Skip to content
Content type · 1,941 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

551–600 of 1,941 sort newestlargest fineoldest
€6,600 Eigenaar van een apotheek: Overtreding van de algemene principes van gegevensverwerking. Een boete van 6.600 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6, 14, 32 Health Data Processing Data Controller NL May 8, 2025
€7,000 Company: Non-compliance with general data processing principles The DPA of Luxembourg has issued a fine of EUR 7,000 on a company. The controller failed to maintain complete records of its processing activities. LUXEMBOURG ·CNPD ·Art. 30 Controllers Processing IP Address Apr 30, 2025
€30,000 Orde van psychologen van Lombardije: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 30.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 32 Security Education Data Breaches NL Apr 29, 2025
€40,000 Municipality of Bologna: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 40,000 on the Municipality of Bologna. The controller used a data processor (Cooperativa Sociale Quadrifoglio | ETid: 2274) to process… ITALY ·Garante ·Art. 5, 6, 9 Controllers Processors Security Apr 29, 2025
€1,200 Gemeente San Francesco al Campo: Niet-naleving van algemene principes voor gegevensverwerking. 1.200 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5 Data Controller Processing Education NL Apr 29, 2025
€20,000 Cooperativa Sociale Quadrifoglio: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio. The entity that was fined, acting as a data processor, forwarded files containing the… ITALY ·Garante ·Art. 28, 32 Processors Security Controllers Apr 29, 2025
€50,000 Regio Lombardije: Onvoldoende juridische basis voor gegevensverwerking. Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 25 +3 Processing Controllers Data Controller NL Apr 29, 2025
€100,000 Energia Verde S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Energia Verde S.p.A. The controller had been active in direct marketing activities. The controller processed data without a… ITALY ·Garante ·Art. 5, 6, 7 +13 IP Address Processing Agreement Controllers Apr 29, 2025
€40,000 Gemeente Bologna: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 40.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 Security Processors Health Data NL Apr 29, 2025
€30,000 Ordine degli psicologi della Lombardia: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 30,000 on Ordine degli psicologi della Lombardia. The controller suffered a data breach due to insufficient technical and organisational… ITALY ·Garante ·Art. 5, 32 Data Breaches Security Controllers Apr 29, 2025
€2,000 Tirrenia Hospital S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 2,000 on Tirrenia Hospital S.r.l. The controller failed to respond to a data access request from a data subject. ITALY ·Garante ·Art. 12, 15 Right of Access Procedures Personal Data Healthcare Apr 29, 2025
€2,000 Versilmagra Immobiliare, gevestigd bij Robertelli Davide & C. S.a.s.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +7 Processing Data Controller Controllers NL Apr 29, 2025
€2,000 Ziekenhuis Tirrenia S.r.l.: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 12, 15 Healthcare Personal Data Health Data NL Apr 29, 2025
€40,000 MA Immobiliare S.r.l.s.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 40.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +6 Data Controller Processing Personal Data NL Apr 29, 2025
€100,000 Energia Verde S.p.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 100.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +13 Data Controller Security Processing NL Apr 29, 2025
€20,000 Cooperativa Sociale Quadrifoglio: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 20.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 28, 32 Health Data Security Processors NL Apr 29, 2025
€50,000 Regione Lombardia: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 50,000 on the Regione Lombardia. The controller tracked its employees' browser activities, including private ones, without a sufficient legal… ITALY ·Garante ·Art. 5, 6, 25 +3 Employees Controllers Processing Apr 29, 2025
€2,000 Versilmagra Immobiliare di Robertelli Davide & C. S.a.s.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2,000 on Versilmagra Immobiliare di Robertelli Davide & C. S.a.s. The controller obtained personal data of potential customers by… ITALY ·Garante ·Art. 5, 6, 7 +7 IP Address Controllers Marketing Apr 29, 2025
€40,000 MA Immobiliare S.r.l.s.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on MA Immobiliare S.r.l.s. The controller obtained personal data of potential customers by Realmaps S.r.l., which obtained the… ITALY ·Garante ·Art. 5, 6, 7 +6 Direct Marketing IP Address Marketing Apr 29, 2025
€1,200 Municipality of San Francesco al Campo: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1,200 on the Municipality of San Francesco al Campo. The controller published the personal data of employees on its website, thereby… ITALY ·Garante ·Art. 5 Retention Period Personal Data IP Address Apr 29, 2025
€1,000 Xiting ROM SRL: Onvoldoende naleving van de rechten van betrokkenen. Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Right of Access Personal Data Data Controller NL Apr 28, 2025
€1,000 Xiting ROM SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Xiting ROM SRL. The controller failed to respond adequately to a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Apr 28, 2025
€6,000 SC Travel Planner SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 6.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15, 32 +1 Data Breaches Security Controllers NL Apr 25, 2025
€1,000 Sole Trader: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 1,000 on a sole trader. The controller published personal data on a website without a legal basis and despite being subject to a… SLOVENIA ·Art. 5 ·Insufficient legal basis for data processing Controllers Personal Data Processing Agreement Apr 25, 2025
€6,000 SC Travel Planner SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 6,000 on SC Travel Planner SRL. The controller failed to implement sufficient technical and organisational measures, resulting in a data… ROMANIA ·ANSPDCP ·Art. 12, 15, 32 +1 Data Breaches Controllers Security Apr 25, 2025
