Skip to content
Content type · 277 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

101–150 of 277 sort newestlargest fineoldest
€101,000 Croatian Insurance Bureau: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined Croatian Insurance Bureau €101,000 on 2025-07-02 for: Insufficient technical and organisational measures to ensure information… Croatia ·AZOP ·Art. 5, 32 Security Insurance Education Jul 2, 2025
€15,600 L. Zamenhof University Children's Clinical Hospital in Białystok: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 15,600 on the L. Zamenhof University Children's Clinical Hospital in Białystok. The controller did not implement sufficient technical and… POLAND ·UODO ·Art. 5, 32 Security Controllers Personal Data Jun 30, 2025
€15,600 Children's Hospital of the L. Zamenhof University in Białystok: Insufficient technical and organizational measures to ensure information security. ⇄ 15.600 euro boete - Poolse nationale instantie voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 32 Security Controllers Accountability Jun 30, 2025
€25,000 Party "Alliance for the Union of Romanians": Non-compliance with the general principles of data processing. ⇄ Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 25 +1 Processing Personal Data Security Jun 26, 2025
€25,000 Alliance for the Union of Romanians Party: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 25,000 on the Alliance for the Union of Romanians Party. The controller did not implement adeqaute technical and organisational measures… ROMANIA ·ANSPDCP ·Art. 5, 6, 25 +1 Security Controllers Personal Data Jun 26, 2025
€7,000 General Hospital of the University of Larissa: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 7,000 on the General Hospital of the University of Larissa. The controller failed to adequately fulfil the rights of data subjects. It… GREECE ·HDPA ·Art. 5, 14, 15 Personal Data Controllers Supervisory Authorities Jun 24, 2025
€7,000 General Hospital of the University of Larissa: Inadequate compliance with data subjects' rights. ⇄ Een boete van €7.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 14, 15 Supervisory Authorities Controllers Personal Data Jun 24, 2025
€3,500 Municipal Social Welfare Center Aleksandrów: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 3,500 on the Municipal Social Welfare Center in Aleksandrów. The controller did not implement sufficient technical and organisational… POLAND ·UODO ·Art. 32 Security Controllers Personal Data Jun 23, 2025
€3,500 Municipal Social Assistance Centre in Aleksandrów: Insufficient Technical and Organisational Measures to Ensure Information Security. ⇄ Een boete van 3.500 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 32 Security Controllers Data Breaches Jun 23, 2025
€125,000 City of Dublin Education and Training Board: Insufficient technical and organizational measures to ensure information security. ⇄ 125.000 euro boete - Ierse Autoriteit voor Gegevensbescherming. IRELAND ·DPC ·Art. 5, 32, 33 +1 Security Personal Data Controllers Jun 23, 2025
€125,000 City of Dublin Education and Training Board: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 125,000 on the City of Dublin Education and Training Board. The controller suffered a data breach due to insufficient technical and… IRELAND ·DPC ·Art. 5, 32, 33 +1 Data Breaches Controllers Security Jun 23, 2025
€24,000 COLEGIO VIRGEN DE EUROPA, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 24,000 on COLEGIO VIRGEN DE EUROPA, S.L. An employee of the controller, a school, took pictures of minor pupils without a sufficient legal… SPAIN ·AEPD ·Art. 5, 6, 13 Controllers Personal Data Supervisory Authorities Jun 20, 2025
€24,000 COLEGIO VIRGEN DE EUROPA, S.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 24.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 6, 13 Personal Data Processing Controllers Jun 20, 2025
€550,000 Departement of Social Security: Insufficient legal basis for data processing The Irish DPA imposed a fine of EUR 550,000 on the Departement of Social Security. The controller uses the so called SAFE 2 registration process for anyone applying for a Public… IRELAND ·DPC ·Art. 5, 6, 9 +2 DPIA Types of Special Categories of Personal Data Controllers Jun 12, 2025
€550,000 Ministry of Social Security: Insufficient legal basis for data processing. ⇄ 550.000 euro boete - Ierse Autoriteit voor Gegevensbescherming. IRELAND ·DPC ·Art. 5, 6, 9 +2 Types of Special Categories of Personal Data Personal Data Controllers Jun 12, 2025
€22,000 Kristiansand municipality: Insufficient legal basis for data processing The Norwegian DPA imposed a fine of EUR 22,000 on Kristiansand municipality. The controller offers a helpline for childreen, which had become victims of violence, abuse or… NORWAY ·Datatilsynet (NO) ·Art. 6, 12, 13 Personal Data Controllers Supervisory Authorities Jun 10, 2025
