Skip to content
Content type · 568 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

101–150 of 568 sort newestlargest fineoldest
€4,750 The District Sanitary Inspector in Police: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 4.750 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 24, 25 +1 Security Encryption Controllers Nov 15, 2025
€4,750 Powiatowego Inspektora Sanitarnego w Policach: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 4750 on the Powiatowego Inspektora Sanitarnego w Policach. The controller failed to implement adequate technical and organisational… POLAND ·UODO ·Art. 5, 24, 25 +1 Security Encryption Controllers Nov 15, 2025
€40,000 Quarantadue S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 40,000 on Quarantadue S.r.l. The controller produced a television series about a criminal case which included real audio recordings that… ITALY ·Garante ·Art. 5 Controllers Processing IP Address Nov 13, 2025
€4,000 Fan Courier Express S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 4,000 on Fan Courier Express S.R.L. The controller failed to adequately react to a data subject's request to exercise their rights, and… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +2 Personal Data Controllers Supervisory Authorities Nov 12, 2025
€7,000 Klass Wagen S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 7,000 on Klass Wagen S.R.L. The controller suffered a cyber incident due to a former employee exposing the login credentials of… ROMANIA ·ANSPDCP ·Art. 32 Controllers Security Personal Data Nov 7, 2025
€1,000 Company: Insufficient fulfilment of data subjects rights The Greek DPA has imposed a fine of EUR 1,000 on a Company. The controller failed to react adequately to a data subject's request to exercise their rights. GREECE ·HDPA ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Nov 7, 2025
€10M Aena, S.M.E., S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 10,043,002 on Aena, S.M.E., S.A. The controller conducted a pilot project involving multiple airports, including the use of facial… SPAIN ·AEPD ·Art. 35 DPIA Controllers Supervisory Authorities Nov 6, 2025
€750 ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓN: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 750 on the ASOCIACIÓN ESCUELA NACIONAL DE EQUITACIÓN. The controller failed to certify compliance with the corrective measures imposed by… SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Controllers Nov 5, 2025
€300,000 SIA 'ZZ Dats': Insufficient technical and organisational measures to ensure information security The Latvian DPA has imposed a fine of EUR 300,000 on SIA 'ZZ Dats'. The entity that was fined was the data processor for almost all local governments in Latvia. It failed to… LATVIA ·DSI ·Art. 32 Processors Security Controllers Oct 28, 2025
€9,450 Gynecological Center: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 9,450 on a Gynecological Center. The controller sufferd a data breach and failed to report this to the DPO. POLAND ·UODO ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 27, 2025
€20,000 Multimedia News Società Cooperativa: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 20,000 on Multimedia News Società Cooperativa. The controller failed to adequatly react to a request by a data subject to exercise their… ITALY ·Garante ·Art. 12 Personal Data Controllers Supervisory Authorities Oct 23, 2025
€15,000 Ordine degli Avvocati di Latina: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on the Ordine degli Avvocati di Latina. The controller published a document relating to criminal proceedings that included… ITALY ·Garante ·Art. 5, 6, 10 Controllers Personal Data Processing Oct 23, 2025
€2,000 Comune di Avola: Lack of appointment of data protection officer The Italian DPA has imposed a fine of EUR 2,000 on the Comune di Avola. The controller failed to communicate the DPO's contact details to the DPA. ITALY ·Garante ·Art. 37 Supervisory Authorities Public Authority Controllers Oct 23, 2025
€2,000 Agency for Control of Outstanding Debts S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on the Agency for Control of Outstanding Debts S.R.L. The controller failed to adequatly react to a data subjects request to… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Oct 22, 2025
€2,000 PRIME TRANSACTION SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on PRIME TRANSACTION SA. The controller failed to implement adequate technical and organisational measures, resulting in a data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Oct 16, 2025
€2.7M Experian Nederland B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 2,700,000 on Experian Nederland B.V. The controller, a company that determines individuals' creditworthiness and sells this information,… THE NETHERLANDS ·AP ·Art. 5, 6, 12 +2 Personal Data Controllers Processing Oct 16, 2025
