Skip to content
Content type · 3,651 documents

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

851–900 of 3,651 sort newestlargest fineoldest
€15,000 Tensa Art Design S.A.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 15,000 on Tensa Art Design S.A. The controller contacted a data for direct marketing purposes without consent. The controller also… ROMANIA ·ANSPDCP ·Art. 6, 12, 15 +1 Direct Marketing Controllers Marketing Apr 10, 2025
€5M Luka Inc.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 5,000,000 on Luka Inc. The developer created a chatbot called Replika with a written and voice interface. It is based on a generative AI… ITALY ·Garante ·Art. 5, 6, 12 +3 AI Act Formal Non-Compliance AI Act Violations Artificial Intelligence Apr 10, 2025
€4,000 Municipality of Ponte nelle Alpi: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 4,000 on the Municipality of Ponte nelli Apli. The controller has performed an evaluation of the performance of their employees. The… ITALY ·Garante ·Art. 5, 6 Controllers IP Address Employees Apr 10, 2025
€5,000 Patronage and Assistance for Citizens and Agriculture Board: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 5,000 on Patronage and Assistance for Citizens and Agriculture Board. The controller has stored personal data of a data subject for a… ITALY ·Garante ·Art. 5, 6 Personal Data Public Authority Education Apr 10, 2025
€4,000 Gemeente Ponte nelle Alpi: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 4.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Processing Data Controller Controllers NL Apr 10, 2025
€5,000 Gynaecoloog: Onvoldoende nakoming van de informatieplicht. Een boete van €5.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 15 Health Data Personal Data Healthcare NL Apr 9, 2025
€5,000 Gynaecologist: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 5,000 on a gynaecologist. The controller failed to completely fullfill an information request by a patient. GREECE ·HDPA ·Art. 15 Healthcare Controllers Supervisory Authorities Apr 9, 2025
€600 FEDERACION DE COLUMBICULTURA DE CASTILLA-LA MANCHA: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine on FEDERACION DE COLUMBICULTURA DE CASTILLA-LA MANCHA. The controller was unable to ensure the confidentiality of personal data, which resulted in a… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Personal Data Apr 9, 2025
€14M AMADEUS IT GROUP, S.A.: Insufficient legal basis for data processing Spanish Data Protection Authority (aepd) fined AMADEUS IT GROUP, S.A. €14,400,000 on 2025-04-07 for: Insufficient legal basis for data processing. Spain ·aepd ·Art. 6, 14 Processing Supervisory Authorities Apr 7, 2025
€120,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on BANCO BILBAO VIZCAYA ARGENTARIA, S.A. A customer of the bank had lodged a complaint with the DPA because the controller had signed a data… SPAIN ·aepd ·Art. 6 Controllers Insurance Processing Agreement Apr 4, 2025
€360 SINDICAT CATAC-CTSC: Onvoldoende samenwerking met de toezichthoudende instantie. Een boete van 360 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 58 Supervisory Authorities Controllers Supervision NL Apr 4, 2025
€120,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 120.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6 Processing Consent Processing Agreement NL Apr 4, 2025
€360 SINDICAT CATAC-CTSC: Insufficient cooperation with supervisory authority The Spanish DPA imposed a fine of on SINDICAT CATAC-CTSC. The controller failed to react to a communication attempt by the AEPD. The original fine of EUR 600 was reduced to EUR… SPAIN ·aepd ·Art. 58 Supervision Supervisory Authorities Law Enforcement Apr 4, 2025
€600 Owner of a Law Firm: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine on the owner of a law firm. The controller disclosed personal information in an external email because they did not implement sufficient technical… SPAIN ·aepd ·Art. 5 Security Controllers Processing Agreement Apr 3, 2025
€5,000 Banca Transilvania S.A.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 5,000 on Banca Transilvania S.A. The controller forwarded client data to an insurance company without a sufficient legal basis. ROMANIA ·ANSPDCP ·Art. 5, 6 Insurance Processing Agreement Controllers Apr 3, 2025
