Skip to content
Content type · 3,429 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

251–300 of 3,429 sort newestlargest fineoldest
€600 4USPORT INSTALACIONES DEPORTIVAS, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 300 on 4USPORT INSTALACIONES DEPORTIVAS, S.L. The controller failed to react to requests made by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Controllers Dec 20, 2025
€300 SPAIN, DPA: Onvoldoende samenwerking met de toezichthoudende instantie. Een boete van 300 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). aepd ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Controllers Data Controller NL Dec 20, 2025
€6,000 BLUE TEAM FLIGHT SCHOOL, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 6,000 on BLUE TEAM FLIGHT SCHOOL, S.L. The controller failed to react to requests made by the DPA. SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Controllers Dec 20, 2025
€32,000 EXCEL HOTELS & RESORTS, S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 32.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Security Controllers Accountability NL Dec 20, 2025
€2,000 Elba Catering Distribuzioni s.r.I.s.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on Elba Catering Distribuzioni s.r.I.s. The controller installed video surveillance, which affected the public road. Furthermore,… ITALY ·Garante ·Art. 5, 13 Video Surveillance Controllers Monitoring Dec 18, 2025
€6,000 Comune di Nave: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Commune di Nave. The controller has installed an automatic licence plate recognition system which processes data on when a… ITALY ·Garante ·Art. 5, 6, 12 +2 DPIA Insurance Privacy Impact Assessment Dec 18, 2025
€120,000 Pioneer Hi-Bred Italia Sementi s.r.l.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 120,000 on Pioneer Hi-Bred Italia Sementi s.r.l. The controller installed satellite telematics tracking devices to monitor driving… ITALY ·Garante ·Art. 5, 6, 28 Monitoring Employees Controllers Dec 18, 2025
€1.5M Bank: Non-compliance with general data processing principles Croatian Data Protection Authority (azop) fined Bank €1,500,000 on 2025-12-18 for: Non-compliance with general data processing principles. Croatia ·azop ·Art. 5, 6, 13 +1 IP Address Human Resources Insurance Dec 18, 2025
€40,000 LTL S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 40,000 on LTL S.p.A. The controller failed to respond within the legal time period to a request by a former employee to exercise their… ITALY ·Garante ·Art. 5, 12, 15 Controllers Personal Data Processing Agreement Dec 18, 2025
€1,000 Data Controller: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on a data controller. The controller disclosed personal data by sending an email to an address that third parties who were not… ITALY ·Garante ·Art. 5, 6 Controllers Personal Data Processing Agreement Dec 18, 2025
€40,000 Anticimex s.r.l.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 40,000 on Anticimex s.r.l. Following termination of employment, the former employer requested to exercise his rights. The controller… ITALY ·Garante ·Art. 5, 12, 13 +2 Controllers Employees Processing Agreement Dec 18, 2025
€175,000 Arnhem and Nijmegen University of Applied Sciences: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 175,000 on Arnhem and Nijmegen University of Applied Sciences. The controller suffered a data breach due to insufficient technical and… THE NETHERLANDS ·AP ·Art. 32 Data Breaches Security Education Dec 15, 2025
€1M MOBIUS SOLUTIONS LTD: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 1,000,000 on MOBIUS SOLUTIONS LTD. The fined entity had been the former data processor for Deezer, which suffered a data breach in 2022.… FRANCE ·CNIL ·Art. 28, 29, 30 Data Breaches Processors Controllers Dec 11, 2025
€75,474 Legal Entity: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 75,474 on a legal entity. Without a sufficient legal basis, the controller installed software on an employee's work computer which… SLOVENIA ·Art. 5, 6 ·Insufficient legal basis for data processing Social Media Controllers Employees Dec 11, 2025
€15,000 Crowd Entertainment Limited: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 15,000 on Crowd Entertainment Limited. The controller failed to adequatly react to a data subjects request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 15 Controllers Personal Data Supervisory Authorities Dec 10, 2025
€15,000 Crowd Entertainment Limited: Onvoldoende naleving van de rechten van betrokkenen (betreffende hun persoonsgegevens). Een boete van €15.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Right of Access Data Controller NL Dec 10, 2025
