Data Identification Jul 17, 2026
€50,000 Garante · 10128005 The Calabrian Regional Agency for Agricultural Development (the controller) implemented a remote work policy that required employees to use a time-tracking application called… Italy ·Art. 5, 6, 13 +3 Personal Data Monitoring DPIA
€6,000 Municipality of Rieti: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Municipality of Rieti €6,000 for violations of general data processing principles under the GDPR. The enforcement action… Italy ·Garante ·Art. 5, 12, 24 +3 Privacy by Design Retention Period Supervision Jul 14, 2026
€2M Garante fines Lusha Systems Inc. over unauthorized B2B contact database Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was a… Italy ·Art. 3, 5, 6 +2 Personal Data IP Address Legitimate Interest Jul 14, 2026
€2,000 Municipality of San Genesio and Uniti: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of San Genesio and Uniti €2,000 for processing personal data without a sufficient legal basis. The Authority… Italy ·Garante ·Art. 5, 6, 9 Personal Data Processing Public Authority Jul 3, 2026
€2,000 Municipality of Villaputzu: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of Villaputzu €2,000 for processing personal data without a sufficient legal basis. The enforcement action… Italy ·Garante ·Art. 5, 6 Personal Data Processing Public Authority Jul 3, 2026
€15,000 University of Pisa: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the University of Pisa €15,000 for failing to implement adequate technical and organizational measures to ensure information… Italy ·Garante ·Art. 5, 6, 25 +1 Security Personal Data Public Authority Jul 3, 2026
2025010364 The DPA received a complaint from a data subject regarding the processing of their personal data by Borgarholtsskóli (a school and the controller) in connection with an anonymous… 2025010364 ·Iceland ·Persónuvernd Personal Data Fairness & Transparency Right to be Forgotten Jun 24, 2026
€5,000 Garante · 457/2026 The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A… Italy ·Art. 5, 6, 12 +2 DPIA Personal Data Fairness & Transparency Jun 18, 2026
€90,000 Acquirente Unico S.p.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) fined Acquirente Unio S.p.A. €90,000 for insufficient fulfilment of data subjects' rights under GDPR Articles 12, 16, and 28. The… Italy ·Garante ·Art. 12, 16, 28 Processors Supervision Controllers Jun 18, 2026
€2,760 UODO fines accounting firm €2,760 for email breach security failures An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained… Poland ·Art. 5, 24, 25 +1 Data Breaches Integrity and Confidentiality Principle Notification Obligation Jun 13, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland ·DPC ·Art. 5, 28, 30 +2 Integrity and Confidentiality Principle Notification Obligation Data Breaches Jun 11, 2026
€1,000 Pietro d'Abano State Vocational School: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Pietro d'Abano State Vocational School €1,000 for processing personal data without a sufficient legal basis, finding… Italy ·Garante ·Art. 5, 6 Personal Data Processing Public Authority Jun 11, 2026
€5,000 Municipality of Vasto: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined the Municipality of Vasto €5,000 for failing to adequately fulfill its information obligations under the GDPR. The authority… Italy ·Garante ·Art. 5, 12, 13 +1 Accountability Personal Data DPIA Jun 8, 2026
€23,540 Minister of Justice: Insufficient technical and organisational measures to ensure information security Polish National Personal Data Protection Office (UODO) fined Minister of Justice €23,540 on 2026-06-02 for: Insufficient technical and organisational measures to ensure… Poland ·UODO ·Art. 32 Security Personal Data Education Jun 2, 2026
UODO fines controller for refusing to cooperate and provide information in two data The DPA received two complaints against the same company (the controller) due to the unauthorised access to the data subjects’ personal data. The first complaint concerned… DKE.561.1.2026 ·Poland ·Art. 31, 58 Controllers Personal Data Supervisory Authorities Jun 1, 2026
€6,000 Municipality of Sciacca: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of Sciacca €6,000 for processing personal data without a sufficient legal basis. The Garante found that the… Italy ·Garante ·Art. 5, 6 Personal Data Public Authority Supervisory Authorities May 28, 2026