€9.2M CAPITA PLC: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 8,000,000 (EUR 9,180,000) on CAPITA PLC. CAPITA PLC acts as the data controller for the CAPITA Group, which has suffered a cyber attack. The… UNITED KINGDOM ·ICO ·Art. 5, 32 Controllers Security Processing Oct 15, 2025
€6.9M CAPITA PENSION SOLUTIONS LIMITED: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 6,000,000 (EUR 6,880,000) on CAPITA PENSION SOLUTIONS LIMITED. CAPITA PENSION SOLUTIONS LIMITED acts as the data processor for the CAPITA Group,… UNITED KINGDOM ·ICO ·Art. 32 Processors Controllers Security Oct 15, 2025
€5,000 Vellea Home SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Vellea Home SRL. The controller failed to implement adequate technical and organisational measures, resulting in a data breach. ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Oct 13, 2025
€25,000 EON ENERGIE ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on EON ENERGIE ROMANIA S.A. The controller failed to implement adequate technical and organisational measures, resulting in a… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Oct 9, 2025
€10,000 Municipality of Moschato–Tavros: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 10,000 on the Municipality of Moschato–Tavros. The controller installed a video surveillance system in a depot to protect municipal… GREECE ·HDPA ·Art. 5, 12, 13 +1 Controllers Processing Supervisory Authorities Oct 9, 2025
€6,000 Interprovincial Order of Medical Radiology Technicians and Technical Health Professions in Rehabilitation and Prevention of AQ - CH - PE - TE: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Interprovincial Order of Medical Radiology Technicians and Technical Health Professions in Rehabilitation and Prevention of… ITALY ·Garante ·Art. 5, 6, 37 Controllers Supervisory Authorities Processing Oct 9, 2025
€5,000 FT Solutions S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on FT Solutions S.r.l. The fined entity had been active in direct marketing activities as a data processor. During these… ITALY ·Garante ·Art. 5, 6, 7 +7 Integrity and Confidentiality Principle Processors Controllers Oct 9, 2025
€30,000 THE RED KIWI, S.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 30.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 32 Personal Data Processing Controllers Oct 3, 2025
€492,000 Company: Non-compliance with general data processing principles The DPA of Hamburg has imposed a fine of EUR 492,000 on a company in the finance sector. The controller used automated systems to decide whether to approve a credit application,… GERMANY ·HmbBfDI ·Non-compliance with general data processing principles Insurance Controllers Supervisory Authorities Sep 30, 2025
€195,000 Company: Insufficient fulfilment of data subjects rights The DPA of Hamburg has imposed a fine of EUR 195,000 on a company. The controller was active in direct marketing via post and failed to adequately respond to requests from data… GERMANY ·HmbBfDI ·Insufficient fulfilment of data subjects rights Direct Marketing Personal Data Controllers Sep 30, 2025
€600 Owner of a Tesla Car: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 600 on the owner of a Tesla car. The controller's car had seven cameras installed, which filmed while the car was in use and while it… AUSTRIA ·DSB ·Art. 5, 6, 12 +1 Controllers Personal Data Supervisory Authorities Sep 29, 2025
€3,000 Comune di Isola del Gran Sasso: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on the Comuni di Isola del Gran Sasso. The controller published a resolution on its institutional website which included the… ITALY ·Garante ·Art. 5, 6, 10 +2 Personal Data Controllers Supervisory Authorities Sep 25, 2025
€20,000 S.C. PRIMONET RO S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on S.C. PRIMONET RO S.R.L. The controller failed to implement adequate technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Sep 25, 2025
€3,960 Comune di Pazzano: Insufficient cooperation with supervisory authority The Italian DPA has imposed a fine of EUR 3,960 on the Commune di Pazzano. The controller failed to comply with a order of the DPA. ITALY ·Garante ·Art. 12, 13, 58 Supervisory Authorities Supervision Controllers Sep 25, 2025
€15,000 Vimar S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on Vimar S.p.A. The controller created an internal and personalised email account with the personal data of a third party, without… ITALY ·Garante ·Art. 5, 6, 13 Controllers Personal Data Supervisory Authorities Sep 25, 2025
€10,000 La Prima Srl: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on La Prima Srl. The controller sent direct marketing messages without a legal basis. They also failed to respond to a data… ITALY ·Garante ·Art. 6, 12, 17 +1 Personal Data Controllers Supervisory Authorities Sep 25, 2025
