Skip to content
Content type · 568 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

201–250 of 568 sort newestlargest fineoldest
€21,000 Menarini Silicon Biosystems SpA: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 21,000 on Menarini Silicon Biosystems SpA. The controller is conducting oncological research and has developed a software that is able to… ITALY ·Garante ·Art. 5, 13 Retention Period Storage Limitation Accountability May 21, 2025
€12,000 Data Diggers Market Research SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 12,000 on Data Diggers Market Research SRL. The controller processed personal data without sufficient legal basis. The controller also… ROMANIA ·ANSPDCP ·Art. 6, 12, 14 +1 Personal Data Controllers Supervisory Authorities May 21, 2025
€360 RED ESPAÑOLA DE IDENTIFICACIÓN DE ANIMALES DE COMPAÑÍA: Insufficient cooperation with supervisory authority The Spanish DPA imposed a fine of EUR 360 on RED ESPAÑOLA DE IDENTIFICACIÓN DE ANIMALES DE COMPAÑÍA. The controller failed to react to communication from the supervisory authority. SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Controllers May 20, 2025
€200,000 ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 200,000 on ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L. The controller obtained personal data from a third party… SPAIN ·AEPD ·Art. 6, 17 Controllers Personal Data Insurance May 19, 2025
€1,000 Home Owner Association: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 1,000 on a home owner association. The HOA displayed the personal data of debtors in the entrance hall of a building, which infringed on the… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Personal Data Processing May 19, 2025
€80,000 CALOGA: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 80,000 on CALOGA. The controller is a company obtaining data from data brokers to use those for marketing purposes. The DPA found multiple… FRANCE ·CNIL ·Art. 5, 6 Controllers Processing IP Address May 15, 2025
€16,000 Sole Trader: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 16,000 on a sole trader. The controller rented out apartments to tenants and installed video surveillance inside them. SLOVENIA ·IP-RS ·Art. 5, 6 Controllers Processing Video Surveillance May 14, 2025
€6,600 Owner of a Pharmacy Office: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the owner of a pharmacy office. The controller processed data of residents of two geriatric centers without a sufficient legal basis. The… SPAIN ·AEPD ·Art. 6, 14, 32 Controllers Encryption Personal Data May 9, 2025
€6,600 Owner of a Pharmacy Office: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the owner of a pharmacy office. The controller processed data of residents of geriatric centers without a sufficient legal basis. The… SPAIN ·AEPD ·Art. 6, 14, 32 Controllers Encryption Personal Data May 8, 2025
€530M TikTok Technology Limited: Insufficient legal basis for data processing The Irish DPA (DPC) has fined TikTok EUR 530 million. In its decision, the DPC found, that TikTok infringed Art. 13 (1) f) GDPR and Art. 46 (1) GDPR due to the unlawful transfer… DPC ·Art. 13, 46 Processing Agreement International Transfer Personal Data May 2, 2025
€7,000 Company: Non-compliance with general data processing principles The DPA of Luxembourg has issued a fine of EUR 7,000 on a company. The controller failed to maintain complete records of its processing activities. LUXEMBOURG ·CNPD (LU) ·Art. 30 Processing Controllers Supervisory Authorities Apr 30, 2025
€7,000 Company: Non-compliance with general principles for data processing. ⇄ Boete van €7.000 - Nationale Commissie voor de Bescherming van Persoonsgegevens (CNPD). LUXEMBOURG ·CNPD (LU) ·Art. 30 Personal Data Processing IP Address Apr 30, 2025
€2,000 Tirrenia Hospital S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 2,000 on Tirrenia Hospital S.r.l. The controller failed to respond to a data access request from a data subject. ITALY ·Garante ·Art. 12, 15 Right of Access Personal Data Controllers Apr 29, 2025
€30,000 Lombardy Order of Psychologists: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 30.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 32 Security Controllers Accountability Apr 29, 2025
€40,000 Municipality of Bologna: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 40,000 on the Municipality of Bologna. The controller used a data processor (Cooperativa Sociale Quadrifoglio | ETid: 2274) to process… ITALY ·Garante ·Art. 5, 6, 9 Controllers Security Healthcare Apr 29, 2025
€40,000 MA Immobiliare S.r.l.s.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on MA Immobiliare S.r.l.s. The controller obtained personal data of potential customers by Realmaps S.r.l., which obtained the… ITALY ·Garante ·Art. 5, 6, 7 +6 Controllers Personal Data Marketing Apr 29, 2025
