Skip to content
Content type · 1,529 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

201–250 of 1,529 sort newestlargest fineoldest
€260,000 CAMERDATA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 260,000 on CAMERDATA, S.A. The controller operates a database in which it collects data on individual entrepreneurs from the Spanish… SPAIN ·aepd ·Art. 6, 14 Controllers Personal Data Processing Agreement Apr 15, 2025
€500,000 Chamber of Commerce, Industry, Services and Navigation of Spain: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500,000 on the Chamber of Commerce, Industry, Services and Navigation of Spain. Due to its function within the Spanish Executive, the… aepd ·Art. 5, 6, 14 ·Insufficient legal basis for data processing Controllers Processors Fairness & Transparency Apr 15, 2025
€7,800 Uitvaartonderneming: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €7.800 - van het Poolse Nationaal Bureau voor de Bescherming van Persoonlijke Gegevens (UODO). POLAND ·UODO ·Art. 5 Health Data Security Data Breaches NL Apr 15, 2025
€2,000 United Business Solutions SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on United Business Solutions SRL. The controller failed to implement sufficient technical and organisational measuresto ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Apr 15, 2025
€600 SPAIN, DPA: Niet-naleving van de algemene principes voor gegevensverwerking. 600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). aepd ·Art. 5 ·Non-compliance with general data processing principles Data Controller Processing Controllers NL Apr 15, 2025
€7,800 Funeral Home: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined a funeral home EUR 7,800. The funeral home failed to implement sufficient technical and organisational measures to prevent a data breach. The funeral home… POLAND ·UODO ·Art. 5 Data Breaches Security Healthcare Apr 15, 2025
€1,000 Office Nova Concept SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Office Nova Concept SRL. The controller failed to respond adequately to a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 15, 17 +1 Controllers Personal Data Supervisory Authorities Apr 14, 2025
€70,300 DPP Law Ltd.: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has imposed a fine of £ 60,000 (EUR 70,300) on the law firm DPP Law Ltd. The controller had suffered a cyber attack during which personal data of 791 clients and… UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Security Processing Agreement Law Enforcement Apr 14, 2025
€2,000 NEW GAMBLING SOLUTIONS S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on NEW GAMBLING SOLUTIONS S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure data… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Apr 11, 2025
€8,000 Undici S.r.l.s.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 8,000 on Undici S.r.l.s. The controller obtained personal data of potential customers by Realmaps S.r.l., which obtained the data in… ITALY ·Garante ·Art. 5, 6, 7 +6 IP Address Personal Data Controllers Apr 10, 2025
€8,000 Eastern Parma Apennine Mountain Community: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 8,000 on the Eastern Parma Apennine Mountain Community. The controller had set up video surveillance in front of a police station, that… ITALY ·Garante ·Art. 5, 6, 12 +2 Video Surveillance Monitoring Public Authority Apr 10, 2025
€15,000 Tensa Art Design S.A.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 15,000 on Tensa Art Design S.A. The controller contacted a data for direct marketing purposes without consent. The controller also… ROMANIA ·ANSPDCP ·Art. 6, 12, 15 +1 Direct Marketing Marketing Controllers Apr 10, 2025
€8,000 Gemeenschap van de oostelijke Apennijnen in Parma: Niet-naleving van de algemene principes voor gegevensverwerking. 8.000 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +2 Video Surveillance Education Processing NL Apr 10, 2025
€15,000 Immobiliare Valdalpone S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on Immobiliare Valdalpone S.r.l. The controller obtained personal data of potential customers by Realmaps S.r.l., which obtained… ITALY ·Garante ·Art. 5, 6, 7 +8 IP Address Personal Data Controllers Apr 10, 2025
€5M Luka Inc.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 5,000,000 on Luka Inc. The developer created a chatbot called Replika with a written and voice interface. It is based on a generative AI… ITALY ·Garante ·Art. 5, 6, 12 +3 AI Act Formal Non-Compliance AI Act Violations Minors Apr 10, 2025
€850,000 Network of Agencies and Companies: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 850,000 on a network of agencies and companies. The network operated on behalf of Acea Energia S.p.A. and engaged in aggresive customer… ITALY ·Garante ·Art. 5, 6, 7 +6 Fines IP Address Telecommunications Apr 10, 2025
