Content type · 2,273 documents in this view · 3,651 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3581 Processing Agreement2804 Processing2648 Personal Data2613 Controllers2228 Data Controller1873 Law Enforcement1546 IP Address1284 Security1034 Supervision890 Monitoring548 Consent522
€120,000 SERVICIOS ESPECIALES, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on SERVICIOS ESPECIALES, S.A. The case concerned a GDPR breach during an internal workplace conflict investigation: the company shared a report via… SPAIN · ·Art. 5 Mar 28, 2025
€12,000 ESTUDIO ALCAZAR DEL GENIL 2022, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine on ESTUDIO ALCAZAR DEL GENIL 2022, S.L. The controller collected property data by having its employees visit and photograph the properties,… SPAIN · ·Art. 6, 14 Mar 28, 2025
€18,000 Multiple Companies: Insufficient legal basis for data processing The Italian DPA imposed fines on 3 companies which ammount to EUR 6,000 each. The fined companies (Powerfit s.s.d.a.r.l., Soleo s.s.d.a.r.l. and Zero Due Villa s.s.d.a.r.l.) run a… ITALY · ·Art. 5, 6, 12 +1 Mar 27, 2025
€18,000 Meerdere bedrijven: Onvoldoende juridische basis voor gegevensverwerking. Een boete van €18.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 12 +1 Mar 27, 2025
€4,000 Istituto di Istruzione Superiore 'P. Galluppi' Tropea: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,500 on the Istituto di Istruzione Superiore 'P. Galluppi' Tropea. The controller processed biometric data of its employees to control… ITALY · ·Art. 5, 6, 9 Mar 27, 2025
€4,000 Istituto di Istruzione Superiore 'P. Galluppi' Tropea: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 4.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 9 Mar 27, 2025
€3.5M Advanced Computer Software Group Ltd: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined Advanced Computer Software Group Ltd £3.07 million (EUR 3.5 million) for insufficient IT security (infringiment of Art. 32 (1) UK GDPR). The controller… UNITED KINGDOM · ·Art. 32 Mar 26, 2025
€3.5M Advanced Computer Software Group Ltd: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.500.000 euro - Informatiecommissaris (ICO). UNITED KINGDOM · ·Art. 32 Mar 26, 2025
€25,000 NTT DATA ROMANIA S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ·Art. 32, 33 ·Insufficient technical and organisational measures to ensure information security Mar 25, 2025
€25,000 NTT DATA ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on NTT DATA ROMANIA S.A. The controller failed to implement sufficient technical and organisational measures, resulting in a data… ·Art. 32, 33 ·Insufficient technical and organisational measures to ensure information security Mar 25, 2025
€4,000 Ziekenhuis: Niet-naleving van de algemene principes voor gegevensverwerking. 4.000 euro boete - Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA · ·Art. 13, 14, 25 +1 Mar 24, 2025
€17,600 Chief Commander of the Police: Insufficient legal basis for data processing The Polish DPA has fined the Chief Commander of the Polish Police EUR 17,600. During a press conference, the Chief Commander of the Police disclosed the personal and medical data… POLAND · ·Art. 6, 9 Mar 24, 2025
€40,000 Company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 40,000 on a company that published personal data of sole traders on its website. The data originated from public sources and from… CROATIA · ·Art. 5, 6, 12 +3 Mar 24, 2025
€20,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) imposed a fine of EUR 20,000 on a hospital for failing to implement adequate technical and organizational measures to protect personal data in line with… CROATIA · ·Art. 32 Mar 24, 2025
€2,000 INDEPENDENTS DE VALLROMANES: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,000 on INDEPENDENTS DE VALLROMANES. The controller, a political party, posted a court decision on its social media, which included… SPAIN · ·Art. 5 Mar 24, 2025
€4,000 Hospital: Non-compliance with general data processing principles The Croation DPA (AZOP) has imposed a fine of EUR 4,000 on a hospital. The AZOP found that the hospital used a company which automatically retrieved personal data of vehicle… CROATIA · ·Art. 13, 14, 25 +1 Mar 24, 2025
