Skip to content
Content type · 2,395 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

251–300 of 2,395 sort newestlargest fineoldest
DSB: Art. 15 GDPR access right does not extend to full documents with third-party data The data protection authority (DPA) has determined that, according to Article 15 of the GDPR, an individual has the right to access personal data relating to them, but this right… 2025-0.395.497 ·Austria ·Art. 15 Right of Access Personal Data Supervisory Authorities Jan 12, 2026
€200 Medical Student: Insufficient legal basis for data processing The Austrian Data Protection Authority (dsb) fined a medical student €200 for processing personal data without a sufficient legal basis under GDPR Article 6(1)(f) and Article… Austria ·DSB ·Art. 6, 9 Legitimate Interest Types of Special Categories of Personal Data Personal Data Jan 12, 2026
€500 VOX ESPAÑA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500 on VOX ESPAÑA. The controller, a political party, posted a picture of of a receipt on its Facebook page. The picture of the recipt… SPAIN ·AEPD ·Art. 6 Personal Data Controllers IP Address Jan 10, 2026
€18,500 Commander of the Municipal Police of Krakow: Failure to Comply with General Data Protection Principles ⇄ 18.500 euro boete - Poolse nationale autoriteit voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Non-compliance with general data processing principles Law Enforcement Health Data Education Jan 9, 2026
The controller, an Austrian registered association, operates a therapy centre for psychosomatic illnesses The data subject was a patient of the controller. On 28 July 2025, the data subject sent an access request by email under Article 15 GDPR, asking for full information on all… DSB-D124.2437/25 ·Austria ·DSB Right of Access Personal Data Controllers Jan 9, 2026
€18,500 Komendanta Miejskiego Policji w Krakowie: Non-compliance with general data processing principles The Polish DPA has imposd a fine of EUR 18,500 on the Komendanta Miejskiego Policji w Krakowie. The controller published personal data, including health data, of a data subject… POLAND ·UODO ·Non-compliance with general data processing principles Personal Data Education Public Authority Jan 9, 2026
€27M FREE MOBILE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 27,000,000 on FREE MOBILE. The controller suffered a data breach due to insufficient technical and organisational measures. This was… FRANCE ·CNIL ·Art. 5, 32 Personal Data Controllers Security Jan 8, 2026
€27M FREE MOBILE: Insufficient technical and organizational measures to ensure information security. ⇄ 27 miljoen euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 5, 32 Security Controllers Personal Data Jan 8, 2026
€15M FREE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 15,000,000 on FREE. The controller suffered a data breach due to insufficient technical and organisational measures. This was caused by… FRANCE ·CNIL ·Art. 32, 34 Data Breaches Security Controllers Jan 8, 2026
€2,000 Money Seeds S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Money Seeds S.R.L. The controller failed to fulfil a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervisory Authorities Jan 8, 2026
€2,000 Money Seeds S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. ⇄ The Romanian supervisory authority ANSPDCP has imposed a fine of 2,000 euros on Money Seeds S.R.L., a financial and consultancy company, for failing to honor a data subject's… ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervision Jan 8, 2026
Decision No. 3R-1700. Facts: The data protection authority (DPA) ruled that a gambling operator had lawfully transferred data to a processor for the purpose of sending invitations to sporting events,… 3R-1700 ·Lithuania ·VDAI Personal Data Fairness & Transparency Processors Jan 7, 2026
AEPD: fines of €400,000 and €300,000 for telecom providers in SIM card fraud ⇄ Facts: The Data Protection Authority has imposed a fine of 400,000 euros on a telephone company for unlawfully changing the ownership of a mobile phone subscription and issuing a… EXP202306073 ·Spanje Telecommunications Personal Data Supervisory Authorities Jan 7, 2026
VDAI (Lithuania) - Decision no. 3R-1700. ⇄ Facts: The Data Protection Authority (DPA) ruled that a gambling provider had lawfully transferred data to a processor for the purpose of sending invitations to sporting events,… 3R-1700 ·Litouwen Controllers Fairness & Transparency Personal Data Jan 7, 2026
DSB: complaint against Austrian media company dismissed, but cookie banner instruction issued ⇄ An Austrian media company (the controller) that published local news operated a website that collected personal data from visitors using cookies and a cookie consent banner. The… 2025-0.276.820 ·Oostenrijk Cookies Personal Data Right to be Forgotten Jan 7, 2026
