Skip to content
Content type · 139 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–100 of 139 sort newestlargest fineoldest
€80,000 SENDING TRANSPORTE Y COMUNICACIÓN, S.A.: Insufficient agreement regarding data processing. ⇄ Een boete van 80.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 28 Controllers Processors Processing Oct 22, 2025
AEPD · PS-00140-2025 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In… PS-00140-2025 ·Spain ·Art. 5, 9, 24 +2 Data Breaches Notification Obligation Integrity and Confidentiality Principle Oct 10, 2025
€4,000 CREMA GAMES, S.L.: Insufficient compliance with information obligations. ⇄ Een boete van 4.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 15 Personal Data Controllers Right of Access Mar 28, 2025
€4,000 CREMA GAMES, S.L.: Insufficient fulfilment of information obligations The Spanish DPA imposed a fine on CREMA GAMES, S.L. The controller failed to fulfill an information request from an online customer. The controller asked the data subject for an… SPAIN ·AEPD ·Art. 15 Personal Data Controllers Supervisory Authorities Mar 28, 2025
€3.5M Advanced Computer Software Group Ltd: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined Advanced Computer Software Group Ltd £3.07 million (EUR 3.5 million) for insufficient IT security (infringiment of Art. 32 (1) UK GDPR). The controller… UNITED KINGDOM ·ICO ·Art. 32 Security Controllers Personal Data Mar 26, 2025
€45M Vodafone GmbH: Non-compliance with general data processing principles The Federal Commissioner for Data Protection and Freedom of Information (BfDI) has imposed a fine of EUR 45,000,000 on Vodafone GmbH. The controller failed to properly supervise a… BfDI Processors Controllers Personal Data Jan 1, 2025
€1M LIGA NACIONAL DE FÚTBOL PROFESIONAL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1 million on LIGA NACIONAL DE FÚTBOL PROFESIONAL. The controller had introduced access controls for visitors to football stadiums using… SPAIN ·AEPD ·Art. 35 DPIA Controllers Security Dec 20, 2024
€75,000 Azienda ospedale università di Padova: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 75,000 on Azienda ospedale università di Padova. During its investigation, the DPA found that employees had accessed patient files… ITALY ·Garante ·Art. 5, 9, 25 +1 Controllers Healthcare Processing May 9, 2024
€5,000 CENTRUL MEDICAL UNIREA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on CENTRUL MEDICAL UNIREA SRL. The controller had suffered a data breach in which personal data of patients and employees were… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 8, 2024
Following an investigation in 2019-2020, the EDPS issued recommendations and the Commission modified the ILA The EDPS investigated whether these modifications were sufficient to bring processing in compliance with data protection requirements and found infringements. Data accessed by… 2021-0518 ·European Union ·Art. 5, 6, 28 +1 International Transfer Controllers Legitimate Interest Mar 8, 2024
€2,000 Bar: Non-compliance with general data processing principles The Italian DPA has fined the owner of a bar EUR 2,000. The controller had operated video surveillance cameras in one of their premises without the required authorization.… ITALY ·Garante ·Art. 5, 13, 114 Personal Data Controllers Processing Mar 7, 2024
€5,000 EURO MINI STORAGE ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of 5,000 euros on EURO MINI STORAGE ROMANIA SRL. The controller had suffered a data breach in which customer data was accessed without… ANSPDCP ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Mar 5, 2024
€3,000 VESTA CEU ROMÂNIA SRL.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on VESTA CEU ROMÂNIA SRL. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Feb 26, 2024
€800,000 NTT Data Italia S.P.A: Insufficient fulfilment of data breach notification obligations The Italian DPA has imposed a fine of EUR 800,000 on NTT Data Italia S.P.A. The fine is related to the fine imposed on UniCredit (ETid-2227). UniCredit had contracted NTT to carry… ITALY ·Garante ·Art. 28, 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Feb 8, 2024
€20,000 Pharmaceutical wholesaler: €20,000 fine The French DPA has imposed a fine of EUR 20,000 on a pharmaceutical wholesaler due to violations of several regulations, including a lack of data security and insufficient… FRANCE ·CNIL ·Unknown Controllers Accountability Processors Jan 24, 2024
€40,000 Azienda socio sanitaria territoriale nord Milano, C.F.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 40,000 on Azienda socio sanitaria territoriale nord Milano, C.F.. During its investigation, the DPA found that a patient's spouse had… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Processing Supervisory Authorities Dec 7, 2023
€3,000 A R.L Spartan Gym: Non-compliance with general data processing principles The Italian DPA has fined A R.L Spartan Gym EUR 3,000. The controller had operated video surveillance cameras in one of their premises without the required authorization.… ITALY ·Garante ·Art. 5, 13, 114 Personal Data Controllers Processing Nov 30, 2023
