Skip to content
Content type · 2,395 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

651–700 of 2,395 sort newestlargest fineoldest
€40,000 Interflora Italia S.p.A.: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 20,000 on Interflora Italia S.p.A. The controller, who operates an online shop, used customer data for direct marketing purposes without a… ITALY ·Garante ·Art. 5, 6, 12 +2 Direct Marketing Right to Object Marketing Mar 13, 2025
€5,000 Automobilus International S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Automobilus International S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Mar 12, 2025
€1,000 Noy Business Tranzactions SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Noy Business Tranzactions SRL. The controller failed to provide a data subject with requested data. ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Controllers Supervisory Authorities Mar 11, 2025
€13,400 Polskie Radio Szczecin: Insufficient technical and organisational measures to ensure information security The Polish DPA fined Polskie Radio Szczecin (Polish Radio Szczecin) EUR 13,400. Due to the lack of sufficient technical measures, Polskie Radio Szczecin failed to protect the… POLAND ·UODO ·Art. 24, 32 Security Personal Data Processing Mar 11, 2025
€2,000 SHOPBAG GROUP ONLINE SRL: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 2,000 onSHOPBAG GROUP ONLINE SRL. The controller failed to respond to a request made by the DPA. ROMANIA ·ANSPDCP ·Art. 58 Supervision Supervisory Authorities Controllers Mar 6, 2025
€20,000 WEBRASOFT SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on WEBRASOFT SRL. The controller failed to implement sufficient technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Mar 4, 2025
€10,000 BEKO ROMANIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on BEKO ROMANIA SA. The controller failed to implement sufficient technical and organisational measures to provide data security,… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Mar 3, 2025
€2,556 Registry Agency of Republic of Bulgaria: Insufficient legal basis for data processing Bulgarian Commission for Personal Data Protection (KZLD) fined Registry Agency of Republic of Bulgaria €2,556 on 2025-03-01 for: Insufficient legal basis for data processing. CPDP ·Insufficient legal basis for data processing Public Authority Education Personal Data Mar 1, 2025
€1,000 Velvet Medical SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Velvet Medical SRL. The controller failed to provide the data subject with the requested health data. ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Feb 27, 2025
€600,000 IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274. Due to a technical error in its online platform, personal data, including… SPAIN ·AEPD ·Art. 5 Controllers Personal Data Processing Feb 25, 2025
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… SPAIN ·AEPD ·Art. 6 Personal Data Consent Telecommunications Feb 25, 2025
€2,000 Medstar S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 2,000 on Medstar S.R.L. The controller had mistakenly sent a patient's health data via unsecured email to another patient. The DPA found… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Feb 20, 2025
€2,000 Meedea Construct Prest SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 in Meedea Construct Prest SRL. The controller disclosed personal and health data of a former employee to a third party, who then… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 Controllers Personal Data Types of Special Categories of Personal Data Feb 17, 2025
€200,000 ORANGE BANK, S.A. SUCURSAL EN ESPAÑA: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 200,000 on ORANGE BANK, S.A. SUCURSAL EN ESPAÑA. The AEPD reacted to multiple complaints of private individuals regarding a data… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Feb 14, 2025
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… SPAIN ·AEPD ·Art. 6 Personal Data Consent Telecommunications Feb 14, 2025
€3,000 PPC Energie Muntenia SA: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 3,000 on PPC Energie Muntenia SA. The controller forwarded customer data to a third company, which then contacted the data subjects for… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +1 Personal Data Controllers Marketing Feb 10, 2025
€3,000 Omniasig Vienna Insurance Group S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Omniasig Vienna Insurance Group S.A. The controller failed to implement sufficient technical and organisational measures to… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Feb 6, 2025
€5,000 FARMEC SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on FARMEC SA. The controller failed to implement sufficient technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 25, 32 Security Controllers Personal Data Feb 5, 2025
