Skip to content
Content type · 482 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

101–150 of 482 sort newestlargest fineoldest
€2,000 Linea Stampalibera Società Cooperativa r.I.: Non-compliance with the general principles for data processing. ⇄ Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor gegevensbescherming (Garante). ITALY ·Garante ·Art. 5 Controllers Processing Health Data Aug 4, 2025
€3,000 Zougla TZI-AP, an anonymous mass media conglomerate: Insufficient legal basis for the processing of personal data. ⇄ Boete van €3.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 31 Personal Data Processing Controllers Jul 4, 2025
€3,000 Zougla TZI-AP Anonymous Mass Media Company: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 3,000 on Zougla TZI-AP Anonymous Media Company. The controller, who operates a news website, published an article revealing the personal… GREECE ·HDPA ·Art. 5, 31 Personal Data Controllers Supervisory Authorities Jul 4, 2025
€40,000 KARAMBELAS KONSTANTINOS & CO. E.E.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 40,000 on KARAMBELAS KONSTANTINOS & CO. E.E. The processor, which was processing data for a telecommunications provider (ETid: 2878),… GREECE ·HDPA ·Art. 29, 32 Security Processors Controllers Jun 25, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 550.000 euro - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 28 Security Supervisory Authorities Controllers Jun 25, 2025
€40,000 KARAMBELAS KONSTANTINOS & CO. E.E.: Insufficient Technical and Organizational Measures for Data Security ⇄ Boete van 40.000 euro - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 29, 32 Security Personal Data Telecommunications Jun 25, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 550,000 on Vodafone – PANAFON A.E.E.T. The controller failed to implement sufficient technical and organisational measures to ensure data… GREECE ·HDPA ·Art. 5, 28 Security Controllers Processors Jun 25, 2025
€4,000 Vodafone Romania S.A.: Insufficient technical and organizational measures to ensure information security. ⇄ 4.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Security Processing Personal Data Jun 23, 2025
€4,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 4,000 on Vodafone Romania S.A. The controller failed to implement sufficient technical and organisational measures to ensure data… ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Jun 23, 2025
€60,000 AIRE NETWORKS DEL MEDITERRÁNEO, S.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 60.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability May 23, 2025
€60,000 AIRE NETWORKS DEL MEDITERRÃNEO, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 60,000 on AIRE NETWORKS DEL MEDITERRÃNEO, S.L. The controller did not implement sufficient technical and organisational measures to ensure… SPAIN ·AEPD ·Art. 5 Security Controllers Data Breaches May 23, 2025
€200,000 TELEFÓNICA MÓVILES ESPAÑA, S.A.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 200,000 on TELEFÓNICA MÓVILES ESPAÑA, S.A. The controller forwarded personal data to a third party without a sufficient legal basis. SPAIN ·AEPD ·Art. 6 Controllers Personal Data Telecommunications May 21, 2025
€200,000 TELEFÓNICA MÓVILES ESPAÑA, S.A.: Insufficient legal basis for data processing. ⇄ Een boete van 200.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6 Controllers Personal Data Processing May 21, 2025
€30,000 ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.: Non-compliance with the general principles for data processing. ⇄ Boete van 30.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Personal Data Processing May 16, 2025
€30,000 ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 30,000 on ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A. The controller published a video of a violent incident, which contained the… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Identification May 16, 2025
€80,000 CALOGA: Non-compliance with general principles of data processing. ⇄ Een boete van 80.000 euro - van de Franse Autoriteit voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 5, 6 Controllers Processing Accountability May 15, 2025
€80,000 CALOGA: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 80,000 on CALOGA. The controller is a company obtaining data from data brokers to use those for marketing purposes. The DPA found multiple… FRANCE ·CNIL ·Art. 5, 6 Controllers Processing IP Address May 15, 2025