€5,000 Gynaecologist: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 5,000 on a gynaecologist. The controller failed to completely fullfill an information request by a patient. GREECE ·HDPA ·Art. 15 Healthcare Controllers Supervisory Authorities Apr 9, 2025
€5,000 Gynaecoloog: Onvoldoende nakoming van de informatieplicht. Een boete van €5.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 15 Health Data Healthcare Personal Data NL Apr 9, 2025
€360 SINDICAT CATAC-CTSC: Insufficient cooperation with supervisory authority The Spanish DPA imposed a fine of on SINDICAT CATAC-CTSC. The controller failed to react to a communication attempt by the AEPD. The original fine of EUR 600 was reduced to EUR… SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Law Enforcement Apr 4, 2025
€3,000 BINBOX GLOBAL SERVICES S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on BINBOX GLOBAL SERVICES S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure data… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Telecommunications Apr 2, 2025
€4,000 CREMA GAMES, S.L.: Insufficient fulfilment of information obligations The Spanish DPA imposed a fine on CREMA GAMES, S.L. The controller failed to fulfill an information request from an online customer. The controller asked the data subject for an… SPAIN ·aepd ·Art. 15 Controllers Personal Data Telecommunications Mar 28, 2025
€6,600 GRUAS IGNACI, S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on GRUAS IGNACI, S.L. The controller uses too much data to verify a person's identity, which breaches the principle of data minimization.… SPAIN ·aepd ·Art. 5, 13, 32 Video Surveillance Controllers IP Address Mar 28, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 120.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Professional Secrecy Integrity and Confidentiality Principle Processing NL Mar 28, 2025
€12,000 ESTUDIO ALCAZAR DEL GENIL 2022, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine on ESTUDIO ALCAZAR DEL GENIL 2022, S.L. The controller collected property data by having its employees visit and photograph the properties,… SPAIN ·aepd ·Art. 6, 14 Controllers Personal Data Processing Mar 28, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on SERVICIOS ESPECIALES, S.A. The case concerned a GDPR breach during an internal workplace conflict investigation: the company shared a report via… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle Professional Secrecy IP Address Mar 28, 2025
€3,000 Municipality of Palma di Montechiaro: Lack of appointment of data protection officer The Italian DPA has imposed a fine of EUR 3,000 on the Municipality of Palma di Montechiaro. The controller failed to appoint a DPO and report the DPO to the DPA. ITALY ·Garante ·Art. 37 Supervisory Authorities Public Authority Public Sector Mar 27, 2025
€18,000 Multiple Companies: Insufficient legal basis for data processing The Italian DPA imposed fines on 3 companies which ammount to EUR 6,000 each. The fined companies (Powerfit s.s.d.a.r.l., Soleo s.s.d.a.r.l. and Zero Due Villa s.s.d.a.r.l.) run a… ITALY ·Garante ·Art. 5, 6, 12 +1 Right to be Forgotten Fines Direct Marketing Mar 27, 2025
€3.5M Advanced Computer Software Group Ltd: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined Advanced Computer Software Group Ltd £3.07 million (EUR 3.5 million) for insufficient IT security (infringiment of Art. 32 (1) UK GDPR). The controller… UNITED KINGDOM ·ICO ·Art. 32 Security Access Controls Healthcare Mar 26, 2025
€25,000 NTT DATA ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on NTT DATA ROMANIA S.A. The controller failed to implement sufficient technical and organisational measures, resulting in a data… ANSPDCP ·Art. 32, 33 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Mar 25, 2025
€4,000 Hospital: Non-compliance with general data processing principles The Croation DPA (AZOP) has imposed a fine of EUR 4,000 on a hospital. The AZOP found that the hospital used a company which automatically retrieved personal data of vehicle… CROATIA ·azop ·Art. 13, 14, 25 +1 Fines Healthcare Healthcare Mar 24, 2025
€20,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) imposed a fine of EUR 20,000 on a hospital for failing to implement adequate technical and organizational measures to protect personal data in line with… CROATIA ·azop ·Art. 32 Data Breaches Security Healthcare Mar 24, 2025
€17,600 Chief Commander of the Police: Insufficient legal basis for data processing The Polish DPA has fined the Chief Commander of the Polish Police EUR 17,600. During a press conference, the Chief Commander of the Police disclosed the personal and medical data… POLAND ·UODO ·Art. 6, 9 Healthcare Health Data Healthcare Mar 24, 2025
€1,000 Bucharest Down Town Hotel SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Bucharest Down Town Hotel SRL. The controller failed to provide a data subject with requested data. ROMANIA ·ANSPDCP ·Art. 12, 13, 15 Personal Data Controllers Processing Agreement Mar 21, 2025
