Skip to content
Content type · 2,395 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

501–550 of 2,395 sort newestlargest fineoldest
€4,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 4,000 on Vodafone Romania S.A. The controller failed to implement sufficient technical and organisational measures to ensure data… ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Jun 23, 2025
€50,000 Piraeus Bank S.A.: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 50,000 on Piraeus Bank S.A.The controller has processed personal data even though the data subject rightfully opposed the the data… GREECE ·HDPA ·Art. 5, 6 Personal Data Controllers Processing Jun 23, 2025
€3,500 Municipal Social Welfare Center Aleksandrów: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 3,500 on the Municipal Social Welfare Center in Aleksandrów. The controller did not implement sufficient technical and organisational… POLAND ·UODO ·Art. 32 Security Controllers Personal Data Jun 23, 2025
€24,000 COLEGIO VIRGEN DE EUROPA, S.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 24.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 6, 13 Personal Data Processing Controllers Jun 20, 2025
€24,000 COLEGIO VIRGEN DE EUROPA, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 24,000 on COLEGIO VIRGEN DE EUROPA, S.L. An employee of the controller, a school, took pictures of minor pupils without a sufficient legal… SPAIN ·AEPD ·Art. 5, 6, 13 Controllers Personal Data Supervisory Authorities Jun 20, 2025
€1,000 SC Diamir SRL: Violation of the general principles of data processing. ⇄ Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 58 Processing Personal Data Supervisory Authorities Jun 19, 2025
€1,000 SC Diamir SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 1,000 on SC Diamir SRL. The controller failed to properly cooperate with the supervisory authority and also disclosed personal data to… ROMANIA ·ANSPDCP ·Art. 6, 58 Supervisory Authorities Supervision Controllers Jun 19, 2025
€6,800 Waxholms Ångfartygs AB: Insufficient legal basis for the processing of personal data. ⇄ 6.800 euro boete - De Zweedse Autoriteit voor Gegevensbescherming (Integritetsskyddsmyndigheten). SWEDEN ·IMY ·Art. 6, 9 Processing Personal Data Controllers Jun 18, 2025
€200 Dincă Viorel George: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 200 on a private individual. The controller failed to react to communication from the supervisory authority. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Controllers Jun 18, 2025
€200 Dincă Viorel George: Insufficient cooperation with the supervisory authority. ⇄ Een boete van 200 euro - De Roemeense nationale toezichthouder op de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Processing Jun 18, 2025
€550,000 Ministry of Social Security: Insufficient legal basis for data processing. ⇄ 550.000 euro boete - Ierse Autoriteit voor Gegevensbescherming. IRELAND ·DPC ·Art. 5, 6, 9 +2 Types of Special Categories of Personal Data Personal Data Controllers Jun 12, 2025
€550,000 Departement of Social Security: Insufficient legal basis for data processing The Irish DPA imposed a fine of EUR 550,000 on the Departement of Social Security. The controller uses the so called SAFE 2 registration process for anyone applying for a Public… IRELAND ·DPC ·Art. 5, 6, 9 +2 DPIA Types of Special Categories of Personal Data Controllers Jun 12, 2025
€10,000 Accounting Audit Ltd: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van €10.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Jun 12, 2025
€10,000 Accounting Audit SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 10,000 on Accounting Audit SRL. The company failed to implement sufficient technical and organizational measures, resulting in a data breach… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Data Breaches Jun 12, 2025
€22,000 Kristiansand municipality: Insufficient legal basis for data processing The Norwegian DPA imposed a fine of EUR 22,000 on Kristiansand municipality. The controller offers a helpline for childreen, which had become victims of violence, abuse or… NORWAY ·Datatilsynet (NO) ·Art. 6, 12, 13 Personal Data Controllers Supervisory Authorities Jun 10, 2025
€22,000 Municipality of Kristiansand: Insufficient legal basis for data processing. ⇄ 22.000 euro boete - Noorse Toezichtsautoriteit (Datatilsynet). NORWAY ·Datatilsynet (NO) ·Art. 6, 12, 13 Personal Data Processing Supervision Jun 10, 2025
€45,000 Noi Compriamo Auto.it S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 45,000 on Noi Compriamo Auto.it S.r.l. The controller contacted the data subject multiple times for direct marketing purposes via… ITALY ·Garante ·Art. 5, 6, 12 +2 Controllers Personal Data Security Jun 4, 2025
€45,000 Noi Compriamo Auto.it S.r.l.: Violation of the general principles for data processing. ⇄ Een boete van 45.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +2 Controllers Personal Data Security Jun 4, 2025
€5,000 AG-BROKER ASIGURARE S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on AG-BROKER ASIGURARE S.R.L. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 30, 2025
€42,000 LVMH IBERIA, S.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 42.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6 Personal Data Processing Controllers May 30, 2025
€5,000 AG-BROKER ASIGURARE S.R.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van €5.000 - De Roemeense nationale toezichthouder op de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data May 30, 2025
€1.1M Yliopiston Apteekin: Non-compliance with general data processing principles The Finish DPA has imposed a fine of EUR 1,100,000 on Yliopiston Apteekin. The controller, who runs an online pharmacy, used various web analytics and monitoring tools. These… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 32 Retention Period Controllers Personal Data May 27, 2025
€1.4M REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 1,380,000 on REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS, S.L. The controller used outdated technical and organisational measures to manage… SPAIN ·AEPD ·Art. 5, 32 Controllers Security Personal Data May 26, 2025
