Skip to content
Content type · 1,013 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

151–200 of 1,013 sort newestlargest fineoldest
€40,000 Slovak Telekom: Insufficient technical and organisational measures to ensure information security The controller did not take adequate security measures when processing personal data, thereby breaching the obligation to protect the processed personal data. SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Security Controllers Personal Data
SLOVENIA: Insufficient technical and organizational measures to ensure information security. ⇄ Slovaakse Autoriteit voor Gegevensbescherming. SLOVAKIA ·Slovak Data Protection Office ·Art. 5, 32 Security Accountability Privacy by Design & Default Dec 30, 2025
SLOVAKIA: Insufficient technical and organisational measures to ensure information security. ⇄ Slovaakse Autoriteit voor de Bescherming van Persoonsgegevens. Slovak Data Protection Office ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Processing Dec 30, 2025
€12,000 Madrileña Red de Gas: Insufficient technical and organizational measures to ensure information security. ⇄ 12.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 32 Security Personal Data Privacy by Design & Default Dec 30, 2025
€980 Individual entrepreneur - no further details published: Insufficient technical and organisational measures to ensure information security The operator of an online game was exposed to several DDoS attacks which caused the malfunctioning of the servers. The attacker blackmailed the operator stating that the attacks… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 32 Security Personal Data Law Enforcement
€10,000 Roumasport S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on Roumasport S.R.L The controller failed to implement adequate technical and organisational measures, resulting in multiple… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Dec 30, 2025
€50,000 Social security institution: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 50.000 euro - van het Slowaakse databeschermingskantoor. SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Security Health Data Healthcare Dec 30, 2025
SLOVAKIA DPA: Insufficient technical and organisational measures to ensure information security Documents containing personal data were disposed of in the area of the municipal garbage dump. Slovak Data Protection Office ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Supervisory Authorities
€2,000 Order of General Nurses, Midwives and Medical Assistants of Romania – Neamt Branch: Non-compliance with the general principles of data processing. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Processing Supervisory Authorities Supervision Dec 29, 2025
€500,000 CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 500.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 25 Security Privacy by Design Privacy by Default Dec 22, 2025
€1.7M NEXPUBLICA FRANCE: Insufficient technical and organisational measures to ensure information security. ⇄ 1.700.000 euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Privacy by Design & Default Dec 22, 2025
€500,000 CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 500,000 on CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U. The controller used a communication tool that was not designed in… SPAIN ·AEPD ·Art. 25 Controllers Personal Data Security Dec 22, 2025
€1.7M NEXPUBLICA FRANCE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 1,700,000 on NEXPUBLICA FRANCE. The controller, who was a software developer, created and offered a software package designed to manage… CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Controllers Security Processing Agreement Dec 22, 2025
€32,000 EXCEL HOTELS & RESORTS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on EXCEL HOTELS & RESORTS, S.A. The controller used guards to control access to its facility. The guards regularly left documents… SPAIN ·AEPD ·Art. 5 Controllers Security Personal Data Dec 20, 2025
€32,000 EXCEL HOTELS & RESORTS, S.A.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 32.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Dec 20, 2025
€175,000 HAN University of Applied Sciences: Insufficient technical and organizational measures to ensure information security. ⇄ 175.000 euro boete - Nederlandse Autoriteit Persoonsgegevens (AP). THE NETHERLANDS ·AP ·Art. 32 Security Personal Data Controllers Dec 15, 2025
€175,000 Arnhem and Nijmegen University of Applied Sciences: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 175,000 on Arnhem and Nijmegen University of Applied Sciences. The controller suffered a data breach due to insufficient technical and… THE NETHERLANDS ·AP ·Art. 32 Security Controllers Data Breaches Dec 15, 2025
€75,700 Chief Constable of the Police Service of Scotland: Insufficient technical and organisational measures to ensure information security Information Commissioner (ICO) fined Chief Constable of the Police Service of Scotland €75,700 on 2025-12-12 for: Insufficient technical and organisational measures to ensure… United Kingdom ·ICO ·Art. 5, 25, 32 +1 Security Education Public Authority Dec 12, 2025
€98,000 University of Limerick: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined University of Limerick €98,000 on 2025-12-10 for: Insufficient technical and organisational measures to ensure information security. Ireland ·DPC ·Art. 5, 30, 32 +2 Security Supervisory Authorities Education Dec 10, 2025
€1,000 Compania de Apa Oltenia S.A.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 29, 32 Security Processing Personal Data Dec 8, 2025
€1,000 Compania de Apa Oltenia S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Compania de Apa Oltenia S.A. The controller failed to implement adequate technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 29, 32 Security Controllers Personal Data Dec 8, 2025
€1,300 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 1,300 on a legal entity. An employee of the controller stored personal data on her work laptop without securing it, for example by… SLOVENIA ·IP-RS ·Art. 32 Encryption Security Controllers Dec 4, 2025
€12,000 Comune di Tuscania: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 12,000 on the Commune di Tuscania. The controller had been using video surveillance and licence plate recognition within its territory… ITALY ·Garante ·Art. 5, 6, 12 +5 Controllers Processors Monitoring Dec 4, 2025