€98,000 University of Limerick: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined University of Limerick €98,000 on 2025-12-10 for: Insufficient technical and organisational measures to ensure information security. Ireland ·Art. 5, 30, 32 +2 ·Insufficient technical and organisational measures to ensure information security Security Education Public Sector Dec 10, 2025
€1,000 Compania de Apa Oltenia S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 29, 32 Security Processing Controllers NL Dec 8, 2025
€1,000 Compania de Apa Oltenia S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Compania de Apa Oltenia S.A. The controller failed to implement adequate technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 29, 32 Security Social Media Controllers Dec 8, 2025
€5,100 Legal Entity: Insufficient fulfilment of data subjects rights The Slovenian DPA has imposed a fine of EUR 5,100 on a legal entity. The controller operated a website where natural persons could fil in their personal data in a form. The… SLOVENIA ·Art. 12, 13 ·Insufficient fulfilment of data subjects rights Personal Data Controllers Processing Agreement Dec 8, 2025
€1,000 Roverbella Comprehensive School: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on Roverbella Comprehensive School. The controller has sent an email containing a reminder about the vaccination of pupils under… ITALY ·Garante ·Art. 5, 6, 9 Education IP Address Controllers Dec 4, 2025
€1,300 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 1,300 on a legal entity. An employee of the controller stored personal data on her work laptop without securing it, for example by… SLOVENIA ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Encryption Security Controllers Dec 4, 2025
€1,000 'Principe Umberto di Savoia' State Scientific and Linguistic High School: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on 'Principe Umberto di Savoia' State Scientific and Linguistic High School. The controller processed the personal data of… ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Right of Access Healthcare Dec 4, 2025
€12,000 Comune di Tuscania: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 12,000 on the Commune di Tuscania. The controller had been using video surveillance and licence plate recognition within its territory… ITALY ·Garante ·Art. 5, 6, 12 +5 Video Surveillance IP Address Controllers Dec 4, 2025
€2,000 Istituto Comprensivo Centro di Casalecchio di Reno: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 2,000 on Istituto Comprensivo Centro di Casalecchio di Reno. The controller published a ranking of its teachers on its website without a… ITALY ·Garante ·Art. 5, 6 Personal Data Controllers Employees Dec 4, 2025
€72,000 TIGER MEDIA INC.: Insufficient legal basis for data processing Spanish Data Protection Authority (aepd) fined TIGER MEDIA INC. €72,000 on 2025-12-03 for: Insufficient legal basis for data processing. Spain ·aepd ·Art. 6, 27 Telecommunications Processing Supervisory Authorities Dec 3, 2025
Austrian DSB: sharing ADHD diagnosis from public forum post did not breach Art. 9 GDPR A data subject published a post concerning their ADHD diagnosis on a publicly accessible online forum under a pseudonym. A person (the controller) who was a follower of the data… 2025-0.968.031 ·Austria ·Art. 9 Health Data Healthcare Personal Data Dec 3, 2025
€3,600 DELAFRUIT, S.L.: Niet-naleving van de algemene principes voor gegevensverwerking. Boete van €3.600 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Video Surveillance Processing Controllers NL Dec 1, 2025
€3,600 DELAFRUIT, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,600 on DELAFRUIT, S.L. The controller installed video surveillance in the staff break area and dining room, but did not put up the… SPAIN ·aepd ·Art. 5 Video Surveillance Controllers IP Address Dec 1, 2025
€3,600 RISING SUN CAR RENTAL S.L.: Niet-naleving van de algemene principes voor gegevensverwerking. De Spaanse autoriteit voor gegevensbescherming (DPA) heeft RISING SUN CAR RENTAL S.L. een boete van 3.600 euro opgelegd. De verantwoordelijke partij gebruikte videobewaking om de… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Processing Controllers NL Dec 1, 2025
€3,600 RISING SUN CAR RENTAL S..L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,600 on RISING SUN CAR RENTAL S..L. The controller used video surveillance to ensure security at its facility, affecting more areas than… SPAIN ·aepd ·Art. 5, 13 Video Surveillance IP Address Controllers Dec 1, 2025
€1.6M SPRINTER MEGACENTROS DEL DEPORTE, S.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 1.560.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 34 Security Data Breaches Controllers NL Nov 28, 2025
