Skip to content
Content type · 2,256 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

151–200 of 2,256 sort newestlargest fineoldest
€3,140 UniCredit Bank Tsjechië en Slowakije, a.s.: Onvoldoende juridische basis voor de verwerking van gegevens. Boete van €3.140 - Tsjechische Autoriteit voor Gegevensbescherming (UOOU). CZECH REPUBLIC ·UOOU ·Art. 6 Personal Data Consent Processing NL Dec 30, 2025
€960 POLEN, Autoriteit voor Persoonsgegevens: Onvoldoende samenwerking met de toezichthoudende instantie. Een boete van 960 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 58 Personal Data Supervisory Authorities Processing NL Dec 30, 2025
€588 Alza.cz a.s.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 588 euro - opgelegd door de Tsjechische Autoriteit voor Gegevensbescherming (UOOU). CZECH REPUBLIC ·UOOU ·Art. 6, 7 Consent Personal Data Processing NL Dec 30, 2025
€960 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined a data controller EUR 1,450 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Dec 30, 2025
€20,000 Telecommunicatiebedrijf: Onvoldoende juridische basis voor gegevensverwerking. De Kroatische gegevensbeschermingsautoriteit (DPA) heeft een telecombedrijf een boete van 20.000 euro opgelegd. Een betrokkene had een klacht ingediend bij de DPA, waarin hij… CROATIA ·azop ·Art. 5, 6 Processing Accuracy Personal Data NL Dec 30, 2025
€3.5M Company: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 3,500,000 on a company. The controller operated a loyalty program in France and 16 other EU countries, using customer data obtained… FRANCE ·CNIL ·Art. 6, 13, 32 +1 DPIA IP Address Processing Agreement Dec 30, 2025
SLOVENAKIË: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Slovaakse Autoriteit voor de Bescherming van Persoonsgegevens. SLOVAKIA ·Slovak Data Protection Office ·Art. 5, 32 Security Processing Personal Data NL Dec 30, 2025
€40,000 Slovak Telekom: Insufficient technical and organisational measures to ensure information security The controller did not take adequate security measures when processing personal data, thereby breaching the obligation to protect the processed personal data. SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Security Telecommunications Controllers Dec 30, 2025
€27,000 Vodafone España, S.A.U.: Onvoldoende naleving van de rechten van betrokkenen bij de verwerking van persoonsgegevens. Een boete van 27.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Personal Data Processing Telecommunications NL Dec 30, 2025
€10,000 Ikea Ibérica: Insufficient legal basis for data processing The company installed cookies on an end users terminal device without prior consent of the data subject. SPAIN ·aepd ·Art. 6 Cookies Consent Personal Data Dec 30, 2025
€50,000 Social Insurance Agency: Insufficient technical and organisational measures to ensure information security Applications for social benefits from Slovak citizens were sent by post to foreign authorities. These were lost by post, with the result that the whereabouts of these personal… SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Healthcare Insurance Security Dec 30, 2025
SLOVAKIA DPA: Insufficient fulfilment of data subjects rights A Data Controller failed to comply with data subject´s request to access his/her personal data processed by audio recordings. Slovak Data Protection Office ·Art. 15 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Data Controller Dec 30, 2025
SLOVENAKIË, Dataprotectieautoriteit: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Slovaakse Autoriteit voor de Bescherming van Persoonsgegevens. SLOVAKIA ·Slovak Data Protection Office ·Art. 5, 6 Personal Data Processing Education NL Dec 30, 2025
SLOVAKIA DPA: Insufficient technical and organisational measures to ensure information security Documents containing personal data were disposed of in the area of the municipal garbage dump. Slovak Data Protection Office ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Security IP Address Dec 30, 2025
€40,000 Slovak Telekom: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 40.000 euro - van het Slowaakse databeschermingskantoor. SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Security Telecommunications Personal Data NL Dec 30, 2025
€12,000 Madrileña Red de Gas: Insufficient technical and organisational measures to ensure information security The gas company did not have appropriate measures in place to verify the identity of the data subject. The person who filed the complaint alleges that the company e-mailed his… SPAIN ·aepd ·Art. 32 Personal Data Security Law Enforcement Dec 30, 2025
