Skip to content
Content type · 2,395 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

451–500 of 2,395 sort newestlargest fineoldest
€7,700 Non-Public Health Care Institution: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 7,700 on a non-public health care institution. The controller offered home visits by doctors as part of its services. For this purpose,… POLAND ·UODO ·Art. 5, 25, 32 Controllers Security Personal Data Aug 4, 2025
€4,400 Entrepreneur: Insufficient cooperation with the supervisory authority. ⇄ 4.400 euro boete - Pools Nationaal Bureau voor de Bescherming van Persoonsgegevens (UODO). POLAND ·UODO ·Art. 58 Personal Data Controllers Supervisory Authorities Jul 28, 2025
€4,400 Entrepreneur: Insufficient cooperation with supervisory authority The Polish DPA has imposed a fine of EUR 4,400 on an Entrepreneur. The controller failed to adequatly react to a request from the DPA. POLAND ·UODO ·Art. 58 Supervisory Authorities Supervision Controllers Jul 28, 2025
€5,020 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 5,020 on a legal entity. The controller had developed an application that allowed the exchange of personal data, but failed to… SLOVENIA ·IP-RS ·Art. 32 Security Controllers Personal Data Jul 25, 2025
€5,810 Legal Entity: Insufficient data processing agreement The Slovenian DPA has imposed a fine of EUR 5,810 on a legal entity. The controller employed a person authorised to perform clerical work. However, this person used a data… SLOVENIA ·IP-RS ·Art. 28 Processors Controllers Processing Jul 25, 2025
€26,400 Debt Collector: Insufficient fulfilment of data subjects rights The Hungarian DPA has imposed a fine of EUR 26,400 on a debt collector. The controller processed the personal data of a natural person, specifically data relating to a consumer… HUNGARY ·NAIH ·Art. 6, 17 Personal Data Controllers Insurance Jul 24, 2025
€5,000 Agricola International SA: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Jul 23, 2025
€5,000 Agricola International SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Agricola International SA. The controller failed to implement sufficient technical and organisational measures, resulting in a… ROMANIA ·ANSPDCP ·Art. 32 Controllers Security Personal Data Jul 23, 2025
€43,000 24/7 Communication Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 43,000 on 24/7 Communication Sp. z o.o. The fined entity acted as the data processor for McDonald’s Polska Sp. z o.o. (see ETid: 2757).… POLAND ·UODO ·Art. 5, 25, 38 Controllers Processors Retention Period Jul 21, 2025
€43,000 24/7 Communication Sp. z o.o.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 43.000 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 38 Security Controllers Processors Jul 21, 2025
€9,000 Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 9,000 on Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A. The controller disclosed the identity of an anonymous author by… GREECE ·HDPA ·Art. 5, 25, 32 +2 Pseudonymization Security Controllers Jul 21, 2025
€4M McDonald’s Polska Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed a fine of EUR 3,955,000 on McDonald’s Polska Sp. z o.o. The controller used a third party processor (see ETid: 2758) for the purpose of managing work… POLAND ·UODO ·Art. 5, 25, 28 +1 Controllers Processors Security Jul 21, 2025
€1,200 TRUEBA SPORT S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,200 on TRUEBA SPORT S.L. The controller disclosed personal data due to an human error. The controller also failed to include a privacy… SPAIN ·AEPD ·Art. 5, 13 Personal Data Controllers Supervisory Authorities Jul 17, 2025
€4,000 Georgescu Călin: Inadequate compliance with data subjects' rights (regarding their personal data). ⇄ Een boete van 4.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Processing Supervisory Authorities Jul 16, 2025
€4,000 Georgescu Călin: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine on the politican Georgescu Călin. The controller failed to inform data subjects on his website regarding the processing of their data and how… ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervisory Authorities Jul 16, 2025
€20,000 NN Greek Single-Member Anonymous Life Insurance Company: Insufficient fulfilment of data subjects rights The Greek DPA has imposed a fine of EUR 20,000 on NN Greek Single-Member Anonymous Life Insurance Company. The controller failed to provide the data subject with the personal data… GREECE ·HDPA ·Art. 15 Right of Access Personal Data Controllers Jul 11, 2025
€20,000 NN Greek Single-Member Insurance Company Anonymous: Insufficient compliance with data subject rights. ⇄ Boete van 20.000 euro - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 15 Personal Data Controllers Supervisory Authorities Jul 11, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on VALORA PREVENCIÓN, S.L.U. The controller, a company offering occupational health and safety services, failed to implement… SPAIN ·AEPD ·Art. 5, 32 Controllers Security Personal Data Jul 11, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 32.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 32 Security Controllers Personal Data Jul 11, 2025
€50,000 Magna PT S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine on Magna PT S.p.A. Employees of the controllers were subjected to 'return to work interviews' after returning from an absence due to illness or… ITALY ·Garante ·Art. 5, 6, 9 +2 Retention Period Controllers Storage Limitation Jul 10, 2025
€50,000 Magna PT S.p.A.: Insufficient legal basis for the processing of data. ⇄ Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Retention Period Jul 10, 2025
€100,000 Banco Bilbao Vizcaya Argentaria SA: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Banco Bilbao Vizcaya Argentaria SA €100,000 on 2025-07-10 for: Insufficient fulfilment of data subjects rights. Italy ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Insurance Jul 10, 2025
€80,000 Poste Vita S.p.a.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 33 Security Controllers Personal Data Jul 10, 2025
