Skip to content
Content type · 3,808 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

551–600 of 3,808 sort newestlargest fineoldest
€2,000 Whitedecor SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on Whitedecor SRL. The controller had sent marketing messages to customers without a sufficient legal basis. ROMANIA ·ANSPDCP ·Art. 6, 7, 12 +3 Direct Marketing Controllers Personal Data Nov 10, 2025
€2,000 Whitedecor SRL: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 7, 12 +3 Personal Data Processing Supervisory Authorities Nov 10, 2025
€1,000 Company: Insufficient fulfilment of data subjects rights The Greek DPA has imposed a fine of EUR 1,000 on a Company. The controller failed to react adequately to a data subject's request to exercise their rights. GREECE ·HDPA ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Nov 7, 2025
€7,000 Klass Wagen S.R.L.: Insufficient technical and organizational measures to ensure information security. ⇄ Boete van €7.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Nov 7, 2025
€7,000 Klass Wagen S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 7,000 on Klass Wagen S.R.L. The controller suffered a cyber incident due to a former employee exposing the login credentials of… ROMANIA ·ANSPDCP ·Art. 32 Controllers Security Personal Data Nov 7, 2025
€1,000 Company: Insufficient compliance with data subjects' rights (regarding their personal data). ⇄ Boete van €1.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 12, 15 Personal Data Right of Access Controllers Nov 7, 2025
€10M Aena, a small and medium-sized enterprise (SME), S.A.: Non-compliance with the general principles of data processing. ⇄ 10.043.002 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 35 DPIA Controllers Processing Nov 6, 2025
€10M Aena, S.M.E., S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 10,043,002 on Aena, S.M.E., S.A. The controller conducted a pilot project involving multiple airports, including the use of facial… SPAIN ·AEPD ·Art. 35 DPIA Controllers Supervisory Authorities Nov 6, 2025
€750 ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓN: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 750 on the ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓN. The controller failed to certify compliance with the corrective measures imposed by… SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Controllers Nov 5, 2025
€2,556 Municipality of Kyustendil: Insufficient legal basis for data processing Bulgarian Commission for Personal Data Protection (KZLD) fined Municipality of Kyustendil €2,556 on 2025-11-01 for: Insufficient legal basis for data processing. Bulgaria ·CPDP ·Insufficient legal basis for data processing Public Authority Education Personal Data Nov 1, 2025
€6,000 APARELLS ORTOPEDICS CURTO, S.L: Insufficient compliance with data subjects' rights. ⇄ Een boete van 6.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Personal Data Health Data Oct 28, 2025
€300,000 SIA 'ZZ Dats': Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 300.000 euro - Inspectie gegevensbescherming (DSI). LATVIA ·DSI ·Art. 32 Security Controllers Processors Oct 28, 2025
€300,000 SIA 'ZZ Dats': Insufficient technical and organisational measures to ensure information security The Latvian DPA has imposed a fine of EUR 300,000 on SIA 'ZZ Dats'. The entity that was fined was the data processor for almost all local governments in Latvia. It failed to… LATVIA ·DSI ·Art. 32 Processors Security Controllers Oct 28, 2025
€6,000 APARELLS ORTOPEDICS CURTO, S.L: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 6,000 on APARELLS ORTOPEDICS CURTO, S.L. The controller was unable to retain the data it was required to ensure the availability of,… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Supervisory Authorities Oct 28, 2025
€9,450 Gynecological center: Insufficient compliance with obligations to report data breaches. ⇄ Boete van €9.450 - Pools Nationaal Bureau voor de Bescherming van Persoonsgegevens (UODO). POLAND ·UODO ·Insufficient fulfilment of data breach notification obligations Data Breaches Personal Data Health Data Oct 27, 2025
€1,500 Shop Owner: Insufficient legal basis for data processing Austrian Data Protection Authority (dsb) fined Shop Owner €1,500 on 2025-10-27 for: Insufficient legal basis for data processing. Austria ·DSB ·Art. 5, 6 Processing IP Address Human Resources Oct 27, 2025
