Content type · 2,395 documents in this view · 3,813 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3589 Processing 2636 Personal Data 2395 Controllers 2018 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
€600 CENTRO MEDICO REY FERNANDO, S.L.P.: Insufficient fulfilment of data subjects rights Spanish Data Protection Authority (aepd) fined CENTRO MEDICO REY FERNANDO, S.L.P. €600 on 2026-03-13 for: Insufficient fulfilment of data subjects rights. Spain · ·Art. 12 Mar 13, 2026
€50,000 ITAS Mutua: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined ITAS Mutua €50,000 on 2026-03-12 for: Insufficient fulfilment of data subjects rights. Italy · ·Art. 5, 12, 13 +2 Mar 12, 2026
€60,000 AEPD: Ramona Films failed to comply with Article 58(2) order to provide processor RAMONA FILMS, S.L., the controller, operated websites offering audiovisual content through subscriptions. In November 2023, the DPA fined the controller in proceedings… Spain ·Art. 28, 58 Mar 9, 2026
€400,000 Italian DPA finds Cerved Group failed to disclose creditworthiness scores in Art. 15 The DPA received several complaints from data subjects concerning Cerved Group S.p.A. (the controller) an Italian credit rating agency. The controller was processing the personal… Italy · ·Art. 5, 12, 15 +3 Mar 7, 2026
€8,000 Altex Romania S.R.L.: Insufficient cooperation with supervisory authority Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Altex Romania S.R.L. €8,000 on 2026-03-05 for: Insufficient cooperation with supervisory… ·Art. 58 ·Insufficient cooperation with supervisory authority Mar 5, 2026
Slovenian DPA: Controller breached Art. 32, 15 and 34 GDPR over data breach and access A controller, not named in the original decision but presumed to be a public institution, notified the Slovenian DPA after experiencing a data breach in relation to its website.… 0612-91/2025/40 ·Slovenia · Mar 4, 2026
€2,000 MALAGASUITE SHOWROOM, S.L.: Insufficient fulfilment of data subjects rights Spanish Data Protection Authority (aepd) fined MALAGASUITE SHOWROOM, S.L. €2,000 on 2026-03-02 for: Insufficient fulfilment of data subjects rights. Spain · ·Art. 13 Mar 2, 2026
€5,000 Suomen Numerokeskus Oy: Insufficient fulfilment of data subjects rights Deputy Data Protection Ombudsman fined Suomen Numerokeskus Oy €5,000 on 2026-03-02 for: Insufficient fulfilment of data subjects rights. Finland · ·Art. 15 Mar 2, 2026
€3,000 Groupharma s.r.l.s.: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Groupharma s.r.l.s. €3,000 on 2026-02-26 for: Insufficient fulfilment of data subjects rights. Italy · ·Art. 5, 12, 15 +1 Feb 26, 2026
€10,000 Radio Immagine Uno S.r.l.: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Radio Immagine Uno S.r.l. €10,000 on 2026-02-26 for: Insufficient fulfilment of data subjects rights. Italy · ·Art. 12 Feb 26, 2026
€2,000 SC Hayat Dent SRL: Insufficient cooperation with supervisory authority Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined SC Hayat Dent SRL €2,000 on 2026-02-20 for: Insufficient cooperation with supervisory… Romania · ·Art. 83 Feb 20, 2026
€5,000 KEAT - Centre for Education & Rehabilitation of the Blind: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) fined KEAT - Centre for Education & Rehabilitation of the Blind €5,000 on 2026-02-20 for: Insufficient fulfilment of data subjects rights. Greece · ·Art. 12, 15 Feb 20, 2026
€3,000 Your Consulting SRL: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Your Consulting SRL €3,000 on 2026-02-19 for: Insufficient technical and organisational… Romania · ·Art. 25, 32 Feb 19, 2026
€1.4M Restaurant Partner Polska: Insufficient legal basis for data processing Polish National Personal Data Protection Office (UODO) fined Restaurant Partner Polska €1,393,300 on 2026-02-19 for: Insufficient legal basis for data processing. Poland · ·Art. 5, 6 Feb 19, 2026
€8,470 Election Committee of Karol Nawrocki: Insufficient legal basis for data processing Polish National Personal Data Protection Office (UODO) fined Election Committee of Karol Nawrocki €8,470 on 2026-02-13 for: Insufficient legal basis for data processing. Poland · ·Art. 5, 6 Feb 13, 2026
€30,000 Sportitalia Società Sportiva Dilettantistica a.r.l.: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Sportitalia Società Sportiva Dilettantistica a.r.l. €30,000 on 2026-02-12 for: Insufficient fulfilment of data subjects rights. Italy · ·Art. 12, 17 Feb 12, 2026
€12,000 Based s.r.l.: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Based s.r.l. €12,000 on 2026-02-12 for: Insufficient fulfilment of data subjects rights. Italy · ·Art. 5, 12, 13 +2 Feb 12, 2026
€30,000 Vodafone – PANAFON A.E.E.T.: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) fined Vodafone – PANAFON A.E.E.T. €30,000 on 2026-02-11 for: Insufficient fulfilment of data subjects rights. Greece · ·Art. 12, 15, 18 Feb 11, 2026
€150,000 The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested a duplicate SIM card for the mobile line of a data subject. The request was… EXP202306354 (PS/00312/2024) ·Spain ·Art. 5, 6 Feb 11, 2026
€5,220 Fundację Lumus: Non-compliance with general data processing principles Polish National Personal Data Protection Office (UODO) fined Fundację Lumus €5,220 on 2026-02-10 for: Non-compliance with general data processing principles. Poland · ·Art. 33, 34, 37 +1 Feb 10, 2026
€2.7M DPD Polska sp. z o.o.: Insufficient data processing agreement ⇄ Polish National Personal Data Protection Office (UODO) fined DPD Polska sp. z o.o. €2,682,000 on 2026-02-05 for: Insufficient data processing agreement. Poland · ·Art. 5, 24, 29 +1 Feb 5, 2026
