Skip to content
Content type · 568 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–100 of 568 sort newestlargest fineoldest
€18,500 Commander of the Municipal Police of Krakow: Failure to Comply with General Data Protection Principles ⇄ 18.500 euro boete - Poolse nationale autoriteit voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Non-compliance with general data processing principles Law Enforcement Health Data Education Jan 9, 2026
€18,500 Komendanta Miejskiego Policji w Krakowie: Non-compliance with general data processing principles The Polish DPA has imposd a fine of EUR 18,500 on the Komendanta Miejskiego Policji w Krakowie. The controller published personal data, including health data, of a data subject… POLAND ·UODO ·Non-compliance with general data processing principles Personal Data Education Public Authority Jan 9, 2026
€15M UNACCEPTABLE: Insufficient technical and organizational measures to ensure information security. ⇄ The French data protection authority (CNIL) has imposed a fine of €15,000,000 on FREE. The company suffered a data breach as a result of insufficient technical and organizational… FRANCE ·CNIL ·Art. 32, 34 Security Data Breaches Notification Obligation Jan 8, 2026
€2,000 Money Seeds S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Money Seeds S.R.L. The controller failed to fulfil a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervisory Authorities Jan 8, 2026
€15M FREE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 15,000,000 on FREE. The controller suffered a data breach due to insufficient technical and organisational measures. This was caused by… FRANCE ·CNIL ·Art. 32, 34 Data Breaches Security Controllers Jan 8, 2026
€27M FREE MOBILE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 27,000,000 on FREE MOBILE. The controller suffered a data breach due to insufficient technical and organisational measures. This was… FRANCE ·CNIL ·Art. 5, 32 Personal Data Controllers Security Jan 8, 2026
€27M FREE MOBILE: Insufficient technical and organizational measures to ensure information security. ⇄ 27 miljoen euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 5, 32 Security Controllers Personal Data Jan 8, 2026
Decision No. 3R-1700. Facts: The data protection authority (DPA) ruled that a gambling operator had lawfully transferred data to a processor for the purpose of sending invitations to sporting events,… 3R-1700 ·Lithuania ·VDAI Personal Data Fairness & Transparency Processors Jan 7, 2026
€6,820 Austrian media company fined €6,820 for failing to comply with order to fix cookie banner An Austrian media company has been fined €6,820 by the Data Protection Authority because it failed to implement a binding instruction to modify the cookie banner on its website.… Austria ·DSB ·Art. 58 Right to be Forgotten Supervisory Authorities Cookies Jan 7, 2026
€232,379 Polish Postal Service: Lack of appointment of data protection officer The Polish DPA has imposed a fine of EUR 232,379 on the Polish Postal Service. The controller appointed a person as DPO who also held a managerial position with authority over… POLAND ·UODO ·Art. 38 Supervisory Authorities Controllers Personal Data Jan 2, 2026
€5,000 REVMA PLUS Retail S.A.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 5,000 on REVMA PLUS Retail S.A.. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… GREECE ·HDPA ·Art. 32 Controllers Processors Personal Data Dec 31, 2025
€10,000 Thessaloniki–Thessaly Gas Supply Company S.A.: Insufficient data processing agreement The Greek DPA has imposed a fine of EUR 10,000 on Thessaloniki–Thessaly Gas Supply Company S.A. The controller, an energy provider, used external processors for direct marketing… GREECE ·HDPA ·Art. 28, 32 Controllers Processors Supervisory Authorities Dec 31, 2025
SLOVAKIA DPA: Insufficient fulfilment of data subjects rights A Data Controller failed to comply with data subject´s request to access his/her personal data processed by audio recordings. Slovak Data Protection Office ·Art. 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Controllers
€20,000 Telecommunications company: Insufficient legal basis for data processing The Croatian DPA (azop) has imposed a fine of EUR 20,000 on a telecommunications company. A data subject had filed a complaint with the DPA claiming that the company was still… CROATIA ·AZOP ·Art. 5, 6 Personal Data Processing Telecommunications
€3.5M Company: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 3,500,000 on a company. The controller operated a loyalty program in France and 16 other EU countries, using customer data obtained… FRANCE ·CNIL ·Art. 6, 13, 32 +1 Controllers DPIA International Transfer Dec 30, 2025
€10,000 Roumasport S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on Roumasport S.R.L The controller failed to implement adequate technical and organisational measures, resulting in multiple… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Dec 30, 2025
€10,000 Ikea Ibérica: Insufficient legal basis for data processing The company installed cookies on an end users terminal device without prior consent of the data subject. SPAIN ·AEPD ·Art. 6 Consent Personal Data Cookies