€80,000 Poste Vita S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine on Poste Vita S.p.a. The controller failed to implement adequate technical and organisational measures to ensure data security. This resulted in… ITALY ·Garante ·Art. 5, 33 Security Personal Data Controllers Jul 10, 2025
€3,000 Zougla TZI-AP, an anonymous mass media conglomerate: Insufficient legal basis for the processing of personal data. ⇄ Boete van €3.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 31 Personal Data Processing Controllers Jul 4, 2025
€6,000 CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Violation of the General Principles for Data Processing ⇄ Boete van 6.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Processing Personal Data Jul 4, 2025
€3,000 Zougla TZI-AP Anonymous Mass Media Company: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 3,000 on Zougla TZI-AP Anonymous Media Company. The controller, who operates a news website, published an article revealing the personal… GREECE ·HDPA ·Art. 5, 31 Personal Data Controllers Supervisory Authorities Jul 4, 2025
€6,000 CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 6,000 on CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U. The controller processed personal data in order to conclude a contract. But the… SPAIN ·AEPD ·Art. 5 Controllers Personal Data Processing Jul 4, 2025
€15,600 L. Zamenhof University Children's Clinical Hospital in Białystok: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 15,600 on the L. Zamenhof University Children's Clinical Hospital in Białystok. The controller did not implement sufficient technical and… POLAND ·UODO ·Art. 5, 32 Security Controllers Personal Data Jun 30, 2025
€3,000 Selgros Cash & Carry SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Selgros Cash & Carry SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Jun 26, 2025
€3,000 SC Piramida Trade Invest SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 3,000 on SC Piramida Trade Invest SRL. The controller processed personal data without a sufficient legal basis and without sufficient… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +4 Personal Data Controllers Security Jun 26, 2025
€96,000 SIDECU, S.A.: Non-compliance with the general principles for data processing. ⇄ Een boete van 96.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 9, 13, 35 Controllers Processing Supervisory Authorities Jun 26, 2025
€3,000 SC Tremend Software Consulting SRL: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Processing Jun 26, 2025
€3,000 SC Tremend Software Consulting SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on SC Tremend Software Consulting SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Jun 26, 2025
€3,000 SC Piramida Trade Invest SRL: Non-compliance with the general principles of data processing. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +4 Personal Data Processing Supervisory Authorities Jun 26, 2025
€25,000 Party "Alliance for the Union of Romanians": Non-compliance with the general principles of data processing. ⇄ Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 25 +1 Processing Personal Data Security Jun 26, 2025
€3,000 Selgros Cash & Carry SRL: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Processing Jun 26, 2025
€25,000 Alliance for the Union of Romanians Party: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 25,000 on the Alliance for the Union of Romanians Party. The controller did not implement adeqaute technical and organisational measures… ROMANIA ·ANSPDCP ·Art. 5, 6, 25 +1 Security Controllers Personal Data Jun 26, 2025
€96,000 SIDECU, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 96,000 on SIDECU, S.A. The controller introduced facial recognistion system as the only access method to their facilities, without offering… SPAIN ·AEPD ·Art. 9, 13, 35 DPIA Controllers Personal Data Jun 26, 2025
€40,000 KARAMBELAS KONSTANTINOS & CO. E.E.: Insufficient Technical and Organizational Measures for Data Security ⇄ Boete van 40.000 euro - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 29, 32 Security Personal Data Telecommunications Jun 25, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 550.000 euro - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 28 Security Supervisory Authorities Controllers Jun 25, 2025
€7,000 General Hospital of the University of Larissa: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 7,000 on the General Hospital of the University of Larissa. The controller failed to adequately fulfil the rights of data subjects. It… GREECE ·HDPA ·Art. 5, 14, 15 Personal Data Controllers Supervisory Authorities Jun 24, 2025
€10,000 Shield of David - K.I.D.A.F.: Non-compliance with general principles of data processing. ⇄ Boete van €10.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 12, 13 +3 Personal Data Controllers Processing Jun 24, 2025
€10,000 Shield of David - K.I.D.A.F.: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Shield of David - K.I.D.A.F. The controller, a day care centre for people with autism, has legally installed video… GREECE ·HDPA ·Art. 5, 12, 13 +3 Controllers Personal Data Supervisory Authorities Jun 24, 2025
€7,000 General Hospital of the University of Larissa: Inadequate compliance with data subjects' rights. ⇄ Een boete van €7.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 14, 15 Supervisory Authorities Controllers Personal Data Jun 24, 2025
€50,000 Piraeus Bank S.A.: Insufficient legal basis for data processing. ⇄ Een boete van 50.000 euro - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 6 Personal Data Controllers Processing Jun 23, 2025
€4,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 4,000 on Vodafone Romania S.A. The controller failed to implement sufficient technical and organisational measures to ensure data… ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Jun 23, 2025
€125,000 City of Dublin Education and Training Board: Insufficient technical and organizational measures to ensure information security. ⇄ 125.000 euro boete - Ierse Autoriteit voor Gegevensbescherming. IRELAND ·DPC ·Art. 5, 32, 33 +1 Security Controllers Personal Data Jun 23, 2025
€4,000 Vodafone Romania S.A.: Insufficient technical and organizational measures to ensure information security. ⇄ 4.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Security Processing Personal Data Jun 23, 2025