Skip to content
Content type · 950 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

101–150 of 950 sort newestlargest fineoldest
€1.7M NEXPUBLICA FRANKRIJK: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 1.700.000 euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 32 Security Controllers Data Controller NL Dec 22, 2025
€1.7M NEXPUBLICA FRANCE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 1,700,000 on NEXPUBLICA FRANCE. The controller, who was a software developer, created and offered a software package designed to manage… CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Processing Agreement Dec 22, 2025
€500,000 CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 500,000 on CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U. The controller used a communication tool that was not designed in… SPAIN ·aepd ·Art. 25 IP Address Controllers Security Dec 22, 2025
€500,000 CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 500.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 25 Privacy by Default Privacy by Design Security NL Dec 22, 2025
€32,000 EXCEL HOTELS & RESORTS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on EXCEL HOTELS & RESORTS, S.A. The controller used guards to control access to its facility. The guards regularly left documents… SPAIN ·aepd ·Art. 5 Security Controllers Processing Agreement Dec 20, 2025
€32,000 EXCEL HOTELS & RESORTS, S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 32.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Security Controllers Data Controller NL Dec 20, 2025
€175,000 Arnhem and Nijmegen University of Applied Sciences: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 175,000 on Arnhem and Nijmegen University of Applied Sciences. The controller suffered a data breach due to insufficient technical and… THE NETHERLANDS ·AP ·Art. 32 Data Breaches Security Education Dec 15, 2025
€175,000 De Hogeschool Arnhem en Nijmegen: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 175.000 euro boete - Nederlandse Autoriteit Persoonsgegevens (AP). THE NETHERLANDS ·AP ·Art. 32 Security Education Data Breaches NL Dec 15, 2025
€75,700 Chief Constable of the Police Service of Scotland: Insufficient technical and organisational measures to ensure information security Information Commissioner (ICO) fined Chief Constable of the Police Service of Scotland €75,700 on 2025-12-12 for: Insufficient technical and organisational measures to ensure… United Kingdom ·ICO ·Art. 5, 25, 32 +1 Security Public Authority Public Sector Dec 12, 2025
€98,000 University of Limerick: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined University of Limerick €98,000 on 2025-12-10 for: Insufficient technical and organisational measures to ensure information security. Ireland ·Art. 5, 30, 32 +2 ·Insufficient technical and organisational measures to ensure information security Security Education Public Authority Dec 10, 2025
€1,000 Compania de Apa Oltenia S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Compania de Apa Oltenia S.A. The controller failed to implement adequate technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 29, 32 Security Social Media Controllers Dec 8, 2025
€1,000 Compania de Apa Oltenia S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 29, 32 Security Processing Controllers NL Dec 8, 2025
€1,300 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 1,300 on a legal entity. An employee of the controller stored personal data on her work laptop without securing it, for example by… SLOVENIA ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Controllers Dec 4, 2025
€12,000 Comune di Tuscania: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 12,000 on the Commune di Tuscania. The controller had been using video surveillance and licence plate recognition within its territory… ITALY ·Garante ·Art. 5, 6, 12 +5 Video Surveillance IP Address Controllers Dec 4, 2025
Austrian DSB: sharing ADHD diagnosis from public forum post did not breach Art. 9 GDPR A data subject published a post concerning their ADHD diagnosis on a publicly accessible online forum under a pseudonym. A person (the controller) who was a follower of the data… 2025-0.968.031 ·Austria ·Art. 9 Healthcare Health Data Pseudonymization Dec 3, 2025
€3,600 RISING SUN CAR RENTAL S..L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,600 on RISING SUN CAR RENTAL S..L. The controller used video surveillance to ensure security at its facility, affecting more areas than… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Monitoring Dec 1, 2025
€1.6M SPRINTER MEGACENTROS DEL DEPORTE, S.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 1.560.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 34 Security Data Breaches Controllers NL Nov 28, 2025
€1.6M SPRINTER MEGACENTROS DEL DEPORTE, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,560,000 on SPRINTER MEGACENTROS DEL DEPORTE, S.L. The controller suffered a cyber attack due to insufficient technical and… SPAIN ·aepd ·Art. 5, 34 Security Controllers Law Enforcement Nov 28, 2025
€2,000 Nițu A. Cleopatra – Expert Accountant: Insufficient technical and organisational measures to ensure information security Thr Romanian DPA has imposed a fine of EUR 2,000 on Nițu A. Cleopatra – Expert Accountant. The controller was the target of a successful cyber attack due to the inadequate… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing Agreement Nov 27, 2025
€2,000 Nițu A. Cleopatra – Expert Accountant: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data NL Nov 27, 2025
€4.5M Telecommunicatiebedrijf (exploitant van elektronische communicatienetwerken en -diensten): Overtreding van de algemene principes van gegevensverwerking. Een boete van 4.500.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·azop ·Art. 5, 6, 12 +4 Data Processor Controllers Processors NL Nov 24, 2025
€4.5M Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer… CROATIA ·azop ·Art. 5, 6, 12 +4 Processing Agreement Employees Privacy Shield Nov 24, 2025
DSB Austria: Online shop violated GDPR by ignoring request to stop gender-specific On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Art. 5, 6, 16 +2 Privacy by Design Privacy by Default Personal Data Nov 24, 2025
