Skip to content
Content type · 179 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–100 of 179 sort newestlargest fineoldest
€45M Vodafone GmbH: Non-compliance with general data processing principles The Federal Commissioner for Data Protection and Freedom of Information (BfDI) has imposed a fine of EUR 45,000,000 on Vodafone GmbH. The controller failed to properly supervise a… BfDI Processors Controllers Personal Data Jan 1, 2025
€200,000 Hospital: Insufficient technical and organisational measures to ensure information security The Belgian DPA has fined a hospital EUR 200,000. The hospital had suffered a ransomware attack through a vulnerability in the server, which paralyzed parts of the computer system… BELGIUM ·APD/GBA ·Art. 5, 24, 32 +1 Security DPIA Personal Data Dec 17, 2024
€70,000 INTERURBANA DE AUTOBUSES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined INTERURBANA DE AUTOBUSES, S.A. EUR 70,000 after an employee filed a complaint over the publication of personal data on the company's bulletin boards.… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Personal Data Dec 16, 2024
€5M Foodinho Srl: Non-compliance with general data processing principles The Italian DPA has fined the food delivery service Foodinho Srl EUR 5 million for unlawfully processing the data of approximately 35,000 drivers and for several violations of the… ITALY ·Garante ·Art. 2, 5, 6 +11 Types of Special Categories of Personal Data Personal Data Supervisory Authorities Nov 13, 2024
€250,000 COSMOSPACE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 250,000 on COSMOSPACE. The controller is a company that offers personalized clairvoyance consultations by telephone. As part of its services,… FRANCE ·CNIL ·Art. 5, 9 Controllers Consent Processing Sep 26, 2024
€150,000 TELEMAQUE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 150,000 on TELEMAQUE. The controller is a company that offers digital services in the field of divinatory arts, including fortune telling by… FRANCE ·CNIL ·Art. 5, 9 Controllers Consent Processing Sep 26, 2024
€45,000 Croatian DPA fines two hotels €45,000 for unlawful cookie processing The Croatian DPA (AZOP) has imposed a fine of EUR 45,000 on two hotels for unlawfully processing personal data through the use of cookies. CROATIA ·AZOP ·Unknown Supervisory Authorities Cookies Personal Data Sep 13, 2024
€190,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 190,000 on a hospital. The hospital had suffered a data breach in which radiological image files were irrevocably lost. AZOP had… CROATIA ·AZOP ·Art. 5, 6, 12 +4 Data Breaches Retention Period Storage Limitation Sep 13, 2024
€26,800 Municipality of Vejen: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 26,800 on the municipality of Vejen. The municipality had suffered a security incident involving the theft of three unencrypted computers… DENMARK ·Datatilsynet (DK) ·Insufficient technical and organisational measures to ensure information security Public Authority Encryption Education Aug 14, 2024
€80,000 Selectra S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 80,000 on Selectra S.p.A.. A former employee had lodged a complaint with the DPA on the grounds that the controller was able to access… ITALY ·Garante ·Art. 5, 13, 88 +1 Storage Limitation Retention Period Controllers Jul 17, 2024
€8,700 Central Young Men’s Christian Association: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined the Central Young Men’s Christian Association EUR 8,700. The controller had sent an email to individuals participating in a program for individuals… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers IP Address Apr 30, 2024
€20,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 20,000 on a data controller operating in the gambling and betting sector. The data controller collected and processed personal… CROATIA ·AZOP ·Art. 6, 7, 13 Fairness & Transparency Controllers Consent Apr 22, 2024
€15,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 15,000 on a data controller operating in the gambling and betting sector. The data controller collected and processed personal… CROATIA ·AZOP ·Art. 6, 7, 13 Consent Controllers Fairness & Transparency Apr 22, 2024
CROATIA DPA: Insufficient fulfilment of information obligations The Croatian DPA (AZOP) has imposed seven fines totaling EUR 16,000 on data controllers for failing to adequately mark video-monitored areas. This lack of marking resulted in… AZOP ·Art. 13, 27 ·Insufficient fulfilment of information obligations Supervisory Authorities Controllers Processing Apr 22, 2024
€100,000 Olimpia S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Olimpia S.r.l.. During its investigation, the DPA found that data subjects had received advertising calls on behalf of the… ITALY ·Garante ·Art. 5, 6, 24 +3 Controllers Supervisory Authorities Processing Apr 11, 2024
€100,000 Facile.Energy S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Facile.Energy S.r.l.. During its investigation, the DPA found that data subjects had received advertising calls on behalf of… ITALY ·Garante ·Art. 5, 6, 24 +3 Controllers Supervisory Authorities Personal Data Apr 11, 2024
€20,000 Banca di Credito Cooperativo Appulo Lucana soc. cooperativa: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 20,000 on Banca di Credito Cooperativo Appulo Lucana soc. cooperativa. A former employee had requested access to the personal data in… ITALY ·Garante ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Mar 7, 2024
