Skip to content
Content type · 2,796 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Poland · €2,760 UODO (Poland) - DKN.5131.34.2023 Facts — An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account… Data Breaches Notification Obligation Security Jun 13, 2026
Poland · €33,700 UODO (Poland) - DKN.5131.27.2023 Facts — A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and… Controllers Personal Data Supervisory Authorities May 19, 2026
Poland · €2,415 UODO (Poland) - DKN.5131.7.2022 Facts — An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a… Data Breaches Notification Obligation Processors Apr 13, 2026
aepd · €1,000 Spain DPA: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) fined an unnamed party €1,000 on 2026-03-01 for: Non-compliance with general data processing principles. Processing Agreement IP Address Processing Mar 1, 2026
Garante · €15,000 Ministero delle Imprese e del Made in Italy: Insufficient data processing agreement Italian Data Protection Authority (Garante) fined Ministero delle Imprese e del Made in Italy €15,000 on 2026-02-26 for: Insufficient data processing agreement. Processing Agreement Education Public Sector Feb 26, 2026
HDPA · €5,000 KEAT - Centre for Education & Rehabilitation of the Blind: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) fined KEAT - Centre for Education & Rehabilitation of the Blind €5,000 on 2026-02-20 for: Insufficient fulfilment of data subjects rights. Education Personal Data Supervisory Authorities Feb 20, 2026
€5,500 Slovenia DPA: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined an unnamed party €5,500 on 2026-02-16 for: Insufficient technical and organisational measures to ensure… Security Supervision Supervisory Authorities Feb 16, 2026
HDPA · €30,000 Vodafone – PANAFON A.E.E.T.: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) fined Vodafone – PANAFON A.E.E.T. €30,000 on 2026-02-11 for: Insufficient fulfilment of data subjects rights. Telecommunications Personal Data Processing Agreement Feb 11, 2026
Spain · €150,000 AEPD (Spain) - EXP202306354 (PS/00312/2024) Facts — The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party… Personal Data Controllers Integrity and Confidentiality Principle Feb 11, 2026
aepd · €1,800 Landlord: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,800 on a Landlord. The landlord used video surveillance in rental apartments without having a sufficient legal basis. The original fine… Video Surveillance Controllers Processing Agreement Feb 6, 2026
ICO · €284,450 MediaLab.AI, Inc.: Insufficient legal basis for data processing The UK DPA has imposed a fine of GBP 247,590 (EUR 284,450) on MediaLab.AI, Inc.The controller of the image-sharing and hosting platform Imgur failed to implement age verification.… Minors Controllers Processing Agreement Feb 5, 2026
UODO · €2,682,000 DPD Polska sp. z o.o.: Insufficient data processing agreement Polish National Personal Data Protection Office (UODO) fined DPD Polska sp. z o.o. €2,682,000 on 2026-02-05 for: Insufficient data processing agreement. Processing Agreement Personal Data Data Processor Feb 5, 2026
ANSPDCP · €20,000 Tensa Art Design S.A: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 20,000 onTensa Art Design S.A.The DPA began investigating the controller's data processing activities, but the controller failed to… Supervisory Authorities Controllers Supervision Feb 5, 2026
ANSPDCP · €10,000 GENPACT ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational… Security Access Controls Processing Agreement Feb 4, 2026
AP · €25,000 Municipality of Zoetermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Zoetermeer. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Public Authority Feb 3, 2026
AP · €25,000 Municipality of Ede: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Ede. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Public Authority Health Data Feb 3, 2026
AP · €25,000 Municipality of Eindhoven: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Eindhoven. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Public Authority Feb 3, 2026
AP · €25,000 Municipality of Gooise Meren: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Gooise Meren. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Public Authority Feb 3, 2026
AP · €25,000 Municipality of Huizen: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Huizen. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Controllers Feb 3, 2026
AP · €25,000 Municipality of Delft: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Delft. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Public Authority Feb 3, 2026
aepd · €10,000 FREE TECHNOLOGIES EXCOM, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 10,000 on FREE TECHNOLOGIES EXCOM, S.L. The controller had reset user passwords and communicated the new passwords to the clients via… Encryption Integrity and Confidentiality Principle Security Feb 3, 2026
ANSPDCP · €1,000 Alliance for the Union of Romanians (AUR) Party: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on the Alliance for the Union of Romanians (AUR) Party. The controller failed to react adequately to a data subject's request to… Personal Data Controllers Processing Agreement Feb 3, 2026
AP · €25,000 Municipality of Veenendaal: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Controllers Feb 3, 2026
AP · €25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… Political Opinions Health Data Controllers Feb 3, 2026
AP · €25,000 Municipality of Tilburg: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Tilburg. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Controllers Public Authority Feb 3, 2026
AP · €25,000 Municipality of Hilversum: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Hilversum. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… Political Opinions Health Data Public Authority Feb 3, 2026
ANSPDCP · €10,000 Natural Person: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 10,000 on a natural person. The controller operated a website on which identity cards containing personal data, including special… Criminal Data Personal Data Health Data Jan 30, 2026