€2,000 Versilmagra Immobiliare di Robertelli Davide & C. S.a.s.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2,000 on Versilmagra Immobiliare di Robertelli Davide & C. S.a.s. The controller obtained personal data of potential customers by… ITALY ·Garante ·Art. 5, 6, 7 +7 Direct Marketing Personal Data Controllers Apr 29, 2025
€100,000 Energia Verde S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Energia Verde S.p.A. The controller had been active in direct marketing activities. The controller processed data without a… ITALY ·Garante ·Art. 5, 6, 7 +13 Direct Marketing Controllers Processors Apr 29, 2025
€1,000 Xiting ROM SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Xiting ROM SRL. The controller failed to respond adequately to a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Apr 28, 2025
€6,000 SC Travel Planner SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 6,000 on SC Travel Planner SRL. The controller failed to implement sufficient technical and organisational measures, resulting in a data… ROMANIA ·ANSPDCP ·Art. 12, 15, 32 +1 Data Breaches Controllers Security Apr 25, 2025
€10,000 Dante International SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 10,000 on Dante International SA. The controller failed to respond adequately to a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 17, 19 Personal Data Controllers Supervisory Authorities Apr 24, 2025
€6,000 Real Estate Agency: Insufficient cooperation with supervisory authority The Belgian DPA imposed a fine of EUR 6,000 on a real estate agency. The Belgian DPA had previously issued a remedy to the controller in an earlier case due to the controller… BELGIUM ·APD/GBA ·Art. 5, 6, 17 +1 Right to be Forgotten Controllers Personal Data Apr 24, 2025
€20,000 Company: Non-compliance with general data processing principles The Belgian DPA imposed a fine of EUR 20,000 on a company. The controller is a company engaging in direct marketing activities. During those activies the company failed to comply… BELGIUM ·APD/GBA ·Art. 5, 6, 12 +4 Controllers Personal Data Marketing Apr 22, 2025
€600 SPAIN, DPA: Non-compliance with the general principles of data processing. ⇄ 600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). AEPD ·Art. 5 ·Non-compliance with general data processing principles Controllers Processing Accountability Apr 15, 2025
€7,800 Funeral company: insufficient technical and organisational measures to ensure information security. ⇄ Een boete van €7.800 - van het Poolse Nationaal Bureau voor de Bescherming van Persoonlijke Gegevens (UODO). POLAND ·UODO ·Art. 5 Security Controllers Processing Apr 15, 2025
€7,800 Funeral Home: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined a funeral home EUR 7,800. The funeral home failed to implement sufficient technical and organisational measures to prevent a data breach. The funeral home… POLAND ·UODO ·Art. 5 Security Controllers Personal Data Apr 15, 2025
€500,000 Chamber of Commerce, Industry, Services and Navigation of Spain: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500,000 on the Chamber of Commerce, Industry, Services and Navigation of Spain. Due to its function within the Spanish Executive, the… AEPD ·Art. 5, 6, 14 ·Insufficient legal basis for data processing Integrity and Confidentiality Principle Controllers Retention Period Apr 15, 2025
€260,000 CAMERDATA, S.A.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 260,000 on CAMERDATA, S.A. The controller operates a database in which it collects data on individual entrepreneurs from the Spanish… SPAIN ·AEPD ·Art. 6, 14 Controllers Personal Data Supervisory Authorities Apr 15, 2025
€2,000 United Business Solutions SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on United Business Solutions SRL. The controller failed to implement sufficient technical and organisational measuresto ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Apr 15, 2025
€1,000 Office Nova Concept SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Office Nova Concept SRL. The controller failed to respond adequately to a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 15, 17 +1 Personal Data Controllers Supervisory Authorities Apr 14, 2025
€70,300 DPP Law Ltd.: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has imposed a fine of £ 60,000 (EUR 70,300) on the law firm DPP Law Ltd. The controller had suffered a cyber attack during which personal data of 791 clients and… UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Controllers Security Personal Data Apr 14, 2025
€2,000 NEW GAMBLING SOLUTIONS S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on NEW GAMBLING SOLUTIONS S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Apr 11, 2025
€8,000 Undici S.r.l.s.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 8,000 on Undici S.r.l.s. The controller obtained personal data of potential customers by Realmaps S.r.l., which obtained the data in… ITALY ·Garante ·Art. 5, 6, 7 +6 Personal Data Controllers Marketing Apr 10, 2025
