Skip to content
Content type · 2,395 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

151–200 of 2,395 sort newestlargest fineoldest
€2,951 Land-surveying office: Insufficient technical and organisational measures to ensure information security The Polish National Personal Data Protection Office (UODO) fined a land-surveying office €2,951 for failing to implement sufficient technical and organizational measures to ensure… Poland ·UODO ·Art. 28, 32 Security Controllers Processors May 25, 2026
€4,958 District Governor of Lubartów: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) fined the District Governor of Lubartów €4,958 for failing to implement adequate technical and organizational measures to ensure information security, citing… Poland ·UODO ·Art. 5, 25, 28 +1 Privacy by Design Processors Controllers May 25, 2026
PLN 21,000 DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Poland ·UODO ·Art. 24, 25, 28 +1 Integrity and Confidentiality Principle Security Controllers May 25, 2026
PLN 26,711 DKE.561.4.2026 The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance extending… Poland ·UODO ·Art. 5 Accountability Monitoring Right to be Forgotten May 22, 2026
€6,292 Private individual: Insufficient cooperation with supervisory authority The Polish National Personal Data Protection Office (UODO) fined a private individual €6,292 for failing to adequately cooperate with the supervisory authority during an… Poland ·UODO ·Art. 58, 83 Supervision Supervisory Authorities Personal Data May 22, 2026
GBP 300 ICO (UK) - KRA Consultancy Ltd The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related services.… United Kingdom Personal Data Consent Processing May 20, 2026
PLN 33,700 DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Poland ·UODO ·Art. 5, 24, 25 +3 Data Breaches Integrity and Confidentiality Principle Notification Obligation May 19, 2026
UODO reprimands mayor for disclosing data subject's data to company without legal basis The data subject requested the mayor of their place of residence (the controller) to provide them scans of contracts the city had concluded with certain companies and invoices… DS.523.2582.2024 ·Poland ·Art. 5, 6 Personal Data Integrity and Confidentiality Principle Right to Restriction May 18, 2026
€15,000 Monaldi-Cotugno-CTO: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Monaldi-Cotugno-CTO hospital entity €15,000 for violating general data processing principles under the GDPR. The… Italy ·Garante ·Art. 5, 9, 13 +2 Healthcare Types of Special Categories of Personal Data Security May 14, 2026
€1,000 Danta di Cadore Hunting Reserve: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined the Danta di Cadore Hunting Reserve €1,000 for failing to adequately fulfill its information obligations regarding the… Italy ·Garante ·Art. 5, 6, 13 Personal Data Processing Transparency May 14, 2026
€8,000 Municipality of Ventasso: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Municipality of Ventasso €8,000 for violating the general data processing principles under Articles 5, 6, and 9 of the… Italy ·Garante ·Art. 5, 6, 9 Types of Special Categories of Personal Data Personal Data Public Authority May 14, 2026
€180,000 Emirates: Insufficient fulfilment of information obligations The Italian Data Protection Authority (Garante) fined Emirates €180,000 for insufficient fulfillment of its information obligations under the GDPR. The authority found that the… Italy ·Garante ·Art. 5, 12, 13 Personal Data Supervisory Authorities May 14, 2026
€1,000 FeGi M&A Services s.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined FeGi M&A Services s.r.l. €1,000 for non-compliance with general data processing principles under Article 5(1)(a) and Article… Italy ·Garante ·Art. 5, 14 Supervision Supervisory Authorities Personal Data May 14, 2026
€100,000 Energia Sostenibile S.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Energia Sostenibile S.r.l. €100,000 for violations of multiple GDPR provisions, including Articles 5, 6, 7, 12, 13, 15, 24,… Italy ·Garante ·Art. 5, 6, 7 +5 Controllers Processors Supervision May 14, 2026
€1,500 Francesco Gagliardi: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) found Francesco Gagliardi, operating as a sole proprietorship, in violation of Articles 5(1)(a) and 14 of the GDPR and Article 130… Italy ·Garante ·Art. 5, 14 Legitimate Interest Personal Data Lawful Basis May 14, 2026
€1,800 Municipality of Mirabella Imbaccari: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Municipality of Mirabella Imbaccari €1,800 for processing personal data without a sufficient legal basis, in violation of… Italy ·Garante ·Art. 5, 6, 37 Public Authority Supervisory Authorities Supervision May 14, 2026
