Skip to content
Content type · 3,589 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

201–250 of 3,589 sort newestlargest fineoldest
HUF 10M NAIH-4462-5-2026 The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Personal Data Fairness & Transparency Accountability Apr 30, 2026
€277,500 Permanent TSB plc: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Permanent TSB plc €277,500 for failing to implement sufficient technical and organisational measures to ensure information security,… Ireland ·DPC ·Art. 5, 32, 33 Notification Obligation Data Breaches Supervision Apr 30, 2026
€2,500 BLUE PROJECTS INDUSTRIES S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined BLUE PROJECTS INDUSTRIES S.R.L. €2,500 on 2026-04-30 for: Insufficient technical and… Romania ·ANSPDCP ·Art. 32 Security Personal Data Supervision Apr 30, 2026
€1,790 Mayor of the City and Municipality of Myślenice: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined the Mayor of the City and Municipality of Myślenice €1,790 for insufficient fulfilment of personal data breach notification obligations under Article… Poland ·UODO ·Art. 33 Notification Obligation Data Breaches Supervisory Authorities Apr 30, 2026
€8,600 Matera Local Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the Matera Local Health Authority €8,600 for failing to implement sufficient technical and organizational measures to ensure… Italy ·Garante ·Art. 5, 32 Security Personal Data Supervision Apr 29, 2026
€100,000 Lepida S.c.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Lepida S.c.p.A. €100,000 for violating general data processing principles under the GDPR. The enforcement action addressed… Italy ·Garante ·Art. 5, 13, 25 +1 Retention Period Storage Limitation Security Apr 29, 2026
€34,000 Pianeta S.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Pianeta S.r.l. €34,000 for violations of multiple GDPR provisions, including Article 5(1)(a) and (b) on general data… Italy ·Garante ·Art. 5, 6, 12 +5 Personal Data Processing Supervision Apr 29, 2026
€4,000 Montelibretti State Comprehensive School: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Montelibretti State Comprehensive School €4,000 for lacking a sufficient legal basis for its data processing activities. The… Italy ·Garante ·Art. 5, 6, 9 Personal Data Healthcare Processing Apr 29, 2026
€5,000 Dr. Guzzo: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Dr. Guzzo €5,000 for processing personal data without a sufficient legal basis. The violation concerned healthcare data and… Italy ·Garante ·Art. 5, 9 Retention Period Controllers Healthcare Apr 29, 2026
€12,000 Ministry of Justice: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Ministry of Justice €12,000 for insufficient legal basis for personal data processing. The enforcement action, decided on… Italy ·Garante ·Art. 5, 6, 9 Fairness & Transparency Personal Data Healthcare Apr 29, 2026
€15,000 Nouva Corrente S.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Nouva Corrente S.r.l. €15,000 for non-compliance with general data processing principles under the GDPR. The enforcement… Italy ·Garante ·Art. 1, 2, 5 +3 Personal Data Supervision Consent Apr 29, 2026
€240 Posada del León de Oro: Non-compliance with general data processing principles Spanish Data Protection Authority (aepd) fined Posada del León de Oro €240 on 2026-04-28 for: Non-compliance with general data processing principles. Spain ·AEPD ·Art. 5, 13 Supervisory Authorities Processing IP Address Apr 28, 2026
€35,000 Crowd Entertainment Ltd: Insufficient legal basis for data processing Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Crowd Entertainment Ltd €35,000 on 2026-04-28 for: Insufficient legal basis for data… Romania ·ANSPDCP ·Art. 5 Personal Data Processing Supervisory Authorities Apr 28, 2026
€1,800 RESIDENCIAL ETXE-LAN, S.L.: Insufficient cooperation with supervisory authority Spanish Data Protection Authority (aepd) fined RESIDENCIAL ETXE-LAN, S.L. €1,800 on 2026-04-28 for: Insufficient cooperation with supervisory authority. Spain ·AEPD ·Art. 58 Supervisory Authorities Supervision Apr 28, 2026
€1,000 Non-Profit Foundation: Insufficient cooperation with supervisory authority Belgian Data Protection Authority (APD) fined Non-Profit Foundation €1,000 on 2026-04-28 for: Insufficient cooperation with supervisory authority. Belgium ·APD/GBA ·Art. 31 Supervisory Authorities Supervision Apr 28, 2026
