Skip to content
Content type · 136 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–100 of 136 sort newestlargest fineoldest
€1,000 'Principe Umberto di Savoia' State Scientific and Linguistic High School: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on 'Principe Umberto di Savoia' State Scientific and Linguistic High School. The controller processed the personal data of… ITALY ·Garante ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Right of Access Controllers Dec 4, 2025
€3,000 Cucina di Fabio S.R.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 15, 17 +1 Personal Data Processing Supervisory Authorities Nov 26, 2025
DSB: No processor access violation under Art. 15 GDPR when controller deleted data On 07. August 2023, the data subject made a request to the processor to provide the report and the questionnaire completed by the data subject at an information event. The… 2025-0.566.415 ·Austria ·Art. 4, 5, 12 +3 Controllers Processors Right of Access Nov 21, 2025
€2,000 Whitedecor SRL: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 7, 12 +3 Personal Data Processing Supervisory Authorities Nov 10, 2025
€1,000 Company: Insufficient compliance with data subjects' rights (regarding their personal data). ⇄ Boete van €1.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 12, 15 Personal Data Right of Access Controllers Nov 7, 2025
€2,000 Agency for Control of Outstanding Debts S.R.L.: Insufficient compliance with data subjects' rights. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Processing Supervision Oct 22, 2025
€1,000 Green.mec. s.r.l.: Insufficient compliance with data subject rights. ⇄ Een boete van €1.000 - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 13, 15 Right of Access Personal Data Controllers Sep 25, 2025
€1,000 Giada FM S.r.l.: Insufficient compliance with data subjects' rights. ⇄ Een boete van €1.000 - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 12, 15 Right of Access Controllers Personal Data Sep 11, 2025
€1,000 Order of Biochemists, Biologists and Chemists in the Romanian Healthcare System: Insufficient Compliance with Data Subjects' Rights. ⇄ 1.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Processing Supervisory Authorities Aug 5, 2025
€20,000 NN Greek Single-Member Anonymous Life Insurance Company: Insufficient fulfilment of data subjects rights The Greek DPA has imposed a fine of EUR 20,000 on NN Greek Single-Member Anonymous Life Insurance Company. The controller failed to provide the data subject with the personal data… GREECE ·HDPA ·Art. 15 Right of Access Personal Data Controllers Jul 11, 2025
€12,000 Data Diggers Market Research SRL: Non-compliance with general principles of data processing. ⇄ Een boete van €12.000 - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 12, 14 +1 Personal Data Processing Supervisory Authorities May 21, 2025
€2,000 Tirrenia Hospital S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 2,000 on Tirrenia Hospital S.r.l. The controller failed to respond to a data access request from a data subject. ITALY ·Garante ·Art. 12, 15 Right of Access Personal Data Controllers Apr 29, 2025
€2,000 Tirrenia Hospital S.r.l.: Insufficient compliance with data subjects' rights. ⇄ Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 12, 15 Personal Data Right of Access Controllers Apr 29, 2025
€1,000 Xiting ROM SRL: Insufficient compliance with data subjects' rights. ⇄ Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Supervisory Authorities Processing Apr 28, 2025
€20,000 Company: Non-compliance with general principles for data processing. ⇄ Een boete van 20.000 euro - De Belgische Autoriteit voor gegevensbescherming (APD). BELGIUM ·APD/GBA ·Art. 5, 6, 12 +4 Processing Marketing Personal Data Apr 22, 2025
€1,000 Office Nova Concept SRL: Insufficient compliance with data subjects' rights. ⇄ Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15, 17 +1 Personal Data Supervisory Authorities Processing Apr 14, 2025
€5,000 Gynecologist: Insufficient compliance with the information obligation. ⇄ Een boete van €5.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 15 Supervisory Authorities Personal Data Right of Access Apr 9, 2025
€4,000 CREMA GAMES, S.L.: Insufficient compliance with information obligations. ⇄ Een boete van 4.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 15 Personal Data Controllers Right of Access Mar 28, 2025
€2.4M Vinted: Insufficient fulfilment of data subjects rights The Lithuanian DPA has imposed a fine of EUR 2,385,276 on the second-hand online store 'Vinted'. The DPA initiated an investigation after the Polish and French DPAs forwarded… LITHUANIA ·VDAI ·Art. 5, 12 Transparency Accountability Controllers Jul 2, 2024
