Content type · 2,395 documents in this view · 3,813 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3589 Processing 2636 Personal Data 2395 Controllers 2018 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
€2,000 Municipality of San Genesio and Uniti: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of San Genesio and Uniti €2,000 for processing personal data without a sufficient legal basis. The Authority… Italy · ·Art. 5, 6, 9 Jul 3, 2026
RON 26,172 The Romanian DPA (ANSPDCP) launched an investigation into a bank, Banca Transilvania S.A (the controller), following a data subject’s complaint. The data subject claimed that their personal data associated with their bank account had been processed without their… 02/07/2026 ·Romania ·Art. 32
€23,750 Società Editoriale Il Fatto S.p.A.: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Società Editoriale Il Fatto S.p.A. €23,750 for processing personal data without a sufficient legal basis, in violation of… Italy · ·Art. 5 Jul 3, 2026
€2,000 Municipality of Villaputzu: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of Villaputzu €2,000 for processing personal data without a sufficient legal basis. The enforcement action… Italy · ·Art. 5, 6 Jul 3, 2026
€15,000 University of Pisa: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the University of Pisa €15,000 for failing to implement adequate technical and organizational measures to ensure information… Italy · ·Art. 5, 6, 25 +1 Jul 3, 2026
IMY-2024-2904 The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of… IMY-2024-2904 ·Sweden ·Art. 13 Jul 3, 2026
€120,000 Experian Italia S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Experian Italia S.p.A. €120,000 for violating GDPR Articles 5(1)(a) and (c), 12, 15, and 25, concerning non-compliance with… Italy · ·Art. 5, 12, 15 +1 Jul 3, 2026
€158,000 Garante · 487/2026 Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Art. 3, 5, 12 +7 Jul 3, 2026
€1.4M EstEnergy S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined EstEnergy S.p.A. €1,400,000 for violations of general data processing principles under Article 5(1) of the GDPR, alongside… Italy · ·Art. 5, 12, 13 +3 Jul 3, 2026
€5.8M 483/2026 Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas… Italy · ·Art. 5, 12, 13 +3 Jul 3, 2026
€5,000 Banca Transilvania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Banca Transilvania S.A. €5,000 on July 2, 2026, for failing to implement sufficient… Romania · ·Art. 32 Jul 2, 2026
€11,000 Ascendex Technology SRL: Insufficient fulfilment of data subjects rights The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Ascendex Technology SRL €11,000 for insufficient fulfillment of data subjects' rights. The… Romania · ·Art. 12, 17 Jul 1, 2026
Persónuvernd (Island) - 2025010358 The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… 2025010358 ·Iceland ·Art. 5, 32 Jul 1, 2026
2025010364 The DPA received a complaint from a data subject regarding the processing of their personal data by Borgarholtsskóli (a school and the controller) in connection with an anonymous… 2025010364 ·Iceland · Jun 24, 2026
€450,000 VDAI fines medical company €450,000 for inadequate security measures in data breaches Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Lithuania ·Art. 5, 24 Jun 19, 2026
€450,000 InMedica UAB: Insufficient technical and organisational measures to ensure information security The Lithuanian Data Protection Authority (VDAI) fined InMedica UAB €450,000 for failing to implement sufficient technical and organizational measures to ensure information… Lithuania · ·Art. 5, 24, 32 Jun 19, 2026
€10,000 Docplanner Italy S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined Docplanner Italy S.r.l. €10,000 for failing to implement sufficient technical and organizational measures to ensure… ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Jun 18, 2026
€460,000 Garante · 476/2026 Two former employees (the data subjects) of Piaggio (the controller) were dismissed for just cause in March 2023. Following the termination of their employment, they asked the… Italy ·Art. 5, 6, 12 +2 Jun 18, 2026
€5,000 Garante · 457/2026 The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A… Italy ·Art. 5, 6, 12 +2 Jun 18, 2026
€6,600 Garante · 462/2026 The case involves a worker (the data subject), his former employer (the controller), and the staffing agency that had provided the company with the worker. In late 2023 the data… Italy ·Art. 2, 4, 5 +2 Jun 18, 2026
€10,000 Altex Romania S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Altex Romania S.R.L. €10,000 for failing to implement sufficient technical and… ·Art. 32, 33, 34 ·Insufficient technical and organisational measures to ensure information security Jun 18, 2026
€1,000 Dormeo Home SRL: Insufficient fulfilment of data subjects rights The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Dormeo Home SRL €1,000 for insufficient fulfillment of data subjects' rights under the… Romania · ·Art. 6, 21 Jun 16, 2026
€2,000 SSG SELECT SOLUTIONS S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined SSG Select Solutions S.R.L. €2,000 for failing to implement adequate technical and… Romania · ·Art. 29, 32 Jun 15, 2026
€2,760 UODO fines accounting firm €2,760 for email breach security failures An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained… Poland ·Art. 5, 24, 25 +1 Jun 13, 2026
€2,760 Sole trader providing accounting and tax advisory services: Insufficient technical and organisational measures to ensure information security The Polish National Personal Data Protection Office (UODO) fined a sole trader providing accounting and tax advisory services €2,760 for failing to implement sufficient technical… Poland · ·Art. 5, 25, 32 Jun 13, 2026
€65,000 MEDE S.A.: Non-compliance with general data processing principles The Hellenic Data Protection Authority fined MEDE S.A. €65,000 for violating general data processing principles under Article 5 GDPR, along with failures concerning transparency… Greece · ·Art. 5, 12, 13 +2 Jun 12, 2026
