Skip to content
Content type · 2,798 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

101–150 of 2,798 sort newestlargest fineoldest
€1,300 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 1,300 on a legal entity. An employee of the controller stored personal data on her work laptop without securing it, for example by… SLOVENIA ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Controllers Dec 4, 2025
€3,600 DELAFRUIT, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,600 on DELAFRUIT, S.L. The controller installed video surveillance in the staff break area and dining room, but did not put up the… SPAIN ·aepd ·Art. 5 Video Surveillance Controllers IP Address Dec 1, 2025
€3,600 RISING SUN CAR RENTAL S..L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,600 on RISING SUN CAR RENTAL S..L. The controller used video surveillance to ensure security at its facility, affecting more areas than… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Controllers IP Address Dec 1, 2025
€3,600 DELAFRUIT, S.L.: Niet-naleving van de algemene principes voor gegevensverwerking. Boete van €3.600 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Video Surveillance Controllers Processing NL Dec 1, 2025
€3,600 RISING SUN CAR RENTAL S.L.: Niet-naleving van de algemene principes voor gegevensverwerking. De Spaanse autoriteit voor gegevensbescherming (DPA) heeft RISING SUN CAR RENTAL S.L. een boete van 3.600 euro opgelegd. De verantwoordelijke partij gebruikte videobewaking om de… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Processing Data Controller NL Dec 1, 2025
€1.6M SPRINTER MEGACENTROS DEL DEPORTE, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,560,000 on SPRINTER MEGACENTROS DEL DEPORTE, S.L. The controller suffered a cyber attack due to insufficient technical and… SPAIN ·aepd ·Art. 5, 34 Security Controllers Processing Agreement Nov 28, 2025
€1.6M SPRINTER MEGACENTROS DEL DEPORTE, S.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 1.560.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 34 Security Data Breaches Controllers NL Nov 28, 2025
€2,000 Nițu A. Cleopatra – Expert Accountant: Insufficient technical and organisational measures to ensure information security Thr Romanian DPA has imposed a fine of EUR 2,000 on Nițu A. Cleopatra – Expert Accountant. The controller was the target of a successful cyber attack due to the inadequate… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing Agreement Nov 27, 2025
€2,000 Nițu A. Cleopatra – Expert Accountant: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data NL Nov 27, 2025
€40,000 Infobel: Onvoldoende juridische basis voor gegevensverwerking. Een boete van 40.000 euro - De Belgische Autoriteit voor gegevensbescherming (APD). BELGIUM ·APD ·Art. 5, 6, 24 Data Controller Processing Controllers NL Nov 27, 2025
€40,000 Infobel: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 40,000 on Infobel. The controller, a data broker, sold personal data for direct marketing purposes. However, it processed the data it had… BELGIUM ·APD ·Art. 5, 6, 24 Controllers Marketing Personal Data Nov 27, 2025
€300,000 Aimag S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 300,000 on Aimag S.p.A. The controller offered its customers a service that allowed them to view their consumption data on the… ITALY ·Garante ·Art. 5, 6, 7 +4 IP Address Processing Agreement Direct Marketing Nov 27, 2025
€300,000 Aimag S.p.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 300.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +4 Processing Controllers Data Controller NL Nov 27, 2025
€400,000 Verisure Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 400,000 on Verisure Italy s.r.l. The controller had been active in direkt marketing activities. The controller failed to ensure that the… Garante ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles IP Address Controllers Storage Limitation Nov 27, 2025
€1.5M AMERICAN EXPRESS CARTE FRANCE: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 1,500,000 on AMERICAN EXPRESS CARTE FRANCE. The controller used excessive cookies on its website and failed to adequately inform data… CNIL ·Art. 82 ·Insufficient legal basis for data processing Cookies Insurance Controllers Nov 27, 2025
€6,600 Legal Entity: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 6,600 on a legal entity. The controller used GPS trackers to systematically and indiscriminately monitor its employees' activities… SLOVENIA ·Art. 5, 6 ·Insufficient legal basis for data processing Employees Controllers Processing Agreement Nov 26, 2025
€3,000 Cucina di Fabio S.R.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 15, 17 +1 Marketing Personal Data Processing NL Nov 26, 2025
€3,000 Cucina di Fabio S.R.L.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 3,000 on Cucina di Fabio S.R.L. The controller was active in direct marketing activities, using personal data that had not been obtained… ROMANIA ·ANSPDCP ·Art. 6, 15, 17 +1 Direct Marketing Controllers Personal Data Nov 26, 2025
€4.5M Telecommunicatiebedrijf (exploitant van elektronische communicatienetwerken en -diensten): Overtreding van de algemene principes van gegevensverwerking. Een boete van 4.500.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·azop ·Art. 5, 6, 12 +4 Processors Data Processor Controllers NL Nov 24, 2025
DSB Austria: Online shop violated GDPR by ignoring request to stop gender-specific On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Art. 5, 6, 16 +2 Privacy by Design Privacy by Default Privacy by Design & Default Nov 24, 2025
€4.5M Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer… CROATIA ·azop ·Art. 5, 6, 12 +4 Employees Processing Agreement Controllers Nov 24, 2025
€5,000 ACTIVOS INTELIGENTES, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5,000 on ACTIVOS INTELIGENTES, S.L. The controller is asking its guests for selfies with their ID-card to verify their identity,… SPAIN ·aepd ·Art. 5 IP Address Controllers Processing Nov 23, 2025
€5,000 ACTIVOS INTELIGENTES, S.L.: Overtreding van de algemene principes voor gegevensverwerking. Boete van €5.000 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Processing IP Address Accountability NL Nov 23, 2025
€1.2M IDCQ HOSPITALES Y SANIDAD, S.L.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,200,000 on IDCQ HOSPITALES Y SANIDAD, S.L.U. The controller offered MRI scans as part of its services, and patients could bring copies… SPAIN ·aepd ·Art. 6, 9, 25 Healthcare IP Address Healthcare Nov 21, 2025
