Skip to content
Content type · 3,446 documents in this view · 3,651 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

701–750 of 3,446 sort newestlargest fineoldest
€6,000 SC Travel Planner SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 6,000 on SC Travel Planner SRL. The controller failed to implement sufficient technical and organisational measures, resulting in a data… ROMANIA ·ANSPDCP ·Art. 12, 15, 32 +1 Data Breaches Controllers Security Apr 25, 2025
€1,000 Sole Trader: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 1,000 on a sole trader. The controller published personal data on a website without a legal basis and despite being subject to a… SLOVENIA ·Art. 5 ·Insufficient legal basis for data processing Controllers Personal Data Processing Agreement Apr 25, 2025
€6,000 SC Travel Planner SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 6.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15, 32 +1 Data Breaches Security Controllers NL Apr 25, 2025
€10,000 Dante International SA: Onvoldoende naleving van de rechten van betrokkenen bij de verwerking van persoonsgegevens. Een boete van €10.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 17, 19 Personal Data Processing Article 19 GDPR - Notification of Rectification, Erasure or Restriction NL Apr 24, 2025
€6,000 Real Estate Agency: Insufficient cooperation with supervisory authority The Belgian DPA imposed a fine of EUR 6,000 on a real estate agency. The Belgian DPA had previously issued a remedy to the controller in an earlier case due to the controller… BELGIUM ·APD ·Art. 5, 6, 17 +1 Right to be Forgotten Supervisory Authorities Controllers Apr 24, 2025
€1,500 ULPIA TRAJANA ALAMEDA S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on ULPIA TRAJANA ALAMEDA S.L. During the booking process, the controller processed data that was unnecessary for the purpose, infringing on the… SPAIN ·aepd ·Art. 5, 9 Controllers IP Address DPIA Apr 24, 2025
€10,000 Dante International SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 10,000 on Dante International SA. The controller failed to respond adequately to a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 17, 19 Personal Data Controllers Processing Agreement Apr 24, 2025
€9,200 Diskrimineringsombudsmannen: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 9,200 on the Swedish Disrimination Ombudsman. The controller was unable to implement sufficient data security measures, resulting in the… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Public Authority Controllers Apr 23, 2025
€1,200 FUNDACIÓ PRIVADA DE SERVEIS PER ALS USUARIS DEL HABITATGE SOCIAL DE CATALUNYA: Insufficient legal basis for data processing The Spanish DPA imposed a fine on FUNDACIÓ PRIVADA DE SERVEIS PER ALS USUARIS DEL HABITATGE SOCIAL DE CATALUNYA. The controller processed personal data without a sufficient legal… SPAIN ·aepd ·Art. 6 Personal Data Controllers Processing Apr 22, 2025
€1,200 SERVICIOS DE INTEGRACIÓN DE ANDALUCÍA: Onvoldoende juridische basis voor de verwerking van gegevens. 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6 Controllers Data Controller Processing NL Apr 22, 2025
€20,000 Company: Non-compliance with general data processing principles The Belgian DPA imposed a fine of EUR 20,000 on a company. The controller is a company engaging in direct marketing activities. During those activies the company failed to comply… BELGIUM ·APD ·Art. 5, 6, 12 +4 Controllers Direct Marketing IP Address Apr 22, 2025
€12,000 NOVATES ALIMENTACIÓN MADRID, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine on NOVATES ALIMENTACIÓN MADRID, S.L. The controller used surveillance cameras without implementing the necessary technical and organizational… SPAIN ·aepd ·Art. 32 Security Video Surveillance Monitoring Apr 22, 2025
€1,200 SERVICIOS DE INTEGRACIÓN DE ANDALUCÍA: Insufficient legal basis for data processing The Spanish DPA imposed a fine on SERVICIOS DE INTEGRACIÓN DE ANDALUCÍA. The controller hired an employee and processed the mobile phone number of the new employee without consent… SPAIN ·aepd ·Art. 6 Controllers Employees Processing Agreement Apr 22, 2025
€600 SPAIN DPA: Non-compliance with general data processing principles The Spanish DPA imposed a fine on an unknown data controller. The controller stored full copies of personal IDs for verification purposes. In this case, storing all the… aepd ·Art. 5 ·Non-compliance with general data processing principles Controllers IP Address Processing Agreement Apr 15, 2025
