Skip to content
Content type · 3,651 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

551–600 of 3,651 sort newestlargest fineoldest
€5,400 YUNEXPRESS SPAIN, S.L.: Insufficient data processing agreement The Spanish DPA has imposed a fine of EUR 5,400 on YUNEXPRESS SPAIN, S.L. The controller used a data processor and failed to sign a sufficient data processing agreement. The… aepd ·Art. 5, 28 ·Insufficient data processing agreement Controllers Processors Processing Agreement Aug 25, 2025
€1,800 LEIVA BUS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,800 on LEIVA BUS, S.L. The controller leaked personal data due to insufficient technical and organisational measures to ensure data… SPAIN ·aepd ·Art. 5 Security Controllers Processing Agreement Aug 25, 2025
€18,000 GRUPO BONATEL SL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 18,000 on the GRUPO BONATEL SL. The controller suffered a data leak due to insufficient technical and organisational measures to ensure… SPAIN ·aepd ·Art. 5 Security Telecommunications Controllers Aug 22, 2025
€18,000 GRUPO BONATEL SL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €18.000 - van de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Security Data Breaches Telecommunications NL Aug 22, 2025
€6,000 BANCO INVERSIS, S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van 6.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Security Data Breaches Controllers NL Aug 22, 2025
€6,000 BANCO INVERSIS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 6,000 on BANCO INVERSIS, S.A. The controller suffered a data leak due to insufficient technical and organisational measures to ensure… SPAIN ·aepd ·Art. 5 Security Controllers Insurance Aug 22, 2025
€3,000 SC Elite Conta SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Aug 18, 2025
€3,000 SC Elite Conta SRL: Insufficient technical and organisational measures to ensure information security The Romainian DPA has imposed a fine of EUR 3,000 on SC Elite Conta SRL. The controller failed to implement adequate technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Security Processing Agreement Controllers Aug 18, 2025
€42,000 WORLD 2 MEET, S.L.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 42.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Processing IP Address Accountability NL Aug 14, 2025
€42,000 WORLD 2 MEET, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 42,000 on WORLD 2 MEET, S.L. The controller requires its guests to provide a copy of their identity card or passport for registration… SPAIN ·aepd ·Art. 5 Controllers IP Address Processing Agreement Aug 14, 2025
€500 Sole Trader: Insufficient cooperation with supervisory authority The Slovenian DPA has imposed a fine of EUR 500 on a sole trader. The controller failed to react to a request by the DPA within the set 10-day period. SLOVENIA ·Art. 31 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Aug 13, 2025
€3,000 'FLEXICREDIT' Mutual Aid House Association: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on 'FLEXICREDIT' Mutual Aid House Association. The controller failed to implement adequate technical and organisational measures… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Insurance Aug 12, 2025
€4,800 GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 4,800 on GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U. The controller failed to process customer data accurately,… SPAIN ·aepd ·Art. 5 Insurance Personal Data Controllers Aug 12, 2025
€1,600 REAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESA: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. 1.600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Personal Data Processing Data Controller NL Aug 12, 2025
€4,800 GACM SEGUROS GENERALES, een verzekerings- en herverzekeringsmaatschappij S.A.U.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 4.800 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Insurance Processing Data Controller NL Aug 12, 2025
€3,000 'FLEXICREDIT' Vereniging voor wederzijdse hulp: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing NL Aug 12, 2025
€1,600 REAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,600 on the REAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESA. The controller pubilshed personal data on its website without a sufficient legal… SPAIN ·aepd ·Art. 5 Personal Data Controllers Processing Agreement Aug 12, 2025
€66,000 REAL SOCIEDAD DE FUTBOL S.A.D.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 66,000 on REAL SOCIEDAD DE FUTBOL S.A.D. The controller suffered a ransomwareattack due to insufficient technical and organisational… SPAIN ·aepd ·Art. 5, 32 Security Controllers Processing Agreement Aug 12, 2025
€66,000 REAL SOCIEDAD DE FUTBOL S.A.D.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 66.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 32 Security Controllers Data Controller NL Aug 12, 2025
€80,000 BIZUM, S.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 80.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 32 Security Data Breaches Controllers NL Aug 11, 2025
€80,000 BIZUM, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 80,000 on BIZUM, S.L. The controller failed to implement sufficient technical and organisational measures to ensure data security,… SPAIN ·aepd ·Art. 32 Data Breaches Security Controllers Aug 11, 2025
€6,200 Mediabedrijf: Onvoldoende samenwerking met de toezichthoudende instantie. Boete van 6.200 euro - Oostenrijkse Autoriteit voor Gegevensbescherming (dsb). AUSTRIA ·dsb ·Art. 58 Telecommunications Supervisory Authorities Supervision NL Aug 6, 2025
€6,200 Media Company: Insufficient cooperation with supervisory authority The Austrian DPA has imposed a fine of EUR 6,200 on a media company. The controller failed to comply with an order from the DPA to implement an adequate cookie banner. AUSTRIA ·dsb ·Art. 58 Supervisory Authorities Supervision Cookies Aug 6, 2025
€1,000 Order of Biochemists, Biologists and Chemists in the Romanian Health System: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on the Order of Biochemists, Biologists and Chemists in the Romanian Health System. The controller failed to adequatly respond to… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Healthcare Controllers Aug 5, 2025
€25,000 Bank of Cyprus Public Company Limited: Insufficient technical and organisational measures to ensure information security Cypriot Data Protection Commissioner fined Bank of Cyprus Public Company Limited €25,000 on 2025-08-05 for: Insufficient technical and organisational measures to ensure… Art. 5, 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Insurance Aug 5, 2025
