Skip to content
Content type · 1,529 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

151–200 of 1,529 sort newestlargest fineoldest
€4,000 Georgescu Călin: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine on the politican Georgescu Călin. The controller failed to inform data subjects on his website regarding the processing of their data and how… ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Data Controller Jul 16, 2025
€20,000 NN Greek Single-Member Anonymous Life Insurance Company: Insufficient fulfilment of data subjects rights The Greek DPA has imposed a fine of EUR 20,000 on NN Greek Single-Member Anonymous Life Insurance Company. The controller failed to provide the data subject with the personal data… GREECE ·HDPA ·Art. 15 Right of Access Procedures Right of Access Personal Data Jul 11, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on VALORA PREVENCIÓN, S.L.U. The controller, a company offering occupational health and safety services, failed to implement… SPAIN ·aepd ·Art. 5, 32 Security Healthcare Health Data Jul 11, 2025
€8,000 Università degli Studi di Cassino e del Lazio Meridionale: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 8,000 on Università degli Studi di Cassino e del Lazio Meridionale. The controller failed to delete a former employee's email address… ITALY ·Garante ·Art. 5, 6, 12 +2 Controllers IP Address Employees Jul 10, 2025
€50,000 Magna PT S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine on Magna PT S.p.A. Employees of the controllers were subjected to 'return to work interviews' after returning from an absence due to illness or… ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Retention Period Jul 10, 2025
€3,000 Comune di Conversano: Lack of appointment of data protection officer The Italian DPA has imposed a fine of EUR 3,000 on the Comune di Conversano. The controller failed to correctly appoint a DPA. ITALY ·Garante ·Art. 37 Supervisory Authorities Public Authority Controllers Jul 10, 2025
€80,000 Poste Vita S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine on Poste Vita S.p.a. The controller failed to implement adequate technical and organisational measures to ensure data security. This resulted in… ITALY ·Garante ·Art. 5, 33 Security Insurance Personal Data Jul 10, 2025
€3,000 Zougla TZI-AP Anonymous Mass Media Company: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 3,000 on Zougla TZI-AP Anonymous Media Company. The controller, who operates a news website, published an article revealing the personal… GREECE ·HDPA ·Art. 5, 31 Controllers Personal Data Processing Jul 4, 2025
€3,000 SC Piramida Trade Invest SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 3,000 on SC Piramida Trade Invest SRL. The controller processed personal data without a sufficient legal basis and without sufficient… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +4 Controllers Personal Data Data Subject Rights Exercise Modalities and Procedures Jun 26, 2025
€96,000 SIDECU, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 96,000 on SIDECU, S.A. The controller introduced facial recognistion system as the only access method to their facilities, without offering… SPAIN ·aepd ·Art. 9, 13, 35 DPIA Privacy Impact Assessment IP Address Jun 26, 2025
€40,000 KARAMBELAS KONSTANTINOS & CO. E.E.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 40,000 on KARAMBELAS KONSTANTINOS & CO. E.E. The processor, which was processing data for a telecommunications provider (ETid: 2878),… GREECE ·HDPA ·Art. 29, 32 Security Telecommunications Processors Jun 25, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 550,000 on Vodafone – PANAFON A.E.E.T. The controller failed to implement sufficient technical and organisational measures to ensure data… GREECE ·HDPA ·Art. 5, 28 Controllers Telecommunications Security Jun 25, 2025
€7,000 General Hospital of the University of Larissa: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 7,000 on the General Hospital of the University of Larissa. The controller failed to adequately fulfil the rights of data subjects. It… GREECE ·HDPA ·Art. 5, 14, 15 Healthcare Healthcare Controllers Jun 24, 2025
€10,000 Shield of David - K.I.D.A.F.: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Shield of David - K.I.D.A.F. The controller, a day care centre for people with autism, has legally installed video… GREECE ·HDPA ·Art. 5, 12, 13 +3 Video Surveillance Controllers Personal Data Jun 24, 2025
€20,725 Birthlink: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 18,000 (EUR 20,725) on Birthlink. The controller, a scottish registered charity, failed to implement sufficient technical and organisational… UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Security Controllers Processing Agreement Jun 24, 2025
€4,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 4,000 on Vodafone Romania S.A. The controller failed to implement sufficient technical and organisational measures to ensure data… ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Telecommunications Jun 23, 2025
