Skip to content
Content type · 1,280 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

251–300 of 1,280 sort newestlargest fineoldest
€338,000 Telenor ASA.: Non-compliance with general data processing principles The Norwegian DPA has imposed a fine of EUR 333,800 on Telenor ASA. During its investigation, the DPA found that the company had not conducted sufficient assessments and… NORWAY ·Datatilsynet ·Art. 24, 37, 38 Supervisory Authorities IP Address Telecommunications Mar 10, 2025
€600,000 IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on IBERMUTUA, MUTUA COLABORADORA CON LA SEGURIDAD SOCIAL NUM.274. Due to a technical error in its online platform, personal data, including… SPAIN ·aepd ·Art. 5 Healthcare Processing Agreement Controllers Feb 25, 2025
€200,000 ORANGE BANK, S.A. SUCURSAL EN ESPAÑA: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine of EUR 200,000 on ORANGE BANK, S.A. SUCURSAL EN ESPAÑA. The AEPD reacted to multiple complaints of private individuals regarding a data… SPAIN ·aepd ·Art. 5 Processors Controllers Security Feb 14, 2025
€120,000 BEEDIGITAL AI, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine against BEEDIGITAL AI, S.A.. A individual had lodged a complaint with the DPA against the controller because they had received advertising from… SPAIN ·aepd ·Art. 5 Integrity and Confidentiality Principle IP Address Controllers Feb 11, 2025
€500,000 MARINA SALUD, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 500,000 on MARINA SALUD, S.A. Marina Salud, acting as a processor for a health authority, engaged sub-processors without obtaining the… SPAIN ·aepd ·Art. 28 Processors Controllers Processing Agreement Feb 5, 2025
€40,000 Real estate company: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 40,000 on a real estate company for inappropriately monitoring its employees. A software program recorded “periods of inactivity” and… FRANCE ·CNIL ·Art. 5, 6, 12 +3 Monitoring DPIA Audit Logs Feb 4, 2025
€40,000 Orange Romania SA: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 40,000 on Orange Romania SA. The controller failed to fulfil a request for the erasure of data. The controller also execsevly stored and… ANSPDCP ·Art. 5, 6, 7 +2 ·Non-compliance with general data processing principles Controllers IP Address Personal Data Jan 27, 2025
€16,000 CAJA RURAL DEL SUR, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DEL SUR, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers IP Address Jan 17, 2025
€200,000 CAJA RURAL DE SALAMANCA, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE SALAMANCA, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers Processing Agreement Jan 17, 2025
€12,000 CAJA RURAL DE ASTURIAS, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ASTURIAS, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security IP Address Controllers Jan 17, 2025
€12,000 CAJA RURAL DE ARAGÓN, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ARAGÓN, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers IP Address Jan 17, 2025
€12,000 CAJA RURAL DE ONDA, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ONDA, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers IP Address Jan 17, 2025
€10,000 CAJA RURAL NTRA. SRA. DEL ROSARIO: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL NTRA. SRA. DEL ROSARIO. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN ·aepd ·Art. 5 Security Controllers Insurance Jan 17, 2025
€12,000 CAJA RURAL DE ARAGÓN, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ARAGÓN, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers IP Address Jan 17, 2025
€80,000 CAJA RURAL DE ALBACETE, CIUDAD REAL Y CUENCA, S.C.T: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE ALBACETE, CIUDAD REAL Y CUENCA, S.C.T. The controller had suffered a cyber attack in which the attackers were able to access… SPAIN ·aepd ·Art. 5 Security IP Address Processing Agreement Jan 17, 2025
€76,000 CAJA RURAL DE GIJÓN, S.C.A.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE GIJÓN, S.C.A.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers IP Address Jan 17, 2025
€88,000 CAJA RURAL DE EXTREMADURA S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE EXTREMADURA S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN ·aepd ·Art. 5 Security Controllers IP Address Jan 17, 2025
€12,000 CAJA RURAL GRANADA, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL GRANADA, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security Controllers Insurance Jan 17, 2025
€8,000 CAJA RURAL NTRA. SRA. DEL ROSARIO: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL NTRA. SRA. DEL ROSARIO. The controller had suffered a cyber attack in which the attackers were able to access customer data due to… SPAIN ·aepd ·Art. 5 Security Insurance Controllers Jan 17, 2025
