Skip to content
Content type · 2,018 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

451–500 of 2,018 sort newestlargest fineoldest
€1,000 Order of Biochemists, Biologists and Chemists in the Romanian Healthcare System: Insufficient Compliance with Data Subjects' Rights. ⇄ 1.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Processing Supervisory Authorities Aug 5, 2025
€1,000 Order of Biochemists, Biologists and Chemists in the Romanian Health System: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on the Order of Biochemists, Biologists and Chemists in the Romanian Health System. The controller failed to adequatly respond to… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Aug 5, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2,000 on Linea Stampalibera Società Cooperativa r.I. The controller, who operates a news site, has disclosed too much personal… ITALY ·Garante ·Art. 5 Retention Period Controllers Processing Aug 4, 2025
€10,000 Comune di Venezia: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on the Comune di Venezia. The controller implemented a tourist tax, which includes exceptions for certain groups of visitors. When… ITALY ·Garante ·Art. 5, 6, 25 +1 Controllers Processing Education Aug 4, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Non-compliance with the general principles for data processing. ⇄ Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor gegevensbescherming (Garante). ITALY ·Garante ·Art. 5 Controllers Processing Health Data Aug 4, 2025
€7,700 Not a healthcare institution: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van €7.700 - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 32 Security Controllers Healthcare Aug 4, 2025
€80,000 Ospedaliero-Universitaria Careggi: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 80,000 on the Ospedaliero-Universitaria Careggi. The controller, a university hospital, used software that allowed medical personnel to… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Controllers Security Aug 4, 2025
€230 Police Officer: Insufficient legal basis for data processing The UK DPA has imposed a fine of £ 200 (EUR 230) on a police officer. The controller forwarded sensitive and restricted personal data that he had obtained in the course of his… UNITED KINGDOM ·ICO ·Insufficient legal basis for data processing Education Public Authority Personal Data Aug 4, 2025
€7,700 Non-Public Health Care Institution: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 7,700 on a non-public health care institution. The controller offered home visits by doctors as part of its services. For this purpose,… POLAND ·UODO ·Art. 5, 25, 32 Controllers Security Personal Data Aug 4, 2025
€10,000 Municipality of Venice: Non-compliance with the general principles of data processing. ⇄ Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 25 +1 Controllers Processing Public Authority Aug 4, 2025
€80,000 Careggi University Hospital: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9, 25 +1 Security Health Data Healthcare Aug 4, 2025
€11,614 Legal Entity: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 11,614 on a legal entity. The controller did not delete the email address of a former employee, but rather continued to receive and… SLOVENIA ·IP-RS ·Art. 5, 6 Controllers Processing Supervisory Authorities Jul 29, 2025
€4,400 Entrepreneur: Insufficient cooperation with the supervisory authority. ⇄ 4.400 euro boete - Pools Nationaal Bureau voor de Bescherming van Persoonsgegevens (UODO). POLAND ·UODO ·Art. 58 Personal Data Controllers Supervisory Authorities Jul 28, 2025
€4,400 Entrepreneur: Insufficient cooperation with supervisory authority The Polish DPA has imposed a fine of EUR 4,400 on an Entrepreneur. The controller failed to adequatly react to a request from the DPA. POLAND ·UODO ·Art. 58 Supervisory Authorities Supervision Controllers Jul 28, 2025
€5,020 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 5,020 on a legal entity. The controller had developed an application that allowed the exchange of personal data, but failed to… SLOVENIA ·IP-RS ·Art. 32 Security Controllers Personal Data Jul 25, 2025
€5,810 Legal Entity: Insufficient data processing agreement The Slovenian DPA has imposed a fine of EUR 5,810 on a legal entity. The controller employed a person authorised to perform clerical work. However, this person used a data… SLOVENIA ·IP-RS ·Art. 28 Processors Controllers Processing Jul 25, 2025