€1.6M SPRINTER MEGACENTROS DEL DEPORTE, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,560,000 on SPRINTER MEGACENTROS DEL DEPORTE, S.L. The controller suffered a cyber attack due to insufficient technical and… SPAIN ·aepd ·Art. 5, 34 Security Controllers Processing Agreement Nov 28, 2025
€40,000 Infobel: Onvoldoende juridische basis voor gegevensverwerking. Een boete van 40.000 euro - De Belgische Autoriteit voor gegevensbescherming (APD). BELGIUM ·APD ·Art. 5, 6, 24 Data Controller Processing Controllers NL Nov 27, 2025
€2,000 Nițu A. Cleopatra – Expert Accountant: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data NL Nov 27, 2025
€1.5M AMERICAN EXPRESS CARTE FRANCE: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 1,500,000 on AMERICAN EXPRESS CARTE FRANCE. The controller used excessive cookies on its website and failed to adequately inform data… CNIL ·Art. 82 ·Insufficient legal basis for data processing Cookies Insurance Controllers Nov 27, 2025
€300,000 Aimag S.p.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 300.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +4 Processing Controllers Data Controller NL Nov 27, 2025
€400,000 Verisure Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 400,000 on Verisure Italy s.r.l. The controller had been active in direkt marketing activities. The controller failed to ensure that the… Garante ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles IP Address Controllers Direct Marketing Nov 27, 2025
€300,000 Aimag S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 300,000 on Aimag S.p.A. The controller offered its customers a service that allowed them to view their consumption data on the… ITALY ·Garante ·Art. 5, 6, 7 +4 IP Address Controllers Processing Agreement Nov 27, 2025
€2,000 Nițu A. Cleopatra – Expert Accountant: Insufficient technical and organisational measures to ensure information security Thr Romanian DPA has imposed a fine of EUR 2,000 on Nițu A. Cleopatra – Expert Accountant. The controller was the target of a successful cyber attack due to the inadequate… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing Agreement Nov 27, 2025
€40,000 Infobel: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 40,000 on Infobel. The controller, a data broker, sold personal data for direct marketing purposes. However, it processed the data it had… BELGIUM ·APD ·Art. 5, 6, 24 Marketing Controllers Direct Marketing Nov 27, 2025
€6,600 Legal Entity: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 6,600 on a legal entity. The controller used GPS trackers to systematically and indiscriminately monitor its employees' activities… SLOVENIA ·Art. 5, 6 ·Insufficient legal basis for data processing Employees Controllers Processing Agreement Nov 26, 2025
€3,000 Cucina di Fabio S.R.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 15, 17 +1 Marketing Personal Data Processing NL Nov 26, 2025
€3,000 Cucina di Fabio S.R.L.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 3,000 on Cucina di Fabio S.R.L. The controller was active in direct marketing activities, using personal data that had not been obtained… ROMANIA ·ANSPDCP ·Art. 6, 15, 17 +1 Direct Marketing Controllers Personal Data Nov 26, 2025
DSB Austria: Online shop violated GDPR by ignoring request to stop gender-specific On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Art. 5, 6, 16 +2 Privacy by Design Privacy by Default Privacy by Design & Default Nov 24, 2025
€4.5M Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer… CROATIA ·azop ·Art. 5, 6, 12 +4 Processing Agreement Employees Fairness & Transparency Nov 24, 2025
€4.5M Telecommunicatiebedrijf (exploitant van elektronische communicatienetwerken en -diensten): Overtreding van de algemene principes van gegevensverwerking. Een boete van 4.500.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·azop ·Art. 5, 6, 12 +4 Data Processor Controllers Processing NL Nov 24, 2025
€5,000 ACTIVOS INTELIGENTES, S.L.: Overtreding van de algemene principes voor gegevensverwerking. Boete van €5.000 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Processing IP Address Accountability NL Nov 23, 2025
€5,000 ACTIVOS INTELIGENTES, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5,000 on ACTIVOS INTELIGENTES, S.L. The controller is asking its guests for selfies with their ID-card to verify their identity,… SPAIN ·aepd ·Art. 5 IP Address Controllers Processing Nov 23, 2025
€16,650 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 16,650 on a legal entity. The controller stored personal data on a publicly accessible web server without taking sufficient technical… SLOVENIA ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Nov 21, 2025