Skip to content
Content type · 3,808 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

151–200 of 3,808 sort newestlargest fineoldest
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland ·DPC ·Art. 5, 28, 30 +2 Integrity and Confidentiality Principle Notification Obligation Data Breaches Jun 11, 2026
€15,300 Green Partner S.r.l.s.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Green Partner S.r.l.s. €15,300 for violations of multiple GDPR provisions, including Articles 5, 6, 7, 12, 15–22, and 28,… Italy ·Garante ·Art. 5, 6, 7 +3 Controllers Processors Supervision Jun 11, 2026
€4,500 Lecce Local Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the Lecce Local Health Authority €4,500 for failing to implement adequate technical and organizational measures to ensure… Italy ·Garante ·Art. 5, 29, 32 Security Supervision Supervisory Authorities Jun 11, 2026
UODO reprimands hospital for inadequate processor oversight and email security failures The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Poland ·Art. 5, 24, 25 +3 Controllers Processors Security Jun 11, 2026
€1,000 Pietro d'Abano State Vocational School: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Pietro d'Abano State Vocational School €1,000 for processing personal data without a sufficient legal basis, finding… Italy ·Garante ·Art. 5, 6 Personal Data Processing Public Authority Jun 11, 2026
Belgian DPA rejects delisting request for US government URL showing criminal conviction The data subject requested from a search engine (controller) the removal of a URL that appears when the data subject’s name is entered into the search engine. The URL points to… DOS-2025-04652 ·Belgium ·APD/GBA Supervisory Authorities Right to be Forgotten Criminal Data Jun 8, 2026
€5,000 Municipality of Vasto: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined the Municipality of Vasto €5,000 for failing to adequately fulfill its information obligations under the GDPR. The authority… Italy ·Garante ·Art. 5, 12, 13 +1 Accountability Personal Data DPIA Jun 8, 2026
€100,000 ZeniΘ (Thessaloniki-Thessalia Gas Supply Company S.A.): Insufficient fulfilment of data subjects rights The Hellenic Data Protection Authority (HDPA) fined ZeniΘ (Thessaloniki-Thessalia Gas Supply Company S.A.) €100,000 for insufficient fulfillment of data subjects' rights,… Greece ·HDPA ·Art. 5, 12, 15 +1 Processors Supervisory Authorities Controllers Jun 5, 2026
€10,000 Piraeus Bank S.A.: Insufficient fulfilment of data subjects rights The Hellenic Data Protection Authority (HDPA) fined Piraeus Bank S.A. €10,000 for insufficient fulfillment of data subjects' access rights under Article 15 of the GDPR. The… Greece ·HDPA ·Art. 15 Personal Data Supervision Supervisory Authorities Jun 5, 2026
€1,153 Reda Naujokaitienė: Insufficient legal basis for data processing The Lithuanian Data Protection Authority (VDAI) fined Reda Naujokaitienė €1,153 on June 5, 2026, for insufficient legal basis for personal data processing in the health care… Lithuania ·VDAI ·Art. 5, 6, 9 Personal Data Types of Special Categories of Personal Data Supervisory Authorities Jun 5, 2026
€880,000 Greek HDPA sanctions DEI for unsolicited promotional calls via processors The Greek DPA (HDPA) received twelve complaints filed against DEI, the Greek Public Power Corporation, (the controller) from telephone subscribers (data subjects) regarding the… Greece ·Art. 5, 28, 29 +1 Jun 2, 2026
€45,000 MEDIATEL Telephone Information Services S.A.: Insufficient technical and organisational measures to ensure information security The Hellenic Data Protection Authority (HDPA) fined MEDIATEL Telephone Information Services S.A. €45,000 for failing to implement sufficient technical and organizational measures… Greece ·HDPA ·Art. 32 Security Supervisory Authorities Jun 2, 2026
€80,000 PRELUDE GROUP E.E.: Insufficient technical and organisational measures to ensure information security The Hellenic Data Protection Authority (HDPA) fined PRELUDE GROUP E.E. €80,000 for failing to implement sufficient technical and organizational measures to ensure information… Greece ·HDPA ·Art. 28, 29, 32 Security Processors Controllers Jun 2, 2026
€90,000 Ypiresia 800 Teleperformance Single Member S.A.: Insufficient technical and organisational measures to ensure information security The Hellenic Data Protection Authority fined Ypiresia 800 Teleperformance Single Member S.A. €90,000 for failing to implement sufficient technical and organizational measures to… Greece ·HDPA ·Art. 5, 32 Security Supervisory Authorities Jun 2, 2026
€23,540 Minister of Justice: Insufficient technical and organisational measures to ensure information security Polish National Personal Data Protection Office (UODO) fined Minister of Justice €23,540 on 2026-06-02 for: Insufficient technical and organisational measures to ensure… Poland ·UODO ·Art. 32 Security Personal Data Education Jun 2, 2026
€20,000 CQS S.A. Customer-Centric Services: Insufficient technical and organisational measures to ensure information security The Hellenic Data Protection Authority (HDPA) fined CQS S.A. Customer-Centric Services €20,000 for failing to implement sufficient technical and organizational measures to ensure… Greece ·HDPA ·Art. 32 Security Supervisory Authorities Jun 2, 2026