€8,000 CAJA RURAL DE BAENA NTRA. SRA. DE GUADALUPE, S.C.C.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE BAENA NTRA. SRA. DE GUADALUPE, S.C.C.A.. The controller had suffered a cyber attack in which the attackers were able to access… SPAIN ·aepd ·Art. 5 Security Controllers IP Address Jan 17, 2025
€8,000 CAJA RURAL NTRA MADRE DEL SOL S.C.A.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL NTRA MADRE DEL SOL S.C.A.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data… SPAIN ·aepd ·Art. 5 Security IP Address Controllers Jan 17, 2025
€2,000 Municipality of Cori: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on the Municipality of Cori. The controller published the names of those receiving food cards intended for people in need on its… ITALY ·Garante ·Art. 6 IP Address Controllers Public Authority Jan 16, 2025
€100,000 Realmaps S.r.l.: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 100,000 on Realmaps S.r.l. The controller collects data on every real estate owner and sells it to customers who use it for direct marketing… ITALY ·Garante ·Art. 5, 6, 7 +12 Controllers Processors Marketing Jan 16, 2025
€72,000 CAJA RURAL CENTRAL, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL CENTRAL, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access customer data due to a… SPAIN ·aepd ·Art. 5 Security IP Address Controllers Jan 16, 2025
€400,000 CAJA RURAL DE JAEN, BARCELONA Y MADRID, S.C.C.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on CAJA RURAL DE JAEN, BARCELONA Y MADRID, S.C.C.. The controller had suffered a cyber attack in which the attackers were able to access… SPAIN ·aepd ·Art. 5 Security IP Address Processing Agreement Jan 16, 2025
€45M Vodafone GmbH: Non-compliance with general data processing principles The Federal Commissioner for Data Protection and Freedom of Information (BfDI) has imposed a fine of EUR 45,000,000 on Vodafone GmbH. The controller failed to properly supervise a… BfDI Controllers Processors IP Address Jan 1, 2025
€200,000 Hospital: Insufficient technical and organisational measures to ensure information security The Belgian DPA has fined a hospital EUR 200,000. The hospital had suffered a ransomware attack through a vulnerability in the server, which paralyzed parts of the computer system… BELGIUM ·APD ·Art. 5, 24, 32 +1 DPIA Security Healthcare Dec 17, 2024
€251M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish Data Protection Commission (DPC) has fined Meta Platforms Ireland Limited EUR 251 million. The fine was imposed for data protection violations related to a data breach… Data Breaches Notification Obligation Integrity and Confidentiality Principle Dec 17, 2024
€70,000 INTERURBANA DE AUTOBUSES, S.A.: Non-compliance with general data processing principles The Spanish DPA has fined INTERURBANA DE AUTOBUSES, S.A. EUR 70,000 after an employee filed a complaint over the publication of personal data on the company's bulletin boards.… SPAIN ·aepd ·Art. 5 Controllers Personal Data Employees Dec 16, 2024
€2,000 Maddaloni municipality: Insufficient involvement of data protection officer The Italian DPA has imposed a fine of EUR 2,000 on Maddaloni municipality for failing to provide the DPA with the contact details of their data protection officer in good time. ITALY ·Garante ·Art. 37 Public Authority Supervisory Authorities Public Sector Dec 14, 2024
€2,000 Torre Annunziata municipality: Insufficient involvement of data protection officer The Italian DPA has imposed a fine of EUR 2,000 on Torre Annunziata municipality for failing to provide the DPA with the contact details of their data protection officer in good… ITALY ·Garante ·Art. 37 Supervisory Authorities Public Authority Public Sector Dec 14, 2024
€3.5M CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 3.5 million on CAIXABANK, S.A. Following a complaint from customers, it was found that the mother of an account holder had access to a… SPAIN ·aepd ·Art. 5, 25 Privacy by Default Privacy by Design Privacy by Design & Default Dec 12, 2024
Lyngby-Taarbæk Municipality: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine between EUR 46,900 and EUR 53,600 on the Lyngby-Taarbæk Municipality. The controller failled to implement sufficient security measures resulting… DENMARK ·Datatilsynet ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Public Authority Nov 27, 2024
€40,000 Maynooth University: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 40,000 on Maynooth University. The controller failed to implement adequate technical and organisational measures, resulting in an… IRELAND ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Security Education Public Authority Nov 22, 2024
€2,300 Company: Non-compliance with general data processing principles The DPA of Luxembourg has issued a fine of EUR 2,300 on a company, that is active in the retail sale of telecommunication equipement in specialised stores. The controller had… LUXEMBOURG ·CNPD ·Art. 5, 6, 13 +2 Video Surveillance Retention Period IP Address Nov 20, 2024
