Skip to content
Content type · 1,529 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

101–150 of 1,529 sort newestlargest fineoldest
€30,000 THE RED KIWI, S.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 30.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 32 Personal Data Data Controller Processing NL Oct 3, 2025
€492,000 Company: Non-compliance with general data processing principles The DPA of Hamburg has imposed a fine of EUR 492,000 on a company in the finance sector. The controller used automated systems to decide whether to approve a credit application,… GERMANY ·HmbBfDI ·Non-compliance with general data processing principles Insurance Controllers IP Address Sep 30, 2025
€195,000 Company: Insufficient fulfilment of data subjects rights The DPA of Hamburg has imposed a fine of EUR 195,000 on a company. The controller was active in direct marketing via post and failed to adequately respond to requests from data… GERMANY ·HmbBfDI ·Insufficient fulfilment of data subjects rights Controllers Personal Data Direct Marketing Sep 30, 2025
€600 Owner of a Tesla Car: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 600 on the owner of a Tesla car. The controller's car had seven cameras installed, which filmed while the car was in use and while it… AUSTRIA ·dsb ·Art. 5, 6, 12 +1 IP Address Controllers Personal Data Sep 29, 2025
€20,000 S.C. PRIMONET RO S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on S.C. PRIMONET RO S.R.L. The controller failed to implement adequate technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing Agreement Sep 25, 2025
€1,000 Green.mec. s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,000 on Green.mec. s.r.l. The controller failed to adequately respond to a former employee's request to exercise their data subject… ITALY ·Garante ·Art. 13, 15 Data Subject Rights Exercise Modalities and Procedures Personal Data Controllers Sep 25, 2025
€15,000 Vimar S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on Vimar S.p.A. The controller created an internal and personalised email account with the personal data of a third party, without… ITALY ·Garante ·Art. 5, 6, 13 Controllers IP Address Processing Agreement Sep 25, 2025
€10,000 La Prima Srl: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on La Prima Srl. The controller sent direct marketing messages without a legal basis. They also failed to respond to a data… ITALY ·Garante ·Art. 6, 12, 17 +1 Direct Marketing Controllers Personal Data Sep 25, 2025
€3,960 Comune di Pazzano: Insufficient cooperation with supervisory authority The Italian DPA has imposed a fine of EUR 3,960 on the Commune di Pazzano. The controller failed to comply with a order of the DPA. ITALY ·Garante ·Art. 12, 13, 58 Supervisory Authorities Supervision Public Authority Sep 25, 2025
€3,000 Comune di Isola del Gran Sasso: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on the Comuni di Isola del Gran Sasso. The controller published a resolution on its institutional website which included the… ITALY ·Garante ·Art. 5, 6, 10 +2 Personal Data Controllers Employees Sep 25, 2025
€100,000 SAMARITAINE SAS: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 100,000 on SAMARITAINE SAS. After multiple theft incidents, the controller installed security cameras disguised as smoke detectors to… FRANCE ·CNIL ·Art. 5, 33, 38 Data Breaches Video Surveillance Monitoring Sep 18, 2025
€1,000 Dr. Max SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Dr. Max SRL. The controller failed to comply with a data subject's request to delete their personal data. ROMANIA ·ANSPDCP ·Art. 12, 17 Personal Data Controllers Healthcare Sep 18, 2025
€6,000 Municipality of Buccino: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Municipality of Buccino. The controller published pictures of minors and people with mental health conditions in multiple… ITALY ·Garante ·Art. 5, 6, 9 +2 Public Authority Social Media Education Sep 11, 2025
€1,000 Giada FM S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,000 on Giada FM S.r.l. The controller failed to provide an employee with requested certificates. ITALY ·Garante ·Art. 5, 12, 15 Controllers Personal Data Employees Sep 11, 2025
€33,500 Bakery Chain: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 33,500 on a bakery chain. The controller used video surveillance which affected both public areas and areas intended solely for… AUSTRIA ·dsb ·Art. 5, 6 Video Surveillance Retention Period Monitoring Sep 5, 2025
€3M Allium UPI: Insufficient technical and organisational measures to ensure information security The Estonian DPA has imposed a fine of EUR 3,000,000 on Allium UPI. The controller failed to implement adequate technical and organisational measures to ensure data security. This… ESTONIA ·AKI ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Sep 5, 2025
