Skip to content
Content type · 621 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

101–150 of 621 sort newestlargest fineoldest
€12,000 Casa di Cura Città di Roma: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 12.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9, 25 +1 Security Health Data Healthcare Sep 11, 2025
€6,000 Municipality of Buccino: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Municipality of Buccino. The controller published pictures of minors and people with mental health conditions in multiple… ITALY ·Garante ·Art. 5, 6, 9 +2 Public Authority Controllers Supervisory Authorities Sep 11, 2025
€42,000 WORLD 2 MEET, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 42,000 on WORLD 2 MEET, S.L. The controller requires its guests to provide a copy of their identity card or passport for registration… SPAIN ·AEPD ·Art. 5 Controllers Processing IP Address Aug 14, 2025
€1,000 Order of Biochemists, Biologists and Chemists in the Romanian Health System: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on the Order of Biochemists, Biologists and Chemists in the Romanian Health System. The controller failed to adequatly respond to… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Aug 5, 2025
€1,000 Order of Biochemists, Biologists and Chemists in the Romanian Healthcare System: Insufficient Compliance with Data Subjects' Rights. ⇄ 1.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Processing Supervision Aug 5, 2025
€80,000 Careggi University Hospital: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9, 25 +1 Security Health Data Healthcare Aug 4, 2025
€7,700 Not a healthcare institution: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van €7.700 - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 32 Security Controllers Healthcare Aug 4, 2025
€7,700 Non-Public Health Care Institution: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 7,700 on a non-public health care institution. The controller offered home visits by doctors as part of its services. For this purpose,… POLAND ·UODO ·Art. 5, 25, 32 Controllers Security Personal Data Aug 4, 2025
€80,000 Ospedaliero-Universitaria Careggi: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 80,000 on the Ospedaliero-Universitaria Careggi. The controller, a university hospital, used software that allowed medical personnel to… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Controllers Security Aug 4, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Non-compliance with the general principles for data processing. ⇄ Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor gegevensbescherming (Garante). ITALY ·Garante ·Art. 5 Controllers Processing Health Data Aug 4, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2,000 on Linea Stampalibera Società Cooperativa r.I. The controller, who operates a news site, has disclosed too much personal… ITALY ·Garante ·Art. 5 Retention Period Controllers Processing Aug 4, 2025
€2,200 Legal Entity: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 2,200 on a legal entity. An employee of the company forwarded health data to a lawyer without sufficient grounds. The company was fined… SLOVENIA ·IP-RS ·Art. 6, 9 Healthcare Types of Special Categories of Personal Data Processing Jul 22, 2025
€4M McDonald’s Polska Sp. z o.o.: Non-compliance with general principles for data processing. ⇄ Een boete van 3.955.000 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 28 +1 Controllers Security Processing Jul 21, 2025
€5,400 SUNERIS, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5,400 on SUNERIS, S.A. The controller processed scans of ID cards and passports of their guests, infringing the principle of data… SPAIN ·AEPD ·Art. 5 Retention Period Controllers Processing Jul 16, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on VALORA PREVENCIÓN, S.L.U. The controller, a company offering occupational health and safety services, failed to implement… SPAIN ·AEPD ·Art. 5, 32 Security Controllers Personal Data Jul 11, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 32.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 32 Security Controllers Personal Data Jul 11, 2025
€50,000 Magna PT S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine on Magna PT S.p.A. Employees of the controllers were subjected to 'return to work interviews' after returning from an absence due to illness or… ITALY ·Garante ·Art. 5, 6, 9 +2 Retention Period Controllers Storage Limitation Jul 10, 2025
€50,000 Magna PT S.p.A.: Insufficient legal basis for the processing of data. ⇄ Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Retention Period Jul 10, 2025
€15,600 Children's Hospital of the L. Zamenhof University in Białystok: Insufficient technical and organizational measures to ensure information security. ⇄ 15.600 euro boete - Poolse nationale instantie voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 32 Security Controllers Accountability Jun 30, 2025
€15,600 L. Zamenhof University Children's Clinical Hospital in Białystok: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 15,600 on the L. Zamenhof University Children's Clinical Hospital in Białystok. The controller did not implement sufficient technical and… POLAND ·UODO ·Art. 5, 32 Security Controllers Personal Data Jun 30, 2025
€10,000 Shield of David - K.I.D.A.F.: Non-compliance with general principles of data processing. ⇄ Boete van €10.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 12, 13 +3 Personal Data Controllers Processing Jun 24, 2025
€10,000 Shield of David - K.I.D.A.F.: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Shield of David - K.I.D.A.F. The controller, a day care centre for people with autism, has legally installed video… GREECE ·HDPA ·Art. 5, 12, 13 +3 Controllers Personal Data Supervisory Authorities Jun 24, 2025
€7,000 General Hospital of the University of Larissa: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 7,000 on the General Hospital of the University of Larissa. The controller failed to adequately fulfil the rights of data subjects. It… GREECE ·HDPA ·Art. 5, 14, 15 Personal Data Controllers Supervisory Authorities Jun 24, 2025
€7,000 General Hospital of the University of Larissa: Inadequate compliance with data subjects' rights. ⇄ Een boete van €7.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 14, 15 Supervisory Authorities Controllers Personal Data Jun 24, 2025
