Skip to content
Content type · 950 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

201–250 of 950 sort newestlargest fineoldest
€320,000 HEP-Toplinarstvo: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined HEP-Toplinarstvo €320,000 on 2025-07-22 for: Insufficient technical and organisational measures to ensure information security. Croatia ·azop ·Art. 31, 32 Security Human Resources Supervisory Authorities Jul 22, 2025
€50,000 Information and Communication Company: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined Information and Communication Company €50,000 on 2025-07-22 for: Insufficient technical and organisational measures to ensure… Croatia ·azop ·Art. 32 Security Human Resources Supervisory Authorities Jul 22, 2025
€4M McDonald’s Polska Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed a fine of EUR 3,955,000 on McDonald’s Polska Sp. z o.o. The controller used a third party processor (see ETid: 2758) for the purpose of managing work… POLAND ·UODO ·Art. 5, 25, 28 +1 Controllers Processors Data Breaches Jul 21, 2025
€43,000 24/7 Communication Sp. z o.o.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 43.000 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 38 Security Processors Controllers NL Jul 21, 2025
€43,000 24/7 Communication Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 43,000 on 24/7 Communication Sp. z o.o. The fined entity acted as the data processor for McDonald’s Polska Sp. z o.o. (see ETid: 2757).… POLAND ·UODO ·Art. 5, 25, 38 Data Breaches Controllers Processors Jul 21, 2025
€9,000 Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 9,000 on Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A. The controller disclosed the identity of an anonymous author by… GREECE ·HDPA ·Art. 5, 25, 32 +2 Pseudonymization Personal Data Security Jul 21, 2025
€4M McDonald’s Polska Sp. z o.o.: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van 3.955.000 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 28 +1 Controllers Security Processing NL Jul 21, 2025
€1,200 TRUEBA SPORT S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,200 on TRUEBA SPORT S.L. The controller disclosed personal data due to an human error. The controller also failed to include a privacy… SPAIN ·aepd ·Art. 5, 13 Controllers Personal Data Processing Agreement Jul 17, 2025
€1,200 TRUEBA SPORT S.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 13 Security Data Controller Controllers NL Jul 17, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 32.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 32 Health Data Security Healthcare NL Jul 11, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on VALORA PREVENCIÓN, S.L.U. The controller, a company offering occupational health and safety services, failed to implement… SPAIN ·aepd ·Art. 5, 32 Security Healthcare Health Data Jul 11, 2025
€80,000 Poste Vita S.p.a.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 33 Security Controllers Data Controller NL Jul 10, 2025
€80,000 Poste Vita S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine on Poste Vita S.p.a. The controller failed to implement adequate technical and organisational measures to ensure data security. This resulted in… ITALY ·Garante ·Art. 5, 33 Security Insurance Personal Data Jul 10, 2025
€175,000 FAVORIT SPORTSKA KLADIONICA d.o.o.: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined FAVORIT SPORTSKA KLADIONICA d.o.o. €175,000 on 2025-07-02 for: Insufficient technical and organisational measures to ensure… Croatia ·azop ·Art. 5 Security Human Resources Supervisory Authorities Jul 2, 2025
€101,000 Croatian Insurance Bureau: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined Croatian Insurance Bureau €101,000 on 2025-07-02 for: Insufficient technical and organisational measures to ensure information… Croatia ·azop ·Art. 5, 32 Security Public Sector Insurance Jul 2, 2025
€15,600 Kinderziekenhuis van de L. Zamenhof Universiteit in Białystok: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 15.600 euro boete - Poolse nationale instantie voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 32 Security Healthcare Health Data NL Jun 30, 2025
€15,600 L. Zamenhof University Children's Clinical Hospital in Białystok: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 15,600 on the L. Zamenhof University Children's Clinical Hospital in Białystok. The controller did not implement sufficient technical and… POLAND ·UODO ·Art. 5, 32 Healthcare Security Healthcare Jun 30, 2025
€3,000 SC Tremend Software Consulting SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Jun 26, 2025
€25,000 Partij "Alliantie voor de Unie van Roemenië": Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 25 +1 Security Processing Education NL Jun 26, 2025
€25,000 Alliance for the Union of Romanians Party: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 25,000 on the Alliance for the Union of Romanians Party. The controller did not implement adeqaute technical and organisational measures… ROMANIA ·ANSPDCP ·Art. 5, 6, 25 +1 Data Breaches Security Controllers Jun 26, 2025
€3,000 SC Piramida Trade Invest SRL: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +4 Security Personal Data Data Controller NL Jun 26, 2025
€3,000 Selgros Cash & Carry SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Selgros Cash & Carry SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Jun 26, 2025
€3,000 SC Tremend Software Consulting SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on SC Tremend Software Consulting SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Processing Agreement Jun 26, 2025
€3,000 SC Piramida Trade Invest SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 3,000 on SC Piramida Trade Invest SRL. The controller processed personal data without a sufficient legal basis and without sufficient… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +4 Controllers Personal Data Data Subject Rights Exercise Modalities and Procedures Jun 26, 2025
€3,000 Selgros Cash & Carry SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Jun 26, 2025