€125,000 Onderwijs- en opleidingsraad van de stad Dublin: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 125.000 euro boete - Ierse Autoriteit voor Gegevensbescherming. IRELAND ·Art. 5, 32, 33 +1 ·Insufficient technical and organisational measures to ensure information security Security Education Data Breaches NL Jun 23, 2025
€125,000 City of Dublin Education and Training Board: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 125,000 on the City of Dublin Education and Training Board. The controller suffered a data breach due to insufficient technical and… IRELAND ·Art. 5, 32, 33 +1 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Education Jun 23, 2025
€1,000 SC Diamir SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 1,000 on SC Diamir SRL. The controller failed to properly cooperate with the supervisory authority and also disclosed personal data to… ROMANIA ·ANSPDCP ·Art. 6, 58 Controllers IP Address Supervisory Authorities Jun 19, 2025
€200 Dincă Viorel George: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 200 on a private individual. The controller failed to react to communication from the supervisory authority. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Controllers Jun 18, 2025
€540 CUBILLO GALLEGO, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA imposed a fine of EUR 540 on CUBILLO GALLEGO, S.L. The controller failed to comply with an order issued by the DPA, as well as failing to react adequately to… SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Law Enforcement Jun 13, 2025
€550,000 Departement of Social Security: Insufficient legal basis for data processing The Irish DPA imposed a fine of EUR 550,000 on the Departement of Social Security. The controller uses the so called SAFE 2 registration process for anyone applying for a Public… IRELAND ·Art. 5, 6, 9 +2 ·Insufficient legal basis for data processing DPIA Privacy Impact Assessment Types of Special Categories of Personal Data Jun 12, 2025
€10,000 Accounting Audit SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 10,000 on Accounting Audit SRL. The company failed to implement sufficient technical and organizational measures, resulting in a data breach… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Processing Agreement Jun 12, 2025
€2.7M 23andMe, Inc.: Insufficient technical and organisational measures to ensure information security The UK DPA imposed a fine of £ 2,310,000 (EUR 2,700,000) on 23andMe, Inc. The controller, a company offering DNA testing to private individuals, failed to implement sufficient… UNITED KINGDOM ·ICO ·Art. 5, 32 Data Breaches Security Genetic Data Jun 5, 2025
€45,000 Noi Compriamo Auto.it S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 45,000 on Noi Compriamo Auto.it S.r.l. The controller contacted the data subject multiple times for direct marketing purposes via… ITALY ·Garante ·Art. 5, 6, 12 +2 Direct Marketing IP Address Controllers Jun 4, 2025
€16,000 Car Park Management Company: Insufficient cooperation with supervisory authority The Austrian DPA has imposed a fine in the amount of EUR 16,000 on a car park management company. The controller failed to react to communication from the supervisory authority. AUSTRIA ·dsb ·Art. 31 Supervisory Authorities Supervision Controllers Jun 3, 2025
€1.1M Yliopiston Apteekin: Non-compliance with general data processing principles The Finish DPA has imposed a fine of EUR 1,100,000 on Yliopiston Apteekin. The controller, who runs an online pharmacy, used various web analytics and monitoring tools. These… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 32 IP Address Audit Logs Controllers May 27, 2025
€12,000 Data Diggers Market Research SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 12,000 on Data Diggers Market Research SRL. The controller processed personal data without sufficient legal basis. The controller also… ROMANIA ·ANSPDCP ·Art. 6, 12, 14 +1 Personal Data Controllers IP Address May 21, 2025
€21,000 Menarini Silicon Biosystems SpA: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 21,000 on Menarini Silicon Biosystems SpA. The controller is conducting oncological research and has developed a software that is able to… ITALY ·Garante ·Art. 5, 13 Retention Period Health Data Healthcare May 21, 2025
€360 RED ESPAÑOLA DE IDENTIFICACIÓN DE ANIMALES DE COMPAÑÍA: Insufficient cooperation with supervisory authority The Spanish DPA imposed a fine of EUR 360 on RED ESPAÑOLA DE IDENTIFICACIÓN DE ANIMALES DE COMPAÑÍA. The controller failed to react to communication from the supervisory authority. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Controllers May 20, 2025
€1,000 Home Owner Association: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 1,000 on a home owner association. The HOA displayed the personal data of debtors in the entrance hall of a building, which infringed on the… SPAIN ·aepd ·Art. 5 Professional Secrecy Integrity and Confidentiality Principle Personal Data May 19, 2025
€200,000 ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 200,000 on ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L. The controller obtained personal data from a third party… SPAIN ·aepd ·Art. 6, 17 Controllers Insurance Personal Data May 19, 2025
