Content type · 847 documents in this view · 3,813 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3589 Processing 2636 Personal Data 2395 Controllers 2018 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
€10,000 Monza and Brianza Local Education Authority: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Monza and Brianza Local Education Authority €10,000 for failing to establish a sufficient legal basis for data processing… Italy · ·Art. 5, 6 Jul 23, 2026
€30,000 Emiglia-Romagna Regional Employment Agency: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Emiglia-Romagna Regional Employment Agency €30,000 for violations of Articles 5, 6, and 9 of the GDPR concerning an… Italy · ·Art. 5, 6, 9 Jul 23, 2026
€8,000 Municipality of Terralba: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of Terralba €8,000 for processing personal data without a sufficient legal basis. The Garante found that the… Italy · ·Art. 5, 6, 24 +2 Jul 23, 2026
€6,500 Top Secrert Investigazioni e sicurezza s.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Top Secrert Investigazioni e sicurezza s.r.l. €6,500 for violating the general data processing principles under Article… Italy · ·Art. 5, 13 Jul 23, 2026
HUF 2M NAIH-11443-3/2026 The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The… Hungary ·Art. 12, 13 Jul 22, 2026
€90,000 AEPD · PS-00159-2025 On 13 December 2024, the DPA received a complaint against ACVIL Aparcamientos, S.L.U., the controller, concerning a request for video surveillance footage from a car park. The… Spain ·Art. 14, 15
€20,000 Garante · 471/2026 The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Italy ·Art. 5, 6, 10 +1 Jul 18, 2026
APDCAT sanctions Madremanya City Council for inadequate redaction of sensitive data in On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing… PS-0036/2026 ·Spain ·Art. 5, 31 Jul 17, 2026
€100,000 Orange Romania SA: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Orange Romania SA €100,000 for failing to implement sufficient technical and… ·Art. 25, 32 ·Insufficient technical and organisational measures to ensure information security Jul 17, 2026
€1M CNIL · SAN-2022-011 The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French… France ·Art. 12, 14, 15 +2
AEPD · EXP202102529 A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3
€200,000 Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first… PS-00020-2025 ·Spain · Jul 16, 2026
€6,000 Municipality of Rieti: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Municipality of Rieti €6,000 for violations of general data processing principles under the GDPR. The enforcement action… Italy · ·Art. 5, 12, 24 +3 Jul 14, 2026
€2M Garante fines Lusha Systems Inc. over unauthorized B2B contact database Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was a… Italy ·Art. 3, 5, 6 +2 Jul 14, 2026
€120,000 NIER Ingeriegna S.p.A. SB: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined NIER Ingegneria S.p.A. SB €120,000 for failing to implement adequate technical and organizational measures to ensure… Italy · ·Art. 5, 32 Jul 14, 2026
€57,839 Fine against Ascendex Technology SRL The Romanian DPA (ANSPDCP) launched an investigation into the cryptocurrency exchange platform Ascendex Technology SRL (the controller). The DPA was notified by the French DPA… Romania · ·Art. 4, 12, 17 +1
€158,000 Garante · 487/2026 Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Art. 3, 5, 12 +7 Jul 3, 2026
IMY-2024-2904 The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of… IMY-2024-2904 ·Sweden ·Art. 13 Jul 3, 2026
€1.4M EstEnergy S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined EstEnergy S.p.A. €1,400,000 for violations of general data processing principles under Article 5(1) of the GDPR, alongside… Italy · ·Art. 5, 12, 13 +3 Jul 3, 2026
€23,750 Società Editoriale Il Fatto S.p.A.: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Società Editoriale Il Fatto S.p.A. €23,750 for processing personal data without a sufficient legal basis, in violation of… Italy · ·Art. 5 Jul 3, 2026
€120,000 Experian Italia S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Experian Italia S.p.A. €120,000 for violating GDPR Articles 5(1)(a) and (c), 12, 15, and 25, concerning non-compliance with… Italy · ·Art. 5, 12, 15 +1 Jul 3, 2026
€15,000 University of Pisa: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the University of Pisa €15,000 for failing to implement adequate technical and organizational measures to ensure information… Italy · ·Art. 5, 6, 25 +1 Jul 3, 2026
€5.8M Hera Comm S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Hera Comm S.p.A. €5,800,000 for violations of the general data processing principles under Article 5 of the GDPR, alongside… Italy · ·Art. 5, 12, 13 +3 Jul 3, 2026
€2,000 Municipality of Villaputzu: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of Villaputzu €2,000 for processing personal data without a sufficient legal basis. The enforcement action… Italy · ·Art. 5, 6 Jul 3, 2026
€10,000 Giuliano Isontina University Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the Giuliano Isontina University Health Authority €10,000 for failing to implement adequate technical and organizational… Italy · ·Art. 5, 9, 25 +1 Jul 3, 2026
RON 26,172 The Romanian DPA (ANSPDCP) launched an investigation into a bank, Banca Transilvania S.A (the controller), following a data subject’s complaint. The data subject claimed that their personal data associated with their bank account had been processed without their… 02/07/2026 ·Romania ·Art. 32