€16,650 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 16,650 on a legal entity. The controller stored personal data on a publicly accessible web server without taking sufficient technical… SLOVENIA ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Nov 21, 2025
€1.4M LastPass UK Ltd: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 1,228,283 (EUR 1,400,000) on LastPass UK Ltd. The controller suffered a succesfull cyber attack due to insufficient technical and organisational… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers Processing Agreement Nov 20, 2025
€1.4M LastPass UK Ltd: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 1.400.000 euro boete - Informatiecommissaris (ICO) UNITED KINGDOM ·ICO ·Art. 5, 32 Security Accountability Controllers NL Nov 20, 2025
€750,000 LES PUBLICATIONS CONDE NAST: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 750,000 on LES PUBLICATIONS CONDE NAST. The controller used multiple cookies on its website but failed to adequately implement them. FRANCE ·CNIL ·Art. 82 Cookies IP Address Controllers Nov 20, 2025
€800 SOBLADA RESTAURACIÓN, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 800 on SOBLADA RESTAURACIÓN, S.L. The controller installed video surveillance without providing the necessary information signs or… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Controllers Monitoring Nov 19, 2025
€800 SOBLADA RESTAURACIÓN, S.L.: Overtreding van de algemene principes voor gegevensverwerking. 800 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 13 Video Surveillance Processing Controllers NL Nov 19, 2025
€60,000 STRATESYS TECHNOLOGY SOLUTIONS, S.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 60.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Security Data Breaches Controllers NL Nov 19, 2025
€2,000 ASOCIACIÓN NACIONAL DE TASADORES Y PERITOS JUDICIALES INFORMÁTICOS: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 2,000 on the ASOCIACIÓN NACIONAL DE TASADORES Y PERITOS JUDICIALES INFORMÁTICOS. The controller published a court ruling which included… SPAIN ·aepd ·Art. 13, 17 Personal Data Controllers Supervisory Authorities Nov 19, 2025
€3,000 Greencorp S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Greencorp S.R.L. The controller failed to implement adequate technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Security Processing Agreement Controllers Nov 19, 2025
€60,000 STRATESYS TECHNOLOGY SOLUTIONS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 60,000 on STRATESYS TECHNOLOGY SOLUTIONS, S.L. The controller failed to implement adequate technical and organisational measures,… SPAIN ·aepd ·Art. 5 Data Breaches Security Controllers Nov 19, 2025
€80 Journalist: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 80 on a Journalist. The controller published unnecessary private data about a data subject on social media, including their address. AUSTRIA ·dsb ·Art. 5, 6 Personal Data Controllers Social Media Nov 18, 2025
€8,000 PGS SOFA & CO SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 8.000 euro boete - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing NL Nov 17, 2025
€8,000 PGS SOFA & CO SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PGS SOFA & CO SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures. ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing Agreement Nov 17, 2025
€4,750 Powiatowego Inspektora Sanitarnego w Policach: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 4750 on the Powiatowego Inspektora Sanitarnego w Policach. The controller failed to implement adequate technical and organisational… POLAND ·UODO ·Art. 5, 24, 25 +1 Encryption Data Breaches Security Nov 15, 2025
€2,400 AXARQUIA VELEZ DENTAL, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,400 on AXARQUIA VELEZ DENTAL, S.L. The controller used video surveillance to ensure security at its facility, affecting more areas than… SPAIN ·aepd ·Art. 5 Video Surveillance Healthcare IP Address Nov 14, 2025
€2,400 AXARQUIA VELEZ DENTAL, S.L.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.400 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Health Data Video Surveillance Processing NL Nov 14, 2025
€6,000 Gemeente Orte: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 6.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +2 Video Surveillance Processing Education NL Nov 13, 2025
€6,000 Comune di Orte: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 6,000 on the Comuni di Orte. The controller implemented video surveillance on its territory in a manner that did not comply with the… ITALY ·Garante ·Art. 5, 6, 12 +2 Video Surveillance IP Address Monitoring Nov 13, 2025
€40,000 Quarantadue S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 40,000 on Quarantadue S.r.l. The controller produced a television series about a criminal case which included real audio recordings that… ITALY ·Garante ·Art. 5 IP Address Controllers Processing Nov 13, 2025
€4,000 Fan Courier Express S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 4.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +2 Personal Data Data Controller Controllers NL Nov 12, 2025
€4,000 Fan Courier Express S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 4,000 on Fan Courier Express S.R.L. The controller failed to adequately react to a data subject's request to exercise their rights, and… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +2 Personal Data Controllers Processing Nov 12, 2025
€2,000 Whitedecor SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on Whitedecor SRL. The controller had sent marketing messages to customers without a sufficient legal basis. ROMANIA ·ANSPDCP ·Art. 6, 7, 12 +3 Controllers Direct Marketing Processing Agreement Nov 10, 2025
€2,000 Whitedecor SRL: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 7, 12 +3 Processing Personal Data Data Controller NL Nov 10, 2025
€1,000 Bedrijf: Onvoldoende naleving van de rechten van betrokkenen (betreffende hun persoonsgegevens). Boete van €1.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 12, 15 Personal Data Right of Access Data Controller NL Nov 7, 2025
€1,000 Company: Insufficient fulfilment of data subjects rights The Greek DPA has imposed a fine of EUR 1,000 on a Company. The controller failed to react adequately to a data subject's request to exercise their rights. GREECE ·HDPA ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Nov 7, 2025
€7,000 Klass Wagen S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van €7.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing NL Nov 7, 2025