Content type · 3,587 documents in this view · 3,811 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3587 Processing 2635 Personal Data 2394 Controllers 2017 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
Tietosuojavaltuutetun toimisto (Finland) - TSV/5059/2023 The DPA held that a pension insurance company had not violated Articles 5(1)(c) and 25(2) GDPR by disclosing a disability pension applicant's accrued pension in euros to a… TSV/5059/2023 ·
A private website operator published documents they collected from public registers The DPA held that the operator failed to ensure that later access restrictions imposed by the authorities are considered and that a legitimate interest could not be blanket legal… 2.1.-4/26/1106-2333-4 ·Estonia · Oct 1, 2026
2026-0.690.562 The DPA issued a reprimand against a journalist for failing to comply with the data minimisation principle pursuant to Article 5(1)(c) GDPR by publishing a court decision on his… 2026-0.690.562 ·Austria · Oct 1, 2026
€5,000 Italian DPA: Municipality of Aprilia unlawfully disclosed whistleblower data to employer The data subject, an employee of a municipal agency, sent a certified email to the Municipality of Aprilia (the controller), requesting a meeting with its Extraordinary Commission… Italy · ·Art. 5, 6 Sep 30, 2026
Icelandic DPA opens formal proceedings against Isavia over ANPR parking cameras at The DPA initiated an investigation into Isavia domestic airports Ltd. (the controller) concerning the electronic monitoring of car parks in five airports: Reykjavík, Akureyri,… 2025061555 ·Iceland · Sep 30, 2026
€30,000 Garante: Bologna University Hospital rightly refused erasure of recruitment ranking data The DPA received a complaint from a data subject, regarding the ranking list published as part of a recruitment procedure at the Bologna University Hospital IRCCS (the… Italy ·Art. 5, 6, 9 Sep 29, 2026
€39,000 Italian DPA: employer breached Art. 15 GDPR by ignoring access request over disciplinary The data subject, a security guard of La Patria S.p.A. (the controller), complained to the DPA about the lack of response by the controller to two access requests regarding the… Italy · ·Art. 12, 13, 15 Sep 23, 2026
€750,000 AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight Vodafone España, S.A.U., the controller, operated a service known as "Super WiFi" through a third-party processor. Following a data breach affecting the service, the DPA's… Spain ·Art. 5, 28, 32 Sep 23, 2026
Persónuvernd: Icelandic Farmers’ Association breached GDPR by disclosing owner data to The DPA received a complaint from a data subject, after the Icelandic Farmers’ Association operating a database, disclosed her personal data without consent to the company… 2025010358 ·Iceland ·Art. 5, 14 Sep 23, 2026
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Sep 22, 2026
Icelandic DPA: City of Reykjavik cannot request bank statements from NPA disabled service The DPA received a request from a the NPA Centre, the service manager of services for disabled people with long-term care needs, asking whether the Social Services Department of… 2025020567 ·Iceland · Sep 17, 2026
€6,000 Italian DPA: Municipality of Rieti breached GDPR by publishing 31,000 taxpayers' waste The Municipality of Rieti (the controller) published its administrative acts on its official notice board and in the "Transparent Administration" section of its website. A… Italy · ·Art. 5, 12, 24 +3
€140 AEPD fines DIGI Telecom for issuing duplicate SIM to impersonator without consent On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Spain ·Art. 5, 6, 83 Sep 16, 2026
€10,000 AEPD fines MÁS SOL ENERGÍA for marketing call to Robinson List subscriber MÁS SOL ENERGÍA 15, S.L., the controller, is a company that carries out customer acquisition through telephone calls to offer solar panel installation services. On 18 November… Spain ·Art. 4, 5, 7 +1 Sep 16, 2026
€120 Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on The DPA received several complaints from data subjects concerning Experian Italia S.p.A (the controller) an Italian credit information system. The controller was processing the… Italy · ·Art. 5, 12, 15 +1 Sep 16, 2026
€1M AEPD sanctions Iberdrola Clientes for improper identity verification and unauthorized Iberdrola Clientes, S.A.U., an electricity retailer of the Iberdrola group (the controller), verified the identity of customers calling its call centres under an internal guide… Spain ·Art. 24, 32, 58 +1
