Skip to content
Content type · 219 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

151–200 of 219 sort newestlargest fineoldest
€1,000 Homeowners' Association: Failure to Comply with the Principle of Confidentiality ⇄ Boete van €1.000 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Processing Accountability Professional Secrecy May 19, 2025
€80,000 CALOGA: Non-compliance with general principles of data processing. ⇄ Een boete van 80.000 euro - van de Franse Autoriteit voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 5, 6 Controllers Processing Accountability May 15, 2025
€100,000 PLATAFORMA CABANILLAS SA.: Violation of the general principles for data processing. ⇄ Een boete van 100.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Processing Accountability IP Address May 13, 2025
€2,000 Romoffice Construct Holding Ag SRL: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6 Processing Personal Data Controllers May 13, 2025
€5,000 ROUMASPORT SRL: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6 Processing Personal Data Controllers May 9, 2025
€50,000 Lombardy Region: Insufficient legal basis for data processing. ⇄ Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 25 +3 Controllers Processing Processors Apr 29, 2025
€1,200 Municipality of San Francesco al Campo: Non-compliance with general principles of data processing. ⇄ 1.200 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5 Controllers Processing Accountability Apr 29, 2025
€30,000 Lombardy Order of Psychologists: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 30.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 32 Security Controllers Accountability Apr 29, 2025
€1,500 ULPIA TRAJANA ALAMEDA S.L.: Non-compliance with the general principles for data processing. ⇄ 1.500 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 9 Controllers Processing Personal Data Apr 24, 2025
€4,000 AEPD: Continuous workplace audio recording violates GDPR data minimisation principle On 22 April 2025, a data subject lodged a complaint with the DPA against BODENSE ESTRUCTURAS Y CALDELERÍA, S.L., the controller. The data subject claimed that the controller had… Spain ·Art. 5 Retention Period Monitoring IP Address Apr 22, 2025
€20,000 Company: Non-compliance with general principles for data processing. ⇄ Een boete van 20.000 euro - De Belgische Autoriteit voor gegevensbescherming (APD). BELGIUM ·APD/GBA ·Art. 5, 6, 12 +4 Processing Marketing Personal Data Apr 22, 2025
€600 SPAIN, DPA: Non-compliance with the general principles of data processing. ⇄ 600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). AEPD ·Art. 5 ·Non-compliance with general data processing principles Controllers Processing Accountability Apr 15, 2025
€3,000 EDA TV CONSULTING, S.L.: Infringement of the general principles for data processing. ⇄ Boete van 3.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Processing Accountability Apr 14, 2025
€70,300 DPP Law Ltd.: Insufficient technical and organizational measures to ensure information security. ⇄ Boete van €70.300 - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Security Accountability Notification Obligation Apr 14, 2025
€4,000 Municipality of Ponte nelle Alpi: Insufficient legal basis for data processing. ⇄ Een boete van 4.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Controllers Processing Accountability Apr 10, 2025
€5,000 Board for Support to Citizens and Agriculture: Insufficient legal basis for data processing. ⇄ Een boete van 5.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Retention Period Storage Limitation Personal Data Apr 10, 2025
€360 SINDICAT CATAC-CTSC: Insufficient cooperation with the supervisory authority. ⇄ Een boete van 360 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 58 Supervisory Authorities Controllers Supervision Apr 4, 2025
€600 Owner of a law firm: Insufficient technical and organizational measures to ensure information security. ⇄ 600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Apr 3, 2025
€5,000 Banca Transilvania S.A.: Insufficient legal basis for data processing. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6 Personal Data Processing Controllers Apr 3, 2025
€3,500 MAD COOL FESTIVAL S.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Boete van €3.500 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 32 Security Controllers Personal Data Mar 30, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Non-compliance with the general principles for data processing. ⇄ Een boete van 120.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Processing Personal Data Mar 28, 2025