€20,000 FORO ASTURIAS: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 20,000 on FORO ASTURIAS. An individual had filed a complaint with the DPA due to the fact that personal data stored by the controller had… SPAIN ·AEPD ·Art. 5, 32 Personal Data Controllers Processing Nov 16, 2023
€110,000 Rompetrol Downstream SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 110,000 on Rompetrol Downstream SRL. The controller had suffered a data breach in which customer data was repeatedly accessed and used… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Controllers Nov 13, 2023
€3M Trygg-Hansa: Non-compliance with general data processing principles The Swedish DPA has fined Trygg-Hansa EUR 3 million for serious data security breaches. The security breach was discovered when a recipient of an email from Trygg-Hansa realized… SWEDEN ·Art. 5, 32 ·Non-compliance with general data processing principles Security Personal Data Identification Aug 28, 2023
€1,000 Prodav srl: Non-compliance with general data processing principles The Italian DPA has fined Prodav srl EUR 1,000. The controller had operated video surveillance cameras in one of their shops without the required authorization. Furthermore, the… ITALY ·Garante ·Art. 5, 13, 114 Personal Data Controllers Processing Jul 18, 2023
€5,000 Ristorante Francesco srl: Non-compliance with general data processing principles The Italian DPA has fined Ristorante Francesco srl EUR 5,000. The controller had operated video surveillance cameras in its premises without the required authorization.… ITALY ·Garante ·Art. 5, 13, 114 Personal Data Controllers Processing Jul 6, 2023
€13,400 Sjúkratyringur Íslands: Insufficient technical and organisational measures to ensure information security The Icelandic DPA has imposed a fine of EUR 13,400 on Sjúkratyringur Íslands. During its investigation, the DPA found that the controller had failed to implement adequate… ICELAND ·Persónuvernd ·Art. 5, 25, 32 Security Privacy by Design & Default Controllers Jun 28, 2023
€2.3M Debt collection agency: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 2,265,000 on a debt collection agency. The fine is the highest ever imposed by AZOP. AZOP had received an anonymous complaint in… CROATIA ·AZOP ·Art. 6, 13, 28 +1 Controllers Personal Data Processors May 4, 2023
€20,000 Company: Non-compliance with general data processing principles The Lithuanian DPA has fined a company EUR 20,000. The company had suffered a data breach in which personal data of 50,000 data subjects were compromised. During its… LITHUANIA ·VDAI ·Art. 5, 32 Retention Period Storage Limitation Security Apr 20, 2023
€3,000 Store owner: Non-compliance with general data processing principles The Italian DPA has fined a store owner EUR 3,000. The controller had operated video surveillance cameras in its premises without the required authorization. Furthermore, the DPA… ITALY ·Garante ·Art. 5, 13, 114 Personal Data Controllers Processing Mar 9, 2023
€50,000 H&M Hennes & Mauritz s.r.l. EUR 50,000: Non-compliance with general data processing principles The Italian DPA has fined H&M Hennes & Mauritz s.r.l. EUR 50,000. H&M had installed numerous video surveillance systems in its Italian stores for the purpose of preventing theft… ITALY ·Garante ·Art. 5, 114 Processing Video Surveillance Monitoring Mar 2, 2023
€460,000 Centric Health Ltd.: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 460,000 on Centric Health Ltd.. The controller suffered a ransomware attack in which personal data such as name, date of birth and contact… IRELAND ·DPC ·Art. 5, 32 Security Controllers Personal Data Jan 23, 2023
Company: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine on a company. The controller had installed video cameras in the offices and monitored employees before, during and after their working hours… GERMANY ·Insufficient legal basis for data processing Employees Controllers Access Controls Jan 1, 2023
€6,000 Store owner (Joy Unique Collection): Insufficient fulfilment of information obligations The Italian DPA has fined the owner of the store 'Joy Unique Collection' EUR 6,000 . The controller had operated video surveillance cameras in its premises without the required… ITALY ·Garante ·Art. 5, 13, 114 Personal Data Controllers Processing Dec 1, 2022
€3,000 Store owner (Woolen): Insufficient fulfilment of information obligations The Italian DPA has fined the owner of the store 'Woolen' EUR 3,000 . The controller had operated video surveillance cameras in its premises without the required authorization.… ITALY ·Garante ·Art. 5, 13, 114 Personal Data Controllers Processing Dec 1, 2022
€1,000 Medicover S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Medicover S.R.L.. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Personal Data Security Nov 24, 2022
€20,000 ING Bank NV Amsterdam Sucursala București: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on ING Bank NV Amsterdam Sucursala București. The bank had reported a data breach to the DPA pursuant to Art. 33 GDPR. Several… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Personal Data Nov 21, 2022
