Skip to content
Content type · 3,429 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–100 of 3,429 sort newestlargest fineoldest
€55,000 Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful The data controller for the case is a government body called the Agency for Digital Italy (AgID). AgID is tasked with driving the adoption of digital technologies in both… Italy ·Garante per la protezione dei dati personali ·Art. 5, 12, 14 +1 Controllers Personal Data Processing May 28, 2026
EDPB - Binding Decision 1/2026 On 10 August 2021, a data subject represented by noyb lodged a complaint with the Austrian DPA against Vlaamse Radio- en Televisieomroeporganisatie (VRT), the controller. The… Binding Decision 1/2026 ·European Union ·Art. 4, 57, 60 +3 Supervisory Authorities Cookies Telecommunications May 28, 2026
€700 Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy ·Garante per la protezione dei dati personali ·Art. 5, 9 Personal Data Healthcare Healthcare May 28, 2026
€6,000 Italian DPA: vehicle tracking by Liguria Health Agency lawful, information duties met A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller). The data subject was employed by the Ligurian Social and Health Care… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 13 +3 DPIA Privacy by Design Monitoring May 28, 2026
€5M IQVIA OPERATIONS FRANCE: Non-compliance with general data processing principles French Data Protection Authority (CNIL) fined IQVIA OPERATIONS FRANCE €5,000,000 on 2026-05-26 for: Non-compliance with general data processing principles. CNIL ·Art. 14, 25 ·Non-compliance with general data processing principles IP Address Healthcare Processing May 26, 2026
PLN 21,000 UODO (Poland) - DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Art. 24, 25, 28 +1 Security Controllers Processors May 25, 2026
PLN 26,711 UODO (Poland) - DKE.561.4.2026 The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance extending… Art. 5 Monitoring Video Surveillance Fairness & Transparency May 22, 2026
GBP 300 ICO (UK) - KRA Consultancy Ltd The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related services.… United Kingdom Recipient Direct Marketing Telecommunications May 20, 2026
PLN 33,700 UODO (Poland) - DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Art. 5, 24, 25 +3 Controllers Personal Data Security May 19, 2026
HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Art. 23 Personal Data Criminal Data Controllers May 13, 2026
€120,000 Isabel SA: Insufficient fulfilment of data subjects rights Belgian Data Protection Authority (APD) fined Isabel SA €120,000 on 2026-05-12 for: Insufficient fulfilment of data subjects rights. Belgium ·APD ·Art. 5, 12, 13 +2 Personal Data Supervisory Authorities Insurance May 12, 2026
HUF 15M NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Transparency Personal Data Information Provision Modalities and Communication Methods May 12, 2026
€86,000 Société Wallonne des Eaux: Insufficient legal basis for data processing Belgian Data Protection Authority (APD) fined Société Wallonne des Eaux €86,000 on 2026-05-12 for: Insufficient legal basis for data processing. Belgium ·APD ·Art. 5, 12, 13 +1 Education Public Authority Processing May 12, 2026
€177,000 Technology Company: Insufficient legal basis for data processing Belgian Data Protection Authority (APD) fined Technology Company €177,000 on 2026-05-12 for: Insufficient legal basis for data processing. Belgium ·APD ·Art. 5, 6, 12 +1 Employees Processing Supervisory Authorities May 12, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Fines Notification Obligation May 8, 2026
€4,920 Law Firm: Insufficient fulfilment of data subjects rights Belgian Data Protection Authority (APD) fined Law Firm €4,920 on 2026-05-08 for: Insufficient fulfilment of data subjects rights. Belgium ·APD ·Art. 5, 12, 13 +2 Personal Data Supervisory Authorities Insurance May 8, 2026
APD/GBA: Controller failed to provide copies of service sheets for GDPR access request The data subject was a technician employed by the controller. The controller used weekly handwritten service sheets as a system for recording working time. These sheets contained… 97/2026 ·Belgium ·Art. 12, 15 Right of Access Procedures Accuracy Right of Access May 6, 2026