€21,600 SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 21.600 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 7, 28 Processing Personal Data Retention Period Mar 28, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on SERVICIOS ESPECIALES, S.A. The case concerned a GDPR breach during an internal workplace conflict investigation: the company shared a report via… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Accountability Personal Data Mar 28, 2025
€40,000 Company: Insufficient legal basis for the processing of data. ⇄ Een boete van 40.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·AZOP ·Art. 5, 6, 12 +3 Processing Professional Secrecy Personal Data Mar 24, 2025
€3.5M CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 3.5 million on CAIXABANK, S.A. Following a complaint from customers, it was found that the mother of an account holder had access to a… SPAIN ·AEPD ·Art. 5, 25 Privacy by Design & Default Privacy by Default Privacy by Design Dec 12, 2024
€2.4M Vinted: Insufficient fulfilment of data subjects rights The Lithuanian DPA has imposed a fine of EUR 2,385,276 on the second-hand online store 'Vinted'. The DPA initiated an investigation after the Polish and French DPAs forwarded… LITHUANIA ·VDAI ·Art. 5, 12 Transparency Accountability Controllers Jul 2, 2024
€20,000 Pharmaceutical wholesaler: €20,000 fine The French DPA has imposed a fine of EUR 20,000 on a pharmaceutical wholesaler due to violations of several regulations, including a lack of data security and insufficient… FRANCE ·CNIL ·Unknown Controllers Accountability Processors Jan 24, 2024
€7,500 SLOVAKIA DPA: Non-compliance with general data processing principles The Slovak DPA has imposed a fine of EUR 7,500 on an unknown controller. The controller violated the principle of lawfulness, the principle of transparency and the principle of… Slovak Data Protection Office ·Non-compliance with general data processing principles Supervisory Authorities Accountability Controllers Jan 1, 2024
€5M CAIXABANK, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5 million on CAIXABANK, S.A.. A customer had filed a complaint about having access to a document containing information on a transfer… SPAIN ·AEPD ·Art. 5, 25, 32 Privacy by Design & Default Privacy by Default Privacy by Design Oct 26, 2023
€50,000 Athens Urban Transport Organization: Non-compliance with general data processing principles The Hellenic DPA imposed a fine of EUR 50,000 on the Athens Urban Transport Organization. As part of its investigation, the DPA found that the controller had failed to comply with… GREECE ·HDPA ·Art. 5, 25, 35 Privacy by Design & Default Privacy by Default Privacy by Design Sep 25, 2023
06/SIU/2018 The Irish DPC started an own volition inquiry into processing operations carried out by the Galway County Council (the controller), focusing mainly into the surveillance… 06/SIU/2018 ·Ireland ·DPC Monitoring DPIA Accountability Aug 22, 2023
€50,000 DPC (Ireland) reprimands Kildare County Council over surveillance tech and CCTV compliance This case involves an own-volition investigation conducted by the Irish DPA (DPC) into Kildare County Council, the controller. In June 2018, Officers from the Special… Art. 2, 5, 6 +5 Legitimate Interest Controllers Personal Data Jan 16, 2023
€75,000 Burwebs S.L.: Non-compliance with general data processing principles The Spanish DPA has fined Burwebs S.L. EUR 75,000. Burwebs operates websites with adult content. During its investigation, the DPA found that Burwebs did not process users' data… SPAIN ·AEPD ·Art. 5, 12, 13 +3 Accountability Personal Data Processing Nov 3, 2022
€1.4M Douglas Italia S.p.a.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1.4 million on Douglas Italia S.p.a. for various GDPR violations. In the course of its investigation, the DPA initially found that… ITALY ·Garante ·Art. 5, 6, 7 +4 Personal Data Accountability Consent Oct 20, 2022
Danish DPA reprimands Region Syddanmark for inadequate processor audit procedures The Danish DPA had decided to investigate three research projects of Region Syddanmark (the controller) with regards to its processing activities, the use of processors, data… 2020-422-0026 ·Denmark ·Datatilsynet (DK) Processors Controllers Supervisory Authorities
