Skip to content
Content type · 1,114 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–100 of 1,114 sort newestlargest fineoldest
€500,000 AEPD fines bank €500,000 for losing customer documents via courier service (Art. 32) Facts: The data protection authority (DPA) has fined a bank €500,000 after documents belonging to a customer were lost during delivery by a courier service. The authority ruled… Spain ·Art. 32 Controllers Security Personal Data Jan 13, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organizational measures to ensure information security. ⇄ 8.000 euro boete - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Security Processing Supervisory Authorities Jan 13, 2026
€1.7M CNIL fines data processor €1.7M for misconfigured disability-records software causing The data protection authority (DPA) has imposed a fine of €1,700,000 on a data processor that had incorrectly configured a software program. This program processed files related… France Controllers Processors Processing Jan 12, 2026
DSB: Art. 15 GDPR access right does not extend to full documents with third-party data The data protection authority (DPA) has determined that, according to Article 15 of the GDPR, an individual has the right to access personal data relating to them, but this right… 2025-0.395.497 ·Austria ·Art. 15 Right of Access Personal Data Supervisory Authorities Jan 12, 2026
€500 VOX ESPAÑA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500 on VOX ESPAÑA. The controller, a political party, posted a picture of of a receipt on its Facebook page. The picture of the recipt… SPAIN ·AEPD ·Art. 6 Personal Data Controllers IP Address Jan 10, 2026
€8,000 KVIKU SPAIN, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 8,000 on KVIKU SPAIN, S.L.The controller requires customers to send a photo of themselves holding their ID card when verifying their… AEPD ·Art. 5 ·Non-compliance with general data processing principles Retention Period Controllers Processing Jan 10, 2026
€18,500 Komendanta Miejskiego Policji w Krakowie: Non-compliance with general data processing principles The Polish DPA has imposd a fine of EUR 18,500 on the Komendanta Miejskiego Policji w Krakowie. The controller published personal data, including health data, of a data subject… POLAND ·UODO ·Non-compliance with general data processing principles Personal Data Education Public Authority Jan 9, 2026
€2,000 Money Seeds S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Money Seeds S.R.L. The controller failed to fulfil a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervisory Authorities Jan 8, 2026
€15M FREE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 15,000,000 on FREE. The controller suffered a data breach due to insufficient technical and organisational measures. This was caused by… FRANCE ·CNIL ·Art. 32, 34 Data Breaches Security Controllers Jan 8, 2026
€2,000 Money Seeds S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. ⇄ The Romanian supervisory authority ANSPDCP has imposed a fine of 2,000 euros on Money Seeds S.R.L., a financial and consultancy company, for failing to honor a data subject's… ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervision Jan 8, 2026
€27M FREE MOBILE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 27,000,000 on FREE MOBILE. The controller suffered a data breach due to insufficient technical and organisational measures. This was… FRANCE ·CNIL ·Art. 5, 32 Personal Data Controllers Security Jan 8, 2026
€10,000 Headquarter of a Fire Brigade: Insufficient legal basis for data processing The Greek DPA has imposed a fine of EUR 10,000 on a Fire Brigade Head Quarter. The controller had stored health data of an employee which had been in relation with her sick leave.… GREECE ·HDPA ·Art. 5 Controllers Processing Health Data Jan 8, 2026
VDAI (Lithuania) - Decision no. 3R-1700. ⇄ Facts: The Data Protection Authority (DPA) ruled that a gambling provider had lawfully transferred data to a processor for the purpose of sending invitations to sporting events,… 3R-1700 ·Litouwen Controllers Fairness & Transparency Personal Data Jan 7, 2026
Decision No. 3R-1700. Facts: The data protection authority (DPA) ruled that a gambling operator had lawfully transferred data to a processor for the purpose of sending invitations to sporting events,… 3R-1700 ·Lithuania ·VDAI Personal Data Fairness & Transparency Processors Jan 7, 2026
AEPD: fines of €400,000 and €300,000 for telecom providers in SIM card fraud ⇄ Facts: The Data Protection Authority has imposed a fine of 400,000 euros on a telephone company for unlawfully changing the ownership of a mobile phone subscription and issuing a… EXP202306073 ·Spanje Telecommunications Personal Data Supervisory Authorities Jan 7, 2026
