Skip to content
Content type · 240 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–100 of 240 sort newestlargest fineoldest
€50,000 Magna PT S.p.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Data Controller NL Jul 10, 2025
€15,600 Kinderziekenhuis van de L. Zamenhof Universiteit in Białystok: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 15.600 euro boete - Poolse nationale instantie voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 32 Security Healthcare Health Data NL Jun 30, 2025
€7,000 Algemeen Ziekenhuis van de Universiteit van Larissa: Onvoldoende naleving van de rechten van betrokkenen. Een boete van €7.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 14, 15 Health Data Healthcare Personal Data NL Jun 24, 2025
€10,000 Shield of David - K.I.D.A.F.: Niet-naleving van algemene principes voor gegevensverwerking. Boete van €10.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 12, 13 +3 Personal Data Health Data Video Surveillance NL Jun 24, 2025
€2.7M 23andMe, Inc.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.700.000 euro - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32 Security Genetic Data Health Data NL Jun 5, 2025
€1.1M Universiteitsapotheek: Niet-naleving van algemene principes voor gegevensverwerking. 1.100.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 32 Health Data Processing Education NL May 27, 2025
€21,000 Menarini Silicon Biosystems SpA: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 21,000 on Menarini Silicon Biosystems SpA. The controller is conducting oncological research and has developed a software that is able to… ITALY ·Garante ·Art. 5, 13 Retention Period Healthcare Health Data May 21, 2025
€7,000 Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 7,000 on Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North. The controller… ITALY ·Garante ·Art. 5, 9 Health Data Healthcare Personal Data May 21, 2025
€21,000 Menarini Silicon Biosystems SpA: Niet-naleving van de algemene principes voor gegevensverwerking. 21.000 euro boete - Italiaanse Autoriteit voor de bescherming van persoonlijke gegevens (Garante). ITALY ·Garante ·Art. 5, 13 Health Data Healthcare Healthcare NL May 21, 2025
€5,000 Maravet S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Health Data NL May 19, 2025
€6,600 Eigenaar van een apotheek: Niet-naleving van algemene principes voor gegevensverwerking. Boete van 6.600 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6, 14, 32 Health Data Data Controller Processing NL May 9, 2025
€6,600 Eigenaar van een apotheek: Overtreding van de algemene principes van gegevensverwerking. Een boete van 6.600 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6, 14, 32 Health Data Data Controller Processing NL May 8, 2025
€40,000 Municipality of Bologna: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 40,000 on the Municipality of Bologna. The controller used a data processor (Cooperativa Sociale Quadrifoglio | ETid: 2274) to process… ITALY ·Garante ·Art. 5, 6, 9 Processors Controllers Security Apr 29, 2025
€20,000 Cooperativa Sociale Quadrifoglio: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio. The entity that was fined, acting as a data processor, forwarded files containing the… ITALY ·Garante ·Art. 28, 32 Processors Controllers Health Data Apr 29, 2025
€2,000 Ziekenhuis Tirrenia S.r.l.: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 12, 15 Personal Data Healthcare Health Data NL Apr 29, 2025
€20,000 Cooperativa Sociale Quadrifoglio: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 20.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 28, 32 Health Data Security Processors NL Apr 29, 2025
€40,000 Gemeente Bologna: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 40.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 Security Processors Health Data NL Apr 29, 2025
€7,800 Uitvaartonderneming: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €7.800 - van het Poolse Nationaal Bureau voor de Bescherming van Persoonlijke Gegevens (UODO). POLAND ·UODO ·Art. 5 Health Data Security Data Breaches NL Apr 15, 2025
€5,000 Gynaecoloog: Onvoldoende nakoming van de informatieplicht. Een boete van €5.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 15 Health Data Personal Data Healthcare NL Apr 9, 2025
