Skip to content
Content type · 1,832 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

51–100 of 1,832 sort newestlargest fineoldest
GBP 120,000 ICO (UK) - Allay Claims Ltd Allay Claims Ltd (the controller) sent over 4 million direct marketing text messages to individuals promoting a different entity’s services. The DPA received over 48,000… United Kingdom Direct Marketing Telecommunications Consent Jan 15, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PREMIER RESTAURANTS ROMANIA SRL. The controller failed to implement adequate technical and organisational measures, resulting… ANSPDCP ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Law Enforcement Jan 13, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 8.000 euro boete - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Processing NL Jan 13, 2026
€200 DSB: Medical student fined for recording dementia patient video without Art 9 GDPR basis A medical student (the controller) worked as a ward attendant at a hospital. Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the… Austria ·Art. 4, 5, 6 +1 Legitimate Interest Personal Data Healthcare Jan 12, 2026
€500 VOX ESPAÑA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500 on VOX ESPAÑA. The controller, a political party, posted a picture of of a receipt on its Facebook page. The picture of the recipt… SPAIN ·aepd ·Art. 6 Social Media Personal Data Controllers Jan 10, 2026
€8,000 KVIKU SPAIN, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 8,000 on KVIKU SPAIN, S.L.The controller requires customers to send a photo of themselves holding their ID card when verifying their… aepd ·Art. 5 ·Non-compliance with general data processing principles Retention Period Controllers IP Address Jan 10, 2026
€18,500 Komendanta Miejskiego Policji w Krakowie: Non-compliance with general data processing principles The Polish DPA has imposd a fine of EUR 18,500 on the Komendanta Miejskiego Policji w Krakowie. The controller published personal data, including health data, of a data subject… POLAND ·UODO ·Non-compliance with general data processing principles Personal Data Healthcare Health Data Jan 9, 2026
€2,000 Money Seeds S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Money Seeds S.R.L. The controller failed to fulfil a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Insurance Jan 8, 2026
€27M FREE MOBILE: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 27 miljoen euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 5, 32 Security Data Breaches Access Controls NL Jan 8, 2026
€10,000 Headquarter of a Fire Brigade: Insufficient legal basis for data processing The Greek DPA has imposed a fine of EUR 10,000 on a Fire Brigade Head Quarter. The controller had stored health data of an employee which had been in relation with her sick leave.… GREECE ·HDPA ·Art. 5 Healthcare Health Data Healthcare Jan 8, 2026
€15M FREE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 15,000,000 on FREE. The controller suffered a data breach due to insufficient technical and organisational measures. This was caused by… FRANCE ·CNIL ·Art. 32, 34 Data Breaches Access Controls Security Jan 8, 2026
€27M FREE MOBILE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 27,000,000 on FREE MOBILE. The controller suffered a data breach due to insufficient technical and organisational measures. This was… FRANCE ·CNIL ·Art. 5, 32 Data Breaches Access Controls Security Jan 8, 2026
€2,000 Money Seeds S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. De Roemeense toezichthouder ANSPDCP heeft aan Money Seeds S.R.L., een financiële en consultancyonderneming, een boete van 2.000 euro opgelegd wegens het niet honoreren van een… ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervisory Authorities NL Jan 8, 2026
€232,379 Polish Postal Service: Lack of appointment of data protection officer The Polish DPA has imposed a fine of EUR 232,379 on the Polish Postal Service. The controller appointed a person as DPO who also held a managerial position with authority over… POLAND ·UODO ·Art. 38 Supervisory Authorities Public Authority Controllers Jan 2, 2026
€80,000 ONE WAY PRIVATE COMPANY: Non-compliance with general data processing principles The Greek DPA has imposed a fine of EUR 80,000 on ONE WAY PRIVATE COMPANY. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… GREECE ·HDPA ·Art. 5, 6, 7 +2 Controllers Direct Marketing IP Address Dec 31, 2025
€5,000 REVMA PLUS Retail S.A.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 5,000 on REVMA PLUS Retail S.A.. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… GREECE ·HDPA ·Art. 32 Controllers Processors Direct Marketing Dec 31, 2025
