Skip to content
Content type · 1,013 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

201–250 of 1,013 sort newestlargest fineoldest
€865,000 Aktia Bank Plc: Insufficient technical and organizational measures to ensure information security. ⇄ 865.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Privacy by Design Privacy by Default Oct 23, 2025
€5,000 S.P.E.E.H. HIDROELECTRICA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on S.P.E.E.H. HIDROELECTRICA SA. A technical error in the controller's computer systems was exploited by attackers to cause a… ROMANIA ·ANSPDCP ·Art. 32 Controllers Security Personal Data Oct 20, 2025
€5,000 S.P.E.E.H. HIDROELECTRICA SA: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Oct 20, 2025
€2,000 PRIME TRANSACTION SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on PRIME TRANSACTION SA. The controller failed to implement adequate technical and organisational measures, resulting in a data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Oct 16, 2025
€2,000 PRIME TRANSACTION SA: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Processing Oct 16, 2025
€9.2M CAPITA PLC: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 8,000,000 (EUR 9,180,000) on CAPITA PLC. CAPITA PLC acts as the data controller for the CAPITA Group, which has suffered a cyber attack. The… UNITED KINGDOM ·ICO ·Art. 5, 32 Controllers Security Processing Oct 15, 2025
€6.9M CAPITA PENSION SOLUTIONS LIMITED: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 6,000,000 (EUR 6,880,000) on CAPITA PENSION SOLUTIONS LIMITED. CAPITA PENSION SOLUTIONS LIMITED acts as the data processor for the CAPITA Group,… UNITED KINGDOM ·ICO ·Art. 32 Processors Controllers Security Oct 15, 2025
€9.2M CAPITA PLC: Insufficient technical and organizational measures to ensure information security. ⇄ 9.180.000 euro boete - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers Accountability Oct 15, 2025
€6.9M CAPITA PENSION SOLUTIONS LIMITED: Inadequate technical and organisational measures to ensure information security. ⇄ Een boete van 6.880.000 euro - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 32 Security Controllers Processors Oct 15, 2025
€5,000 Vellea Home SRL: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Oct 13, 2025
€5,000 Vellea Home SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Vellea Home SRL. The controller failed to implement adequate technical and organisational measures, resulting in a data breach. ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Oct 13, 2025
AEPD · PS-00140-2025 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In… PS-00140-2025 ·Spain ·Art. 5, 9, 24 +2 Data Breaches Notification Obligation Integrity and Confidentiality Principle Oct 10, 2025
€25,000 E.ON ENERGIE ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Processing Personal Data Oct 9, 2025
€25,000 EON ENERGIE ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on EON ENERGIE ROMANIA S.A. The controller failed to implement adequate technical and organisational measures, resulting in a… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Oct 9, 2025
€30,000 THE RED KIWI, S.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 30.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 32 Personal Data Processing Controllers Oct 3, 2025
€20,000 S.C. PRIMONET RO S.R.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 20.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Sep 25, 2025
€20,000 S.C. PRIMONET RO S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on S.C. PRIMONET RO S.R.L. The controller failed to implement adequate technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Sep 25, 2025
€600 Property manager: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 600 on a porperty manager. The controller operated a website for owners and tenants that did not implement adequate technical and… SPAIN ·AEPD ·Art. 32 Security Controllers Processing Agreement Sep 23, 2025
€3,000 DHL PARCEL IBERIA, S.L.: Violation of the general principles of data processing. ⇄ Een boete van 3.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 32 Controllers Processing Security Sep 22, 2025
€100,000 SAMARITAINE SAS: Non-compliance with the general principles of data processing. ⇄ Een boete van 100.000 euro - van de Franse Autoriteit voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 5, 33, 38 Controllers Processing Security Sep 18, 2025
€100,000 SAMARITAINE SAS: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 100,000 on SAMARITAINE SAS. After multiple theft incidents, the controller installed security cameras disguised as smoke detectors to… FRANCE ·CNIL ·Art. 5, 33, 38 Data Breaches Controllers Supervisory Authorities Sep 18, 2025
€1.5M SERVICIOS FINANCIEROS CARREFOUR, E.F.C.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,500,000 on SERVICIOS FINANCIEROS CARREFOUR, E.F.C. The controller suffered a successfull cyberattack due to insufficient technical and… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Agreement Sep 17, 2025
€1.5M CARREFOUR FINANCIAL SERVICES, E.F.C.: Insufficient technical and organizational measures to ensure information security. ⇄ 1.500.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Sep 17, 2025
€12,000 Casa di Cura Città di Roma: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 12.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9, 25 +1 Security Health Data Healthcare Sep 11, 2025
€12,000 Casa di Cura Città di Roma: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 12,000 on the Casa di Cura Città di Roma. The controller used patient management software that gave users access to excessive amounts of… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Controllers Security Sep 11, 2025
