Skip to content
Content type · 3,446 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

501–550 of 3,446 sort newestlargest fineoldest
€10,000 Gemeente Venetië: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 25 +1 Education Processing Data Controller NL Aug 4, 2025
€80,000 Ospedaliero-Universitaria Careggi: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 80,000 on the Ospedaliero-Universitaria Careggi. The controller, a university hospital, used software that allowed medical personnel to… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Healthcare Personal Data Aug 4, 2025
€7,700 Non-Public Health Care Institution: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 7,700 on a non-public health care institution. The controller offered home visits by doctors as part of its services. For this purpose,… POLAND ·UODO ·Art. 5, 25, 32 Healthcare Security Controllers Aug 4, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2,000 on Linea Stampalibera Società Cooperativa r.I. The controller, who operates a news site, has disclosed too much personal… ITALY ·Garante ·Art. 5 Retention Period Health Data IP Address Aug 4, 2025
€230 Police Officer: Insufficient legal basis for data processing The UK DPA has imposed a fine of £ 200 (EUR 230) on a police officer. The controller forwarded sensitive and restricted personal data that he had obtained in the course of his… UNITED KINGDOM ·ICO ·Insufficient legal basis for data processing Personal Data Controllers Education Aug 4, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor gegevensbescherming (Garante). ITALY ·Garante ·Art. 5 Health Data Healthcare Processing NL Aug 4, 2025
€10,000 Comune di Venezia: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on the Comune di Venezia. The controller implemented a tourist tax, which includes exceptions for certain groups of visitors. When… ITALY ·Garante ·Art. 5, 6, 25 +1 IP Address Controllers Processing Agreement Aug 4, 2025
€80,000 Ospedaliero-Universitaria Careggi: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Health Data Healthcare NL Aug 4, 2025
€11,614 Legal Entity: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 11,614 on a legal entity. The controller did not delete the email address of a former employee, but rather continued to receive and… SLOVENIA ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Processing Processing Agreement Jul 29, 2025
€4,400 Entrepreneur: Insufficient cooperation with supervisory authority The Polish DPA has imposed a fine of EUR 4,400 on an Entrepreneur. The controller failed to adequatly react to a request from the DPA. POLAND ·UODO ·Art. 58 Supervisory Authorities Supervision Controllers Jul 28, 2025
€4,400 Ondernemer: Onvoldoende samenwerking met de toezichthoudende instantie. 4.400 euro boete - Pools Nationaal Bureau voor de Bescherming van Persoonsgegevens (UODO). POLAND ·UODO ·Art. 58 Supervisory Authorities Controllers Data Controller NL Jul 28, 2025
€5,020 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 5,020 on a legal entity. The controller had developed an application that allowed the exchange of personal data, but failed to… SLOVENIA ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Jul 25, 2025
€5,810 Legal Entity: Insufficient data processing agreement The Slovenian DPA has imposed a fine of EUR 5,810 on a legal entity. The controller employed a person authorised to perform clerical work. However, this person used a data… SLOVENIA ·Art. 28 ·Insufficient data processing agreement Processors Controllers Processing Agreement Jul 25, 2025
€26,400 Debt Collector: Insufficient fulfilment of data subjects rights The Hungarian DPA has imposed a fine of EUR 26,400 on a debt collector. The controller processed the personal data of a natural person, specifically data relating to a consumer… HUNGARY ·NAIH ·Art. 6, 17 Personal Data Controllers Insurance Jul 24, 2025
€5,000 Agricola International SA: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing NL Jul 23, 2025
€10,000 SATI S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on SATI S.p.A. Information about the reasons for employees' absences was displayed on boards and in emails, which were accessible… ITALY ·Garante ·Art. 5, 9 Controllers Employees IP Address Jul 23, 2025
€10,000 SATI S.p.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9 Processing Controllers Data Controller NL Jul 23, 2025
€5,000 Agricola International SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Agricola International SA. The controller failed to implement sufficient technical and organisational measures, resulting in a… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Law Enforcement Jul 23, 2025
€10,000 Order of Nursing Professions of Viterbo: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on the Order of Nursing Professions of Viterbo. The controller suffered a data leak due to insufficient technical and… ITALY ·Garante ·Art. 5, 32 Security Education Controllers Jul 23, 2025
€2,200 Legal Entity: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 2,200 on a legal entity. An employee of the company forwarded health data to a lawyer without sufficient grounds. The company was fined… SLOVENIA ·Art. 6, 9 ·Insufficient legal basis for data processing Health Data Healthcare Processing Agreement Jul 22, 2025
€320,000 HEP-Toplinarstvo: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined HEP-Toplinarstvo €320,000 on 2025-07-22 for: Insufficient technical and organisational measures to ensure information security. Croatia ·azop ·Art. 31, 32 Security Human Resources Supervisory Authorities Jul 22, 2025
€50,000 Information and Communication Company: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined Information and Communication Company €50,000 on 2025-07-22 for: Insufficient technical and organisational measures to ensure… Croatia ·azop ·Art. 32 Security Human Resources Supervisory Authorities Jul 22, 2025
€4M McDonald’s Polska Sp. z o.o.: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van 3.955.000 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 28 +1 Controllers Security Processing NL Jul 21, 2025
€4M McDonald’s Polska Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed a fine of EUR 3,955,000 on McDonald’s Polska Sp. z o.o. The controller used a third party processor (see ETid: 2758) for the purpose of managing work… POLAND ·UODO ·Art. 5, 25, 28 +1 Controllers Processors Data Breaches Jul 21, 2025