€80,000 Company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 80,000 on a company. The company was responsible for monitoring parking lots at several supermarkets and a hospital. However, it… CROATIA · ·Art. 5, 6, 32 Mar 24, 2025
€40,000 Bedrijf: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 40.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA · ·Art. 5, 6, 12 +3 Mar 24, 2025
€1,000 Bucharest Down Town Hotel SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Bucharest Down Town Hotel SRL. The controller failed to provide a data subject with requested data. ROMANIA · ·Art. 12, 13, 15 Mar 21, 2025
€2,000 ONE UNITED PROPERTIES S.A: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on ONE UNITED PROPERTIES S.A. The controller contacted a data subject multiple times for direct marketing purposes without… ROMANIA · ·Art. 6, 12, 15 +1 Mar 20, 2025
€6.3M Poczta Polska SA (Polish Post): Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 6.3 million on Poczta Polska SA (Polish Post) for the unlawful disclosure of personal data of over 30 million citizens from the PESEL… POLAND · ·Art. 6 Mar 17, 2025
€23,500 Minister of Digital Affairs: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 23,500 on the Polish Minister for Digital Affairs. The Minister unlawfully processed personal data of Polish citizens in the PESEL… POLAND · ·Art. 5, 6 Mar 17, 2025
€3.2M CENTROS COMERCIALES CARREFOUR, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 3,200,000 on CENTROS COMERCIALES CARREFOUR, S.A. The controller suffered a cyberattack, resulting in the leak of a large amount of personal… SPAIN · ·Art. 5, 32, 34 Mar 14, 2025
€1.6M ING BANK N.V., SUCURSAL EN ESPAÑA: Insufficient legal basis for data processing The Spanish data protection authority (AEPD) has imposed a fine on ING BANK N.V., SUCURSAL EN ESPAÑA. As part of the verification process for new banking customers, ING carries… SPAIN · ·Art. 6 Mar 14, 2025
€2,000 Municipality of Roccaraso: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 2,000 on the Municipality of Roccaraso. The controller published personal data of a worker on its public notice board website without a… ITALY · ·Art. 5, 6 Mar 13, 2025
€20,000 Encore Thermoengineering s.r.l.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 20,000 on Encore Thermoengineering s.r.l. The controller legally obtained employee data from another company that had gone bankrupt. The… ITALY · ·Art. 5, 6, 17 Mar 13, 2025
€40,000 Interflora Italia S.p.A.: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 20,000 on Interflora Italia S.p.A. The controller, who operates an online shop, used customer data for direct marketing purposes without a… ITALY · ·Art. 5, 6, 12 +2 Mar 13, 2025
€15,000 G@S Telecomunicazioni di Losito Lucia: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 15,000 on G@S Telecomunicazioni di Losito Lucia. The controller processed customer data without sufficient legal basis and additionally… ITALY · ·Art. 5, 6, 7 +2 Mar 13, 2025
€5,000 Automobilus International S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Automobilus International S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure… ROMANIA · ·Art. 32 Mar 12, 2025
€1,000 Noy Business Tranzactions SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Noy Business Tranzactions SRL. The controller failed to provide a data subject with requested data. ROMANIA · ·Art. 12, 15, 17 Mar 11, 2025
€13,400 Polskie Radio Szczecin: Insufficient technical and organisational measures to ensure information security The Polish DPA fined Polskie Radio Szczecin (Polish Radio Szczecin) EUR 13,400. Due to the lack of sufficient technical measures, Polskie Radio Szczecin failed to protect the… POLAND · ·Art. 24, 32 Mar 11, 2025
€2,000 SHOPBAG GROUP ONLINE SRL: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 2,000 onSHOPBAG GROUP ONLINE SRL. The controller failed to respond to a request made by the DPA. ROMANIA · ·Art. 58 Mar 6, 2025