€400,000 AEPD fines two telecom providers €400,000 and €300,000 for SIM card fraud Facts: The Data Protection Authority has fined a telecommunications company €400,000 for unlawfully changing the ownership of a mobile phone subscription and issuing a dual SIM… Spain ·Art. 6 Telecommunications IP Address Identification Jan 7, 2026
€232,379 Polish Postal Service: Lack of appointment of data protection officer The Polish DPA has imposed a fine of EUR 232,379 on the Polish Postal Service. The controller appointed a person as DPO who also held a managerial position with authority over… POLAND ·UODO ·Art. 38 Supervisory Authorities Controllers Personal Data Jan 2, 2026
€1,282 Unknown legal entity: Insufficient data processing agreement The Slovenian Supervisory Authority (Informacijski pooblaščenec) fined an unnamed legal entity €1,282 for maintaining an insufficient data processing agreement. The enforcement… Slovenia ·IP-RS ·Art. 28 Supervision Supervisory Authorities Processing Agreement Jan 1, 2026
€5,000 REVMA PLUS Retail S.A.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 5,000 on REVMA PLUS Retail S.A.. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… GREECE ·HDPA ·Art. 32 Controllers Processors Personal Data Dec 31, 2025
€6,000 I Mathisi: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) fined I Mathisi €6,000 on 2025-12-31 for: Insufficient fulfilment of data subjects rights. Greece ·HDPA ·Art. 12, 15, 31 Personal Data Supervisory Authorities Education Dec 31, 2025
€10,000 Thessaloniki–Thessaly Gas Supply Company S.A.: Insufficient data processing agreement The Greek DPA has imposed a fine of EUR 10,000 on Thessaloniki–Thessaly Gas Supply Company S.A. The controller, an energy provider, used external processors for direct marketing… GREECE ·HDPA ·Art. 28, 32 Controllers Processors Supervisory Authorities Dec 31, 2025
€10,000 SIGMA & KAPPA IMPORTING SOCIÉTÉ ANONYME: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 10,000 on SIGMA & KAPPA IMPORTING SOCIÉTÉ ANONYME. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A.… GREECE ·HDPA ·Art. 32 Processors Controllers Security Dec 31, 2025
€80,000 ONE WAY PRIVATE COMPANY: Non-compliance with general data processing principles The Greek DPA has imposed a fine of EUR 80,000 on ONE WAY PRIVATE COMPANY. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… GREECE ·HDPA ·Art. 5, 6, 7 +2 Controllers Processors Personal Data Dec 31, 2025
€20,000 Telecommunications company: Insufficient legal basis for data processing The Croatian DPA (azop) has imposed a fine of EUR 20,000 on a telecommunications company. A data subject had filed a complaint with the DPA claiming that the company was still… CROATIA ·AZOP ·Art. 5, 6 Personal Data Processing Telecommunications
€600 GERMANY DPA: Insufficient legal basis for data processing Unlawful use of a dashcam Art. 6 ·Insufficient legal basis for data processing Supervisory Authorities Processing Agreement Processing
€3.5M Company: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 3,500,000 on a company. The controller operated a loyalty program in France and 16 other EU countries, using customer data obtained… FRANCE ·CNIL ·Art. 6, 13, 32 +1 Controllers International Transfer DPIA Dec 30, 2025
€300 GERMANY DPA: Insufficient legal basis for data processing Unlawful use of a dashcam Art. 6 ·Insufficient legal basis for data processing Supervisory Authorities Processing Agreement Processing
€10,000 Roumasport S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on Roumasport S.R.L The controller failed to implement adequate technical and organisational measures, resulting in multiple… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Dec 30, 2025
€50 GERMANY DPA: Insufficient legal basis for data processing Unlawful use of a dashcam Art. 6 ·Insufficient legal basis for data processing Supervisory Authorities Processing Processing Agreement
SLOVAKIA DPA: Insufficient fulfilment of data subjects rights A Data Controller failed to comply with data subject´s request to access his/her personal data processed by audio recordings. Slovak Data Protection Office ·Art. 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Controllers
€118 GERMANY DPA: Insufficient legal basis for data processing Illegal disclosure of personal data relating to a third party. Art. 6 ·Insufficient legal basis for data processing Personal Data Supervisory Authorities Processing Agreement
€10,000 Roumasport S.R.L: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van €10.000 - De Roemeense nationale toezichthouder op de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Dec 30, 2025
€118 GERMANY, DPA: Insufficient legal basis for data processing. ⇄ 118 euro boete - Autoriteit voor gegevensbescherming van Saarland. Art. 6 ·Insufficient legal basis for data processing Processing Supervisory Authorities Processing Agreement Dec 30, 2025
