Skip to content
Content type · 162 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–100 of 162 sort newestlargest fineoldest
Slovenian DPA: Controller breached Art. 32, 15 and 34 GDPR over data breach and access A controller, not named in the original decision but presumed to be a public institution, notified the Slovenian DPA after experiencing a data breach in relation to its website.… 0612-91/2025/40 ·Slovenia ·IP-RS Data Breaches Controllers Supervisory Authorities Mar 4, 2026
€150,000 The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested a duplicate SIM card for the mobile line of a data subject. The request was… EXP202306354 (PS/00312/2024) ·Spain ·Art. 5, 6 Integrity and Confidentiality Principle Personal Data Controllers Feb 11, 2026
€10,000 GENPACT ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Feb 4, 2026
DSB · 2026-0.043.390 Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop… 2026-0.043.390 ·Austria ·Art. 5, 12, 13 Personal Data IP Address Fairness & Transparency Jan 16, 2026
€27M FREE MOBILE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 27,000,000 on FREE MOBILE. The controller suffered a data breach due to insufficient technical and organisational measures. This was… FRANCE ·CNIL ·Art. 5, 32 Personal Data Controllers Security Jan 8, 2026
€15M FREE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 15,000,000 on FREE. The controller suffered a data breach due to insufficient technical and organisational measures. This was caused by… FRANCE ·CNIL ·Art. 32, 34 Data Breaches Security Controllers Jan 8, 2026
€400,000 AEPD fines two telecom providers €400,000 and €300,000 for SIM card fraud Facts: The Data Protection Authority has fined a telecommunications company €400,000 for unlawfully changing the ownership of a mobile phone subscription and issuing a dual SIM… Spain ·Art. 6 Telecommunications IP Address Identification Jan 7, 2026
DSB: complaint against Austrian media company dismissed, but cookie banner instruction issued ⇄ An Austrian media company (the controller) that published local news operated a website that collected personal data from visitors using cookies and a cookie consent banner. The… 2025-0.276.820 ·Oostenrijk Cookies Personal Data Right to be Forgotten Jan 7, 2026
€588 Alza.cz a.s.: Insufficient legal basis for the processing of data. ⇄ Een boete van 588 euro - opgelegd door de Tsjechische Autoriteit voor Gegevensbescherming (UOOU). CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 7 Consent Personal Data Processing Dec 30, 2025
DSB · 2025-0.968.031 A data subject published a post concerning their ADHD diagnosis on a publicly accessible online forum under a pseudonym. A person (the controller) who was a follower of the data… 2025-0.968.031 ·Austria ·Art. 9 Pseudonymization Anonymization Health Data Dec 3, 2025
DSB · 2025-0.950.759 On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Austria ·Art. 5, 6, 16 +2 Privacy by Design & Default Privacy by Design Privacy by Default Nov 24, 2025
€4.5M Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer… CROATIA ·AZOP ·Art. 5, 6, 12 +4 International Transfer Privacy Shield Controllers Nov 24, 2025
€72,000 AEPD · PS-00480-2025 Tiger Media Inc., the controller, operated an advertising platform for publishers and advertisers of adult products and services. The platform acted as an ad network, connecting… Spain ·Art. 6, 27 Legitimate Interest Controllers Processors Nov 14, 2025
€865,000 Aktia Pankki Oyj: Insufficient technical and organisational measures to ensure information security The Finish DPA has imposed a fine of EUR 865,000 on Aktia Pankki Oyj. The controller changed its strong authentication process in such a way that it no longer guaranteed adequate… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Controllers Identification Oct 23, 2025
€865,000 Aktia Bank Plc: Insufficient technical and organizational measures to ensure information security. ⇄ 865.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Privacy by Design Accountability Oct 23, 2025
AEPD · PS-00140-2025 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In… PS-00140-2025 ·Spain ·Art. 5, 9, 24 +2 Data Breaches Notification Obligation Integrity and Confidentiality Principle Oct 10, 2025
€30,000 ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 30,000 on ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A. The controller published a video of a violent incident, which contained the… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Identification May 16, 2025
€30,000 ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.: Non-compliance with the general principles for data processing. ⇄ Boete van 30.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Personal Data Processing May 16, 2025