€9,700 Landlord: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 9,700 on a Landlord. The controller installed video surveillance in and around a student residence. However, the surveillance was too… BELGIUM ·APD ·Art. 5, 6 Video Surveillance Monitoring Controllers Sep 4, 2025
€870 Company: Insufficient fulfilment of data breach notification obligations The Austrian DPA has imposed a fine of EUR 870 on a company. After being informed of a data breach, the controller took adequate measures to close it but failed to inform the DPA. AUSTRIA ·dsb ·Art. 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Sep 4, 2025
€200,900 ILVA A/S: Non-compliance with general data processing principles The Danish DPA has imposed a fine of EUR 200,900 on ILVA A/S. The controller failed to implement data deletion deadlines. This led to an infringement of the principle of storage… DENMARK ·Datatilsynet ·Non-compliance with general data processing principles Storage Limitation Retention Period Controllers Sep 2, 2025
€150M INFINITE STYLES SERVICES CO. LIMITED: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. 150 miljoen euro boete - Franse Autoriteit voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 82 Cookies Personal Data Processing NL Sep 1, 2025
€150M INFINITE STYLES SERVICES CO. LIMITED: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 150,000,000 on INFINITE STYLES SERVICES CO. LIMITED, which operates under the name 'SHEIN'. The controller used cookies unlawfully on its… FRANCE ·CNIL ·Art. 82 Cookies Controllers Processing Agreement Sep 1, 2025
€2,000 GESTIÓN DE VENTAS IBERIA S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 2,000 on GESTIÓN DE VENTAS IBERIA S.L. The controller contacted a data subject for direct marketing purposes, thereby violating local… SPAIN ·aepd ·Art. 14 Direct Marketing Personal Data Controllers Aug 31, 2025
€300 Driving School: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 300 on a driving school. The controller has installed video surveillance, but failed to adequatly inform data subjects. The original fine… SPAIN ·aepd ·Art. 13 Video Surveillance Monitoring Education Aug 26, 2025
€4.3M ING Bank Śląski: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 4,323,250 on ING Bank Śląski. The controller scanned the identity documents of every customer and potential customer without a sufficient… POLAND ·UODO ·Art. 5, 6 Controllers Processing Agreement Insurance Aug 26, 2025
€5,400 YUNEXPRESS SPAIN, S.L.: Insufficient data processing agreement The Spanish DPA has imposed a fine of EUR 5,400 on YUNEXPRESS SPAIN, S.L. The controller used a data processor and failed to sign a sufficient data processing agreement. The… aepd ·Art. 5, 28 ·Insufficient data processing agreement Controllers Processors Processing Agreement Aug 25, 2025
€6,000 BANCO INVERSIS, S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van 6.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Security Data Breaches Controllers NL Aug 22, 2025
€18,000 GRUPO BONATEL SL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €18.000 - van de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Security Data Breaches Telecommunications NL Aug 22, 2025
€3,000 SC Elite Conta SRL: Insufficient technical and organisational measures to ensure information security The Romainian DPA has imposed a fine of EUR 3,000 on SC Elite Conta SRL. The controller failed to implement adequate technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing Agreement Aug 18, 2025
€500 Sole Trader: Insufficient cooperation with supervisory authority The Slovenian DPA has imposed a fine of EUR 500 on a sole trader. The controller failed to react to a request by the DPA within the set 10-day period. SLOVENIA ·Art. 31 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Aug 13, 2025
€3,000 'FLEXICREDIT' Mutual Aid House Association: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on 'FLEXICREDIT' Mutual Aid House Association. The controller failed to implement adequate technical and organisational measures… ROMANIA ·ANSPDCP ·Art. 32 Security Insurance Controllers Aug 12, 2025
€4,800 GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 4,800 on GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U. The controller failed to process customer data accurately,… SPAIN ·aepd ·Art. 5 Insurance Personal Data Controllers Aug 12, 2025
€80,000 BIZUM, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 80,000 on BIZUM, S.L. The controller failed to implement sufficient technical and organisational measures to ensure data security,… SPAIN ·aepd ·Art. 32 Data Breaches Security Controllers Aug 11, 2025
