Skip to content
Content type · 1,114 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

201–250 of 1,114 sort newestlargest fineoldest
€2.7M Experian Nederland B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 2,700,000 on Experian Nederland B.V. The controller, a company that determines individuals' creditworthiness and sells this information,… THE NETHERLANDS ·AP ·Art. 5, 6, 12 +2 Personal Data Controllers Processing Oct 16, 2025
€2,000 PRIME TRANSACTION SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on PRIME TRANSACTION SA. The controller failed to implement adequate technical and organisational measures, resulting in a data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Oct 16, 2025
€2,000 PRIME TRANSACTION SA: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Processing Oct 16, 2025
€9.2M CAPITA PLC: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 8,000,000 (EUR 9,180,000) on CAPITA PLC. CAPITA PLC acts as the data controller for the CAPITA Group, which has suffered a cyber attack. The… UNITED KINGDOM ·ICO ·Art. 5, 32 Controllers Security Processing Oct 15, 2025
€9.2M CAPITA PLC: Insufficient technical and organizational measures to ensure information security. ⇄ 9.180.000 euro boete - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers Processing Oct 15, 2025
€6.9M CAPITA PENSION SOLUTIONS LIMITED: Inadequate technical and organisational measures to ensure information security. ⇄ Een boete van 6.880.000 euro - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 32 Security Controllers Processors Oct 15, 2025
€6.9M CAPITA PENSION SOLUTIONS LIMITED: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 6,000,000 (EUR 6,880,000) on CAPITA PENSION SOLUTIONS LIMITED. CAPITA PENSION SOLUTIONS LIMITED acts as the data processor for the CAPITA Group,… UNITED KINGDOM ·ICO ·Art. 32 Processors Controllers Security Oct 15, 2025
€5,000 Vellea Home SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Vellea Home SRL. The controller failed to implement adequate technical and organisational measures, resulting in a data breach. ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Oct 13, 2025
€5,000 Vellea Home SRL: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Oct 13, 2025
€6,000 Interprovincial Order of Medical Radiology Technicians and Technical Health Professions in Rehabilitation and Prevention of AQ - CH - PE - TE: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Interprovincial Order of Medical Radiology Technicians and Technical Health Professions in Rehabilitation and Prevention of… ITALY ·Garante ·Art. 5, 6, 37 Controllers Supervisory Authorities Processing Oct 9, 2025
€5,000 FT Solutions S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on FT Solutions S.r.l. The fined entity had been active in direct marketing activities as a data processor. During these… ITALY ·Garante ·Art. 5, 6, 7 +7 Integrity and Confidentiality Principle Processors Controllers Oct 9, 2025
€16,000 Order of Nursing Professions of Pisa: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 16,000 on the Order of Nursing Professions of Pisa. The controller is publishing a list of all professionals within their area of… ITALY ·Garante ·Art. 5, 6 Controllers Processing Healthcare Oct 9, 2025
€25,000 EON ENERGIE ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on EON ENERGIE ROMANIA S.A. The controller failed to implement adequate technical and organisational measures, resulting in a… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Oct 9, 2025
€16,000 Order of Nurses of Pisa: Insufficient legal basis for data processing. ⇄ Een boete van 16.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Health Data Controllers Processing Oct 9, 2025
€25,000 E.ON ENERGIE ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Processing Personal Data Oct 9, 2025
€10,000 Municipality of Moschato–Tavros: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 10,000 on the Municipality of Moschato–Tavros. The controller installed a video surveillance system in a depot to protect municipal… GREECE ·HDPA ·Art. 5, 12, 13 +1 Controllers Processing Supervisory Authorities Oct 9, 2025
€5,000 FT Solutions S.r.l.: Non-compliance with general principles of data processing. ⇄ Een boete van 5.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +7 Processors Processing Controllers Oct 9, 2025
€10,000 Municipality of Moschato–Tavros: Insufficient legal basis for the processing of data. ⇄ Boete van €10.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 12, 13 +1 Processing Controllers Personal Data Oct 9, 2025
€30,000 THE RED KIWI, S.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 30.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 32 Personal Data Processing Controllers Oct 3, 2025
€30,000 THE RED KIWI, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 30,000 on THE RED KIWI, S.L. The controller created a WhatsApp group for its customers, disclosing the mobile phone numbers of other… SPAIN ·AEPD ·Art. 5, 32 Controllers Processing Processing Agreement Oct 3, 2025
€195,000 Company: Insufficient fulfilment of data subjects rights The DPA of Hamburg has imposed a fine of EUR 195,000 on a company. The controller was active in direct marketing via post and failed to adequately respond to requests from data… GERMANY ·HmbBfDI ·Insufficient fulfilment of data subjects rights Direct Marketing Personal Data Controllers Sep 30, 2025
€492,000 Company: Non-compliance with general principles for data processing. ⇄ 492.000 euro boete - Autoriteit voor gegevensbescherming van Hamburg (HmbBfDI). GERMANY ·HmbBfDI ·Non-compliance with general data processing principles Meaningful Human Review and Decision-Making Supervisory Authorities Processing Sep 30, 2025
€492,000 Company: Non-compliance with general data processing principles The DPA of Hamburg has imposed a fine of EUR 492,000 on a company in the finance sector. The controller used automated systems to decide whether to approve a credit application,… GERMANY ·HmbBfDI ·Non-compliance with general data processing principles Insurance Controllers Supervisory Authorities Sep 30, 2025