€26,400 Debt Collector: Insufficient fulfilment of data subjects rights The Hungarian DPA has imposed a fine of EUR 26,400 on a debt collector. The controller processed the personal data of a natural person, specifically data relating to a consumer… HUNGARY ·NAIH ·Art. 6, 17 Personal Data Controllers Insurance Jul 24, 2025
€5,000 Agricola International SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Agricola International SA. The controller failed to implement sufficient technical and organisational measures, resulting in a… ROMANIA ·ANSPDCP ·Art. 32 Controllers Security Personal Data Jul 23, 2025
€10,000 SATI S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on SATI S.p.A. Information about the reasons for employees' absences was displayed on boards and in emails, which were accessible… ITALY ·Garante ·Art. 5, 9 Controllers Processing Employees Jul 23, 2025
€10,000 Order of Nursing Professions of Viterbo: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on the Order of Nursing Professions of Viterbo. The controller suffered a data leak due to insufficient technical and… ITALY ·Garante ·Art. 5, 32 Security Controllers Education Jul 23, 2025
€10,000 SATI S.p.A.: Non-compliance with the general principles for data processing. ⇄ Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9 Controllers Processing Accountability Jul 23, 2025
€5,000 Agricola International SA: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Jul 23, 2025
€10,000 Order of Nurses of Viterbo: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 32 Security Controllers Accountability Jul 23, 2025
€43,000 24/7 Communication Sp. z o.o.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 43.000 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 38 Security Controllers Processors Jul 21, 2025
€9,000 Hestia Publishers & Booksellers, I. D. Kollaros & Co. S.A.: Insufficient technical and organisational measures to ensure information security. ⇄ Boete van €9.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 25, 32 +2 Security Pseudonymization Controllers Jul 21, 2025
€43,000 24/7 Communication Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 43,000 on 24/7 Communication Sp. z o.o. The fined entity acted as the data processor for McDonald’s Polska Sp. z o.o. (see ETid: 2757).… POLAND ·UODO ·Art. 5, 25, 38 Controllers Processors Retention Period Jul 21, 2025
€4M McDonald’s Polska Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed a fine of EUR 3,955,000 on McDonald’s Polska Sp. z o.o. The controller used a third party processor (see ETid: 2758) for the purpose of managing work… POLAND ·UODO ·Art. 5, 25, 28 +1 Controllers Processors Security Jul 21, 2025
€9,000 Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 9,000 on Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A. The controller disclosed the identity of an anonymous author by… GREECE ·HDPA ·Art. 5, 25, 32 +2 Pseudonymization Security Personal Data Jul 21, 2025
€4M McDonald’s Polska Sp. z o.o.: Non-compliance with general principles for data processing. ⇄ Een boete van 3.955.000 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 28 +1 Controllers Security Processing Jul 21, 2025
€1,100 ADMINISTRACIONES BENIPON, S.L.: Insufficient fulfilment of data breach notification obligations The Spanish DPA has imposed a fine of EUR 1,100 on ADMINISTRACIONES BENIPON, S.L. The processor failed to notify the controller of a data breach and also used a sub-processor… SPAIN ·AEPD ·Art. 28, 33 Notification Obligation Data Breaches Processors Jul 18, 2025
€1,000 CLUB BALONCESTO TELDE: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,000 on the club BALONCESTO TELDE. The controller published an image of a minor without the consent of the minors representative. SPAIN ·AEPD ·Art. 6 Controllers Consent Minors Jul 18, 2025
€1,100 ADMINISTRACIONES BENIPON, S.L.: Failure to comply with the obligations regarding the notification of personal data breaches. ⇄ 1.100 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 28, 33 Controllers Processing Processors Jul 18, 2025
€1,000 CLUB BALONCESTO TELDE: Insufficient legal basis for the processing of data. ⇄ 1.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6 Consent Controllers Processing Jul 18, 2025
