Content type · 3,587 documents in this view · 3,811 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3587 Processing 2635 Personal Data 2394 Controllers 2017 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
€2M Garante fines Lusha Systems Inc. over unauthorized B2B contact database Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was a… Italy ·Art. 3, 5, 6 +2 Jul 14, 2026
€120,000 NIER Ingeriegna S.p.A. SB: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined NIER Ingegneria S.p.A. SB €120,000 for failing to implement adequate technical and organizational measures to ensure… Italy · ·Art. 5, 32 Jul 14, 2026
€700 La Terrazza: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined La Terrazza, an entity in the accommodation and hospitality sector, €700 for failing to adequately fulfill its information… Italy · ·Art. 5, 6, 13 Jul 14, 2026
€57,839 Fine against Ascendex Technology SRL The Romanian DPA (ANSPDCP) launched an investigation into the cryptocurrency exchange platform Ascendex Technology SRL (the controller). The DPA was notified by the French DPA… Romania · ·Art. 4, 12, 17 +1
€1,198 A company (the controller) operates an online store An employee of the controller used a pirated and unlicensed software when creating the website. This software contained malicious code, which allowed a third person to access the… 0609-36/2026/7 ·Slovenia · Jul 8, 2026
€15,000 University of Pisa: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the University of Pisa €15,000 for failing to implement adequate technical and organizational measures to ensure information… Italy · ·Art. 5, 6, 25 +1 Jul 3, 2026
€10,000 Giuliano Isontina University Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the Giuliano Isontina University Health Authority €10,000 for failing to implement adequate technical and organizational… Italy · ·Art. 5, 9, 25 +1 Jul 3, 2026
€158,000 Garante · 487/2026 Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Art. 3, 5, 12 +7 Jul 3, 2026
€5.8M Hera Comm S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Hera Comm S.p.A. €5,800,000 for violations of the general data processing principles under Article 5 of the GDPR, alongside… Italy · ·Art. 5, 12, 13 +3 Jul 3, 2026
€23,750 Società Editoriale Il Fatto S.p.A.: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Società Editoriale Il Fatto S.p.A. €23,750 for processing personal data without a sufficient legal basis, in violation of… Italy · ·Art. 5 Jul 3, 2026
IMY-2024-2904 The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of… IMY-2024-2904 ·Sweden ·Art. 13 Jul 3, 2026
€400,000 Cerved Group S.p.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) fined Cerved Group S.p.A. €400,000 for insufficient fulfillment of data subjects' rights, including violations of Article 5(1)(a),… Italy · ·Art. 5, 12, 15 Jul 3, 2026
€2,000 Municipality of Villaputzu: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of Villaputzu €2,000 for processing personal data without a sufficient legal basis. The enforcement action… Italy · ·Art. 5, 6 Jul 3, 2026
€158,000 Character Technologies Inc.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Character Technologies Inc. €158,000 for violations of multiple GDPR provisions, including Article 5(2) on general data… Italy · ·Art. 5, 12, 13 +5 Jul 3, 2026
€2,000 Municipality of San Genesio and Uniti: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of San Genesio and Uniti €2,000 for processing personal data without a sufficient legal basis. The Authority… Italy · ·Art. 5, 6, 9 Jul 3, 2026
€120,000 Experian Italia S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Experian Italia S.p.A. €120,000 for violating GDPR Articles 5(1)(a) and (c), 12, 15, and 25, concerning non-compliance with… Italy · ·Art. 5, 12, 15 +1 Jul 3, 2026
€1.4M EstEnergy S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined EstEnergy S.p.A. €1,400,000 for violations of general data processing principles under Article 5(1) of the GDPR, alongside… Italy · ·Art. 5, 12, 13 +3 Jul 3, 2026
€5.8M 483/2026 Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas… Italy · ·Art. 5, 12, 13 +3 Jul 3, 2026
€1.4M Garante · 484/2026 EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller… Italy ·Art. 5, 13, 14 +2 Jul 3, 2026
RON 26,172 The Romanian DPA (ANSPDCP) launched an investigation into a bank, Banca Transilvania S.A (the controller), following a data subject’s complaint. The data subject claimed that their personal data associated with their bank account had been processed without their… 02/07/2026 ·Romania ·Art. 32
€5,000 Banca Transilvania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Banca Transilvania S.A. €5,000 on July 2, 2026, for failing to implement sufficient… Romania · ·Art. 32 Jul 2, 2026
€11,000 Ascendex Technology SRL: Insufficient fulfilment of data subjects rights The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Ascendex Technology SRL €11,000 for insufficient fulfillment of data subjects' rights. The… Romania · ·Art. 12, 17 Jul 1, 2026
Persónuvernd (Island) - 2025010358 The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… 2025010358 ·Iceland ·Art. 5, 32 Jul 1, 2026
2025010364 The DPA received a complaint from a data subject regarding the processing of their personal data by Borgarholtsskóli (a school and the controller) in connection with an anonymous… 2025010364 ·Iceland · Jun 24, 2026
€450,000 VDAI fines medical company €450,000 for inadequate security measures in data breaches Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Lithuania ·Art. 5, 24 Jun 19, 2026