DKK 500,000 Danish DPA fines Sirius Lawyers DKK 500,000 for inadequate security after hacker attack A law firm was exposed to a hacker attack. Thereby, hackers received access to the firm's servers that contained personal data and encrypted them. This posed a serious risk that… Denmark ·Datatilsynet (DK) ·Art. 5, 9, 24 +2 Integrity and Confidentiality Principle Supervisory Authorities Encryption
€800 Company: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 800 on a company. The controller had installed video surveillance cameras without obtaining authorization for the installation. In… SPAIN ·AEPD ·Art. 6, 13 Controllers Supervisory Authorities Video Surveillance Oct 9, 2022
NAIH: School grades are personal data; failure to provide access in eKRÉTA system A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Hungary ·Art. |, 10, 28 +1 Personal Data Right of Access Controllers Sep 22, 2022
€5,000 EDYTE SA: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 5,000 on EDYTE SA. EDYTE, as a processor, had unlawfully disclosed personal data to third parties without the authorization of the data… GREECE ·HDPA ·Art. 29 Controllers Processors Personal Data Sep 6, 2022
€20,000 Intesa Sanpaolo Vita S.p.a.: Non-compliance with general data processing principles The Italian DPA has fined Intesa Sanpaolo Vita S.p.a. EUR 20,000. The data subject, who had taken out a life insurance policy with the controller, had filed a complaint with the… ITALY ·Garante ·Art. 5 Personal Data Controllers Processing Jul 7, 2022
€1,500 Wens Experience SRL: Insufficient data processing agreement The Romanian DPA has imposed a fine of EUR 1,500 on Wens Experience SRL. In the course of its investigation, the DPA found that Wens Experience, in the course of acting as a… ROMANIA ·ANSPDCP ·Art. 28 Processors Controllers Supervisory Authorities Jun 8, 2022
€100,000 Intesa Sanpaolo S.p.A: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 100,000 on Intesa Sanpaolo S.p.A.. The bank had unlawfully disclosed data of the data subject to unauthorized third parties (the father… ITALY ·Garante ·Art. 5, 6 Personal Data Processing Insurance May 26, 2022
€50 Belgian DPA: Roularta Media Group violated cookie consent rules On 16 January 2019, the Executive-committee of the Belgian DPA (GBA) started an investigation on the use of cookies on Belgian media websites. The controller in this case is… Belgium ·APD/GBA ·Art. 4, 5, 6 +3 Consent Supervisory Authorities Personal Data May 25, 2022
€10M Google LLC: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 10 million on GOOGLE LLC. Two data subjects had complained to the DPA that Google had disclosed their personal data to third… SPAIN ·AEPD ·Art. 6, 17 Right to be Forgotten Personal Data Data Subject Rights Exercise Modalities and Procedures May 18, 2022
€5,000 Kredyt Inkaso Investments RO S.A: Insufficient legal basis for data processing The Romanian DPA has fined Kredyt Inkaso Investments RO S.A. EUR 5,000. A data subject had filed a complaint with the DPA against the controller for having disclosed their… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 +1 Data Breaches Personal Data Controllers May 18, 2022
€10,000 Italian Ministry of Defense: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on the Italian Ministry of Defense. An employee of the ministry had filed a complaint with the DPA. During its investigation, the… ITALY ·Garante ·Art. 2, 5, 6 +2 Personal Data Healthcare Processing Apr 28, 2022
€1.5M DEDALUS BIOLOGIE: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) has imposed a fine of EUR 1.5 million on DEDALUS BIOLOGIE. DEDALUS distributes software solutions for medical analysis laboratories. In February, the press… FRANCE ·CNIL ·Art. 28, 29, 32 Security Encryption Personal Data Apr 15, 2022
€10,000 Tecnomed Trento s.r.l.: Non-compliance with general data processing principles The Italian DPA has fined Tecnomed Trento s.r.l. EUR 10,000. The controller had operated several video surveillance cameras in its premises, some of them without the required… ITALY ·Garante ·Art. 5, 13, 29 +2 Integrity and Confidentiality Principle Personal Data Controllers Apr 7, 2022
€195,000 Norwegian Parliament: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has fined the Norwegian Parliament EUR195,000. The parliament had suffered a data breach in which unauthorized persons gained access to the email accounts of… NORWAY ·Datatilsynet (NO) ·Art. 5, 32 Security Personal Data Identification Mar 4, 2022
€6,000 Private individual: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 6,000 on a private individual. The data subject had filed a complaint against the data controller for publishing images of herself… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Access Controls Feb 16, 2022
EDPS: European Parliament is sole controller for COVID testing website and failed In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Controllers Processors IP Address Jan 5, 2022