€2.7M 23andMe, Inc.: Insufficient technical and organisational measures to ensure information security The UK DPA imposed a fine of £ 2,310,000 (EUR 2,700,000) on 23andMe, Inc. The controller, a company offering DNA testing to private individuals, failed to implement sufficient… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers Data Breaches Jun 5, 2025
€2.7M 23andMe, Inc.: Inadequate technical and organisational measures to ensure information security. ⇄ Een boete van 2.700.000 euro - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers Accountability Jun 5, 2025
€1.1M University Pharmacy: Non-compliance with general principles of data processing. ⇄ 1.100.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 32 Controllers Processing Health Data May 27, 2025
€1.1M Yliopiston Apteekin: Non-compliance with general data processing principles The Finish DPA has imposed a fine of EUR 1,100,000 on Yliopiston Apteekin. The controller, who runs an online pharmacy, used various web analytics and monitoring tools. These… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 32 Retention Period Controllers Personal Data May 27, 2025
€7,000 Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 7,000 on Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North. The controller… ITALY ·Garante ·Art. 5, 9 Healthcare Controllers Personal Data May 21, 2025
€21,000 Menarini Silicon Biosystems SpA: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 21,000 on Menarini Silicon Biosystems SpA. The controller is conducting oncological research and has developed a software that is able to… ITALY ·Garante ·Art. 5, 13 Retention Period Storage Limitation Accountability May 21, 2025
€21,000 Menarini Silicon Biosystems SpA: Non-compliance with the general principles for data processing. ⇄ 21.000 euro boete - Italiaanse Autoriteit voor de bescherming van persoonlijke gegevens (Garante). ITALY ·Garante ·Art. 5, 13 Controllers Processing Personal Data May 21, 2025
€5,000 Maravet S.R.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data May 19, 2025
€5,000 Maravet S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Maravet S.R.L. The controller did not implement sufficient technical and organisational measures to ensure information… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 19, 2025
€6,600 Owner of a Pharmacy Office: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the owner of a pharmacy office. The controller processed data of residents of two geriatric centers without a sufficient legal basis. The… SPAIN ·AEPD ·Art. 6, 14, 32 Controllers Encryption Personal Data May 9, 2025
€6,600 Owner of a pharmacy: Non-compliance with general principles for data processing. ⇄ Boete van 6.600 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6, 14, 32 Health Data Controllers Processing May 9, 2025
€6,600 Owner of a Pharmacy Office: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the owner of a pharmacy office. The controller processed data of residents of geriatric centers without a sufficient legal basis. The… SPAIN ·AEPD ·Art. 6, 14, 32 Controllers Encryption Personal Data May 8, 2025
€6,600 Owner of a Pharmacy: Violation of the General Principles of Data Processing. ⇄ Een boete van 6.600 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6, 14, 32 Health Data Controllers Processing May 8, 2025
€40,000 Municipality of Bologna: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 40,000 on the Municipality of Bologna. The controller used a data processor (Cooperativa Sociale Quadrifoglio | ETid: 2274) to process… ITALY ·Garante ·Art. 5, 6, 9 Controllers Security Healthcare Apr 29, 2025
€2,000 Tirrenia Hospital S.r.l.: Insufficient compliance with data subjects' rights. ⇄ Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 12, 15 Personal Data Right of Access Controllers Apr 29, 2025
€20,000 Cooperativa Sociale Quadrifoglio: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio. The entity that was fined, acting as a data processor, forwarded files containing the… ITALY ·Garante ·Art. 28, 32 Processors Controllers Security Apr 29, 2025
€2,000 Tirrenia Hospital S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 2,000 on Tirrenia Hospital S.r.l. The controller failed to respond to a data access request from a data subject. ITALY ·Garante ·Art. 12, 15 Right of Access Personal Data Controllers Apr 29, 2025
€40,000 Municipality of Bologna: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 40.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 Security Controllers Health Data Apr 29, 2025
€20,000 Cooperativa Sociale Quadrifoglio: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 20.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 28, 32 Security Processors Controllers Apr 29, 2025
€1,500 ULPIA TRAJANA ALAMEDA S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on ULPIA TRAJANA ALAMEDA S.L. During the booking process, the controller processed data that was unnecessary for the purpose, infringing on the… SPAIN ·AEPD ·Art. 5, 9 Retention Period Controllers Types of Special Categories of Personal Data Apr 24, 2025
€7,800 Funeral company: insufficient technical and organisational measures to ensure information security. ⇄ Een boete van €7.800 - van het Poolse Nationaal Bureau voor de Bescherming van Persoonlijke Gegevens (UODO). POLAND ·UODO ·Art. 5 Security Controllers Processing Apr 15, 2025
€7,800 Funeral Home: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined a funeral home EUR 7,800. The funeral home failed to implement sufficient technical and organisational measures to prevent a data breach. The funeral home… POLAND ·UODO ·Art. 5 Security Controllers Personal Data Apr 15, 2025
€2,000 United Business Solutions SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on United Business Solutions SRL. The controller failed to implement sufficient technical and organisational measuresto ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Apr 15, 2025
€5,000 Gynecologist: Insufficient compliance with the information obligation. ⇄ Een boete van €5.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 15 Supervisory Authorities Personal Data Right of Access Apr 9, 2025