Skip to content
Content type · 2,636 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

201–250 of 2,636 sort newestlargest fineoldest
€20,000 Tensa Art Design S.A: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 20,000 onTensa Art Design S.A.The DPA began investigating the controller's data processing activities, but the controller failed to… ROMANIA ·ANSPDCP ·Art. 58, 83 Supervisory Authorities Supervision Controllers Feb 5, 2026
€284,450 MediaLab.AI, Inc.: Insufficient legal basis for data processing The UK DPA has imposed a fine of GBP 247,590 (EUR 284,450) on MediaLab.AI, Inc.The controller of the image-sharing and hosting platform Imgur failed to implement age verification.… UNITED KINGDOM ·ICO ·Insufficient legal basis for data processing Minors Controllers Consent Feb 5, 2026
€4,200 Obuda University: Insufficient legal basis for data processing Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined Obuda University €4,200 on 2026-02-05 for: Insufficient legal basis for data… Hungary ·NAIH ·Art. 5, 6, 9 Processing Education Public Authority Feb 5, 2026
€2.7M DPD Polska sp. z o.o.: Insufficient data processing agreement ⇄ Polish National Personal Data Protection Office (UODO) fined DPD Polska sp. z o.o. €2,682,000 on 2026-02-05 for: Insufficient data processing agreement. Poland ·UODO ·Art. 5, 24, 29 +1 Processing Agreement Processors Personal Data Feb 5, 2026
€10,000 GENPACT ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Feb 4, 2026
€25,000 Municipality of Zoetermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Zoetermeer. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Huizen: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Huizen. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Gooise Meren: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Gooise Meren. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€1,000 Alliance for the Union of Romanians (AUR) Party: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on the Alliance for the Union of Romanians (AUR) Party. The controller failed to react adequately to a data subject's request to… ROMANIA ·ANSPDCP ·Art. 12, 15, 17 +1 Personal Data Controllers Supervisory Authorities Feb 3, 2026
€25,000 Municipality of Tilburg: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Tilburg. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Eindhoven: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Eindhoven. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Ede: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Ede. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Hilversum: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Hilversum. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Veenendaal: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Delft: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Delft. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€4,200 Hungarian University of Agriculture and Life Sciences: Insufficient legal basis for data processing Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined Hungarian University of Agriculture and Life Sciences €4,200 on 2026-01-30 for:… Hungary ·NAIH ·Art. 5, 6, 13 Processing Education Public Authority Jan 30, 2026
€10,000 Natural Person: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 10,000 on a natural person. The controller operated a website on which identity cards containing personal data, including special… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 +6 Criminal Data Personal Data Types of Special Categories of Personal Data Jan 30, 2026
€5,000 Dr. Paolo Montemurro: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Dr. Paolo Montemurro €5,000 on 2026-01-29 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 9 Healthcare Processing Cookies Jan 29, 2026
€12,000 Ministero della Cultura: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Ministero della Cultura €12,000 on 2026-01-29 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 12 +3 Supervisory Authorities Processing Employees Jan 29, 2026
€10,000 Istituto tecnico industriale statale “Stanislao Cannizzaro” di Catania: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Istituto tecnico industriale statale “Stanislao Cannizzaro” di Catania €10,000 on 2026-01-29 for: Insufficient legal basis for… Italy ·Garante ·Art. 5, 6, 9 Processing Education Public Authority Jan 29, 2026
€12,000 Istituto San Giuseppe La Salle di Milano: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Istituto San Giuseppe La Salle di Milano €12,000 on 2026-01-29 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 12 +3 Supervisory Authorities Processing Education Jan 29, 2026
€2,000 Federazione Nazionale Ordini Professioni Infermieristiche (FNOPI): Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Federazione Nazionale Ordini Professioni Infermieristiche (FNOPI) €2,000 on 2026-01-29 for: Insufficient legal basis for data… Italy ·Garante ·Art. 5, 6 Processing Cookies Telecommunications Jan 29, 2026
€50,000 Università Telematica e-Campus: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Università Telematica e-Campus €50,000 on 2026-01-29 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6, 9 +1 Processing Education Cookies Jan 29, 2026
DSB Austria: disclosure of health data to court-appointed expert in legal dispute lawful The data subject was involved in a legal dispute before a civil court in which the findings of an expert opinion led to the dismissal of the case. The expert opinion concerned the… DSB-D124.0850/25 ·Art. 9 Health Data Healthcare Types of Special Categories of Personal Data Jan 28, 2026
€15,000 Continental Automotive Products SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 15,000 on Continental Automotive Products SRL. The controller failed to implement adequate technical and organisational measures,… ROMANIA ·ANSPDCP ·Art. 5, 32 Controllers Security Processing Jan 19, 2026
€15,000 Continental Automotive Products SRL: Insufficient technical and organisational measures to ensure information security. ⇄ Boete van €15.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 32 Security Processing Personal Data Jan 19, 2026
€1,200 Dental Clinic: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,200 on a dental clinic. The controller used video surveillance in its clinic for security purposes, including a camera in the doctor's… SPAIN ·AEPD ·Art. 5 Controllers Processing Security Jan 19, 2026
