Skip to content
Content type · 2,802 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

551–600 of 2,802 sort newestlargest fineoldest
€5,000 Banca Transilvania S.A.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 5,000 on Banca Transilvania S.A. The controller forwarded client data to an insurance company without a sufficient legal basis. ROMANIA ·ANSPDCP ·Art. 5, 6 Insurance Controllers Processing Agreement Apr 3, 2025
€5,000 Banca Transilvania S.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6 Data Controller Processing Personal Data NL Apr 3, 2025
€600 Owner of a Law Firm: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine on the owner of a law firm. The controller disclosed personal information in an external email because they did not implement sufficient technical… SPAIN ·aepd ·Art. 5 Security Controllers Insurance Apr 3, 2025
€3,000 BINBOX GLOBAL SERVICES S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Telecommunications NL Apr 2, 2025
€3,000 BINBOX GLOBAL SERVICES S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on BINBOX GLOBAL SERVICES S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure data… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Telecommunications Apr 2, 2025
€3,500 MAD COOL FESTIVAL S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 3,500 on MAD COOL FESTIVAL S.L. The controller suffered a data breach due to insufficient technical and organizational measures.… SPAIN ·aepd ·Art. 5, 32 Data Breaches Security Processing Agreement Mar 30, 2025
€6,600 GRUAS IGNACI, S.L.: Overtreding van de algemene principes voor gegevensverwerking. Boete van 6.600 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 13, 32 Security Video Surveillance Controllers NL Mar 28, 2025
€4,000 CREMA GAMES, S.L.: Insufficient fulfilment of information obligations The Spanish DPA imposed a fine on CREMA GAMES, S.L. The controller failed to fulfill an information request from an online customer. The controller asked the data subject for an… SPAIN ·aepd ·Art. 15 Controllers Telecommunications Personal Data Mar 28, 2025
€12,000 ESTUDIO ALCAZAR DEL GENIL 2022, S.L.: Onvoldoende juridische basis voor de verwerking van gegevens. 12.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6, 14 Data Controller Processing Personal Data NL Mar 28, 2025
€4,000 CREMA GAMES, S.L.: Onvoldoende nakoming van de informatieverplichtingen. Een boete van 4.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 15 Controllers Personal Data Data Controller NL Mar 28, 2025
€6,600 GRUAS IGNACI, S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on GRUAS IGNACI, S.L. The controller uses too much data to verify a person's identity, which breaches the principle of data minimization.… SPAIN ·aepd ·Art. 5, 13, 32 Video Surveillance Controllers IP Address Mar 28, 2025
€12,000 ESTUDIO ALCAZAR DEL GENIL 2022, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine on ESTUDIO ALCAZAR DEL GENIL 2022, S.L. The controller collected property data by having its employees visit and photograph the properties,… SPAIN ·aepd ·Art. 6, 14 Controllers Personal Data Processing Agreement Mar 28, 2025
€21,600 SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 21.600 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 7, 28 Education Processing Data Controller NL Mar 28, 2025
€21,600 SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed fine on SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L. The controller offers fitness courses which are recorded and published. The consent obtained for the… SPAIN ·aepd ·Art. 5, 7, 28 Storage Limitation Retention Period Controllers Mar 28, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on SERVICIOS ESPECIALES, S.A. The case concerned a GDPR breach during an internal workplace conflict investigation: the company shared a report via… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy IP Address Mar 28, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 120.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Professional Secrecy Integrity and Confidentiality Principle Processing NL Mar 28, 2025
€3,000 Municipality of Palma di Montechiaro: Lack of appointment of data protection officer The Italian DPA has imposed a fine of EUR 3,000 on the Municipality of Palma di Montechiaro. The controller failed to appoint a DPO and report the DPO to the DPA. ITALY ·Garante ·Art. 37 Supervisory Authorities Public Authority Public Sector Mar 27, 2025
€18,000 Multiple Companies: Insufficient legal basis for data processing The Italian DPA imposed fines on 3 companies which ammount to EUR 6,000 each. The fined companies (Powerfit s.s.d.a.r.l., Soleo s.s.d.a.r.l. and Zero Due Villa s.s.d.a.r.l.) run a… ITALY ·Garante ·Art. 5, 6, 12 +1 Right to be Forgotten Direct Marketing Fines Mar 27, 2025
