Skip to content
Content type · 394 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–100 of 394 sort newestlargest fineoldest
€4.3M ING Bank Śląski: Onvoldoende juridische basis voor de verwerking van gegevens. 4.323.250 euro boete - Pools Nationaal Bureau voor de Bescherming van Persoonsgegevens (UODO). POLAND ·UODO ·Art. 5, 6 Processing Personal Data Accountability NL Aug 26, 2025
€4.3M ING Bank Śląski: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 4,323,250 on ING Bank Śląski. The controller scanned the identity documents of every customer and potential customer without a sufficient… POLAND ·UODO ·Art. 5, 6 Controllers Processing Agreement Insurance Aug 26, 2025
€6,000 BANCO INVERSIS, S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van 6.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Security Data Breaches Accountability NL Aug 22, 2025
€6,000 BANCO INVERSIS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 6,000 on BANCO INVERSIS, S.A. The controller suffered a data leak due to insufficient technical and organisational measures to ensure… SPAIN ·aepd ·Art. 5 Security Controllers Insurance Aug 22, 2025
€3,000 SC Elite Conta SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Aug 18, 2025
€3,000 SC Elite Conta SRL: Insufficient technical and organisational measures to ensure information security The Romainian DPA has imposed a fine of EUR 3,000 on SC Elite Conta SRL. The controller failed to implement adequate technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Security Processing Agreement Controllers Aug 18, 2025
€3,000 'FLEXICREDIT' Mutual Aid House Association: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on 'FLEXICREDIT' Mutual Aid House Association. The controller failed to implement adequate technical and organisational measures… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Insurance Aug 12, 2025
€4,800 GACM SEGUROS GENERALES, een verzekerings- en herverzekeringsmaatschappij S.A.U.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 4.800 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Processing Insurance Controllers NL Aug 12, 2025
€4,800 GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 4,800 on GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U. The controller failed to process customer data accurately,… SPAIN ·aepd ·Art. 5 Insurance Personal Data Controllers Aug 12, 2025
€3,000 'FLEXICREDIT' Vereniging voor wederzijdse hulp: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Controller Processing NL Aug 12, 2025
€80,000 BIZUM, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 80,000 on BIZUM, S.L. The controller failed to implement sufficient technical and organisational measures to ensure data security,… SPAIN ·aepd ·Art. 32 Data Breaches Security Controllers Aug 11, 2025
€80,000 BIZUM, S.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 80.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 32 Security Data Breaches Controllers NL Aug 11, 2025
€25,000 Bank of Cyprus Public Company Limited: Insufficient technical and organisational measures to ensure information security Cypriot Data Protection Commissioner fined Bank of Cyprus Public Company Limited €25,000 on 2025-08-05 for: Insufficient technical and organisational measures to ensure… Art. 5, 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Insurance Aug 5, 2025
€26,400 Debt Collector: Insufficient fulfilment of data subjects rights The Hungarian DPA has imposed a fine of EUR 26,400 on a debt collector. The controller processed the personal data of a natural person, specifically data relating to a consumer… HUNGARY ·NAIH ·Art. 6, 17 Personal Data Controllers Insurance Jul 24, 2025
€180,000 TRIVE CREDIT SPAIN, S.L.: Onvoldoende samenwerking met de toezichthoudende instantie. Een boete van 180.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). aepd ·Art. 58 ·Insufficient cooperation with supervisory authority Controllers Supervisory Authorities Processing Agreement NL Jul 16, 2025
€180,000 TRIVE CREDIT SPAIN, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 180,000 on TRIVE CREDITSPAIN, S.L. The controller failed to adequatly comply with a order from the DPA. The original fine of EUR 225,000… aepd ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Law Enforcement Jul 16, 2025
€2,000 PAVLOS BIKOS SOLE PROPRIETORSHIP DENTAL PRIVATE CAPITAL COMPANY: Insufficient cooperation with supervisory authority The Greek DPA has imposed a fine of EUR 2,000 on PAVLOS BIKOS SOLE PROPRIETORSHIP DENTAL PRIVATE CAPITAL COMPANY. The fined party was a data processor in case ETid: 2880. During… GREECE ·HDPA ·Art. 31 Supervisory Authorities Controllers Supervision Jul 11, 2025
€20,000 NN Greek Single-Member Anonymous Life Insurance Company: Insufficient fulfilment of data subjects rights The Greek DPA has imposed a fine of EUR 20,000 on NN Greek Single-Member Anonymous Life Insurance Company. The controller failed to provide the data subject with the personal data… GREECE ·HDPA ·Art. 15 Right of Access Procedures Right of Access Personal Data Jul 11, 2025
€20,000 NN Griekse levensverzekeringsmaatschappij met één aandeelhouder, anoniem: Onvoldoende naleving van de rechten van betrokkenen. Boete van 20.000 euro - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 15 Personal Data Data Controller Controllers NL Jul 11, 2025
€80,000 Poste Vita S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine on Poste Vita S.p.a. The controller failed to implement adequate technical and organisational measures to ensure data security. This resulted in… ITALY ·Garante ·Art. 5, 33 Security Insurance Personal Data Jul 10, 2025
€80,000 Poste Vita S.p.a.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 33 Security Controllers Personal Data NL Jul 10, 2025
€100,000 Banco Bilbao Vizcaya Argentaria SA: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Banco Bilbao Vizcaya Argentaria SA €100,000 on 2025-07-10 for: Insufficient fulfilment of data subjects rights. Italy ·Garante ·Art. 12, 15 Personal Data Insurance Supervisory Authorities Jul 10, 2025
