Skip to content
Content type · 2,395 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

601–650 of 2,395 sort newestlargest fineoldest
€15,000 Immobiliare Valdalpone S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on Immobiliare Valdalpone S.r.l. The controller obtained personal data of potential customers by Realmaps S.r.l., which obtained… ITALY ·Garante ·Art. 5, 6, 7 +8 Direct Marketing Personal Data Controllers Apr 10, 2025
€8,000 Undici S.r.l.s.: Non-compliance with the general principles of data processing. ⇄ Een boete van 8.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +6 Marketing Controllers Processing Apr 10, 2025
€8,000 Undici S.r.l.s.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 8,000 on Undici S.r.l.s. The controller obtained personal data of potential customers by Realmaps S.r.l., which obtained the data in… ITALY ·Garante ·Art. 5, 6, 7 +6 Personal Data Controllers Marketing Apr 10, 2025
€5M Luka Inc.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 5,000,000 on Luka Inc. The developer created a chatbot called Replika with a written and voice interface. It is based on a generative AI… ITALY ·Garante ·Art. 5, 6, 12 +3 Controllers Personal Data Supervisory Authorities Apr 10, 2025
€15,000 Tensa Art Design S.A.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 15,000 on Tensa Art Design S.A. The controller contacted a data for direct marketing purposes without consent. The controller also… ROMANIA ·ANSPDCP ·Art. 6, 12, 15 +1 Personal Data Marketing Controllers Apr 10, 2025
€5,000 Board for Support to Citizens and Agriculture: Insufficient legal basis for data processing. ⇄ Een boete van 5.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Retention Period Storage Limitation Personal Data Apr 10, 2025
€15,000 Tensa Art Design S.A.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 15.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 12, 15 +1 Personal Data Processing Supervisory Authorities Apr 10, 2025
€5,000 Patronage and Assistance for Citizens and Agriculture Board: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 5,000 on Patronage and Assistance for Citizens and Agriculture Board. The controller has stored personal data of a data subject for a… ITALY ·Garante ·Art. 5, 6 Personal Data Controllers Processing Apr 10, 2025
€15,000 Immobiliare Valdalpone S.r.l.: Non-compliance with the general principles for data processing. ⇄ Een boete van 15.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +8 Marketing Controllers Processing Apr 10, 2025
€5,000 Gynecologist: Insufficient compliance with the information obligation. ⇄ Een boete van €5.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 15 Supervisory Authorities Personal Data Right of Access Apr 9, 2025
€600 FEDERACION DE COLUMBICULTURA DE CASTILLA-LA MANCHA: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine on FEDERACION DE COLUMBICULTURA DE CASTILLA-LA MANCHA. The controller was unable to ensure the confidentiality of personal data, which resulted in a… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Controllers Apr 9, 2025
€5,000 Banca Transilvania S.A.: Insufficient legal basis for data processing. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Processing Controllers Apr 3, 2025
€5,000 Banca Transilvania S.A.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 5,000 on Banca Transilvania S.A. The controller forwarded client data to an insurance company without a sufficient legal basis. ROMANIA ·ANSPDCP ·Art. 5, 6 Controllers Personal Data Processing Apr 3, 2025
€3,000 BINBOX GLOBAL SERVICES S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on BINBOX GLOBAL SERVICES S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Apr 2, 2025
€3,000 BINBOX GLOBAL SERVICES S.R.L.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Apr 2, 2025
€3,500 MAD COOL FESTIVAL S.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Boete van €3.500 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 32 Security Controllers Accountability Mar 30, 2025
€21,600 SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 21.600 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 7, 28 Processing Personal Data Retention Period Mar 28, 2025
€6,600 GRUAS IGNACI, S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on GRUAS IGNACI, S.L. The controller uses too much data to verify a person's identity, which breaches the principle of data minimization.… SPAIN ·AEPD ·Art. 5, 13, 32 Retention Period Controllers Security Mar 28, 2025
