Skip to content
Content type · 749 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–100 of 749 sort newestlargest fineoldest
€400,000 CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined Caixabank, S.A. €400,000 for failing to implement sufficient technical and organizational measures to ensure information… Spain ·aepd ·Art. 5, 25 Privacy by Default Accountability Security Apr 15, 2026
€2,415 UODO (Poland) - DKN.5131.7.2022 An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone… Art. 5, 24, 25 +2 Processors Data Breaches Notification Obligation Apr 13, 2026
€2,500 BLUE PROJECTS S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined BLUE PROJECTS S.R.L. €2,500 on 2026-04-03 for: Insufficient technical and organisational… Romania ·ANSPDCP ·Art. 32 Security Supervisory Authorities Personal Data Apr 3, 2026
€100M Ridetech International B.V.: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) fined Ridetech International B.V. €100,000,000 on 2026-04-01 for: Insufficient legal basis for data processing. The Netherlands ·AP ·Art. 5, 44, 46 Processing Personal Data Supervisory Authorities Apr 1, 2026
€13,491 Legal Person: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Legal Person €13,491 on 2026-03-27 for: Insufficient technical and organisational measures to ensure information… Slovenia ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security IP Address Supervisory Authorities Mar 27, 2026
€125,000 RENAULT COMMERCIAL ROUMANIE S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined RENAULT COMMERCIAL ROUMANIE S.R.L. €125,000 on 2026-03-25 for: Insufficient technical and… Romania ·ANSPDCP ·Art. 28, 32 Security Supervisory Authorities Personal Data Mar 25, 2026
€4,000 ING Bank NV Amsterdam – Sucursala București S.A.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined ING Bank NV Amsterdam – Sucursala București S.A. €4,000 on 2026-03-23 for: Insufficient… Romania ·ANSPDCP ·Art. 32 Security Supervisory Authorities Insurance Mar 23, 2026
€3,000 Public and Private Domain SA: Insufficient legal basis for data processing Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Public and Private Domain SA €3,000 on 2026-03-20 for: Insufficient legal basis for data… Romania ·ANSPDCP ·Art. 5, 6, 12 +1 Personal Data Employees Processing Mar 20, 2026
€3,000 Domeniul Public și Privat SA: Insufficient legal basis for data processing Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Domeniul Public și Privat SA €3,000 on 2026-03-20 for: Insufficient legal basis for data… Romania ·ANSPDCP ·Art. 5, 6, 12 +1 Education Personal Data Public Authority Mar 20, 2026
€150,000 ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L. €150,000 for failing to implement sufficient technical and organizational measures to… Spain ·aepd ·Art. 5 Integrity and Confidentiality Principle Security Supervisory Authorities Mar 20, 2026
Austrian DSB rules 360-degree feedback unlawful without specific works agreement The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025. They worked as a manager in the controller’s finance department,… 2025-0.960.016 ·Austria ·Art. 6, 88 Legitimate Interest Personal Data Employees Mar 20, 2026
€450 Housing Association: Insufficient cooperation with supervisory authority Spanish Data Protection Authority (aepd) fined Housing Association €450 on 2026-03-13 for: Insufficient cooperation with supervisory authority. Spain ·aepd ·Art. 58 Supervision Supervisory Authorities Mar 13, 2026
€600 SERVICIOS INMOBILIARIOS Y GESTIÓN RCL MADRID, S.L.: Insufficient cooperation with supervisory authority Spanish Data Protection Authority (aepd) fined SERVICIOS INMOBILIARIOS Y GESTIÓN RCL MADRID, S.L. €600 on 2026-03-13 for: Insufficient cooperation with supervisory authority. Spain ·aepd ·Art. 58 Supervisory Authorities Supervision Mar 13, 2026
€8,000 Altex Romania S.R.L.: Insufficient cooperation with supervisory authority Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Altex Romania S.R.L. €8,000 on 2026-03-05 for: Insufficient cooperation with supervisory… ANSPDCP ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Personal Data Mar 5, 2026
Tien gemeenten elk EUR 25.000 boete voor overtreding AVG-artikelen 5, 6 en 9 Het gaat om de gemeenten Delft, Ede, Eindhoven, Gooise Meren, Haarlemmermeer, Hilversum, Huizen, Tilburg, Veenendaal en Zoetermeer. Ze krijgen elk een boete van EUR 25.000,- voor… Enforcement Supervision NL Mar 2, 2026
€1,000 Ciemme S.r.l.s.: Insufficient cooperation with supervisory authority Italian Data Protection Authority (Garante) fined Ciemme S.r.l.s. €1,000 on 2026-02-26 for: Insufficient cooperation with supervisory authority. Italy ·Garante ·Art. 58 Supervision Supervisory Authorities Telecommunications Feb 26, 2026
€2,000 SC Hayat Dent SRL: Insufficient cooperation with supervisory authority Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined SC Hayat Dent SRL €2,000 on 2026-02-20 for: Insufficient cooperation with supervisory… Romania ·ANSPDCP ·Art. 83 Supervisory Authorities Supervision Personal Data Feb 20, 2026
€3,000 Your Consulting SRL: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Your Consulting SRL €3,000 on 2026-02-19 for: Insufficient technical and organisational… Romania ·ANSPDCP ·Art. 25, 32 Security Supervisory Authorities Personal Data Feb 19, 2026
€5,500 Slovenia DPA: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined an unnamed party €5,500 on 2026-02-16 for: Insufficient technical and organisational measures to ensure… Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Supervisory Authorities Processing Agreement Feb 16, 2026
€150,000 AEPD (Spain) - EXP202306354 (PS/00312/2024) The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested… Art. 5, 6 Personal Data Integrity and Confidentiality Principle Access Controls Feb 11, 2026
€20,000 Tensa Art Design S.A: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 20,000 onTensa Art Design S.A.The DPA began investigating the controller's data processing activities, but the controller failed to… ROMANIA ·ANSPDCP ·Art. 58, 83 Supervisory Authorities Supervision Controllers Feb 5, 2026