€1,000 Green.mec. s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,000 on Green.mec. s.r.l. The controller failed to adequately respond to a former employee's request to exercise their data subject… ITALY ·Garante ·Art. 13, 15 Personal Data Controllers Supervisory Authorities Sep 25, 2025
€1,000 Dr. Max SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Dr. Max SRL. The controller failed to comply with a data subject's request to delete their personal data. ROMANIA ·ANSPDCP ·Art. 12, 17 Personal Data Controllers Supervisory Authorities Sep 18, 2025
€100,000 SAMARITAINE SAS: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 100,000 on SAMARITAINE SAS. After multiple theft incidents, the controller installed security cameras disguised as smoke detectors to… FRANCE ·CNIL ·Art. 5, 33, 38 Data Breaches Controllers Supervisory Authorities Sep 18, 2025
€1,000 Giada FM S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,000 on Giada FM S.r.l. The controller failed to provide an employee with requested certificates. ITALY ·Garante ·Art. 5, 12, 15 Controllers Personal Data Supervisory Authorities Sep 11, 2025
€6,000 Municipality of Buccino: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Municipality of Buccino. The controller published pictures of minors and people with mental health conditions in multiple… ITALY ·Garante ·Art. 5, 6, 9 +2 Public Authority Controllers Supervisory Authorities Sep 11, 2025
€3M Allium UPI: Insufficient technical and organisational measures to ensure information security The Estonian DPA has imposed a fine of EUR 3,000,000 on Allium UPI. The controller failed to implement adequate technical and organisational measures to ensure data security. This… ESTONIA ·AKI ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processing Agreement Sep 5, 2025
€33,500 Bakery Chain: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 33,500 on a bakery chain. The controller used video surveillance which affected both public areas and areas intended solely for… AUSTRIA ·DSB ·Art. 5, 6 Retention Period Controllers Processing Sep 5, 2025
€870 Company: Insufficient fulfilment of data breach notification obligations The Austrian DPA has imposed a fine of EUR 870 on a company. After being informed of a data breach, the controller took adequate measures to close it but failed to inform the DPA. AUSTRIA ·DSB ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Sep 4, 2025
€9,700 Landlord: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 9,700 on a Landlord. The controller installed video surveillance in and around a student residence. However, the surveillance was too… BELGIUM ·APD/GBA ·Art. 5, 6 Controllers Processing Video Surveillance Sep 4, 2025
€200,900 ILVA A/S: Non-compliance with general data processing principles The Danish DPA has imposed a fine of EUR 200,900 on ILVA A/S. The controller failed to implement data deletion deadlines. This led to an infringement of the principle of storage… DENMARK ·Datatilsynet (DK) ·Non-compliance with general data processing principles Storage Limitation Retention Period Controllers Sep 2, 2025
€150M INFINITE STYLES SERVICES CO. LIMITED: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 150,000,000 on INFINITE STYLES SERVICES CO. LIMITED, which operates under the name 'SHEIN'. The controller used cookies unlawfully on its… FRANCE ·CNIL ·Art. 82 Controllers Personal Data Cookies Sep 1, 2025
€150M INFINITE STYLES SERVICES CO. LIMITED: Insufficient legal basis for the processing of personal data. ⇄ 150 miljoen euro boete - Franse Autoriteit voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 82 Personal Data Processing Controllers Sep 1, 2025
€2,000 GESTIÓN DE VENTAS IBERIA S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 2,000 on GESTIÓN DE VENTAS IBERIA S.L. The controller contacted a data subject for direct marketing purposes, thereby violating local… SPAIN ·AEPD ·Art. 14 Personal Data Controllers Marketing Aug 31, 2025
€300 Driving School: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 300 on a driving school. The controller has installed video surveillance, but failed to adequatly inform data subjects. The original fine… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Aug 26, 2025
€4.3M ING Bank Śląski: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 4,323,250 on ING Bank Śląski. The controller scanned the identity documents of every customer and potential customer without a sufficient… POLAND ·UODO ·Art. 5, 6 Controllers Personal Data Processing Aug 26, 2025
€5,400 YUNEXPRESS SPAIN, S.L.: Insufficient data processing agreement The Spanish DPA has imposed a fine of EUR 5,400 on YUNEXPRESS SPAIN, S.L. The controller used a data processor and failed to sign a sufficient data processing agreement. The… AEPD ·Art. 5, 28 ·Insufficient data processing agreement Processors Controllers Processing Aug 25, 2025
€18,000 GRUPO BONATEL SL: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van €18.000 - van de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Aug 22, 2025