€6,600 GRUAS IGNACI, S.L.: Violation of the general principles for data processing. ⇄ Boete van 6.600 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 13, 32 Controllers Security Processing Mar 28, 2025
€4,000 CREMA GAMES, S.L.: Insufficient compliance with information obligations. ⇄ Een boete van 4.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 15 Personal Data Controllers Right of Access Mar 28, 2025
€4,000 CREMA GAMES, S.L.: Insufficient fulfilment of information obligations The Spanish DPA imposed a fine on CREMA GAMES, S.L. The controller failed to fulfill an information request from an online customer. The controller asked the data subject for an… SPAIN ·AEPD ·Art. 15 Personal Data Controllers Supervisory Authorities Mar 28, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Non-compliance with the general principles for data processing. ⇄ Een boete van 120.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Processing Personal Data Mar 28, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on SERVICIOS ESPECIALES, S.A. The case concerned a GDPR breach during an internal workplace conflict investigation: the company shared a report via… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Accountability Personal Data Mar 28, 2025
€12,000 ESTUDIO ALCAZAR DEL GENIL 2022, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine on ESTUDIO ALCAZAR DEL GENIL 2022, S.L. The controller collected property data by having its employees visit and photograph the properties,… SPAIN ·AEPD ·Art. 6, 14 Controllers Personal Data Supervisory Authorities Mar 28, 2025
€12,000 ESTUDIO ALCAZAR DEL GENIL 2022, S.L.: Insufficient legal basis for data processing. ⇄ 12.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6, 14 Controllers Processing Personal Data Mar 28, 2025
€18,000 Multiple Companies: Insufficient legal basis for data processing The Italian DPA imposed fines on 3 companies which ammount to EUR 6,000 each. The fined companies (Powerfit s.s.d.a.r.l., Soleo s.s.d.a.r.l. and Zero Due Villa s.s.d.a.r.l.) run a… ITALY ·Garante ·Art. 5, 6, 12 +1 Right to be Forgotten Marketing Consent Mar 27, 2025
€4,000 Istituto di Istruzione Superiore 'P. Galluppi' Tropea: Insufficient legal basis for data processing. ⇄ Een boete van 4.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 Types of Special Categories of Personal Data Controllers Fairness & Transparency Mar 27, 2025
€18,000 Multiple companies: Insufficient legal basis for data processing. ⇄ Een boete van €18.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +1 Marketing Consent Personal Data Mar 27, 2025
€4,000 Istituto di Istruzione Superiore 'P. Galluppi' Tropea: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,500 on the Istituto di Istruzione Superiore 'P. Galluppi' Tropea. The controller processed biometric data of its employees to control… ITALY ·Garante ·Art. 5, 6, 9 Types of Special Categories of Personal Data Controllers Fairness & Transparency Mar 27, 2025
€3.5M Advanced Computer Software Group Ltd: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined Advanced Computer Software Group Ltd £3.07 million (EUR 3.5 million) for insufficient IT security (infringiment of Art. 32 (1) UK GDPR). The controller… UNITED KINGDOM ·ICO ·Art. 32 Security Controllers Personal Data Mar 26, 2025
€25,000 NTT DATA ROMANIA S.A.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 32, 33 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Processing Mar 25, 2025
€25,000 NTT DATA ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on NTT DATA ROMANIA S.A. The controller failed to implement sufficient technical and organisational measures, resulting in a data… ANSPDCP ·Art. 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Controllers Security Mar 25, 2025
€20,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) imposed a fine of EUR 20,000 on a hospital for failing to implement adequate technical and organizational measures to protect personal data in line with… CROATIA ·AZOP ·Art. 32 Security Personal Data Data Breaches Mar 24, 2025
€17,600 Chief Commander of the Police: Insufficient legal basis for data processing The Polish DPA has fined the Chief Commander of the Polish Police EUR 17,600. During a press conference, the Chief Commander of the Police disclosed the personal and medical data… POLAND ·UODO ·Art. 6, 9 Healthcare Personal Data Processing Mar 24, 2025