€10,000 Dante International SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 10,000 on Dante International SA. The controller failed to respond adequately to a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 17, 19 Personal Data Controllers Processing Agreement Apr 24, 2025
€6,000 Real Estate Agency: Insufficient cooperation with supervisory authority The Belgian DPA imposed a fine of EUR 6,000 on a real estate agency. The Belgian DPA had previously issued a remedy to the controller in an earlier case due to the controller… BELGIUM ·APD ·Art. 5, 6, 17 +1 Right to be Forgotten Data Subject Rights Exercise Modalities and Procedures Controllers Apr 24, 2025
€6,000 Immobiliënbureau: Onvoldoende samenwerking met de toezichthoudende instantie. 6.000 euro boete - Belgische Autoriteit voor gegevensbescherming (APD). BELGIUM ·APD ·Art. 5, 6, 17 +1 Personal Data Data Controller Right to be Forgotten NL Apr 24, 2025
€10,000 Dante International SA: Onvoldoende naleving van de rechten van betrokkenen bij de verwerking van persoonsgegevens. Een boete van €10.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 17, 19 Personal Data Processing Controllers NL Apr 24, 2025
€1,500 ULPIA TRAJANA ALAMEDA S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on ULPIA TRAJANA ALAMEDA S.L. During the booking process, the controller processed data that was unnecessary for the purpose, infringing on the… SPAIN ·aepd ·Art. 5, 9 Controllers IP Address Personal Data Apr 24, 2025
€9,200 Diskrimineringsombudsmannen: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 9,200 on the Swedish Disrimination Ombudsman. The controller was unable to implement sufficient data security measures, resulting in the… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Education Controllers Apr 23, 2025
€9,200 Discriminatiecommissarissen: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 9.200 euro boete - De Zweedse Autoriteit voor Gegevensbescherming (Integritetsskyddsmyndigheten). SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Education Controllers NL Apr 23, 2025
€1,200 SERVICIOS DE INTEGRACIÓN DE ANDALUCÍA: Onvoldoende juridische basis voor de verwerking van gegevens. 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6 Processing Data Controller Controllers NL Apr 22, 2025
€1,200 SERVICIOS DE INTEGRACIÓN DE ANDALUCÍA: Insufficient legal basis for data processing The Spanish DPA imposed a fine on SERVICIOS DE INTEGRACIÓN DE ANDALUCÍA. The controller hired an employee and processed the mobile phone number of the new employee without consent… SPAIN ·aepd ·Art. 6 Controllers Employees Processing Agreement Apr 22, 2025
€20,000 Company: Non-compliance with general data processing principles The Belgian DPA imposed a fine of EUR 20,000 on a company. The controller is a company engaging in direct marketing activities. During those activies the company failed to comply… BELGIUM ·APD ·Art. 5, 6, 12 +4 Controllers Direct Marketing IP Address Apr 22, 2025
€1,200 FUNDACIÓ PRIVADA DE SERVEIS PER ALS USUARIS DEL HABITATGE SOCIAL DE CATALUNYA: Insufficient legal basis for data processing The Spanish DPA imposed a fine on FUNDACIÓ PRIVADA DE SERVEIS PER ALS USUARIS DEL HABITATGE SOCIAL DE CATALUNYA. The controller processed personal data without a sufficient legal… SPAIN ·aepd ·Art. 6 Personal Data Controllers Processing Apr 22, 2025
€12,000 NOVATES ALIMENTACIÓN MADRID, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine on NOVATES ALIMENTACIÓN MADRID, S.L. The controller used surveillance cameras without implementing the necessary technical and organizational… SPAIN ·aepd ·Art. 32 Security Video Surveillance Controllers Apr 22, 2025
€2,000 United Business Solutions SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on United Business Solutions SRL. The controller failed to implement sufficient technical and organisational measuresto ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Apr 15, 2025
€260,000 CAMERDATA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 260,000 on CAMERDATA, S.A. The controller operates a database in which it collects data on individual entrepreneurs from the Spanish… SPAIN ·aepd ·Art. 6, 14 Controllers Personal Data Processing Agreement Apr 15, 2025
€7,800 Funeral Home: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined a funeral home EUR 7,800. The funeral home failed to implement sufficient technical and organisational measures to prevent a data breach. The funeral home… POLAND ·UODO ·Art. 5 Data Breaches Security Healthcare Apr 15, 2025
€7,800 Uitvaartonderneming: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €7.800 - van het Poolse Nationaal Bureau voor de Bescherming van Persoonlijke Gegevens (UODO). POLAND ·UODO ·Art. 5 Health Data Security Data Breaches NL Apr 15, 2025
€600 SPAIN, DPA: Niet-naleving van de algemene principes voor gegevensverwerking. 600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). aepd ·Art. 5 ·Non-compliance with general data processing principles Processing Data Controller Controllers NL Apr 15, 2025
€500,000 Chamber of Commerce, Industry, Services and Navigation of Spain: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500,000 on the Chamber of Commerce, Industry, Services and Navigation of Spain. Due to its function within the Spanish Executive, the… aepd ·Art. 5, 6, 14 ·Insufficient legal basis for data processing Controllers Fairness & Transparency Processors Apr 15, 2025
€500,000 Handelskamer, Industrie, Dienstverlening en Transport van Spanje: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 500.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 6, 14 Processors Processing Data Processor NL Apr 15, 2025
€600 SPAIN DPA: Non-compliance with general data processing principles The Spanish DPA imposed a fine on an unknown data controller. The controller stored full copies of personal IDs for verification purposes. In this case, storing all the… aepd ·Art. 5 ·Non-compliance with general data processing principles Controllers IP Address Processing Apr 15, 2025
€2,000 United Business Solutions SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Apr 15, 2025
€6,000 LÄSER METALPRINT 3D, S.L.: Onvoldoende gegevensverwerkings overeenkomst. Boete van 6.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 28 Controllers Processors Processing NL Apr 14, 2025