€5,000 Națională Poșta Română: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Națională Poșta Română €5,000 on 2026-06-12 for: Insufficient technical and organisational… Romania · ·Art. 32 Jun 12, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland · ·Art. 5, 28, 30 +2 Jun 11, 2026
UODO reprimands hospital for inadequate processor oversight and email security failures The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Poland ·Art. 5, 24, 25 +3 Jun 11, 2026
€15,300 Green Partner S.r.l.s.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Green Partner S.r.l.s. €15,300 for violations of multiple GDPR provisions, including Articles 5, 6, 7, 12, 15–22, and 28,… Italy · ·Art. 5, 6, 7 +3 Jun 11, 2026
€1,000 Pietro d'Abano State Vocational School: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Pietro d'Abano State Vocational School €1,000 for processing personal data without a sufficient legal basis, finding… Italy · ·Art. 5, 6 Jun 11, 2026
Belgian DPA rejects delisting request for US government URL showing criminal conviction The data subject requested from a search engine (controller) the removal of a URL that appears when the data subject’s name is entered into the search engine. The URL points to… DOS-2025-04652 ·Belgium · Jun 8, 2026
€5,000 Municipality of Vasto: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined the Municipality of Vasto €5,000 for failing to adequately fulfill its information obligations under the GDPR. The authority… Italy · ·Art. 5, 12, 13 +1 Jun 8, 2026
€10,000 Piraeus Bank S.A.: Insufficient fulfilment of data subjects rights The Hellenic Data Protection Authority (HDPA) fined Piraeus Bank S.A. €10,000 for insufficient fulfillment of data subjects' access rights under Article 15 of the GDPR. The… Greece · ·Art. 15 Jun 5, 2026
€1,153 Reda Naujokaitienė: Insufficient legal basis for data processing The Lithuanian Data Protection Authority (VDAI) fined Reda Naujokaitienė €1,153 on June 5, 2026, for insufficient legal basis for personal data processing in the health care… Lithuania · ·Art. 5, 6, 9 Jun 5, 2026
€23,540 Minister of Justice: Insufficient technical and organisational measures to ensure information security Polish National Personal Data Protection Office (UODO) fined Minister of Justice €23,540 on 2026-06-02 for: Insufficient technical and organisational measures to ensure… Poland · ·Art. 32 Jun 2, 2026
€80,000 PRELUDE GROUP E.E.: Insufficient technical and organisational measures to ensure information security The Hellenic Data Protection Authority (HDPA) fined PRELUDE GROUP E.E. €80,000 for failing to implement sufficient technical and organizational measures to ensure information… Greece · ·Art. 28, 29, 32 Jun 2, 2026
UODO fines controller for refusing to cooperate and provide information in two data The DPA received two complaints against the same company (the controller) due to the unauthorised access to the data subjects’ personal data. The first complaint concerned… DKE.561.1.2026 ·Poland ·Art. 31, 58 Jun 1, 2026
€70,518 IndaNext Hungary Kft. (legal successor of Blikk Kft.): Insufficient legal basis for data processing The Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined IndaNext Hungary Kft., as legal successor to Blikk Kft., €70,518 for publishing… ·Art. 6, 9, 12 ·Insufficient legal basis for data processing May 29, 2026
€12,000 Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Unicredit Bank SA €12,000 on 2026-05-29 for: Insufficient technical and organisational… Romania · ·Art. 32, 33 May 29, 2026
€3,930 Action Fit di Milano: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Action Fit di Milano €3,930 for violations of Articles 6(1)(a), 12, and 21(2) GDPR, relating to non-compliance with general… Italy · ·Art. 6, 12, 21 May 28, 2026
€55,000 The data controller for the case is a government body called the Agency for Digital Italy (AgID) AgID is tasked with driving the adoption of digital technologies in both government and the private sector. Additionally, AgID is Italy’s soon-to-be notification authority for the… 419/2026 · ·Art. 5, 12, 14 +1 May 28, 2026
Binding Decision 1/2026 On 10 August 2021, a data subject represented by noyb lodged a complaint with the Austrian DPA against Vlaamse Radio- en Televisieomroeporganisatie (VRT), the controller. The… Binding Decision 1/2026 ·European Union · May 28, 2026
€3,000 Autonomous Region of Sardinia: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Autonomous Region of Sardinia €3,000 on May 28, 2026, for processing personal data without a sufficient legal basis. The… Italy · ·Art. 5, 6 May 28, 2026
€6,000 Liguria Health Protection Authority: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Liguria Health Protection Authority €6,000 for lacking a sufficient legal basis for personal data processing in the… Italy · ·Art. 5, 6, 25 +2 May 28, 2026
€1,400 Ristorante Carlo Menta s.r.l.: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined Ristorante Carlo Menta s.r.l. €1,400 for failing to adequately fulfill its information obligations under the GDPR. The… Italy · ·Art. 5, 13 May 28, 2026
€6,000 A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller) The data subject was employed by the Ligurian Social and Health Care Agency, however, the organisation was later merged with the controller. According to the data subject, the… 382/2026 ·Italy · May 28, 2026
€700 Garante · 385/2026 A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy ·Art. 5, 9 May 28, 2026
€6,000 Municipality of Sciacca: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of Sciacca €6,000 for processing personal data without a sufficient legal basis. The Garante found that the… Italy · ·Art. 5, 6 May 28, 2026
€140,127 Mediaworks Hungary Zrt.: Insufficient legal basis for data processing The Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined Mediaworks Hungary Zrt. €140,127 for processing and publishing personal data… ·Art. 6, 9 ·Insufficient legal basis for data processing May 26, 2026