Content type · 1,114 documents in this view · 3,811 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3587 Processing 2635 Personal Data 2394 Controllers 2017 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
€750,000 AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight Vodafone España, S.A.U., the controller, operated a service known as "Super WiFi" through a third-party processor. Following a data breach affecting the service, the DPA's… Spain ·Art. 5, 28, 32 Sep 23, 2026
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Sep 22, 2026
DSB: Retailer must grant full access and delete data after third-party fraud order A retailer (controller) sent a notebook to the address of a data subject after having received an order to that address. However, the data subject has never placed the order and… DSB-D124.2016/23 ·Austria ·Art. 6, 13, 14 +2 Aug 26, 2026
Austrian DSB: e-marketplace transfer of customer data to China and US requires valid Art. The DPA was acting upon a complaint addressing the subject matter of third country personal data transfers. The controller, established in Ireland, operates an e-marketplace… D130.2269 ·Austria ·Art. 45, 46, 49 Aug 25, 2026
€15,300 10266250 The data subject received unsolicited promotional phone calls and a email containing contractual information from Green Partner (the processor), despite the data subject's phone… Italy · ·Art. 5, 6, 7 +6 Aug 19, 2026
€1,282 IP-RS · 0609-41/2026/7 A company (the controller) used a service provider (the processor) to store personal data, manage a database, and provide technical support and maintenance on its behalf. A legal… Slovenia ·Art. 28
€200,000M 15/2026 The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information… Greece · ·Art. 5, 28, 32 Jul 28, 2026
€5.8M Hera Comm S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Hera Comm S.p.A. €5,800,000 for violations of the general data processing principles under Article 5 of the GDPR, alongside… Italy · ·Art. 5, 12, 13 +3 Jul 3, 2026
UODO reprimands hospital for inadequate processor oversight and email security failures The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Poland ·Art. 5, 24, 25 +3 Jun 11, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland · ·Art. 5, 28, 30 +2 Jun 11, 2026
€100,000 ZeniΘ (Thessaloniki-Thessalia Gas Supply Company S.A.): Insufficient fulfilment of data subjects rights The Hellenic Data Protection Authority (HDPA) fined ZeniΘ (Thessaloniki-Thessalia Gas Supply Company S.A.) €100,000 for insufficient fulfillment of data subjects' rights,… Greece · ·Art. 5, 12, 15 +1 Jun 5, 2026
HUF 15M NAIH-450-7-2026 The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 May 12, 2026
€2,415 UODO reprimands electricity seller for Art. 5, 24, 25, 28, 32 GDPR violations over An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone… Poland ·Art. 5, 24, 25 +2 Apr 13, 2026
€2,415 Sole trader: Insufficient technical and organisational measures to ensure information security The Polish National Personal Data Protection Office (UODO) fined a sole trader operating in the industry and commerce sector €2,415 for failing to implement sufficient technical… Poland · ·Art. 28, 32 Apr 13, 2026
€60,000 AEPD: Ramona Films failed to comply with Article 58(2) order to provide processor RAMONA FILMS, S.L., the controller, operated websites offering audiovisual content through subscriptions. In November 2023, the DPA fined the controller in proceedings… Spain ·Art. 28, 58 Mar 9, 2026
€1,000 Spain DPA: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) fined an unnamed party €1,000 on 2026-03-01 for: Non-compliance with general data processing principles. ·Art. 5 ·Non-compliance with general data processing principles Mar 1, 2026
€15,000 Ministry of Enterprises and Made in Italy: Insufficient data processing agreement ⇄ Italian Data Protection Authority (Garante) fined Ministry of Enterprises and Made in Italy €15,000 on 2026-02-26 for: Insufficient data processing agreement. ·Art. 28 ·Insufficient data processing agreement Feb 26, 2026
€5,000 KEAT - Centre for Education & Rehabilitation of the Blind: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) fined KEAT - Centre for Education & Rehabilitation of the Blind €5,000 on 2026-02-20 for: Insufficient fulfilment of data subjects rights. Greece · ·Art. 12, 15 Feb 20, 2026
€5,500 Slovenia DPA: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined an unnamed party €5,500 on 2026-02-16 for: Insufficient technical and organisational measures to ensure… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Feb 16, 2026
€150,000 The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested a duplicate SIM card for the mobile line of a data subject. The request was… EXP202306354 (PS/00312/2024) ·Spain ·Art. 5, 6 Feb 11, 2026
€30,000 Vodafone – PANAFON A.E.E.T.: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) fined Vodafone – PANAFON A.E.E.T. €30,000 on 2026-02-11 for: Insufficient fulfilment of data subjects rights. Greece · ·Art. 12, 15, 18 Feb 11, 2026
€1,800 Landlord: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,800 on a Landlord. The landlord used video surveillance in rental apartments without having a sufficient legal basis. The original fine… SPAIN · ·Art. 6 Feb 6, 2026