HDPA · 12/2026 The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Greece ·Art. 23 Right of Access Criminal Data Personal Data May 13, 2026
HUF 15M NAIH-450-7-2026 The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Fairness & Transparency Personal Data Transparency May 12, 2026
€120,000 Isabel SA: Insufficient fulfilment of data subjects rights Belgian Data Protection Authority (APD) fined Isabel SA €120,000 on 2026-05-12 for: Insufficient fulfilment of data subjects rights. Belgium ·APD/GBA ·Art. 5, 12, 13 +2 Personal Data Supervisory Authorities Insurance May 12, 2026
€42,052 Operator of an online marketplace: Insufficient fulfilment of information obligations The Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined an online marketplace operator €42,052 for failing to adequately fulfill its… Hungary ·NAIH ·Art. 5, 12, 13 Transparency Personal Data May 12, 2026
€4,920 Law Firm: Insufficient fulfilment of data subjects rights Belgian Data Protection Authority (APD) fined Law Firm €4,920 on 2026-05-08 for: Insufficient fulfilment of data subjects rights. Belgium ·APD/GBA ·Art. 5, 12, 13 +2 Personal Data Supervisory Authorities Insurance May 8, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·DPC ·Art. 5, 32, 33 Integrity and Confidentiality Principle Data Breaches Notification Obligation May 8, 2026
The data subject was a technician employed by the controller The controller used weekly handwritten service sheets as a system for recording working time. These sheets contained the technician’s working hours, journeys, services performed… 97/2026 ·Belgium ·APD/GBA Personal Data Right of Access Controllers May 6, 2026
€2,802 IP-RS · 0609-42/2026/7 A processor was contracted by a company (the controller) to maintain an online store, fix errors, and provide support. This included ensuring that the controller had installed the… Slovenia ·Art. 32 Controllers Processors Security May 1, 2026
€1,790 Mayor of the City and Municipality of Myślenice: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined the Mayor of the City and Municipality of Myślenice €1,790 for insufficient fulfilment of personal data breach notification obligations under Article… Poland ·UODO ·Art. 33 Notification Obligation Data Breaches Supervisory Authorities Apr 30, 2026
€277,500 Permanent TSB plc: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Permanent TSB plc €277,500 for failing to implement sufficient technical and organisational measures to ensure information security,… Ireland ·DPC ·Art. 5, 32, 33 Notification Obligation Data Breaches Supervision Apr 30, 2026
€2,500 BLUE PROJECTS INDUSTRIES S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined BLUE PROJECTS INDUSTRIES S.R.L. €2,500 on 2026-04-30 for: Insufficient technical and… Romania ·ANSPDCP ·Art. 32 Security Personal Data Supervision Apr 30, 2026
HUF 10M NAIH-4462-5-2026 The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Personal Data Fairness & Transparency Accountability Apr 30, 2026
€34,000 Pianeta S.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Pianeta S.r.l. €34,000 for violations of multiple GDPR provisions, including Article 5(1)(a) and (b) on general data… Italy ·Garante ·Art. 5, 6, 12 +5 Personal Data Processing Supervision Apr 29, 2026
€12,000 Ministry of Justice: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Ministry of Justice €12,000 for insufficient legal basis for personal data processing. The enforcement action, decided on… Italy ·Garante ·Art. 5, 6, 9 Fairness & Transparency Personal Data Healthcare Apr 29, 2026
€8,600 Matera Local Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the Matera Local Health Authority €8,600 for failing to implement sufficient technical and organizational measures to ensure… Italy ·Garante ·Art. 5, 32 Security Personal Data Supervision Apr 29, 2026
€5,000 Dr. Guzzo: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Dr. Guzzo €5,000 for processing personal data without a sufficient legal basis. The violation concerned healthcare data and… Italy ·Garante ·Art. 5, 9 Retention Period Controllers Healthcare Apr 29, 2026
€4,000 Montelibretti State Comprehensive School: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Montelibretti State Comprehensive School €4,000 for lacking a sufficient legal basis for its data processing activities. The… Italy ·Garante ·Art. 5, 6, 9 Personal Data Healthcare Processing Apr 29, 2026
€15,000 Nouva Corrente S.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Nouva Corrente S.r.l. €15,000 for non-compliance with general data processing principles under the GDPR. The enforcement… Italy ·Garante ·Art. 1, 2, 5 +3 Personal Data Supervision Consent Apr 29, 2026