RON 108,570 Fine against Homelux SRL HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR. The controller was operating a website on a platform… Romania · ·Art. 32 Sep 16, 2026
€20,000 AEPD fines El Español for publishing video of minor assailant without anonymization El León de El Español Publicaciones, S.A., the controller, operates the Spanish digital newspaper „El Español“. It published an article concerning an assault and embedded a video… Spain ·Art. 5, 25, 58 Sep 16, 2026
RON 10,517 Fine against Dormeo Home S.R.L Dormeo Home S.R.L. (the controller), received a request from one of its customers (the data subject) exercising their right to object to direct marketing. Despite this objection,… Romania · ·Art. 21
HDPA investigates Greek Infrastructure Ministry for SMS sent without consent or The DPA started an investigation, after receiving 83 complaints from data subjects, against the Ministry of Infrastructure and Transportation (the controller). Particularly,… 17/2026 ·Greece ·Art. 5, 14 Sep 15, 2026
€3,150 APDCAT: Public body violated GDPR by disclosing audio recording to four extra recipients On 22 January 2025, an employee and trade union representative of a public-sector organisation, the data subject, emailed the DPO requesting access to and a copy of a recording of… Spain ·Art. 5, 6, 12 +1 Sep 15, 2026
AEPD: Data subject entitled to identity of professionals who accessed medical records Suspecting unauthorised access to his medical records, a public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide a log copy of… pd-00055-2026 ·Spain ·Art. 5, 12, 15 +2 Sep 15, 2026
€6,500 Italian DPA sanctions Top Secret Investigazioni for unjustified email forwarding after The data subjects filed a complaint claiming that Top Secret Investigazioni e sicurezza s.r.l. (the controller) violated the protection of personal data, as a result of failing to… Italy · ·Art. 5, 13 Sep 10, 2026
€408,000 AEPD: CaixaBank requested excessive inheritance documentation from heirs A data subject and other heirs were handling the inheritance of a deceased customer through CaixaBank, S.A., the controller. In the course of the inheritance procedure, the… Spain ·Art. 13, 25, 30 Sep 10, 2026
€10,000 Italian DPA finds Ministry of Education's disclosure of disciplinary dismissal excessive The data subject, an employee of the Ministry of Education and Merit (the controller), filed a complaint with the DPA after the controller notified various administrative branches… Italy · ·Art. 5, 6 Sep 9, 2026
Garante warns ReLife Recycling for failing to timely respond to GDPR access request The data subject sent a complaint to the DPA regarding correspondence between him and the company ReLife Recycling s.r.l. (the controller), which was sent without his consent to… 515/2026 ·Italy ·Art. 12
€2,000 AEPD · ps-00256-2025 After receiving an in-person visit at her address, a data subject received a letter from a third party concerning a plot of land. The third party asked the data subject to… Spain ·Art. 6 Sep 8, 2026
€10,000 Garante · 551/2026 The Bologna University Hospital IRCCS (the controller), published on its website a pdf list containing the names and the eligibility status of candidates to an income-based… Italy ·Art. 5, 6, 9
IP Slovenia: Controller breached Art. 15(1)(d) and 15(3) GDPR by denying storage info and The data subject made an access request asking for (i) a copy of their personal data processed by the controller and (ii) information on the envisaged storage period of this data.… 0602-68/2025/18 · ·Art. 12, 15 Sep 8, 2026
€160 The controller owned an apartment rented by the data subject, who had lived in the property since late 2021 Following a dispute concerning the tenancy and an alleged outstanding debt, the controller asked the data subject to leave the property. On 1 October 2023, the controller sent an… ps-0035-2025 ·Spain · Sep 8, 2026
RON 26,237 Fine against GEROCOSSEN S.R.L. Gerocossen SRL (the controller) suffered a cyberattack that affected its IT infrastructure. As a result, unauthorised parties gained access to personal data relating to some data… Romania · ·Art. 32 Sep 8, 2026
Finnish DPA orders Espoo to ensure pupil data protection in Google learning tools In April 2018, the DPA received a complaint stating that the city of Espoo (the controller) was using Google's digital learning tools in a school without obtaining consent from… TSV/40/2018 ·Finland · Sep 4, 2026
