Skip to content
Content type · 1,114 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

251–300 of 1,114 sort newestlargest fineoldest
€100,000 SAMARITAINE SAS: Non-compliance with the general principles of data processing. ⇄ Een boete van 100.000 euro - van de Franse Autoriteit voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 5, 33, 38 Controllers Processing Security Sep 18, 2025
€150,000 DIGI SPAIN TELECOM, S.L.U.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 150,000 on Digi Spain Telecom S.L.U. The controller rejected the application for a contract due to outstanding debt, despite this being… AEPD ·Art. 6 ·Insufficient legal basis for data processing Controllers Telecommunications Processing Agreement Sep 17, 2025
€1.5M SERVICIOS FINANCIEROS CARREFOUR, E.F.C.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,500,000 on SERVICIOS FINANCIEROS CARREFOUR, E.F.C. The controller suffered a successfull cyberattack due to insufficient technical and… SPAIN ·AEPD ·Art. 5 Controllers Security Processing Agreement Sep 17, 2025
€1.5M CARREFOUR FINANCIAL SERVICES, E.F.C.: Insufficient technical and organizational measures to ensure information security. ⇄ 1.500.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Sep 17, 2025
€2,670 POLAND DPA: Lack of appointment of data protection officer The Polish DPA has imposed a fine of EUR 2,670 on an unkonwn company in the health care sector. The controller appointed its CEO as the DPO. UODO ·Art. 38 ·Lack of appointment of data protection officer Supervisory Authorities Controllers Personal Data Sep 12, 2025
€6,000 Company: Insufficient legal basis for the processing of data. ⇄ Een boete van 6.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 13 Processing Personal Data Supervisory Authorities Sep 11, 2025
€18,000 Comune di Nichelino: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 18,000 on the Comune di Nichelino. The controller published the sensitive personal data of a former employee, including the decision to… ITALY ·Garante ·Art. 5, 6, 12 +1 Personal Data Types of Special Categories of Personal Data Controllers Sep 11, 2025
€1,000 Giada FM S.r.l.: Insufficient compliance with data subjects' rights. ⇄ Een boete van €1.000 - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 12, 15 Right of Access Controllers Personal Data Sep 11, 2025
€12,000 Casa di Cura Città di Roma: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 12,000 on the Casa di Cura Città di Roma. The controller used patient management software that gave users access to excessive amounts of… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Controllers Security Sep 11, 2025
€8,000 Migliarino San Rossore Massaciuccoli Regional Park Authority: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 8,000 on Migliarino San Rossore Massaciuccoli Regional Park Authority. The controller published personal data of a job applicant on its… ITALY ·Garante ·Art. 5, 6, 20 Personal Data Controllers Processing Sep 11, 2025
€1,000 Giada FM S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,000 on Giada FM S.r.l. The controller failed to provide an employee with requested certificates. ITALY ·Garante ·Art. 5, 12, 15 Controllers Personal Data Supervisory Authorities Sep 11, 2025
€6,000 Municipality of Buccino: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Municipality of Buccino. The controller published pictures of minors and people with mental health conditions in multiple… ITALY ·Garante ·Art. 5, 6, 9 +2 Public Authority Controllers Supervisory Authorities Sep 11, 2025
€8,000 Migliarino San Rossore Massaciuccoli Regional Park Authority: Insufficient legal basis for the processing of data. ⇄ 8.000 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 20 Controllers Processing Accountability Sep 11, 2025
€12,000 Ministry of the Interior - Department of Firefighters, Public Rescue, and Civil Defense - Provincial Command of Florence: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 12,000 on the Minstry of the Interior. During the Covid-19 pandemic, the controller published a list of employees' with names and… ITALY ·Garante ·Art. 5, 6, 9 Controllers Processing Education Sep 11, 2025
€6,000 Company: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on a company. The controller used video surveillance at its sites, but did not display adequate signs to inform data subjects about… ITALY ·Garante ·Art. 5, 13 Controllers Personal Data Supervisory Authorities Sep 11, 2025