€35,000 Crowd Entertainment Ltd: Insufficient legal basis for data processing Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Crowd Entertainment Ltd €35,000 on 2026-04-28 for: Insufficient legal basis for data… Romania ·ANSPDCP ·Art. 5 Personal Data Processing Supervisory Authorities Apr 28, 2026
OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only… No. 2.1-1/24/397-890-38 ·Estonia ·AKI Controllers Processors Privacy by Design & Default Apr 16, 2026
€2,415 UODO reprimands electricity seller for Art. 5, 24, 25, 28, 32 GDPR violations over An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone… Poland ·Art. 5, 24, 25 +2 Processors Integrity and Confidentiality Principle Controllers Apr 13, 2026
€2,415 Sub Agent: Insufficient technical and organisational measures to ensure information security The Polish National Personal Data Protection Office (UODO) fined Sub Agent €2,415 for failing to implement sufficient technical and organizational measures to ensure information… Poland ·UODO ·Art. 28, 32 Security Personal Data Apr 13, 2026
€2,415 Sole trader: Insufficient technical and organisational measures to ensure information security The Polish National Personal Data Protection Office (UODO) fined a sole trader operating in the industry and commerce sector €2,415 for failing to implement sufficient technical… Poland ·UODO ·Art. 28, 32 Processors Controllers Personal Data Apr 13, 2026
€2,350 Housing Associaction: Insufficient fulfilment of data breach notification obligations Polish National Personal Data Protection Office (UODO) fined Housing Associaction €2,350 on 2026-04-07 for: Insufficient fulfilment of data breach notification obligations. Poland ·UODO ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Apr 7, 2026
€2,500 BLUE PROJECTS S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined BLUE PROJECTS S.R.L. €2,500 on 2026-04-03 for: Insufficient technical and organisational… Romania ·ANSPDCP ·Art. 32 Security Personal Data Supervision Apr 3, 2026
€100M Ridetech International B.V.: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) fined Ridetech International B.V. €100,000,000 on 2026-04-01 for: Insufficient legal basis for data processing. The Netherlands ·AP ·Art. 5, 44, 46 Supervision Supervisory Authorities Processing Apr 1, 2026
€2,000 Physician: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Physician €2,000 on 2026-03-26 for: Insufficient fulfilment of data subjects rights. Italy ·Garante ·Art. 13 Personal Data Supervisory Authorities Healthcare Mar 26, 2026
€5,000 Esselunga S.p.A.: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Esselunga S.p.A. €5,000 on 2026-03-26 for: Insufficient fulfilment of data subjects rights. Italy ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Employees Mar 26, 2026
€125,000 RENAULT COMMERCIAL ROUMANIE S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined RENAULT COMMERCIAL ROUMANIE S.R.L. €125,000 on 2026-03-25 for: Insufficient technical and… Romania ·ANSPDCP ·Art. 28, 32 Security Supervisory Authorities Supervision Mar 25, 2026
€4,000 ING Bank NV Amsterdam – Sucursala București S.A.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined ING Bank NV Amsterdam – Sucursala București S.A. €4,000 on 2026-03-23 for: Insufficient… Romania ·ANSPDCP ·Art. 32 Security Personal Data Supervisory Authorities Mar 23, 2026
The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025 They worked as a manager in the controller’s finance department, with technical and disciplinary responsibility for up to five employees. The controller operated a 360-degree… 2025-0.960.016 ·Austria ·DSB Legitimate Interest Personal Data Controllers Mar 20, 2026
€150,000 ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L. €150,000 for failing to implement sufficient technical and organizational measures to… Spain ·AEPD ·Art. 5 Integrity and Confidentiality Principle Security Personal Data Mar 20, 2026
€3,000 Public and Private Domain SA: Insufficient legal basis for data processing Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Public and Private Domain SA €3,000 on 2026-03-20 for: Insufficient legal basis for data… Romania ·ANSPDCP ·Art. 5, 6, 12 +1 Personal Data Supervisory Authorities Supervision Mar 20, 2026
€3,000 Domeniul Public și Privat SA: Insufficient legal basis for data processing Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Domeniul Public și Privat SA €3,000 on 2026-03-20 for: Insufficient legal basis for data… Romania ·ANSPDCP ·Art. 5, 6, 12 +1 Personal Data Supervision Supervisory Authorities Mar 20, 2026