Skip to content
Content type · 2,636 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

451–500 of 2,636 sort newestlargest fineoldest
€200M GOOGLE LLC: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 200,000,000 on GOOGLE LLC. While creating an account for the controller's services, the controller designed the cookie consent process in… FRANCE ·CNIL ·Art. 82 Controllers Personal Data Cookies Sep 1, 2025
€2,400 KVIKU SPAIN, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,400 on KVIKU SPAIN, S.L. The controller processed personal data of a data subject without sufficient consent. The original fine of EUR… AEPD ·Art. 6 ·Insufficient legal basis for data processing Personal Data Consent Controllers Aug 29, 2025
€1,200 GOHIPOTECA, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR on GOHIPOTECA, S.L. The controller processed data of a data subject without a sufficient legal basis. The contract used as the basis for… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Insurance Aug 29, 2025
€1,200 GOHIPOTECA, S.L.: Insufficient legal basis for the processing of personal data. ⇄ 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6 Personal Data Processing Controllers Aug 29, 2025
€2,400 KVIKU SPAIN, S.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 2.400 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). AEPD ·Art. 6 ·Insufficient legal basis for data processing Personal Data Processing Consent Aug 29, 2025
€4.3M ING Bank Śląski: Insufficient legal basis for data processing. ⇄ 4.323.250 euro boete - Pools Nationaal Bureau voor de Bescherming van Persoonsgegevens (UODO). POLAND ·UODO ·Art. 5, 6 Personal Data Processing Accountability Aug 26, 2025
€4.3M ING Bank Śląski: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 4,323,250 on ING Bank Śląski. The controller scanned the identity documents of every customer and potential customer without a sufficient… POLAND ·UODO ·Art. 5, 6 Controllers Personal Data Processing Aug 26, 2025
€300 Driving School: Insufficient Compliance with Information Obligations. ⇄ Een boete van 300 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 13 Controllers Personal Data Processing Aug 26, 2025
€5,400 YUNEXPRESS SPAIN, S.L.: Insufficient data processing agreement The Spanish DPA has imposed a fine of EUR 5,400 on YUNEXPRESS SPAIN, S.L. The controller used a data processor and failed to sign a sufficient data processing agreement. The… AEPD ·Art. 5, 28 ·Insufficient data processing agreement Processors Controllers Processing Aug 25, 2025
€5,400 YUNEXPRESS SPAIN, S.L.: Insufficient agreement regarding data processing. ⇄ Boete van €5.400 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). AEPD ·Art. 5, 28 ·Insufficient data processing agreement Controllers Processors Processing Aug 25, 2025
€3,000 SC Elite Conta SRL: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Aug 18, 2025
€3,000 SC Elite Conta SRL: Insufficient technical and organisational measures to ensure information security The Romainian DPA has imposed a fine of EUR 3,000 on SC Elite Conta SRL. The controller failed to implement adequate technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Aug 18, 2025
€42,000 WORLD 2 MEET, S.L.: Non-compliance with the general principles of data processing. ⇄ Een boete van 42.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Processing Accountability IP Address Aug 14, 2025
€42,000 WORLD 2 MEET, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 42,000 on WORLD 2 MEET, S.L. The controller requires its guests to provide a copy of their identity card or passport for registration… SPAIN ·AEPD ·Art. 5 Controllers Processing IP Address Aug 14, 2025
€3,000 'FLEXICREDIT' Mutual Aid House Association: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on 'FLEXICREDIT' Mutual Aid House Association. The controller failed to implement adequate technical and organisational measures… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Aug 12, 2025
€1,600 REAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,600 on the REAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESA. The controller pubilshed personal data on its website without a sufficient legal… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Aug 12, 2025
€3,000 'FLEXICREDIT' Mutual Aid Cooperative: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Aug 12, 2025
€1,600 REAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESA: Insufficient legal basis for the processing of personal data. ⇄ 1.600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Personal Data Processing Controllers Aug 12, 2025
€4,800 GACM SEGUROS GENERALES, an insurance and reinsurance company S.A.U.: Non-compliance with the general principles of data processing. ⇄ Een boete van 4.800 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Processing Accountability Aug 12, 2025
€4,800 GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 4,800 on GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U. The controller failed to process customer data accurately,… SPAIN ·AEPD ·Art. 5 Controllers Personal Data Processing Aug 12, 2025
€1,000 Order of Biochemists, Biologists and Chemists in the Romanian Health System: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on the Order of Biochemists, Biologists and Chemists in the Romanian Health System. The controller failed to adequatly respond to… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Aug 5, 2025
€1,000 Order of Biochemists, Biologists and Chemists in the Romanian Healthcare System: Insufficient Compliance with Data Subjects' Rights. ⇄ 1.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Processing Supervisory Authorities Aug 5, 2025
€230 Police Officer: Insufficient legal basis for data processing The UK DPA has imposed a fine of £ 200 (EUR 230) on a police officer. The controller forwarded sensitive and restricted personal data that he had obtained in the course of his… UNITED KINGDOM ·ICO ·Insufficient legal basis for data processing Education Public Authority Personal Data Aug 4, 2025
€10,000 Municipality of Venice: Non-compliance with the general principles of data processing. ⇄ Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 25 +1 Controllers Processing Public Authority Aug 4, 2025
€230 Police officer: Insufficient legal basis for data processing. ⇄ Een boete van 230 euro - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Insufficient legal basis for data processing Education Public Authority Processing Aug 4, 2025
