Skip to content
Content type · 408 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–100 of 408 sort newestlargest fineoldest
€2,000 PRIME TRANSACTION SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on PRIME TRANSACTION SA. The controller failed to implement adequate technical and organisational measures, resulting in a data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Oct 16, 2025
€492,000 Company: Non-compliance with general data processing principles The DPA of Hamburg has imposed a fine of EUR 492,000 on a company in the finance sector. The controller used automated systems to decide whether to approve a credit application,… GERMANY ·HmbBfDI ·Non-compliance with general data processing principles Insurance Controllers Supervisory Authorities Sep 30, 2025
€492,000 Company: Non-compliance with general principles for data processing. ⇄ 492.000 euro boete - Autoriteit voor gegevensbescherming van Hamburg (HmbBfDI). GERMANY ·HmbBfDI ·Non-compliance with general data processing principles Meaningful Human Review and Decision-Making Supervisory Authorities Processing Sep 30, 2025
€1.5M CARREFOUR FINANCIAL SERVICES, E.F.C.: Insufficient technical and organizational measures to ensure information security. ⇄ 1.500.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Sep 17, 2025
€1.5M SERVICIOS FINANCIEROS CARREFOUR, E.F.C.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,500,000 on SERVICIOS FINANCIEROS CARREFOUR, E.F.C. The controller suffered a successfull cyberattack due to insufficient technical and… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Agreement Sep 17, 2025
€1.8M S-Pankki Oyj: Insufficient technical and organisational measures to ensure information security The Finish DPA has imposed a fine of EUR 1,800,000 on S-Pankki Oyj. Due to a software error, customers of the controller were able to log in to the bank accounts of other… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Controllers Processing Agreement Sep 8, 2025
€1.8M S-Pankki Oyj: Insufficient technical and organizational measures to ensure information security. ⇄ 1.800.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Privacy by Design Privacy by Default Sep 8, 2025
€180,000 Sociedad de Gestión de Activos Procedentes de la Reestructuración Bancaria S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 180,000 on Sociedad de Gestión de Activos Procedentes de la Reestructuración Bancaria S.A. The controller suffered a cyber attack due to… SPAIN ·AEPD ·Art. 5, 28 Processors Controllers Security Sep 4, 2025
€180,000 Sociedad de Gestión de Activos Procedentes de la Reestructuración Bancaria S.A.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 180.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 28 Security Processors Processing Sep 4, 2025
€1,200 GOHIPOTECA, S.L.: Insufficient legal basis for the processing of personal data. ⇄ 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6 Personal Data Processing Controllers Aug 29, 2025
€2,400 KVIKU SPAIN, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,400 on KVIKU SPAIN, S.L. The controller processed personal data of a data subject without sufficient consent. The original fine of EUR… AEPD ·Art. 6 ·Insufficient legal basis for data processing Personal Data Consent Controllers Aug 29, 2025
€2,400 KVIKU SPAIN, S.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 2.400 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). AEPD ·Art. 6 ·Insufficient legal basis for data processing Personal Data Processing Consent Aug 29, 2025
€1,200 GOHIPOTECA, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR on GOHIPOTECA, S.L. The controller processed data of a data subject without a sufficient legal basis. The contract used as the basis for… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Insurance Aug 29, 2025
€4.3M ING Bank Śląski: Insufficient legal basis for data processing. ⇄ 4.323.250 euro boete - Pools Nationaal Bureau voor de Bescherming van Persoonsgegevens (UODO). POLAND ·UODO ·Art. 5, 6 Personal Data Processing Accountability Aug 26, 2025
€4.3M ING Bank Śląski: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 4,323,250 on ING Bank Śląski. The controller scanned the identity documents of every customer and potential customer without a sufficient… POLAND ·UODO ·Art. 5, 6 Controllers Personal Data Processing Aug 26, 2025
€6,000 BANCO INVERSIS, S.A.: Insufficient technical and organisational measures to ensure information security. ⇄ Boete van 6.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Aug 22, 2025
€6,000 BANCO INVERSIS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 6,000 on BANCO INVERSIS, S.A. The controller suffered a data leak due to insufficient technical and organisational measures to ensure… SPAIN ·AEPD ·Art. 5 Security Controllers Processing Agreement Aug 22, 2025
€3,000 SC Elite Conta SRL: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Aug 18, 2025
€3,000 SC Elite Conta SRL: Insufficient technical and organisational measures to ensure information security The Romainian DPA has imposed a fine of EUR 3,000 on SC Elite Conta SRL. The controller failed to implement adequate technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Aug 18, 2025
€3,000 'FLEXICREDIT' Mutual Aid Cooperative: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Aug 12, 2025
€4,800 GACM SEGUROS GENERALES, an insurance and reinsurance company S.A.U.: Non-compliance with the general principles of data processing. ⇄ Een boete van 4.800 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Processing Accountability Aug 12, 2025
€4,800 GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 4,800 on GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U. The controller failed to process customer data accurately,… SPAIN ·AEPD ·Art. 5 Controllers Personal Data Processing Aug 12, 2025
€3,000 'FLEXICREDIT' Mutual Aid House Association: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on 'FLEXICREDIT' Mutual Aid House Association. The controller failed to implement adequate technical and organisational measures… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Aug 12, 2025
€80,000 BIZUM, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 80,000 on BIZUM, S.L. The controller failed to implement sufficient technical and organisational measures to ensure data security,… SPAIN ·AEPD ·Art. 32 Security Controllers Data Breaches Aug 11, 2025