€9,600 Restaurant (SANTI 3000, S.L.): Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Boete van €9.600 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 6 Processing Personal Data IP Address NL Dec 30, 2025
€2,000 Orde van Algemene Verpleegkundigen, Verloskundigen en Medische Assistenten van Roemenië – Afdeling Neamt: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +1 Video Surveillance Processing Controllers NL Dec 29, 2025
€2,000 Order of General Nurses, Midwives and Medical Assistants of Romania – Neamt Branch: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 2,000 on the Order of General Nurses, Midwives and Medical Assistants of Romania – Neamt Branch. The controller used video surveillance… ANSPDCP ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Video Surveillance Employees Monitoring Dec 29, 2025
€6,000 Geturhotels Srl: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 6,000 on Geturhotels Srl. The controller was involved in direct marketing operations, using personal data that had not been acquired or… ITALY ·Garante ·Art. 5, 6, 17 +1 Direct Marketing Controllers IP Address Dec 23, 2025
€6,000 Geturhotels Srl: Overtreding van de algemene principes voor gegevensverwerking. Een boete van 6.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 17 +1 Processing Data Controller Controllers NL Dec 23, 2025
€500,000 CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 500,000 on CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U. The controller used a communication tool that was not designed in… SPAIN ·aepd ·Art. 25 IP Address Controllers Processing Agreement Dec 22, 2025
€32,000 EXCEL HOTELS & RESORTS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on EXCEL HOTELS & RESORTS, S.A. The controller used guards to control access to its facility. The guards regularly left documents… SPAIN ·aepd ·Art. 5 Security Controllers Personal Data Dec 20, 2025
€6,000 Comune di Nave: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Commune di Nave. The controller has installed an automatic licence plate recognition system which processes data on when a… ITALY ·Garante ·Art. 5, 6, 12 +2 Insurance DPIA Privacy Impact Assessment Dec 18, 2025
€2,000 Elba Catering Distribuzioni s.r.I.s.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on Elba Catering Distribuzioni s.r.I.s. The controller installed video surveillance, which affected the public road. Furthermore,… ITALY ·Garante ·Art. 5, 13 Video Surveillance Controllers Monitoring Dec 18, 2025
€40,000 LTL S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 40,000 on LTL S.p.A. The controller failed to respond within the legal time period to a request by a former employee to exercise their… ITALY ·Garante ·Art. 5, 12, 15 Controllers Personal Data Processing Agreement Dec 18, 2025
€1,000 Data Controller: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on a data controller. The controller disclosed personal data by sending an email to an address that third parties who were not… ITALY ·Garante ·Art. 5, 6 Controllers Personal Data Processing Agreement Dec 18, 2025
€175,000 De Hogeschool Arnhem en Nijmegen: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 175.000 euro boete - Nederlandse Autoriteit Persoonsgegevens (AP). THE NETHERLANDS ·AP ·Art. 32 Security Education Data Breaches NL Dec 15, 2025
€15,000 Crowd Entertainment Limited: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 15,000 on Crowd Entertainment Limited. The controller failed to adequatly react to a data subjects request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 15 Controllers Personal Data Telecommunications Dec 10, 2025
€15,000 Crowd Entertainment Limited: Onvoldoende naleving van de rechten van betrokkenen (betreffende hun persoonsgegevens). Een boete van €15.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Right of Access Data Controller NL Dec 10, 2025
€5,100 Legal Entity: Insufficient fulfilment of data subjects rights The Slovenian DPA has imposed a fine of EUR 5,100 on a legal entity. The controller operated a website where natural persons could fil in their personal data in a form. The… SLOVENIA ·Art. 12, 13 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Processing Agreement Dec 8, 2025
€1,000 Compania de Apa Oltenia S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Compania de Apa Oltenia S.A. The controller failed to implement adequate technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 29, 32 Security Social Media Controllers Dec 8, 2025
€1,000 Compania de Apa Oltenia S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 29, 32 Security Processing Controllers NL Dec 8, 2025