€450,000 InMedica UAB: Insufficient technical and organisational measures to ensure information security The Lithuanian Data Protection Authority (VDAI) fined InMedica UAB €450,000 for failing to implement sufficient technical and organizational measures to ensure information… Lithuania · ·Art. 5, 24, 32 Jun 19, 2026
€10,000 Altex Romania S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Altex Romania S.R.L. €10,000 for failing to implement sufficient technical and… ·Art. 32, 33, 34 ·Insufficient technical and organisational measures to ensure information security Jun 18, 2026
€20,000 Enna Provincial Health Authority: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Enna Provincial Health Authority €20,000 for violating GDPR Articles 5, 6, 10, and 12, which concern general data… Italy · ·Art. 5, 6, 10 +1 Jun 18, 2026
€90,000 Acquirente Unico S.p.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) fined Acquirente Unio S.p.A. €90,000 for insufficient fulfilment of data subjects' rights under GDPR Articles 12, 16, and 28. The… Italy · ·Art. 12, 16, 28 Jun 18, 2026
€6,600 Garante · 462/2026 The case involves a worker (the data subject), his former employer (the controller), and the staffing agency that had provided the company with the worker. In late 2023 the data… Italy ·Art. 2, 4, 5 +2 Jun 18, 2026
€5,000 Garante · 457/2026 The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A… Italy ·Art. 5, 6, 12 +2 Jun 18, 2026
€2,075 Edizioni Grandangolo di Giuseppe Castaldo: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Edizioni Grandangolo di Giuseppe Castaldo €2,075 for failing to comply with general data processing principles under Articles… Italy · ·Art. 5, 12, 13 +4 Jun 18, 2026
€460,000 Garante · 476/2026 Two former employees (the data subjects) of Piaggio (the controller) were dismissed for just cause in March 2023. Following the termination of their employment, they asked the… Italy ·Art. 5, 6, 12 +2 Jun 18, 2026
€6,600 Cosmint S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Cosmint S.p.A. €6,600 for violating general data processing principles in the employment sector, specifically under Articles… Italy · ·Art. 5, 6, 13 Jun 18, 2026
€10,000 Docplanner Italy S.r.l.: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined Docplanner Italy S.r.l. €10,000 for failing to implement sufficient technical and organizational measures to ensure… ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Jun 18, 2026
€3,000 SILVANERGIA 2022, S.L.: Insufficient legal basis for data processing Spain · ·Art. 6 Jun 16, 2026
€1,000 Dormeo Home SRL: Insufficient fulfilment of data subjects rights The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Dormeo Home SRL €1,000 for insufficient fulfillment of data subjects' rights under the… Romania · ·Art. 6, 21 Jun 16, 2026
€2,000 SSG SELECT SOLUTIONS S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined SSG Select Solutions S.R.L. €2,000 for failing to implement adequate technical and… Romania · ·Art. 29, 32 Jun 15, 2026
€2,760 UODO fines accounting firm €2,760 for email breach security failures An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained… Poland ·Art. 5, 24, 25 +1 Jun 13, 2026
€95,000 Market-In: Non-compliance with general data processing principles The Hellenic Data Protection Authority (HDPA) fined Market-In €95,000 for violations of the general data processing principles under Article 5 GDPR, including failures related to… Greece · ·Art. 5, 12, 13 +2 Jun 12, 2026
€65,000 MEDE S.A.: Non-compliance with general data processing principles The Hellenic Data Protection Authority fined MEDE S.A. €65,000 for violating general data processing principles under Article 5 GDPR, along with failures concerning transparency… Greece · ·Art. 5, 12, 13 +2 Jun 12, 2026
€5,000 Națională Poșta Română: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Națională Poșta Română €5,000 on 2026-06-12 for: Insufficient technical and organisational… Romania · ·Art. 32 Jun 12, 2026
€1,000 Pietro d'Abano State Vocational School: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Pietro d'Abano State Vocational School €1,000 for processing personal data without a sufficient legal basis, finding… Italy · ·Art. 5, 6 Jun 11, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland · ·Art. 5, 28, 30 +2 Jun 11, 2026
UODO reprimands hospital for inadequate processor oversight and email security failures The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Poland ·Art. 5, 24, 25 +3 Jun 11, 2026
€15,300 Green Partner S.r.l.s.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Green Partner S.r.l.s. €15,300 for violations of multiple GDPR provisions, including Articles 5, 6, 7, 12, 15–22, and 28,… Italy · ·Art. 5, 6, 7 +3 Jun 11, 2026
€4,500 Lecce Local Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the Lecce Local Health Authority €4,500 for failing to implement adequate technical and organizational measures to ensure… Italy · ·Art. 5, 29, 32 Jun 11, 2026
Belgian DPA rejects delisting request for US government URL showing criminal conviction The data subject requested from a search engine (controller) the removal of a URL that appears when the data subject’s name is entered into the search engine. The URL points to… DOS-2025-04652 ·Belgium · Jun 8, 2026
€5,000 Municipality of Vasto: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined the Municipality of Vasto €5,000 for failing to adequately fulfill its information obligations under the GDPR. The authority… Italy · ·Art. 5, 12, 13 +1 Jun 8, 2026
€10,000 Piraeus Bank S.A.: Insufficient fulfilment of data subjects rights The Hellenic Data Protection Authority (HDPA) fined Piraeus Bank S.A. €10,000 for insufficient fulfillment of data subjects' access rights under Article 15 of the GDPR. The… Greece · ·Art. 15 Jun 5, 2026