€80,000 BIZUM, S.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 80.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 32 Security Controllers Data Breaches Aug 11, 2025
€25,000 Bank of Cyprus Public Company Limited: Insufficient technical and organisational measures to ensure information security Cypriot Data Protection Commissioner fined Bank of Cyprus Public Company Limited €25,000 on 2025-08-05 for: Insufficient technical and organisational measures to ensure… Cyprus DPA ·Art. 5, 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Insurance Aug 5, 2025
€26,400 Debt Collector: Insufficient fulfilment of data subjects rights The Hungarian DPA has imposed a fine of EUR 26,400 on a debt collector. The controller processed the personal data of a natural person, specifically data relating to a consumer… HUNGARY ·NAIH ·Art. 6, 17 Personal Data Controllers Insurance Jul 24, 2025
€180,000 TRIVE CREDIT SPAIN, S.L.: Insufficient cooperation with the supervisory authority. ⇄ Een boete van 180.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). AEPD ·Art. 58 ·Insufficient cooperation with supervisory authority Controllers Supervisory Authorities Supervision Jul 16, 2025
€180,000 TRIVE CREDIT SPAIN, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 180,000 on TRIVE CREDITSPAIN, S.L. The controller failed to adequatly comply with a order from the DPA. The original fine of EUR 225,000… AEPD ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Jul 16, 2025
€20,000 NN Greek Single-Member Anonymous Life Insurance Company: Insufficient fulfilment of data subjects rights The Greek DPA has imposed a fine of EUR 20,000 on NN Greek Single-Member Anonymous Life Insurance Company. The controller failed to provide the data subject with the personal data… GREECE ·HDPA ·Art. 15 Right of Access Personal Data Controllers Jul 11, 2025
€20,000 NN Greek Single-Member Insurance Company Anonymous: Insufficient compliance with data subject rights. ⇄ Boete van 20.000 euro - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 15 Personal Data Controllers Supervisory Authorities Jul 11, 2025
€2,000 PAVLOS BIKOS SOLE PROPRIETORSHIP DENTAL PRIVATE CAPITAL COMPANY: Insufficient cooperation with supervisory authority The Greek DPA has imposed a fine of EUR 2,000 on PAVLOS BIKOS SOLE PROPRIETORSHIP DENTAL PRIVATE CAPITAL COMPANY. The fined party was a data processor in case ETid: 2880. During… GREECE ·HDPA ·Art. 31 Supervisory Authorities Supervision Processors Jul 11, 2025
€80,000 Poste Vita S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine on Poste Vita S.p.a. The controller failed to implement adequate technical and organisational measures to ensure data security. This resulted in… ITALY ·Garante ·Art. 5, 33 Security Personal Data Controllers Jul 10, 2025
€100,000 Banco Bilbao Vizcaya Argentaria SA: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Banco Bilbao Vizcaya Argentaria SA €100,000 on 2025-07-10 for: Insufficient fulfilment of data subjects rights. Italy ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Insurance Jul 10, 2025
€80,000 Poste Vita S.p.a.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 33 Security Controllers Personal Data Jul 10, 2025
€101,000 Croatian Insurance Bureau: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined Croatian Insurance Bureau €101,000 on 2025-07-02 for: Insufficient technical and organisational measures to ensure information… Croatia ·AZOP ·Art. 5, 32 Security Insurance Education Jul 2, 2025
€50,000 Piraeus Bank S.A.: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 50,000 on Piraeus Bank S.A.The controller has processed personal data even though the data subject rightfully opposed the the data… GREECE ·HDPA ·Art. 5, 6 Personal Data Controllers Processing Jun 23, 2025
€50,000 Piraeus Bank S.A.: Insufficient legal basis for data processing. ⇄ Een boete van 50.000 euro - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 6 Personal Data Controllers Processing Jun 23, 2025
€42,000 IBERCAJA BANCO, S.A.: Violation of the general principles of data processing. ⇄ Een boete van 42.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Processing Accountability Jun 20, 2025
€42,000 IBERCAJA BANCO, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 42,000 on IBERCAJA BANCO, S.A. During a bank transfer, the controller transmitted more data then necessary to the recipient of the payment.… SPAIN ·AEPD ·Art. 5 Controllers Processing Recipient Jun 20, 2025
€10,000 Accounting Audit SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 10,000 on Accounting Audit SRL. The company failed to implement sufficient technical and organizational measures, resulting in a data breach… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Data Breaches Jun 12, 2025
€10,000 Accounting Audit Ltd: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van €10.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Jun 12, 2025
€5,000 AG-BROKER ASIGURARE S.R.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van €5.000 - De Roemeense nationale toezichthouder op de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data May 30, 2025
€5,000 AG-BROKER ASIGURARE S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on AG-BROKER ASIGURARE S.R.L. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 30, 2025
€1,200 Lawyer: There is insufficient legal basis for processing the data. ⇄ 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6 Controllers Processing Personal Data May 22, 2025
€1,200 Attorney: Insufficient legal basis for data processing The Spanish DPA imposed a fine on an attorney. The controller processed data of a data subject without sufficient legal basis. The original fine of EUR 2,000 was reduced to EUR… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Insurance May 22, 2025
€200,000 ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 200,000 on ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L. The controller obtained personal data from a third party… SPAIN ·AEPD ·Art. 6, 17 Controllers Personal Data Insurance May 19, 2025
€200,000 ASNEF-EQUIFAX, a company providing creditworthiness information, lacks a sufficient legal basis for data processing. ⇄ Een boete van 200.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6, 17 Controllers Personal Data Right to be Forgotten May 19, 2025
€5,000 ACCOUNTING & AUDIT CONSULTING SRL: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data May 16, 2025