€2,802 Slovenian DPA fines processor €2,802 for failing to patch known vulnerability (Art. 32) A processor was contracted by a company (the controller) to maintain an online store, fix errors, and provide support. This included ensuring that the controller had installed the… Slovenia ·IP ·Art. 32 Security Encryption Controllers May 1, 2026
HUF 10M NAIH fines online store HUF 10M for missing and inadequate privacy notice The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Personal Data Accountability Controllers Apr 30, 2026
€2,500 BLUE PROJECTS INDUSTRIES S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined BLUE PROJECTS INDUSTRIES S.R.L. €2,500 on 2026-04-30 for: Insufficient technical and… Romania ·ANSPDCP ·Art. 32 Security Supervisory Authorities Personal Data Apr 30, 2026
€1,790 Mayor of the City and Municipality of Myślenice: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined the Mayor of the City and Municipality of Myślenice €1,790 for insufficient fulfilment of personal data breach notification obligations under Article… Poland ·UODO ·Art. 33 Notification Obligation Data Breaches Public Authority Apr 30, 2026
€6,000 GATIGOS, S.L.: Insufficient cooperation with supervisory authority Spanish Data Protection Authority (aepd) fined GATIGOS, S.L. €6,000 on 2026-04-28 for: Insufficient cooperation with supervisory authority. Spain ·aepd ·Art. 58 Supervisory Authorities Supervision Apr 28, 2026
€1,000 Non-Profit Foundation: Insufficient cooperation with supervisory authority Belgian Data Protection Authority (APD) fined Non-Profit Foundation €1,000 on 2026-04-28 for: Insufficient cooperation with supervisory authority. Belgium ·APD ·Art. 31 Supervisory Authorities Supervision Apr 28, 2026
€240 Posada del León de Oro: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) fined Posada del León de Oro €240 on 2026-04-28 for: Non-compliance with general data processing principles. Spain ·aepd ·Art. 5, 13 IP Address Employees Processing Apr 28, 2026
€35,000 Crowd Entertainment Ltd: Insufficient legal basis for data processing Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Crowd Entertainment Ltd €35,000 on 2026-04-28 for: Insufficient legal basis for data… Romania ·ANSPDCP ·Art. 5 Personal Data Telecommunications Processing Apr 28, 2026
€4,000 SIPHONE 2020, S.L.: Insufficient legal basis for data processing Spanish Data Protection Authority (aepd) fined SIPHONE 2020, S.L. €4,000 on 2026-04-28 for: Insufficient legal basis for data processing. Spain ·aepd ·Art. 6, 13 IP Address Employees Processing Apr 28, 2026
€1,800 RESIDENCIAL ETXE-LAN, S.L.: Insufficient cooperation with supervisory authority Spanish Data Protection Authority (aepd) fined RESIDENCIAL ETXE-LAN, S.L. €1,800 on 2026-04-28 for: Insufficient cooperation with supervisory authority. Spain ·aepd ·Art. 58 Supervisory Authorities Supervision Apr 28, 2026
€8,500 Accountancy Firm: Insufficient legal basis for data processing Belgian Data Protection Authority (APD) fined Accountancy Firm €8,500 on 2026-04-23 for: Insufficient legal basis for data processing. Belgium ·APD ·Art. 5, 6, 12 +1 Processing Employees Supervisory Authorities Apr 23, 2026
€300,000 KONECTA BTO, S.L.: Insufficient technical and organisational measures to ensure information security Spanish Data Protection Authority (aepd) fined KONECTA BTO, S.L. €300,000 on 2026-04-22 for: Insufficient technical and organisational measures to ensure information security. Spain ·aepd ·Art. 5 Security Supervisory Authorities Apr 22, 2026
€5,000 Framos Italia s.r.l.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Framos Italia s.r.l. €5,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 12 +3 Employees IP Address Processing Apr 17, 2026
€6.6M Poste Italiane S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Poste Italiane S.p.a. €6,624,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 13 +4 IP Address Insurance Processing Apr 17, 2026
€6,000 Comune di Campo Calabro: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Comune di Campo Calabro €6,000 on 2026-04-17 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6 Employees Processing Supervisory Authorities Apr 17, 2026