€40,000 KARAMBELAS KONSTANTINOS & CO. E.E.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van 40.000 euro - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 29, 32 Security Telecommunications Personal Data NL Jun 25, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 550.000 euro - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 28 Security Controllers Processors NL Jun 25, 2025
€40,000 KARAMBELAS KONSTANTINOS & CO. E.E.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 40,000 on KARAMBELAS KONSTANTINOS & CO. E.E. The processor, which was processing data for a telecommunications provider (ETid: 2878),… GREECE ·HDPA ·Art. 29, 32 Security Telecommunications Processors Jun 25, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 550,000 on Vodafone – PANAFON A.E.E.T. The controller failed to implement sufficient technical and organisational measures to ensure data… GREECE ·HDPA ·Art. 5, 28 Controllers Security Telecommunications Jun 25, 2025
€20,725 Birthlink: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van €20.725 - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Security Notification Obligation Accountability NL Jun 24, 2025
€20,725 Birthlink: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 18,000 (EUR 20,725) on Birthlink. The controller, a scottish registered charity, failed to implement sufficient technical and organisational… UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Security Controllers Processing Agreement Jun 24, 2025
€125,000 Onderwijs- en opleidingsraad van de stad Dublin: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 125.000 euro boete - Ierse Autoriteit voor Gegevensbescherming. IRELAND ·Art. 5, 32, 33 +1 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Education NL Jun 23, 2025
€3,500 Gemeentelijk Sociaal Hulpcentrum Aleksandrów: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.500 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 32 Security Education Data Breaches NL Jun 23, 2025
€4,000 Vodafone Romania S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 4.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Security Data Breaches Telecommunications NL Jun 23, 2025
€3,500 Municipal Social Welfare Center Aleksandrów: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 3,500 on the Municipal Social Welfare Center in Aleksandrów. The controller did not implement sufficient technical and organisational… POLAND ·UODO ·Art. 32 Data Breaches Security IP Address Jun 23, 2025
€125,000 City of Dublin Education and Training Board: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 125,000 on the City of Dublin Education and Training Board. The controller suffered a data breach due to insufficient technical and… IRELAND ·Art. 5, 32, 33 +1 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Education Jun 23, 2025
€4,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 4,000 on Vodafone Romania S.A. The controller failed to implement sufficient technical and organisational measures to ensure data… ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Telecommunications Jun 23, 2025
€18,000 OCI CINE, S.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 18.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 32 Security Controllers Data Controller NL Jun 13, 2025
€18,000 OCI CINE, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 18,000 on OCI CINE, S.L. The controller had implemented insufficient technical and organisational measures to ensure data security, resulting… SPAIN ·aepd ·Art. 5, 32 Security Controllers Processing Agreement Jun 13, 2025
€550,000 Departement of Social Security: Insufficient legal basis for data processing The Irish DPA imposed a fine of EUR 550,000 on the Departement of Social Security. The controller uses the so called SAFE 2 registration process for anyone applying for a Public… IRELAND ·Art. 5, 6, 9 +2 ·Insufficient legal basis for data processing DPIA Privacy Impact Assessment Special Categories of Data Jun 12, 2025
€10,000 Accounting Audit SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €10.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Processing NL Jun 12, 2025
€10,000 Accounting Audit SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 10,000 on Accounting Audit SRL. The company failed to implement sufficient technical and organizational measures, resulting in a data breach… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Processing Agreement Jun 12, 2025
€2.7M 23andMe, Inc.: Insufficient technical and organisational measures to ensure information security The UK DPA imposed a fine of £ 2,310,000 (EUR 2,700,000) on 23andMe, Inc. The controller, a company offering DNA testing to private individuals, failed to implement sufficient… UNITED KINGDOM ·ICO ·Art. 5, 32 Data Breaches Security Genetic Data Jun 5, 2025
€2.7M 23andMe, Inc.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.700.000 euro - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32 Security Data Breaches Health Data NL Jun 5, 2025
€45,000 Noi Compriamo Auto.it S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 45,000 on Noi Compriamo Auto.it S.r.l. The controller contacted the data subject multiple times for direct marketing purposes via… ITALY ·Garante ·Art. 5, 6, 12 +2 Direct Marketing IP Address Controllers Jun 4, 2025
€45,000 Noi Compriamo Auto.it S.r.l.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 45.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +2 Data Controller Marketing Personal Data NL Jun 4, 2025
€5,000 AG-BROKER ASIGURARE S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on AG-BROKER ASIGURARE S.R.L. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Insurance May 30, 2025
€5,000 AG-BROKER ASIGURARE S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €5.000 - De Roemeense nationale toezichthouder op de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL May 30, 2025
€1.4M REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 1,380,000 on REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS, S.L. The controller used outdated technical and organisational measures to manage… SPAIN ·aepd ·Art. 5, 32 Controllers Processing Agreement Security May 26, 2025