€16,650 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 16,650 on a legal entity. The controller stored personal data on a publicly accessible web server without taking sufficient technical… SLOVENIA ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Nov 21, 2025
€1.4M LastPass UK Ltd: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 1,228,283 (EUR 1,400,000) on LastPass UK Ltd. The controller suffered a succesfull cyber attack due to insufficient technical and organisational… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers Processing Agreement Nov 20, 2025
€1.4M LastPass UK Ltd: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 1.400.000 euro boete - Informatiecommissaris (ICO) UNITED KINGDOM ·ICO ·Art. 5, 32 Security Accountability Controllers NL Nov 20, 2025
€3,000 Greencorp S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing NL Nov 19, 2025
€60,000 STRATESYS TECHNOLOGY SOLUTIONS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 60,000 on STRATESYS TECHNOLOGY SOLUTIONS, S.L. The controller failed to implement adequate technical and organisational measures,… SPAIN ·aepd ·Art. 5 Data Breaches Security Controllers Nov 19, 2025
€3,000 Greencorp S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Greencorp S.R.L. The controller failed to implement adequate technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Security Processing Agreement Controllers Nov 19, 2025
€60,000 STRATESYS TECHNOLOGY SOLUTIONS, S.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 60.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Security Data Breaches Controllers NL Nov 19, 2025
€8,000 PGS SOFA & CO SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 8.000 euro boete - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Controllers NL Nov 17, 2025
€8,000 PGS SOFA & CO SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PGS SOFA & CO SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures. ROMANIA ·ANSPDCP ·Art. 32 Security Processing Agreement Controllers Nov 17, 2025
€4,750 Powiatowego Inspektora Sanitarnego w Policach: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 4750 on the Powiatowego Inspektora Sanitarnego w Policach. The controller failed to implement adequate technical and organisational… POLAND ·UODO ·Art. 5, 24, 25 +1 Encryption Data Breaches Security Nov 15, 2025
€4,750 De districtsinspecteur voor volksgezondheid in Police: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 4.750 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 24, 25 +1 Security Health Data Encryption NL Nov 15, 2025
€2,400 AXARQUIA VELEZ DENTAL, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,400 on AXARQUIA VELEZ DENTAL, S.L. The controller used video surveillance to ensure security at its facility, affecting more areas than… SPAIN ·aepd ·Art. 5 Video Surveillance Healthcare Monitoring Nov 14, 2025
€7,000 Klass Wagen S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 7,000 on Klass Wagen S.R.L. The controller suffered a cyber incident due to a former employee exposing the login credentials of… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Law Enforcement Nov 7, 2025
€7,000 Klass Wagen S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van €7.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing NL Nov 7, 2025
€300,000 SIA 'ZZ Dats': Insufficient technical and organisational measures to ensure information security The Latvian DPA has imposed a fine of EUR 300,000 on SIA 'ZZ Dats'. The entity that was fined was the data processor for almost all local governments in Latvia. It failed to… LATVIA ·DSI ·Art. 32 Data Breaches Security Processors Oct 28, 2025
€300,000 SIA 'ZZ Dats': Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 300.000 euro - Inspectie gegevensbescherming (DSI). LATVIA ·DSI ·Art. 32 Security Data Processor Data Breaches NL Oct 28, 2025
€865,000 Aktia Pankki Oyj: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 865.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Data Breaches Access Controls NL Oct 23, 2025
€865,000 Aktia Pankki Oyj: Insufficient technical and organisational measures to ensure information security The Finish DPA has imposed a fine of EUR 865,000 on Aktia Pankki Oyj. The controller changed its strong authentication process in such a way that it no longer guaranteed adequate… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Data Breaches Security Access Controls Oct 23, 2025
€5,000 S.P.E.E.H. HIDROELECTRICA SA: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing NL Oct 20, 2025
€5,000 S.P.E.E.H. HIDROELECTRICA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on S.P.E.E.H. HIDROELECTRICA SA. A technical error in the controller's computer systems was exploited by attackers to cause a… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Supervisory Authorities Oct 20, 2025
€2,000 PRIME TRANSACTION SA: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Oct 16, 2025
€2,000 PRIME TRANSACTION SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on PRIME TRANSACTION SA. The controller failed to implement adequate technical and organisational measures, resulting in a data… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Processing Agreement Oct 16, 2025
€9.2M CAPITA PLC: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 8,000,000 (EUR 9,180,000) on CAPITA PLC. CAPITA PLC acts as the data controller for the CAPITA Group, which has suffered a cyber attack. The… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers Processing Agreement Oct 15, 2025
€6.9M CAPITA PENSION SOLUTIONS LIMITED: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 6,000,000 (EUR 6,880,000) on CAPITA PENSION SOLUTIONS LIMITED. CAPITA PENSION SOLUTIONS LIMITED acts as the data processor for the CAPITA Group,… UNITED KINGDOM ·ICO ·Art. 32 Processors Security Controllers Oct 15, 2025
€9.2M CAPITA PLC: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 9.180.000 euro boete - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers Processing NL Oct 15, 2025
€5,000 Vellea Home SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Vellea Home SRL. The controller failed to implement adequate technical and organisational measures, resulting in a data breach. ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Oct 13, 2025