€6,820 Austrian media company fined €6,820 for failing to comply with order to fix cookie banner An Austrian media company has been fined €6,820 by the Data Protection Authority because it failed to implement a binding instruction to modify the cookie banner on its website.… Austria ·DSB ·Art. 58 Right to be Forgotten Supervisory Authorities Cookies Jan 7, 2026
€232,379 Polish Postal Service: Lack of appointment of data protection officer The Polish DPA has imposed a fine of EUR 232,379 on the Polish Postal Service. The controller appointed a person as DPO who also held a managerial position with authority over… POLAND ·UODO ·Art. 38 Supervisory Authorities Controllers Personal Data Jan 2, 2026
€6,000 I Mathisi: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) fined I Mathisi €6,000 on 2025-12-31 for: Insufficient fulfilment of data subjects rights. Greece ·HDPA ·Art. 12, 15, 31 Personal Data Supervisory Authorities Education Dec 31, 2025
€10,000 SIGMA & KAPPA IMPORTING SOCIÉTÉ ANONYME: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 10,000 on SIGMA & KAPPA IMPORTING SOCIÉTÉ ANONYME. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A.… GREECE ·HDPA ·Art. 32 Processors Controllers Security Dec 31, 2025
€5,000 REVMA PLUS Retail S.A.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 5,000 on REVMA PLUS Retail S.A.. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… GREECE ·HDPA ·Art. 32 Controllers Processors Personal Data Dec 31, 2025
€10,000 Thessaloniki–Thessaly Gas Supply Company S.A.: Insufficient data processing agreement The Greek DPA has imposed a fine of EUR 10,000 on Thessaloniki–Thessaly Gas Supply Company S.A. The controller, an energy provider, used external processors for direct marketing… GREECE ·HDPA ·Art. 28, 32 Controllers Processors Supervisory Authorities Dec 31, 2025
€80,000 ONE WAY PRIVATE COMPANY: Non-compliance with general data processing principles The Greek DPA has imposed a fine of EUR 80,000 on ONE WAY PRIVATE COMPANY. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… GREECE ·HDPA ·Art. 5, 6, 7 +2 Controllers Processors Personal Data Dec 31, 2025
€27,000 Vodafone España, S.A.U.: Inadequate compliance with data subjects' rights in the processing of personal data. ⇄ Een boete van 27.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Personal Data Processing Accountability Dec 30, 2025
€27,000 Vodafone España, S.A.U.: Insufficient fulfilment of data subjects rights Although the complainant (a former Vodafone customer) had requested Vodafone to delete his data in 2015 and this request had been confirmed by the company, he received more than… SPAIN ·AEPD ·Art. 5 Personal Data Telecommunications Supervisory Authorities
SLOVAKIA DPA: Insufficient legal basis for data processing Personal data have been unlawfully published on the website of a city within the framework of fulfilling its disclosure obligation under the Freedom of Information Act. However,… Slovak Data Protection Office ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Consent Processing
SLOVAKIA DPA: Insufficient technical and organisational measures to ensure information security Documents containing personal data were disposed of in the area of the municipal garbage dump. Slovak Data Protection Office ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Supervisory Authorities
€10,000 Roumasport S.R.L: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van €10.000 - De Roemeense nationale toezichthouder op de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Dec 30, 2025
€3,140 UniCredit Bank Czech Republic and Slovakia, a.s.: Insufficient legal basis for data processing The bank established a personal bank account for a data subject without his consent or knowledge. The bank supposedly had his personal data available because the subject had… ÚOOÚ (CZ) ·Art. 6 ·Insufficient legal basis for data processing Personal Data Consent Insurance
€12,000 Madrileña Red de Gas: Insufficient technical and organizational measures to ensure information security. ⇄ 12.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 32 Security Personal Data Privacy by Design & Default Dec 30, 2025
€10,000 Ikea Ibérica: Insufficient legal basis for data processing The company installed cookies on an end users terminal device without prior consent of the data subject. SPAIN ·AEPD ·Art. 6 Consent Personal Data Cookies
€118 GERMANY DPA: Insufficient legal basis for data processing Illegal disclosure of personal data relating to a third party. Art. 6 ·Insufficient legal basis for data processing Personal Data Supervisory Authorities Processing Agreement
€10,000 Ikea Ibérica: Insufficient legal basis for the processing of personal data. ⇄ Boete van €10.000 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6 Personal Data Processing Consent Dec 30, 2025
€960 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined a data controller EUR 1,450 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 58 ·Insufficient cooperation with supervisory authority Supervision Supervisory Authorities Controllers
