Skip to content
Content type · 2,511 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Italy · €20,000 Garante per la protezione dei dati personali (Italy) - 471/2026 Facts — The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Personal Data Fairness & Transparency Criminal Data Jul 18, 2026
Spain AEPD (Spain) - EXP202102529 Facts — A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as… Consent Health Data Healthcare Jul 16, 2026
Italy · €16,000 Garante per la protezione dei dati personali (Italy) - 10192784 Facts — The data subject, a professional registered with the OPI of Pisa, discovered while consulting the Public Register of Professionals online that the database included the… Personal Data Retention Period Fairness & Transparency Jul 16, 2026
Italy · €50,000 Garante per la protezione dei dati personali (Italy) - 10128005 Facts — The Calabrian Regional Agency for Agricultural Development (the controller) implemented a remote work policy that required employees to use a time-tracking application… DPIA Monitoring Personal Data Jul 16, 2026
Spain AEPD (Spain) - E/03783/2020 Facts — The Directorate for National Security of the Ministry of Interior issued guidelines for the police forces to monitor news and social networks to spot fake news and… Social Media Monitoring Personal Data Jul 15, 2026
Spain · €140 AEPD (Spain) - EXP202310345 Facts — On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Telecommunications Personal Data Accountability Jul 13, 2026
Romania · €57,839 ANSPDCP (Romania) - Fine against Ascendex Technology SRL Facts — The Romanian DPA (ANSPDCP) launched an investigation into the cryptocurrency exchange platform Ascendex Technology SRL (the controller). The DPA was notified by the French… Supervisory Authorities Controllers Personal Data Jul 9, 2026
Slovenia · €1,198 IP (Slovenia) - 0609-36/2026/7 Facts — A company (the controller) operates an online store. An employee of the controller used a pirated and unlicensed software when creating the website. This software… Integrity and Confidentiality Principle Data Breaches Security Jul 8, 2026
Italy · €158,000 Garante per la protezione dei dati personali (Italy) - 487/2026 Facts — Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows… DPIA Processing Artificial Intelligence Jul 3, 2026
Sweden IMY (Sweden) - IMY-2024-2904 Facts — The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the… Personal Data Controllers Information Provision Modalities and Communication Methods Jul 3, 2026
Island Persónuvernd (Island) - 2025010358 Facts — The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… Monitoring Cloud Computing Integrity and Confidentiality Principle Jul 1, 2026
Lithuania · €450,000 VDAI (Lithuania) - 3R-1143 Facts — Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and… Security Data Breaches Access Controls Jun 19, 2026
Poland · €2,760 UODO (Poland) - DKN.5131.34.2023 Facts — An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account… Data Breaches Right of Access Notification Obligation Jun 13, 2026
ANSPDCP · €5,000 Națională Poșta Română: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Națională Poșta Română €5,000 on 2026-06-12 for: Insufficient technical and organisational… Security Personal Data Supervisory Authorities Jun 12, 2026
Datatilsynet · €1,820,000 Elkjøp AS: Insufficient legal basis for data processing Norwegian Supervisory Authority (Datatilsynet) fined Elkjøp AS €1,820,000 on 2026-06-01 for: Insufficient legal basis for data processing. Processing Supervision Supervisory Authorities Jun 1, 2026
ANSPDCP · €12,000 Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Unicredit Bank SA €12,000 on 2026-05-29 for: Insufficient technical and organisational… Security Supervisory Authorities Personal Data May 29, 2026
NAIH · €70,300 Blikk Kft.: Insufficient legal basis for data processing Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined Blikk Kft. €70,300 on 2026-05-29 for: Insufficient legal basis for data processing. Processing Telecommunications May 29, 2026
Italy · €700 Garante per la protezione dei dati personali (Italy) - 385/2026 Facts — A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was… Personal Data Healthcare Retention Period May 28, 2026
Italy · €6,000 Garante per la protezione dei dati personali (Italy) - 382/2026 Facts — A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller). The data subject was employed by the Ligurian Social and… DPIA Privacy by Design Privacy by Default May 28, 2026
Italy · €55,000 Garante per la protezione dei dati personali (Italy) - 419/2026 Facts — The data controller for the case is a government body called the Agency for Digital Italy (AgID). AgID is tasked with driving the adoption of digital technologies in both… Personal Data Controllers Processing May 28, 2026
CNIL · €5,000,000 IQVIA OPERATIONS FRANCE: Non-compliance with general data processing principles French Data Protection Authority (CNIL) fined IQVIA OPERATIONS FRANCE €5,000,000 on 2026-05-26 for: Non-compliance with general data processing principles. IP Address Processing Healthcare May 26, 2026
NAIH · €140,500 Mediaworks Hungary Zrt.: Insufficient legal basis for data processing Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined Mediaworks Hungary Zrt. €140,500 on 2026-05-26 for: Insufficient legal basis for data… Processing Telecommunications May 26, 2026
Poland · €26,711 UODO (Poland) - DKE.561.4.2026 Facts — The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance… Monitoring Video Surveillance Accountability May 22, 2026
UK · €300 ICO (UK) - KRA Consultancy Ltd Facts — The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related… Direct Marketing Telecommunications Marketing May 20, 2026
Poland · €33,700 UODO (Poland) - DKN.5131.27.2023 Facts — A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and… Personal Data Controllers Security May 19, 2026