€5.5M Banco Bilbao Vizcaya Argentaria S.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) found Banco Bilbao Vizcaya Argentaria, S.A. (Italian branch) violated Articles 5(1)(a), 12, 21, and 24 of the GDPR by continuing to… Italy · ·Art. 5, 12, 21 +1 Sep 3, 2026
€24,000 Friuli Centrale University Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) found that the Friuli Centrale University Health Authority (ASUFC) violated Articles 5(1)(f), 9, 25, and 32 of the GDPR based on a… Italy · ·Art. 5, 9, 25 +1 Sep 3, 2026
€8,000 Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) found that Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento (A.S.I.S.) unlawfully installed video… Italy · ·Art. 5, 6, 12 +1 Sep 3, 2026
Datatilsynet authorises AC Horsens facial recognition at matches under conditions AC Horsens (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial recognition… 09-07-2026 ·Denmark ·
09-07-2026 (Lyngby Boldklub) Lyngby Boldklub (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial… 09-07-2026 ·Denmark ·
AEPD: Canals City Council breached Art. 5(1)(f) GDPR by discarding exam papers unshredded The DPA became aware that examination papers from an employment-training programme managed by Canals City Council, the controller, had been found next to waste containers in a… PS-00506-2026 ·Spain ·Art. 5 Sep 2, 2026
€5,320 Slovenian DPA fines controller €5,320 for leaving employee personal data documents Paper documents containing the personal data of employees (the data subjects) were meant to be destroyed at a company (the controller). The personal data in these documents… Slovenia · ·Art. 5, 32 Sep 1, 2026
€7,200 UODO fines controller PLN 31,507 for failing to provide information under Art. 58(1) GDPR The DPA launched an investigation into two websites operated by the controller under case number DKN.5101.8.2025. The controller collected the names and the occupations of… Poland ·Art. 58 Sep 1, 2026
09-07-2026 (Lyngby Boldklub) Lyngby Boldklub (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial… 09-07-2026 ·Denmark · Sep 1, 2026
€5,000 GEROCOSSEN S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) sanctioned GEROCOSSEN S.R.L. for failing to implement adequate technical and organizational… Romania · ·Art. 32 Aug 28, 2026
€23,750 Italian DPA: Il Fatto Quotidiano must erase data subject's personal data from cable car On 4 January 2024, the newspaper “Il Fatto Quotidiano” (‘the controller’) published an article pertaining to the cable car accident of the data subject. The data subject sent a… Italy · ·Art. 5, 83 Aug 26, 2026
DSB: Retailer must grant full access and delete data after third-party fraud order A retailer (controller) sent a notebook to the address of a data subject after having received an order to that address. However, the data subject has never placed the order and… DSB-D124.2016/23 ·Austria ·Art. 6, 13, 14 +2 Aug 26, 2026
Austrian DSB: e-marketplace transfer of customer data to China and US requires valid Art. The DPA was acting upon a complaint addressing the subject matter of third country personal data transfers. The controller, established in Ireland, operates an e-marketplace… D130.2269 ·Austria ·Art. 45, 46, 49 Aug 25, 2026
HDPA orders TEIRESIAS S.A. to ensure data accuracy under Art. 5(1)(d) GDPR 29 January 2023, the data subject requested TEIRESIAS S.A. (‘the controller’) to delete an entry registered in their database, and to correct the “erroneous financial data”… 4/2026 ·Greece ·Art. 5
Datatilsynet reprimands Danish Tax Administration for access request delays (2019-2024) In November 2024 the DPA started an investigation against the Danish Tax Administration (‘the controller’) for their processing time of access requests. 30 September 2025 the DPA… 2024-432-0039 ·Denmark ·
RON 15,728 Fine against Poliserv JG (PJG) SRL A personal data breach occurred because of a cyberattack made possible through a phishing method that stole the credentials of a controller account with administrator privileges.… Romania · ·Art. 32
€825M AP (The Netherlands) - Uber B.V and Uber Technologies Inc. Uber B.V. and Uber Technologies Inc., the controllers, used software between 2018 and 2022 to monitor drivers’ behaviour and customer ratings. Where the system detected suspected… Art. 22 Aug 21, 2026
€825M Uber Technologies Inc.: Non-compliance with general data processing principles The Dutch Supervisory Authority for Data Protection (AP) fined Uber Technologies Inc. €824,990,000 for non-compliance with general data processing principles, specifically… The Netherlands · ·Art. 13, 14, 22 Aug 21, 2026