Skip to content
Content type · 3,806 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–100 of 3,806 sort newestlargest fineoldest
Austrian DSB: e-marketplace transfer of customer data to China and US requires valid Art. The DPA was acting upon a complaint addressing the subject matter of third country personal data transfers. The controller, established in Ireland, operates an e-marketplace… D130.2269 ·Austria ·Art. 45, 46, 49 Privacy Shield Processing Agreement International Transfer Aug 25, 2026
Datatilsynet reprimands Danish Tax Administration for access request delays (2019-2024) In November 2024 the DPA started an investigation against the Danish Tax Administration (‘the controller’) for their processing time of access requests. 30 September 2025 the DPA… 2024-432-0039 ·Denmark ·Datatilsynet (DK) Right of Access Personal Data Supervisory Authorities
HDPA orders TEIRESIAS S.A. to ensure data accuracy under Art. 5(1)(d) GDPR 29 January 2023, the data subject requested TEIRESIAS S.A. (‘the controller’) to delete an entry registered in their database, and to correct the “erroneous financial data”… 4/2026 ·Greece ·Art. 5 Accuracy Personal Data Right to Restriction
€825M AP (The Netherlands) - Uber B.V and Uber Technologies Inc. Uber B.V. and Uber Technologies Inc., the controllers, used software between 2018 and 2022 to monitor drivers’ behaviour and customer ratings. Where the system detected suspected… Art. 22 Automated Decision-Making Profiling Controllers Aug 21, 2026
€825M Uber Technologies Inc.: Non-compliance with general data processing principles The Dutch Supervisory Authority for Data Protection (AP) fined Uber Technologies Inc. €824,990,000 for non-compliance with general data processing principles, specifically… The Netherlands ·AP ·Art. 13, 14, 22 Automated Decision-Making Supervision Profiling Aug 21, 2026
RON 15,728 Fine against Poliserv JG (PJG) SRL A personal data breach occurred because of a cyberattack made possible through a phishing method that stole the credentials of a controller account with administrator privileges.… Romania ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security
€280,000 Garante · 10269624 The controller is a publishing company that sells subscriptions to consumer information services through its website. Users can sign up by filling in a registration form on the… Italy ·Art. 6, 7, 12 +2 Right to Object Personal Data Direct Marketing
€3,000 Poliserv JG (PJG) SRL: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Poliserv JG (PJG) SRL €3,000 for failing to implement sufficient technical and… Romania ·ANSPDCP ·Art. 32 Security Personal Data Supervision Aug 19, 2026
€15,300 10266250 The data subject received unsolicited promotional phone calls and a email containing contractual information from Green Partner (the processor), despite the data subject's phone… Italy ·Garante ·Art. 5, 6, 7 +6 Processors Controllers Personal Data Aug 19, 2026
HDPA: Hellenic Open University found to have met breach notification duties after The Hellenic Open University (‘the controller’) submitted initial and supplementary notifications to the DPA after it was subject to a data breach resulting from a ransomware… 14/2026 ·Greece ·Art. 32, 33, 34 +1 Data Breaches Notification Obligation Integrity and Confidentiality Principle Aug 19, 2026
RON 285,395 AMATO BESTSELLER S.R.L. A general wholesale/retail trade company (controller) failed to implement adequate technical and organisational measures, such as appropriate training of its employees, in order… Romania ·ANSPDCP ·Art. 5, 9, 12 +2 Integrity and Confidentiality Principle Personal Data Retention Period Aug 18, 2026
An Italian broadcasting company (controller) disseminated an episode about the murder of a woman The murder case dates back several years but gained new attention after the investigation into the murder case was re-opened. In the dissemination, the interior of the home of the… 10273026 ·Italy ·Garante Personal Data Retention Period Right to be Forgotten Aug 18, 2026
Datatilsynet (DK) · 2023-31-0321 A customer of a bank ('the data subject'), suspected that their former spouse, who was employed by the same bank ('the controller'), was accessing their accounts and decided to… 2023-31-0321 ·Denmark ·Art. 12, 15 Right of Access Personal Data Controllers Aug 18, 2026
€1,000 Austrian DSB: Employee who shared customer's phone number acted as GDPR controller An employee (controller) of a company shared the telephone number of a costumer (data subject) with a third person. The third person who was a personal acquaintance of the… Austria ·Art. 4, 5, 6 +1 Controllers Legitimate Interest Personal Data Aug 18, 2026
€200,000 XFERA MÓVILES, S.A.U. (XFERA), the controller, is a telecommunications provider The data subject was a customer of the controller and held a mobile telephone line. On 24 July 2023, an unauthorised third party requested a duplicate SIM card for the data… ps-00148-2025 ·Spain ·AEPD Personal Data Legitimate Interest Controllers Aug 13, 2026
