Skip to content
Content type · 3,446 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

551–600 of 3,446 sort newestlargest fineoldest
€3,000 Gemeente Conversano: Gebrek aan benoeming van een functionaris voor gegevensbescherming. Een boete van 3.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 37 Education Supervisory Authorities Public Authority NL Jul 10, 2025
€100,000 Banco Bilbao Vizcaya Argentaria SA: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Banco Bilbao Vizcaya Argentaria SA €100,000 on 2025-07-10 for: Insufficient fulfilment of data subjects rights. Italy ·Garante ·Art. 12, 15 Personal Data Insurance Supervisory Authorities Jul 10, 2025
€3,000 Comune di Conversano: Lack of appointment of data protection officer The Italian DPA has imposed a fine of EUR 3,000 on the Comune di Conversano. The controller failed to correctly appoint a DPA. ITALY ·Garante ·Art. 37 Supervisory Authorities Controllers Public Authority Jul 10, 2025
€4,000 Istituto Comprensivo 2 C.D. “G. Modugno” S.M. “G. Galilei” di Monopoli: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 4,000 on Istituto Comprensivo 2 C.D. “G. Modugno” S.M. “G. Galilei” di Monopoli. The controller published a list with the name of pupils… ITALY ·Garante ·Art. 5, 6, 9 Education Controllers Processing Agreement Jul 10, 2025
€8,000 Università degli Studi di Cassino e del Lazio Meridionale: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 8.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +2 Right to be Forgotten Data Controller Processing NL Jul 10, 2025
€8,000 Università degli Studi di Cassino e del Lazio Meridionale: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 8,000 on Università degli Studi di Cassino e del Lazio Meridionale. The controller failed to delete a former employee's email address… ITALY ·Garante ·Art. 5, 6, 12 +2 Controllers IP Address Processing Agreement Jul 10, 2025
€80,000 Poste Vita S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine on Poste Vita S.p.a. The controller failed to implement adequate technical and organisational measures to ensure data security. This resulted in… ITALY ·Garante ·Art. 5, 33 Security Personal Data Insurance Jul 10, 2025
€6,000 CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Overtreding van de algemene principes voor gegevensverwerking. Boete van 6.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Data Controller Controllers Processing NL Jul 4, 2025
€3,000 Zougla TZI-AP Anonymous Mass Media Company: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 3,000 on Zougla TZI-AP Anonymous Media Company. The controller, who operates a news website, published an article revealing the personal… GREECE ·HDPA ·Art. 5, 31 Personal Data Controllers Processing Jul 4, 2025
€6,000 CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 6,000 on CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U. The controller processed personal data in order to conclude a contract. But the… SPAIN ·aepd ·Art. 5 Controllers IP Address Processing Agreement Jul 4, 2025
€3,000 Zougla TZI-AP, een anoniem massamediaconcern: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Boete van €3.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 31 Personal Data Processing Data Controller NL Jul 4, 2025
€175,000 FAVORIT SPORTSKA KLADIONICA d.o.o.: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined FAVORIT SPORTSKA KLADIONICA d.o.o. €175,000 on 2025-07-02 for: Insufficient technical and organisational measures to ensure… Croatia ·azop ·Art. 5 Security Human Resources Supervisory Authorities Jul 2, 2025
€900 ARCONADA 1932, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA imposed a fine of EUR 900 on ARCONADA 1932, S.L. The controller did not react adequatly to communication from the DPA. The original fine of EUR 1,500 was reduced… SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Controllers Jul 2, 2025
€900 ARCONADA 1932, S.L.: Onvoldoende samenwerking met de toezichthoudende instantie. 900 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 58 Controllers Supervisory Authorities Data Controller NL Jul 2, 2025
€101,000 Croatian Insurance Bureau: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined Croatian Insurance Bureau €101,000 on 2025-07-02 for: Insufficient technical and organisational measures to ensure information… Croatia ·azop ·Art. 5, 32 Security Public Sector Human Resources Jul 2, 2025
€15,600 L. Zamenhof University Children's Clinical Hospital in Białystok: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 15,600 on the L. Zamenhof University Children's Clinical Hospital in Białystok. The controller did not implement sufficient technical and… POLAND ·UODO ·Art. 5, 32 Healthcare Security Healthcare Jun 30, 2025
€3,000 Selgros Cash & Carry SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Selgros Cash & Carry SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Jun 26, 2025
€3,000 SC Tremend Software Consulting SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on SC Tremend Software Consulting SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Jun 26, 2025
€3,000 SC Piramida Trade Invest SRL: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +4 Security Personal Data Data Controller NL Jun 26, 2025
€3,000 SC Piramida Trade Invest SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 3,000 on SC Piramida Trade Invest SRL. The controller processed personal data without a sufficient legal basis and without sufficient… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +4 Personal Data Controllers Data Subject Rights Exercise Modalities and Procedures Jun 26, 2025
€3,000 SC Tremend Software Consulting SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Jun 26, 2025
€3,000 Selgros Cash & Carry SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Jun 26, 2025
€25,000 Alliance for the Union of Romanians Party: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 25,000 on the Alliance for the Union of Romanians Party. The controller did not implement adeqaute technical and organisational measures… ROMANIA ·ANSPDCP ·Art. 5, 6, 25 +1 Data Breaches Security Controllers Jun 26, 2025
€25,000 Partij "Alliantie voor de Unie van Roemenië": Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 25 +1 Security Education Personal Data NL Jun 26, 2025
€96,000 SIDECU, S.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 96.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 9, 13, 35 Controllers Data Controller Processing NL Jun 26, 2025