€22,000 Municipality of Kristiansand: Insufficient legal basis for data processing. ⇄ 22.000 euro boete - Noorse Toezichtsautoriteit (Datatilsynet). NORWAY ·Datatilsynet (NO) ·Art. 6, 12, 13 Personal Data Processing Supervision Jun 10, 2025
€1.1M University Pharmacy: Non-compliance with general principles of data processing. ⇄ 1.100.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 32 Controllers Processing Health Data May 27, 2025
€1,000 MP Dumitru Viorel Focșa: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 1,000 on the MP Dumitru Viorel Focșa. The controller published a post on social media containing personal data of a third person. The… ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Controllers Processing May 22, 2025
€1,000 MP Dumitru Viorel Focșa: Insufficient legal basis for data processing. ⇄ Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6 Processing Personal Data Controllers May 22, 2025
€7,000 Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 7,000 on Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North. The controller… ITALY ·Garante ·Art. 5, 9 Healthcare Controllers Personal Data May 21, 2025
€1,200 Municipality of San Francesco al Campo: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1,200 on the Municipality of San Francesco al Campo. The controller published the personal data of employees on its website, thereby… ITALY ·Garante ·Art. 5 Retention Period Personal Data Controllers Apr 29, 2025
€30,000 Lombardy Order of Psychologists: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 30.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 32 Security Controllers Accountability Apr 29, 2025
€40,000 Municipality of Bologna: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 40.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 Security Controllers Health Data Apr 29, 2025
€40,000 Municipality of Bologna: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 40,000 on the Municipality of Bologna. The controller used a data processor (Cooperativa Sociale Quadrifoglio | ETid: 2274) to process… ITALY ·Garante ·Art. 5, 6, 9 Controllers Security Healthcare Apr 29, 2025
€30,000 Ordine degli psicologi della Lombardia: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 30,000 on Ordine degli psicologi della Lombardia. The controller suffered a data breach due to insufficient technical and organisational… ITALY ·Garante ·Art. 5, 32 Security Controllers Data Breaches Apr 29, 2025
€1,200 Municipality of San Francesco al Campo: Non-compliance with general principles of data processing. ⇄ 1.200 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5 Controllers Processing Accountability Apr 29, 2025
€9,200 Discrimination Ombudsmen: Insufficient technical and organizational measures to ensure information security. ⇄ 9.200 euro boete - De Zweedse Autoriteit voor Gegevensbescherming (Integritetsskyddsmyndigheten). SWEDEN ·IMY ·Art. 32 Security Controllers Education Apr 23, 2025
€9,200 Diskrimineringsombudsmannen: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 9,200 on the Swedish Disrimination Ombudsman. The controller was unable to implement sufficient data security measures, resulting in the… SWEDEN ·IMY ·Art. 32 Security Controllers Education Apr 23, 2025
€500,000 Chamber of Commerce, Industry, Services and Transport of Spain: Insufficient legal basis for the processing of data. ⇄ Een boete van 500.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). AEPD ·Art. 5, 6, 14 ·Insufficient legal basis for data processing Integrity and Confidentiality Principle Controllers Processing Apr 15, 2025
€500,000 Chamber of Commerce, Industry, Services and Navigation of Spain: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500,000 on the Chamber of Commerce, Industry, Services and Navigation of Spain. Due to its function within the Spanish Executive, the… AEPD ·Art. 5, 6, 14 ·Insufficient legal basis for data processing Integrity and Confidentiality Principle Controllers Retention Period Apr 15, 2025
€8,000 Community of the Eastern Apennines in Parma: Non-compliance with the general principles of data processing. ⇄ 8.000 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +2 Controllers Processing Supervisory Authorities Apr 10, 2025
€5,000 Patronage and Assistance for Citizens and Agriculture Board: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 5,000 on Patronage and Assistance for Citizens and Agriculture Board. The controller has stored personal data of a data subject for a… ITALY ·Garante ·Art. 5, 6 Personal Data Controllers Processing Apr 10, 2025
€8,000 Eastern Parma Apennine Mountain Community: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 8,000 on the Eastern Parma Apennine Mountain Community. The controller had set up video surveillance in front of a police station, that… ITALY ·Garante ·Art. 5, 6, 12 +2 Monitoring Controllers Supervisory Authorities Apr 10, 2025