€3,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croation DPA (AZOP) has imposed a fine of EUR 3,000 on a hospital. Despite the extensive and high-risk processing of health data, the hospital had not implemented sufficient… CROATIA ·azop ·Art. 13, 32, 33 +1 Integrity and Confidentiality Principle Healthcare Healthcare Mar 24, 2025
€17,600 Chief Commander of the Police: Insufficient legal basis for data processing The Polish DPA has fined the Chief Commander of the Polish Police EUR 17,600. During a press conference, the Chief Commander of the Police disclosed the personal and medical data… POLAND ·UODO ·Art. 6, 9 Health Data Healthcare Healthcare Mar 24, 2025
€4,000 Ziekenhuis: Niet-naleving van de algemene principes voor gegevensverwerking. 4.000 euro boete - Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·azop ·Art. 13, 14, 25 +1 Health Data Healthcare Personal Data NL Mar 24, 2025
€1,000 Velvet Medical SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Velvet Medical SRL. The controller failed to provide the data subject with the requested health data. ROMANIA ·ANSPDCP ·Art. 12, 15 Healthcare Health Data Healthcare Feb 27, 2025
€2,000 Medstar S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 2,000 on Medstar S.R.L. The controller had mistakenly sent a patient's health data via unsecured email to another patient. The DPA found… ROMANIA ·ANSPDCP ·Art. 32 Healthcare Security Health Data Feb 20, 2025
€2,000 Meedea Construct Prest SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 in Meedea Construct Prest SRL. The controller disclosed personal and health data of a former employee to a third party, who then… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 Health Data Healthcare Controllers Feb 17, 2025
€34,300 Primary Health Care in the Capital Area: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 34,300 on the Primary Health Care in the Capital Area. The controller processed personal and health data in shared medical record… ICELAND ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Health Data Healthcare Healthcare Feb 17, 2025
€6,900 Hospital: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined a district hospital in Września EUR 6,900 for failing to report a data breach to the DPA and data subjects in a timely manner. A patient had accidentally… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Nov 26, 2024
€290M Uber Technologies Inc., Uber B.V.: Non-compliance with general data processing principles The Dutch DPA has imposed a fine of EUR 290 million on Uber for transferring personal data of European drivers to the USA without sufficient privacy safeguards. The DPA launched… Autoriteit Persoonsgegevens Privacy Shield Processing Agreement IP Address Jul 22, 2024
€900,000 Postel S.p.A: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 900,000 on Postel S.p.A. The company suffered a ransomware attack that resulted in the loss of access to files containing personal data… ITALY ·Garante ·Art. 5, 25, 32 +1 Criminal Data Security Healthcare Jul 4, 2024
€9,200 Healthcare facility: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 9,200 on a healthcare facility. The company suffered a ransomware attack on its systems, resulting in the loss of personal data. During… POLAND ·UODO ·Art. 24, 25, 32 +1 Security Healthcare Health Data Jun 13, 2024
€500 Comune di Ustica: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 500 on Comune di Ustica. The municipality had published a document, containing personal data (including health data) of private… ITALY ·Garante ·Art. 2, 5, 6 +2 Health Data Healthcare Public Authority Jun 6, 2024
€1,000 MEDICOVER SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on MEDICOVER SRL. The healthcare facility had mistakenly forwarded a patient file to the wrong patient. ROMANIA ·ANSPDCP ·Art. 32 Healthcare Healthcare Health Data May 9, 2024
€12,000 DENTALCUADROS BCN S.L.P.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on DENTALCUADROS BCN S.L.P.. The controller had suffered a cyberattack in which patient data was unlawfully accessed. During its investigation,… SPAIN ·aepd ·Art. 32, 33 Data Breaches Security Health Data May 8, 2024
€18,000 Azienda socio-sanitaria locale n. 1 di Sassari: Insufficient technical and organisational measures to ensure information security Ist das gut: The Italian DPA has imposed a fine of EUR 18,000 on Azienda socio-sanitaria locale n. 1 di Sassari. The controller had mistakenly sent an e-mail containing health… ITALY ·Garante ·Art. 5, 9, 32 Healthcare Health Data Healthcare Feb 8, 2024