€10,000 Comune di Venezia: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on the Comune di Venezia. The controller implemented a tourist tax, which includes exceptions for certain groups of visitors. When… ITALY ·Garante ·Art. 5, 6, 25 +1 Controllers Processing Education Aug 4, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2,000 on Linea Stampalibera Società Cooperativa r.I. The controller, who operates a news site, has disclosed too much personal… ITALY ·Garante ·Art. 5 Retention Period Controllers Processing Aug 4, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Non-compliance with the general principles for data processing. ⇄ Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor gegevensbescherming (Garante). ITALY ·Garante ·Art. 5 Controllers Processing Health Data Aug 4, 2025
€11,614 Legal Entity: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 11,614 on a legal entity. The controller did not delete the email address of a former employee, but rather continued to receive and… SLOVENIA ·IP-RS ·Art. 5, 6 Controllers Processing Supervisory Authorities Jul 29, 2025
€5,810 Legal Entity: Insufficient data processing agreement The Slovenian DPA has imposed a fine of EUR 5,810 on a legal entity. The controller employed a person authorised to perform clerical work. However, this person used a data… SLOVENIA ·IP-RS ·Art. 28 Processors Controllers Processing Jul 25, 2025
€10,000 SATI S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on SATI S.p.A. Information about the reasons for employees' absences was displayed on boards and in emails, which were accessible… ITALY ·Garante ·Art. 5, 9 Controllers Processing Employees Jul 23, 2025
€5,000 Agricola International SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Agricola International SA. The controller failed to implement sufficient technical and organisational measures, resulting in a… ROMANIA ·ANSPDCP ·Art. 32 Controllers Security Personal Data Jul 23, 2025
€10,000 SATI S.p.A.: Non-compliance with the general principles for data processing. ⇄ Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9 Controllers Processing Accountability Jul 23, 2025
€5,000 Agricola International SA: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Jul 23, 2025
€2,200 Legal Entity: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 2,200 on a legal entity. An employee of the company forwarded health data to a lawyer without sufficient grounds. The company was fined… SLOVENIA ·IP-RS ·Art. 6, 9 Types of Special Categories of Personal Data Healthcare Processing Jul 22, 2025
€43,000 24/7 Communication Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 43,000 on 24/7 Communication Sp. z o.o. The fined entity acted as the data processor for McDonald’s Polska Sp. z o.o. (see ETid: 2757).… POLAND ·UODO ·Art. 5, 25, 38 Controllers Processors Retention Period Jul 21, 2025
€4M McDonald’s Polska Sp. z o.o.: Non-compliance with general principles for data processing. ⇄ Een boete van 3.955.000 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 28 +1 Controllers Security Processing Jul 21, 2025
€4M McDonald’s Polska Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed a fine of EUR 3,955,000 on McDonald’s Polska Sp. z o.o. The controller used a third party processor (see ETid: 2758) for the purpose of managing work… POLAND ·UODO ·Art. 5, 25, 28 +1 Controllers Processors Security Jul 21, 2025
€43,000 24/7 Communication Sp. z o.o.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 43.000 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 38 Security Controllers Processors Jul 21, 2025
€1,100 ADMINISTRACIONES BENIPON, S.L.: Failure to comply with the obligations regarding the notification of personal data breaches. ⇄ 1.100 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 28, 33 Controllers Processing Processors Jul 18, 2025
€1,000 CLUB BALONCESTO TELDE: Insufficient legal basis for the processing of data. ⇄ 1.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6 Consent Controllers Processing Jul 18, 2025
€1,000 CLUB BALONCESTO TELDE: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,000 on the club BALONCESTO TELDE. The controller published an image of a minor without the consent of the minors representative. SPAIN ·AEPD ·Art. 6 Controllers Consent Minors Jul 18, 2025
€200,000 ENDESA ENERGIA, S.A.U.: Violation of the general principles of data processing. ⇄ Een boete van 200.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Processing Accountability Jul 17, 2025
€200,000 ENDESA ENERGIA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 200,000 on ENDESA ENERGIA, S.A.U. The controller mistakenly linked two unrelated parties, resulting in a third party having its energy… SPAIN ·AEPD ·Art. 5 Controllers Processing IP Address Jul 17, 2025
€4,000 Georgescu Călin: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine on the politican Georgescu Călin. The controller failed to inform data subjects on his website regarding the processing of their data and how… ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervisory Authorities Jul 16, 2025
€5,400 SUNERIS, S.A.: Non-compliance with the general principles of data processing. ⇄ Boete van €5.400 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Processing Accountability IP Address Jul 16, 2025
€4,000 Georgescu Călin: Inadequate compliance with data subjects' rights (regarding their personal data). ⇄ Een boete van 4.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Processing Supervisory Authorities Jul 16, 2025
€5,400 SUNERIS, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5,400 on SUNERIS, S.A. The controller processed scans of ID cards and passports of their guests, infringing the principle of data… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Jul 16, 2025
€2,000 PAVLOS BIKOS SOLE PROPRIETORSHIP DENTAL PRIVATE CAPITAL COMPANY: Insufficient cooperation with supervisory authority The Greek DPA has imposed a fine of EUR 2,000 on PAVLOS BIKOS SOLE PROPRIETORSHIP DENTAL PRIVATE CAPITAL COMPANY. The fined party was a data processor in case ETid: 2880. During… GREECE ·HDPA ·Art. 31 Supervisory Authorities Supervision Processors Jul 11, 2025
€50,000 Magna PT S.p.A.: Insufficient legal basis for the processing of data. ⇄ Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Retention Period Jul 10, 2025