€5,000 Unita Turism Holding S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Unita Turism Holding S.A. The controller did not implement adequate technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Sep 9, 2025
€5,000 Unita Turism Holding S.A.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Sep 9, 2025
€1.8M S-Pankki Oyj: Insufficient technical and organizational measures to ensure information security. ⇄ 1.800.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Privacy by Design Privacy by Default Sep 8, 2025
€1.8M S-Pankki Oyj: Insufficient technical and organisational measures to ensure information security The Finish DPA has imposed a fine of EUR 1,800,000 on S-Pankki Oyj. Due to a software error, customers of the controller were able to log in to the bank accounts of other… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Controllers Processing Agreement Sep 8, 2025
€3M Allium UPI: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 3.000.000 euro - De Estische Autoriteit voor Gegevensbescherming (AKI). ESTONIA ·AKI ·Insufficient technical and organisational measures to ensure information security Security Data Breaches Minors Sep 5, 2025
€3M Allium UPI: Insufficient technical and organisational measures to ensure information security The Estonian DPA has imposed a fine of EUR 3,000,000 on Allium UPI. The controller failed to implement adequate technical and organisational measures to ensure data security. This… ESTONIA ·AKI ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processing Agreement Sep 5, 2025
€180,000 Sociedad de Gestión de Activos Procedentes de la Reestructuración Bancaria S.A.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 180.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 28 Security Processors Processing Sep 4, 2025
€180,000 Sociedad de Gestión de Activos Procedentes de la Reestructuración Bancaria S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 180,000 on Sociedad de Gestión de Activos Procedentes de la Reestructuración Bancaria S.A. The controller suffered a cyber attack due to… SPAIN ·AEPD ·Art. 5, 28 Controllers Processors Security Sep 4, 2025
€10,000 La Fântâna S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on La Fântâna S.R.L. The controller suffered a cyber attack due to insufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Sep 1, 2025
€10,000 La Fântâna S.R.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van €10.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Sep 1, 2025
€1,800 LEIVA BUS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,800 on LEIVA BUS, S.L. The controller leaked personal data due to insufficient technical and organisational measures to ensure data… SPAIN ·AEPD ·Art. 5 Security Controllers Personal Data Aug 25, 2025
€1,800 LEIVA BUS, S.L.: Insufficient technical and organizational measures to ensure information security. ⇄ 1.800 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Aug 25, 2025
€6,000 BANCO INVERSIS, S.A.: Insufficient technical and organisational measures to ensure information security. ⇄ Boete van 6.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Aug 22, 2025
€18,000 GRUPO BONATEL SL: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van €18.000 - van de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Aug 22, 2025
€18,000 GRUPO BONATEL SL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 18,000 on the GRUPO BONATEL SL. The controller suffered a data leak due to insufficient technical and organisational measures to ensure… SPAIN ·AEPD ·Art. 5 Security Controllers Telecommunications Aug 22, 2025
€6,000 BANCO INVERSIS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 6,000 on BANCO INVERSIS, S.A. The controller suffered a data leak due to insufficient technical and organisational measures to ensure… SPAIN ·AEPD ·Art. 5 Security Controllers Processing Agreement Aug 22, 2025
€3,000 SC Elite Conta SRL: Insufficient technical and organisational measures to ensure information security The Romainian DPA has imposed a fine of EUR 3,000 on SC Elite Conta SRL. The controller failed to implement adequate technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Aug 18, 2025
€3,000 SC Elite Conta SRL: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Aug 18, 2025
€3,000 'FLEXICREDIT' Mutual Aid Cooperative: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Aug 12, 2025
€66,000 REAL SOCIEDAD DE FUTBOL S.A.D.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 66.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 32 Security Controllers Accountability Aug 12, 2025
€66,000 REAL SOCIEDAD DE FUTBOL S.A.D.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 66,000 on REAL SOCIEDAD DE FUTBOL S.A.D. The controller suffered a ransomwareattack due to insufficient technical and organisational… SPAIN ·AEPD ·Art. 5, 32 Security Controllers Processing Agreement Aug 12, 2025
€3,000 'FLEXICREDIT' Mutual Aid House Association: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on 'FLEXICREDIT' Mutual Aid House Association. The controller failed to implement adequate technical and organisational measures… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Aug 12, 2025
€80,000 BIZUM, S.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 80.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 32 Security Controllers Data Breaches Aug 11, 2025
€80,000 BIZUM, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 80,000 on BIZUM, S.L. The controller failed to implement sufficient technical and organisational measures to ensure data security,… SPAIN ·AEPD ·Art. 32 Security Controllers Data Breaches Aug 11, 2025