Skip to content
Content type · 2,395 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

201–250 of 2,395 sort newestlargest fineoldest
€600 CENTRO MEDICO REY FERNANDO, S.L.P.: Insufficient fulfilment of data subjects rights Spanish Data Protection Authority (aepd) fined CENTRO MEDICO REY FERNANDO, S.L.P. €600 on 2026-03-13 for: Insufficient fulfilment of data subjects rights. Spain ·AEPD ·Art. 12 Personal Data Supervisory Authorities Healthcare Mar 13, 2026
€50,000 ITAS Mutua: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined ITAS Mutua €50,000 on 2026-03-12 for: Insufficient fulfilment of data subjects rights. Italy ·Garante ·Art. 5, 12, 13 +2 Personal Data Supervisory Authorities Employees Mar 12, 2026
€60,000 AEPD: Ramona Films failed to comply with Article 58(2) order to provide processor RAMONA FILMS, S.L., the controller, operated websites offering audiovisual content through subscriptions. In November 2023, the DPA fined the controller in proceedings… Spain ·Art. 28, 58 Controllers Processors Processing Agreement Mar 9, 2026
€400,000 Italian DPA finds Cerved Group failed to disclose creditworthiness scores in Art. 15 The DPA received several complaints from data subjects concerning Cerved Group S.p.A. (the controller) an Italian credit rating agency. The controller was processing the personal… Italy ·Garante ·Art. 5, 12, 15 +3 Supervisory Authorities Personal Data Right of Access Mar 7, 2026
€8,000 Altex Romania S.R.L.: Insufficient cooperation with supervisory authority Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Altex Romania S.R.L. €8,000 on 2026-03-05 for: Insufficient cooperation with supervisory… ANSPDCP ·Art. 58 ·Insufficient cooperation with supervisory authority Supervision Supervisory Authorities Personal Data Mar 5, 2026
Slovenian DPA: Controller breached Art. 32, 15 and 34 GDPR over data breach and access A controller, not named in the original decision but presumed to be a public institution, notified the Slovenian DPA after experiencing a data breach in relation to its website.… 0612-91/2025/40 ·Slovenia ·IP-RS Data Breaches Controllers Supervisory Authorities Mar 4, 2026
€2,000 MALAGASUITE SHOWROOM, S.L.: Insufficient fulfilment of data subjects rights Spanish Data Protection Authority (aepd) fined MALAGASUITE SHOWROOM, S.L. €2,000 on 2026-03-02 for: Insufficient fulfilment of data subjects rights. Spain ·AEPD ·Art. 13 Personal Data Supervisory Authorities Healthcare Mar 2, 2026
€5,000 Suomen Numerokeskus Oy: Insufficient fulfilment of data subjects rights Deputy Data Protection Ombudsman fined Suomen Numerokeskus Oy €5,000 on 2026-03-02 for: Insufficient fulfilment of data subjects rights. Finland ·Deputy Data Protection Ombudsman ·Art. 15 Personal Data Mar 2, 2026
€3,000 Groupharma s.r.l.s.: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Groupharma s.r.l.s. €3,000 on 2026-02-26 for: Insufficient fulfilment of data subjects rights. Italy ·Garante ·Art. 5, 12, 15 +1 Personal Data Supervisory Authorities Employees Feb 26, 2026
€10,000 Radio Immagine Uno S.r.l.: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Radio Immagine Uno S.r.l. €10,000 on 2026-02-26 for: Insufficient fulfilment of data subjects rights. Italy ·Garante ·Art. 12 Personal Data Supervisory Authorities Cookies Feb 26, 2026
€2,000 SC Hayat Dent SRL: Insufficient cooperation with supervisory authority Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined SC Hayat Dent SRL €2,000 on 2026-02-20 for: Insufficient cooperation with supervisory… Romania ·ANSPDCP ·Art. 83 Supervision Supervisory Authorities Personal Data Feb 20, 2026
€5,000 KEAT - Centre for Education & Rehabilitation of the Blind: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) fined KEAT - Centre for Education & Rehabilitation of the Blind €5,000 on 2026-02-20 for: Insufficient fulfilment of data subjects rights. Greece ·HDPA ·Art. 12, 15 Personal Data Supervisory Authorities Education Feb 20, 2026
€3,000 Your Consulting SRL: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Your Consulting SRL €3,000 on 2026-02-19 for: Insufficient technical and organisational… Romania ·ANSPDCP ·Art. 25, 32 Security Personal Data Supervision Feb 19, 2026