€5,000 Board for Support to Citizens and Agriculture: Insufficient legal basis for data processing. ⇄ Een boete van 5.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Retention Period Storage Limitation Personal Data Apr 10, 2025
€21,600 SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 21.600 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 7, 28 Processing Personal Data Retention Period Mar 28, 2025
€21,600 SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed fine on SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L. The controller offers fitness courses which are recorded and published. The consent obtained for the… SPAIN ·AEPD ·Art. 5, 7, 28 Retention Period Storage Limitation Controllers Mar 28, 2025
€3,000 Municipality of Palma di Montechiaro: Failure to appoint a data protection officer. ⇄ Een boete van 3.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 37 Public Authority Supervisory Authorities Controllers Mar 27, 2025
€3,000 Municipality of Palma di Montechiaro: Lack of appointment of data protection officer The Italian DPA has imposed a fine of EUR 3,000 on the Municipality of Palma di Montechiaro. The controller failed to appoint a DPO and report the DPO to the DPA. ITALY ·Garante ·Art. 37 Public Authority Supervisory Authorities Controllers Mar 27, 2025
€17,600 Chief Commander of the Police: Insufficient legal basis for data processing The Polish DPA has fined the Chief Commander of the Polish Police EUR 17,600. During a press conference, the Chief Commander of the Police disclosed the personal and medical data… POLAND ·UODO ·Art. 6, 9 Healthcare Personal Data Processing Mar 24, 2025
€2,000 INDEPENDENTS DE VALLROMANES: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,000 on INDEPENDENTS DE VALLROMANES. The controller, a political party, posted a court decision on its social media, which included… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Personal Data Mar 24, 2025
€23,500 Minister of Digital Affairs: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 23,500 on the Polish Minister for Digital Affairs. The Minister unlawfully processed personal data of Polish citizens in the PESEL… POLAND ·UODO ·Art. 5, 6 Personal Data Processing Education Mar 17, 2025
€2,000 l’Istituto Alberghiero Mediterraneo di Pulsano: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 2,000 on l’Istituto Alberghiero Mediterraneo di Pulsano. The controller, a school, published a christmas video on the video platform YouTube,… ITALY ·Garante ·Art. 5, 6 Consent Controllers Processing Mar 13, 2025
€50,000 Azienda regionale per lo sviluppo e per i servizi in agricoltura (ARSAC): Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 50,000 on the Regional agency for development and services in agriculture (ARSAC). The controller processed geographic data of its employees… ITALY ·Garante ·Art. 5, 6, 13 +3 Controllers Fairness & Transparency Transparency Mar 13, 2025
€2,556 Registry Agency of Republic of Bulgaria: Insufficient legal basis for data processing Bulgarian Commission for Personal Data Protection (KZLD) fined Registry Agency of Republic of Bulgaria €2,556 on 2025-03-01 for: Insufficient legal basis for data processing. CPDP ·Insufficient legal basis for data processing Public Authority Education Personal Data Mar 1, 2025
€9,000 Employment Service under the Ministry of Social Security and Labor of the Republic of Lithuania: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA has imposed a fine of EUR 9,000 against the Employment Service under the Ministry of Social Security and Labor of the Republic of Lithuania. Following a data… VDAI ·Art. 5, 24, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Education Jan 21, 2025
€2,000 Municipality of Cori: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Municipality of Cori. The controller published the names of those receiving food cards intended for people in need on its… ITALY ·Garante ·Art. 6 Controllers Public Authority Education Jan 16, 2025
€2,000 Alessandro Volta Classical and Scientific High School in Como: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Alessandro Volta Classical and Scientific High School in Como. The controller published the results of the state exam,… ITALY ·Garante ·Art. 5, 6 Controllers Processing Education Jan 16, 2025
€2,000 Maddaloni municipality: Insufficient involvement of data protection officer The Italian DPA has imposed a fine of EUR 2,000 on Maddaloni municipality for failing to provide the DPA with the contact details of their data protection officer in good time. ITALY ·Garante ·Art. 37 Public Authority Supervisory Authorities Education Dec 14, 2024