Skip to content
Content type · 2,394 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 2,394 sort newestlargest fineoldest
Tietosuojavaltuutetun toimisto (Finland) - TSV/5059/2023 The DPA held that a pension insurance company had not violated Articles 5(1)(c) and 25(2) GDPR by disclosing a disability pension applicant's accrued pension in euros to a… TSV/5059/2023 ·Tietosuojavaltuutettu Retention Period Insurance GDPR Article 5 Principles of Processing
Icelandic DPA opens formal proceedings against Isavia over ANPR parking cameras at The DPA initiated an investigation into Isavia domestic airports Ltd. (the controller) concerning the electronic monitoring of car parks in five airports: Reykjavík, Akureyri,… 2025061555 ·Iceland ·Persónuvernd Supervisory Authorities Personal Data Fairness & Transparency Sep 30, 2026
€5,000 Italian DPA: Municipality of Aprilia unlawfully disclosed whistleblower data to employer The data subject, an employee of a municipal agency, sent a certified email to the Municipality of Aprilia (the controller), requesting a meeting with its Extraordinary Commission… Italy ·Garante ·Art. 5, 6 Public Authority Supervisory Authorities Personal Data Sep 30, 2026
€30,000 Garante: Bologna University Hospital rightly refused erasure of recruitment ranking data The DPA received a complaint from a data subject, regarding the ranking list published as part of a recruitment procedure at the Bologna University Hospital IRCCS (the… Italy ·Art. 5, 6, 9 Personal Data Retention Period Healthcare Sep 29, 2026
€750,000 AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight Vodafone España, S.A.U., the controller, operated a service known as "Super WiFi" through a third-party processor. Following a data breach affecting the service, the DPA's… Spain ·Art. 5, 28, 32 Processors Controllers Processing Agreement Sep 23, 2026
Persónuvernd: Icelandic Farmers’ Association breached GDPR by disclosing owner data to The DPA received a complaint from a data subject, after the Icelandic Farmers’ Association operating a database, disclosed her personal data without consent to the company… 2025010358 ·Iceland ·Art. 5, 14 Legitimate Interest Personal Data Fairness & Transparency Sep 23, 2026
€39,000 Italian DPA: employer breached Art. 15 GDPR by ignoring access request over disciplinary The data subject, a security guard of La Patria S.p.A. (the controller), complained to the DPA about the lack of response by the controller to two access requests regarding the… Italy ·Garante ·Art. 12, 13, 15 Supervisory Authorities Right of Access Personal Data Sep 23, 2026
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Data Breaches Notification Obligation Controllers Sep 22, 2026
€403M Google Ireland Limited: Insufficient legal basis for data processing The Irish Data Protection Commission (DPC) fined Google Ireland Limited €403 million on September 21, 2026, following an inquiry into the company's processing of personal data… DPC ·Art. 5, 6, 12 +1 ·Insufficient legal basis for data processing Legitimate Interest Personal Data Supervision Sep 21, 2026
Icelandic DPA: City of Reykjavik cannot request bank statements from NPA disabled service The DPA received a request from a the NPA Centre, the service manager of services for disabled people with long-term care needs, asking whether the Social Services Department of… 2025020567 ·Iceland ·Persónuvernd Supervisory Authorities Public Authority Personal Data Sep 17, 2026
€10,000 AEPD fines MÁS SOL ENERGÍA for marketing call to Robinson List subscriber MÁS SOL ENERGÍA 15, S.L., the controller, is a company that carries out customer acquisition through telephone calls to offer solar panel installation services. On 18 November… Spain ·Art. 4, 5, 7 +1 Personal Data IP Address Consent Sep 16, 2026
€20,000 AEPD fines El Español for publishing video of minor assailant without anonymization El León de El Español Publicaciones, S.A., the controller, operates the Spanish digital newspaper „El Español“. It published an article concerning an assault and embedded a video… Spain ·Art. 5, 25, 58 Anonymization Privacy by Design & Default Privacy by Default Sep 16, 2026
€1M AEPD sanctions Iberdrola Clientes for improper identity verification and unauthorized Iberdrola Clientes, S.A.U., an electricity retailer of the Iberdrola group (the controller), verified the identity of customers calling its call centres under an internal guide… Spain ·Art. 24, 32, 58 +1 Identification Personal Data Accountability
RON 108,570 Fine against Homelux SRL HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR. The controller was operating a website on a platform… Romania ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security Sep 16, 2026
€120 Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on The DPA received several complaints from data subjects concerning Experian Italia S.p.A (the controller) an Italian credit information system. The controller was processing the… Italy ·Garante ·Art. 5, 12, 15 +1 Supervisory Authorities Privacy by Design Personal Data Sep 16, 2026
€140 AEPD fines DIGI Telecom for issuing duplicate SIM to impersonator without consent On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Spain ·Art. 5, 6, 83 Consent Integrity and Confidentiality Principle Personal Data Sep 16, 2026
