Skip to content
Content type · 2,256 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

201–250 of 2,256 sort newestlargest fineoldest
€3,000 Cucina di Fabio S.R.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 15, 17 +1 Processing Personal Data Marketing NL Nov 26, 2025
€3,000 Cucina di Fabio S.R.L.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 3,000 on Cucina di Fabio S.R.L. The controller was active in direct marketing activities, using personal data that had not been obtained… ROMANIA ·ANSPDCP ·Art. 6, 15, 17 +1 Direct Marketing Controllers Personal Data Nov 26, 2025
DSB Austria: Online shop violated GDPR by ignoring request to stop gender-specific On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Art. 5, 6, 16 +2 Privacy by Design Privacy by Default Privacy by Design & Default Nov 24, 2025
€4.5M Telecommunicatiebedrijf (exploitant van elektronische communicatienetwerken en -diensten): Overtreding van de algemene principes van gegevensverwerking. Een boete van 4.500.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·azop ·Art. 5, 6, 12 +4 Processors Data Processor Processing NL Nov 24, 2025
€4.5M Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer… CROATIA ·azop ·Art. 5, 6, 12 +4 Processing Agreement Employees Processors Nov 24, 2025
€1.2M IDCQ HOSPITALES Y SANIDAD, S.L.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,200,000 on IDCQ HOSPITALES Y SANIDAD, S.L.U. The controller offered MRI scans as part of its services, and patients could bring copies… SPAIN ·aepd ·Art. 6, 9, 25 Healthcare Healthcare IP Address Nov 21, 2025
€16,650 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 16,650 on a legal entity. The controller stored personal data on a publicly accessible web server without taking sufficient technical… SLOVENIA ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Nov 21, 2025
€2,000 ASOCIACIÓN NACIONAL DE TASADORES Y PERITOS JUDICIALES INFORMÁTICOS: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 2,000 on the ASOCIACIÓN NACIONAL DE TASADORES Y PERITOS JUDICIALES INFORMÁTICOS. The controller published a court ruling which included… SPAIN ·aepd ·Art. 13, 17 Personal Data Controllers Supervisory Authorities Nov 19, 2025
€3,000 Greencorp S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing NL Nov 19, 2025
€3,000 Greencorp S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Greencorp S.R.L. The controller failed to implement adequate technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing Agreement Nov 19, 2025
€80 Journalist: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 80 on a Journalist. The controller published unnecessary private data about a data subject on social media, including their address. AUSTRIA ·dsb ·Art. 5, 6 Personal Data Controllers Social Media Nov 18, 2025
€80 Journalist: Er is onvoldoende juridische basis voor de verwerking van gegevens. 80 euro boete - Oostenrijkse Autoriteit voor Gegevensbescherming (dsb). AUSTRIA ·dsb ·Art. 5, 6 Personal Data Data Controller Processing NL Nov 18, 2025
€8,000 PGS SOFA & CO SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 8.000 euro boete - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing NL Nov 17, 2025
€8,000 PGS SOFA & CO SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PGS SOFA & CO SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures. ROMANIA ·ANSPDCP ·Art. 32 Security Processing Agreement Controllers Nov 17, 2025
€4,750 Powiatowego Inspektora Sanitarnego w Policach: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 4750 on the Powiatowego Inspektora Sanitarnego w Policach. The controller failed to implement adequate technical and organisational… POLAND ·UODO ·Art. 5, 24, 25 +1 Encryption Data Breaches Security Nov 15, 2025
€72,000 AEPD sanctions Tiger Media Inc. for installing advertising cookies without user consent Tiger Media Inc., the controller, operated an advertising platform for publishers and advertisers of adult products and services. The platform acted as an ad network, connecting… Spain ·Art. 6, 27 Legitimate Interest Cookies Marketing Nov 14, 2025
€4,000 Fan Courier Express S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 4,000 on Fan Courier Express S.R.L. The controller failed to adequately react to a data subject's request to exercise their rights, and… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +2 Personal Data Controllers Processing Agreement Nov 12, 2025
€4,000 Fan Courier Express S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 4.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +2 Data Controller Personal Data Controllers NL Nov 12, 2025
€2,000 Whitedecor SRL: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 7, 12 +3 Personal Data Processing Data Controller NL Nov 10, 2025
€2,000 Whitedecor SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on Whitedecor SRL. The controller had sent marketing messages to customers without a sufficient legal basis. ROMANIA ·ANSPDCP ·Art. 6, 7, 12 +3 Direct Marketing Controllers Processing Agreement Nov 10, 2025
€7,000 Klass Wagen S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 7,000 on Klass Wagen S.R.L. The controller suffered a cyber incident due to a former employee exposing the login credentials of… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Law Enforcement Nov 7, 2025
€7,000 Klass Wagen S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van €7.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Controllers NL Nov 7, 2025
€1,000 Bedrijf: Onvoldoende naleving van de rechten van betrokkenen (betreffende hun persoonsgegevens). Boete van €1.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 12, 15 Personal Data Right of Access Data Controller NL Nov 7, 2025
€1,000 Company: Insufficient fulfilment of data subjects rights The Greek DPA has imposed a fine of EUR 1,000 on a Company. The controller failed to react adequately to a data subject's request to exercise their rights. GREECE ·HDPA ·Art. 12, 15 Personal Data Controllers Employees Nov 7, 2025