€1.4M Restaurant Partner Polska: Insufficient legal basis for data processing Polish National Personal Data Protection Office (UODO) fined Restaurant Partner Polska €1,393,300 on 2026-02-19 for: Insufficient legal basis for data processing. Poland ·UODO ·Art. 5, 6 Personal Data Processing Feb 19, 2026
€8,470 Election Committee of Karol Nawrocki: Insufficient legal basis for data processing Polish National Personal Data Protection Office (UODO) fined Election Committee of Karol Nawrocki €8,470 on 2026-02-13 for: Insufficient legal basis for data processing. Poland ·UODO ·Art. 5, 6 Personal Data Processing Feb 13, 2026
€30,000 Sportitalia Società Sportiva Dilettantistica a.r.l.: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Sportitalia Società Sportiva Dilettantistica a.r.l. €30,000 on 2026-02-12 for: Insufficient fulfilment of data subjects rights. Italy ·Garante ·Art. 12, 17 Personal Data Supervisory Authorities Cookies Feb 12, 2026
€12,000 Based s.r.l.: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Based s.r.l. €12,000 on 2026-02-12 for: Insufficient fulfilment of data subjects rights. Italy ·Garante ·Art. 5, 12, 13 +2 Personal Data Supervisory Authorities Cookies Feb 12, 2026
€30,000 Vodafone – PANAFON A.E.E.T.: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) fined Vodafone – PANAFON A.E.E.T. €30,000 on 2026-02-11 for: Insufficient fulfilment of data subjects rights. Greece ·HDPA ·Art. 12, 15, 18 Personal Data Supervisory Authorities Telecommunications Feb 11, 2026
€150,000 The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested a duplicate SIM card for the mobile line of a data subject. The request was… EXP202306354 (PS/00312/2024) ·Spain ·Art. 5, 6 Integrity and Confidentiality Principle Personal Data Controllers Feb 11, 2026
€5,220 Fundację Lumus: Non-compliance with general data processing principles Polish National Personal Data Protection Office (UODO) fined Fundację Lumus €5,220 on 2026-02-10 for: Non-compliance with general data processing principles. Poland ·UODO ·Art. 33, 34, 37 +1 Personal Data IP Address Processing Feb 10, 2026
€2.7M DPD Polska sp. z o.o.: Insufficient data processing agreement ⇄ Polish National Personal Data Protection Office (UODO) fined DPD Polska sp. z o.o. €2,682,000 on 2026-02-05 for: Insufficient data processing agreement. Poland ·UODO ·Art. 5, 24, 29 +1 Processing Agreement Processors Personal Data Feb 5, 2026
€20,000 Tensa Art Design S.A: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 20,000 onTensa Art Design S.A.The DPA began investigating the controller's data processing activities, but the controller failed to… ROMANIA ·ANSPDCP ·Art. 58, 83 Supervisory Authorities Supervision Controllers Feb 5, 2026
€10,000 GENPACT ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Feb 4, 2026
€25,000 Municipality of Hilversum: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Hilversum. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€1,000 Alliance for the Union of Romanians (AUR) Party: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on the Alliance for the Union of Romanians (AUR) Party. The controller failed to react adequately to a data subject's request to… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 +1 Personal Data Controllers Supervisory Authorities Feb 3, 2026
€25,000 Municipality of Zoetermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Zoetermeer. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Huizen: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Huizen. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Ede: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Ede. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Delft: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Delft. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Veenendaal: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Gooise Meren: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Gooise Meren. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Eindhoven: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Eindhoven. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Tilburg: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Tilburg. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€10,000 Natural Person: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 10,000 on a natural person. The controller operated a website on which identity cards containing personal data, including special… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 +6 Criminal Data Personal Data Types of Special Categories of Personal Data Jan 30, 2026