€1.2M ORANGE ESPAGNE, S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,200,000 on ORANGE ESPAGNE, S.A.U.. An individual had filed a complaint with the DPA because the company had given a duplicate of their… SPAIN ·AEPD ·Art. 6, 25 Personal Data Security Consent Feb 5, 2025
€10,000 V&M Contab & Management SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on V&M Contab & Management SRL. The controller failed to implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32, 58 Data Breaches Security Controllers Feb 4, 2025
€15,000 Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Unicredit Bank SA. The controller failed to implement sufficient technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 25 Security Controllers Personal Data Feb 3, 2025
€15,000 S.P.E.E.H. HIDROELECTRICA S.A: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on S.P.E.E.H. HIDROELECTRICA S.A. The controller failed to implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 25 Security Controllers Personal Data Jan 31, 2025
€40,000 Orange Romania SA: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 40,000 on Orange Romania SA. The controller failed to fulfil a request for the erasure of data. The controller also execsevly stored and… ANSPDCP ·Art. 5, 6, 7 +2 ·Non-compliance with general data processing principles Controllers Personal Data Processing Jan 27, 2025
€5,000 Softehnica S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Softehnica S.R.L. The controller had suffered a ransomware attack, which allowed unauthorized third parties to gain access to… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Jan 23, 2025
€15,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Vodafone Romania S.A. Personal data such as names, email addresses and customer numbers were repeatedly disclosed due to… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Controllers Jan 20, 2025
€2,000 DELIVERY SOLUTIONS S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on DELIVERY SOLUTIONS S.A. A security incident led to the unauthorized disclosure of personal data (name, address, telephone… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Jan 17, 2025
€600 Pro Loco Tourist Association of Cittareale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 600 on the Pro Loco Tourist Association of Cittareale. The controller published personal data of its members on its website without a… ITALY ·Garante ·Art. 5, 6 Personal Data Controllers Processing Jan 16, 2025
€100,000 Realmaps S.r.l.: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 100,000 on Realmaps S.r.l. The controller collects data on every real estate owner and sells it to customers who use it for direct marketing… ITALY ·Garante ·Art. 5, 6, 7 +12 Retention Period Controllers Processors Jan 16, 2025
€6,000 San Pio Hospital in Benevento: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the San Pio Hospital in Benevento. The controller did not ensure that only entitled employees had access to technical… ITALY ·Garante ·Art. 5, 6, 9 Personal Data Controllers Types of Special Categories of Personal Data Jan 16, 2025
Asper Biogene OÜ: Insufficient technical and organisational measures to ensure information security The Estonian DPA imposed a fine of EUR 85,000 on Asper Biogene OÜ. Asper Biogene OÜ suffered a data leak due to a lack of adequate security measures. The leak affected… ESTONIA ·AKI ·Insufficient technical and organisational measures to ensure information security Genetic Data Security Types of Special Categories of Personal Data Jan 10, 2025
€175,000 Credit Institution: Insufficient fulfilment of data subjects rights The DPA of Luxembourg has issued a fine of EUR 175,000 on a Credit Institution. The controller failed to respond to information requests within the timeframe specified in Art. 12… LUXEMBOURG ·CNPD (LU) ·Art. 12 Supervisory Authorities Personal Data Controllers Jan 6, 2025
€2,000 Unirea Medical Center S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Unirea Medical Center S.R.L. The controller publicly exposed the access credentials for a data subject's email account on a… ROMANIA ·ANSPDCP ·Art. 24, 32 Personal Data Controllers Security Jan 3, 2025
€45M Vodafone GmbH: Non-compliance with general data processing principles The Federal Commissioner for Data Protection and Freedom of Information (BfDI) has imposed a fine of EUR 45,000,000 on Vodafone GmbH. The controller failed to properly supervise a… BfDI Processors Controllers Personal Data Jan 1, 2025
€357,000 Panek SA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 357,000 on Panek SA. During the reconstruction of its website, the controller failed to implement adequate technical and organisational… POLAND ·UODO ·Art. 32 Security Controllers Personal Data Dec 23, 2024