€25,500 DSB · 2025-1.049.138 The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted… Austria ·Art. 5, 6, 12 +1 Legitimate Interest Personal Data Retention Period Jan 19, 2026
DSB · 2026-0.043.390 Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop… 2026-0.043.390 ·Austria ·Art. 5, 12, 13 Personal Data IP Address Fairness & Transparency Jan 16, 2026
€1,500 10214411 The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of security… Italy ·Garante ·Art. 5, 6, 13 +2 Fairness & Transparency Controllers Transparency Jan 16, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organizational measures to ensure information security. ⇄ 8.000 euro boete - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Security Processing Supervisory Authorities Jan 13, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PREMIER RESTAURANTS ROMANIA SRL. The controller failed to implement adequate technical and organisational measures, resulting… ANSPDCP ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Controllers Security Supervisory Authorities Jan 13, 2026
€1M CNIL fines data processor €1,000,000 for unlawful retention, purpose conflict, and no ROPA The data protection authority (DPA) has imposed a fine of 1 million euros on a data processor for failing to delete user personal data, processing that data for purposes that… France Processors Controllers Processing Jan 13, 2026
€200 Medical Student: Insufficient legal basis for data processing The Austrian Data Protection Authority (dsb) fined a medical student €200 for processing personal data without a sufficient legal basis under GDPR Article 6(1)(f) and Article… Austria ·DSB ·Art. 6, 9 Legitimate Interest Types of Special Categories of Personal Data Personal Data Jan 12, 2026
€1.7M CNIL fines data processor €1.7M for misconfigured disability-records software causing The data protection authority (DPA) has imposed a fine of €1,700,000 on a data processor that had incorrectly configured a software program. This program processed files related… France Controllers Processors Processing Jan 12, 2026
€200 A medical student (the controller) worked as a ward attendant at a hospital Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the nursing staff immediately when necessary. While assigned to a patient with… 2026-0.016.479 ·Austria ·DSB Legitimate Interest Personal Data Integrity and Confidentiality Principle Jan 12, 2026
€8,000 KVIKU SPAIN, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 8,000 on KVIKU SPAIN, S.L.The controller requires customers to send a photo of themselves holding their ID card when verifying their… AEPD ·Art. 5 ·Non-compliance with general data processing principles Retention Period Controllers Processing Jan 10, 2026
€500 VOX ESPAÑA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500 on VOX ESPAÑA. The controller, a political party, posted a picture of of a receipt on its Facebook page. The picture of the recipt… SPAIN ·AEPD ·Art. 6 Personal Data Controllers IP Address Jan 10, 2026
The controller, an Austrian registered association, operates a therapy centre for psychosomatic illnesses The data subject was a patient of the controller. On 28 July 2025, the data subject sent an access request by email under Article 15 GDPR, asking for full information on all… DSB-D124.2437/25 ·Austria ·DSB Right of Access Personal Data Controllers Jan 9, 2026
€18,500 Commander of the Municipal Police of Krakow: Failure to Comply with General Data Protection Principles ⇄ 18.500 euro boete - Poolse nationale autoriteit voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Non-compliance with general data processing principles Law Enforcement Health Data Education Jan 9, 2026
€18,500 Komendanta Miejskiego Policji w Krakowie: Non-compliance with general data processing principles The Polish DPA has imposd a fine of EUR 18,500 on the Komendanta Miejskiego Policji w Krakowie. The controller published personal data, including health data, of a data subject… POLAND ·UODO ·Non-compliance with general data processing principles Personal Data Education Public Authority Jan 9, 2026
€10,000 Headquarter of a Fire Brigade: Insufficient legal basis for data processing The Greek DPA has imposed a fine of EUR 10,000 on a Fire Brigade Head Quarter. The controller had stored health data of an employee which had been in relation with her sick leave.… GREECE ·HDPA ·Art. 5 Controllers Processing Health Data Jan 8, 2026
€2,000 Money Seeds S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Money Seeds S.R.L. The controller failed to fulfil a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervisory Authorities Jan 8, 2026
VDAI (Lithuania) - Decision no. 3R-1700. ⇄ Facts: The Data Protection Authority (DPA) ruled that a gambling provider had lawfully transferred data to a processor for the purpose of sending invitations to sporting events,… 3R-1700 ·Litouwen Controllers Fairness & Transparency Personal Data Jan 7, 2026
€5,000 Sole Trader: Non-compliance with general data processing principles Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Sole Trader €5,000 on 2026-01-06 for: Non-compliance with general data processing principles. Slovenia ·IP-RS ·Art. 5 Processing Supervision IP Address Jan 6, 2026
€80,000 ONE WAY PRIVATE COMPANY: Non-compliance with general data processing principles The Greek DPA has imposed a fine of EUR 80,000 on ONE WAY PRIVATE COMPANY. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… GREECE ·HDPA ·Art. 5, 6, 7 +2 Processors Controllers Personal Data Dec 31, 2025
€10,000 Thessaloniki–Thessaly Gas Supply Company S.A.: Insufficient data processing agreement The Greek DPA has imposed a fine of EUR 10,000 on Thessaloniki–Thessaly Gas Supply Company S.A. The controller, an energy provider, used external processors for direct marketing… GREECE ·HDPA ·Art. 28, 32 Controllers Processors Supervisory Authorities Dec 31, 2025
€10,000 Roumasport S.R.L: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van €10.000 - De Roemeense nationale toezichthouder op de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Dec 30, 2025
€600 GERMANY DPA: Insufficient legal basis for data processing Unlawful use of a dashcam Art. 6 ·Insufficient legal basis for data processing Supervisory Authorities Processing Processing Agreement