DSB Austria: disclosure of health data to court-appointed expert in legal dispute lawful The data subject was involved in a legal dispute before a civil court in which the findings of an expert opinion led to the dismissal of the case. The expert opinion concerned the… DSB-D124.0850/25 ·Art. 9 Healthcare Health Data Types of Special Categories of Personal Data Jan 28, 2026
€565,000 Sportadmin i Skandinavien AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 565,500 on Sportadmin i Skandinavien AB. The controller suffered a sucessfull cyber attack, resulting in personal and special category… SWEDEN ·IMY ·Art. 32 Security Controllers Personal Data Jan 26, 2026
€5M FRANCE TRAVAIL: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 5,000,000 on FRANCE TRAVAIL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures,… CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Jan 22, 2026
€25,500 DSB · 2025-1.049.138 The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted… Austria ·Art. 5, 6, 12 +1 Legitimate Interest Personal Data Retention Period Jan 19, 2026
€15,000 Continental Automotive Products SRL: Insufficient technical and organisational measures to ensure information security. ⇄ Boete van €15.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 32 Security Processing Personal Data Jan 19, 2026
€15,000 Continental Automotive Products SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Continental Automotive Products SRL. The controller failed to implement adequate technical and organisational measures,… ROMANIA ·ANSPDCP ·Art. 5, 32 Controllers Security Processing Jan 19, 2026
€1,500 10214411 The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of security… Italy ·Garante ·Art. 5, 6, 13 +2 Fairness & Transparency Controllers Transparency Jan 16, 2026
DSB · 2026-0.043.390 Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop… 2026-0.043.390 ·Austria ·Art. 5, 12, 13 Personal Data IP Address Fairness & Transparency Jan 16, 2026
€21,650 Timegrip AS: Insufficient fulfilment of data subjects rights The Norwegian DPA has imposed a fine of EUR 21,650 on Timegrip AS. The controller had been tracking the working hours of employees at a company that went bankrupt. A former… NORWAY ·Datatilsynet (NO) ·Art. 15 Personal Data Controllers Supervisory Authorities Jan 16, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PREMIER RESTAURANTS ROMANIA SRL. The controller failed to implement adequate technical and organisational measures, resulting… ANSPDCP ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Controllers Security Supervisory Authorities Jan 13, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organizational measures to ensure information security. ⇄ 8.000 euro boete - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Security Processing Supervisory Authorities Jan 13, 2026
€500,000 AEPD fines bank €500,000 for losing customer documents via courier service (Art. 32) Facts: The data protection authority (DPA) has fined a bank €500,000 after documents belonging to a customer were lost during delivery by a courier service. The authority ruled… Spain ·Art. 32 Controllers Security Personal Data Jan 13, 2026
€1M CNIL fines data processor €1,000,000 for unlawful retention, purpose conflict, and no ROPA The data protection authority (DPA) has imposed a fine of 1 million euros on a data processor for failing to delete user personal data, processing that data for purposes that… France Processors Controllers Processing Jan 13, 2026
€200 A medical student (the controller) worked as a ward attendant at a hospital Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the nursing staff immediately when necessary. While assigned to a patient with… 2026-0.016.479 ·Austria ·DSB Legitimate Interest Personal Data Integrity and Confidentiality Principle Jan 12, 2026
DSB: Art. 15 GDPR access right does not extend to full documents with third-party data The data protection authority (DPA) has determined that, according to Article 15 of the GDPR, an individual has the right to access personal data relating to them, but this right… 2025-0.395.497 ·Austria ·Art. 15 Right of Access Personal Data Supervisory Authorities Jan 12, 2026