€20,000 Company: Insufficient legal basis for data processing Croatian Data Protection Authority (azop) fined Company €20,000 on 2024-02-26 for: Insufficient legal basis for data processing. Croatia ·AZOP ·Art. 6, 7, 13 Supervisory Authorities Processing Human Resources Feb 26, 2024
€79M Enel Energia SpA: Insufficient technical and organisational measures to ensure information security The Italian DPA has fined Enel Energia SpA EUR 79.1 million due to its lack of compliance with technical and organisational measures aimed at limiting the potential abuses by… Garante Security Supervisory Authorities Human Resources Feb 8, 2024
€10,000 Company: Insufficient legal basis for data processing The DPA of Hessen has imposed a fine of EUR 10,000 on a company. The controller used data for marketing purposes without a legal basis. The company obtained the data through… GERMANY ·Art. 6, 7 ·Insufficient legal basis for data processing Controllers Processing Direct Marketing Jan 1, 2024
Private individual: Insufficient legal basis for data processing The DPA of Hamburg has imposed a fine on a private individual for recording a video of their neighbor in the bathroom without their consent. GERMANY ·HmbBfDI ·Insufficient legal basis for data processing Consent Human Resources Processing Jan 1, 2024
€16,000 Freelancer: Insufficient cooperation with supervisory authority The DPA of Hessen has imposed a fine of EUR 16,000 on a freelancer. The controller operates a website without a privacy policy. The DPA contacted the controller, ordering him to… GERMANY ·Art. 13, 31, 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Jan 1, 2024
€400,000 UK Ministry of Defense: Insufficient technical and organisational measures to ensure information security The UK DPA has fined the Ministry of Defense EUR 400,000 for disclosing personal data of individuals who were to be relocated to the UK after the Taliban took control of… UNITED KINGDOM ·ICO ·Insufficient technical and organisational measures to ensure information security Personal Data Public Authority Human Resources Dec 13, 2023
€48,000 INSTITUT MARQUÉS OBSTETRICIA I GINECOLOGIA, S.L.P.: Non-compliance with general data processing principles The Spanish DPA has imposed a finea INSTITUT MARQUÉS OBSTETRICIA I GINECOLOGIA, S.L.P. The controller had suffered a data breach in which personal patient and employee data had… SPAIN ·AEPD ·Art. 5, 32, 34 Data Breaches Security Controllers Nov 2, 2023
€10M Axpo Italia Spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10 million on electricity and gas supplier Axpo Italia Spa. The DPA had received numerous complaints from data subjects who complained… ITALY ·Garante ·Art. 5, 24 Controllers Personal Data Processing Sep 28, 2023
€20,000 Shardana Working Soc. Coop. a r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has fined Shardana Working Soc. Coop. a r.l. EUR 20,000 for failing to respond adequately to requests from employees for access to information regarding their… ITALY ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Human Resources Sep 14, 2023
€20,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 20,000 on a company engaged in gambling and betting activities due to three identified violations of the GDPR. As noted by AZOP,… CROATIA ·AZOP ·Art. 6, 7, 13 Personal Data Controllers Consent Sep 14, 2023
€30,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 30,000 on a company engaged in gambling and betting activities due to three identified violations of the GDPR. As noted by AZOP,… CROATIA ·AZOP ·Art. 6, 7, 13 Personal Data Controllers Consent Sep 14, 2023
€345M TikTok Limited: Non-compliance with general data processing principles The Irish DPA (DPC), has imposed a fine of EUR 345 million on TikTok Limited. The DPC conducted an investigation primarily focused on the processing of personal data between July… IRELAND ·DPC ·Art. 5, 12, 13 +2 Privacy by Design & Default Processing Personal Data Sep 1, 2023
€3,400 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 3,400 on a company. The controller had reported a data breach to the DPA. The company car of a senior employee had been broken into,… POLAND ·UODO ·Art. 5, 24, 25 +1 Encryption Security Privacy by Design & Default Jul 18, 2023
€1M Tele2 Sverige Aktiebolag: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 1 million on Tele2 Sverige Aktiebolag. The Austrian organization None of your Business (NOYB) had filed a complaint against the company… SWEDEN ·Art. 44 ·Insufficient technical and organisational measures to ensure information security Personal Data Privacy Shield International Transfer Jun 30, 2023
€25,000 CDON AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 25,000 on CDON AB. The Austrian organization None of your Business (NOYB) had filed a complaint against the company in light of the… SWEDEN ·Art. 44 ·Insufficient technical and organisational measures to ensure information security Personal Data Privacy Shield International Transfer Jun 30, 2023
€1.1M Bonnier News AB: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 1.1 million on Bonnier News AB. During its investigation, the DPA found that Bonnier News collects customer data, for example, through… SWEDEN ·Art. 6 ·Insufficient legal basis for data processing Consent Personal Data Marketing Jun 26, 2023
€30,000 Belgian Order of Pharmacists: Non-compliance with general data processing principles The Belgian DPA has imposed a fine of EUR 30,000 on the Belgian Order of Pharmacists. The controller had conducted disciplinary proceedings against the data subject (pharmacist).… BELGIUM ·APD/GBA ·Art. 5 Personal Data Controllers Processing Jun 16, 2023
