Skip to content
Content type · 3,651 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

651–700 of 3,651 sort newestlargest fineoldest
€15,600 L. Zamenhof University Children's Clinical Hospital in Białystok: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 15,600 on the L. Zamenhof University Children's Clinical Hospital in Białystok. The controller did not implement sufficient technical and… POLAND ·UODO ·Art. 5, 32 Security Healthcare Healthcare Jun 30, 2025
€15,600 Kinderziekenhuis van de L. Zamenhof Universiteit in Białystok: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 15.600 euro boete - Poolse nationale instantie voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 32 Security Healthcare Health Data NL Jun 30, 2025
€96,000 SIDECU, S.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 96.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 9, 13, 35 Controllers Data Controller Processing NL Jun 26, 2025
€96,000 SIDECU, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 96,000 on SIDECU, S.A. The controller introduced facial recognistion system as the only access method to their facilities, without offering… SPAIN ·aepd ·Art. 9, 13, 35 DPIA Privacy Impact Assessment IP Address Jun 26, 2025
€3,000 SC Tremend Software Consulting SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on SC Tremend Software Consulting SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Processing Agreement Jun 26, 2025
€3,000 SC Piramida Trade Invest SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 3,000 on SC Piramida Trade Invest SRL. The controller processed personal data without a sufficient legal basis and without sufficient… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +4 Controllers Personal Data Data Subject Rights Exercise Modalities and Procedures Jun 26, 2025
€25,000 Alliance for the Union of Romanians Party: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 25,000 on the Alliance for the Union of Romanians Party. The controller did not implement adeqaute technical and organisational measures… ROMANIA ·ANSPDCP ·Art. 5, 6, 25 +1 Data Breaches Security Controllers Jun 26, 2025
€3,000 Selgros Cash & Carry SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Jun 26, 2025
€25,000 Partij "Alliantie voor de Unie van Roemenië": Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 25 +1 Security Personal Data Education NL Jun 26, 2025
€3,000 SC Piramida Trade Invest SRL: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +4 Security Personal Data Controllers NL Jun 26, 2025
€3,000 SC Tremend Software Consulting SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Jun 26, 2025
€3,000 Selgros Cash & Carry SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Selgros Cash & Carry SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Processing Agreement Jun 26, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 550,000 on Vodafone – PANAFON A.E.E.T. The controller failed to implement sufficient technical and organisational measures to ensure data… GREECE ·HDPA ·Art. 5, 28 Security Telecommunications Controllers Jun 25, 2025
€40,000 KARAMBELAS KONSTANTINOS & CO. E.E.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 40,000 on KARAMBELAS KONSTANTINOS & CO. E.E. The processor, which was processing data for a telecommunications provider (ETid: 2878),… GREECE ·HDPA ·Art. 29, 32 Security Telecommunications Processors Jun 25, 2025
€40,000 KARAMBELAS KONSTANTINOS & CO. E.E.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van 40.000 euro - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 29, 32 Security Telecommunications Personal Data NL Jun 25, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 550.000 euro - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 28 Security Data Processor Processors NL Jun 25, 2025
€7,000 General Hospital of the University of Larissa: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 7,000 on the General Hospital of the University of Larissa. The controller failed to adequately fulfil the rights of data subjects. It… GREECE ·HDPA ·Art. 5, 14, 15 Healthcare Healthcare Personal Data Jun 24, 2025
€20,725 Birthlink: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van €20.725 - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Security Notification Obligation Accountability NL Jun 24, 2025
€7,000 Algemeen Ziekenhuis van de Universiteit van Larissa: Onvoldoende naleving van de rechten van betrokkenen. Een boete van €7.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 14, 15 Health Data Healthcare Personal Data NL Jun 24, 2025
€10,000 Shield of David - K.I.D.A.F.: Niet-naleving van algemene principes voor gegevensverwerking. Boete van €10.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 12, 13 +3 Personal Data Health Data Video Surveillance NL Jun 24, 2025
€10,000 Shield of David - K.I.D.A.F.: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Shield of David - K.I.D.A.F. The controller, a day care centre for people with autism, has legally installed video… GREECE ·HDPA ·Art. 5, 12, 13 +3 Video Surveillance Controllers Healthcare Jun 24, 2025
€20,725 Birthlink: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 18,000 (EUR 20,725) on Birthlink. The controller, a scottish registered charity, failed to implement sufficient technical and organisational… UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Security Controllers Processing Agreement Jun 24, 2025
€50,000 Piraeus Bank S.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 50.000 euro - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 6 Personal Data Processing Data Controller NL Jun 23, 2025
€125,000 City of Dublin Education and Training Board: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 125,000 on the City of Dublin Education and Training Board. The controller suffered a data breach due to insufficient technical and… IRELAND ·Art. 5, 32, 33 +1 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Education Jun 23, 2025
€3,500 Gemeentelijk Sociaal Hulpcentrum Aleksandrów: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.500 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 32 Security Education Data Breaches NL Jun 23, 2025