€2,000 INDEPENDENTS DE VALLROMANES: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,000 on INDEPENDENTS DE VALLROMANES. The controller, a political party, posted a court decision on its social media, which included… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Personal Data Mar 24, 2025
€4,000 Hospital: Non-compliance with general principles of data processing. ⇄ 4.000 euro boete - Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·AZOP ·Art. 13, 14, 25 +1 Personal Data Processing Processors Mar 24, 2025
€80,000 Company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 80,000 on a company. The company was responsible for monitoring parking lots at several supermarkets and a hospital. However, it… CROATIA ·AZOP ·Art. 5, 6, 32 Processors Personal Data Processing Mar 24, 2025
€40,000 Company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 40,000 on a company that published personal data of sole traders on its website. The data originated from public sources and from… CROATIA ·AZOP ·Art. 5, 6, 12 +3 Personal Data Supervisory Authorities Processing Mar 24, 2025
€4,000 Hospital: Non-compliance with general data processing principles The Croation DPA (AZOP) has imposed a fine of EUR 4,000 on a hospital. The AZOP found that the hospital used a company which automatically retrieved personal data of vehicle… CROATIA ·AZOP ·Art. 13, 14, 25 +1 Privacy by Design & Default Personal Data Supervisory Authorities Mar 24, 2025
€40,000 Company: Insufficient legal basis for the processing of data. ⇄ Een boete van 40.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·AZOP ·Art. 5, 6, 12 +3 Processing Professional Secrecy Personal Data Mar 24, 2025
€1,000 Bucharest Down Town Hotel SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Bucharest Down Town Hotel SRL. The controller failed to provide a data subject with requested data. ROMANIA ·ANSPDCP ·Art. 12, 13, 15 Personal Data Controllers Supervisory Authorities Mar 21, 2025
€2,000 ONE UNITED PROPERTIES S.A: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on ONE UNITED PROPERTIES S.A. The controller contacted a data subject multiple times for direct marketing purposes without… ROMANIA ·ANSPDCP ·Art. 6, 12, 15 +1 Personal Data Marketing Controllers Mar 20, 2025
€23,500 Minister of Digital Affairs: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 23,500 on the Polish Minister for Digital Affairs. The Minister unlawfully processed personal data of Polish citizens in the PESEL… POLAND ·UODO ·Art. 5, 6 Personal Data Processing Education Mar 17, 2025
€6.3M Poczta Polska SA (Polish Post): Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 6.3 million on Poczta Polska SA (Polish Post) for the unlawful disclosure of personal data of over 30 million citizens from the PESEL… POLAND ·UODO ·Art. 6 Personal Data Processing Agreement International Transfer Mar 17, 2025
€1.6M ING BANK N.V., SUCURSAL EN ESPAÑA: Insufficient legal basis for data processing The Spanish data protection authority (AEPD) has imposed a fine on ING BANK N.V., SUCURSAL EN ESPAÑA. As part of the verification process for new banking customers, ING carries… SPAIN ·AEPD ·Art. 6 Personal Data Insurance Processing Mar 14, 2025
€3.2M CENTROS COMERCIALES CARREFOUR, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 3,200,000 on CENTROS COMERCIALES CARREFOUR, S.A. The controller suffered a cyberattack, resulting in the leak of a large amount of personal… SPAIN ·AEPD ·Art. 5, 32, 34 Data Breaches Security Personal Data Mar 14, 2025
€2,000 Municipality of Roccaraso: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 2,000 on the Municipality of Roccaraso. The controller published personal data of a worker on its public notice board website without a… ITALY ·Garante ·Art. 5, 6 Personal Data Controllers Processing Mar 13, 2025
€15,000 G@S Telecomunicazioni di Losito Lucia: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 15,000 on G@S Telecomunicazioni di Losito Lucia. The controller processed customer data without sufficient legal basis and additionally… ITALY ·Garante ·Art. 5, 6, 7 +2 Personal Data Controllers Supervisory Authorities Mar 13, 2025
€20,000 Encore Thermoengineering s.r.l.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 20,000 on Encore Thermoengineering s.r.l. The controller legally obtained employee data from another company that had gone bankrupt. The… ITALY ·Garante ·Art. 5, 6, 17 Retention Period Controllers Personal Data Mar 13, 2025