SLOVAKIA, DPA: Insufficient compliance with data subjects' rights. ⇄ Slovaakse Autoriteit voor Gegevensbescherming. Slovak Data Protection Office ·Art. 15 ·Insufficient fulfilment of data subjects rights Right of Access Personal Data Controllers Dec 30, 2025
€3,140 UniCredit Bank Czech Republic and Slovakia, a.s.: Insufficient legal basis for data processing. ⇄ Boete van €3.140 - Tsjechische Autoriteit voor Gegevensbescherming (UOOU). ÚOOÚ (CZ) ·Art. 6 ·Insufficient legal basis for data processing Personal Data Consent Processing Dec 30, 2025
€12,000 Madrileña Red de Gas: Insufficient technical and organisational measures to ensure information security The gas company did not have appropriate measures in place to verify the identity of the data subject. The person who filed the complaint alleges that the company e-mailed his… SPAIN ·AEPD ·Art. 32 Personal Data Security Law Enforcement
€960 POLAND, Personal Data Protection Authority: Insufficient cooperation with the supervisory authority. ⇄ Een boete van 960 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). UODO ·Art. 58 ·Insufficient cooperation with supervisory authority Personal Data Supervisory Authorities Supervision Dec 30, 2025
SLOVAKIA, Data Protection Authority: Insufficient legal basis for the processing of personal data. ⇄ Slovaakse Autoriteit voor de Bescherming van Persoonsgegevens. Slovak Data Protection Office ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Processing Consent Dec 30, 2025
€60,000 Debt collection agency (GESTIÓN DE COBROS, YO COBRO SL): Insufficient legal basis for the processing of personal data. ⇄ Boete van 60.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Personal Data Processing Accountability Dec 30, 2025
€10,000 Roumasport S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on Roumasport S.R.L The controller failed to implement adequate technical and organisational measures, resulting in multiple… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Dec 30, 2025
€20,000 Telecommunications company: Insufficient legal basis for data processing The Croatian DPA (azop) has imposed a fine of EUR 20,000 on a telecommunications company. A data subject had filed a complaint with the DPA claiming that the company was still… CROATIA ·AZOP ·Art. 5, 6 Personal Data Processing Telecommunications
€9,600 Restaurant (SANTI 3000, S.L.): Insufficient legal basis for the processing of personal data. ⇄ Boete van €9.600 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 6 Processing Personal Data Accountability Dec 30, 2025
€588 Alza.cz a.s.: Insufficient legal basis for the processing of data. ⇄ Een boete van 588 euro - opgelegd door de Tsjechische Autoriteit voor Gegevensbescherming (UOOU). CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 7 Consent Personal Data Processing Dec 30, 2025
€20,000 Telecommunications company: Insufficient legal basis for data processing. ⇄ The Croatian data protection authority (DPA) has imposed a fine of 20,000 euros on a telecommunications company. A data subject had filed a complaint with the DPA, claiming that… CROATIA ·AZOP ·Art. 5, 6 Personal Data Processing Accountability Dec 30, 2025
€588 Alza.cz a.s.: Insufficient legal basis for data processing The company obtained a copy of photographic ID of the personal data subject with his consent, however did not react to his consent withdrawal and continued in processing of his… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 7 Consent Personal Data Processing
€40,000 Slovak Telekom: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 40.000 euro - van het Slowaakse databeschermingskantoor. SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Security Personal Data Controllers Dec 30, 2025
€40,000 Slovak Telekom: Insufficient technical and organisational measures to ensure information security The controller did not take adequate security measures when processing personal data, thereby breaching the obligation to protect the processed personal data. SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Security Controllers Personal Data
€50,000 Social Insurance Agency: Insufficient technical and organisational measures to ensure information security Applications for social benefits from Slovak citizens were sent by post to foreign authorities. These were lost by post, with the result that the whereabouts of these personal… SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Personal Data Security Insurance
€980 Individual entrepreneur - no further details published: Insufficient technical and organisational measures to ensure information security The operator of an online game was exposed to several DDoS attacks which caused the malfunctioning of the servers. The attacker blackmailed the operator stating that the attacks… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 32 Security Personal Data Law Enforcement