€96,000 SIDECU, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 96,000 on SIDECU, S.A. The controller introduced facial recognistion system as the only access method to their facilities, without offering… SPAIN ·aepd ·Art. 9, 13, 35 DPIA Privacy Impact Assessment IP Address Jun 26, 2025
€40,000 KARAMBELAS KONSTANTINOS & CO. E.E.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 40,000 on KARAMBELAS KONSTANTINOS & CO. E.E. The processor, which was processing data for a telecommunications provider (ETid: 2878),… GREECE ·HDPA ·Art. 29, 32 Security Telecommunications Processors Jun 25, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 550.000 euro - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 28 Security Telecommunications Data Processor NL Jun 25, 2025
€40,000 KARAMBELAS KONSTANTINOS & CO. E.E.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van 40.000 euro - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 29, 32 Security Telecommunications Personal Data NL Jun 25, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 550,000 on Vodafone – PANAFON A.E.E.T. The controller failed to implement sufficient technical and organisational measures to ensure data… GREECE ·HDPA ·Art. 5, 28 Telecommunications Security Controllers Jun 25, 2025
€20,725 Birthlink: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 18,000 (EUR 20,725) on Birthlink. The controller, a scottish registered charity, failed to implement sufficient technical and organisational… UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Security Controllers Processing Agreement Jun 24, 2025
€7,000 Algemeen Ziekenhuis van de Universiteit van Larissa: Onvoldoende naleving van de rechten van betrokkenen. Een boete van €7.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 14, 15 Health Data Healthcare Personal Data NL Jun 24, 2025
€10,000 Shield of David - K.I.D.A.F.: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Shield of David - K.I.D.A.F. The controller, a day care centre for people with autism, has legally installed video… GREECE ·HDPA ·Art. 5, 12, 13 +3 Video Surveillance Controllers Monitoring Jun 24, 2025
€20,725 Birthlink: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van €20.725 - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Security Notification Obligation Accountability NL Jun 24, 2025
€10,000 Shield of David - K.I.D.A.F.: Niet-naleving van algemene principes voor gegevensverwerking. Boete van €10.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 12, 13 +3 Personal Data Health Data Video Surveillance NL Jun 24, 2025
€7,000 General Hospital of the University of Larissa: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 7,000 on the General Hospital of the University of Larissa. The controller failed to adequately fulfil the rights of data subjects. It… GREECE ·HDPA ·Art. 5, 14, 15 Healthcare Healthcare Personal Data Jun 24, 2025
€50,000 Piraeus Bank S.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 50.000 euro - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 6 Personal Data Processing Data Controller NL Jun 23, 2025
€4,000 Vodafone Romania S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 4.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Security Data Breaches Telecommunications NL Jun 23, 2025
€3,500 Municipal Social Welfare Center Aleksandrów: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 3,500 on the Municipal Social Welfare Center in Aleksandrów. The controller did not implement sufficient technical and organisational… POLAND ·UODO ·Art. 32 Data Breaches Security IP Address Jun 23, 2025
€50,000 Piraeus Bank S.A.: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 50,000 on Piraeus Bank S.A.The controller has processed personal data even though the data subject rightfully opposed the the data… GREECE ·HDPA ·Art. 5, 6 Personal Data Controllers Processing Agreement Jun 23, 2025
€125,000 City of Dublin Education and Training Board: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 125,000 on the City of Dublin Education and Training Board. The controller suffered a data breach due to insufficient technical and… IRELAND ·Art. 5, 32, 33 +1 ·Insufficient technical and organisational measures to ensure information security Data Breaches Education Security Jun 23, 2025
€125,000 Onderwijs- en opleidingsraad van de stad Dublin: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 125.000 euro boete - Ierse Autoriteit voor Gegevensbescherming. IRELAND ·Art. 5, 32, 33 +1 ·Insufficient technical and organisational measures to ensure information security Data Breaches Education Security NL Jun 23, 2025
€4,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 4,000 on Vodafone Romania S.A. The controller failed to implement sufficient technical and organisational measures to ensure data… ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Telecommunications Jun 23, 2025
€42,000 IBERCAJA BANCO, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 42,000 on IBERCAJA BANCO, S.A. During a bank transfer, the controller transmitted more data then necessary to the recipient of the payment.… SPAIN ·aepd ·Art. 5 Recipient IP Address Controllers Jun 20, 2025
€42,000 IBERCAJA BANCO, S.A.: Overtreding van de algemene principes voor gegevensverwerking. Een boete van 42.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Recipient Processing Data Controller NL Jun 20, 2025
€24,000 COLEGIO VIRGEN DE EUROPA, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 24,000 on COLEGIO VIRGEN DE EUROPA, S.L. An employee of the controller, a school, took pictures of minor pupils without a sufficient legal… SPAIN ·aepd ·Art. 5, 6, 13 Education Controllers Personal Data Jun 20, 2025
€24,000 COLEGIO VIRGEN DE EUROPA, S.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 24.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 6, 13 Education Processing Personal Data NL Jun 20, 2025
€1,000 SC Diamir SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 1,000 on SC Diamir SRL. The controller failed to properly cooperate with the supervisory authority and also disclosed personal data to… ROMANIA ·ANSPDCP ·Art. 6, 58 Controllers IP Address Processing Agreement Jun 19, 2025
€1,000 SC Diamir SRL: Overtreding van de algemene principes voor gegevensverwerking. Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 58 Processing Controllers Personal Data NL Jun 19, 2025
€6,800 AB Storstockholms Lokaltrafik: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 6,800 on AB Storstockholms Lokaltrafik. The controller, a public transportation company, requires employees operating a ferry to take a… SWEDEN ·Art. 6, 9 ·Insufficient legal basis for data processing Controllers Processing Agreement Processing Jun 18, 2025