€2,000 Io e te s.r.l.s.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Io e te s.r.l.s. €2,000 on 2026-04-17 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 13, 88 Processing Supervisory Authorities Apr 17, 2026
€2,000 Business Owner: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Business Owner €2,000 on 2026-04-17 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 13, 32 Processing Supervisory Authorities Apr 17, 2026
€5.9M Postepay S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Postepay S.p.a. €5,877,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 13 +4 IP Address Insurance Processing Apr 17, 2026
AKI (Estonia) - No. 2.1-1/24/397-890-38 OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to… No. 2.1-1/24/397-890-38 ·Art. 4, 5, 6 +8 Controllers Processors Data Controller Apr 16, 2026
€6,600 Utility Company: Insufficient legal basis for data processing Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Utility Company €6,600 on 2026-04-15 for: Insufficient legal basis for data processing. Slovenia ·Art. 5 ·Insufficient legal basis for data processing IP Address Supervisory Authorities Processing Apr 15, 2026
€400,000 CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined Caixabank, S.A. €400,000 for failing to implement sufficient technical and organizational measures to ensure information… Spain ·aepd ·Art. 5, 25 Privacy by Default Security Accountability Apr 15, 2026
€2,415 UODO (Poland) - DKN.5131.7.2022 An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone… Art. 5, 24, 25 +2 Processors Data Breaches Notification Obligation Apr 13, 2026
€2,500 BLUE PROJECTS S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined BLUE PROJECTS S.R.L. €2,500 on 2026-04-03 for: Insufficient technical and organisational… Romania ·ANSPDCP ·Art. 32 Security Supervisory Authorities Personal Data Apr 3, 2026
€100M Ridetech International B.V.: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) fined Ridetech International B.V. €100,000,000 on 2026-04-01 for: Insufficient legal basis for data processing. The Netherlands ·AP ·Art. 5, 44, 46 Processing Personal Data Supervisory Authorities Apr 1, 2026
€13,491 Legal Person: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Legal Person €13,491 on 2026-03-27 for: Insufficient technical and organisational measures to ensure information… Slovenia ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Supervisory Authorities IP Address Mar 27, 2026
€2,000 Physician: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Physician €2,000 on 2026-03-26 for: Insufficient fulfilment of data subjects rights. Italy ·Garante ·Art. 13 Personal Data Healthcare Supervisory Authorities Mar 26, 2026
€32M Intesa Sanpaolo S.p.A.: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) fined Intesa Sanpaolo S.p.A. €31,800,000 on 2026-03-26 for: Insufficient technical and organisational measures to ensure information… Italy ·Garante ·Art. 5, 24, 32 +1 Security Insurance Supervisory Authorities Mar 26, 2026
€3,000 Municipality: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Municipality €3,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6, 9 Employees IP Address Processing Mar 26, 2026
€96,000 Eni S.p.A.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Eni S.p.A. €96,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6 Processing Supervisory Authorities Mar 26, 2026
€1,000 Euro Bangla Minimarket in Jesi: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Euro Bangla Minimarket in Jesi €1,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 88 Employees Processing Supervisory Authorities Mar 26, 2026
€3,000 Piacenza Bar Association: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Piacenza Bar Association €3,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6 Education Public Authority DPIA Mar 26, 2026
€2,500 Comune di Cassino: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Comune di Cassino €2,500 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6 Education Public Authority Processing Mar 26, 2026
€2,000 Business Owner: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Business Owner €2,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 13, 88 Processing Supervisory Authorities Mar 26, 2026