NOK 205,000 Datatilsynet ordered Lab Pharma AS to erase influencer's personal data used after Lab Pharma AS, the controller, is a Norwegian manufacturer of dietary supplements which markets and sells its products online. In 2016, an influencer, the data subject, entered… Norway ·Datatilsynet (NO) ·Art. 6, 17, 21 +1 Personal Data Legitimate Interest Controllers Aug 12, 2026
€1,282 IP-RS · 0609-41/2026/7 A company (the controller) used a service provider (the processor) to store personal data, manage a database, and provide technical support and maintenance on its behalf. A legal… Slovenia ·Art. 28 Processors Controllers Representatives
ICO (UK) - ACRO Criminal Records Office ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates,… ACRO Criminal Records Office ·United Kingdom ·Art. 32 Controllers Processors Accountability Aug 7, 2026
Finnish DPA finds 12-year retention of rental applicant data violates minimisation The DPA began investigating the storage periods of the personal data of housing applicants (the data subjects) contained in rental housing applications during a previous… TSV/1319/2025 ·Finland ·Tietosuojavaltuutettu Retention Period Storage Limitation Privacy by Design Aug 7, 2026
€45,000 AMATO BESTSELLER S.R.L: Non-compliance with general data processing principles The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined AMATO BESTSELLER S.R.L €45,000 for non-compliance with general data processing principles.… Romania ·ANSPDCP ·Art. 5, 9, 14 +1 Integrity and Confidentiality Principle Retention Period Supervision Aug 6, 2026
€1,000 Leontinoi Società Cooperativa Sociale: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) fined Leontinoi Società Cooperativa Sociale €1,000 for insufficient fulfilment of data subjects' rights, citing violations of… Italy ·Garante ·Art. 12, 15, 31 Supervisory Authorities Personal Data Supervision Aug 6, 2026
Finnish DPA examines anti-doping organization's GDPR compliance over public suspension An athlete (the data subject) gave a doping sample containing a low concentration of a banned substance in August 2020. The national anti-doping organisation (the controller)… TSV/179/2021 ·Finland ·Tietosuojavaltuutettu Supervisory Authorities Personal Data Retention Period Aug 4, 2026
HRK 940,000 Decision 08-03-2022 (energy company) The controller is a company that manages gas stations. The data subject tried to refuel at one of the controller's gas stations and was dissatisfied with the measurement of the… Croatia ·AZOP ·Art. 15 Right of Access Personal Data Controllers
€15,000 HOMELUX S.R.L: Non-compliance with general data processing principles The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined HOMELUX S.R.L €15,000 for non-compliance with general data processing principles,… Romania ·ANSPDCP ·Art. 32 Security Personal Data Supervision Jul 31, 2026
RON 523,900 Fine against Orange Romania SA of July 17, 2026 The investigation was initiated after Orange Romania SA (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR, related to its… ANSPDCP ·Art. 25, 32 Data Breaches Privacy by Design & Default Privacy by Design Jul 29, 2026
€200,000M 15/2026 The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information… Greece ·HDPA ·Art. 5, 28, 32 Controllers Data Breaches Integrity and Confidentiality Principle Jul 28, 2026
RON 30 Fine against There's an AI for that S.R.L In October 2025, the Romanian National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal –… Romania ·ANSPDCP ·Art. 4 Personal Data Consent Controllers
€5,000 PS/00421/2020 The client of a financial institution lodged a complaint before the Spanish DPA (AEPD) due to the delivery of a mail for commercial purposes, even though he had expressly rejected… Spain ·AEPD ·Art. 21 Right to Object Recipient Personal Data
HmbBfDI (Hamburg) - Einstellung Gerichtsverfahren in Sachen Videmo 360 Following the 2017 G20 summit in Hamburg, the Hamburg Police used automated facial recognition software to analyze video footage. A template database containing mathematical… Einstellung Gerichtsverfahren in Sachen Videmo 360 ·Germany Biometric Data Video Surveillance Types of Special Categories of Personal Data
€2,000 33/2020 The data subject was under the employment of the College for a certain period of time, during which two female students of the College filed a complaint against the complainant… Greece ·HDPA ·Art. 4, 5, 12 +8 Right to be Forgotten Personal Data Right of Access
€9.5M TIM S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined TIM S.p.A. €9,516,000 for violations of multiple GDPR provisions, including Articles 5, 6, 7, 15, 22, 24, 25, 28, and 32,… Italy ·Garante ·Art. 5, 6, 7 +6 Supervision Personal Data Supervisory Authorities Jul 23, 2026
€2,000 Ancel Keys Comprehensive School Castelnuovo Cilento: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Ancel Keys Comprehensive School Castelnuovo Cilento €2,000 for processing personal data without a sufficient legal basis,… Italy ·Garante ·Art. 5, 6, 9 Personal Data Public Authority Supervisory Authorities Jul 23, 2026