€320,000 Public Power Corporation S.A. (DEI): Insufficient legal basis for data processing The Hellenic Data Protection Authority (HDPA) fined Public Power Corporation S.A. (DEI) €320,000 for lacking a sufficient legal basis for data processing. The decision addresses… Greece ·HDPA ·Art. 5, 32 Retention Period Storage Limitation Supervisory Authorities Jun 2, 2026
UODO fines controller for refusing to cooperate and provide information in two data The DPA received two complaints against the same company (the controller) due to the unauthorised access to the data subjects’ personal data. The first complaint concerned… DKE.561.1.2026 ·Poland ·Art. 31, 58 Controllers Personal Data Supervisory Authorities Jun 1, 2026
€1.8M Elkjøp AS: Insufficient legal basis for data processing Norwegian Supervisory Authority (Datatilsynet) fined Elkjøp AS €1,820,000 on 2026-06-01 for: Insufficient legal basis for data processing. Norway ·Datatilsynet (NO) ·Art. 5, 6, 12 Supervision Supervisory Authorities Processing Jun 1, 2026
€70,300 Blikk Kft.: Insufficient legal basis for data processing Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined Blikk Kft. €70,300 on 2026-05-29 for: Insufficient legal basis for data processing. Hungary ·NAIH ·Art. 6, 9, 12 Processing Telecommunications May 29, 2026
€70,518 IndaNext Hungary Kft. (legal successor of Blikk Kft.): Insufficient legal basis for data processing The Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined IndaNext Hungary Kft., as legal successor to Blikk Kft., €70,518 for publishing… NAIH ·Art. 6, 9, 12 ·Insufficient legal basis for data processing Legitimate Interest Personal Data Controllers May 29, 2026
€12,000 Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Unicredit Bank SA €12,000 on 2026-05-29 for: Insufficient technical and organisational… Romania ·ANSPDCP ·Art. 32, 33 Security Supervisory Authorities Supervision May 29, 2026
Binding Decision 1/2026 On 10 August 2021, a data subject represented by noyb lodged a complaint with the Austrian DPA against Vlaamse Radio- en Televisieomroeporganisatie (VRT), the controller. The… Binding Decision 1/2026 ·European Union ·EDPB Supervision Supervisory Authorities Controllers May 28, 2026
€700 Italian Red Cross: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Italian Red Cross €700 for violating general data processing principles under GDPR Articles 5(1)(c), 5(1)(f), and 9. The… Italy ·Garante ·Art. 5, 9 Integrity and Confidentiality Principle Retention Period Professional Secrecy May 28, 2026
€1,400 Ristorante Carlo Menta s.r.l.: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined Ristorante Carlo Menta s.r.l. €1,400 for failing to adequately fulfill its information obligations under the GDPR. The… Italy ·Garante ·Art. 5, 13 Personal Data Transparency Supervisory Authorities May 28, 2026
€6,000 Municipality of Sciacca: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of Sciacca €6,000 for processing personal data without a sufficient legal basis. The Garante found that the… Italy ·Garante ·Art. 5, 6 Personal Data Public Authority Supervisory Authorities May 28, 2026
€3,000 Autonomous Region of Sardinia: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Autonomous Region of Sardinia €3,000 on May 28, 2026, for processing personal data without a sufficient legal basis. The… Italy ·Garante ·Art. 5, 6 Personal Data Public Authority Supervisory Authorities May 28, 2026
€6,000 Liguria Health Protection Authority: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Liguria Health Protection Authority €6,000 for lacking a sufficient legal basis for personal data processing in the… Italy ·Garante ·Art. 5, 6, 25 +2 Controllers Retention Period Processing May 28, 2026
€55,000 The data controller for the case is a government body called the Agency for Digital Italy (AgID) AgID is tasked with driving the adoption of digital technologies in both government and the private sector. Additionally, AgID is Italy’s soon-to-be notification authority for the… 419/2026 ·Garante ·Art. 5, 12, 14 +1 Personal Data Controllers Processing May 28, 2026
€6,000 A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller) The data subject was employed by the Ligurian Social and Health Care Agency, however, the organisation was later merged with the controller. According to the data subject, the… 382/2026 ·Italy ·Garante Privacy by Design Privacy by Design & Default DPIA May 28, 2026
€700 Rosetta Trastervere s.r.l.s.: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined Rosetta Trastervere s.r.l.s. €700 for failing to adequately fulfill its information obligations under the GDPR. The authority… Italy ·Garante ·Art. 5, 13 Supervisory Authorities May 28, 2026
€700 Garante · 385/2026 A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy ·Art. 5, 9 Personal Data Retention Period Integrity and Confidentiality Principle May 28, 2026