€3,000 Gemeente Palma di Montechiaro: Gebrek aan benoeming van een functionaris voor gegevensbescherming. Een boete van 3.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 37 Public Authority Supervisory Authorities Education NL Mar 27, 2025
€4,000 Istituto di Istruzione Superiore 'P. Galluppi' Tropea: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 4.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 Special Categories of Data Processing Types of Special Categories of Personal Data NL Mar 27, 2025
€4,000 Istituto di Istruzione Superiore 'P. Galluppi' Tropea: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,500 on the Istituto di Istruzione Superiore 'P. Galluppi' Tropea. The controller processed biometric data of its employees to control… ITALY ·Garante ·Art. 5, 6, 9 Employees Fairness & Transparency Special Categories of Data Mar 27, 2025
€18,000 Meerdere bedrijven: Onvoldoende juridische basis voor gegevensverwerking. Een boete van €18.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +1 Processing Right to be Forgotten Consent NL Mar 27, 2025
€3.5M Advanced Computer Software Group Ltd: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined Advanced Computer Software Group Ltd £3.07 million (EUR 3.5 million) for insufficient IT security (infringiment of Art. 32 (1) UK GDPR). The controller… UNITED KINGDOM ·ICO ·Art. 32 Security Access Controls Healthcare Mar 26, 2025
€25,000 NTT DATA ROMANIA S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Personal Data NL Mar 25, 2025
€25,000 NTT DATA ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on NTT DATA ROMANIA S.A. The controller failed to implement sufficient technical and organisational measures, resulting in a data… ANSPDCP ·Art. 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processing Agreement Mar 25, 2025
€20,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) imposed a fine of EUR 20,000 on a hospital for failing to implement adequate technical and organizational measures to protect personal data in line with… CROATIA ·azop ·Art. 32 Data Breaches Security Healthcare Mar 24, 2025
€10,000 Oil and fat manufacturer: Lack of appointment of data protection officer The Croatian DPA (AZOP) has imposed a fine of EUR 10,000 on an oil and fat manufacturer for for failing to appoint and designate a data protection officer. CROATIA ·azop ·Art. 37 Supervisory Authorities Processing Agreement Mar 24, 2025
€2,000 INDEPENDENTS DE VALLROMANES: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,000 on INDEPENDENTS DE VALLROMANES. The controller, a political party, posted a court decision on its social media, which included… SPAIN ·aepd ·Art. 5 Social Media IP Address Personal Data Mar 24, 2025
€4,000 Ziekenhuis: Niet-naleving van de algemene principes voor gegevensverwerking. 4.000 euro boete - Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·azop ·Art. 13, 14, 25 +1 Health Data Healthcare Personal Data NL Mar 24, 2025
€40,000 Company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 40,000 on a company that published personal data of sole traders on its website. The data originated from public sources and from… CROATIA ·azop ·Art. 5, 6, 12 +3 Notified Body Responsibilities and Operational Obligations Personal Data Processing Agreement Mar 24, 2025
€17,600 Chief Commander of the Police: Insufficient legal basis for data processing The Polish DPA has fined the Chief Commander of the Polish Police EUR 17,600. During a press conference, the Chief Commander of the Police disclosed the personal and medical data… POLAND ·UODO ·Art. 6, 9 Healthcare Health Data Healthcare Mar 24, 2025
€3,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croation DPA (AZOP) has imposed a fine of EUR 3,000 on a hospital. Despite the extensive and high-risk processing of health data, the hospital had not implemented sufficient… CROATIA ·azop ·Art. 13, 32, 33 +1 Healthcare Health Data Integrity and Confidentiality Principle Mar 24, 2025
€80,000 Company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 80,000 on a company. The company was responsible for monitoring parking lots at several supermarkets and a hospital. However, it… CROATIA ·azop ·Art. 5, 6, 32 Audit Logs Processing Agreement Monitoring Mar 24, 2025
€4,000 Hospital: Non-compliance with general data processing principles The Croation DPA (AZOP) has imposed a fine of EUR 4,000 on a hospital. The AZOP found that the hospital used a company which automatically retrieved personal data of vehicle… CROATIA ·azop ·Art. 13, 14, 25 +1 Fines Healthcare Healthcare Mar 24, 2025