€2,556 Municipality of Kyustendil: Insufficient legal basis for data processing Bulgarian Commission for Personal Data Protection (KZLD) fined Municipality of Kyustendil €2,556 on 2025-11-01 for: Insufficient legal basis for data processing. Bulgaria ·KZLD ·Insufficient legal basis for data processing Public Authority Education Personal Data Nov 1, 2025
€6,000 APARELLS ORTOPEDICS CURTO, S.L: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 6.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Health Data Healthcare Data Controller NL Oct 28, 2025
€6,000 APARELLS ORTOPEDICS CURTO, S.L: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 6,000 on APARELLS ORTOPEDICS CURTO, S.L. The controller was unable to retain the data it was required to ensure the availability of,… SPAIN ·aepd ·Art. 5 Controllers Personal Data Healthcare Oct 28, 2025
€300,000 SIA 'ZZ Dats': Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 300.000 euro - Inspectie gegevensbescherming (DSI). LATVIA ·DSI ·Art. 32 Security Data Processor Data Breaches NL Oct 28, 2025
€9,450 Gynaecologisch centrum: Onvoldoende naleving van de verplichtingen om datalekken te melden. Boete van €9.450 - Pools Nationaal Bureau voor de Bescherming van Persoonsgegevens (UODO). POLAND ·UODO ·Insufficient fulfilment of data breach notification obligations Data Breaches Health Data Healthcare NL Oct 27, 2025
€9,450 Gynecological Center: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 9,450 on a Gynecological Center. The controller sufferd a data breach and failed to report this to the DPO. POLAND ·UODO ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 27, 2025
€4,000 'Statista Aldo Moro' Higher Education Institute in Fara Sabina: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 4,000 on the 'Statista Aldo Moro' Higher Education Institute in Fara Sabina. The controller published a protocol of disciplinary… ITALY ·Garante ·Art. 5, 6, 37 Personal Data Education IP Address Oct 23, 2025
€5,000 Court Bailiff: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 5,000 on a court bailiff. The controller forwarded a letter containing personal data to the wrong person, failing to inform either the… POLAND ·UODO ·Art. 33, 34 Data Breaches Notification Obligation Article 19 GDPR - Notification of Rectification, Erasure or Restriction Oct 23, 2025
€20,000 Multimedia News Società Cooperativa: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 20,000 on Multimedia News Società Cooperativa. The controller failed to adequatly react to a request by a data subject to exercise their… ITALY ·Garante ·Art. 12 Personal Data Controllers Supervisory Authorities Oct 23, 2025
€20,000 Multimedia News Società Cooperativa: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 20.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 12 Personal Data Data Controller Controllers NL Oct 23, 2025
€15,000 Ordine degli Avvocati di Latina: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on the Ordine degli Avvocati di Latina. The controller published a document relating to criminal proceedings that included… ITALY ·Garante ·Art. 5, 6, 10 Personal Data Education Public Authority Oct 23, 2025
€2,000 Agency for Control of Outstanding Debts S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on the Agency for Control of Outstanding Debts S.R.L. The controller failed to adequatly react to a data subjects request to… ROMANIA ·ANSPDCP ·Art. 12, 15 Controllers Personal Data Supervisory Authorities Oct 22, 2025
€2,000 Bureau voor het innen van openstaande schulden S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Right of Access Personal Data Processing NL Oct 22, 2025
€5,000 S.P.E.E.H. HIDROELECTRICA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on S.P.E.E.H. HIDROELECTRICA SA. A technical error in the controller's computer systems was exploited by attackers to cause a… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing Agreement Oct 20, 2025
€5,000 S.P.E.E.H. HIDROELECTRICA SA: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing NL Oct 20, 2025
€2,000 PRIME TRANSACTION SA: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Personal Data NL Oct 16, 2025
€2,000 PRIME TRANSACTION SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on PRIME TRANSACTION SA. The controller failed to implement adequate technical and organisational measures, resulting in a data… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Oct 16, 2025
€2.7M Experian Nederland B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 2,700,000 on Experian Nederland B.V. The controller, a company that determines individuals' creditworthiness and sells this information,… THE NETHERLANDS ·AP ·Art. 5, 6, 12 +2 Controllers Personal Data Insurance Oct 16, 2025
€2.7M Experian Nederland B.V.: Onvoldoende juridische basis voor de verwerking van gegevens. 2.700.000 euro boete - Nederlandse Autoriteit Persoonsgegevens (AP). THE NETHERLANDS ·AP ·Art. 5, 6, 12 +2 Data Controller Processing Personal Data NL Oct 16, 2025
€5,000 Vellea Home SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Vellea Home SRL. The controller failed to implement adequate technical and organisational measures, resulting in a data breach. ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Oct 13, 2025
€5,000 Vellea Home SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Oct 13, 2025
AEPD sanctions 23andMe for security failures in credential-stuffing breach 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In… PS-00140-2025 ·Spain ·Art. 5, 9, 24 +2 Data Breaches Notification Obligation Integrity and Confidentiality Principle Oct 10, 2025
€25,000 EON ENERGIE ROMANIA S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Data Breaches Controllers NL Oct 9, 2025
€5,000 FT Solutions S.r.l.: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van 5.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +7 Processing Data Processor Processors NL Oct 9, 2025
€25,000 EON ENERGIE ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on EON ENERGIE ROMANIA S.A. The controller failed to implement adequate technical and organisational measures, resulting in a… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processing Agreement Oct 9, 2025