€4,000 SIPHONE 2020, S.L.: Insufficient legal basis for data processing Spanish Data Protection Authority (aepd) fined SIPHONE 2020, S.L. €4,000 on 2026-04-28 for: Insufficient legal basis for data processing. Spain ·AEPD ·Art. 6, 13 Supervisory Authorities IP Address Employees Apr 28, 2026
€6,000 GATIGOS, S.L.: Insufficient cooperation with supervisory authority Spanish Data Protection Authority (aepd) fined GATIGOS, S.L. €6,000 on 2026-04-28 for: Insufficient cooperation with supervisory authority. Spain ·AEPD ·Art. 58 Supervision Supervisory Authorities Apr 28, 2026
€8,500 Accountancy Firm: Insufficient legal basis for data processing Belgian Data Protection Authority (APD) fined Accountancy Firm €8,500 on 2026-04-23 for: Insufficient legal basis for data processing. Belgium ·APD/GBA ·Art. 5, 6, 12 +1 Processing Supervisory Authorities Employees Apr 23, 2026
€300,000 KONECTA BTO, S.L.: Insufficient technical and organisational measures to ensure information security Spanish Data Protection Authority (aepd) fined KONECTA BTO, S.L. €300,000 on 2026-04-22 for: Insufficient technical and organisational measures to ensure information security. Spain ·AEPD ·Art. 5 Security Supervisory Authorities Apr 22, 2026
€2,000 Business Owner: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Business Owner €2,000 on 2026-04-17 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 13, 32 Processing Supervisory Authorities Apr 17, 2026
€6.6M Poste Italiane S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Poste Italiane S.p.a. €6,624,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 13 +4 Supervisory Authorities Processing IP Address Apr 17, 2026
€2,000 Io e te s.r.l.s.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Io e te s.r.l.s. €2,000 on 2026-04-17 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 13, 88 Supervisory Authorities Processing Apr 17, 2026
€5,000 Framos Italia s.r.l.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Framos Italia s.r.l. €5,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 12 +3 Processing Supervisory Authorities Employees Apr 17, 2026
€6,000 Comune di Campo Calabro: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Comune di Campo Calabro €6,000 on 2026-04-17 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6 Processing Employees Supervisory Authorities Apr 17, 2026
€5.9M Postepay S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Postepay S.p.a. €5,877,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 13 +4 Supervisory Authorities Processing IP Address Apr 17, 2026
OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only… No. 2.1-1/24/397-890-38 ·Estonia ·AKI Controllers Processors Privacy by Design & Default Apr 16, 2026
€6,600 Utility Company: Insufficient legal basis for data processing Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Utility Company €6,600 on 2026-04-15 for: Insufficient legal basis for data processing. Slovenia ·IP-RS ·Art. 5 Processing Supervision IP Address Apr 15, 2026
€400,000 CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined Caixabank, S.A. €400,000 for failing to implement sufficient technical and organizational measures to ensure information… Spain ·AEPD ·Art. 5, 25 Privacy by Design & Default Privacy by Default Privacy by Design Apr 15, 2026
€2,415 UODO reprimands electricity seller for Art. 5, 24, 25, 28, 32 GDPR violations over An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone… Poland ·Art. 5, 24, 25 +2 Processors Integrity and Confidentiality Principle Controllers Apr 13, 2026
€2,500 BLUE PROJECTS S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined BLUE PROJECTS S.R.L. €2,500 on 2026-04-03 for: Insufficient technical and organisational… Romania ·ANSPDCP ·Art. 32 Security Personal Data Supervision Apr 3, 2026
€100M Ridetech International B.V.: Insufficient legal basis for data processing Dutch Supervisory Authority for Data Protection (AP) fined Ridetech International B.V. €100,000,000 on 2026-04-01 for: Insufficient legal basis for data processing. The Netherlands ·AP ·Art. 5, 44, 46 Supervision Supervisory Authorities Processing Apr 1, 2026
€13,491 Legal Person: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Legal Person €13,491 on 2026-03-27 for: Insufficient technical and organisational measures to ensure information… Slovenia ·IP-RS ·Art. 32 Security Supervision IP Address Mar 27, 2026
€3,000 Piacenza Bar Association: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Piacenza Bar Association €3,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6 Processing Education Public Authority Mar 26, 2026