€10,000 Bologna University Hospital IRCCS: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Bologna University Hospital IRCCS €10,000 for processing personal data without a sufficient legal basis. The Garante found… Italy ·Garante ·Art. 5, 6, 9 Legitimate Interest Healthcare Types of Special Categories of Personal Data Jul 23, 2026
€6,500 Top Secrert Investigazioni e sicurezza s.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Top Secrert Investigazioni e sicurezza s.r.l. €6,500 for violating the general data processing principles under Article… Italy ·Garante ·Art. 5, 13 Retention Period Storage Limitation Processing Jul 23, 2026
€8,000 Municipality of Terralba: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of Terralba €8,000 for processing personal data without a sufficient legal basis. The Garante found that the… Italy ·Garante ·Art. 5, 6, 24 +2 Personal Data Processing Public Authority Jul 23, 2026
€30,000 Emiglia-Romagna Regional Employment Agency: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Emiglia-Romagna Regional Employment Agency €30,000 for violations of Articles 5, 6, and 9 of the GDPR concerning an… Italy ·Garante ·Art. 5, 6, 9 Legitimate Interest Personal Data Processing Jul 23, 2026
The case involves media company RTI S.p.a (the data controller, now part of Mediaset S.p.a.) and its popular TV program Striscia la Notizia. The program aired a segment consisting of satirical, AI-generated deepfakes of… Case number: 577/2026 Internal number (from the DPA): 10281021 ·Italy ·Garante Transparency Privacy by Design Controllers Jul 23, 2026
€9.5M Garante · 556/2026 Following numerous complaints and reports, the Italian DPA (Garante) investigated the telemarketing practices of TIM S.p.A. (the controller). The complaints concerned unsolicited… Italy ·Art. 5, 6, 7 +5 Personal Data Integrity and Confidentiality Principle Controllers Jul 23, 2026
€10,000 Monza and Brianza Local Education Authority: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Monza and Brianza Local Education Authority €10,000 for failing to establish a sufficient legal basis for data processing… Italy ·Garante ·Art. 5, 6 Personal Data Public Authority Supervision Jul 23, 2026
HUF 2M NAIH-11443-3/2026 The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The… Hungary ·Art. 12, 13 Legitimate Interest Personal Data Lawful Basis Jul 22, 2026
Finnish DPA: requesting address, ID number and strong authentication for access request A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022.… TSV/4630/2023 ·Finland ·Tietosuojavaltuutettu Identification Personal Data Supervisory Authorities Jul 22, 2026
€90,000 AEPD · PS-00159-2025 On 13 December 2024, the DPA received a complaint against ACVIL Aparcamientos, S.L.U., the controller, concerning a request for video surveillance footage from a car park. The… Spain ·Art. 14, 15 Right to Restriction Right of Access Controllers
€300,000 CNIL fines EXTIA for failing to properly handle job applicant erasure requests EXTIA, the controller, is a French consulting company specialising in IT and engineering services. As part of its recruitment activities, the controller processed personal data of… France ·Art. 12, 17 Right to be Forgotten Personal Data Right to Restriction Jul 21, 2026
€500,000 Hôpital privé de la Loire: Insufficient technical and organisational measures to ensure information security The French Data Protection Authority (CNIL) sanctioned Hôpital Privé de la Loire, a Ramsay Santé group hospital, following a June 2025 personal data breach in which an attacker… France ·CNIL ·Art. 32, 34 Data Breaches Notification Obligation Healthcare Jul 21, 2026
€12,000 Garante · 10254256 The data subject was an employee at a detention facility run by the Italian Ministry of Justice (the controller). Following an assessment by the occupational health physician, who… Italy ·Art. 4, 5, 6 +2 Personal Data Health Data Types of Special Categories of Personal Data
€20,000 Garante · 471/2026 The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Italy ·Art. 5, 6, 10 +1 Personal Data Retention Period Criminal Data Jul 18, 2026
BfDI · 4/2021 Both of the TKG and TMG are fundamental for the electronic communication and there are many regulations still written in both laws that are only partially or not valid at all.… 2021-02-18 - 4/2021 ·Germany Telecommunications Cookies Supervisory Authorities
€100,000 Orange Romania SA: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Orange Romania SA €100,000 for failing to implement sufficient technical and… ANSPDCP ·Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Privacy by Design Security Privacy by Design & Default Jul 17, 2026
APDCAT sanctions Madremanya City Council for inadequate redaction of sensitive data in On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing… PS-0036/2026 ·Spain ·Art. 5, 31 Integrity and Confidentiality Principle Personal Data Identification Jul 17, 2026
AEPD · EXP202103746 A complaint is filed against the controller for having six surveillance cameras facing public highway and private spaces without authorisation. In addition to the claim, there is… PS-00601-2021 ·Spain ·Art. 5, 12, 15 +3 Retention Period Access Controls Personal Data