€12,000 Madrileña Red de Gas: Insufficient technical and organisational measures to ensure information security The gas company did not have appropriate measures in place to verify the identity of the data subject. The person who filed the complaint alleges that the company e-mailed his… SPAIN ·AEPD ·Art. 32 Personal Data Security Law Enforcement
€3,140 UniCredit Bank Czech Republic and Slovakia, a.s.: Insufficient legal basis for data processing The bank established a personal bank account for a data subject without his consent or knowledge. The bank supposedly had his personal data available because the subject had… ÚOOÚ (CZ) ·Art. 6 ·Insufficient legal basis for data processing Personal Data Consent Insurance
€60,000 Debt collecting agancy (GESTIÓN DE COBROS, YO COBRO SL): Insufficient legal basis for data processing After the claimant did alledgedly not pay back a microcredit to an online credit agany, the claim was assigned to the debt collecting agancy. Subsequently, the latter startet… SPAIN ·AEPD ·Art. 5 Processing Insurance Supervisory Authorities
€980 Individual entrepreneur - no further details published: Insufficient technical and organisational measures to ensure information security The operator of an online game was exposed to several DDoS attacks which caused the malfunctioning of the servers. The attacker blackmailed the operator stating that the attacks… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 32 Security Personal Data Law Enforcement
€1,600 NAROBESA INV, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,600 on NAROBESA INV, S.L. The controller failed to react to requests made by the DPA. The original fine of EUR 2,000 was reduced to EUR… SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Controllers Dec 29, 2025
€300 SPAIN DPA: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 300 on an unkonwn person/entity. The controller failed to react to requests made by the DPA. AEPD ·Art. 58 ·Insufficient cooperation with supervisory authority Supervision Supervisory Authorities Controllers Dec 20, 2025
€600 4USPORT INSTALACIONES DEPORTIVAS, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 300 on 4USPORT INSTALACIONES DEPORTIVAS, S.L. The controller failed to react to requests made by the DPA. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Controllers Dec 20, 2025
€6,000 BLUE TEAM FLIGHT SCHOOL, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 6,000 on BLUE TEAM FLIGHT SCHOOL, S.L. The controller failed to react to requests made by the DPA. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Controllers Dec 20, 2025
€2,000 Elba Catering Distribuzioni s.r.I.s.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on Elba Catering Distribuzioni s.r.I.s. The controller installed video surveillance, which affected the public road. Furthermore,… ITALY ·Garante ·Art. 5, 13 Controllers Personal Data Supervisory Authorities Dec 18, 2025
€40,000 Anticimex s.r.l.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 40,000 on Anticimex s.r.l. Following termination of employment, the former employer requested to exercise his rights. The controller… ITALY ·Garante ·Art. 5, 12, 13 +2 Controllers Supervisory Authorities Processing Dec 18, 2025
€6,000 Comune di Nave: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Commune di Nave. The controller has installed an automatic licence plate recognition system which processes data on when a… ITALY ·Garante ·Art. 5, 6, 12 +2 DPIA Controllers Personal Data Dec 18, 2025
€120,000 Pioneer Hi-Bred Italia Sementi s.r.l.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 120,000 on Pioneer Hi-Bred Italia Sementi s.r.l. The controller installed satellite telematics tracking devices to monitor driving… ITALY ·Garante ·Art. 5, 6, 28 Controllers Supervisory Authorities Processing Dec 18, 2025
€40,000 LTL S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 40,000 on LTL S.p.A. The controller failed to respond within the legal time period to a request by a former employee to exercise their… ITALY ·Garante ·Art. 5, 12, 15 Personal Data Controllers Supervisory Authorities Dec 18, 2025
€175,000 HAN University of Applied Sciences: Insufficient technical and organizational measures to ensure information security. ⇄ 175.000 euro boete - Nederlandse Autoriteit Persoonsgegevens (AP). THE NETHERLANDS ·AP ·Art. 32 Security Personal Data Controllers Dec 15, 2025
€75,700 Chief Constable of the Police Service of Scotland: Insufficient technical and organisational measures to ensure information security Information Commissioner (ICO) fined Chief Constable of the Police Service of Scotland €75,700 on 2025-12-12 for: Insufficient technical and organisational measures to ensure… United Kingdom ·ICO ·Art. 5, 25, 32 +1 Security Education Public Authority Dec 12, 2025
€1M MOBIUS SOLUTIONS LTD: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 1,000,000 on MOBIUS SOLUTIONS LTD. The fined entity had been the former data processor for Deezer, which suffered a data breach in 2022.… FRANCE ·CNIL ·Art. 28, 29, 30 Processors Controllers Processing Dec 11, 2025