€15,000 Tensa Art Design S.A.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 15,000 on Tensa Art Design S.A. The controller contacted a data for direct marketing purposes without consent. The controller also… ROMANIA ·ANSPDCP ·Art. 6, 12, 15 +1 Personal Data Marketing Controllers Apr 10, 2025
€8,000 Eastern Parma Apennine Mountain Community: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 8,000 on the Eastern Parma Apennine Mountain Community. The controller had set up video surveillance in front of a police station, that… ITALY ·Garante ·Art. 5, 6, 12 +2 Monitoring Controllers Supervisory Authorities Apr 10, 2025
€850,000 Network of Agencies and Companies: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 850,000 on a network of agencies and companies. The network operated on behalf of Acea Energia S.p.A. and engaged in aggresive customer… ITALY ·Garante ·Art. 5, 6, 7 +6 Supervisory Authorities Processing Agreement Processing Apr 10, 2025
€8,000 Community of the Eastern Apennines in Parma: Non-compliance with the general principles of data processing. ⇄ 8.000 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +2 Controllers Processing Supervisory Authorities Apr 10, 2025
€15,000 Immobiliare Valdalpone S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on Immobiliare Valdalpone S.r.l. The controller obtained personal data of potential customers by Realmaps S.r.l., which obtained… ITALY ·Garante ·Art. 5, 6, 7 +8 Direct Marketing Personal Data Controllers Apr 10, 2025
€5M Luka Inc.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 5,000,000 on Luka Inc. The developer created a chatbot called Replika with a written and voice interface. It is based on a generative AI… ITALY ·Garante ·Art. 5, 6, 12 +3 Controllers Personal Data Supervisory Authorities Apr 10, 2025
€5,000 Gynaecologist: Insufficient fulfilment of information obligations The Hellenic DPA has imposed a fine of EUR 5,000 on a gynaecologist. The controller failed to completely fullfill an information request by a patient. GREECE ·HDPA ·Art. 15 Controllers Supervisory Authorities Healthcare Apr 9, 2025
€5,000 Gynecologist: Insufficient compliance with the information obligation. ⇄ Een boete van €5.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 15 Supervisory Authorities Personal Data Right of Access Apr 9, 2025
€360 SINDICAT CATAC-CTSC: Insufficient cooperation with supervisory authority The Spanish DPA imposed a fine of on SINDICAT CATAC-CTSC. The controller failed to react to a communication attempt by the AEPD. The original fine of EUR 600 was reduced to EUR… SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Controllers Apr 4, 2025
€3,000 BINBOX GLOBAL SERVICES S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on BINBOX GLOBAL SERVICES S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Apr 2, 2025
€4,000 CREMA GAMES, S.L.: Insufficient fulfilment of information obligations The Spanish DPA imposed a fine on CREMA GAMES, S.L. The controller failed to fulfill an information request from an online customer. The controller asked the data subject for an… SPAIN ·AEPD ·Art. 15 Personal Data Controllers Supervisory Authorities Mar 28, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Non-compliance with the general principles for data processing. ⇄ Een boete van 120.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Processing Personal Data Mar 28, 2025
€6,600 GRUAS IGNACI, S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on GRUAS IGNACI, S.L. The controller uses too much data to verify a person's identity, which breaches the principle of data minimization.… SPAIN ·AEPD ·Art. 5, 13, 32 Retention Period Controllers Security Mar 28, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on SERVICIOS ESPECIALES, S.A. The case concerned a GDPR breach during an internal workplace conflict investigation: the company shared a report via… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Accountability Personal Data Mar 28, 2025
€12,000 ESTUDIO ALCAZAR DEL GENIL 2022, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine on ESTUDIO ALCAZAR DEL GENIL 2022, S.L. The controller collected property data by having its employees visit and photograph the properties,… SPAIN ·AEPD ·Art. 6, 14 Controllers Personal Data Supervisory Authorities Mar 28, 2025
€18,000 Multiple Companies: Insufficient legal basis for data processing The Italian DPA imposed fines on 3 companies which ammount to EUR 6,000 each. The fined companies (Powerfit s.s.d.a.r.l., Soleo s.s.d.a.r.l. and Zero Due Villa s.s.d.a.r.l.) run a… ITALY ·Garante ·Art. 5, 6, 12 +1 Right to be Forgotten Marketing Consent Mar 27, 2025
€3,000 Municipality of Palma di Montechiaro: Lack of appointment of data protection officer The Italian DPA has imposed a fine of EUR 3,000 on the Municipality of Palma di Montechiaro. The controller failed to appoint a DPO and report the DPO to the DPA. ITALY ·Garante ·Art. 37 Public Authority Supervisory Authorities Controllers Mar 27, 2025