€101,000 Croatian Insurance Bureau: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined Croatian Insurance Bureau €101,000 on 2025-07-02 for: Insufficient technical and organisational measures to ensure information… Croatia ·azop ·Art. 5, 32 Security Insurance Public Authority Jul 2, 2025
€50,000 Piraeus Bank S.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 50.000 euro - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 6 Personal Data Processing Controllers NL Jun 23, 2025
€50,000 Piraeus Bank S.A.: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 50,000 on Piraeus Bank S.A.The controller has processed personal data even though the data subject rightfully opposed the the data… GREECE ·HDPA ·Art. 5, 6 Personal Data Controllers Insurance Jun 23, 2025
€42,000 IBERCAJA BANCO, S.A.: Overtreding van de algemene principes voor gegevensverwerking. Een boete van 42.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Recipient Data Controller Controllers NL Jun 20, 2025
€42,000 IBERCAJA BANCO, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 42,000 on IBERCAJA BANCO, S.A. During a bank transfer, the controller transmitted more data then necessary to the recipient of the payment.… SPAIN ·aepd ·Art. 5 Recipient Controllers Processing Agreement Jun 20, 2025
€10,000 Accounting Audit SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 10,000 on Accounting Audit SRL. The company failed to implement sufficient technical and organizational measures, resulting in a data breach… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Processing Agreement Jun 12, 2025
€10,000 Accounting Audit SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €10.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Processing NL Jun 12, 2025
€5,000 AG-BROKER ASIGURARE S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on AG-BROKER ASIGURARE S.R.L. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Insurance May 30, 2025
€5,000 AG-BROKER ASIGURARE S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €5.000 - De Roemeense nationale toezichthouder op de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL May 30, 2025
€1,200 Attorney: Insufficient legal basis for data processing The Spanish DPA imposed a fine on an attorney. The controller processed data of a data subject without sufficient legal basis. The original fine of EUR 2,000 was reduced to EUR… SPAIN ·aepd ·Art. 6 Controllers Insurance Personal Data May 22, 2025
€1,200 Advocaat: Er is onvoldoende juridische basis voor de verwerking van gegevens. 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6 Data Controller Controllers Processing NL May 22, 2025
€200,000 ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 200,000 on ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L. The controller obtained personal data from a third party… SPAIN ·aepd ·Art. 6, 17 Controllers Insurance Personal Data May 19, 2025
€200,000 ASNEF-EQUifax, een bedrijf dat informatie verstrekt over kredietwaardigheid, heeft onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 200.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6, 17 Processing Controllers Personal Data NL May 19, 2025
€5,000 ACCOUNTING & AUDIT CONSULTING SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL May 16, 2025
€5,000 ACCOUNTING & AUDIT CONSULTING SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on ACCOUNTING & AUDIT CONSULTING SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Processing Agreement May 16, 2025
€2,000 CVA TAX & FINANCE S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL May 14, 2025
€2,000 CVA TAX & FINANCE S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 CVA TAX & FINANCE S.R.L. The controller did not implement sufficient technical and organisational measures to ensure information… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Insurance May 14, 2025
€2,000 CV PRO CONSULT S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL May 12, 2025
€2,000 CV PRO CONSULT S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on CV PRO CONSULT S.R.L. The controller did not implement sufficient technical and organisational measures to ensure information… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers May 12, 2025
€120,000 CREDITUUNIE VOOR FINANCIERING VAN ROEREND EN ONROEREND GOED EFC: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 120.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6 Data Controller Controllers Processing NL May 9, 2025
€120,000 UNIÓN DE CRÉDITO PARA LA FINANCIACIÓN MOBILIARIA E INMOBILIARIA EFC: Insufficient legal basis for data processing The Spanish DPA imposed a fine on UNIÓN DE CRÉDITO PARA LA FINANCIACIÓN MOBILIARIA E INMOBILIARIA EFCD. The controller forwarded customerdata to a credit information system… SPAIN ·aepd ·Art. 6 Controllers Insurance Processing Agreement May 9, 2025
€70,300 DPP Law Ltd.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van €70.300 - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Security Notification Obligation Accountability NL Apr 14, 2025
€70,300 DPP Law Ltd.: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has imposed a fine of £ 60,000 (EUR 70,300) on the law firm DPP Law Ltd. The controller had suffered a cyber attack during which personal data of 791 clients and… UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Security Processing Agreement Controllers Apr 14, 2025
€120,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine on BANCO BILBAO VIZCAYA ARGENTARIA, S.A. A customer of the bank had lodged a complaint with the DPA because the controller had signed a data… SPAIN ·aepd ·Art. 6 Controllers Processing Agreement Insurance Apr 4, 2025
€120,000 BANCO BILBAO VIZCAYA ARGENTARIA, S.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 120.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6 Processing Consent Processing Agreement NL Apr 4, 2025
€600 Owner of a Law Firm: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine on the owner of a law firm. The controller disclosed personal information in an external email because they did not implement sufficient technical… SPAIN ·aepd ·Art. 5 Security Controllers Processing Agreement Apr 3, 2025