€5,000 Banca Transilvania S.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Data Controller Processing NL Apr 3, 2025
€3,000 BINBOX GLOBAL SERVICES S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on BINBOX GLOBAL SERVICES S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure data… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Telecommunications Apr 2, 2025
€3,000 BINBOX GLOBAL SERVICES S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Telecommunications NL Apr 2, 2025
€20,000 Hospital: Non-compliance with general data processing principles Data Protection Commissioner of Malta fined Hospital €20,000 on 2025-04-02 for: Non-compliance with general data processing principles. Malta ·Art. 5, 6, 14 +2 ·Non-compliance with general data processing principles IP Address Healthcare Healthcare Apr 2, 2025
€3,500 MAD COOL FESTIVAL S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 3,500 on MAD COOL FESTIVAL S.L. The controller suffered a data breach due to insufficient technical and organizational measures.… SPAIN ·aepd ·Art. 5, 32 Data Breaches Security Processing Agreement Mar 30, 2025
€3,500 MAD COOL FESTIVAL S.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van €3.500 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 32 Security Data Breaches Data Controller NL Mar 30, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on SERVICIOS ESPECIALES, S.A. The case concerned a GDPR breach during an internal workplace conflict investigation: the company shared a report via… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy Employees Mar 28, 2025
€4,000 CREMA GAMES, S.L.: Onvoldoende nakoming van de informatieverplichtingen. Een boete van 4.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 15 Controllers Data Controller Personal Data NL Mar 28, 2025
€4,000 CREMA GAMES, S.L.: Insufficient fulfilment of information obligations The Spanish DPA imposed a fine on CREMA GAMES, S.L. The controller failed to fulfill an information request from an online customer. The controller asked the data subject for an… SPAIN ·aepd ·Art. 15 Controllers Telecommunications Personal Data Mar 28, 2025
€6,600 GRUAS IGNACI, S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on GRUAS IGNACI, S.L. The controller uses too much data to verify a person's identity, which breaches the principle of data minimization.… SPAIN ·aepd ·Art. 5, 13, 32 Video Surveillance Controllers IP Address Mar 28, 2025
€6,600 GRUAS IGNACI, S.L.: Overtreding van de algemene principes voor gegevensverwerking. Boete van 6.600 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 13, 32 Video Surveillance Security Controllers NL Mar 28, 2025
€21,600 SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed fine on SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L. The controller offers fitness courses which are recorded and published. The consent obtained for the… SPAIN ·aepd ·Art. 5, 7, 28 Storage Limitation Retention Period Controllers Mar 28, 2025
€12,000 ESTUDIO ALCAZAR DEL GENIL 2022, S.L.: Onvoldoende juridische basis voor de verwerking van gegevens. 12.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6, 14 Data Controller Processing Controllers NL Mar 28, 2025
€12,000 ESTUDIO ALCAZAR DEL GENIL 2022, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine on ESTUDIO ALCAZAR DEL GENIL 2022, S.L. The controller collected property data by having its employees visit and photograph the properties,… SPAIN ·aepd ·Art. 6, 14 Controllers Personal Data Processing Agreement Mar 28, 2025
€21,600 SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 21.600 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 7, 28 Education Processing Storage Limitation NL Mar 28, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 120.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Professional Secrecy Processing Integrity and Confidentiality Principle NL Mar 28, 2025
€3,000 Municipality of Palma di Montechiaro: Lack of appointment of data protection officer The Italian DPA has imposed a fine of EUR 3,000 on the Municipality of Palma di Montechiaro. The controller failed to appoint a DPO and report the DPO to the DPA. ITALY ·Garante ·Art. 37 Supervisory Authorities Public Authority Public Sector Mar 27, 2025