€60,000 Company: Insufficient technical and organisational measures to ensure information security The DPA of Berlin imposed a fine of EUR 60,000 on a healthcare company. The company offers practice management software that includes a patient communication portal with… GERMANY ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Jan 1, 2024
€41 GERMANY DPA: €41 fine The DPA of Hessen has imposed fines totaling EUR 13,486 on 41 data controllers. In its 2024 activity report, the DPA of Hesse reported a total of 47 fines that year. Six of these… Unknown Fines Supervisory Authorities Healthcare Jan 1, 2024
€3,300 Doctor´s Office: Insufficient legal basis for data processing The DPA of Hessen has imposed a fine of EUR 3,300 on a doctor´s office. While responding to negative Google reviews, the controller revealed health data about the reviewers. GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Health Data Healthcare Controllers Jan 1, 2024
€3,700 Doctor´s Office: Insufficient legal basis for data processing The DPA of Hessen has imposed a fine of EUR 3,700 on a doctor´s office. While responding to negative Google reviews, the controller revealed health data about the reviewers. GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Healthcare Health Data Controllers Jan 1, 2024
€1,500 Physician: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 1,500 on a physician. An individual had filed a complaint with the DPA because the physician had accessed their personal data in a… CYPRUS ·Art. 5 ·Non-compliance with general data processing principles Health Data Healthcare Healthcare Dec 7, 2023
€1,000 GREECE DPA: Non-compliance with general data processing principles Unlawful disclosure of health data. HDPA ·Art. 5 ·Non-compliance with general data processing principles Health Data Healthcare IP Address Oct 11, 2023
€30,000 Asl Napoli 3 Sud: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Asl Napoli 3 Sud EUR 30,000. The healthcare facility had suffered a ransomware attack that used a virus to restrict access to the healthcare facility's… ITALY ·Garante ·Art. 5, 25, 32 Security Healthcare Healthcare Sep 28, 2023
€50,000 Azienda Usl Toscana centro: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 50,000 on Azienda Usl Toscana centro. A person had reported that medical records containing sensitive patient data were still being… ITALY ·Garante ·Art. 5, 32 Health Data Healthcare Healthcare Sep 28, 2023
€5,000 Physician: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on a physician for unlawfully disclosing patient data. ITALY ·Garante ·Art. 5, 9 Health Data Healthcare IP Address Sep 28, 2023
€5,000 Ministero dell'Ambiente e della Sicurezza Energetica: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Ministero dell'Ambiente e della Sicurezza Energetica. The controller had published a document on its website that contained… ITALY ·Garante ·Art. 2, 5, 6 +1 Healthcare Health Data Education Sep 28, 2023
€60,000 Salvator Mundi International Hospital s.r.l: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 60,000 on Salvator Mundi International Hospital s.r.l. The hospital had restricted access to its services to people with a Covid-19 Green… ITALY ·Garante ·Art. 5, 9 Healthcare Healthcare Health Data Sep 28, 2023
€10,000 Phyisician: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 10,000 on a physician. The physician had responded to an online review regarding their practice, disclosing personal health data of a… AUSTRIA ·dsb ·Art. 5, 9 Healthcare Health Data IP Address Sep 26, 2023
€17,000 FEDERACIÓN DE BALONMANO DE CASTILLA LA MANCHA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 17,000 on FEDERACIÓN DE BALONMANO DE CASTILLA LA MANCHA. Athletes were required to upload the vaccination certificate against COVID with… SPAIN ·aepd ·Art. 9, 13 Health Data Healthcare Personal Data Sep 25, 2023
€20,000 Azienda Usl Toscana Sud Est.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 20,000 against Azienda Usl Toscana Sud Est. The controller had put up an information poster in the emergency room showing a healthcare… ITALY ·Garante ·Art. 2, 5, 9 +1 Health Data Healthcare Healthcare Jun 1, 2023