Skip to content
Content type · 3,589 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

851–900 of 3,589 sort newestlargest fineoldest
€9,200 Diskrimineringsombudsmannen: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 9,200 on the Swedish Disrimination Ombudsman. The controller was unable to implement sufficient data security measures, resulting in the… SWEDEN ·IMY ·Art. 32 Security Controllers Education Apr 23, 2025
€1,200 FUNDACIÓ PRIVADA DE SERVEIS PER ALS USUARIS DEL HABITATGE SOCIAL DE CATALUNYA: Insufficient legal basis for data processing The Spanish DPA imposed a fine on FUNDACIÓ PRIVADA DE SERVEIS PER ALS USUARIS DEL HABITATGE SOCIAL DE CATALUNYA. The controller processed personal data without a sufficient legal… SPAIN ·AEPD ·Art. 6 Personal Data Controllers Supervisory Authorities Apr 22, 2025
€12,000 NOVATES ALIMENTACIÓN MADRID, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine on NOVATES ALIMENTACIÓN MADRID, S.L. The controller used surveillance cameras without implementing the necessary technical and organizational… SPAIN ·AEPD ·Art. 32 Security Controllers Privacy by Design & Default Apr 22, 2025
€12,000 NOVATES ALIMENTACIÓN MADRID, S.L.: Insufficient technical and organisational measures to ensure information security. ⇄ 12.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 32 Security Controllers Video Surveillance Apr 22, 2025
€20,000 Company: Non-compliance with general data processing principles The Belgian DPA imposed a fine of EUR 20,000 on a company. The controller is a company engaging in direct marketing activities. During those activies the company failed to comply… BELGIUM ·APD/GBA ·Art. 5, 6, 12 +4 Controllers Personal Data Marketing Apr 22, 2025
€4,000 AEPD: Continuous workplace audio recording violates GDPR data minimisation principle On 22 April 2025, a data subject lodged a complaint with the DPA against BODENSE ESTRUCTURAS Y CALDELERÍA, S.L., the controller. The data subject claimed that the controller had… Spain ·Art. 5 Retention Period Monitoring IP Address Apr 22, 2025
€1,200 ANDALUSIA INTEGRATION SERVICES: Insufficient legal basis for the processing of data. ⇄ 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6 Controllers Processing Consent Apr 22, 2025
€1,200 SERVICIOS DE INTEGRACIÓN DE ANDALUCÍA: Insufficient legal basis for data processing The Spanish DPA imposed a fine on SERVICIOS DE INTEGRACIÓN DE ANDALUCÍA. The controller hired an employee and processed the mobile phone number of the new employee without consent… SPAIN ·AEPD ·Art. 6 Controllers Consent Employees Apr 22, 2025
€7,800 Funeral Home: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined a funeral home EUR 7,800. The funeral home failed to implement sufficient technical and organisational measures to prevent a data breach. The funeral home… POLAND ·UODO ·Art. 5 Security Controllers Personal Data Apr 15, 2025
€2,000 United Business Solutions SRL: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Apr 15, 2025
€600 SPAIN, DPA: Non-compliance with the general principles of data processing. ⇄ 600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). AEPD ·Art. 5 ·Non-compliance with general data processing principles Controllers Processing Accountability Apr 15, 2025
€600 SPAIN DPA: Non-compliance with general data processing principles The Spanish DPA imposed a fine on an unknown data controller. The controller stored full copies of personal IDs for verification purposes. In this case, storing all the… AEPD ·Art. 5 ·Non-compliance with general data processing principles Retention Period Controllers Processing Apr 15, 2025
€260,000 CAMERDATA, S.A.: Insufficient legal basis for the processing of data. ⇄ Een boete van 260.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6, 14 Personal Data Processing Supervisory Authorities Apr 15, 2025
€2,000 United Business Solutions SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on United Business Solutions SRL. The controller failed to implement sufficient technical and organisational measuresto ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Apr 15, 2025
€260,000 CAMERDATA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 260,000 on CAMERDATA, S.A. The controller operates a database in which it collects data on individual entrepreneurs from the Spanish… SPAIN ·AEPD ·Art. 6, 14 Controllers Personal Data Supervisory Authorities Apr 15, 2025