€158,000 Character Technologies Inc.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Character Technologies Inc. €158,000 for violations of multiple GDPR provisions, including Article 5(2) on general data… Italy · ·Art. 5, 12, 13 +5 Jul 3, 2026
€5,000 Banca Transilvania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Banca Transilvania S.A. €5,000 on July 2, 2026, for failing to implement sufficient… Romania · ·Art. 32 Jul 2, 2026
€11,000 Ascendex Technology SRL: Insufficient fulfilment of data subjects rights The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Ascendex Technology SRL €11,000 for insufficient fulfillment of data subjects' rights. The… Romania · ·Art. 12, 17 Jul 1, 2026
€450,000 VDAI fines medical company €450,000 for inadequate security measures in data breaches Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Lithuania ·Art. 5, 24 Jun 19, 2026
€6,600 Garante · 462/2026 The case involves a worker (the data subject), his former employer (the controller), and the staffing agency that had provided the company with the worker. In late 2023 the data… Italy ·Art. 2, 4, 5 +2 Jun 18, 2026
€10,000 Docplanner Italy S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined Docplanner Italy S.r.l. €10,000 for failing to implement sufficient technical and organizational measures to ensure… ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Jun 18, 2026
€90,000 Acquirente Unico S.p.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) fined Acquirente Unio S.p.A. €90,000 for insufficient fulfilment of data subjects' rights under GDPR Articles 12, 16, and 28. The… Italy · ·Art. 12, 16, 28 Jun 18, 2026
€20,000 Enna Provincial Health Authority: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Enna Provincial Health Authority €20,000 for violating GDPR Articles 5, 6, 10, and 12, which concern general data… Italy · ·Art. 5, 6, 10 +1 Jun 18, 2026
€6,600 Cosmint S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Cosmint S.p.A. €6,600 for violating general data processing principles in the employment sector, specifically under Articles… Italy · ·Art. 5, 6, 13 Jun 18, 2026
€2,075 Edizioni Grandangolo di Giuseppe Castaldo: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Edizioni Grandangolo di Giuseppe Castaldo €2,075 for failing to comply with general data processing principles under Articles… Italy · ·Art. 5, 12, 13 +4 Jun 18, 2026
€10,000 Altex Romania S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Altex Romania S.R.L. €10,000 for failing to implement sufficient technical and… ·Art. 32, 33, 34 ·Insufficient technical and organisational measures to ensure information security Jun 18, 2026
€5,000 Garante · 457/2026 The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A… Italy ·Art. 5, 6, 12 +2 Jun 18, 2026
€460,000 Garante · 476/2026 Two former employees (the data subjects) of Piaggio (the controller) were dismissed for just cause in March 2023. Following the termination of their employment, they asked the… Italy ·Art. 5, 6, 12 +2 Jun 18, 2026
€1,000 Dormeo Home SRL: Insufficient fulfilment of data subjects rights The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Dormeo Home SRL €1,000 for insufficient fulfillment of data subjects' rights under the… Romania · ·Art. 6, 21 Jun 16, 2026
€2,000 SSG SELECT SOLUTIONS S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined SSG Select Solutions S.R.L. €2,000 for failing to implement adequate technical and… Romania · ·Art. 29, 32 Jun 15, 2026
€2,760 UODO fines accounting firm €2,760 for email breach security failures An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained… Poland ·Art. 5, 24, 25 +1 Jun 13, 2026
€95,000 Market-In: Non-compliance with general data processing principles The Hellenic Data Protection Authority (HDPA) fined Market-In €95,000 for violations of the general data processing principles under Article 5 GDPR, including failures related to… Greece · ·Art. 5, 12, 13 +2 Jun 12, 2026
€5,000 Națională Poșta Română: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Națională Poșta Română €5,000 on 2026-06-12 for: Insufficient technical and organisational… Romania · ·Art. 32 Jun 12, 2026
€65,000 MEDE S.A.: Non-compliance with general data processing principles The Hellenic Data Protection Authority fined MEDE S.A. €65,000 for violating general data processing principles under Article 5 GDPR, along with failures concerning transparency… Greece · ·Art. 5, 12, 13 +2 Jun 12, 2026
€4,500 Lecce Local Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the Lecce Local Health Authority €4,500 for failing to implement adequate technical and organizational measures to ensure… Italy · ·Art. 5, 29, 32 Jun 11, 2026
€1,000 Pietro d'Abano State Vocational School: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Pietro d'Abano State Vocational School €1,000 for processing personal data without a sufficient legal basis, finding… Italy · ·Art. 5, 6 Jun 11, 2026
€15,300 Green Partner S.r.l.s.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Green Partner S.r.l.s. €15,300 for violations of multiple GDPR provisions, including Articles 5, 6, 7, 12, 15–22, and 28,… Italy · ·Art. 5, 6, 7 +3 Jun 11, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland · ·Art. 5, 28, 30 +2 Jun 11, 2026
UODO reprimands hospital for inadequate processor oversight and email security failures The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Poland ·Art. 5, 24, 25 +3 Jun 11, 2026