€20,000 Tensa Art Design S.A: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 20,000 onTensa Art Design S.A.The DPA began investigating the controller's data processing activities, but the controller failed to… ROMANIA · ·Art. 58, 83 Feb 5, 2026
€10,000 GENPACT ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Feb 4, 2026
€25,000 Municipality of Hilversum: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Hilversum. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€1,000 Alliance for the Union of Romanians (AUR) Party: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on the Alliance for the Union of Romanians (AUR) Party. The controller failed to react adequately to a data subject's request to… ROMANIA · ·Art. 12, 15, 17 +1 Feb 3, 2026
€25,000 Municipality of Zoetermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Zoetermeer. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Huizen: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Huizen. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Ede: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Ede. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Delft: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Delft. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Veenendaal: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Gooise Meren: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Gooise Meren. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Eindhoven: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Eindhoven. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Tilburg: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Tilburg. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€10,000 Natural Person: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 10,000 on a natural person. The controller operated a website on which identity cards containing personal data, including special… ROMANIA · ·Art. 5, 6, 9 +6 Jan 30, 2026
DSB Austria: disclosure of health data to court-appointed expert in legal dispute lawful The data subject was involved in a legal dispute before a civil court in which the findings of an expert opinion led to the dismissal of the case. The expert opinion concerned the… DSB-D124.0850/25 ·Art. 9 Jan 28, 2026
€565,000 Sportadmin i Skandinavien AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 565,500 on Sportadmin i Skandinavien AB. The controller suffered a sucessfull cyber attack, resulting in personal and special category… SWEDEN · ·Art. 32 Jan 26, 2026
€5M FRANCE TRAVAIL: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 5,000,000 on FRANCE TRAVAIL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures,… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jan 22, 2026
€25,500 DSB · 2025-1.049.138 The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted… Austria ·Art. 5, 6, 12 +1 Jan 19, 2026
€15,000 Continental Automotive Products SRL: Insufficient technical and organisational measures to ensure information security. ⇄ Boete van €15.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 5, 32 Jan 19, 2026
€15,000 Continental Automotive Products SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Continental Automotive Products SRL. The controller failed to implement adequate technical and organisational measures,… ROMANIA · ·Art. 5, 32 Jan 19, 2026
€1,500 10214411 The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of security… Italy · ·Art. 5, 6, 13 +2 Jan 16, 2026
DSB · 2026-0.043.390 Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop… 2026-0.043.390 ·Austria ·Art. 5, 12, 13 Jan 16, 2026
€21,650 Timegrip AS: Insufficient fulfilment of data subjects rights The Norwegian DPA has imposed a fine of EUR 21,650 on Timegrip AS. The controller had been tracking the working hours of employees at a company that went bankrupt. A former… NORWAY · ·Art. 15 Jan 16, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PREMIER RESTAURANTS ROMANIA SRL. The controller failed to implement adequate technical and organisational measures, resulting… ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Jan 13, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organizational measures to ensure information security. ⇄ 8.000 euro boete - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Jan 13, 2026
€500,000 AEPD fines bank €500,000 for losing customer documents via courier service (Art. 32) Facts: The data protection authority (DPA) has fined a bank €500,000 after documents belonging to a customer were lost during delivery by a courier service. The authority ruled… Spain ·Art. 32 Jan 13, 2026
€1M CNIL fines data processor €1,000,000 for unlawful retention, purpose conflict, and no ROPA The data protection authority (DPA) has imposed a fine of 1 million euros on a data processor for failing to delete user personal data, processing that data for purposes that… France Jan 13, 2026
€200 A medical student (the controller) worked as a ward attendant at a hospital Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the nursing staff immediately when necessary. While assigned to a patient with… 2026-0.016.479 ·Austria · Jan 12, 2026
DSB: Art. 15 GDPR access right does not extend to full documents with third-party data The data protection authority (DPA) has determined that, according to Article 15 of the GDPR, an individual has the right to access personal data relating to them, but this right… 2025-0.395.497 ·Austria ·Art. 15 Jan 12, 2026