€100,000 Energia Verde S.p.A.: Non-compliance with the general principles of data processing. ⇄ Een boete van 100.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +13 Security Controllers Direct Marketing Apr 29, 2025
€100,000 Energia Verde S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Energia Verde S.p.A. The controller had been active in direct marketing activities. The controller processed data without a… ITALY ·Garante ·Art. 5, 6, 7 +13 Direct Marketing Controllers Processors Apr 29, 2025
€4,000 AEPD: Continuous workplace audio recording violates GDPR data minimisation principle On 22 April 2025, a data subject lodged a complaint with the DPA against BODENSE ESTRUCTURAS Y CALDELERÍA, S.L., the controller. The data subject claimed that the controller had… Spain ·Art. 5 Retention Period Monitoring IP Address Apr 22, 2025
€600 SPAIN, DPA: Non-compliance with the general principles of data processing. ⇄ 600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). AEPD ·Art. 5 ·Non-compliance with general data processing principles Controllers Processing Accountability Apr 15, 2025
€3,000 EDA TV CONSULTING, S.L.: Infringement of the general principles for data processing. ⇄ Boete van 3.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Processing Personal Data Apr 14, 2025
€4,000 CREMA GAMES, S.L.: Insufficient compliance with information obligations. ⇄ Een boete van 4.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 15 Personal Data Controllers Right of Access Mar 28, 2025
€4,000 CREMA GAMES, S.L.: Insufficient fulfilment of information obligations The Spanish DPA imposed a fine on CREMA GAMES, S.L. The controller failed to fulfill an information request from an online customer. The controller asked the data subject for an… SPAIN ·AEPD ·Art. 15 Personal Data Controllers Supervisory Authorities Mar 28, 2025
€3.5M Advanced Computer Software Group Ltd: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined Advanced Computer Software Group Ltd £3.07 million (EUR 3.5 million) for insufficient IT security (infringiment of Art. 32 (1) UK GDPR). The controller… UNITED KINGDOM ·ICO ·Art. 32 Security Controllers Personal Data Mar 26, 2025
€45M Vodafone GmbH: Non-compliance with general data processing principles The Federal Commissioner for Data Protection and Freedom of Information (BfDI) has imposed a fine of EUR 45,000,000 on Vodafone GmbH. The controller failed to properly supervise a… BfDI Processors Controllers Personal Data Jan 1, 2025
€4M GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine on GENERALI ESPAÑA, SOCIEDAD ANONIMA DE SEGUROS Y REASEGUROS. The controller had suffered a data breach where unknown third parties gained… SPAIN ·AEPD ·Art. 5, 25, 32 +1 Privacy by Design & Default Security Controllers Dec 10, 2024
APD/GBA · 131/2024 On 10 February 2023 the data subject, a trainee working at noyb – European Center for Digital Rights, visited the website of the controller, a Belgian media company. The data… 131/2024 ·Belgium ·Art. 4, 5, 6 Personal Data Supervisory Authorities Supervision Oct 11, 2024
€800,000 CEGEDIM SANTÉ: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 800,000 on CEGEDIM SANTÉ. The company, which provides software for medical practices, had transferred customer data for research purposes.… FRANCE ·CNIL ·Art. 5, 66 Identification Supervisory Authorities Processing Sep 12, 2024
€900,000 Postel S.p.A: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 900,000 on Postel S.p.A. The company suffered a ransomware attack that resulted in the loss of access to files containing personal data… ITALY ·Garante ·Art. 5, 25, 32 +1 Security Privacy by Design & Default Personal Data Jul 4, 2024
€14M Avast Software s.r.o.: €13,900,000 fine The Czech DPA has fined Avast Software s.r.o. EUR 13.9 million. The company had disclosed the personal data of around 100 million users of its antivirus software to the US company… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Unknown Personal Data Pseudonymization Anonymization Apr 15, 2024
€2.8M UniCredit S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 2.8 million on UniCredit S.p.a.. The bank had suffered a cyberattack on its mobile banking portal, during which the attackers gained… ITALY ·Garante ·Art. 5, 32 Security Controllers Identification Feb 8, 2024
€150,000 International Card Services B.V.: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 150,000 on International Card Services B.V. (ICS). ICS failed to carry out a data protection impact assessment before starting the digital… THE NETHERLANDS ·AP ·Art. 35 DPIA Personal Data Security Jan 15, 2024