€6,000 Italian DPA: Municipality of Rieti breached GDPR by publishing 31,000 taxpayers' waste The Municipality of Rieti (the controller) published its administrative acts on its official notice board and in the "Transparent Administration" section of its website. A… Italy ·Garante ·Art. 5, 12, 24 +3 Public Authority Supervisory Authorities Integrity and Confidentiality Principle
AEPD: Data subject entitled to identity of professionals who accessed medical records Suspecting unauthorised access to his medical records, a public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide a log copy of… pd-00055-2026 ·Spain ·Art. 5, 12, 15 +2 Personal Data Healthcare Right of Access Sep 15, 2026
HDPA investigates Greek Infrastructure Ministry for SMS sent without consent or The DPA started an investigation, after receiving 83 complaints from data subjects, against the Ministry of Infrastructure and Transportation (the controller). Particularly,… 17/2026 ·Greece ·Art. 5, 14 Consent Right to Object Personal Data Sep 15, 2026
RON 10,517 Fine against Dormeo Home S.R.L Dormeo Home S.R.L. (the controller), received a request from one of its customers (the data subject) exercising their right to object to direct marketing. Despite this objection,… Romania ·ANSPDCP ·Art. 21 Right to Object Direct Marketing Personal Data
€3,150 APDCAT: Public body violated GDPR by disclosing audio recording to four extra recipients On 22 January 2025, an employee and trade union representative of a public-sector organisation, the data subject, emailed the DPO requesting access to and a copy of a recording of… Spain ·Art. 5, 6, 12 +1 Personal Data Right of Access Integrity and Confidentiality Principle Sep 15, 2026
€6,500 Italian DPA sanctions Top Secret Investigazioni for unjustified email forwarding after The data subjects filed a complaint claiming that Top Secret Investigazioni e sicurezza s.r.l. (the controller) violated the protection of personal data, as a result of failing to… Italy ·Garante ·Art. 5, 13 Supervisory Authorities Retention Period Personal Data Sep 10, 2026
€408,000 AEPD: CaixaBank requested excessive inheritance documentation from heirs A data subject and other heirs were handling the inheritance of a deceased customer through CaixaBank, S.A., the controller. In the course of the inheritance procedure, the… Spain ·Art. 13, 25, 30 Privacy by Design & Default Personal Data Privacy by Design Sep 10, 2026
€10,000 Italian DPA finds Ministry of Education's disclosure of disciplinary dismissal excessive The data subject, an employee of the Ministry of Education and Merit (the controller), filed a complaint with the DPA after the controller notified various administrative branches… Italy ·Garante ·Art. 5, 6 Supervisory Authorities Personal Data Retention Period Sep 9, 2026
IP Slovenia: Controller breached Art. 15(1)(d) and 15(3) GDPR by denying storage info and The data subject made an access request asking for (i) a copy of their personal data processed by the controller and (ii) information on the envisaged storage period of this data.… 0602-68/2025/18 ·IP-RS ·Art. 12, 15 Right of Access Controllers Personal Data Sep 8, 2026
Garante warns ReLife Recycling for failing to timely respond to GDPR access request The data subject sent a complaint to the DPA regarding correspondence between him and the company ReLife Recycling s.r.l. (the controller), which was sent without his consent to… 515/2026 ·Italy ·Art. 12 Right of Access Personal Data Supervisory Authorities
€10,000 Garante · 551/2026 The Bologna University Hospital IRCCS (the controller), published on its website a pdf list containing the names and the eligibility status of candidates to an income-based… Italy ·Art. 5, 6, 9 Personal Data Types of Special Categories of Personal Data Integrity and Confidentiality Principle
€160 The controller owned an apartment rented by the data subject, who had lived in the property since late 2021 Following a dispute concerning the tenancy and an alleged outstanding debt, the controller asked the data subject to leave the property. On 1 October 2023, the controller sent an… ps-0035-2025 ·Spain ·AEPD Integrity and Confidentiality Principle Personal Data Recipient Sep 8, 2026
€2,000 AEPD · ps-00256-2025 After receiving an in-person visit at her address, a data subject received a letter from a third party concerning a plot of land. The third party asked the data subject to… Spain ·Art. 6 Personal Data Recipient Legitimate Interest Sep 8, 2026
RON 26,237 Fine against GEROCOSSEN S.R.L. Gerocossen SRL (the controller) suffered a cyberattack that affected its IT infrastructure. As a result, unauthorised parties gained access to personal data relating to some data… Romania ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security Sep 8, 2026
Finnish DPA orders Espoo to ensure pupil data protection in Google learning tools In April 2018, the DPA received a complaint stating that the city of Espoo (the controller) was using Google's digital learning tools in a school without obtaining consent from… TSV/40/2018 ·Finland ·Tietosuojavaltuutettu Supervisory Authorities Controllers Retention Period Sep 4, 2026
€24,000 Friuli Centrale University Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) found that the Friuli Centrale University Health Authority (ASUFC) violated Articles 5(1)(f), 9, 25, and 32 of the GDPR based on a… Italy ·Garante ·Art. 5, 9, 25 +1 Integrity and Confidentiality Principle Data Breaches Right of Access Sep 3, 2026