€80,000 CALOGA: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 80,000 on CALOGA. The controller is a company obtaining data from data brokers to use those for marketing purposes. The DPA found multiple… FRANCE ·CNIL ·Art. 5, 6 IP Address Controllers Processing Agreement May 15, 2025
€16,000 Sole Trader: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 16,000 on a sole trader. The controller rented out apartments to tenants and installed video surveillance inside them. SLOVENIA ·Art. 5, 6 ·Insufficient legal basis for data processing Video Surveillance Controllers Monitoring May 14, 2025
€6,600 Owner of a Pharmacy Office: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the owner of a pharmacy office. The controller processed data of residents of two geriatric centers without a sufficient legal basis. The… SPAIN ·aepd ·Art. 6, 14, 32 Encryption Controllers Healthcare May 9, 2025
€6,600 Owner of a Pharmacy Office: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the owner of a pharmacy office. The controller processed data of residents of geriatric centers without a sufficient legal basis. The… SPAIN ·aepd ·Art. 6, 14, 32 Encryption Controllers Healthcare May 8, 2025
€530M TikTok Technology Limited: Insufficient legal basis for data processing The Irish DPA (DPC) has fined TikTok EUR 530 million. In its decision, the DPC found, that TikTok infringed Art. 13 (1) f) GDPR and Art. 46 (1) GDPR due to the unlawful transfer… Art. 13, 46 Social Media Processing Agreement International Transfer May 2, 2025
€7,000 Bedrijf: Niet-naleving van algemene principes voor gegevensverwerking. Boete van €7.000 - Nationale Commissie voor de Bescherming van Persoonsgegevens (CNPD). LUXEMBOURG ·CNPD ·Art. 30 Processing Personal Data IP Address NL Apr 30, 2025
€7,000 Company: Non-compliance with general data processing principles The DPA of Luxembourg has issued a fine of EUR 7,000 on a company. The controller failed to maintain complete records of its processing activities. LUXEMBOURG ·CNPD ·Art. 30 Processing Controllers IP Address Apr 30, 2025
€100,000 Energia Verde S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Energia Verde S.p.A. The controller had been active in direct marketing activities. The controller processed data without a… ITALY ·Garante ·Art. 5, 6, 7 +13 IP Address Processing Agreement Controllers Apr 29, 2025
€2,000 Tirrenia Hospital S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 2,000 on Tirrenia Hospital S.r.l. The controller failed to respond to a data access request from a data subject. ITALY ·Garante ·Art. 12, 15 Right of Access Procedures Healthcare Personal Data Apr 29, 2025
€2,000 Versilmagra Immobiliare di Robertelli Davide & C. S.a.s.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2,000 on Versilmagra Immobiliare di Robertelli Davide & C. S.a.s. The controller obtained personal data of potential customers by… ITALY ·Garante ·Art. 5, 6, 7 +7 IP Address Controllers Marketing Apr 29, 2025
€40,000 MA Immobiliare S.r.l.s.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on MA Immobiliare S.r.l.s. The controller obtained personal data of potential customers by Realmaps S.r.l., which obtained the… ITALY ·Garante ·Art. 5, 6, 7 +6 Marketing Direct Marketing Personal Data Apr 29, 2025
€30,000 Orde van psychologen van Lombardije: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 30.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 32 Security Data Breaches Education NL Apr 29, 2025
€40,000 Municipality of Bologna: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 40,000 on the Municipality of Bologna. The controller used a data processor (Cooperativa Sociale Quadrifoglio | ETid: 2274) to process… ITALY ·Garante ·Art. 5, 6, 9 Processors Controllers Security Apr 29, 2025
€1,000 Xiting ROM SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Xiting ROM SRL. The controller failed to respond adequately to a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Processing Agreement Apr 28, 2025
€6,000 SC Travel Planner SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 6,000 on SC Travel Planner SRL. The controller failed to implement sufficient technical and organisational measures, resulting in a data… ROMANIA ·ANSPDCP ·Art. 12, 15, 32 +1 Data Breaches Controllers Security Apr 25, 2025
€10,000 Dante International SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 10,000 on Dante International SA. The controller failed to respond adequately to a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 17, 19 Personal Data Controllers Processing Agreement Apr 24, 2025
€6,000 Real Estate Agency: Insufficient cooperation with supervisory authority The Belgian DPA imposed a fine of EUR 6,000 on a real estate agency. The Belgian DPA had previously issued a remedy to the controller in an earlier case due to the controller… BELGIUM ·APD ·Art. 5, 6, 17 +1 Right to be Forgotten Supervisory Authorities Data Subject Rights Exercise Modalities and Procedures Apr 24, 2025
€20,000 Company: Non-compliance with general data processing principles The Belgian DPA imposed a fine of EUR 20,000 on a company. The controller is a company engaging in direct marketing activities. During those activies the company failed to comply… BELGIUM ·APD ·Art. 5, 6, 12 +4 Controllers Direct Marketing IP Address Apr 22, 2025