€1,200 TRUEBA SPORT S.L.: Insufficient technical and organizational measures to ensure information security. ⇄ 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 13 Security Controllers Accountability Jul 17, 2025
€1,200 TRUEBA SPORT S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,200 on TRUEBA SPORT S.L. The controller disclosed personal data due to an human error. The controller also failed to include a privacy… SPAIN ·AEPD ·Art. 5, 13 Personal Data Controllers Supervisory Authorities Jul 17, 2025
€200,000 ENDESA ENERGIA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 200,000 on ENDESA ENERGIA, S.A.U. The controller mistakenly linked two unrelated parties, resulting in a third party having its energy… SPAIN ·AEPD ·Art. 5 Controllers Processing IP Address Jul 17, 2025
€200,000 ENDESA ENERGIA, S.A.U.: Violation of the general principles of data processing. ⇄ Een boete van 200.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Processing Accountability Jul 17, 2025
€4,000 Georgescu Călin: Inadequate compliance with data subjects' rights (regarding their personal data). ⇄ Een boete van 4.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Processing Supervisory Authorities Jul 16, 2025
€180,000 TRIVE CREDIT SPAIN, S.L.: Insufficient cooperation with the supervisory authority. ⇄ Een boete van 180.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). AEPD ·Art. 58 ·Insufficient cooperation with supervisory authority Controllers Supervisory Authorities Supervision Jul 16, 2025
€4,000 Georgescu Călin: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine on the politican Georgescu Călin. The controller failed to inform data subjects on his website regarding the processing of their data and how… ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervisory Authorities Jul 16, 2025
€180,000 TRIVE CREDIT SPAIN, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 180,000 on TRIVE CREDITSPAIN, S.L. The controller failed to adequatly comply with a order from the DPA. The original fine of EUR 225,000… AEPD ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Jul 16, 2025
€5,400 SUNERIS, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5,400 on SUNERIS, S.A. The controller processed scans of ID cards and passports of their guests, infringing the principle of data… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Jul 16, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 32.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 32 Security Controllers Personal Data Jul 11, 2025
€20,000 NN Greek Single-Member Insurance Company Anonymous: Insufficient compliance with data subject rights. ⇄ Boete van 20.000 euro - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 15 Personal Data Controllers Supervisory Authorities Jul 11, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on VALORA PREVENCIÓN, S.L.U. The controller, a company offering occupational health and safety services, failed to implement… SPAIN ·AEPD ·Art. 5, 32 Controllers Security Personal Data Jul 11, 2025
€20,000 NN Greek Single-Member Anonymous Life Insurance Company: Insufficient fulfilment of data subjects rights The Greek DPA has imposed a fine of EUR 20,000 on NN Greek Single-Member Anonymous Life Insurance Company. The controller failed to provide the data subject with the personal data… GREECE ·HDPA ·Art. 15 Right of Access Personal Data Controllers Jul 11, 2025
€2,000 PAVLOS BIKOS SOLE PROPRIETORSHIP DENTAL PRIVATE CAPITAL COMPANY: Insufficient cooperation with supervisory authority The Greek DPA has imposed a fine of EUR 2,000 on PAVLOS BIKOS SOLE PROPRIETORSHIP DENTAL PRIVATE CAPITAL COMPANY. The fined party was a data processor in case ETid: 2880. During… GREECE ·HDPA ·Art. 31 Supervisory Authorities Supervision Processors Jul 11, 2025
€4,000 Istituto Comprensivo 2 C.D. “G. Modugno” S.M. “G. Galilei” di Monopoli: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 4,000 on Istituto Comprensivo 2 C.D. “G. Modugno” S.M. “G. Galilei” di Monopoli. The controller published a list with the name of pupils… ITALY ·Garante ·Art. 5, 6, 9 Controllers Processing Education Jul 10, 2025
€10,000 Nursery School “La Combricola Dei Birichini Di Betty”: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on the Nursery School “La Combricola Dei Birichini Di Betty”. The controller only accepted new children if their parents agreed… ITALY ·Garante ·Art. 5, 6, 7 +5 Controllers Public Authority Supervisory Authorities Jul 10, 2025