€7,800 Funeral company: insufficient technical and organisational measures to ensure information security. ⇄ Een boete van €7.800 - van het Poolse Nationaal Bureau voor de Bescherming van Persoonlijke Gegevens (UODO). POLAND ·UODO ·Art. 5 Security Controllers Processing Apr 15, 2025
€500,000 Chamber of Commerce, Industry, Services and Navigation of Spain: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500,000 on the Chamber of Commerce, Industry, Services and Navigation of Spain. Due to its function within the Spanish Executive, the… AEPD ·Art. 5, 6, 14 ·Insufficient legal basis for data processing Integrity and Confidentiality Principle Controllers Retention Period Apr 15, 2025
€3,000 EDA TV CONSULTING, S.L.: Infringement of the general principles for data processing. ⇄ Boete van 3.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Processing Accountability Apr 14, 2025
€6,000 LÄSER METALPRINT 3D, S.L.: Insufficient data processing agreement. ⇄ Boete van 6.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 28 Controllers Processors Processing Apr 14, 2025
€1,000 Office Nova Concept SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Office Nova Concept SRL. The controller failed to respond adequately to a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 15, 17 +1 Personal Data Controllers Supervisory Authorities Apr 14, 2025
€6,000 LÃSER METALPRINT 3D, S.L.: Insufficient data processing agreement The Spanish DPA imposed a fine on LÃSER METALPRINT 3D, S.L. The controller hired a third company to install and maintain a surveillance system. The controller and the hired… SPAIN ·AEPD ·Art. 28 Controllers Processors Supervisory Authorities Apr 14, 2025
€70,300 DPP Law Ltd.: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has imposed a fine of £ 60,000 (EUR 70,300) on the law firm DPP Law Ltd. The controller had suffered a cyber attack during which personal data of 791 clients and… UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Controllers Security Personal Data Apr 14, 2025
€3,000 EDA TV CONSULTING, S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on EDA TV CONSULTING, S.L. The controller had stored copies of personal IDs to verify the identity of data subjects. According to the DPA, the… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Personal Data Apr 14, 2025
€1,000 Office Nova Concept SRL: Insufficient compliance with data subjects' rights. ⇄ Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15, 17 +1 Personal Data Supervisory Authorities Processing Apr 14, 2025
€2,000 NEW GAMBLING SOLUTIONS S.R.L.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Apr 11, 2025
€2,000 NEW GAMBLING SOLUTIONS S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on NEW GAMBLING SOLUTIONS S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Apr 11, 2025
€15,000 Tensa Art Design S.A.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 15.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 12, 15 +1 Personal Data Processing Supervisory Authorities Apr 10, 2025
€8,000 Eastern Parma Apennine Mountain Community: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 8,000 on the Eastern Parma Apennine Mountain Community. The controller had set up video surveillance in front of a police station, that… ITALY ·Garante ·Art. 5, 6, 12 +2 Monitoring Controllers Supervisory Authorities Apr 10, 2025
€5M Luka Inc.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 5,000,000 on Luka Inc. The developer created a chatbot called Replika with a written and voice interface. It is based on a generative AI… ITALY ·Garante ·Art. 5, 6, 12 +3 Controllers Personal Data Supervisory Authorities Apr 10, 2025
€3M Acea Energia S.p.A.: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 3,000,000 on Acea Energia S.p.A. The controller built a network of call centers that engaged in aggressive customer recovery and marketing… ITALY ·Garante ·Art. 5, 6, 7 +5 Controllers Processing Supervisory Authorities Apr 10, 2025
€3M Acea Energia S.p.A.: Insufficient legal basis for the processing of data. ⇄ 3.000.000 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +5 Controllers Processing Marketing Apr 10, 2025
€5M Luka Inc.: Non-compliance with the general principles of data processing. ⇄ Een boete van 5.000.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +3 Controllers Processing Supervisory Authorities Apr 10, 2025
€5,000 Patronage and Assistance for Citizens and Agriculture Board: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 5,000 on Patronage and Assistance for Citizens and Agriculture Board. The controller has stored personal data of a data subject for a… ITALY ·Garante ·Art. 5, 6 Personal Data Controllers Processing Apr 10, 2025