€20,000 Tensa Art Design S.A: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 20,000 onTensa Art Design S.A.The DPA began investigating the controller's data processing activities, but the controller failed to… ROMANIA · ·Art. 58, 83 Feb 5, 2026
€2.7M DPD Polska sp. z o.o.: Insufficient data processing agreement ⇄ Polish National Personal Data Protection Office (UODO) fined DPD Polska sp. z o.o. €2,682,000 on 2026-02-05 for: Insufficient data processing agreement. Poland · ·Art. 5, 24, 29 +1 Feb 5, 2026
€284,450 MediaLab.AI, Inc.: Insufficient legal basis for data processing The UK DPA has imposed a fine of GBP 247,590 (EUR 284,450) on MediaLab.AI, Inc.The controller of the image-sharing and hosting platform Imgur failed to implement age verification.… UNITED KINGDOM · ·Insufficient legal basis for data processing Feb 5, 2026
€10,000 GENPACT ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Feb 4, 2026
€10,000 FREE TECHNOLOGIES EXCOM, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 10,000 on FREE TECHNOLOGIES EXCOM, S.L. The controller had reset user passwords and communicated the new passwords to the clients via… SPAIN · ·Art. 32 Feb 3, 2026
€25,000 Municipality of Eindhoven: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Eindhoven. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Tilburg: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Tilburg. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Veenendaal: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Zoetermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Zoetermeer. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Gooise Meren: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Gooise Meren. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Delft: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Delft. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€1,000 Alliance for the Union of Romanians (AUR) Party: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on the Alliance for the Union of Romanians (AUR) Party. The controller failed to react adequately to a data subject's request to… ROMANIA · ·Art. 12, 15, 17 +1 Feb 3, 2026
€25,000 Municipality of Ede: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Ede. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Hilversum: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Hilversum. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Huizen: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Huizen. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€10,000 Natural Person: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 10,000 on a natural person. The controller operated a website on which identity cards containing personal data, including special… ROMANIA · ·Art. 5, 6, 9 +6 Jan 30, 2026
€565,000 Sportadmin i Skandinavien AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 565,500 on Sportadmin i Skandinavien AB. The controller suffered a sucessfull cyber attack, resulting in personal and special category… SWEDEN · ·Art. 32 Jan 26, 2026
€5M FRANCE TRAVAIL: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 5,000,000 on FRANCE TRAVAIL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures,… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 22, 2026
€4,850 Slovenia DPA: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined an unnamed party €4,850 on 2026-01-20 for: Insufficient technical and organisational measures to ensure… ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Jan 20, 2026
€15,000 Continental Automotive Products SRL: Insufficient technical and organisational measures to ensure information security. ⇄ Boete van €15.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 5, 32 Jan 19, 2026
€15,000 Continental Automotive Products SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Continental Automotive Products SRL. The controller failed to implement adequate technical and organisational measures,… ROMANIA · ·Art. 5, 32 Jan 19, 2026
€1,200 Dental Clinic: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,200 on a dental clinic. The controller used video surveillance in its clinic for security purposes, including a camera in the doctor's… SPAIN · ·Art. 5 Jan 19, 2026
€1,500 10214411 The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of security… Italy · ·Art. 5, 6, 13 +2 Jan 16, 2026
€21,650 Timegrip AS: Insufficient fulfilment of data subjects rights The Norwegian DPA has imposed a fine of EUR 21,650 on Timegrip AS. The controller had been tracking the working hours of employees at a company that went bankrupt. A former… NORWAY · ·Art. 15 Jan 16, 2026
€500,000 AEPD fines bank €500,000 for losing customer documents via courier service (Art. 32) Facts: The data protection authority (DPA) has fined a bank €500,000 after documents belonging to a customer were lost during delivery by a courier service. The authority ruled… Spain ·Art. 32 Jan 13, 2026
€1M CNIL fines data processor €1,000,000 for unlawful retention, purpose conflict, and no ROPA The data protection authority (DPA) has imposed a fine of 1 million euros on a data processor for failing to delete user personal data, processing that data for purposes that… France Jan 13, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organizational measures to ensure information security. ⇄ 8.000 euro boete - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Jan 13, 2026