Content type · 261 documents in this view · 3,813 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3589 Processing 2636 Personal Data 2395 Controllers 2018 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
€4,750 The District Sanitary Inspector in Police: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 4.750 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND · ·Art. 5, 24, 25 +1 Nov 15, 2025
€2,400 AXARQUIA VELEZ DENTAL, S.L.: Non-compliance with the general principles for data processing. ⇄ Een boete van 2.400 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN · ·Art. 5 Nov 14, 2025
€6,000 APARELLS ORTOPEDICS CURTO, S.L: Insufficient compliance with data subjects' rights. ⇄ Een boete van 6.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN · ·Art. 5 Oct 28, 2025
€9,450 Gynecological center: Insufficient compliance with obligations to report data breaches. ⇄ Boete van €9.450 - Pools Nationaal Bureau voor de Bescherming van Persoonsgegevens (UODO). POLAND · ·Insufficient fulfilment of data breach notification obligations Oct 27, 2025
€1,000 Mayor of the Municipality of Calvi Risorta: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on the Mayor of the Municipality of Calvi Risorta. The controller published citizens' health data during the Covid-19 pandemic… ITALY · ·Art. 5, 6, 9 Oct 23, 2025
€1,000 Mayor of the Municipality of Calvi Risorta: Insufficient legal basis for data processing. ⇄ Een boete van €1.000 - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 9 Oct 23, 2025
AEPD · PS-00140-2025 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In… PS-00140-2025 ·Spain ·Art. 5, 9, 24 +2 Oct 10, 2025
€6,000 Interprovincial organization of medical radiology technicians and technical healthcare personnel in rehabilitation and prevention in the regions AQ, CH, PE and TE: Insufficient legal basis for data processing. ⇄ Een boete van 6.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 37 Oct 9, 2025
€16,000 Order of Nurses of Pisa: Insufficient legal basis for data processing. ⇄ Een boete van 16.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6 Oct 9, 2025
€1,000 Dr. Max SRL: Insufficient compliance with data subjects' rights. ⇄ 1.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 12, 17 Sep 18, 2025
€2,670 POLAND, Data Protection Authority: Failure to appoint a data protection officer. ⇄ Een boete van 2.670 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). ·Art. 38 ·Lack of appointment of data protection officer Sep 12, 2025
€12,000 Casa di Cura Città di Roma: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 12.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 9, 25 +1 Sep 11, 2025
€12,000 Casa di Cura Città di Roma: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 12,000 on the Casa di Cura Città di Roma. The controller used patient management software that gave users access to excessive amounts of… ITALY · ·Art. 5, 9, 25 +1 Sep 11, 2025
€1,000 Order of Biochemists, Biologists and Chemists in the Romanian Healthcare System: Insufficient Compliance with Data Subjects' Rights. ⇄ 1.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 12, 15 Aug 5, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2,000 on Linea Stampalibera Società Cooperativa r.I. The controller, who operates a news site, has disclosed too much personal… ITALY · ·Art. 5 Aug 4, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Non-compliance with the general principles for data processing. ⇄ Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor gegevensbescherming (Garante). ITALY · ·Art. 5 Aug 4, 2025
€80,000 Careggi University Hospital: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 9, 25 +1 Aug 4, 2025
€2,200 Legal Entity: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 2,200 on a legal entity. An employee of the company forwarded health data to a lawyer without sufficient grounds. The company was fined… SLOVENIA · ·Art. 6, 9 Jul 22, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 32.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN · ·Art. 5, 32 Jul 11, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on VALORA PREVENCIÓN, S.L.U. The controller, a company offering occupational health and safety services, failed to implement… SPAIN · ·Art. 5, 32 Jul 11, 2025
€50,000 Magna PT S.p.A.: Insufficient legal basis for the processing of data. ⇄ Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 9 +2 Jul 10, 2025
€50,000 Magna PT S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine on Magna PT S.p.A. Employees of the controllers were subjected to 'return to work interviews' after returning from an absence due to illness or… ITALY · ·Art. 5, 6, 9 +2 Jul 10, 2025
€15,600 Children's Hospital of the L. Zamenhof University in Białystok: Insufficient technical and organizational measures to ensure information security. ⇄ 15.600 euro boete - Poolse nationale instantie voor de bescherming van persoonlijke gegevens (UODO). POLAND · ·Art. 5, 32 Jun 30, 2025
€10,000 Shield of David - K.I.D.A.F.: Non-compliance with general principles of data processing. ⇄ Boete van €10.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE · ·Art. 5, 12, 13 +3 Jun 24, 2025
€7,000 General Hospital of the University of Larissa: Inadequate compliance with data subjects' rights. ⇄ Een boete van €7.000 - Hellenic Data Protection Authority (HDPA). GREECE · ·Art. 5, 14, 15 Jun 24, 2025