€1,000 MP Dumitru Viorel Focșa: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 1,000 on the MP Dumitru Viorel Focșa. The controller published a post on social media containing personal data of a third person. The… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Processing May 22, 2025
€1,000 MP Dumitru Viorel Focșa: Insufficient legal basis for data processing. ⇄ Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6 Processing Personal Data Controllers May 22, 2025
€1,200 Lawyer: There is insufficient legal basis for processing the data. ⇄ 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6 Controllers Processing Personal Data May 22, 2025
€1,200 Attorney: Insufficient legal basis for data processing The Spanish DPA imposed a fine on an attorney. The controller processed data of a data subject without sufficient legal basis. The original fine of EUR 2,000 was reduced to EUR… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Insurance May 22, 2025
€12,000 Data Diggers Market Research SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 12,000 on Data Diggers Market Research SRL. The controller processed personal data without sufficient legal basis. The controller also… ROMANIA ·ANSPDCP ·Art. 6, 12, 14 +1 Personal Data Controllers Supervisory Authorities May 21, 2025
€21,000 Menarini Silicon Biosystems SpA: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 21,000 on Menarini Silicon Biosystems SpA. The controller is conducting oncological research and has developed a software that is able to… ITALY ·Garante ·Art. 5, 13 Retention Period Storage Limitation Accountability May 21, 2025
€200,000 TELEFÓNICA MÓVILES ESPAÑA, S.A.: Insufficient legal basis for data processing. ⇄ Een boete van 200.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6 Controllers Personal Data Processing May 21, 2025
€200,000 TELEFÓNICA MÓVILES ESPAÑA, S.A.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 200,000 on TELEFÓNICA MÓVILES ESPAÑA, S.A. The controller forwarded personal data to a third party without a sufficient legal basis. SPAIN ·AEPD ·Art. 6 Controllers Personal Data Telecommunications May 21, 2025
€12,000 Data Diggers Market Research SRL: Non-compliance with general principles of data processing. ⇄ Een boete van €12.000 - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 12, 14 +1 Personal Data Processing Supervisory Authorities May 21, 2025
€7,000 Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 7,000 on Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North. The controller… ITALY ·Garante ·Art. 5, 9 Healthcare Controllers Personal Data May 21, 2025
€21,000 Menarini Silicon Biosystems SpA: Non-compliance with the general principles for data processing. ⇄ 21.000 euro boete - Italiaanse Autoriteit voor de bescherming van persoonlijke gegevens (Garante). ITALY ·Garante ·Art. 5, 13 Controllers Processing Personal Data May 21, 2025
€1,000 Home Owner Association: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 1,000 on a home owner association. The HOA displayed the personal data of debtors in the entrance hall of a building, which infringed on the… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Processing May 19, 2025
€5,000 Maravet S.R.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data May 19, 2025
€200,000 ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 200,000 on ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L. The controller obtained personal data from a third party… SPAIN ·AEPD ·Art. 6, 17 Controllers Personal Data Insurance May 19, 2025
€200,000 ASNEF-EQUIFAX, a company providing creditworthiness information, lacks a sufficient legal basis for data processing. ⇄ Een boete van 200.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6, 17 Controllers Personal Data Right to be Forgotten May 19, 2025
€5,000 Maravet S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Maravet S.R.L. The controller did not implement sufficient technical and organisational measures to ensure information… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 19, 2025
€5,000 ACCOUNTING & AUDIT CONSULTING SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on ACCOUNTING & AUDIT CONSULTING SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 16, 2025
€30,000 ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.: Non-compliance with the general principles for data processing. ⇄ Boete van 30.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Personal Data Processing May 16, 2025
€5,000 ACCOUNTING & AUDIT CONSULTING SRL: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data May 16, 2025
€900,000 SOLOCAL MARKETING SERVICES: Insufficient legal basis for data processing The French DPA imposed a fine of EUR 900,000 on SOLOCAL MARKETING SERVICES. The controller, a company that also engages in direct marketing activities for its clients, ist using… FRANCE ·CNIL ·Art. 6, 7 Consent Controllers Personal Data May 15, 2025
€900,000 SOLOCAL MARKETING SERVICES: Insufficient legal basis for data processing. ⇄ 900.000 euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 6, 7 Consent Controllers Processing May 15, 2025
€2,000 CVA TAX & FINANCE S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 CVA TAX & FINANCE S.R.L. The controller did not implement sufficient technical and organisational measures to ensure information… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 14, 2025
€2,000 CVA TAX & FINANCE S.R.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data May 14, 2025
€2,000 Romoffice Construct Holding Ag SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 Romoffice Construct Holding Ag SRL. The controller processed personal data without a sufficient legal basis. ROMANIA ·ANSPDCP ·Art. 5, 6 Controllers Personal Data Processing May 13, 2025
€2,000 Romoffice Construct Holding Ag SRL: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6 Processing Personal Data Controllers May 13, 2025