€2,000 United Business Solutions SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Apr 15, 2025
€260,000 CAMERDATA, S.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 260.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6, 14 Processing Personal Data Telecommunications NL Apr 15, 2025
€7,800 Funeral Home: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined a funeral home EUR 7,800. The funeral home failed to implement sufficient technical and organisational measures to prevent a data breach. The funeral home… POLAND ·UODO ·Art. 5 Data Breaches Security Healthcare Apr 15, 2025
€2,000 United Business Solutions SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on United Business Solutions SRL. The controller failed to implement sufficient technical and organisational measuresto ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Apr 15, 2025
€7,800 Uitvaartonderneming: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €7.800 - van het Poolse Nationaal Bureau voor de Bescherming van Persoonlijke Gegevens (UODO). POLAND ·UODO ·Art. 5 Health Data Data Breaches Security NL Apr 15, 2025
€260,000 CAMERDATA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 260,000 on CAMERDATA, S.A. The controller operates a database in which it collects data on individual entrepreneurs from the Spanish… SPAIN ·aepd ·Art. 6, 14 Controllers Processing Agreement Personal Data Apr 15, 2025
€500,000 Chamber of Commerce, Industry, Services and Navigation of Spain: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500,000 on the Chamber of Commerce, Industry, Services and Navigation of Spain. Due to its function within the Spanish Executive, the… aepd ·Art. 5, 6, 14 ·Insufficient legal basis for data processing Controllers Fairness & Transparency Processors Apr 15, 2025
€600 SPAIN, DPA: Niet-naleving van de algemene principes voor gegevensverwerking. 600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). aepd ·Art. 5 ·Non-compliance with general data processing principles Processing Data Controller Controllers NL Apr 15, 2025
€6,000 LÃSER METALPRINT 3D, S.L.: Insufficient data processing agreement The Spanish DPA imposed a fine on LÃSER METALPRINT 3D, S.L. The controller hired a third company to install and maintain a surveillance system. The controller and the hired… SPAIN ·aepd ·Art. 28 Controllers Processing Agreement Monitoring Apr 14, 2025
€70,300 DPP Law Ltd.: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has imposed a fine of £ 60,000 (EUR 70,300) on the law firm DPP Law Ltd. The controller had suffered a cyber attack during which personal data of 791 clients and… UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Security Processing Agreement Controllers Apr 14, 2025
€3,000 EDA TV CONSULTING, S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on EDA TV CONSULTING, S.L. The controller had stored copies of personal IDs to verify the identity of data subjects. According to the DPA, the… SPAIN ·aepd ·Art. 5 IP Address Controllers Processing Agreement Apr 14, 2025
€1,000 Office Nova Concept SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Office Nova Concept SRL. The controller failed to respond adequately to a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 15, 17 +1 Personal Data Controllers Supervisory Authorities Apr 14, 2025
€3,000 EDA TV CONSULTING, S.L.: Overtreding van de algemene principes voor gegevensverwerking. Boete van 3.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Processing Controllers IP Address NL Apr 14, 2025
€6,000 LÄSER METALPRINT 3D, S.L.: Onvoldoende gegevensverwerkings overeenkomst. Boete van 6.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 28 Controllers Processing Processors NL Apr 14, 2025
€1,000 Office Nova Concept SRL: Onvoldoende naleving van de rechten van betrokkenen. Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15, 17 +1 Right of Access Personal Data Right to Object NL Apr 14, 2025
€2,000 NEW GAMBLING SOLUTIONS S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Processing NL Apr 11, 2025
€2,000 NEW GAMBLING SOLUTIONS S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on NEW GAMBLING SOLUTIONS S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure data… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Apr 11, 2025
€3M Acea Energia S.p.A.: Onvoldoende juridische basis voor de verwerking van gegevens. 3.000.000 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +5 Data Controller Processing Controllers NL Apr 10, 2025