€195,000 Company: Insufficient compliance with data subjects' rights (regarding their personal data). ⇄ 195.000 euro boete - Autoriteit voor gegevensbescherming van Hamburg (HmbBfDI). GERMANY ·HmbBfDI ·Insufficient fulfilment of data subjects rights Personal Data Direct Marketing Marketing Sep 30, 2025
€600 Owner of a Tesla Car: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 600 on the owner of a Tesla car. The controller's car had seven cameras installed, which filmed while the car was in use and while it… AUSTRIA ·DSB ·Art. 5, 6, 12 +1 Controllers Personal Data Supervisory Authorities Sep 29, 2025
€3,000 Comune di Isola del Gran Sasso: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on the Comuni di Isola del Gran Sasso. The controller published a resolution on its institutional website which included the… ITALY ·Garante ·Art. 5, 6, 10 +2 Personal Data Controllers Supervisory Authorities Sep 25, 2025
€32,000 Provincia Autonoma di Bolzano: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 32,000 on the Provincia Autonoma di Bolzan. The controller implemented video surveillance with automated licence plate recognition… ITALY ·Garante ·Art. 5, 6, 12 +4 Controllers Monitoring Supervisory Authorities Sep 25, 2025
€3,000 Municipality of Isola del Gran Sasso: Insufficient legal basis for data processing. ⇄ Een boete van 3.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 10 +2 Public Authority Criminal Data Controllers Sep 25, 2025
€15,000 Vimar S.p.A.: Insufficient legal basis for the processing of data. ⇄ Een boete van 15.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 13 Controllers Processing Consent Sep 25, 2025
€1,000 Green.mec. s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,000 on Green.mec. s.r.l. The controller failed to adequately respond to a former employee's request to exercise their data subject… ITALY ·Garante ·Art. 13, 15 Personal Data Controllers Supervisory Authorities Sep 25, 2025
€3,960 Comune di Pazzano: Insufficient cooperation with supervisory authority The Italian DPA has imposed a fine of EUR 3,960 on the Commune di Pazzano. The controller failed to comply with a order of the DPA. ITALY ·Garante ·Art. 12, 13, 58 Supervision Supervisory Authorities Controllers Sep 25, 2025
€3,960 Municipality of Pazzano: Insufficient cooperation with the supervisory authority. ⇄ Een boete van €3.960 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 12, 13, 58 Controllers Supervisory Authorities Supervision Sep 25, 2025
€840 SERVACE S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 840 on SERVACE S.L. The controller used its employees' private email addresses for internal communication. The original fine of EUR 1,400… SPAIN ·AEPD ·Art. 5, 6 Controllers Processing IP Address Sep 25, 2025
€20,000 S.C. PRIMONET RO S.R.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 20.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Sep 25, 2025
€20,000 S.C. PRIMONET RO S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on S.C. PRIMONET RO S.R.L. The controller failed to implement adequate technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Sep 25, 2025
€10,000 La Prima Srl: Insufficient legal basis for the processing of personal data. ⇄ Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 6, 12, 17 +1 Personal Data Processing Controllers Sep 25, 2025
€32,000 Autonomous Province of Bolzano: Non-compliance with general principles of data processing. ⇄ Een boete van 32.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +4 Controllers Processing Supervisory Authorities Sep 25, 2025
€15,000 Vimar S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on Vimar S.p.A. The controller created an internal and personalised email account with the personal data of a third party, without… ITALY ·Garante ·Art. 5, 6, 13 Controllers Personal Data Supervisory Authorities Sep 25, 2025
€1,000 Green.mec. s.r.l.: Insufficient compliance with data subject rights. ⇄ Een boete van €1.000 - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 13, 15 Right of Access Personal Data Controllers Sep 25, 2025
€35,000 E-Power S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 35,000 on E-Power S.r.l. The controller engaged in direct marketing activities in a way that violated general data processing principles. ITALY ·Garante ·Art. 5, 6, 7 +5 Direct Marketing Controllers Marketing Sep 25, 2025
€10,000 La Prima Srl: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on La Prima Srl. The controller sent direct marketing messages without a legal basis. They also failed to respond to a data… ITALY ·Garante ·Art. 6, 12, 17 +1 Personal Data Controllers Supervisory Authorities Sep 25, 2025
€600 Property manager: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 600 on a porperty manager. The controller operated a website for owners and tenants that did not implement adequate technical and… SPAIN ·AEPD ·Art. 32 Security Controllers Processing Agreement Sep 23, 2025
€3,000 DHL PARCEL IBERIA, S.L.: Violation of the general principles of data processing. ⇄ Een boete van 3.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 32 Controllers Processing Security Sep 22, 2025
€3,000 DHL PARCEL IBERIA, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,000 on DHL PARCEL IBERIA, S.L. The conroller printed the private phone number of the recipient on a parcel, making it visible to third… SPAIN ·AEPD ·Art. 32 Controllers Recipient IP Address Sep 22, 2025
€1,000 Dr. Max SRL: Insufficient compliance with data subjects' rights. ⇄ 1.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 17 Personal Data Processing Supervisory Authorities Sep 18, 2025
€1,000 Dr. Max SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Dr. Max SRL. The controller failed to comply with a data subject's request to delete their personal data. ROMANIA ·ANSPDCP ·Art. 12, 17 Personal Data Controllers Supervisory Authorities Sep 18, 2025
€100,000 SAMARITAINE SAS: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 100,000 on SAMARITAINE SAS. After multiple theft incidents, the controller installed security cameras disguised as smoke detectors to… FRANCE ·CNIL ·Art. 5, 33, 38 Data Breaches Controllers Supervisory Authorities Sep 18, 2025