€900,000 SOLOCAL MARKETING SERVICES: Insufficient legal basis for data processing The French DPA imposed a fine of EUR 900,000 on SOLOCAL MARKETING SERVICES. The controller, a company that also engages in direct marketing activities for its clients, ist using… FRANCE ·CNIL ·Art. 6, 7 Consent Controllers Personal Data May 15, 2025
€900,000 SOLOCAL MARKETING SERVICES: Insufficient legal basis for data processing. ⇄ 900.000 euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 6, 7 Consent Controllers Processing May 15, 2025
€530M TikTok Technology Limited: Insufficient legal basis for data processing The Irish DPA (DPC) has fined TikTok EUR 530 million. In its decision, the DPC found, that TikTok infringed Art. 13 (1) f) GDPR and Art. 46 (1) GDPR due to the unlawful transfer… DPC ·Art. 13, 46 Processing Agreement International Transfer Personal Data May 2, 2025
€260,000 CAMERDATA, S.A.: Insufficient legal basis for the processing of data. ⇄ Een boete van 260.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6, 14 Personal Data Processing Supervisory Authorities Apr 15, 2025
€260,000 CAMERDATA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 260,000 on CAMERDATA, S.A. The controller operates a database in which it collects data on individual entrepreneurs from the Spanish… SPAIN ·AEPD ·Art. 6, 14 Controllers Personal Data Supervisory Authorities Apr 15, 2025
€3,000 EDA TV CONSULTING, S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on EDA TV CONSULTING, S.L. The controller had stored copies of personal IDs to verify the identity of data subjects. According to the DPA, the… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Personal Data Apr 14, 2025
€3,000 EDA TV CONSULTING, S.L.: Infringement of the general principles for data processing. ⇄ Boete van 3.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Processing Accountability Apr 14, 2025
€5M Luka Inc.: Non-compliance with the general principles of data processing. ⇄ Een boete van 5.000.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +3 Controllers Processing Supervisory Authorities Apr 10, 2025
€850,000 Network of agencies and companies: Non-compliance with general data processing principles. ⇄ 850.000 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +6 Processing Supervisory Authorities Marketing Apr 10, 2025
€5M Luka Inc.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 5,000,000 on Luka Inc. The developer created a chatbot called Replika with a written and voice interface. It is based on a generative AI… ITALY ·Garante ·Art. 5, 6, 12 +3 Controllers Personal Data Supervisory Authorities Apr 10, 2025
€850,000 Network of Agencies and Companies: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 850,000 on a network of agencies and companies. The network operated on behalf of Acea Energia S.p.A. and engaged in aggresive customer… ITALY ·Garante ·Art. 5, 6, 7 +6 Supervisory Authorities Processing Agreement Processing Apr 10, 2025
€3,000 BINBOX GLOBAL SERVICES S.R.L.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Apr 2, 2025
€3,000 BINBOX GLOBAL SERVICES S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on BINBOX GLOBAL SERVICES S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Apr 2, 2025
€4,000 CREMA GAMES, S.L.: Insufficient fulfilment of information obligations The Spanish DPA imposed a fine on CREMA GAMES, S.L. The controller failed to fulfill an information request from an online customer. The controller asked the data subject for an… SPAIN ·AEPD ·Art. 15 Personal Data Controllers Supervisory Authorities Mar 28, 2025
€4,000 CREMA GAMES, S.L.: Insufficient compliance with information obligations. ⇄ Een boete van 4.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 15 Personal Data Controllers Right of Access Mar 28, 2025
€40,000 Company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 40,000 on a company that published personal data of sole traders on its website. The data originated from public sources and from… CROATIA ·AZOP ·Art. 5, 6, 12 +3 Personal Data Supervisory Authorities Processing Mar 24, 2025
€40,000 Company: Insufficient legal basis for the processing of data. ⇄ Een boete van 40.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·AZOP ·Art. 5, 6, 12 +3 Processing Professional Secrecy Personal Data Mar 24, 2025