€10,000 Thessaloniki–Thessaly Gas Supply Company S.A.: Insufficient data processing agreement The Greek DPA has imposed a fine of EUR 10,000 on Thessaloniki–Thessaly Gas Supply Company S.A. The controller, an energy provider, used external processors for direct marketing… GREECE ·HDPA ·Art. 28, 32 Processing Agreement Controllers Processors Dec 31, 2025
€10,000 Roumasport S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on Roumasport S.R.L The controller failed to implement adequate technical and organisational measures, resulting in multiple… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers IP Address Dec 30, 2025
€960 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined a data controller EUR 1,450 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Dec 30, 2025
€40,000 Slovak Telekom: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 40.000 euro - van het Slowaakse databeschermingskantoor. SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Security Telecommunications Personal Data NL Dec 30, 2025
SLOVENAKIË, DPB: Onvoldoende naleving van de rechten van betrokkenen. Slovaakse Autoriteit voor Gegevensbescherming. SLOVAKIA ·Slovak Data Protection Office ·Art. 15 Right of Access Procedures Right of Access Personal Data NL Dec 30, 2025
SLOVAKIA DPA: Insufficient fulfilment of data subjects rights A Data Controller failed to comply with data subject´s request to access his/her personal data processed by audio recordings. Slovak Data Protection Office ·Art. 15 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Data Controller Dec 30, 2025
€10,000 Roumasport S.R.L: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €10.000 - De Roemeense nationale toezichthouder op de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Controllers NL Dec 30, 2025
€3.5M Company: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 3,500,000 on a company. The controller operated a loyalty program in France and 16 other EU countries, using customer data obtained… FRANCE ·CNIL ·Art. 6, 13, 32 +1 DPIA Processing Agreement IP Address Dec 30, 2025
€960 POLEN, Autoriteit voor Persoonsgegevens: Onvoldoende samenwerking met de toezichthoudende instantie. Een boete van 960 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 58 Personal Data Data Controller Processing NL Dec 30, 2025
€40,000 Slovak Telekom: Insufficient technical and organisational measures to ensure information security The controller did not take adequate security measures when processing personal data, thereby breaching the obligation to protect the processed personal data. SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Security Telecommunications Controllers Dec 30, 2025
€2,000 Orde van Algemene Verpleegkundigen, Verloskundigen en Medische Assistenten van Roemenië – Afdeling Neamt: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +1 Video Surveillance Processing Security NL Dec 29, 2025
€1,600 NAROBESA INV, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,600 on NAROBESA INV, S.L. The controller failed to react to requests made by the DPA. The original fine of EUR 2,000 was reduced to EUR… SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Law Enforcement Dec 29, 2025
€1,600 NAROBESA INV, S.L.: Onvoldoende samenwerking met de toezichthoudende instantie. 1.600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 58 Supervisory Authorities Controllers Supervision NL Dec 29, 2025
€2,000 Order of General Nurses, Midwives and Medical Assistants of Romania – Neamt Branch: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 2,000 on the Order of General Nurses, Midwives and Medical Assistants of Romania – Neamt Branch. The controller used video surveillance… ANSPDCP ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Video Surveillance Monitoring Employees Dec 29, 2025
€6,000 Geturhotels Srl: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 6,000 on Geturhotels Srl. The controller was involved in direct marketing operations, using personal data that had not been acquired or… ITALY ·Garante ·Art. 5, 6, 17 +1 Controllers Direct Marketing IP Address Dec 23, 2025
€6,000 Geturhotels Srl: Overtreding van de algemene principes voor gegevensverwerking. Een boete van 6.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 17 +1 Processing Data Controller Controllers NL Dec 23, 2025
€500,000 CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 500,000 on CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U. The controller used a communication tool that was not designed in… SPAIN ·aepd ·Art. 25 IP Address Security Controllers Dec 22, 2025
