Content type · 847 documents in this view · 3,813 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3589 Processing 2636 Personal Data 2395 Controllers 2018 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
€5,000 Municipality of Vasto: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined the Municipality of Vasto €5,000 for failing to adequately fulfill its information obligations under the GDPR. The authority… Italy · ·Art. 5, 12, 13 +1 Jun 8, 2026
Belgian DPA rejects delisting request for US government URL showing criminal conviction The data subject requested from a search engine (controller) the removal of a URL that appears when the data subject’s name is entered into the search engine. The URL points to… DOS-2025-04652 ·Belgium · Jun 8, 2026
€10,000 Piraeus Bank S.A.: Insufficient fulfilment of data subjects rights The Hellenic Data Protection Authority (HDPA) fined Piraeus Bank S.A. €10,000 for insufficient fulfillment of data subjects' access rights under Article 15 of the GDPR. The… Greece · ·Art. 15 Jun 5, 2026
€1.8M Elkjøp AS: Insufficient legal basis for data processing Norwegian Supervisory Authority (Datatilsynet) fined Elkjøp AS €1,820,000 on 2026-06-01 for: Insufficient legal basis for data processing. Norway · ·Art. 5, 6, 12 Jun 1, 2026
UODO fines controller for refusing to cooperate and provide information in two data The DPA received two complaints against the same company (the controller) due to the unauthorised access to the data subjects’ personal data. The first complaint concerned… DKE.561.1.2026 ·Poland ·Art. 31, 58 Jun 1, 2026
€12,000 Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Unicredit Bank SA €12,000 on 2026-05-29 for: Insufficient technical and organisational… Romania · ·Art. 32, 33 May 29, 2026
€700 Italian Red Cross: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Italian Red Cross €700 for violating general data processing principles under GDPR Articles 5(1)(c), 5(1)(f), and 9. The… Italy · ·Art. 5, 9 May 28, 2026
€55,000 The data controller for the case is a government body called the Agency for Digital Italy (AgID) AgID is tasked with driving the adoption of digital technologies in both government and the private sector. Additionally, AgID is Italy’s soon-to-be notification authority for the… 419/2026 · ·Art. 5, 12, 14 +1 May 28, 2026
€3,930 Action Fit di Milano: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Action Fit di Milano €3,930 for violations of Articles 6(1)(a), 12, and 21(2) GDPR, relating to non-compliance with general… Italy · ·Art. 6, 12, 21 May 28, 2026
€700 Garante · 385/2026 A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy ·Art. 5, 9 May 28, 2026
Binding Decision 1/2026 On 10 August 2021, a data subject represented by noyb lodged a complaint with the Austrian DPA against Vlaamse Radio- en Televisieomroeporganisatie (VRT), the controller. The… Binding Decision 1/2026 ·European Union · May 28, 2026
PLN 21,000 DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Poland · ·Art. 24, 25, 28 +1 May 25, 2026
€4,958 District Governor of Lubartów: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) fined the District Governor of Lubartów €4,958 for failing to implement adequate technical and organizational measures to ensure information security, citing… Poland · ·Art. 5, 25, 28 +1 May 25, 2026
€6,292 Private individual: Insufficient cooperation with supervisory authority The Polish National Personal Data Protection Office (UODO) fined a private individual €6,292 for failing to adequately cooperate with the supervisory authority during an… Poland · ·Art. 58, 83 May 22, 2026
PLN 26,711 DKE.561.4.2026 The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance extending… Poland · ·Art. 5 May 22, 2026
GBP 300 ICO (UK) - KRA Consultancy Ltd The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related services.… United Kingdom May 20, 2026
PLN 33,700 DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Poland · ·Art. 5, 24, 25 +3 May 19, 2026
€15,000 Monaldi-Cotugno-CTO: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Monaldi-Cotugno-CTO hospital entity €15,000 for violating general data processing principles under the GDPR. The… Italy · ·Art. 5, 9, 13 +2 May 14, 2026
€1,000 FeGi M&A Services s.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined FeGi M&A Services s.r.l. €1,000 for non-compliance with general data processing principles under Article 5(1)(a) and Article… Italy · ·Art. 5, 14 May 14, 2026
€100,000 Energia Sostenibile S.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Energia Sostenibile S.r.l. €100,000 for violations of multiple GDPR provisions, including Articles 5, 6, 7, 12, 13, 15, 24,… Italy · ·Art. 5, 6, 7 +5 May 14, 2026
€1,800 Municipality of Mirabella Imbaccari: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of Mirabella Imbaccari €1,800 for processing personal data without a sufficient legal basis, in violation of… Italy · ·Art. 5, 6, 37 May 14, 2026
€1,500 Francesco Gagliardi: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) found Francesco Gagliardi, operating as a sole proprietorship, in violation of Articles 5(1)(a) and 14 of the GDPR and Article 130… Italy · ·Art. 5, 14 May 14, 2026
€8,000 Municipality of Ventasso: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Municipality of Ventasso €8,000 for violating the general data processing principles under Articles 5, 6, and 9 of the… Italy · ·Art. 5, 6, 9 May 14, 2026
HDPA · 12/2026 The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Greece ·Art. 23 May 13, 2026