€2,000 Business Owner: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Business Owner €2,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 13, 88 Supervisory Authorities Processing Mar 26, 2026
€32M Intesa Sanpaolo S.p.A.: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) fined Intesa Sanpaolo S.p.A. €31,800,000 on 2026-03-26 for: Insufficient technical and organisational measures to ensure information… Italy ·Garante ·Art. 5, 24, 32 +1 Security Supervisory Authorities Insurance Mar 26, 2026
€1,000 Euro Bangla Minimarket in Jesi: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Euro Bangla Minimarket in Jesi €1,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 88 Processing Employees Supervisory Authorities Mar 26, 2026
€2,000 Physician: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Physician €2,000 on 2026-03-26 for: Insufficient fulfilment of data subjects rights. Italy ·Garante ·Art. 13 Personal Data Supervisory Authorities Healthcare Mar 26, 2026
€2,500 Comune di Cassino: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Comune di Cassino €2,500 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6 Processing Education Public Authority Mar 26, 2026
€3,000 Municipality: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Municipality €3,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6, 9 Processing Public Authority Employees Mar 26, 2026
€5,000 Esselunga S.p.A.: Insufficient fulfilment of data subjects rights Italian Data Protection Authority (Garante) fined Esselunga S.p.A. €5,000 on 2026-03-26 for: Insufficient fulfilment of data subjects rights. Italy ·Garante ·Art. 12, 15 Personal Data Supervisory Authorities Employees Mar 26, 2026
€96,000 Eni S.p.A.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Eni S.p.A. €96,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6 Processing Supervisory Authorities Mar 26, 2026
€2,000 Copacabana s.r.l.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Copacabana s.r.l. €2,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 13, 88 Supervisory Authorities Processing Healthcare Mar 26, 2026
€5,000 Municipality: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Municipality €5,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6, 9 Processing Public Authority Employees Mar 26, 2026
€125,000 RENAULT COMMERCIAL ROUMANIE S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined RENAULT COMMERCIAL ROUMANIE S.R.L. €125,000 on 2026-03-25 for: Insufficient technical and… Romania ·ANSPDCP ·Art. 28, 32 Security Supervisory Authorities Supervision Mar 25, 2026
€6,300 Advertising Agency: Insufficient legal basis for data processing Austrian Data Protection Authority (dsb) fined Advertising Agency €6,300 on 2026-03-24 for: Insufficient legal basis for data processing. Austria ·DSB ·Art. 5, 6, 13 Supervisory Authorities Processing Direct Marketing Mar 24, 2026
€4,000 ING Bank NV Amsterdam – Sucursala București S.A.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined ING Bank NV Amsterdam – Sucursala București S.A. €4,000 on 2026-03-23 for: Insufficient… Romania ·ANSPDCP ·Art. 32 Security Personal Data Supervisory Authorities Mar 23, 2026
€3,000 Public and Private Domain SA: Insufficient legal basis for data processing Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Public and Private Domain SA €3,000 on 2026-03-20 for: Insufficient legal basis for data… Romania ·ANSPDCP ·Art. 5, 6, 12 +1 Personal Data Supervision Supervisory Authorities Mar 20, 2026
The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025 They worked as a manager in the controller’s finance department, with technical and disciplinary responsibility for up to five employees. The controller operated a 360-degree… 2025-0.960.016 ·Austria ·DSB Legitimate Interest Personal Data Controllers Mar 20, 2026
€150,000 ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L. €150,000 for failing to implement sufficient technical and organizational measures to… Spain ·AEPD ·Art. 5 Integrity and Confidentiality Principle Security Personal Data Mar 20, 2026
€3,000 Domeniul Public și Privat SA: Insufficient legal basis for data processing Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Domeniul Public și Privat SA €3,000 on 2026-03-20 for: Insufficient legal basis for data… Romania ·ANSPDCP ·Art. 5, 6, 12 +1 Personal Data Supervision Supervisory Authorities Mar 20, 2026