€4,800 TECNOCRÃTICA CENTRO DE DATOS S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 4,800 on TECNOCRÃTICA CENTRO DE DATOS S.L. The controller failed to reply to an information request by the AEPD within the given… SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Controllers Mar 20, 2025
€15,000 G@S Telecomunicazioni di Losito Lucia: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 15,000 on G@S Telecomunicazioni di Losito Lucia. The controller processed customer data without sufficient legal basis and additionally… ITALY ·Garante ·Art. 5, 6, 7 +2 Personal Data Controllers Supervisory Authorities Mar 13, 2025
€13,400 Polskie Radio Szczecin: Insufficient technical and organisational measures to ensure information security The Polish DPA fined Polskie Radio Szczecin (Polish Radio Szczecin) EUR 13,400. Due to the lack of sufficient technical measures, Polskie Radio Szczecin failed to protect the… POLAND ·UODO ·Art. 24, 32 Security Personal Data Processing Mar 11, 2025
€338,000 Telenor ASA.: Non-compliance with general data processing principles The Norwegian DPA has imposed a fine of EUR 333,800 on Telenor ASA. During its investigation, the DPA found that the company had not conducted sufficient assessments and… NORWAY ·Datatilsynet (NO) ·Art. 24, 37, 38 Supervisory Authorities Supervision Processing Mar 10, 2025
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… SPAIN ·AEPD ·Art. 6 Personal Data Consent Telecommunications Feb 25, 2025
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… SPAIN ·AEPD ·Art. 6 Personal Data Consent Telecommunications Feb 14, 2025
€1.2M ORANGE ESPAGNE, S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,200,000 on ORANGE ESPAGNE, S.A.U.. An individual had filed a complaint with the DPA because the company had given a duplicate of their… SPAIN ·AEPD ·Art. 6, 25 Personal Data Security Consent Feb 5, 2025
€40,000 Orange Romania SA: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 40,000 on Orange Romania SA. The controller failed to fulfil a request for the erasure of data. The controller also execsevly stored and… ANSPDCP ·Art. 5, 6, 7 +2 ·Non-compliance with general data processing principles Controllers Personal Data Supervisory Authorities Jan 27, 2025
€15,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Vodafone Romania S.A. Personal data such as names, email addresses and customer numbers were repeatedly disclosed due to… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Controllers Jan 20, 2025
€45M Vodafone GmbH: Non-compliance with general data processing principles The Federal Commissioner for Data Protection and Freedom of Information (BfDI) has imposed a fine of EUR 45,000,000 on Vodafone GmbH. The controller failed to properly supervise a… BfDI Processors Controllers Personal Data Jan 1, 2025
€251M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish Data Protection Commission (DPC) has fined Meta Platforms Ireland Limited EUR 251 million. The fine was imposed for data protection violations related to a data breach… DPC Notification Obligation Data Breaches Controllers Dec 17, 2024
€4.8M Netflix International B.V.: Insufficient fulfilment of information obligations The Dutch DPA has imposed a fine of EUR 4.75 million on Netflix. This fine is based on a complaint filed by the Austrian organization 'noyb'. During its investigation, the DPA… THE NETHERLANDS ·AP ·Art. 5, 12, 13 +1 Personal Data Supervisory Authorities Supervision Nov 26, 2024
€2,300 Company: Non-compliance with general data processing principles The DPA of Luxembourg has issued a fine of EUR 2,300 on a company, that is active in the retail sale of telecommunication equipement in specialised stores. The controller had… LUXEMBOURG ·CNPD (LU) ·Art. 5, 6, 13 +2 Retention Period Controllers Security Nov 20, 2024
€200,000 VODAFONE ESPAÑA, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. An individua had filed a complaint with the DPA because the company had given a duplicate of their… SPAIN ·AEPD ·Art. 6 Personal Data Consent Telecommunications Nov 19, 2024
€15M OpenAI OpCo LLC: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15 million on OpenAI in connection with the operation of the generative AI chatbot “ChatGPT”. The DPA found that OpenAI had violated… ITALY ·Garante ·Art. 5, 6, 12 +4 Transparency Fairness & Transparency Personal Data Nov 2, 2024