€565,000 Sportadmin i Skandinavien AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 565,500 on Sportadmin i Skandinavien AB. The controller suffered a sucessfull cyber attack, resulting in personal and special category… Security Healthcare Health Data Jan 26, 2026
CNIL · €5,000,000 FRANCE TRAVAIL: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 5,000,000 on FRANCE TRAVAIL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures,… Security Health Data Public Sector Jan 22, 2026
€4,850 Slovenia DPA: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined an unnamed party €4,850 on 2026-01-20 for: Insufficient technical and organisational measures to ensure… Security Supervision Supervisory Authorities Jan 20, 2026
ANSPDCP · €15,000 Continental Automotive Products SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van €15.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). Security Accountability Controllers NL Jan 19, 2026
aepd · €1,200 Dental Clinic: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,200 on a dental clinic. The controller used video surveillance in its clinic for security purposes, including a camera in the doctor's… Video Surveillance Controllers IP Address Jan 19, 2026
ANSPDCP · €15,000 Continental Automotive Products SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Continental Automotive Products SRL. The controller failed to implement adequate technical and organisational measures,… Security Controllers Law Enforcement Jan 19, 2026
Italy · €1,500 Garante per la protezione dei dati personali (Italy) - 10214411 Facts — The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of… Video Surveillance Fairness & Transparency Controllers Jan 16, 2026
Datatilsynet · €21,650 Timegrip AS: Insufficient fulfilment of data subjects rights The Norwegian DPA has imposed a fine of EUR 21,650 on Timegrip AS. The controller had been tracking the working hours of employees at a company that went bankrupt. A former… Personal Data Controllers IP Address Jan 16, 2026
ANSPDCP · €8,000 PREMIER RESTAURANTS ROMANIA SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 8.000 euro boete - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). Security Controllers Processing NL Jan 13, 2026
ANSPDCP · €8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PREMIER RESTAURANTS ROMANIA SRL. The controller failed to implement adequate technical and organisational measures, resulting… Security Controllers Processing Agreement Jan 13, 2026
aepd · €500 VOX ESPAÑA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500 on VOX ESPAÑA. The controller, a political party, posted a picture of of a receipt on its Facebook page. The picture of the recipt… Social Media Personal Data Controllers Jan 10, 2026
aepd · €8,000 KVIKU SPAIN, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 8,000 on KVIKU SPAIN, S.L.The controller requires customers to send a photo of themselves holding their ID card when verifying their… Retention Period Controllers IP Address Jan 10, 2026
UODO · €18,500 Komendanta Miejskiego Policji w Krakowie: Non-compliance with general data processing principles The Polish DPA has imposd a fine of EUR 18,500 on the Komendanta Miejskiego Policji w Krakowie. The controller published personal data, including health data, of a data subject… Personal Data Health Data Controllers Jan 9, 2026
CNIL · €27,000,000 FREE MOBILE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 27,000,000 on FREE MOBILE. The controller suffered a data breach due to insufficient technical and organisational measures. This was… Data Breaches Access Controls Telecommunications Jan 8, 2026
ANSPDCP · €2,000 Money Seeds S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. De Roemeense toezichthouder ANSPDCP heeft aan Money Seeds S.R.L., een financiële en consultancyonderneming, een boete van 2.000 euro opgelegd wegens het niet honoreren van een… Personal Data Data Controller Controllers NL Jan 8, 2026
HDPA · €10,000 Headquarter of a Fire Brigade: Insufficient legal basis for data processing The Greek DPA has imposed a fine of EUR 10,000 on a Fire Brigade Head Quarter. The controller had stored health data of an employee which had been in relation with her sick leave.… Health Data Healthcare Healthcare Jan 8, 2026
ANSPDCP · €2,000 Money Seeds S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Money Seeds S.R.L. The controller failed to fulfil a data subject's request to exercise their rights. Controllers Personal Data Insurance Jan 8, 2026
CNIL · €15,000,000 FREE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 15,000,000 on FREE. The controller suffered a data breach due to insufficient technical and organisational measures. This was caused by… Data Breaches Access Controls Telecommunications Jan 8, 2026
UODO · €232,379 Polish Postal Service: Lack of appointment of data protection officer The Polish DPA has imposed a fine of EUR 232,379 on the Polish Postal Service. The controller appointed a person as DPO who also held a managerial position with authority over… Public Sector Supervisory Authorities Public Authority Jan 2, 2026
HDPA · €10,000 SIGMA & KAPPA IMPORTING SOCIÉTÉ ANONYME: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 10,000 on SIGMA & KAPPA IMPORTING SOCIÉTÉ ANONYME. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A.… Telecommunications Processors Controllers Dec 31, 2025
HDPA · €6,000 I Mathisi: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) fined I Mathisi €6,000 on 2025-12-31 for: Insufficient fulfilment of data subjects rights. Personal Data Education Supervisory Authorities Dec 31, 2025
HDPA · €80,000 ONE WAY PRIVATE COMPANY: Non-compliance with general data processing principles The Greek DPA has imposed a fine of EUR 80,000 on ONE WAY PRIVATE COMPANY. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… Controllers Direct Marketing IP Address Dec 31, 2025
HDPA · €10,000 Thessaloniki–Thessaly Gas Supply Company S.A.: Insufficient data processing agreement The Greek DPA has imposed a fine of EUR 10,000 on Thessaloniki–Thessaly Gas Supply Company S.A. The controller, an energy provider, used external processors for direct marketing… Processing Agreement Controllers Processors Dec 31, 2025