€3,000 Gemeente Palma di Montechiaro: Gebrek aan benoeming van een functionaris voor gegevensbescherming. Een boete van 3.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 37 Public Authority Education Supervisory Authorities NL Mar 27, 2025
€4,000 Istituto di Istruzione Superiore 'P. Galluppi' Tropea: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,500 on the Istituto di Istruzione Superiore 'P. Galluppi' Tropea. The controller processed biometric data of its employees to control… ITALY ·Garante ·Art. 5, 6, 9 Fairness & Transparency Employees Controllers Mar 27, 2025
€18,000 Multiple Companies: Insufficient legal basis for data processing The Italian DPA imposed fines on 3 companies which ammount to EUR 6,000 each. The fined companies (Powerfit s.s.d.a.r.l., Soleo s.s.d.a.r.l. and Zero Due Villa s.s.d.a.r.l.) run a… ITALY ·Garante ·Art. 5, 6, 12 +1 Right to be Forgotten Fines Direct Marketing Mar 27, 2025
€18,000 Meerdere bedrijven: Onvoldoende juridische basis voor gegevensverwerking. Een boete van €18.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +1 Processing Right to be Forgotten Consent NL Mar 27, 2025
€4,000 Istituto di Istruzione Superiore 'P. Galluppi' Tropea: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 4.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 Processing Special Categories of Data Fairness & Transparency NL Mar 27, 2025
€3.5M Advanced Computer Software Group Ltd: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined Advanced Computer Software Group Ltd £3.07 million (EUR 3.5 million) for insufficient IT security (infringiment of Art. 32 (1) UK GDPR). The controller… UNITED KINGDOM ·ICO ·Art. 32 Security Access Controls Healthcare Mar 26, 2025
€25,000 NTT DATA ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on NTT DATA ROMANIA S.A. The controller failed to implement sufficient technical and organisational measures, resulting in a data… ANSPDCP ·Art. 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processing Agreement Mar 25, 2025
€25,000 NTT DATA ROMANIA S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processing NL Mar 25, 2025
€17,600 Chief Commander of the Police: Insufficient legal basis for data processing The Polish DPA has fined the Chief Commander of the Polish Police EUR 17,600. During a press conference, the Chief Commander of the Police disclosed the personal and medical data… POLAND ·UODO ·Art. 6, 9 Healthcare Health Data Healthcare Mar 24, 2025
€4,000 Ziekenhuis: Niet-naleving van de algemene principes voor gegevensverwerking. 4.000 euro boete - Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·azop ·Art. 13, 14, 25 +1 Health Data Healthcare Personal Data NL Mar 24, 2025
€3,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croation DPA (AZOP) has imposed a fine of EUR 3,000 on a hospital. Despite the extensive and high-risk processing of health data, the hospital had not implemented sufficient… CROATIA ·azop ·Art. 13, 32, 33 +1 Health Data Integrity and Confidentiality Principle Healthcare Mar 24, 2025
€4,000 Hospital: Non-compliance with general data processing principles The Croation DPA (AZOP) has imposed a fine of EUR 4,000 on a hospital. The AZOP found that the hospital used a company which automatically retrieved personal data of vehicle… CROATIA ·azop ·Art. 13, 14, 25 +1 Fines Healthcare Healthcare Mar 24, 2025
€80,000 Company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 80,000 on a company. The company was responsible for monitoring parking lots at several supermarkets and a hospital. However, it… CROATIA ·azop ·Art. 5, 6, 32 Audit Logs Processing Agreement Monitoring Mar 24, 2025
€20,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) imposed a fine of EUR 20,000 on a hospital for failing to implement adequate technical and organizational measures to protect personal data in line with… CROATIA ·azop ·Art. 32 Data Breaches Security Healthcare Mar 24, 2025
€10,000 Oil and fat manufacturer: Lack of appointment of data protection officer The Croatian DPA (AZOP) has imposed a fine of EUR 10,000 on an oil and fat manufacturer for for failing to appoint and designate a data protection officer. CROATIA ·azop ·Art. 37 Supervisory Authorities Processing Agreement Mar 24, 2025