Skip to content
Content type · 1,013 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

301–350 of 1,013 sort newestlargest fineoldest
€550,000 Departement of Social Security: Insufficient legal basis for data processing The Irish DPA imposed a fine of EUR 550,000 on the Departement of Social Security. The controller uses the so called SAFE 2 registration process for anyone applying for a Public… IRELAND ·DPC ·Art. 5, 6, 9 +2 DPIA Types of Special Categories of Personal Data Controllers Jun 12, 2025
€10,000 Accounting Audit Ltd: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van €10.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Jun 12, 2025
€10,000 Accounting Audit SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 10,000 on Accounting Audit SRL. The company failed to implement sufficient technical and organizational measures, resulting in a data breach… ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Data Breaches Jun 12, 2025
€2.7M 23andMe, Inc.: Insufficient technical and organisational measures to ensure information security The UK DPA imposed a fine of £ 2,310,000 (EUR 2,700,000) on 23andMe, Inc. The controller, a company offering DNA testing to private individuals, failed to implement sufficient… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers Data Breaches Jun 5, 2025
€2.7M 23andMe, Inc.: Inadequate technical and organisational measures to ensure information security. ⇄ Een boete van 2.700.000 euro - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers Accountability Jun 5, 2025
€45,000 Noi Compriamo Auto.it S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 45,000 on Noi Compriamo Auto.it S.r.l. The controller contacted the data subject multiple times for direct marketing purposes via… ITALY ·Garante ·Art. 5, 6, 12 +2 Controllers Personal Data Security Jun 4, 2025
€45,000 Noi Compriamo Auto.it S.r.l.: Violation of the general principles for data processing. ⇄ Een boete van 45.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +2 Controllers Personal Data Security Jun 4, 2025
€5,000 AG-BROKER ASIGURARE S.R.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van €5.000 - De Roemeense nationale toezichthouder op de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data May 30, 2025
€5,000 AG-BROKER ASIGURARE S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on AG-BROKER ASIGURARE S.R.L. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 30, 2025
€1.4M REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 1,380,000 on REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS, S.L. The controller used outdated technical and organisational measures to manage… SPAIN ·AEPD ·Art. 5, 32 Controllers Security Personal Data May 26, 2025
€60,000 AIRE NETWORKS DEL MEDITERRÃNEO, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 60,000 on AIRE NETWORKS DEL MEDITERRÃNEO, S.L. The controller did not implement sufficient technical and organisational measures to ensure… SPAIN ·AEPD ·Art. 5 Security Controllers Data Breaches May 23, 2025
€60,000 AIRE NETWORKS DEL MEDITERRÁNEO, S.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 60.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability May 23, 2025
€5,000 Maravet S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Maravet S.R.L. The controller did not implement sufficient technical and organisational measures to ensure information… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 19, 2025
€5,000 Maravet S.R.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data May 19, 2025
€5,000 ACCOUNTING & AUDIT CONSULTING SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on ACCOUNTING & AUDIT CONSULTING SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 16, 2025
€5,000 ACCOUNTING & AUDIT CONSULTING SRL: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data May 16, 2025
€2,000 CVA TAX & FINANCE S.R.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data May 14, 2025
€2,000 CVA TAX & FINANCE S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 CVA TAX & FINANCE S.R.L. The controller did not implement sufficient technical and organisational measures to ensure information… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 14, 2025
€2,000 CV PRO CONSULT S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on CV PRO CONSULT S.R.L. The controller did not implement sufficient technical and organisational measures to ensure information… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data May 12, 2025
€2,000 CV PRO CONSULT S.R.L.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data May 12, 2025
€6,600 Owner of a Pharmacy: Violation of the General Principles of Data Processing. ⇄ Een boete van 6.600 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6, 14, 32 Health Data Controllers Processing May 8, 2025
€100,000 Energia Verde S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Energia Verde S.p.A. The controller had been active in direct marketing activities. The controller processed data without a… ITALY ·Garante ·Art. 5, 6, 7 +13 Direct Marketing Controllers Processors Apr 29, 2025
€40,000 Municipality of Bologna: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 40.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 Security Controllers Health Data Apr 29, 2025
€20,000 Cooperativa Sociale Quadrifoglio: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 20.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 28, 32 Security Controllers Processors Apr 29, 2025
€30,000 Ordine degli psicologi della Lombardia: Insufficient technical and organisational measures to ensure information security The Italian DPA imposed a fine of EUR 30,000 on Ordine degli psicologi della Lombardia. The controller suffered a data breach due to insufficient technical and organisational… ITALY ·Garante ·Art. 5, 32 Security Controllers Data Breaches Apr 29, 2025