€2.7M 23andMe, Inc.: Inadequate technical and organisational measures to ensure information security. ⇄ Een boete van 2.700.000 euro - Informatiecommissaris (ICO). UNITED KINGDOM · ·Art. 5, 32 Jun 5, 2025
€1.1M University Pharmacy: Non-compliance with general principles of data processing. ⇄ 1.100.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND · ·Art. 5, 32 May 27, 2025
€7,000 Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, North Milan: Insufficient legal basis for the processing of data. ⇄ Een boete van 7.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 9 May 21, 2025
€7,000 Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 7,000 on Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North. The controller… ITALY · ·Art. 5, 9 May 21, 2025
€21,000 Menarini Silicon Biosystems SpA: Non-compliance with the general principles for data processing. ⇄ 21.000 euro boete - Italiaanse Autoriteit voor de bescherming van persoonlijke gegevens (Garante). ITALY · ·Art. 5, 13 May 21, 2025
€21,000 Menarini Silicon Biosystems SpA: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 21,000 on Menarini Silicon Biosystems SpA. The controller is conducting oncological research and has developed a software that is able to… ITALY · ·Art. 5, 13 May 21, 2025
€5,000 Maravet S.R.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 32 May 19, 2025
€6,600 Owner of a pharmacy: Non-compliance with general principles for data processing. ⇄ Boete van 6.600 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN · ·Art. 6, 14, 32 May 9, 2025
€6,600 Owner of a Pharmacy: Violation of the General Principles of Data Processing. ⇄ Een boete van 6.600 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN · ·Art. 6, 14, 32 May 8, 2025
€20,000 Cooperativa Sociale Quadrifoglio: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 20.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 28, 32 Apr 29, 2025
€2,000 Tirrenia Hospital S.r.l.: Insufficient compliance with data subjects' rights. ⇄ Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 12, 15 Apr 29, 2025
€20,000 Cooperativa Sociale Quadrifoglio: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio. The entity that was fined, acting as a data processor, forwarded files containing the… ITALY · ·Art. 28, 32 Apr 29, 2025
€40,000 Municipality of Bologna: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 40,000 on the Municipality of Bologna. The controller used a data processor (Cooperativa Sociale Quadrifoglio | ETid: 2274) to process… ITALY · ·Art. 5, 6, 9 Apr 29, 2025
€40,000 Municipality of Bologna: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 40.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 9 Apr 29, 2025
€7,800 Funeral company: insufficient technical and organisational measures to ensure information security. ⇄ Een boete van €7.800 - van het Poolse Nationaal Bureau voor de Bescherming van Persoonlijke Gegevens (UODO). POLAND · ·Art. 5 Apr 15, 2025
€5,000 Gynecologist: Insufficient compliance with the information obligation. ⇄ Een boete van €5.000 - Hellenic Data Protection Authority (HDPA). GREECE · ·Art. 15 Apr 9, 2025
€3.5M Advanced Computer Software Group Ltd: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 3.500.000 euro - Informatiecommissaris (ICO). UNITED KINGDOM · ·Art. 32 Mar 26, 2025
€17,600 Chief Commander of the Police: Insufficient legal basis for data processing The Polish DPA has fined the Chief Commander of the Polish Police EUR 17,600. During a press conference, the Chief Commander of the Police disclosed the personal and medical data… POLAND · ·Art. 6, 9 Mar 24, 2025
€4,000 Hospital: Non-compliance with general principles of data processing. ⇄ 4.000 euro boete - Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA · ·Art. 13, 14, 25 +1 Mar 24, 2025
€3,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croation DPA (AZOP) has imposed a fine of EUR 3,000 on a hospital. Despite the extensive and high-risk processing of health data, the hospital had not implemented sufficient… CROATIA · ·Art. 13, 32, 33 +1 Mar 24, 2025
€1,000 Velvet Medical SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Velvet Medical SRL. The controller failed to provide the data subject with the requested health data. ROMANIA · ·Art. 12, 15 Feb 27, 2025
€2,000 Medstar S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 2,000 on Medstar S.R.L. The controller had mistakenly sent a patient's health data via unsecured email to another patient. The DPA found… ROMANIA · ·Art. 32 Feb 20, 2025
€2,000 Meedea Construct Prest SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 in Meedea Construct Prest SRL. The controller disclosed personal and health data of a former employee to a third party, who then… ROMANIA · ·Art. 5, 6, 9 Feb 17, 2025
€34,300 Primary Health Care in the Capital Area: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 34,300 on the Primary Health Care in the Capital Area. The controller processed personal and health data in shared medical record… ICELAND · ·Art. 5, 6, 9 Feb 17, 2025
€6,900 Hospital: Insufficient fulfilment of data breach notification obligations The Polish DPA has fined a district hospital in Września EUR 6,900 for failing to report a data breach to the DPA and data subjects in a timely manner. A patient had accidentally… POLAND · ·Art. 33, 34 Nov 26, 2024