Skip to content
Content type · 151 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–100 of 151 sort newestlargest fineoldest
€2,000 PAVLOS BIKOS SOLE PROPRIETORSHIP DENTAL PRIVATE CAPITAL COMPANY: Insufficient cooperation with supervisory authority The Greek DPA has imposed a fine of EUR 2,000 on PAVLOS BIKOS SOLE PROPRIETORSHIP DENTAL PRIVATE CAPITAL COMPANY. The fined party was a data processor in case ETid: 2880. During… GREECE ·HDPA ·Art. 31 Supervisory Authorities Controllers Supervision Jul 11, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 550,000 on Vodafone – PANAFON A.E.E.T. The controller failed to implement sufficient technical and organisational measures to ensure data… GREECE ·HDPA ·Art. 5, 28 Controllers Security Telecommunications Jun 25, 2025
€40,000 KARAMBELAS KONSTANTINOS & CO. E.E.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 40,000 on KARAMBELAS KONSTANTINOS & CO. E.E. The processor, which was processing data for a telecommunications provider (ETid: 2878),… GREECE ·HDPA ·Art. 29, 32 Security Telecommunications Processors Jun 25, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 550.000 euro - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 28 Security Data Processor Controllers NL Jun 25, 2025
€12,000 ALBOR ENERGÍA S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 12,000 on ALBOR ENERGÍA S.L. The controller used third parties acting as data processors for direct marketing purposes. The organisation of… SPAIN ·aepd ·Art. 28 Controllers Processing Agreement Processors Jun 16, 2025
€12,000 ALBOR ENERGÍA S.L.: Onvoldoende juridische basis voor de verwerking van gegevens. 12.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 28 Processors Processing Data Processor NL Jun 16, 2025
€100,000 Energia Verde S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Energia Verde S.p.A. The controller had been active in direct marketing activities. The controller processed data without a… ITALY ·Garante ·Art. 5, 6, 7 +13 IP Address Controllers Processing Agreement Apr 29, 2025
€20,000 Cooperativa Sociale Quadrifoglio: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio. The entity that was fined, acting as a data processor, forwarded files containing the… ITALY ·Garante ·Art. 28, 32 Processors Controllers Health Data Apr 29, 2025
€100,000 Energia Verde S.p.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 100.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +13 Data Controller Processing Security NL Apr 29, 2025
€40,000 Municipality of Bologna: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 40,000 on the Municipality of Bologna. The controller used a data processor (Cooperativa Sociale Quadrifoglio | ETid: 2274) to process… ITALY ·Garante ·Art. 5, 6, 9 Processors Controllers Health Data Apr 29, 2025
€40,000 Gemeente Bologna: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 40.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 Security Processors Health Data NL Apr 29, 2025
€20,000 Cooperativa Sociale Quadrifoglio: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 20.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 28, 32 Health Data Security Processors NL Apr 29, 2025
€500,000 Chamber of Commerce, Industry, Services and Navigation of Spain: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500,000 on the Chamber of Commerce, Industry, Services and Navigation of Spain. Due to its function within the Spanish Executive, the… aepd ·Art. 5, 6, 14 ·Insufficient legal basis for data processing Controllers Processors Fairness & Transparency Apr 15, 2025
€500,000 Handelskamer, Industrie, Dienstverlening en Transport van Spanje: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 500.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 6, 14 Processors Processing Data Processor NL Apr 15, 2025
€6,000 LÃSER METALPRINT 3D, S.L.: Insufficient data processing agreement The Spanish DPA imposed a fine on LÃSER METALPRINT 3D, S.L. The controller hired a third company to install and maintain a surveillance system. The controller and the hired… SPAIN ·aepd ·Art. 28 Controllers Processing Agreement Monitoring Apr 14, 2025
€80,000 Company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 80,000 on a company. The company was responsible for monitoring parking lots at several supermarkets and a hospital. However, it… CROATIA ·azop ·Art. 5, 6, 32 Audit Logs Processing Agreement Monitoring Mar 24, 2025
€200,000 ORANGE BANK, S.A. SUCURSAL EN ESPAÑA: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 200,000 on ORANGE BANK, S.A. SUCURSAL EN ESPAÑA. The AEPD reacted to multiple complaints of private individuals regarding a data… SPAIN ·aepd ·Art. 5 Processors Controllers Security Feb 14, 2025
€500,000 MARINA SALUD, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 500,000 on MARINA SALUD, S.A. Marina Salud, acting as a processor for a health authority, engaged sub-processors without obtaining the… SPAIN ·aepd ·Art. 28 Processors Controllers Processing Agreement Feb 5, 2025