€100,000 Energia Verde S.p.A.: Non-compliance with the general principles of data processing. ⇄ Een boete van 100.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +13 Security Controllers Direct Marketing Apr 29, 2025
€30,000 Lombardy Order of Psychologists: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 30.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 32 Security Controllers Accountability Apr 29, 2025
€40,000 Municipality of Bologna: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 40,000 on the Municipality of Bologna. The controller used a data processor (Cooperativa Sociale Quadrifoglio | ETid: 2274) to process… ITALY ·Garante ·Art. 5, 6, 9 Controllers Security Healthcare Apr 29, 2025
€20,000 Cooperativa Sociale Quadrifoglio: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 20,000 on Cooperativa Sociale Quadrifoglio. The entity that was fined, acting as a data processor, forwarded files containing the… ITALY ·Garante ·Art. 28, 32 Processors Controllers Security Apr 29, 2025
€6,000 SC Travel Planner SRL: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 6.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15, 32 +1 Security Processing Personal Data Apr 25, 2025
€6,000 SC Travel Planner SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 6,000 on SC Travel Planner SRL. The controller failed to implement sufficient technical and organisational measures, resulting in a data… ROMANIA ·ANSPDCP ·Art. 12, 15, 32 +1 Data Breaches Controllers Security Apr 25, 2025
€9,200 Discrimination Ombudsmen: Insufficient technical and organizational measures to ensure information security. ⇄ 9.200 euro boete - De Zweedse Autoriteit voor Gegevensbescherming (Integritetsskyddsmyndigheten). SWEDEN ·IMY ·Art. 32 Security Controllers Education Apr 23, 2025
€9,200 Diskrimineringsombudsmannen: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 9,200 on the Swedish Disrimination Ombudsman. The controller was unable to implement sufficient data security measures, resulting in the… SWEDEN ·IMY ·Art. 32 Security Controllers Education Apr 23, 2025
€12,000 NOVATES ALIMENTACIÓN MADRID, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine on NOVATES ALIMENTACIÓN MADRID, S.L. The controller used surveillance cameras without implementing the necessary technical and organizational… SPAIN ·AEPD ·Art. 32 Security Controllers Privacy by Design & Default Apr 22, 2025
€12,000 NOVATES ALIMENTACIÓN MADRID, S.L.: Insufficient technical and organisational measures to ensure information security. ⇄ 12.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 32 Security Controllers Video Surveillance Apr 22, 2025
€2,000 United Business Solutions SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on United Business Solutions SRL. The controller failed to implement sufficient technical and organisational measuresto ensure… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Apr 15, 2025
€2,000 United Business Solutions SRL: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Apr 15, 2025
€7,800 Funeral company: insufficient technical and organisational measures to ensure information security. ⇄ Een boete van €7.800 - van het Poolse Nationaal Bureau voor de Bescherming van Persoonlijke Gegevens (UODO). POLAND ·UODO ·Art. 5 Security Controllers Processing Apr 15, 2025
€7,800 Funeral Home: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined a funeral home EUR 7,800. The funeral home failed to implement sufficient technical and organisational measures to prevent a data breach. The funeral home… POLAND ·UODO ·Art. 5 Security Controllers Personal Data Apr 15, 2025
€70,300 DPP Law Ltd.: Insufficient technical and organizational measures to ensure information security. ⇄ Boete van €70.300 - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Security Accountability Notification Obligation Apr 14, 2025
€70,300 DPP Law Ltd.: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has imposed a fine of £ 60,000 (EUR 70,300) on the law firm DPP Law Ltd. The controller had suffered a cyber attack during which personal data of 791 clients and… UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Controllers Security Personal Data Apr 14, 2025
€2,000 NEW GAMBLING SOLUTIONS S.R.L.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Apr 11, 2025
€2,000 NEW GAMBLING SOLUTIONS S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on NEW GAMBLING SOLUTIONS S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Apr 11, 2025
€600 FEDERACION DE COLUMBICULTURA DE CASTILLA-LA MANCHA: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine on FEDERACION DE COLUMBICULTURA DE CASTILLA-LA MANCHA. The controller was unable to ensure the confidentiality of personal data, which resulted in a… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Controllers Personal Data Apr 9, 2025
€600 Owner of a Law Firm: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine on the owner of a law firm. The controller disclosed personal information in an external email because they did not implement sufficient technical… SPAIN ·AEPD ·Art. 5 Security Controllers Privacy by Design & Default Apr 3, 2025
€600 Owner of a law firm: Insufficient technical and organizational measures to ensure information security. ⇄ 600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Apr 3, 2025
€3,000 BINBOX GLOBAL SERVICES S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on BINBOX GLOBAL SERVICES S.R.L. The controller failed to implement sufficient technical and organisational measuresto ensure data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Apr 2, 2025
€3,000 BINBOX GLOBAL SERVICES S.R.L.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Apr 2, 2025