€10,000 GENPACT ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Access Controls Controllers Feb 4, 2026
€25,000 Municipality of Eindhoven: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Eindhoven. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Huizen: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Huizen. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Ede: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Ede. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Controllers Feb 3, 2026
€25,000 Municipality of Gooise Meren: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Gooise Meren. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Tilburg: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Tilburg. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Hilversum: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Hilversum. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Zoetermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Zoetermeer. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Controllers Feb 3, 2026
€1,000 Alliance for the Union of Romanians (AUR) Party: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on the Alliance for the Union of Romanians (AUR) Party. The controller failed to react adequately to a data subject's request to… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 +1 Personal Data Controllers Processing Agreement Feb 3, 2026
€25,000 Municipality of Delft: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Delft. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Veenendaal: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… THE NETHERLANDS ·AP ·Art. 6, 9 Political Opinions Health Data Public Authority Feb 3, 2026
€10,000 Natural Person: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 10,000 on a natural person. The controller operated a website on which identity cards containing personal data, including special… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 +6 Criminal Data Personal Data Health Data Jan 30, 2026
€4,850 Slovenia DPA: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined an unnamed party €4,850 on 2026-01-20 for: Insufficient technical and organisational measures to ensure… Art. 25 ·Insufficient technical and organisational measures to ensure information security Supervisory Authorities Security IP Address Jan 20, 2026
€15,000 Continental Automotive Products SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Continental Automotive Products SRL. The controller failed to implement adequate technical and organisational measures,… ROMANIA ·ANSPDCP ·Art. 5, 32 Security Controllers Law Enforcement Jan 19, 2026
€15,000 Continental Automotive Products SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van €15.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 32 Security Accountability Controllers NL Jan 19, 2026
€21,650 Timegrip AS: Insufficient fulfilment of data subjects rights The Norwegian DPA has imposed a fine of EUR 21,650 on Timegrip AS. The controller had been tracking the working hours of employees at a company that went bankrupt. A former… NORWAY ·Datatilsynet ·Art. 15 Personal Data Controllers IP Address Jan 16, 2026
€1,500 Italian DPA fines butcher €1,500 for unlawful video surveillance lacking information signs The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of security… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 13 +2 Video Surveillance Fairness & Transparency Controllers Jan 16, 2026
DSB Austria: No fine imposed on COVID mask shop for cookie consent failure Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop… 2026-0.043.390 ·Art. 5, 12, 13 Cookies IP Address Personal Data Jan 16, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PREMIER RESTAURANTS ROMANIA SRL. The controller failed to implement adequate technical and organisational measures, resulting… ANSPDCP ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Law Enforcement Jan 13, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 8.000 euro boete - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Processing NL Jan 13, 2026
€2,000 Money Seeds S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Money Seeds S.R.L. The controller failed to fulfil a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervisory Authorities Jan 8, 2026
€2,000 Money Seeds S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. De Roemeense toezichthouder ANSPDCP heeft aan Money Seeds S.R.L., een financiële en consultancyonderneming, een boete van 2.000 euro opgelegd wegens het niet honoreren van een… ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Data Controller Controllers NL Jan 8, 2026
€27M FREE MOBILE: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 27 miljoen euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 5, 32 Security Data Breaches Access Controls NL Jan 8, 2026
€5,000 Sole Trader: Non-compliance with general data processing principles Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Sole Trader €5,000 on 2026-01-06 for: Non-compliance with general data processing principles. Slovenia ·Art. 5 ·Non-compliance with general data processing principles IP Address Processing Supervisory Authorities Jan 6, 2026
€960 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined a data controller EUR 1,450 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Dec 30, 2025
€10,000 Roumasport S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on Roumasport S.R.L The controller failed to implement adequate technical and organisational measures, resulting in multiple… ROMANIA ·ANSPDCP ·Art. 32 Security IP Address Law Enforcement Dec 30, 2025
€960 POLEN, Autoriteit voor Persoonsgegevens: Onvoldoende samenwerking met de toezichthoudende instantie. Een boete van 960 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 58 Personal Data Supervisory Authorities Data Controller NL Dec 30, 2025