€6,000 Municipality of Buccino: Insufficient legal basis for data processing. ⇄ Een boete van 6.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 +2 Public Authority Controllers Processing Sep 11, 2025
€5,000 Unita Turism Holding S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Unita Turism Holding S.A. The controller did not implement adequate technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Sep 9, 2025
€5,000 Unita Turism Holding S.A.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Sep 9, 2025
€1.8M S-Pankki Oyj: Insufficient technical and organizational measures to ensure information security. ⇄ 1.800.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Privacy by Design Privacy by Default Sep 8, 2025
€1.8M S-Pankki Oyj: Insufficient technical and organisational measures to ensure information security The Finish DPA has imposed a fine of EUR 1,800,000 on S-Pankki Oyj. Due to a software error, customers of the controller were able to log in to the bank accounts of other… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Controllers Processing Agreement Sep 8, 2025
€33,500 Bakery Chain: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 33,500 on a bakery chain. The controller used video surveillance which affected both public areas and areas intended solely for… AUSTRIA ·DSB ·Art. 5, 6 Retention Period Controllers Processing Sep 5, 2025
€3M Allium UPI: Insufficient technical and organisational measures to ensure information security The Estonian DPA has imposed a fine of EUR 3,000,000 on Allium UPI. The controller failed to implement adequate technical and organisational measures to ensure data security. This… ESTONIA ·AKI ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processing Agreement Sep 5, 2025
€870 Company: Insufficient compliance with obligations regarding the notification of data breaches. ⇄ 870 euro boete - Oostenrijkse Autoriteit voor Gegevensbescherming (dsb). AUSTRIA ·DSB ·Art. 33 Data Breaches Supervisory Authorities Controllers Sep 4, 2025
€180,000 Sociedad de Gestión de Activos Procedentes de la Reestructuración Bancaria S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 180,000 on Sociedad de Gestión de Activos Procedentes de la Reestructuración Bancaria S.A. The controller suffered a cyber attack due to… SPAIN ·AEPD ·Art. 5, 28 Controllers Processors Security Sep 4, 2025
€9,700 Landlord: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 9,700 on a Landlord. The controller installed video surveillance in and around a student residence. However, the surveillance was too… BELGIUM ·APD/GBA ·Art. 5, 6 Controllers Processing Video Surveillance Sep 4, 2025
€180,000 Sociedad de Gestión de Activos Procedentes de la Reestructuración Bancaria S.A.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 180.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 28 Security Processors Processing Sep 4, 2025
€870 Company: Insufficient fulfilment of data breach notification obligations The Austrian DPA has imposed a fine of EUR 870 on a company. After being informed of a data breach, the controller took adequate measures to close it but failed to inform the DPA. AUSTRIA ·DSB ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Sep 4, 2025
€200,900 ILVA A/S: Non-compliance with general data processing principles The Danish DPA has imposed a fine of EUR 200,900 on ILVA A/S. The controller failed to implement data deletion deadlines. This led to an infringement of the principle of storage… DENMARK ·Datatilsynet (DK) ·Non-compliance with general data processing principles Storage Limitation Retention Period Controllers Sep 2, 2025
€10,000 La Fântâna S.R.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van €10.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Sep 1, 2025
€150M INFINITE STYLES SERVICES CO. LIMITED: Insufficient legal basis for the processing of personal data. ⇄ 150 miljoen euro boete - Franse Autoriteit voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 82 Personal Data Processing Controllers Sep 1, 2025
€1,200 Company: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,200 on a company. The controller used personal data for a purpose, which did not align with the initial purpose. The original fine of… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Processing Agreement Sep 1, 2025
€200M GOOGLE LLC: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 200,000,000 on GOOGLE LLC. While creating an account for the controller's services, the controller designed the cookie consent process in… FRANCE ·CNIL ·Art. 82 Controllers Personal Data Cookies Sep 1, 2025