€100,000 Realmaps S.r.l.: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 100,000 on Realmaps S.r.l. The controller collects data on every real estate owner and sells it to customers who use it for direct marketing… ITALY ·Garante ·Art. 5, 6, 7 +12 Controllers IP Address Processors Jan 16, 2025
€45M Vodafone GmbH: Non-compliance with general data processing principles The Federal Commissioner for Data Protection and Freedom of Information (BfDI) has imposed a fine of EUR 45,000,000 on Vodafone GmbH. The controller failed to properly supervise a… BfDI Controllers Processors IP Address Jan 1, 2025
€300,000 LÍNEA DIRECTA ASEGURADORA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 300,000 on LÍNEA DIRECTA ASEGURADORA, S.A.. A data subject had filed a complaint with the DPA stating that they had inquired about a car… SPAIN ·aepd ·Art. 6, 28 Insurance Personal Data Processors Dec 23, 2024
€6,700 Uptime-IT ApS: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 9,700 on Uptime-IT ApS. Uptime-IT ApS, the data processor for a chiropractic clinic, failed to install sufficient security measures,… DENMARK ·Datatilsynet ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processors Nov 12, 2024
€250,000 COSMOSPACE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 250,000 on COSMOSPACE. The controller is a company that offers personalized clairvoyance consultations by telephone. As part of its services,… FRANCE ·CNIL ·Art. 5, 9 Controllers Prior Consultation IP Address Sep 26, 2024
€150,000 TELEMAQUE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 150,000 on TELEMAQUE. The controller is a company that offers digital services in the field of divinatory arts, including fortune telling by… FRANCE ·CNIL ·Art. 5, 9 Controllers Direct Marketing Processors Sep 26, 2024
€190,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 190,000 on a hospital. The hospital had suffered a data breach in which radiological image files were irrevocably lost. AZOP had… CROATIA ·azop ·Art. 5, 6, 12 +4 Data Breaches Healthcare Healthcare Sep 13, 2024
€100,000 Covid 19 Test Lab: Insufficient technical and organisational measures to ensure information security The Austrian DPA has imposed a fine of EUR 100,000 on a Covid 19 test lab. The controller failed to implement sufficient technical and organisational measures, resulting in a data… AUSTRIA ·dsb ·Art. 5, 9, 28 +2 Data Breaches Controllers Healthcare Jun 6, 2024
€50,000 A.S. Watson Health & Beauty Continental Europe B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 600,000 on A.S. Watson Health & Beauty Continental Europe B.V.. The controller had tracked visitors to their drugstore website… THE NETHERLANDS ·AP ·Art. 5 Cookies Controllers Consent May 2, 2024
€36,000 HISPAPOST, S.A.: Insufficient fulfilment of data breach notification obligations The Spanish DPA has imposed a fine on HISPAPOST, S.A.. The police had found over a thousand abandoned letters containing the Hispapost logo. Hispapost had been contracted by… SPAIN ·aepd ·Art. 28 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Feb 1, 2024
€20,000 Pharmaceutical wholesaler: €20,000 fine The French DPA has imposed a fine of EUR 20,000 on a pharmaceutical wholesaler due to violations of several regulations, including a lack of data security and insufficient… FRANCE ·CNIL ·Unknown Accountability Controllers Processing Agreement Jan 24, 2024
€20,000 City of Kópavogur: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 20,000 on the city of Kópavogur. The city had used the Google Education system without sufficiently complying with data protection… ICELAND ·Art. 5, 24, 28 ·Non-compliance with general data processing principles Processing Agreement IP Address Education Dec 6, 2023
€16,600 Reykjanesbær municipality: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 16,600 on the municipality of Reykjanesbær. The municipality had used the Google Education system without sufficiently complying with… ICELAND ·Art. 5, 24, 28 ·Non-compliance with general data processing principles Processors Education Processing Agreement Dec 6, 2023
€13,300 City of Reykjavik: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 13,300 on the city of Reykjavik. The city had used the Google Education system in schools without sufficiently complying with data… ICELAND ·Art. 5, 24, 28 ·Non-compliance with general data processing principles Processing Agreement Processors IP Address Dec 6, 2023
€18,600 City of Hafnarfjörður: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 18,600 on the city of Hafnarfjörður. The city had used the Google Education system without sufficiently complying with data protection… ICELAND ·Art. 5, 24, 28 ·Non-compliance with general data processing principles Processing Agreement IP Address Education Dec 6, 2023