€150,000 KG COM: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 150,000 on the company KG COM. The company operates several websites and offers fortune-telling consultations to customers via chat or… FRANCE ·CNIL ·Art. 5, 6, 9 +6 Data Breaches Legitimate Interest Controllers Jun 8, 2023
€300,000 Rinascente S.p.A.: Non-compliance with general data processing principles The Italian DPA has fined Rinascente S.p.A. EUR 300,000. The DPA acted on a complaint from a customer who, following an incident with a store employee, had her long-standing… ITALY ·Garante ·Art. 5, 12, 32 +1 Retention Period DPIA Storage Limitation Jun 8, 2023
€3,000 Comune di Napoli: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on Comune di Napoli. The municipality had sent three former employees, after termination of their employment an e-mail containing… ITALY ·Garante ·Art. 2, 5, 6 Processing Employees Public Authority Jun 1, 2023
€60,000 Website operator: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 60,000 on a website operator. The controller had published unauthorized personal data on the website www.trovanumeri.com, which it had… ITALY ·Garante ·Art. 5, 6, 12 +6 Personal Data Controllers Supervisory Authorities May 17, 2023
€1,200M Meta Platforms Ireland Limited: Insufficient legal basis for data processing The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 1.2 billion. This is the highest fine imposed to date under the GDPR. In its decision, the DPC found that Meta had… DPC ·Art. 46 Processing Agreement International Transfer Supervision May 12, 2023
€10,000 Alianța pentru Unirea Românilor: Non-compliance with general data processing principles The Romanian DPA imposed a fine of EUR 10,000 on Alianța pentru Unirea Românilor. During its investigation, the DPA found that the controller collected personal data on its… ROMANIA ·ANSPDCP ·Art. 5 Retention Period Personal Data Controllers Mar 15, 2023
€50,000 H&M Hennes & Mauritz s.r.l. EUR 50,000: Non-compliance with general data processing principles The Italian DPA has fined H&M Hennes & Mauritz s.r.l. EUR 50,000. H&M had installed numerous video surveillance systems in its Italian stores for the purpose of preventing theft… ITALY ·Garante ·Art. 5, 114 Processing Video Surveillance Monitoring Mar 2, 2023
€5.5M WhatsApp Ireland Ltd.: Insufficient legal basis for data processing The Irish DPA (DPC) has fined WhatsApp Ireland Ltd. EUR 5.5 million. The Austrian organization 'None of Your Business' (NOYB) had filed a complaint with the DPA on behalf of an… DPC ·Art. 6, 12, 13 ·Insufficient legal basis for data processing Consent Fairness & Transparency Personal Data Jan 19, 2023
€6,400 Szczecin-Centrum District Court: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 6,400 on the Szczecin-Centrum District Court. The court had reported a data breach to the DPA involving the loss of three data carriers.… POLAND ·UODO ·Art. 5, 24, 25 +1 Encryption Privacy by Design & Default Security Jan 19, 2023
€2,000 BRISTOL LOGISTICS SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on BRISTOL LOGISTICS SA. The DPA received a notification from BRISTOL LOGISTICS SA of a personal data breach under Art. 33 GDPR.… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security Jan 12, 2023
€390M Meta Platforms Ireland Limited: Non-compliance with general data processing principles The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 390 million. The DPA has imposed a fine of EUR 210 million for violations related to the provision of its Facebook… DPC Transparency Supervision Supervisory Authorities Jan 4, 2023
Police officer: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a three-figure fine on a police officer. The police officer had used the telephone number of a person who had filed a criminal complaint for… GERMANY ·Insufficient legal basis for data processing Human Resources Supervisory Authorities Processing Jan 1, 2023
Private individual: Non-compliance with general data processing principles The DPA of Bavaria has imposed a fine on an individual. The individual had been pulled over by a police officer and afterwards managed to obtain their telephone number in order to… GERMANY ·Non-compliance with general data processing principles Human Resources Processing Supervisory Authorities Jan 1, 2023
Private individual: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a three-figure fine on six private individuals. The individuals, who worked in a hospital, had accessed the medical records of a colleague who… GERMANY ·Insufficient legal basis for data processing Health Data Healthcare Human Resources Jan 1, 2023
Fishing club: Insufficient legal basis for data processing The DPA of Brandenburg has imposed a three-figure fine on a fishing club due to the fact that lists of members' personal data such as first and last names, full addresses with… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Personal Data Human Resources Processing Jan 1, 2023
€750,000 Alektum Oy: Insufficient fulfilment of data subjects rights The Finnish DPA has fined the debt collection company Alektum Oy EUR 750 000. The DPA opened an investigation against the controller after three people filed complaints against… FINLAND ·Deputy Data Protection Ombudsman ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Dec 13, 2022