APD/GBA · 159/2023 On 19 July 2023, a data subject, represented by noyb (European Centre for Digital Rights), filed a complaint against Mediafin, a Belgian media group, with the Belgian DPA. The… 159/2023 ·Belgium ·Art. 4, 6, 7 Personal Data Consent Supervisory Authorities Nov 24, 2023
€2,000 UNIQUE HOTEL APARTMENT S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,000 on UNIQUE HOTEL APARTMENT. The controller had copied identification documents for the purposes of guest registration and stored the… SPAIN ·AEPD ·Art. 5 Controllers Identification Processing Oct 18, 2023
€15,000 Hotel: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 15,000 to a hotel. The hotel was collecting personal data from guests in excess of what would have been necessary for the… CROATIA ·AZOP ·Art. 6, 13, 32 +1 Controllers Personal Data Encryption Sep 26, 2023
€25,000 Zagreb Holding d.o.o.: Insufficient fulfilment of information obligations The Croatian DPA (AZOP) has imposed a fine of EUR 25,000 on Zagreb Holding d.o.o., utilities company owned by the city of Zagreb. The DPA had received a complaint from a citizen… CROATIA ·AZOP ·Art. 13, 25 Controllers Personal Data Privacy by Design & Default Sep 13, 2023
€3M Trygg-Hansa: Non-compliance with general data processing principles The Swedish DPA has fined Trygg-Hansa EUR 3 million for serious data security breaches. The security breach was discovered when a recipient of an email from Trygg-Hansa realized… SWEDEN ·Art. 5, 32 ·Non-compliance with general data processing principles Security Personal Data Identification Aug 28, 2023
06/SIU/2018 The Irish DPC started an own volition inquiry into processing operations carried out by the Galway County Council (the controller), focusing mainly into the surveillance… 06/SIU/2018 ·Ireland ·DPC Monitoring DPIA Accountability Aug 22, 2023
€13,400 Sjúkratyringur Íslands: Insufficient technical and organisational measures to ensure information security The Icelandic DPA has imposed a fine of EUR 13,400 on Sjúkratyringur Íslands. During its investigation, the DPA found that the controller had failed to implement adequate… ICELAND ·Persónuvernd ·Art. 5, 25, 32 Security Privacy by Design & Default Controllers Jun 28, 2023
€2.3M Debt collection agency: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 2,265,000 on a debt collection agency. The fine is the highest ever imposed by AZOP. AZOP had received an anonymous complaint in… CROATIA ·AZOP ·Art. 6, 13, 28 +1 Controllers Personal Data Processors May 4, 2023
€20,000 Company: Non-compliance with general data processing principles The Lithuanian DPA has fined a company EUR 20,000. The company had suffered a data breach in which personal data of 50,000 data subjects were compromised. During its… LITHUANIA ·VDAI ·Art. 5, 32 Retention Period Storage Limitation Security Apr 20, 2023
€1,020 Telecommunications Operator: Non-compliance with general data processing principles The Bulgarian DPA has imposed a fine of EUR 1,020 on a telecommunications operator. The controller did not implement sufficient identification methodes, resulting in a customer… BULGARIA ·CPDP ·Art. 5 Identification Controllers Personal Data Mar 16, 2023
€3M VOODOO ('provider') was a mobile game developer The investigation service of the French DPA (the investigation service) carried out several checks on voodoo.io and on several of the provider's mobile applications on iOS, in… SAN-2022-026 ·France ·CNIL IP Address Transparency Personal Data Dec 29, 2022
DKK 500,000 Danish DPA fines Sirius Lawyers DKK 500,000 for inadequate security after hacker attack A law firm was exposed to a hacker attack. Thereby, hackers received access to the firm's servers that contained personal data and encrypted them. This posed a serious risk that… Denmark ·Datatilsynet (DK) ·Art. 5, 9, 24 +2 Integrity and Confidentiality Principle Supervisory Authorities Encryption
NAIH: School grades are personal data; failure to provide access in eKRÉTA system A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Hungary ·Art. |, 10, 28 +1 Personal Data Right of Access Controllers Sep 22, 2022
€10,000 SOPHIE ET VOILA, S.L: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on SOPHIE ET VOILA, S.L..The wedding dress company had published a picture of a customer in a wedding dress on its Instagram… SPAIN ·AEPD ·Art. 6 Lawful Basis Personal Data Legitimate Interest Sep 16, 2022
€10,000 Bper Banca S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on Bper Banca S.p.A.. An individual had filed a complaint with the DPA regarding the failure to fulfill their right to erasure of… ITALY ·Garante ·Art. 12 Personal Data Supervisory Authorities Right to be Forgotten Sep 15, 2022