€43,000 24/7 Communication Sp. z o.o.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 43.000 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 38 Security Processors Controllers NL Jul 21, 2025
€9,000 Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 9,000 on Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A. The controller disclosed the identity of an anonymous author by… GREECE ·HDPA ·Art. 5, 25, 32 +2 Pseudonymization Controllers Personal Data Jul 21, 2025
€43,000 24/7 Communication Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 43,000 on 24/7 Communication Sp. z o.o. The fined entity acted as the data processor for McDonald’s Polska Sp. z o.o. (see ETid: 2757).… POLAND ·UODO ·Art. 5, 25, 38 Data Breaches Controllers Processors Jul 21, 2025
€1,000 CLUB BALONCESTO TELDE: Onvoldoende juridische basis voor de verwerking van gegevens. 1.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6 Processing Consent Data Controller NL Jul 18, 2025
€1,100 ADMINISTRACIONES BENIPON, S.L.: Onvoldoende naleving van de verplichtingen met betrekking tot het melden van datalekken. 1.100 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 28, 33 Data Breaches Notification Obligation Controllers NL Jul 18, 2025
€1,100 ADMINISTRACIONES BENIPON, S.L.: Insufficient fulfilment of data breach notification obligations The Spanish DPA has imposed a fine of EUR 1,100 on ADMINISTRACIONES BENIPON, S.L. The processor failed to notify the controller of a data breach and also used a sub-processor… SPAIN ·aepd ·Art. 28, 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jul 18, 2025
€1,000 CLUB BALONCESTO TELDE: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,000 on the club BALONCESTO TELDE. The controller published an image of a minor without the consent of the minors representative. SPAIN ·aepd ·Art. 6 Controllers Representatives Processing Agreement Jul 18, 2025
€1,200 TRUEBA SPORT S.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 13 Security Data Controller Controllers NL Jul 17, 2025
€200,000 ENDESA ENERGIA, S.A.U.: Overtreding van de algemene principes voor gegevensverwerking. Een boete van 200.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Processing Data Controller Controllers NL Jul 17, 2025
€1,200 TRUEBA SPORT S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,200 on TRUEBA SPORT S.L. The controller disclosed personal data due to an human error. The controller also failed to include a privacy… SPAIN ·aepd ·Art. 5, 13 Controllers Personal Data Processing Agreement Jul 17, 2025
€200,000 ENDESA ENERGIA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 200,000 on ENDESA ENERGIA, S.A.U. The controller mistakenly linked two unrelated parties, resulting in a third party having its energy… SPAIN ·aepd ·Art. 5 Controllers Processing Agreement IP Address Jul 17, 2025
€180,000 TRIVE CREDIT SPAIN, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 180,000 on TRIVE CREDITSPAIN, S.L. The controller failed to adequatly comply with a order from the DPA. The original fine of EUR 225,000… aepd ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Law Enforcement Jul 16, 2025
€4,000 Georgescu Călin: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine on the politican Georgescu Călin. The controller failed to inform data subjects on his website regarding the processing of their data and how… ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Data Controller Jul 16, 2025
€5,400 SUNERIS, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5,400 on SUNERIS, S.A. The controller processed scans of ID cards and passports of their guests, infringing the principle of data… SPAIN ·aepd ·Art. 5 Retention Period IP Address Controllers Jul 16, 2025
€180,000 TRIVE CREDIT SPAIN, S.L.: Onvoldoende samenwerking met de toezichthoudende instantie. Een boete van 180.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). aepd ·Art. 58 ·Insufficient cooperation with supervisory authority Controllers Supervisory Authorities Accountability NL Jul 16, 2025
€5,400 SUNERIS, S.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Boete van €5.400 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Processing IP Address Accountability NL Jul 16, 2025
€4,000 Georgescu Călin: Onvoldoende naleving van de rechten van betrokkenen (betreffende hun persoonsgegevens). Een boete van 4.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Data Controller Processing NL Jul 16, 2025
€20,000 NN Griekse levensverzekeringsmaatschappij met één aandeelhouder, anoniem: Onvoldoende naleving van de rechten van betrokkenen. Boete van 20.000 euro - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 15 Personal Data Data Controller Controllers NL Jul 11, 2025
€2,000 PAVLOS BIKOS SOLE PROPRIETORSHIP DENTAL PRIVATE CAPITAL COMPANY: Insufficient cooperation with supervisory authority The Greek DPA has imposed a fine of EUR 2,000 on PAVLOS BIKOS SOLE PROPRIETORSHIP DENTAL PRIVATE CAPITAL COMPANY. The fined party was a data processor in case ETid: 2880. During… GREECE ·HDPA ·Art. 31 Supervisory Authorities Supervision Controllers Jul 11, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on VALORA PREVENCIÓN, S.L.U. The controller, a company offering occupational health and safety services, failed to implement… SPAIN ·aepd ·Art. 5, 32 Health Data Healthcare Security Jul 11, 2025
€20,000 NN Greek Single-Member Anonymous Life Insurance Company: Insufficient fulfilment of data subjects rights The Greek DPA has imposed a fine of EUR 20,000 on NN Greek Single-Member Anonymous Life Insurance Company. The controller failed to provide the data subject with the personal data… GREECE ·HDPA ·Art. 15 Right of Access Procedures Right of Access Insurance Jul 11, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 32.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 32 Security Health Data Healthcare NL Jul 11, 2025
€50,000 Magna PT S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine on Magna PT S.p.A. Employees of the controllers were subjected to 'return to work interviews' after returning from an absence due to illness or… ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Retention Period Jul 10, 2025
€3,000 Gemeente Conversano: Gebrek aan benoeming van een functionaris voor gegevensbescherming. Een boete van 3.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 37 Education Supervisory Authorities Public Authority NL Jul 10, 2025