HUF 15M NAIH-450-7-2026 The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 May 12, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland · ·Art. 5, 32, 33 May 8, 2026
€277,500 Permanent TSB plc: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Permanent TSB plc €277,500 for failing to implement sufficient technical and organisational measures to ensure information security,… Ireland · ·Art. 5, 32, 33 Apr 30, 2026
HUF 10M NAIH-4462-5-2026 The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Apr 30, 2026
€1,790 Mayor of the City and Municipality of Myślenice: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined the Mayor of the City and Municipality of Myślenice €1,790 for insufficient fulfilment of personal data breach notification obligations under Article… Poland · ·Art. 33 Apr 30, 2026
€2,500 BLUE PROJECTS INDUSTRIES S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined BLUE PROJECTS INDUSTRIES S.R.L. €2,500 on 2026-04-30 for: Insufficient technical and… Romania · ·Art. 32 Apr 30, 2026
€100,000 Lepida S.c.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Lepida S.c.p.A. €100,000 for violating general data processing principles under the GDPR. The enforcement action addressed… Italy · ·Art. 5, 13, 25 +1 Apr 29, 2026
€8,600 Matera Local Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the Matera Local Health Authority €8,600 for failing to implement sufficient technical and organizational measures to ensure… Italy · ·Art. 5, 32 Apr 29, 2026
€15,000 Nouva Corrente S.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Nouva Corrente S.r.l. €15,000 for non-compliance with general data processing principles under the GDPR. The enforcement… Italy · ·Art. 1, 2, 5 +3 Apr 29, 2026
€12,000 Ministry of Justice: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Ministry of Justice €12,000 for insufficient legal basis for personal data processing. The enforcement action, decided on… Italy · ·Art. 5, 6, 9 Apr 29, 2026
€34,000 Pianeta S.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Pianeta S.r.l. €34,000 for violations of multiple GDPR provisions, including Article 5(1)(a) and (b) on general data… Italy · ·Art. 5, 6, 12 +5 Apr 29, 2026
€4,000 Montelibretti State Comprehensive School: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Montelibretti State Comprehensive School €4,000 for lacking a sufficient legal basis for its data processing activities. The… Italy · ·Art. 5, 6, 9 Apr 29, 2026
€1,000 Non-Profit Foundation: Insufficient cooperation with supervisory authority Belgian Data Protection Authority (APD) fined Non-Profit Foundation €1,000 on 2026-04-28 for: Insufficient cooperation with supervisory authority. Belgium · ·Art. 31 Apr 28, 2026
€35,000 Crowd Entertainment Ltd: Insufficient legal basis for data processing Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Crowd Entertainment Ltd €35,000 on 2026-04-28 for: Insufficient legal basis for data… Romania · ·Art. 5 Apr 28, 2026
€6,000 GATIGOS, S.L.: Insufficient cooperation with supervisory authority Spanish Data Protection Authority (aepd) fined GATIGOS, S.L. €6,000 on 2026-04-28 for: Insufficient cooperation with supervisory authority. Spain · ·Art. 58 Apr 28, 2026
€1,800 RESIDENCIAL ETXE-LAN, S.L.: Insufficient cooperation with supervisory authority Spanish Data Protection Authority (aepd) fined RESIDENCIAL ETXE-LAN, S.L. €1,800 on 2026-04-28 for: Insufficient cooperation with supervisory authority. Spain · ·Art. 58 Apr 28, 2026
OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only… No. 2.1-1/24/397-890-38 ·Estonia · Apr 16, 2026
€6,600 Utility Company: Insufficient legal basis for data processing Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Utility Company €6,600 on 2026-04-15 for: Insufficient legal basis for data processing. Slovenia · ·Art. 5 Apr 15, 2026
€400,000 CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined Caixabank, S.A. €400,000 for failing to implement sufficient technical and organizational measures to ensure information… Spain · ·Art. 5, 25 Apr 15, 2026
€2,415 UODO reprimands electricity seller for Art. 5, 24, 25, 28, 32 GDPR violations over An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone… Poland ·Art. 5, 24, 25 +2 Apr 13, 2026
€2,500 BLUE PROJECTS S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined BLUE PROJECTS S.R.L. €2,500 on 2026-04-03 for: Insufficient technical and organisational… Romania · ·Art. 32 Apr 3, 2026
€100M Ridetech International B.V.: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) fined Ridetech International B.V. €100,000,000 on 2026-04-01 for: Insufficient legal basis for data processing. The Netherlands · ·Art. 5, 44, 46 Apr 1, 2026
€13,491 Legal Person: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Legal Person €13,491 on 2026-03-27 for: Insufficient technical and organisational measures to ensure information… Slovenia · ·Art. 32 Mar 27, 2026
€125,000 RENAULT COMMERCIAL ROUMANIE S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined RENAULT COMMERCIAL ROUMANIE S.R.L. €125,000 on 2026-03-25 for: Insufficient technical and… Romania · ·Art. 28, 32 Mar 25, 2026
€4,000 ING Bank NV Amsterdam – Sucursala București S.A.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined ING Bank NV Amsterdam – Sucursala București S.A. €4,000 on 2026-03-23 for: Insufficient… Romania · ·Art. 32 Mar 23, 2026
The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025 They worked as a manager in the controller’s finance department, with technical and disciplinary responsibility for up to five employees. The controller operated a 360-degree… 2025-0.960.016 ·Austria · Mar 20, 2026