APD · €86,000 Société Wallonne des Eaux: Insufficient legal basis for data processing Belgian Data Protection Authority (APD) fined Société Wallonne des Eaux €86,000 on 2026-05-12 for: Insufficient legal basis for data processing. Education Public Authority Processing May 12, 2026
APD · €177,000 Technology Company: Insufficient legal basis for data processing Belgian Data Protection Authority (APD) fined Technology Company €177,000 on 2026-05-12 for: Insufficient legal basis for data processing. Processing Employees Supervisory Authorities May 12, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Article 19 GDPR - Notification of Rectification, Erasure or Restriction Data Breaches Compliance Function Establishment and Role May 8, 2026
Slovenia · €2,802 IP (Slovenia) - 0609-42/2026/7 Facts — A processor was contracted by a company (the controller) to maintain an online store, fix errors, and provide support. This included ensuring that the controller had… Controllers Security Processors May 1, 2026
ANSPDCP · €2,500 BLUE PROJECTS INDUSTRIES S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined BLUE PROJECTS INDUSTRIES S.R.L. €2,500 on 2026-04-30 for: Insufficient technical and… Security Supervisory Authorities Personal Data Apr 30, 2026
ANSPDCP · €35,000 Crowd Entertainment Ltd: Insufficient legal basis for data processing Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Crowd Entertainment Ltd €35,000 on 2026-04-28 for: Insufficient legal basis for data… Personal Data Processing Telecommunications Apr 28, 2026
aepd · €4,000 SIPHONE 2020, S.L.: Insufficient legal basis for data processing Spanish Data Protection Authority (aepd) fined SIPHONE 2020, S.L. €4,000 on 2026-04-28 for: Insufficient legal basis for data processing. IP Address Employees Processing Apr 28, 2026
aepd · €240 Posada del León de Oro: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) fined Posada del León de Oro €240 on 2026-04-28 for: Non-compliance with general data processing principles. Employees Processing IP Address Apr 28, 2026
APD · €8,500 Accountancy Firm: Insufficient legal basis for data processing Belgian Data Protection Authority (APD) fined Accountancy Firm €8,500 on 2026-04-23 for: Insufficient legal basis for data processing. Employees Processing Supervisory Authorities Apr 23, 2026
Garante · €6,624,000 Poste Italiane S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Poste Italiane S.p.a. €6,624,000 on 2026-04-17 for: Non-compliance with general data processing principles. IP Address Processing Insurance Apr 17, 2026
Garante · €5,877,000 Postepay S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Postepay S.p.a. €5,877,000 on 2026-04-17 for: Non-compliance with general data processing principles. IP Address Insurance Processing Apr 17, 2026
Garante · €2,000 Io e te s.r.l.s.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Io e te s.r.l.s. €2,000 on 2026-04-17 for: Insufficient legal basis for data processing. Processing Supervisory Authorities Apr 17, 2026
Garante · €2,000 Business Owner: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Business Owner €2,000 on 2026-04-17 for: Insufficient legal basis for data processing. Processing Supervisory Authorities Apr 17, 2026
Garante · €6,000 Comune di Campo Calabro: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Comune di Campo Calabro €6,000 on 2026-04-17 for: Insufficient legal basis for data processing. Employees Processing Supervisory Authorities Apr 17, 2026
Garante · €5,000 Framos Italia s.r.l.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Framos Italia s.r.l. €5,000 on 2026-04-17 for: Non-compliance with general data processing principles. Employees IP Address Processing Apr 17, 2026
Estonia · €1,000 AKI (Estonia) - No. 2.1-1/24/397-890-38 Facts — OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had… Controllers Processors Data Controller Apr 16, 2026
€6,600 Utility Company: Insufficient legal basis for data processing Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Utility Company €6,600 on 2026-04-15 for: Insufficient legal basis for data processing. IP Address Supervisory Authorities Processing Apr 15, 2026
Poland · €2,415 UODO (Poland) - DKN.5131.7.2022 Facts — An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a… Notification Obligation Processors Data Breaches Apr 13, 2026
ANSPDCP · €2,500 BLUE PROJECTS S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined BLUE PROJECTS S.R.L. €2,500 on 2026-04-03 for: Insufficient technical and organisational… Security Supervisory Authorities Personal Data Apr 3, 2026
AP · €100,000,000 Ridetech International B.V.: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) fined Ridetech International B.V. €100,000,000 on 2026-04-01 for: Insufficient legal basis for data processing. Processing Personal Data Supervisory Authorities Apr 1, 2026
Garante · €96,000 Eni S.p.A.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Eni S.p.A. €96,000 on 2026-03-26 for: Insufficient legal basis for data processing. Processing Supervisory Authorities Mar 26, 2026
Garante · €2,500 Comune di Cassino: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Comune di Cassino €2,500 on 2026-03-26 for: Insufficient legal basis for data processing. Education Public Authority Processing Mar 26, 2026
Garante · €2,000 Business Owner: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Business Owner €2,000 on 2026-03-26 for: Insufficient legal basis for data processing. Processing Supervisory Authorities Mar 26, 2026
Garante · €1,000 Euro Bangla Minimarket in Jesi: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Euro Bangla Minimarket in Jesi €1,000 on 2026-03-26 for: Insufficient legal basis for data processing. Employees Processing Supervisory Authorities Mar 26, 2026
Garante · €3,000 Piacenza Bar Association: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Piacenza Bar Association €3,000 on 2026-03-26 for: Insufficient legal basis for data processing. Education Public Authority Processing Mar 26, 2026