€1,000 Orde van biochemici, biologen en chemici in het Roemeense gezondheidszorgsysteem: Onvoldoende naleving van de rechten van betrokkenen. 1.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Health Data Healthcare Right of Access Procedures NL Aug 5, 2025
€10,000 Gemeente Venetië: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 25 +1 Processing Education Data Controller NL Aug 4, 2025
€80,000 Ospedaliero-Universitaria Careggi: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9, 25 +1 Health Data Healthcare Security NL Aug 4, 2025
€7,700 Non-Public Health Care Institution: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 7,700 on a non-public health care institution. The controller offered home visits by doctors as part of its services. For this purpose,… POLAND ·UODO ·Art. 5, 25, 32 Healthcare Security Controllers Aug 4, 2025
€230 Politieagent: Er is onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 230 euro - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Insufficient legal basis for data processing Processing Education Supervisory Authorities NL Aug 4, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2,000 on Linea Stampalibera Società Cooperativa r.I. The controller, who operates a news site, has disclosed too much personal… ITALY ·Garante ·Art. 5 Retention Period Healthcare Health Data Aug 4, 2025
€230 Police Officer: Insufficient legal basis for data processing The UK DPA has imposed a fine of £ 200 (EUR 230) on a police officer. The controller forwarded sensitive and restricted personal data that he had obtained in the course of his… UNITED KINGDOM ·ICO ·Insufficient legal basis for data processing Personal Data Controllers Education Aug 4, 2025
€7,700 Geen zorginstelling: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €7.700 - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 32 Security Healthcare Data Controller NL Aug 4, 2025
€80,000 Ospedaliero-Universitaria Careggi: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 80,000 on the Ospedaliero-Universitaria Careggi. The controller, a university hospital, used software that allowed medical personnel to… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Healthcare Personal Data Aug 4, 2025
€10,000 Comune di Venezia: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on the Comune di Venezia. The controller implemented a tourist tax, which includes exceptions for certain groups of visitors. When… ITALY ·Garante ·Art. 5, 6, 25 +1 IP Address Controllers Education Aug 4, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor gegevensbescherming (Garante). ITALY ·Garante ·Art. 5 Health Data Healthcare Data Controller NL Aug 4, 2025
€11,614 Legal Entity: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 11,614 on a legal entity. The controller did not delete the email address of a former employee, but rather continued to receive and… SLOVENIA ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Processing Agreement Processing Jul 29, 2025
€4,400 Ondernemer: Onvoldoende samenwerking met de toezichthoudende instantie. 4.400 euro boete - Pools Nationaal Bureau voor de Bescherming van Persoonsgegevens (UODO). POLAND ·UODO ·Art. 58 Supervisory Authorities Controllers Data Controller NL Jul 28, 2025
€4,400 Entrepreneur: Insufficient cooperation with supervisory authority The Polish DPA has imposed a fine of EUR 4,400 on an Entrepreneur. The controller failed to adequatly react to a request from the DPA. POLAND ·UODO ·Art. 58 Supervisory Authorities Supervision Controllers Jul 28, 2025
€5,020 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 5,020 on a legal entity. The controller had developed an application that allowed the exchange of personal data, but failed to… SLOVENIA ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Jul 25, 2025
€5,810 Legal Entity: Insufficient data processing agreement The Slovenian DPA has imposed a fine of EUR 5,810 on a legal entity. The controller employed a person authorised to perform clerical work. However, this person used a data… SLOVENIA ·Art. 28 ·Insufficient data processing agreement Controllers Processors Processing Agreement Jul 25, 2025
€26,400 Debt Collector: Insufficient fulfilment of data subjects rights The Hungarian DPA has imposed a fine of EUR 26,400 on a debt collector. The controller processed the personal data of a natural person, specifically data relating to a consumer… HUNGARY ·NAIH ·Art. 6, 17 Personal Data Controllers Insurance Jul 24, 2025
€5,000 Agricola International SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Agricola International SA. The controller failed to implement sufficient technical and organisational measures, resulting in a… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Law Enforcement Jul 23, 2025
€5,000 Agricola International SA: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing NL Jul 23, 2025
€10,000 Orde van de verpleegkundigen van Viterbo: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 32 Security Data Breaches Education NL Jul 23, 2025
€10,000 Order of Nursing Professions of Viterbo: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on the Order of Nursing Professions of Viterbo. The controller suffered a data leak due to insufficient technical and… ITALY ·Garante ·Art. 5, 32 Security Education Controllers Jul 23, 2025
€10,000 SATI S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on SATI S.p.A. Information about the reasons for employees' absences was displayed on boards and in emails, which were accessible… ITALY ·Garante ·Art. 5, 9 Controllers Employees IP Address Jul 23, 2025
€10,000 SATI S.p.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9 Processing Data Controller Controllers NL Jul 23, 2025
€320,000 HEP-Toplinarstvo: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined HEP-Toplinarstvo €320,000 on 2025-07-22 for: Insufficient technical and organisational measures to ensure information security. Croatia ·azop ·Art. 31, 32 Security Human Resources Supervisory Authorities Jul 22, 2025
€50,000 Information and Communication Company: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined Information and Communication Company €50,000 on 2025-07-22 for: Insufficient technical and organisational measures to ensure… Croatia ·azop ·Art. 32 Security Human Resources Supervisory Authorities Jul 22, 2025