€16,600 Garðabær municipality: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 16,600 on the municipality of Garðabær. The municipality had used the Google Education system without sufficiently complying with data… ICELAND ·Art. 5, 24, 28 ·Non-compliance with general data processing principles Education Processors Processing Agreement Dec 6, 2023
€600,000 GROUPE CANAL +: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 600,000 on GROUPE CANAL+ for multiple violations of the GDPR. The DPA determined that the data controller failed to demonstrate that it… FRANCE ·CNIL ·Art. 7, 12, 13 +5 Data Breaches Controllers IP Address Oct 12, 2023
€1M Autostrade per l'Italia spa: Non-compliance with general data processing principles The Italian DPA has fined Autostrade per l'Italia spa ('ASPI') EUR 1 million for unlawfully processing the data of approx. 100,000 registered users of the toll reimbursement app… ITALY ·Garante ·Art. 5, 13, 28 Controllers Fairness & Transparency IP Address Jun 22, 2023
€2.3M Debt collection agency: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 2,265,000 on a debt collection agency. The fine is the highest ever imposed by AZOP. AZOP had received an anonymous complaint in… CROATIA ·azop ·Art. 6, 13, 28 +1 Personal Data Security Controllers May 4, 2023
€30,000 Bolzano municipality: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 30,000 on Bolzano municipality. The Bolzano health authority had reported a data breach to the DPA involving unauthorized access to the… ITALY ·Garante ·Art. 5, 25, 32 +1 Data Breaches Integrity and Confidentiality Principle Health Data Mar 23, 2023
€125,000 CITYSCOOT: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 125,000 on CITYSCOOT, a company that rents out motor scooters for short periods. During its investigation, the DPA found that CITYSCOOT,… FRANCE ·CNIL ·Art. 5, 28, 82 IP Address Processing Agreement Processors Mar 16, 2023
€1,000 Razmataz Live s.r.l..: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1,000 on Razmataz Live s.r.l.. Razmataz had contracted a processor to carry out marketing campaigns, which the processor failed to… ITALY ·Garante ·Art. 5, 6, 28 Processors Controllers Processing Agreement Mar 2, 2023
€7,200 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 7,200 on a company. The controller had suffered a data breach that resulted in the loss of personal data. During its investigation, the… POLAND ·UODO ·Art. 5, 24, 25 +1 Data Breaches Security Controllers Feb 8, 2023
€321 Housing association: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 321 on a housing association. The controller had suffered a data breach involving the theft of documents, including a copy of a notarial… POLAND ·UODO ·Art. 5, 28, 33 +1 Data Breaches Notification Obligation Article 19 GDPR - Notification of Rectification, Erasure or Restriction Feb 7, 2023
€30,000 Verizon Connect Italy S.p.A.: Insufficient legal basis for data processing The Italian DPA has fined Verizon Connect Italy S.p.A. EUR 30,000. An individual who worked for a Verizon customer had filed a complaint with the DPA. Verizon had installed GPS… Garante ·Art. 5, 6, 28 ·Insufficient legal basis for data processing Processors Controllers IP Address Dec 15, 2022
€5,000 Societatea Energetică Electrica S.A.: Insufficient data processing agreement The Romanian DPA has fined Societatea Energetică Electrica S.A. EUR 5,000 for a violation of Art. 28 (3) a) GDPR. ROMANIA ·ANSPDCP ·Art. 28 Processing Agreement Data Processor Processing Dec 15, 2022
€60,000 INFORMÁTICA MÉDICA, S.L.: Insufficient data processing agreement The Spanish DPA has imposed a fine of EUR 60,000 on INFORMÁTICA MÉDICA, S.L.. The company acted as a processor for other companies and had engaged a subcontractor without,… SPAIN ·aepd ·Art. 28 Processing Agreement Processors Controllers Nov 7, 2022
€4.3M Portuguese National Statistical Institute: Non-compliance with general data processing principles The Portuguese DPA has fined the Portuguese National Statistical Institute EUR 4,3 million. The DPA found numerous violations of the GPDR in connection with the 2021 census in… PORTUGAL ·CNPD ·Art. 5, 9, 12 +5 DPIA Privacy Shield Privacy Impact Assessment Nov 2, 2022
Datatilsynet (Denmark) - 2020-431-0061 (Helsingor decision no. 4) This is the Danish DPA's fourth decision in the case relating to Helsingor municipality's processing of personal data in primary and lower secondary school. Helsingor… 2020-431-0061 (Helsingor decision no. 4) ·Art. 28, 36, 58 DPIA Privacy Impact Assessment Controllers Sep 28, 2022
Datatilsynet (Denmark) - 2020-422-0026 The Danish DPA had decided to investigate three research projects of Region Syddanmark (the controller) with regards to its processing activities, the use of processors, data… 2020-422-0026 ·Art. 5 Controllers Processors Processing Sep 28, 2022