DSB · 2025-0.968.031 A data subject published a post concerning their ADHD diagnosis on a publicly accessible online forum under a pseudonym. A person (the controller) who was a follower of the data… 2025-0.968.031 ·Austria ·Art. 9 Pseudonymization Anonymization Health Data Dec 3, 2025
€3,600 RISING SUN CAR RENTAL S..L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,600 on RISING SUN CAR RENTAL S..L. The controller used video surveillance to ensure security at its facility, affecting more areas than… SPAIN ·AEPD ·Art. 5, 13 Controllers Supervisory Authorities Personal Data Dec 1, 2025
€1.6M SPRINTER MEGACENTROS DEL DEPORTE, S.L.: Insufficient technical and organizational measures to ensure information security. ⇄ 1.560.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 34 Security Controllers Supervisory Authorities Nov 28, 2025
€1.6M SPRINTER MEGACENTROS DEL DEPORTE, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,560,000 on SPRINTER MEGACENTROS DEL DEPORTE, S.L. The controller suffered a cyber attack due to insufficient technical and… SPAIN ·AEPD ·Art. 5, 34 Security Controllers Supervisory Authorities Nov 28, 2025
€2,000 Nițu A. Cleopatra – Expert Accountant: Insufficient technical and organisational measures to ensure information security Thr Romanian DPA has imposed a fine of EUR 2,000 on Nițu A. Cleopatra – Expert Accountant. The controller was the target of a successful cyber attack due to the inadequate… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Nov 27, 2025
€2,000 Nițu A. Cleopatra – Expert Accountant: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Nov 27, 2025
DSB · 2025-0.950.759 On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Austria ·Art. 5, 6, 16 +2 Privacy by Design & Default Privacy by Design Privacy by Default Nov 24, 2025
€4.5M Telecommunications Company (Operator of Electronic Communications Networks and Services): Violation of the General Principles of Data Processing. ⇄ Een boete van 4.500.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·AZOP ·Art. 5, 6, 12 +4 Controllers Processors Processing Nov 24, 2025
€4.5M Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer… CROATIA ·AZOP ·Art. 5, 6, 12 +4 International Transfer Privacy Shield Controllers Nov 24, 2025
€16,650 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 16,650 on a legal entity. The controller stored personal data on a publicly accessible web server without taking sufficient technical… SLOVENIA ·IP-RS ·Art. 32 Security Controllers Personal Data Nov 21, 2025
DSB: No processor access violation under Art. 15 GDPR when controller deleted data On 07. August 2023, the data subject made a request to the processor to provide the report and the questionnaire completed by the data subject at an information event. The… 2025-0.566.415 ·Austria ·Art. 4, 5, 12 +3 Controllers Processors Right of Access Nov 21, 2025
€1.4M LastPass UK Ltd: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 1,228,283 (EUR 1,400,000) on LastPass UK Ltd. The controller suffered a succesfull cyber attack due to insufficient technical and organisational… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers Processing Agreement Nov 20, 2025
€1.4M LastPass UK Ltd: Insufficient technical and organizational measures to ensure information security. ⇄ 1.400.000 euro boete - Informatiecommissaris (ICO) UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers Accountability Nov 20, 2025
€3,000 Greencorp S.R.L.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Nov 19, 2025
€3,000 Greencorp S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Greencorp S.R.L. The controller failed to implement adequate technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Nov 19, 2025
€60,000 STRATESYS TECHNOLOGY SOLUTIONS, S.L.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 60.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Nov 19, 2025
€60,000 STRATESYS TECHNOLOGY SOLUTIONS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 60,000 on STRATESYS TECHNOLOGY SOLUTIONS, S.L. The controller failed to implement adequate technical and organisational measures,… SPAIN ·AEPD ·Art. 5 Controllers Security Data Breaches Nov 19, 2025
€8,000 PGS SOFA & CO SRL: Insufficient technical and organizational measures to ensure information security. ⇄ 8.000 euro boete - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Nov 17, 2025
€8,000 PGS SOFA & CO SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PGS SOFA & CO SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures. ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Nov 17, 2025
€4,750 The District Sanitary Inspector in Police: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 4.750 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 24, 25 +1 Security Encryption Controllers Nov 15, 2025
€4,750 Powiatowego Inspektora Sanitarnego w Policach: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 4750 on the Powiatowego Inspektora Sanitarnego w Policach. The controller failed to implement adequate technical and organisational… POLAND ·UODO ·Art. 5, 24, 25 +1 Security Encryption Controllers Nov 15, 2025
€2,400 AXARQUIA VELEZ DENTAL, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,400 on AXARQUIA VELEZ DENTAL, S.L. The controller used video surveillance to ensure security at its facility, affecting more areas than… SPAIN ·AEPD ·Art. 5 Controllers Processing Security Nov 14, 2025
€7,000 Klass Wagen S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 7,000 on Klass Wagen S.R.L. The controller suffered a cyber incident due to a former employee exposing the login credentials of… ROMANIA ·ANSPDCP ·Art. 32 Controllers Security Personal Data Nov 7, 2025
€7,000 Klass Wagen S.R.L.: Insufficient technical and organizational measures to ensure information security. ⇄ Boete van €7.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Nov 7, 2025
€300,000 SIA 'ZZ Dats': Insufficient technical and organisational measures to ensure information security The Latvian DPA has imposed a fine of EUR 300,000 on SIA 'ZZ Dats'. The entity that was fined was the data processor for almost all local governments in Latvia. It failed to… LATVIA ·DSI ·Art. 32 Processors Security Controllers Oct 28, 2025
€300,000 SIA 'ZZ Dats': Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 300.000 euro - Inspectie gegevensbescherming (DSI). LATVIA ·DSI ·Art. 32 Security Controllers Processors Oct 28, 2025
€865,000 Aktia Bank Plc: Insufficient technical and organizational measures to ensure information security. ⇄ 865.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Privacy by Design Privacy by Default Oct 23, 2025