€20,000 Telecommunications company: Insufficient legal basis for data processing. ⇄ The Croatian data protection authority (DPA) has imposed a fine of 20,000 euros on a telecommunications company. A data subject had filed a complaint with the DPA, claiming that… CROATIA ·AZOP ·Art. 5, 6 Personal Data Processing Accountability Dec 30, 2025
SLOVAKIA DPA: Insufficient technical and organisational measures to ensure information security Documents containing personal data were disposed of in the area of the municipal garbage dump. Slovak Data Protection Office ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Supervisory Authorities
SLOVAKIA DPA: Insufficient technical and organisational measures to ensure information security Violation of information security measures (no further information available at the moment) Slovak Data Protection Office ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Supervisory Authorities Processing Agreement
SLOVAKIA DPA: Insufficient legal basis for data processing Personal data have been unlawfully published on the website of a city within the framework of fulfilling its disclosure obligation under the Freedom of Information Act. However,… Slovak Data Protection Office ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Consent Processing
€960 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined a data controller EUR 1,450 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers
€2,000 Order of General Nurses, Midwives and Medical Assistants of Romania – Neamt Branch: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 2,000 on the Order of General Nurses, Midwives and Medical Assistants of Romania – Neamt Branch. The controller used video surveillance… ANSPDCP ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Controllers Supervisory Authorities Supervision Dec 29, 2025
€1,600 NAROBESA INV, S.L.: Insufficient cooperation with the supervisory authority. ⇄ 1.600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 58 Supervisory Authorities Controllers Supervision Dec 29, 2025
€1,600 NAROBESA INV, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,600 on NAROBESA INV, S.L. The controller failed to react to requests made by the DPA. The original fine of EUR 2,000 was reduced to EUR… SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Controllers Dec 29, 2025
€6,000 Geturhotels Srl: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 6,000 on Geturhotels Srl. The controller was involved in direct marketing operations, using personal data that had not been acquired or… ITALY ·Garante ·Art. 5, 6, 17 +1 Controllers Personal Data Processing Dec 23, 2025
€1.7M NEXPUBLICA FRANCE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 1,700,000 on NEXPUBLICA FRANCE. The controller, who was a software developer, created and offered a software package designed to manage… CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Controllers Security Processing Agreement Dec 22, 2025
€500,000 CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 500,000 on CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U. The controller used a communication tool that was not designed in… SPAIN ·AEPD ·Art. 25 Controllers Personal Data Security Dec 22, 2025
€6,000 BLUE TEAM FLIGHT SCHOOL, S.L.: Insufficient cooperation with the supervisory authority. ⇄ Een boete van 6.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 58 Supervisory Authorities Controllers Supervision Dec 20, 2025
€300 SPAIN DPA: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 300 on an unkonwn person/entity. The controller failed to react to requests made by the DPA. AEPD ·Art. 58 ·Insufficient cooperation with supervisory authority Supervision Supervisory Authorities Controllers Dec 20, 2025
€600 4USPORT INSTALACIONES DEPORTIVAS, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 300 on 4USPORT INSTALACIONES DEPORTIVAS, S.L. The controller failed to react to requests made by the DPA. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Controllers Dec 20, 2025
€300 SPAIN, DPA: Insufficient cooperation with the supervisory authority. ⇄ Een boete van 300 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). AEPD ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Controllers Supervision Dec 20, 2025
€6,000 BLUE TEAM FLIGHT SCHOOL, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 6,000 on BLUE TEAM FLIGHT SCHOOL, S.L. The controller failed to react to requests made by the DPA. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Controllers Dec 20, 2025
€32,000 EXCEL HOTELS & RESORTS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on EXCEL HOTELS & RESORTS, S.A. The controller used guards to control access to its facility. The guards regularly left documents… SPAIN ·AEPD ·Art. 5 Controllers Security Personal Data Dec 20, 2025