€15 Greek HDPA: Classroom video surveillance at school unlawful; oral notice insufficient A former teacher (the data subject) at a private primary school (the controller) submitted a complaint to the Greek DPA regarding a video surveillance system in the classrooms,… Greece ·Art. 5, 6, 12 +2 Legitimate Interest Personal Data Accountability Sep 9, 2022
Italy Garante: TikTok switch to legitimate interest for personalized ads violates Social media platform TikTok (the controller) provided personalized advertising to its users (the data subjects) on the legal basis of consent (Article 6(1)(a) GDPR). In June… 9788429 ·Art. 5, 6, 122 Legitimate Interest Direct Marketing Social Media Jul 7, 2022
€26,000 Italian DPA sanctions Municipality of Policoro for CCTV signage, retention and DPO The Municipality of Policoro (Basilicata), implemented the use of CCTV cameras to monitor and fight waste abandonment within its territory. A data subject complained the… Italy ·Garante ·Art. 5, 12, 13 +3 Public Authority Supervisory Authorities Storage Limitation Jun 9, 2022
€50 Belgian DPA: Roularta Media Group violated cookie consent rules On 16 January 2019, the Executive-committee of the Belgian DPA (GBA) started an investigation on the use of cookies on Belgian media websites. The controller in this case is… Belgium ·APD/GBA ·Art. 4, 5, 6 +3 Consent Supervisory Authorities Personal Data May 25, 2022
€1.3M Danske Bank: Non-compliance with general data processing principles The Danish DPA has imposed a fine of EUR 1.3 million on Danske Bank. The DPA had opened an investigation against the bank after it informed the DPA that it had a problem with the… DENMARK ·Datatilsynet (DK) ·Art. 5 Accountability Personal Data Processing Apr 5, 2022
€17M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 17 million on Meta Platforms Ireland Limited (former Facebook Ireland Limited). The decision is based on twelve notifications of data… DPC ·Art. 5, 24 Accountability Supervision Security Mar 15, 2022
EDPS: European Parliament is sole controller for COVID testing website and failed In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Controllers Processors IP Address Jan 5, 2022
€400,000 Régie autonome des transports parisiens: Non-compliance with general data processing principles The French DPA (CNIL) imposed a fine of EUR 400,000 on RATP (the operator of the public transport system in Paris). In May 2020, a trade union filed a complaint with the CNIL… FRANCE ·CNIL ·Art. 5, 32 Retention Period Accountability Security Nov 4, 2021
€225M WhatsApp Ireland Ltd.: Insufficient fulfilment of information obligations The Irish DPA (DPC) has imposed a fine of EUR 225,000,000 on WhatsApp Ireland Ltd. The DPA had started extensive investigations into the messaging service's compliance with… DPC ·Art. 5, 12, 13 +1 ·Insufficient fulfilment of information obligations Transparency Information Provision Modalities and Communication Methods Fairness & Transparency Sep 2, 2021
€4,000 Automecanica Jerez, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has fined Automecanica Jerez, S.L. EUR 4,000. The controller had sent commercial e-mails to a large number of people without their consent. In doing so, the… SPAIN ·AEPD ·Art. 5, 21, 32 Security Personal Data Controllers Sep 2, 2021
€5,000 NOW DOCTOR – Εταιρία Παροχής Ηλεκτρονικών Υπηρεσιών Αναζήτησης και Προβολής Ιατρών Ε.Π.Ε.: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 5,000 on the operator of the medical platform nowdoctor.gr that enables online booking of medical appointments. A doctor had filed a… GREECE ·HDPA ·Art. 5, 6, 12 +1 Personal Data Accountability Controllers Aug 26, 2021
€7,200 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 7,200 on a company. The company had installed a video surveillance system to protect the company's assets, prevent… CNPD (LU) ·Art. 5, 13, 32 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Storage Limitation Jun 11, 2021
€7,600 LUXEMBOURG DPA: Non-compliance with general data processing principles The DPA from Luxembourg (CNPD) has imposed a fine of EUR 7,600 on a company. This company had installed a video surveillance system for the purpose of protecting the company's… CNPD (LU) ·Art. 5, 13 ·Non-compliance with general data processing principles Supervisory Authorities Retention Period Accountability Jun 11, 2021
€15,000 PURPLE SEA MΟΝΟΠΡΟΣΩΠΗ ΙΚΕ: Non-compliance with general data processing principles The Hellenic DPA has fined PURPLE SEA MΟΝΟΠΡΟΣΩΠΗ ΙΚΕ EUR 15,000 due to the illegal installation and operation of a video surveillance system. The controller had installed a video… GREECE ·HDPA ·Art. 5 Accountability Controllers Transparency Jun 3, 2021