€12,000 Casino: Lack of appointment of data protection officer The Croatian DPA (AZOP) has imposed a fine of EUR 12,000 on a casino for for failing to appoint and designate a data protection officer. CROATIA ·azop ·Art. 37 Supervisory Authorities Processing Agreement Mar 24, 2025
€1,000 Bucharest Down Town Hotel SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Bucharest Down Town Hotel SRL. The controller failed to provide a data subject with requested data. ROMANIA ·ANSPDCP ·Art. 12, 13, 15 Personal Data Controllers Processing Agreement Mar 21, 2025
€500 GALENICUM HEALTH, S.L.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 500 on GALENICUM HEALTH, S.L.U. The controller uses video surveillance that partially captures images of a public road, which infringes… SPAIN ·aepd ·Art. 5 Video Surveillance Healthcare IP Address Mar 20, 2025
€2,000 ONE UNITED PROPERTIES S.A: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on ONE UNITED PROPERTIES S.A. The controller contacted a data subject multiple times for direct marketing purposes without… ROMANIA ·ANSPDCP ·Art. 6, 12, 15 +1 Direct Marketing Personal Data Controllers Mar 20, 2025
€4,800 TECNOCRÃTICA CENTRO DE DATOS S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 4,800 on TECNOCRÃTICA CENTRO DE DATOS S.L. The controller failed to reply to an information request by the AEPD within the given… SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Controllers Mar 20, 2025
€6.3M Poczta Polska SA (Polish Post): Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 6.3 million on Poczta Polska SA (Polish Post) for the unlawful disclosure of personal data of over 30 million citizens from the PESEL… POLAND ·UODO ·Art. 6 Personal Data Processing Agreement Processing Mar 17, 2025
€23,500 Minister of Digital Affairs: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 23,500 on the Polish Minister for Digital Affairs. The Minister unlawfully processed personal data of Polish citizens in the PESEL… POLAND ·UODO ·Art. 5, 6 Personal Data Public Authority Education Mar 17, 2025
€3.2M CENTROS COMERCIALES CARREFOUR, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 3,200,000 on CENTROS COMERCIALES CARREFOUR, S.A. The controller suffered a cyberattack, resulting in the leak of a large amount of personal… SPAIN ·aepd ·Art. 5, 32, 34 Data Breaches Security Processing Agreement Mar 14, 2025
€2,000 Municipality of Roccaraso: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 2,000 on the Municipality of Roccaraso. The controller published personal data of a worker on its public notice board website without a… ITALY ·Garante ·Art. 5, 6 Personal Data Controllers IP Address Mar 13, 2025
€20,000 Encore Thermoengineering s.r.l.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 20,000 on Encore Thermoengineering s.r.l. The controller legally obtained employee data from another company that had gone bankrupt. The… ITALY ·Garante ·Art. 5, 6, 17 Controllers IP Address Employees Mar 13, 2025
€50,000 Azienda regionale per lo sviluppo e per i servizi in agricoltura (ARSAC): Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 50,000 on the Regional agency for development and services in agriculture (ARSAC). The controller processed geographic data of its employees… ITALY ·Garante ·Art. 5, 6, 13 +3 Fairness & Transparency Education Controllers Mar 13, 2025
€2,000 l’Istituto Alberghiero Mediterraneo di Pulsano: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 2,000 on l’Istituto Alberghiero Mediterraneo di Pulsano. The controller, a school, published a christmas video on the video platform YouTube,… ITALY ·Garante ·Art. 5, 6 Education Controllers Consent Mar 13, 2025
€40,000 Interflora Italia S.p.A.: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 20,000 on Interflora Italia S.p.A. The controller, who operates an online shop, used customer data for direct marketing purposes without a… ITALY ·Garante ·Art. 5, 6, 12 +2 Direct Marketing Right to Object Controllers Mar 13, 2025
€15,000 G@S Telecomunicazioni di Losito Lucia: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 15,000 on G@S Telecomunicazioni di Losito Lucia. The controller processed customer data without sufficient legal basis and additionally… ITALY ·Garante ·Art. 5, 6, 7 +2 Personal Data Controllers Telecommunications Mar 13, 2025
€5,000 Automobilus International S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Automobilus International S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Mar 12, 2025
€1,000 Noy Business Tranzactions SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Noy Business Tranzactions SRL. The controller failed to provide a data subject with requested data. ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Controllers Processing Agreement Mar 11, 2025