€9,450 Gynecological Center: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 9,450 on a Gynecological Center. The controller sufferd a data breach and failed to report this to the DPO. POLAND ·UODO ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 27, 2025
€5,000 Judicial enforcement officer: Insufficient compliance with obligations regarding the notification of personal data breaches. ⇄ Een boete van 5.000 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 33, 34 Controllers Data Breaches Education Oct 23, 2025
€15,000 Municipality of Curtarolo: Insufficient Legal Basis for Data Processing. ⇄ Een boete van 15.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +3 Controllers Processing DPIA Oct 23, 2025
€2,000 Comune di Avola: Lack of appointment of data protection officer The Italian DPA has imposed a fine of EUR 2,000 on the Comune di Avola. The controller failed to communicate the DPO's contact details to the DPA. ITALY ·Garante ·Art. 37 Supervisory Authorities Public Authority Controllers Oct 23, 2025
€4,000 Higher Education Institution 'Statista Aldo Moro' in Fara Sabina: Insufficient Legal Basis for Data Processing ⇄ Een boete van 4.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 37 Controllers Education Public Authority Oct 23, 2025
€20,000 Multimedia News Società Cooperativa: Insufficient compliance with data subjects' rights. ⇄ Een boete van 20.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 12 Personal Data Controllers Supervisory Authorities Oct 23, 2025
€5,000 Court Bailiff: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 5,000 on a court bailiff. The controller forwarded a letter containing personal data to the wrong person, failing to inform either the… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 23, 2025
€865,000 Aktia Pankki Oyj: Insufficient technical and organisational measures to ensure information security The Finish DPA has imposed a fine of EUR 865,000 on Aktia Pankki Oyj. The controller changed its strong authentication process in such a way that it no longer guaranteed adequate… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Controllers Identification Oct 23, 2025
€15,000 Ordine degli Avvocati di Latina: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on the Ordine degli Avvocati di Latina. The controller published a document relating to criminal proceedings that included… ITALY ·Garante ·Art. 5, 6, 10 Controllers Personal Data Processing Oct 23, 2025
€20,000 Multimedia News Società Cooperativa: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 20,000 on Multimedia News Società Cooperativa. The controller failed to adequatly react to a request by a data subject to exercise their… ITALY ·Garante ·Art. 12 Personal Data Controllers Supervisory Authorities Oct 23, 2025
€1,000 Mayor of the Municipality of Calvi Risorta: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on the Mayor of the Municipality of Calvi Risorta. The controller published citizens' health data during the Covid-19 pandemic… ITALY ·Garante ·Art. 5, 6, 9 Healthcare Types of Special Categories of Personal Data Controllers Oct 23, 2025
€15,000 Comune di Curtarolo: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on the Comune di Curtarolo. The controller used surveillance footage in disciplinary proceedings against an employee, and also… ITALY ·Garante ·Art. 5, 6, 12 +3 Controllers Monitoring Supervisory Authorities Oct 23, 2025
€4,000 'Statista Aldo Moro' Higher Education Institute in Fara Sabina: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 4,000 on the 'Statista Aldo Moro' Higher Education Institute in Fara Sabina. The controller published a protocol of disciplinary… ITALY ·Garante ·Art. 5, 6, 37 Public Authority Personal Data Controllers Oct 23, 2025
€2,000 Municipality of Avola: Failure to appoint a data protection officer. ⇄ Een boete van 2.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 37 Public Authority Supervisory Authorities Controllers Oct 23, 2025
€1,000 Mayor of the Municipality of Calvi Risorta: Insufficient legal basis for data processing. ⇄ Een boete van €1.000 - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 Health Data Types of Special Categories of Personal Data Healthcare Oct 23, 2025