€125,000 Onderwijs- en opleidingsraad van de stad Dublin: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 125.000 euro boete - Ierse Autoriteit voor Gegevensbescherming. IRELAND ·Art. 5, 32, 33 +1 ·Insufficient technical and organisational measures to ensure information security Security Data Breaches Education NL Jun 23, 2025
€50,000 Piraeus Bank S.A.: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 50,000 on Piraeus Bank S.A.The controller has processed personal data even though the data subject rightfully opposed the the data… GREECE ·HDPA ·Art. 5, 6 Personal Data Controllers Insurance Jun 23, 2025
€4,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 4,000 on Vodafone Romania S.A. The controller failed to implement sufficient technical and organisational measures to ensure data… ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Telecommunications Jun 23, 2025
€3,500 Municipal Social Welfare Center Aleksandrów: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 3,500 on the Municipal Social Welfare Center in Aleksandrów. The controller did not implement sufficient technical and organisational… POLAND ·UODO ·Art. 32 Data Breaches Security Education Jun 23, 2025
€4,000 Vodafone Romania S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 4.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Security Data Breaches Telecommunications NL Jun 23, 2025
€42,000 IBERCAJA BANCO, S.A.: Overtreding van de algemene principes voor gegevensverwerking. Een boete van 42.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Recipient Processing Controllers NL Jun 20, 2025
€24,000 COLEGIO VIRGEN DE EUROPA, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 24,000 on COLEGIO VIRGEN DE EUROPA, S.L. An employee of the controller, a school, took pictures of minor pupils without a sufficient legal… SPAIN ·aepd ·Art. 5, 6, 13 Education Controllers Personal Data Jun 20, 2025
€24,000 COLEGIO VIRGEN DE EUROPA, S.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 24.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 6, 13 Education Personal Data Processing NL Jun 20, 2025
€42,000 IBERCAJA BANCO, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 42,000 on IBERCAJA BANCO, S.A. During a bank transfer, the controller transmitted more data then necessary to the recipient of the payment.… SPAIN ·aepd ·Art. 5 Recipient IP Address Processing Agreement Jun 20, 2025
€1,000 SC Diamir SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 1,000 on SC Diamir SRL. The controller failed to properly cooperate with the supervisory authority and also disclosed personal data to… ROMANIA ·ANSPDCP ·Art. 6, 58 Controllers Processing Agreement Supervisory Authorities Jun 19, 2025
€1,000 SC Diamir SRL: Overtreding van de algemene principes voor gegevensverwerking. Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 58 Processing Controllers Personal Data NL Jun 19, 2025
€200 Dincă Viorel George: Onvoldoende samenwerking met de toezichthoudende instantie. Een boete van 200 euro - De Roemeense nationale toezichthouder op de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Controllers Data Controller NL Jun 18, 2025
€6,800 AB Storstockholms Lokaltrafik: Onvoldoende juridische basis voor de verwerking van gegevens. 6.800 euro boete - De Zweedse Autoriteit voor Gegevensbescherming (Integritetsskyddsmyndigheten). SWEDEN ·Art. 6, 9 ·Insufficient legal basis for data processing Processing Special Categories of Data Supervisory Authorities NL Jun 18, 2025
€200 Dincă Viorel George: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 200 on a private individual. The controller failed to react to communication from the supervisory authority. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Law Enforcement Jun 18, 2025
€6,800 Waxholms Ångfartygs AB: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 6,800 on Waxholms Ångfartygs AB. The controller, a public transportation company, requires employees operating a ferry to take a… SWEDEN ·Art. 6, 9 ·Insufficient legal basis for data processing Controllers Processing Agreement Processing Jun 18, 2025
€6,800 AB Storstockholms Lokaltrafik: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 6,800 on AB Storstockholms Lokaltrafik. The controller, a public transportation company, requires employees operating a ferry to take a… SWEDEN ·Art. 6, 9 ·Insufficient legal basis for data processing Controllers Processing Agreement Processing Jun 18, 2025
€6,800 Waxholms Ångfartygs AB: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. 6.800 euro boete - De Zweedse Autoriteit voor Gegevensbescherming (Integritetsskyddsmyndigheten). SWEDEN ·Art. 6, 9 ·Insufficient legal basis for data processing Processing Data Controller Personal Data NL Jun 18, 2025
€12,000 ALBOR ENERGÍA S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 12,000 on ALBOR ENERGÍA S.L. The controller used third parties acting as data processors for direct marketing purposes. The organisation of… SPAIN ·aepd ·Art. 28 Controllers Processing Agreement Processors Jun 16, 2025
€12,000 ALBOR ENERGÍA S.L.: Onvoldoende juridische basis voor de verwerking van gegevens. 12.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 28 Processing Data Processor Processors NL Jun 16, 2025
€3,000 SILVANERGIA 2022, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 3,000 on SILVANERGIA 2022, S.L.The controller, a company providing direct marketing services, processed data of potential customers without a… SPAIN ·aepd ·Art. 6 Direct Marketing Controllers Processing Agreement Jun 16, 2025
€3,000 SILVANERGIA 2022, S.L.: Onvoldoende juridische basis voor de verwerking van gegevens. Boete van 3.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6 Controllers Processing Data Controller NL Jun 16, 2025
€18,000 OCI CINE, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 18,000 on OCI CINE, S.L. The controller had implemented insufficient technical and organisational measures to ensure data security, resulting… SPAIN ·aepd ·Art. 5, 32 Security Controllers Processing Agreement Jun 13, 2025