€2,000 Istituto Comprensivo Centro di Casalecchio di Reno: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 2,000 on Istituto Comprensivo Centro di Casalecchio di Reno. The controller published a ranking of its teachers on its website without a… ITALY ·Garante ·Art. 5, 6 Controllers Personal Data Employees Dec 4, 2025
€2,000 Istituto Comprensivo Centro in Casalecchio di Reno: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Data Controller Personal Data Controllers NL Dec 4, 2025
€12,000 Comune di Tuscania: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 12,000 on the Commune di Tuscania. The controller had been using video surveillance and licence plate recognition within its territory… ITALY ·Garante ·Art. 5, 6, 12 +5 Video Surveillance Controllers IP Address Dec 4, 2025
€1,000 'Principe Umberto di Savoia' State Scientific and Linguistic High School: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on 'Principe Umberto di Savoia' State Scientific and Linguistic High School. The controller processed the personal data of… ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Right of Access Healthcare Dec 4, 2025
€1,300 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 1,300 on a legal entity. An employee of the controller stored personal data on her work laptop without securing it, for example by… SLOVENIA ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Controllers Dec 4, 2025
Austrian DSB: sharing ADHD diagnosis from public forum post did not breach Art. 9 GDPR A data subject published a post concerning their ADHD diagnosis on a publicly accessible online forum under a pseudonym. A person (the controller) who was a follower of the data… 2025-0.968.031 ·Austria ·Art. 9 Health Data Healthcare Pseudonymization Dec 3, 2025
€3,600 RISING SUN CAR RENTAL S..L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,600 on RISING SUN CAR RENTAL S..L. The controller used video surveillance to ensure security at its facility, affecting more areas than… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Monitoring Dec 1, 2025
€3,600 RISING SUN CAR RENTAL S.L.: Niet-naleving van de algemene principes voor gegevensverwerking. De Spaanse autoriteit voor gegevensbescherming (DPA) heeft RISING SUN CAR RENTAL S.L. een boete van 3.600 euro opgelegd. De verantwoordelijke partij gebruikte videobewaking om de… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Processing Data Controller NL Dec 1, 2025
€1.6M SPRINTER MEGACENTROS DEL DEPORTE, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,560,000 on SPRINTER MEGACENTROS DEL DEPORTE, S.L. The controller suffered a cyber attack due to insufficient technical and… SPAIN ·aepd ·Art. 5, 34 Security Controllers Processing Agreement Nov 28, 2025
€40,000 Infobel: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 40,000 on Infobel. The controller, a data broker, sold personal data for direct marketing purposes. However, it processed the data it had… BELGIUM ·APD ·Art. 5, 6, 24 Controllers Marketing Direct Marketing Nov 27, 2025
€1.5M AMERICAN EXPRESS CARTE FRANCE: Onvoldoende juridische basis voor de verwerking van gegevens. 1.500.000 euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). CNIL ·Art. 82 ·Insufficient legal basis for data processing Cookies Processing Data Controller NL Nov 27, 2025
€400,000 Verisure Italy s.r.l.: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van 400.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). Garante ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles Archiving Data Controller Storage Limitation NL Nov 27, 2025
€2,000 Nițu A. Cleopatra – Expert Accountant: Insufficient technical and organisational measures to ensure information security Thr Romanian DPA has imposed a fine of EUR 2,000 on Nițu A. Cleopatra – Expert Accountant. The controller was the target of a successful cyber attack due to the inadequate… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Human Resources Nov 27, 2025
€1.5M AMERICAN EXPRESS CARTE FRANCE: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 1,500,000 on AMERICAN EXPRESS CARTE FRANCE. The controller used excessive cookies on its website and failed to adequately inform data… CNIL ·Art. 82 ·Insufficient legal basis for data processing Cookies Processing Agreement Controllers Nov 27, 2025
€400,000 Verisure Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 400,000 on Verisure Italy s.r.l. The controller had been active in direkt marketing activities. The controller failed to ensure that the… Garante ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles IP Address Direct Marketing Controllers Nov 27, 2025
€2,000 Nițu A. Cleopatra – Expert Accountant: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data NL Nov 27, 2025