€1.7M NEXPUBLICA FRANKRIJK: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 1.700.000 euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 32 Security Controllers Data Controller NL Dec 22, 2025
€1.7M NEXPUBLICA FRANCE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 1,700,000 on NEXPUBLICA FRANCE. The controller, who was a software developer, created and offered a software package designed to manage… CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Processing Agreement Dec 22, 2025
€500,000 CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 500.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 25 Privacy by Default Privacy by Design Security NL Dec 22, 2025
€32,000 EXCEL HOTELS & RESORTS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on EXCEL HOTELS & RESORTS, S.A. The controller used guards to control access to its facility. The guards regularly left documents… SPAIN ·aepd ·Art. 5 Security Controllers Processing Agreement Dec 20, 2025
€600 4USPORT INSTALACIONES DEPORTIVAS, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 300 on 4USPORT INSTALACIONES DEPORTIVAS, S.L. The controller failed to react to requests made by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Controllers Dec 20, 2025
€300 SPAIN DPA: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 300 on an unkonwn person/entity. The controller failed to react to requests made by the DPA. aepd ·Art. 58 ·Insufficient cooperation with supervisory authority Supervision Supervisory Authorities Controllers Dec 20, 2025
€6,000 BLUE TEAM FLIGHT SCHOOL, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 6,000 on BLUE TEAM FLIGHT SCHOOL, S.L. The controller failed to react to requests made by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Controllers Dec 20, 2025
€600 4USPORT INSTALACIONES DEPORTIVAS, S.L.: Onvoldoende samenwerking met de toezichthoudende instantie. 600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 58 Controllers Supervisory Authorities Data Controller NL Dec 20, 2025
€32,000 EXCEL HOTELS & RESORTS, S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 32.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Security Controllers Accountability NL Dec 20, 2025
€300 SPAIN, DPA: Onvoldoende samenwerking met de toezichthoudende instantie. Een boete van 300 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). aepd ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Controllers Data Controller NL Dec 20, 2025
€6,000 BLUE TEAM FLIGHT SCHOOL, S.L.: Onvoldoende samenwerking met de toezichthoudende instantie. Een boete van 6.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 58 Education Supervisory Authorities Controllers NL Dec 20, 2025
€40,000 LTL S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 40,000 on LTL S.p.A. The controller failed to respond within the legal time period to a request by a former employee to exercise their… ITALY ·Garante ·Art. 5, 12, 15 Controllers Personal Data Supervisory Authorities Dec 18, 2025
€120,000 Pioneer Hi-Bred Italia Sementi s.r.l.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 120,000 on Pioneer Hi-Bred Italia Sementi s.r.l. The controller installed satellite telematics tracking devices to monitor driving… ITALY ·Garante ·Art. 5, 6, 28 Monitoring Employees Controllers Dec 18, 2025
€40,000 Anticimex s.r.l.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 40,000 on Anticimex s.r.l. Following termination of employment, the former employer requested to exercise his rights. The controller… ITALY ·Garante ·Art. 5, 12, 13 +2 Controllers Employees Processing Agreement Dec 18, 2025
€2,000 Elba Catering Distribuzioni s.r.I.s.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on Elba Catering Distribuzioni s.r.I.s. The controller installed video surveillance, which affected the public road. Furthermore,… ITALY ·Garante ·Art. 5, 13 Video Surveillance Controllers Monitoring Dec 18, 2025
€6,000 Comune di Nave: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Commune di Nave. The controller has installed an automatic licence plate recognition system which processes data on when a… ITALY ·Garante ·Art. 5, 6, 12 +2 DPIA Insurance Privacy Impact Assessment Dec 18, 2025
€1,000 Data Controller: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on a data controller. The controller disclosed personal data by sending an email to an address that third parties who were not… ITALY ·Garante ·Art. 5, 6 Controllers Personal Data Processing Agreement Dec 18, 2025