€5M Foodinho Srl: Non-compliance with general data processing principles The Italian DPA has fined the food delivery service Foodinho Srl EUR 5 million for unlawfully processing the data of approximately 35,000 drivers and for several violations of the… ITALY ·Garante ·Art. 2, 5, 6 +11 Employees IP Address Processing Agreement Nov 13, 2024
€29,500 Sligo County Council: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 29,500 on the Sligo County Council. The controller used video surveillance but failed to ensure compliance with the GDPR. They failed to… IRELAND ·Art. 5, 13, 24 +3 ·Non-compliance with general data processing principles Video Surveillance IP Address Security Nov 13, 2024
€2,500 COYARE SLU: Non-compliance with general data processing principles The Spanish DPA fined COYARE SLU EUR 2,500 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This resulted in the unauthorized… SPAIN ·aepd ·Art. 5, 32 IP Address Insurance Processing Agreement Nov 13, 2024
€200,000 Correo Inteligente Postal, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA fined Correo Inteligente Postal, S.L. EUR 200,000 after several incidents of undelivered letters containing personal data were reported. These letters, which… SPAIN ·aepd ·Art. 5, 32 Security IP Address Controllers Nov 11, 2024
€2,000 KAFFA KOFFEE ORGANISATION, S.L.: Non-compliance with general data processing principles The Spanish DPA fined KAFFA KOFFEE ORGANISATION, S.L. EUR 2,000 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This… SPAIN ·aepd ·Art. 5, 32 IP Address Processing Agreement Processing Nov 7, 2024
€1,000 MINAS DE VALDECASTILLO, S.A..: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,000 on MINAS DE VALDECASTILLO, S.A.. The controller had installed video surveillance cameras which, among other things, also covered… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Controllers Monitoring Nov 6, 2024
€15M OpenAI OpCo LLC: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15 million on OpenAI in connection with the operation of the generative AI chatbot “ChatGPT”. The DPA found that OpenAI had violated… ITALY ·Garante ·Art. 5, 6, 12 +4 Fairness & Transparency IP Address Transparency Nov 2, 2024
€5,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA fined Vodafone Romania S.A. EUR 5,000 for sending emails to different recipients without including them in the blind carbon copy (BCC) list. This resulted in the… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Telecommunications IP Address Security Oct 28, 2024
€180,000 IBERCAJA BANCO, S.A.: Insufficient legal basis for data processing The Spanish DPA has fined IBERCAJA BANCO, S.A. for unlawfully accessing a customer’s credit file after the termination of their contractual relationship. The DPA concluded that… SPAIN ·aepd ·Art. 6 IP Address Insurance Processing Agreement Oct 22, 2024
€20,800 Grue municipality: Insufficient technical and organisational measures to ensure information security The Norwegian DPA fined Grue municipality EUR 20,800 following the municipality's notification of a data breach. The municipality reported that personal data of students had been… NORWAY ·Datatilsynet ·Art. 24, 32 Data Breaches Security Education Oct 21, 2024
€9,000 Vilnius District Municipality Administration: Insufficient technical and organisational measures to ensure information security The Lithuanian DPA has imposed a fine of EUR 1,000 on the Vilnius District Municipality Administration. The Municipality Administration had been hacked. The attack resulted in… LITHUANIA ·VDAI ·Art. 5, 32, 34 Public Authority Security Public Sector Oct 18, 2024
€1.3M TELEFÓNICA DE ESPAÑA SAU: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1.3 million on TELEFÓNICA DE ESPAÑA SAU. The controller had reported a security incident to the DPA, stating that they had suffered a… SPAIN ·aepd ·Art. 5 Telecommunications Security IP Address Sep 26, 2024
€250,000 COSMOSPACE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 250,000 on COSMOSPACE. The controller is a company that offers personalized clairvoyance consultations by telephone. As part of its services,… FRANCE ·CNIL ·Art. 5, 9 Controllers Prior Consultation IP Address Sep 26, 2024
€150,000 TELEMAQUE: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 150,000 on TELEMAQUE. The controller is a company that offers digital services in the field of divinatory arts, including fortune telling by… FRANCE ·CNIL ·Art. 5, 9 Controllers IP Address Direct Marketing Sep 26, 2024
€800,000 CEGEDIM SANTÉ: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 800,000 on CEGEDIM SANTÉ. The company, which provides software for medical practices, had transferred customer data for research purposes.… FRANCE ·CNIL ·Art. 5, 66 Anonymization Healthcare IP Address Sep 12, 2024