€8,000 Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) found that Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento (A.S.I.S.) unlawfully installed video… Italy ·Garante ·Art. 5, 6, 12 +1 Retention Period Storage Limitation Personal Data Sep 3, 2026
€5.5M Banco Bilbao Vizcaya Argentaria S.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) found Banco Bilbao Vizcaya Argentaria, S.A. (Italian branch) violated Articles 5(1)(a), 12, 21, and 24 of the GDPR by continuing to… Italy ·Garante ·Art. 5, 12, 21 +1 Right to Object Personal Data Direct Marketing Sep 3, 2026
Datatilsynet authorises AC Horsens facial recognition at matches under conditions AC Horsens (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial recognition… 09-07-2026 ·Denmark ·Datatilsynet (DK) DPIA Access Controls Prior Consultation
AEPD: Canals City Council breached Art. 5(1)(f) GDPR by discarding exam papers unshredded The DPA became aware that examination papers from an employment-training programme managed by Canals City Council, the controller, had been found next to waste containers in a… PS-00506-2026 ·Spain ·Art. 5 Integrity and Confidentiality Principle Data Breaches Notification Obligation Sep 2, 2026
09-07-2026 (Lyngby Boldklub) Lyngby Boldklub (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial… 09-07-2026 ·Denmark ·Datatilsynet (DK) DPIA Prior Consultation Access Controls
€7,200 UODO fines controller PLN 31,507 for failing to provide information under Art. 58(1) GDPR The DPA launched an investigation into two websites operated by the controller under case number DKN.5101.8.2025. The controller collected the names and the occupations of… Poland ·Art. 58 Controllers Personal Data Supervision Sep 1, 2026
09-07-2026 (Lyngby Boldklub) Lyngby Boldklub (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial… 09-07-2026 ·Denmark ·Datatilsynet (DK) DPIA Access Controls Prior Consultation Sep 1, 2026
€5,320 Slovenian DPA fines controller €5,320 for leaving employee personal data documents Paper documents containing the personal data of employees (the data subjects) were meant to be destroyed at a company (the controller). The personal data in these documents… Slovenia ·IP-RS ·Art. 5, 32 Personal Data Controllers Integrity and Confidentiality Principle Sep 1, 2026
€5,000 GEROCOSSEN S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) sanctioned GEROCOSSEN S.R.L. for failing to implement adequate technical and organizational… Romania ·ANSPDCP ·Art. 32 Security Personal Data Supervisory Authorities Aug 28, 2026
DSB: Retailer must grant full access and delete data after third-party fraud order A retailer (controller) sent a notebook to the address of a data subject after having received an order to that address. However, the data subject has never placed the order and… DSB-D124.2016/23 ·Austria ·Art. 6, 13, 14 +2 Personal Data Right of Access Right to be Forgotten Aug 26, 2026
€23,750 Italian DPA: Il Fatto Quotidiano must erase data subject's personal data from cable car On 4 January 2024, the newspaper “Il Fatto Quotidiano” (‘the controller’) published an article pertaining to the cable car accident of the data subject. The data subject sent a… Italy ·Garante ·Art. 5, 83 Personal Data Supervisory Authorities Retention Period Aug 26, 2026
Austrian DSB: e-marketplace transfer of customer data to China and US requires valid Art. The DPA was acting upon a complaint addressing the subject matter of third country personal data transfers. The controller, established in Ireland, operates an e-marketplace… D130.2269 ·Austria ·Art. 45, 46, 49 Privacy Shield Processing Agreement International Transfer Aug 25, 2026
HDPA orders TEIRESIAS S.A. to ensure data accuracy under Art. 5(1)(d) GDPR 29 January 2023, the data subject requested TEIRESIAS S.A. (‘the controller’) to delete an entry registered in their database, and to correct the “erroneous financial data”… 4/2026 ·Greece ·Art. 5 Accuracy Personal Data Right to Restriction
Datatilsynet reprimands Danish Tax Administration for access request delays (2019-2024) In November 2024 the DPA started an investigation against the Danish Tax Administration (‘the controller’) for their processing time of access requests. 30 September 2025 the DPA… 2024-432-0039 ·Denmark ·Datatilsynet (DK) Right of Access Personal Data Supervisory Authorities
RON 15,728 Fine against Poliserv JG (PJG) SRL A personal data breach occurred because of a cyberattack made possible through a phishing method that stole the credentials of a controller account with administrator privileges.… Romania ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security
€825M Uber Technologies Inc.: Non-compliance with general data processing principles The Dutch Supervisory Authority for Data Protection (AP) fined Uber Technologies Inc. €824,990,000 for non-compliance with general data processing principles, specifically… The Netherlands ·AP ·Art. 13, 14, 22 Automated Decision-Making Supervision Profiling Aug 21, 2026
€280,000 Garante · 10269624 The controller is a publishing company that sells subscriptions to consumer information services through its website. Users can sign up by filling in a registration form on the… Italy ·Art. 6, 7, 12 +2 Right to Object Personal Data Direct Marketing
€3,000 Poliserv JG (PJG) SRL: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Poliserv JG (PJG) SRL €3,000 for failing to implement sufficient technical and… Romania ·ANSPDCP ·Art. 32 Security Personal Data Supervision Aug 19, 2026