FRANCE DPA: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine on a controller for not sufficiently respecting data subjects' rights (exercising the right of access to a medical file). CNIL ·Insufficient fulfilment of data subjects rights Supervisory Authorities Right of Access Inspection Access Rights and Cooperation Obligations Jun 5, 2024
€31M Clearview AI Inc.: Non-compliance with general data processing principles The Dutch DPA has fined Clearview Al Inc. EUR 30,500,000. Clearview, a company offering facial recognition services, holds a database of over 30 billion images, including those of… AP Transparency Personal Data Representatives May 16, 2024
APD/GBA · 74/2024 On 30 January 2024, the data subject received an email from a candidate in the June 2024 regional elections (‘controller’), promoting their programme. On 3 January 2024, the data… 74/2024 ·Belgium ·Art. 6 Legitimate Interest Personal Data Marketing May 16, 2024
€5,000 Dentist: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 5,000 on a dentist due to a lack of data security and a failure to respect the right of access of a data subject. FRANCE ·CNIL ·Insufficient fulfilment of data subjects rights Right of Access Personal Data Inspection Access Rights and Cooperation Obligations Jan 31, 2024
€174,640 Black Tiger Belgium: Insufficient fulfilment of information obligations The Belgian DPA has imposed a fine of EUR 174,640 on Black Tiger Belgium. An individual had filed a complaint with the DPA due to the controller's failure to properly comply with… APD/GBA ·Art. 5, 6, 12 +5 ·Insufficient fulfilment of information obligations Storage Limitation Retention Period Right of Access Jan 16, 2024
€1.7M Norwegian Labor and Welfare Administration: Insufficient technical and organisational measures to ensure information security The Norwegian DPA has imposed a fine of EUR 1.7 million on Arbeids- og velferdsetaten, the Norwegian Labor and Welfare Administration (NAV). During its investigation, the DPA… NORWAY ·Datatilsynet (NO) ·Art. 5, 24, 25 +1 Security Privacy by Design & Default Right of Access Nov 27, 2023
€110,000 Rompetrol Downstream SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 110,000 on Rompetrol Downstream SRL. The controller had suffered a data breach in which customer data was repeatedly accessed and used… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Controllers Nov 13, 2023
DSB-D124.5337 In August 2021, an unprotected Excel file containing the names and PCR test results of several thousand individuals was sent from the compromised email account of the first data… 2023-0.273.912 ·Austria ·Art. 5, 6, 12 +3 Right to be Forgotten Right of Access Personal Data Oct 6, 2023
€4,000 Partidul Uniunea Salvați România: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined the Partidul Uniunea Salvați România party EUR 4,000. The controller had suffered a phishing attack in which the attackers gained unauthorized access to… ROMANIA ·ANSPDCP ·Art. 32 Security Encryption Right of Access Mar 15, 2023
€3,000 Tinmar Energy SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined Tinmar Energy SA EUR 3,000. The controller had suffered a data breach in which third parties gained unauthorized access to personal data such as first… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Personal Data Mar 14, 2023
€1,600 Deca s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,600 on Deca s.r.l.. Employees had filed a complaint with the DPA because the controller had not complied with their requests for access… ITALY ·Garante ·Art. 12, 15 Right of Access Personal Data Controllers Mar 9, 2023
€3,000 Integral Collection SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3000 on Integral Collection SRL. The controller had suffered a ransomware attack in which unauthorized third parties gained access to… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Personal Data Mar 6, 2023
€2,250 Finopro IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,250 on Finopro IFN SA. The controller had suffered a ransomware attack in which unauthorized third parties gained access to personal… ROMANIA ·ANSPDCP ·Art. 32 Security Right of Access Personal Data Mar 6, 2023
€2,000 BRISTOL LOGISTICS SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on BRISTOL LOGISTICS SA. The DPA received a notification from BRISTOL LOGISTICS SA of a personal data breach under Art. 33 GDPR.… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security Jan 12, 2023
€15,000 A&G Couriers Limited T/A Fastway Couriers (Ireland): Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has fined A&G Couriers Limited T/A Fastway Couriers (Ireland) EUR 15,000. During a changeover of its IT systems, the controller had suffered a cyberattack in… DPC ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Right of Access Dec 30, 2022
€2,000 Homeowners Association: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,000 on a homeowners' association. An individual who did cleaning work in the residential complex had filed a complaint with the DPA… SPAIN ·AEPD ·Art. 6, 15 Personal Data Right of Access Controllers Dec 28, 2022