€8,000 Undici S.r.l.s.: Non-compliance with the general principles of data processing. ⇄ Een boete van 8.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +6 Marketing Controllers Processing Apr 10, 2025
€4,000 Municipality of Ponte nelle Alpi: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 4,000 on the Municipality of Ponte nelli Apli. The controller has performed an evaluation of the performance of their employees. The… ITALY ·Garante ·Art. 5, 6 Controllers Processing Public Authority Apr 10, 2025
€15,000 Immobiliare Valdalpone S.r.l.: Non-compliance with the general principles for data processing. ⇄ Een boete van 15.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +8 Marketing Controllers Processing Apr 10, 2025
€8,000 Community of the Eastern Apennines in Parma: Non-compliance with the general principles of data processing. ⇄ 8.000 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +2 Controllers Processing Supervisory Authorities Apr 10, 2025
€4,000 Municipality of Ponte nelle Alpi: Insufficient legal basis for data processing. ⇄ Een boete van 4.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Controllers Processing Accountability Apr 10, 2025
€850,000 Network of Agencies and Companies: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 850,000 on a network of agencies and companies. The network operated on behalf of Acea Energia S.p.A. and engaged in aggresive customer… ITALY ·Garante ·Art. 5, 6, 7 +6 Supervisory Authorities Processing Agreement Processing Apr 10, 2025
€850,000 Network of agencies and companies: Non-compliance with general data processing principles. ⇄ 850.000 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +6 Processing Supervisory Authorities Marketing Apr 10, 2025
€15,000 Immobiliare Valdalpone S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on Immobiliare Valdalpone S.r.l. The controller obtained personal data of potential customers by Realmaps S.r.l., which obtained… ITALY ·Garante ·Art. 5, 6, 7 +8 Direct Marketing Personal Data Controllers Apr 10, 2025
€5,000 Board for Support to Citizens and Agriculture: Insufficient legal basis for data processing. ⇄ Een boete van 5.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Retention Period Storage Limitation Personal Data Apr 10, 2025
€15,000 Tensa Art Design S.A.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 15,000 on Tensa Art Design S.A. The controller contacted a data for direct marketing purposes without consent. The controller also… ROMANIA ·ANSPDCP ·Art. 6, 12, 15 +1 Personal Data Marketing Controllers Apr 10, 2025
€8,000 Undici S.r.l.s.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 8,000 on Undici S.r.l.s. The controller obtained personal data of potential customers by Realmaps S.r.l., which obtained the data in… ITALY ·Garante ·Art. 5, 6, 7 +6 Personal Data Controllers Marketing Apr 10, 2025
€5,000 Gynecologist: Insufficient compliance with the information obligation. ⇄ Een boete van €5.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 15 Supervisory Authorities Personal Data Right of Access Apr 9, 2025
€600 FEDERACION DE COLUMBICULTURA DE CASTILLA-LA MANCHA: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine on FEDERACION DE COLUMBICULTURA DE CASTILLA-LA MANCHA. The controller was unable to ensure the confidentiality of personal data, which resulted in a… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Controllers Apr 9, 2025
€5,000 Gynaecologist: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 5,000 on a gynaecologist. The controller failed to completely fullfill an information request by a patient. GREECE ·HDPA ·Art. 15 Controllers Supervisory Authorities Healthcare Apr 9, 2025
€14M AMADEUS IT GROUP, S.A.: Insufficient legal basis for data processing Spanish Data Protection Authority (aepd) fined AMADEUS IT GROUP, S.A. €14,400,000 on 2025-04-07 for: Insufficient legal basis for data processing. Spain ·AEPD ·Art. 6, 14 Supervisory Authorities Processing Apr 7, 2025
€120,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on BANCO BILBAO VIZCAYA ARGENTARIA, S.A. A customer of the bank had lodged a complaint with the DPA because the controller had signed a data… SPAIN ·AEPD ·Art. 6 Controllers Consent Insurance Apr 4, 2025
€120,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Insufficient legal basis for the processing of data. ⇄ Een boete van 120.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6 Consent Processing Supervisory Authorities Apr 4, 2025