€4,800 TECNOCRÃTICA CENTRO DE DATOS S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 4,800 on TECNOCRÃTICA CENTRO DE DATOS S.L. The controller failed to reply to an information request by the AEPD within the given… SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Controllers Mar 20, 2025
€2,000 ONE UNITED PROPERTIES S.A: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on ONE UNITED PROPERTIES S.A. The controller contacted a data subject multiple times for direct marketing purposes without… ROMANIA ·ANSPDCP ·Art. 6, 12, 15 +1 Direct Marketing Personal Data Controllers Mar 20, 2025
€3.2M CENTROS COMERCIALES CARREFOUR, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 3,200,000 on CENTROS COMERCIALES CARREFOUR, S.A. The controller suffered a cyberattack, resulting in the leak of a large amount of personal… SPAIN ·aepd ·Art. 5, 32, 34 Data Breaches Security Processing Agreement Mar 14, 2025
€20,000 Encore Thermoengineering s.r.l.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 20,000 on Encore Thermoengineering s.r.l. The controller legally obtained employee data from another company that had gone bankrupt. The… ITALY ·Garante ·Art. 5, 6, 17 Controllers IP Address Employees Mar 13, 2025
€15,000 G@S Telecomunicazioni di Losito Lucia: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 15,000 on G@S Telecomunicazioni di Losito Lucia. The controller processed customer data without sufficient legal basis and additionally… ITALY ·Garante ·Art. 5, 6, 7 +2 Personal Data Controllers Telecommunications Mar 13, 2025
€50,000 Azienda regionale per lo sviluppo e per i servizi in agricoltura (ARSAC): Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 50,000 on the Regional agency for development and services in agriculture (ARSAC). The controller processed geographic data of its employees… ITALY ·Garante ·Art. 5, 6, 13 +3 Fairness & Transparency Controllers Education Mar 13, 2025
€40,000 Interflora Italia S.p.A.: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 20,000 on Interflora Italia S.p.A. The controller, who operates an online shop, used customer data for direct marketing purposes without a… ITALY ·Garante ·Art. 5, 6, 12 +2 Direct Marketing Right to Object Marketing Mar 13, 2025
€5,000 Automobilus International S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Automobilus International S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Processing Agreement Mar 12, 2025
€1,000 Noy Business Tranzactions SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Noy Business Tranzactions SRL. The controller failed to provide a data subject with requested data. ROMANIA ·ANSPDCP ·Art. 12, 15, 17 Personal Data Controllers Processing Agreement Mar 11, 2025
€13,400 Polskie Radio Szczecin: Insufficient technical and organisational measures to ensure information security The Polish DPA fined Polskie Radio Szczecin (Polish Radio Szczecin) EUR 13,400. Due to the lack of sufficient technical measures, Polskie Radio Szczecin failed to protect the… POLAND ·UODO ·Art. 24, 32 Security IP Address Telecommunications Mar 11, 2025
€3,500 Police Officer: Insufficient legal basis for data processing The DPA of Baden-Württemberg has imposed a fine of EUR 3,500 on a police officer. The controller systematically accessed the police database for private purposes, using it to rate… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Processing Processing Agreement Mar 7, 2025
€2,000 SHOPBAG GROUP ONLINE SRL: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 2,000 onSHOPBAG GROUP ONLINE SRL. The controller failed to respond to a request made by the DPA. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Controllers Mar 6, 2025
€20,000 WEBRASOFT SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on WEBRASOFT SRL. The controller failed to implement sufficient technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Mar 4, 2025
€10,000 BEKO ROMANIA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on BEKO ROMANIA SA. The controller failed to implement sufficient technical and organisational measures to provide data security,… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Controllers Mar 3, 2025
€1,000 Velvet Medical SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Velvet Medical SRL. The controller failed to provide the data subject with the requested health data. ROMANIA ·ANSPDCP ·Art. 12, 15 Healthcare Health Data Healthcare Feb 27, 2025
€600,000 IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274. Due to a technical error in its online platform, personal data, including… SPAIN ·aepd ·Art. 5 Healthcare IP Address Controllers Feb 25, 2025
€200,000 Vodafone España, S.A.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 200,000 on Vodafone España, S.A.U.. A person had filed a complaint with the DPA because the company had given a duplicate of their SIM… SPAIN ·aepd ·Art. 6 Personal Data Consent Telecommunications Feb 25, 2025