€3,930 Action Fit di Milano: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Action Fit di Milano €3,930 for violations of Articles 6(1)(a), 12, and 21(2) GDPR, relating to non-compliance with general… Italy ·Garante ·Art. 6, 12, 21 Right to Object Supervision Personal Data May 28, 2026
€140,500 Mediaworks Hungary Zrt.: Insufficient legal basis for data processing Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined Mediaworks Hungary Zrt. €140,500 on 2026-05-26 for: Insufficient legal basis for data… NAIH ·Art. 6, 9 ·Insufficient legal basis for data processing Processing Telecommunications May 26, 2026
€5M IQVIA OPERATIONS FRANCE: Non-compliance with general data processing principles French Data Protection Authority (CNIL) fined IQVIA OPERATIONS FRANCE €5,000,000 on 2026-05-26 for: Non-compliance with general data processing principles. CNIL ·Art. 14, 25 ·Non-compliance with general data processing principles Supervisory Authorities IP Address Healthcare May 26, 2026
€140,127 Mediaworks Hungary Zrt.: Insufficient legal basis for data processing The Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined Mediaworks Hungary Zrt. €140,127 for processing and publishing personal data… NAIH ·Art. 6, 9 ·Insufficient legal basis for data processing Personal Data Processing May 26, 2026
€2,951 Land-surveying office: Insufficient technical and organisational measures to ensure information security The Polish National Personal Data Protection Office (UODO) fined a land-surveying office €2,951 for failing to implement sufficient technical and organizational measures to ensure… Poland ·UODO ·Art. 28, 32 Security Controllers Processors May 25, 2026
PLN 21,000 DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Poland ·UODO ·Art. 24, 25, 28 +1 Integrity and Confidentiality Principle Security Controllers May 25, 2026
€4,958 District Governor of Lubartów: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) fined the District Governor of Lubartów €4,958 for failing to implement adequate technical and organizational measures to ensure information security, citing… Poland ·UODO ·Art. 5, 25, 28 +1 Privacy by Design Processors Controllers May 25, 2026
PLN 26,711 DKE.561.4.2026 The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance extending… Poland ·UODO ·Art. 5 Accountability Monitoring Right to be Forgotten May 22, 2026
€6,292 Private individual: Insufficient cooperation with supervisory authority The Polish National Personal Data Protection Office (UODO) fined a private individual €6,292 for failing to adequately cooperate with the supervisory authority during an… Poland ·UODO ·Art. 58, 83 Supervision Supervisory Authorities Personal Data May 22, 2026
GBP 300 ICO (UK) - KRA Consultancy Ltd The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related services.… United Kingdom Personal Data Consent Processing May 20, 2026
€1,400 Elektronikus Egészségügyi Szolgáltatási Tér: Insufficient technical and organisational measures to ensure information security Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined Elektronikus Egészségügyi Szolgáltatási Tér €1,400 on 2026-05-20 for: Insufficient… Hungary ·NAIH ·Art. 5, 6, 9 Healthcare Security May 20, 2026
PLN 33,700 DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Poland ·UODO ·Art. 5, 24, 25 +3 Data Breaches Integrity and Confidentiality Principle Notification Obligation May 19, 2026
UODO reprimands mayor for disclosing data subject's data to company without legal basis The data subject requested the mayor of their place of residence (the controller) to provide them scans of contracts the city had concluded with certain companies and invoices… DS.523.2582.2024 ·Poland ·Art. 5, 6 Personal Data Integrity and Confidentiality Principle Right to Restriction May 18, 2026
€15,000 Monaldi-Cotugno-CTO: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Monaldi-Cotugno-CTO hospital entity €15,000 for violating general data processing principles under the GDPR. The… Italy ·Garante ·Art. 5, 9, 13 +2 Healthcare Types of Special Categories of Personal Data Security May 14, 2026
€1,800 Municipality of Mirabella Imbaccari: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of Mirabella Imbaccari €1,800 for processing personal data without a sufficient legal basis, in violation of… Italy ·Garante ·Art. 5, 6, 37 Public Authority Supervisory Authorities Supervision May 14, 2026
€100,000 Energia Sostenibile S.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Energia Sostenibile S.r.l. €100,000 for violations of multiple GDPR provisions, including Articles 5, 6, 7, 12, 13, 15, 24,… Italy ·Garante ·Art. 5, 6, 7 +5 Controllers Processors Supervision May 14, 2026
€43,000 Lidl Italia S.r.l.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) fined Lidl Italia S.r.l. €43,000 for insufficient fulfillment of data subjects' rights under Articles 5, 12, 15, and 18 of the… Italy ·Garante ·Art. 5, 12, 15 +1 Supervisory Authorities Transparency May 14, 2026
€180,000 Emirates: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined Emirates €180,000 for insufficient fulfillment of its information obligations under the GDPR. The authority found that the… Italy ·Garante ·Art. 5, 12, 13 Personal Data Supervisory Authorities May 14, 2026