€865,000 Aktia Bank Plc: Insufficient technical and organizational measures to ensure information security. ⇄ 865.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Privacy by Design Privacy by Default Oct 23, 2025
€15,000 Bar Association of Latina: Insufficient legal basis for the processing of data. ⇄ Een boete van 15.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 10 Criminal Data Controllers Public Authority Oct 23, 2025
€2,000 Agency for Control of Outstanding Debts S.R.L.: Insufficient compliance with data subjects' rights. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Processing Supervision Oct 22, 2025
€80,000 SENDING TRANSPORTE Y COMUNICACIÓN, S.A.: Insufficient agreement regarding data processing. ⇄ Een boete van 80.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 28 Controllers Processors Processing Oct 22, 2025
€80,000 SENDING TRANSPORTE Y COMUNICACIÓN, S.A.: Insufficient data processing agreement The Spanish DPA has imposed a fine of EUR 80,000 on SENDING TRANSPORTE Y COMUNICACIÓN, S.A. The fined entity is a subprocessor of the controller. It appointed another… SPAIN ·AEPD ·Art. 28 Controllers Processors Supervisory Authorities Oct 22, 2025
€2,000 Agency for Control of Outstanding Debts S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on the Agency for Control of Outstanding Debts S.R.L. The controller failed to adequatly react to a data subjects request to… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Oct 22, 2025
€5,000 S.P.E.E.H. HIDROELECTRICA SA: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Oct 20, 2025
€5,000 S.P.E.E.H. HIDROELECTRICA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on S.P.E.E.H. HIDROELECTRICA SA. A technical error in the controller's computer systems was exploited by attackers to cause a… ROMANIA ·ANSPDCP ·Art. 32 Controllers Security Personal Data Oct 20, 2025
€2,000 PRIME TRANSACTION SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on PRIME TRANSACTION SA. The controller failed to implement adequate technical and organisational measures, resulting in a data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Oct 16, 2025
€2.7M Experian Nederland B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 2,700,000 on Experian Nederland B.V. The controller, a company that determines individuals' creditworthiness and sells this information,… THE NETHERLANDS ·AP ·Art. 5, 6, 12 +2 Personal Data Controllers Processing Oct 16, 2025
€2,000 PRIME TRANSACTION SA: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Processing Oct 16, 2025
€2.7M Experian Nederland B.V.: Insufficient legal basis for the processing of data. ⇄ 2.700.000 euro boete - Nederlandse Autoriteit Persoonsgegevens (AP). THE NETHERLANDS ·AP ·Art. 5, 6, 12 +2 Personal Data Controllers Processing Oct 16, 2025
€6.9M CAPITA PENSION SOLUTIONS LIMITED: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 6,000,000 (EUR 6,880,000) on CAPITA PENSION SOLUTIONS LIMITED. CAPITA PENSION SOLUTIONS LIMITED acts as the data processor for the CAPITA Group,… UNITED KINGDOM ·ICO ·Art. 32 Processors Controllers Security Oct 15, 2025
€9.2M CAPITA PLC: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 8,000,000 (EUR 9,180,000) on CAPITA PLC. CAPITA PLC acts as the data controller for the CAPITA Group, which has suffered a cyber attack. The… UNITED KINGDOM ·ICO ·Art. 5, 32 Controllers Security Processing Oct 15, 2025
€6.9M CAPITA PENSION SOLUTIONS LIMITED: Inadequate technical and organisational measures to ensure information security. ⇄ Een boete van 6.880.000 euro - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 32 Security Controllers Processors Oct 15, 2025
€9.2M CAPITA PLC: Insufficient technical and organizational measures to ensure information security. ⇄ 9.180.000 euro boete - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers Accountability Oct 15, 2025
€5,000 Vellea Home SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Vellea Home SRL. The controller failed to implement adequate technical and organisational measures, resulting in a data breach. ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Oct 13, 2025
€5,000 Vellea Home SRL: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Oct 13, 2025