€75,474 Legal Entity: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 75,474 on a legal entity. Without a sufficient legal basis, the controller installed software on an employee's work computer which… SLOVENIA ·IP-RS ·Art. 5, 6 Controllers Processing Employees Dec 11, 2025
€15,000 Crowd Entertainment Limited: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 15,000 on Crowd Entertainment Limited. The controller failed to adequatly react to a data subjects request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Dec 10, 2025
€1,000 Compania de Apa Oltenia S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Compania de Apa Oltenia S.A. The controller failed to implement adequate technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 29, 32 Security Controllers Personal Data Dec 8, 2025
€5,100 Legal Entity: Insufficient fulfilment of data subjects rights The Slovenian DPA has imposed a fine of EUR 5,100 on a legal entity. The controller operated a website where natural persons could fil in their personal data in a form. The… SLOVENIA ·IP-RS ·Art. 12, 13 Personal Data Controllers Supervisory Authorities Dec 8, 2025
€12,000 Comune di Tuscania: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 12,000 on the Commune di Tuscania. The controller had been using video surveillance and licence plate recognition within its territory… ITALY ·Garante ·Art. 5, 6, 12 +5 Controllers Processors Monitoring Dec 4, 2025
€1,000 'Principe Umberto di Savoia' State Scientific and Linguistic High School: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on 'Principe Umberto di Savoia' State Scientific and Linguistic High School. The controller processed the personal data of… ITALY ·Garante ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Right of Access Controllers Dec 4, 2025
€3,600 DELAFRUIT, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,600 on DELAFRUIT, S.L. The controller installed video surveillance in the staff break area and dining room, but did not put up the… SPAIN ·AEPD ·Art. 5 Controllers Processing Video Surveillance Dec 1, 2025
€3,600 RISING SUN CAR RENTAL S..L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,600 on RISING SUN CAR RENTAL S..L. The controller used video surveillance to ensure security at its facility, affecting more areas than… SPAIN ·AEPD ·Art. 5, 13 Controllers Supervisory Authorities Personal Data Dec 1, 2025
€1.6M SPRINTER MEGACENTROS DEL DEPORTE, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,560,000 on SPRINTER MEGACENTROS DEL DEPORTE, S.L. The controller suffered a cyber attack due to insufficient technical and… SPAIN ·AEPD ·Art. 5, 34 Security Controllers Supervisory Authorities Nov 28, 2025
€400,000 Verisure Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 400,000 on Verisure Italy s.r.l. The controller had been active in direkt marketing activities. The controller failed to ensure that the… Garante ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles Retention Period Controllers Direct Marketing Nov 27, 2025
€1.5M AMERICAN EXPRESS CARTE FRANCE: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 1,500,000 on AMERICAN EXPRESS CARTE FRANCE. The controller used excessive cookies on its website and failed to adequately inform data… CNIL ·Art. 82 ·Insufficient legal basis for data processing Controllers Personal Data Cookies Nov 27, 2025
€4.5M Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer… CROATIA ·AZOP ·Art. 5, 6, 12 +4 International Transfer Privacy Shield Controllers Nov 24, 2025
€750,000 LES PUBLICATIONS CONDE NAST: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 750,000 on LES PUBLICATIONS CONDE NAST. The controller used multiple cookies on its website but failed to adequately implement them. FRANCE ·CNIL ·Art. 82 Controllers Cookies IP Address Nov 20, 2025
€60,000 STRATESYS TECHNOLOGY SOLUTIONS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 60,000 on STRATESYS TECHNOLOGY SOLUTIONS, S.L. The controller failed to implement adequate technical and organisational measures,… SPAIN ·AEPD ·Art. 5 Controllers Security Data Breaches Nov 19, 2025
€2,000 ASOCIACIÓN NACIONAL DE TASADORES Y PERITOS JUDICIALES INFORMÁTICOS: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 2,000 on the ASOCIACIÓN NACIONAL DE TASADORES Y PERITOS JUDICIALES INFORMÁTICOS. The controller published a court ruling which included… SPAIN ·AEPD ·Art. 13, 17 Personal Data Controllers Supervisory Authorities Nov 19, 2025
€3,000 Greencorp S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Greencorp S.R.L. The controller failed to implement adequate technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Nov 19, 2025
€800 SOBLADA RESTAURACIÓN, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 800 on SOBLADA RESTAURACIÓN, S.L. The controller installed video surveillance without providing the necessary information signs or… SPAIN ·AEPD ·Art. 5, 13 Controllers Supervisory Authorities Processing Nov 19, 2025