€20,000 WEBRASOFT SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on WEBRASOFT SRL. The controller failed to implement sufficient technical and organisational measures to ensure data security,… ROMANIA · ·Art. 32 Mar 4, 2025
€10,000 BEKO ROMANIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on BEKO ROMANIA SA. The controller failed to implement sufficient technical and organisational measures to provide data security,… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Mar 3, 2025
€2,556 Registry Agency of Republic of Bulgaria: Insufficient legal basis for data processing Bulgarian Commission for Personal Data Protection (KZLD) fined Registry Agency of Republic of Bulgaria €2,556 on 2025-03-01 for: Insufficient legal basis for data processing. ·Insufficient legal basis for data processing Mar 1, 2025
€1,000 Velvet Medical SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Velvet Medical SRL. The controller failed to provide the data subject with the requested health data. ROMANIA · ·Art. 12, 15 Feb 27, 2025
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… SPAIN · ·Art. 6 Feb 25, 2025
€600,000 IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274. Due to a technical error in its online platform, personal data, including… SPAIN · ·Art. 5 Feb 25, 2025
€2,000 Medstar S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 2,000 on Medstar S.R.L. The controller had mistakenly sent a patient's health data via unsecured email to another patient. The DPA found… ROMANIA · ·Art. 32 Feb 20, 2025
€2,000 Meedea Construct Prest SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 in Meedea Construct Prest SRL. The controller disclosed personal and health data of a former employee to a third party, who then… ROMANIA · ·Art. 5, 6, 9 Feb 17, 2025
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… SPAIN · ·Art. 6 Feb 14, 2025
€200,000 ORANGE BANK, S.A. SUCURSAL EN ESPAÑA: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 200,000 on ORANGE BANK, S.A. SUCURSAL EN ESPAÑA. The AEPD reacted to multiple complaints of private individuals regarding a data… SPAIN · ·Art. 5 Feb 14, 2025
€3,000 PPC Energie Muntenia SA: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 3,000 on PPC Energie Muntenia SA. The controller forwarded customer data to a third company, which then contacted the data subjects for… ROMANIA · ·Art. 5, 6, 12 +1 Feb 10, 2025
€3,000 Omniasig Vienna Insurance Group S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Omniasig Vienna Insurance Group S.A. The controller failed to implement sufficient technical and organisational measures to… ROMANIA · ·Art. 32 Feb 6, 2025
€1.2M ORANGE ESPAGNE, S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,200,000 on ORANGE ESPAGNE, S.A.U.. An individual had filed a complaint with the DPA because the company had given a duplicate of their… SPAIN · ·Art. 6, 25 Feb 5, 2025
€5,000 FARMEC SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on FARMEC SA. The controller failed to implement sufficient technical and organisational measures to ensure data security,… ROMANIA · ·Art. 25, 32 Feb 5, 2025
€10,000 V&M Contab & Management SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on V&M Contab & Management SRL. The controller failed to implement sufficient technical and organisational measures to ensure… ROMANIA · ·Art. 32, 58 Feb 4, 2025
€15,000 Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Unicredit Bank SA. The controller failed to implement sufficient technical and organisational measures to ensure data… ROMANIA · ·Art. 25 Feb 3, 2025
€15,000 S.P.E.E.H. HIDROELECTRICA S.A: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on S.P.E.E.H. HIDROELECTRICA S.A. The controller failed to implement sufficient technical and organisational measures to ensure… ROMANIA · ·Art. 25 Jan 31, 2025
€40,000 Orange Romania SA: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 40,000 on Orange Romania SA. The controller failed to fulfil a request for the erasure of data. The controller also execsevly stored and… ·Art. 5, 6, 7 +2 ·Non-compliance with general data processing principles Jan 27, 2025