€8,000 Gemeenschap van de oostelijke Apennijnen in Parma: Niet-naleving van de algemene principes voor gegevensverwerking. 8.000 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +2 Video Surveillance Education Processing NL Apr 10, 2025
€8,000 Undici S.r.l.s.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 8.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +6 Data Controller Processing Controllers NL Apr 10, 2025
€15,000 Immobiliare Valdalpone S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on Immobiliare Valdalpone S.r.l. The controller obtained personal data of potential customers by Realmaps S.r.l., which obtained… ITALY ·Garante ·Art. 5, 6, 7 +8 IP Address Personal Data Direct Marketing Apr 10, 2025
€4,000 Gemeente Ponte nelle Alpi: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 4.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Processing Data Controller Controllers NL Apr 10, 2025
€5M Luka Inc.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 5,000,000 on Luka Inc. The developer created a chatbot called Replika with a written and voice interface. It is based on a generative AI… ITALY ·Garante ·Art. 5, 6, 12 +3 AI Act Violations AI Act Formal Non-Compliance IP Address Apr 10, 2025
€15,000 Tensa Art Design S.A.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 15.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 12, 15 +1 Personal Data Marketing Data Controller NL Apr 10, 2025
€15,000 Immobiliare Valdalpone S.r.l.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 15.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +8 Data Controller Processing Controllers NL Apr 10, 2025
€15,000 Tensa Art Design S.A.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 15,000 on Tensa Art Design S.A. The controller contacted a data for direct marketing purposes without consent. The controller also… ROMANIA ·ANSPDCP ·Art. 6, 12, 15 +1 Direct Marketing Marketing Controllers Apr 10, 2025
€850,000 Network of Agencies and Companies: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 850,000 on a network of agencies and companies. The network operated on behalf of Acea Energia S.p.A. and engaged in aggresive customer… ITALY ·Garante ·Art. 5, 6, 7 +6 Fines IP Address Telecommunications Apr 10, 2025
€5,000 Patronage and Assistance for Citizens and Agriculture Board: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 5,000 on Patronage and Assistance for Citizens and Agriculture Board. The controller has stored personal data of a data subject for a… ITALY ·Garante ·Art. 5, 6 Personal Data Education Controllers Apr 10, 2025
€8,000 Eastern Parma Apennine Mountain Community: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 8,000 on the Eastern Parma Apennine Mountain Community. The controller had set up video surveillance in front of a police station, that… ITALY ·Garante ·Art. 5, 6, 12 +2 Video Surveillance Monitoring Education Apr 10, 2025
€5,000 Bestuur voor steun aan burgers en de landbouw: Onvoldoende wettelijke basis voor gegevensverwerking. Een boete van 5.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Storage Limitation Personal Data Processing NL Apr 10, 2025
€850,000 Netwerk van instanties en bedrijven: Niet-naleving van algemene principes voor gegevensverwerking. 850.000 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +6 Telecommunications Fines Processing NL Apr 10, 2025
€3M Acea Energia S.p.A.: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 3,000,000 on Acea Energia S.p.A. The controller built a network of call centers that engaged in aggressive customer recovery and marketing… ITALY ·Garante ·Art. 5, 6, 7 +5 Controllers Direct Marketing Processing Agreement Apr 10, 2025
€4,000 Municipality of Ponte nelle Alpi: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 4,000 on the Municipality of Ponte nelli Apli. The controller has performed an evaluation of the performance of their employees. The… ITALY ·Garante ·Art. 5, 6 Controllers IP Address Employees Apr 10, 2025
€5M Luka Inc.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 5.000.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +3 AI Act Violations AI Act Formal Non-Compliance Minors NL Apr 10, 2025
€8,000 Undici S.r.l.s.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 8,000 on Undici S.r.l.s. The controller obtained personal data of potential customers by Realmaps S.r.l., which obtained the data in… ITALY ·Garante ·Art. 5, 6, 7 +6 Personal Data Direct Marketing Controllers Apr 10, 2025