€150M INFINITE STYLES SERVICES CO. LIMITED: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 150,000,000 on INFINITE STYLES SERVICES CO. LIMITED, which operates under the name 'SHEIN'. The controller used cookies unlawfully on its… FRANCE ·CNIL ·Art. 82 Controllers Personal Data Cookies Sep 1, 2025
€200M GOOGLE LLC: Insufficient legal basis for the processing of data. ⇄ 200 miljoen euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 82 Controllers Personal Data Processing Sep 1, 2025
€10,000 La Fântâna S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on La Fântâna S.R.L. The controller suffered a cyber attack due to insufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Sep 1, 2025
€125M GOOGLE IRELAND LIMITED: Insufficient legal basis for the processing of data. ⇄ 125.000.000 euro boete - Franse Autoriteit voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 82 Controllers Personal Data Processing Sep 1, 2025
€125M GOOGLE IRELAND LIMITED: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 125,000,000 on GOOGLE IRELAND LIMITED. While creating an account for the controller's services, the controller designed the cookie consent… FRANCE ·CNIL ·Art. 82 Controllers Personal Data Cookies Sep 1, 2025
€2,000 GESTIÓN DE VENTAS IBERIA S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 2,000 on GESTIÓN DE VENTAS IBERIA S.L. The controller contacted a data subject for direct marketing purposes, thereby violating local… SPAIN ·AEPD ·Art. 14 Personal Data Controllers Marketing Aug 31, 2025
€2,000 GESTIÓN DE VENTAS IBERIA S.L.: Insufficient compliance with data subjects' rights. ⇄ Een boete van 2.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 14 Personal Data Marketing Controllers Aug 31, 2025
€2,400 KVIKU SPAIN, S.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 2.400 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). AEPD ·Art. 6 ·Insufficient legal basis for data processing Personal Data Processing Consent Aug 29, 2025
€1,200 GOHIPOTECA, S.L.: Insufficient legal basis for the processing of personal data. ⇄ 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6 Personal Data Processing Controllers Aug 29, 2025
€2,400 KVIKU SPAIN, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,400 on KVIKU SPAIN, S.L. The controller processed personal data of a data subject without sufficient consent. The original fine of EUR… AEPD ·Art. 6 ·Insufficient legal basis for data processing Personal Data Consent Controllers Aug 29, 2025
€1,200 GOHIPOTECA, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR on GOHIPOTECA, S.L. The controller processed data of a data subject without a sufficient legal basis. The contract used as the basis for… SPAIN ·AEPD ·Art. 6 Controllers Personal Data Insurance Aug 29, 2025
€4.3M ING Bank Śląski: Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 4,323,250 on ING Bank Śląski. The controller scanned the identity documents of every customer and potential customer without a sufficient… POLAND ·UODO ·Art. 5, 6 Controllers Personal Data Processing Aug 26, 2025
€300 Driving School: Insufficient Compliance with Information Obligations. ⇄ Een boete van 300 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 13 Controllers Personal Data Processing Aug 26, 2025
€300 Driving School: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 300 on a driving school. The controller has installed video surveillance, but failed to adequatly inform data subjects. The original fine… SPAIN ·AEPD ·Art. 13 Personal Data Controllers Supervisory Authorities Aug 26, 2025
€5,400 YUNEXPRESS SPAIN, S.L.: Insufficient data processing agreement The Spanish DPA has imposed a fine of EUR 5,400 on YUNEXPRESS SPAIN, S.L. The controller used a data processor and failed to sign a sufficient data processing agreement. The… AEPD ·Art. 5, 28 ·Insufficient data processing agreement Processors Controllers Processing Aug 25, 2025
€1,800 LEIVA BUS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,800 on LEIVA BUS, S.L. The controller leaked personal data due to insufficient technical and organisational measures to ensure data… SPAIN ·AEPD ·Art. 5 Security Controllers Personal Data Aug 25, 2025
€1,800 LEIVA BUS, S.L.: Insufficient technical and organizational measures to ensure information security. ⇄ 1.800 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Aug 25, 2025