€2,000 Casa Rusu S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on Casa Rusu S.R.L. . The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had used an… ROMANIA ·ANSPDCP ·Art. 25, 32 Data Breaches Privacy by Design & Default Security Dec 9, 2022
€3,000 OTP LEASING ROMANIA IFN SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on OTP LEASING ROMANIA IFN SA. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. An individual had… ANSPDCP ·Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Nov 25, 2022
DKK 500,000 Danish DPA fines Sirius Lawyers DKK 500,000 for inadequate security after hacker attack A law firm was exposed to a hacker attack. Thereby, hackers received access to the firm's servers that contained personal data and encrypted them. This posed a serious risk that… Denmark ·Datatilsynet (DK) ·Art. 5, 9, 24 +2 Integrity and Confidentiality Principle Supervisory Authorities Encryption
NAIH: School grades are personal data; failure to provide access in eKRÉTA system A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Hungary ·Art. |, 10, 28 +1 Personal Data Right of Access Controllers Sep 22, 2022
€40,000 FCA Italy S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 40,000 on FCA Italy S.p.A.. An employee of the controller had requested access to personal data processed in the context of their… Garante ·Art. 12, 15 ·Insufficient fulfilment of data subjects rights Right of Access Personal Data Controllers Sep 15, 2022
€600,000 ACCOR SA: Insufficient fulfilment of data subjects rights The French DPA (CNIL) has imposed a fine of EUR 600,000 on ACCOR SA. Both CNIL and other European DPAS had received complaints against ACCOR from several individuals. In the… FRANCE ·CNIL ·Art. 12, 13, 15 +2 Right to Object Right of Access Direct Marketing Aug 19, 2022
€10,000 Stay over s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has fined Stay Over s.r.l. EUR 10,000. A former employee had filed a complaint with the DPA. The company had failed to respond to a request for access to personal… ITALY ·Garante ·Art. 5, 12, 13 +2 Right of Access Personal Data Supervisory Authorities Jul 21, 2022
Icelandic DPA: genetic research company violated DPO independence under Art. 38(3) GDPR The Icelandic DPA started an investigation into a genetic research company. More specifically, to assess the company's Data Protection Officer (DPO), as well as the performance of… 2020061979 ·Iceland ·Persónuvernd Supervisory Authorities Controllers Prior Consultation Jun 29, 2022
€70,000 Unicredit S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has fined Unicredit S.p.A. EUR 70,000. An employee had filed a complaint with the DPA claiming that their right to access their personal data had not been… ITALY ·Garante ·Art. 12, 15 Right of Access Personal Data Supervisory Authorities Jun 16, 2022
€9M Clearview Al Inc.: Non-compliance with general data processing principles The UK DPA has fined Clearview AI Inc. EUR 9 million. The company holds a database of more than 20 billion facial images (including those of UK residents and nationals) from… UNITED KINGDOM ·ICO ·Art. 5, 6, 9 +7 Retention Period Storage Limitation Right of Access May 18, 2022
€40,000 Il Sole 24 Ore S.p.a.: Insufficient fulfilment of data subjects rights The Italian DPA has fined the newspaper Il Sole 24 Ore S.p.a. EUR 40,000. The newspaper had published an article on the recognition by the Italian authorities of a U.S. judge's… ITALY ·Garante ·Art. 5, 9, 12 Personal Data Supervisory Authorities Processing Apr 28, 2022
AEPD admits claim against Securitas Direct for failure to handle access and erasure Resolution No. R/00665/2022 is highlighted by a case concerning a claimant (namely A.A.A) and a respondent party (namely Securitas Direct España, S.A). The claimant filed against… R/00665/2022 ·Spain ·Art. 17, 55 Right to Restriction Right of Access Data Portability Apr 22, 2022
€10,000 Brav s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on Brav s.r.l.. The operator of the online platform had reported a data breach to the DPA pursuant to Art. 33 GDPR. Unauthorized… ITALY ·Garante ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Security Mar 24, 2022
BfDI: Telekom must name all recipients, data origin and deletion dates in Art. 15 replies The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject… 24-191 II#4781 ·Germany ·Art. 15, 20, 95 Data Portability Recipient Personal Data Jan 27, 2022
€3,000 Kaufland România SCS: Insufficient fulfilment of data subjects rights The Romanian DPA (ANSPDCP) has imposed a fine of EUR 3,000 on Kaufland Romania SCS. The DPA initiated an investigation based on a complaint from an individual stating that the… ROMANIA ·ANSPDCP ·Art. 15 Right of Access Personal Data Controllers Jan 20, 2022