€40,000 Coolblue B.V: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of €40,000 on Coolblue. The company collected personal data via cookies without users' explicit consent, relying on pre-ticked consent boxes. THE NETHERLANDS ·AP ·Art. 5, 6 Consent Personal Data Processing Dec 23, 2024
€300,000 LÍNEA DIRECTA ASEGURADORA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 300,000 on LÍNEA DIRECTA ASEGURADORA, S.A.. A data subject had filed a complaint with the DPA stating that they had inquired about a car… SPAIN ·AEPD ·Art. 6, 28 Processors Personal Data Controllers Dec 23, 2024
€135,600 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA fined a company in the banking sector EUR 135,600. The DPA inspected the fined company and found several violations of the GDPR. First, the company failed to ensure… POLAND ·UODO ·Art. 30, 35, 38 DPIA Marketing Profiling Dec 18, 2024
€251M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish Data Protection Commission (DPC) has fined Meta Platforms Ireland Limited EUR 251 million. The fine was imposed for data protection violations related to a data breach… DPC Notification Obligation Data Breaches Controllers Dec 17, 2024
€950,000 Sambla Group Oy: Insufficient technical and organisational measures to ensure information security The Finnish DPA has imposed a fine of EUR 950,000 on Sambla Group Oy. Security vulnerabilities in two of its comparison portals allowed unauthorized persons to access personal… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Personal Data Insurance Dec 17, 2024
€200,000 Hospital: Insufficient technical and organisational measures to ensure information security The Belgian DPA has fined a hospital EUR 200,000. The hospital had suffered a ransomware attack through a vulnerability in the server, which paralyzed parts of the computer system… BELGIUM ·APD/GBA ·Art. 5, 24, 32 +1 Security DPIA Personal Data Dec 17, 2024
€70,000 INTERURBANA DE AUTOBUSES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined INTERURBANA DE AUTOBUSES, S.A. EUR 70,000 after an employee filed a complaint over the publication of personal data on the company's bulletin boards.… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Personal Data Dec 16, 2024
€3.5M CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 3.5 million on CAIXABANK, S.A. Following a complaint from customers, it was found that the mother of an account holder had access to a… SPAIN ·AEPD ·Art. 5, 25 Privacy by Design & Default Privacy by Default Privacy by Design Dec 12, 2024
€18,400 Granit Bostad Beritsholm AB: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 18,400 on the Granit Bostad Beritsholm AB. The controller, a property management company, installed CCTV cameras in an apartment complex… SWEDEN ·IMY ·Art. 6, 13 Controllers Personal Data Supervisory Authorities Dec 11, 2024
€4M GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS. The controller had suffered a data breach where unknown third parties gained… SPAIN ·AEPD ·Art. 5, 25, 32 +1 Privacy by Design & Default Security Controllers Dec 10, 2024
€300 Private individual: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 300 on a data controller. The controller had installed a video surveillance system without adequately providing information for data… SPAIN ·AEPD ·Art. 13 Controllers Personal Data Supervisory Authorities Dec 3, 2024
€6,900 Hospital: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined a district hospital in Września EUR 6,900 for failing to report a data breach to the DPA and data subjects in a timely manner. A patient had accidentally… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Nov 26, 2024
€4.8M Netflix International B.V.: Insufficient fulfilment of information obligations The Dutch DPA has imposed a fine of EUR 4.75 million on Netflix. This fine is based on a complaint filed by the Austrian organization 'noyb'. During its investigation, the DPA… THE NETHERLANDS ·AP ·Art. 5, 12, 13 +1 Personal Data Supervisory Authorities Supervision Nov 26, 2024
€220,000 CARTONAJES BAÑERES, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 220,000 on CARTONAJES BAÑERES, S.A. following a complaint filed by a former employee. The employee had submitted a request to the controller… SPAIN ·AEPD ·Art. 15, 35 Personal Data Controllers Types of Special Categories of Personal Data Nov 22, 2024
€220,000 CARTONAJES BAÑERES, S.A: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined CARTONAJES BAÑERES, S.A. EUR 220,000. During its investigation, the DPA found that the controller had failed to grant a former employee access to their… SPAIN ·AEPD ·Art. 15, 35 DPIA Controllers Personal Data Nov 22, 2024