€6,200 Media Company: Insufficient cooperation with supervisory authority The Austrian DPA has imposed a fine of EUR 6,200 on a media company. The controller failed to comply with an order from the DPA to implement an adequate cookie banner. AUSTRIA ·dsb ·Art. 58 Supervisory Authorities Supervision Cookies Aug 6, 2025
€1,000 Order of Biochemists, Biologists and Chemists in the Romanian Health System: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on the Order of Biochemists, Biologists and Chemists in the Romanian Health System. The controller failed to adequatly respond to… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Healthcare Controllers Aug 5, 2025
€7,700 Non-Public Health Care Institution: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 7,700 on a non-public health care institution. The controller offered home visits by doctors as part of its services. For this purpose,… POLAND ·UODO ·Art. 5, 25, 32 Healthcare Security Controllers Aug 4, 2025
€230 Politieagent: Er is onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 230 euro - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Insufficient legal basis for data processing Processing Education Supervisory Authorities NL Aug 4, 2025
€10,000 Comune di Venezia: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on the Comune di Venezia. The controller implemented a tourist tax, which includes exceptions for certain groups of visitors. When… ITALY ·Garante ·Art. 5, 6, 25 +1 IP Address Controllers Education Aug 4, 2025
€230 Police Officer: Insufficient legal basis for data processing The UK DPA has imposed a fine of £ 200 (EUR 230) on a police officer. The controller forwarded sensitive and restricted personal data that he had obtained in the course of his… UNITED KINGDOM ·ICO ·Insufficient legal basis for data processing Personal Data Controllers Public Authority Aug 4, 2025
€4,400 Entrepreneur: Insufficient cooperation with supervisory authority The Polish DPA has imposed a fine of EUR 4,400 on an Entrepreneur. The controller failed to adequatly react to a request from the DPA. POLAND ·UODO ·Art. 58 Supervisory Authorities Supervision Controllers Jul 28, 2025
€5,020 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 5,020 on a legal entity. The controller had developed an application that allowed the exchange of personal data, but failed to… SLOVENIA ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Jul 25, 2025
€26,400 Debt Collector: Insufficient fulfilment of data subjects rights The Hungarian DPA has imposed a fine of EUR 26,400 on a debt collector. The controller processed the personal data of a natural person, specifically data relating to a consumer… HUNGARY ·NAIH ·Art. 6, 17 Personal Data Controllers Insurance Jul 24, 2025
€5,000 Agricola International SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Agricola International SA. The controller failed to implement sufficient technical and organisational measures, resulting in a… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing Agreement Jul 23, 2025
€10,000 Orde van de verpleegkundigen van Viterbo: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 32 Security Data Breaches Education NL Jul 23, 2025
€4M McDonald’s Polska Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed a fine of EUR 3,955,000 on McDonald’s Polska Sp. z o.o. The controller used a third party processor (see ETid: 2758) for the purpose of managing work… POLAND ·UODO ·Art. 5, 25, 28 +1 Controllers Processors Data Breaches Jul 21, 2025
€43,000 24/7 Communication Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 43,000 on 24/7 Communication Sp. z o.o. The fined entity acted as the data processor for McDonald’s Polska Sp. z o.o. (see ETid: 2757).… POLAND ·UODO ·Art. 5, 25, 38 Data Breaches Processors Controllers Jul 21, 2025
€1,100 ADMINISTRACIONES BENIPON, S.L.: Insufficient fulfilment of data breach notification obligations The Spanish DPA has imposed a fine of EUR 1,100 on ADMINISTRACIONES BENIPON, S.L. The processor failed to notify the controller of a data breach and also used a sub-processor… SPAIN ·aepd ·Art. 28, 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jul 18, 2025
€1,200 TRUEBA SPORT S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,200 on TRUEBA SPORT S.L. The controller disclosed personal data due to an human error. The controller also failed to include a privacy… SPAIN ·aepd ·Art. 5, 13 Controllers Personal Data Security Jul 17, 2025
€180,000 TRIVE CREDIT SPAIN, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 180,000 on TRIVE CREDITSPAIN, S.L. The controller failed to adequatly comply with a order from the DPA. The original fine of EUR 225,000… aepd ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Jul 16, 2025