Skip to content
Content type · 2,395 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

301–350 of 2,395 sort newestlargest fineoldest
€9,600 Restaurant (SANTI 3000, S.L.): Insufficient legal basis for the processing of personal data. ⇄ Boete van €9.600 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 6 Processing Personal Data Accountability Dec 30, 2025
€588 Alza.cz a.s.: Insufficient legal basis for the processing of data. ⇄ Een boete van 588 euro - opgelegd door de Tsjechische Autoriteit voor Gegevensbescherming (UOOU). CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 6, 7 Consent Personal Data Processing Dec 30, 2025
€20,000 Telecommunications company: Insufficient legal basis for data processing The Croatian DPA (azop) has imposed a fine of EUR 20,000 on a telecommunications company. A data subject had filed a complaint with the DPA claiming that the company was still… CROATIA ·AZOP ·Art. 5, 6 Personal Data Processing Telecommunications
€3.5M Company: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 3,500,000 on a company. The controller operated a loyalty program in France and 16 other EU countries, using customer data obtained… FRANCE ·CNIL ·Art. 6, 13, 32 +1 Controllers International Transfer DPIA Dec 30, 2025
€2,000 Order of General Nurses, Midwives and Medical Assistants of Romania – Neamt Branch: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 2,000 on the Order of General Nurses, Midwives and Medical Assistants of Romania – Neamt Branch. The controller used video surveillance… ANSPDCP ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Controllers Supervisory Authorities Processing Dec 29, 2025
€2,000 Order of General Nurses, Midwives and Medical Assistants of Romania – Neamt Branch: Non-compliance with the general principles of data processing. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Processing Supervisory Authorities Supervision Dec 29, 2025
€6,000 Geturhotels Srl: Violation of the general principles of data processing. ⇄ Een boete van 6.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 17 +1 Controllers Processing Personal Data Dec 23, 2025
€6,000 Geturhotels Srl: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 6,000 on Geturhotels Srl. The controller was involved in direct marketing operations, using personal data that had not been acquired or… ITALY ·Garante ·Art. 5, 6, 17 +1 Controllers Personal Data Processing Dec 23, 2025
€500,000 CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 500,000 on CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U. The controller used a communication tool that was not designed in… SPAIN ·AEPD ·Art. 25 Controllers Personal Data Security Dec 22, 2025
€32,000 EXCEL HOTELS & RESORTS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on EXCEL HOTELS & RESORTS, S.A. The controller used guards to control access to its facility. The guards regularly left documents… SPAIN ·AEPD ·Art. 5 Controllers Security Personal Data Dec 20, 2025
€6,000 Comune di Nave: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Commune di Nave. The controller has installed an automatic licence plate recognition system which processes data on when a… ITALY ·Garante ·Art. 5, 6, 12 +2 DPIA Controllers Personal Data Dec 18, 2025
€40,000 LTL S.p.A.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 40,000 on LTL S.p.A. The controller failed to respond within the legal time period to a request by a former employee to exercise their… ITALY ·Garante ·Art. 5, 12, 15 Controllers Personal Data Supervisory Authorities Dec 18, 2025
€2,000 Elba Catering Distribuzioni s.r.I.s.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,000 on Elba Catering Distribuzioni s.r.I.s. The controller installed video surveillance, which affected the public road. Furthermore,… ITALY ·Garante ·Art. 5, 13 Controllers Personal Data Supervisory Authorities Dec 18, 2025
€1,000 Data Controller: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on a data controller. The controller disclosed personal data by sending an email to an address that third parties who were not… ITALY ·Garante ·Art. 5, 6 Controllers Processing Personal Data Dec 18, 2025
€175,000 HAN University of Applied Sciences: Insufficient technical and organizational measures to ensure information security. ⇄ 175.000 euro boete - Nederlandse Autoriteit Persoonsgegevens (AP). THE NETHERLANDS ·AP ·Art. 32 Security Personal Data Controllers Dec 15, 2025
€15,000 Crowd Entertainment Limited: Insufficient compliance with data subjects' rights (regarding their personal data). ⇄ Een boete van €15.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Processing Supervisory Authorities Dec 10, 2025
€15,000 Crowd Entertainment Limited: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 15,000 on Crowd Entertainment Limited. The controller failed to adequatly react to a data subjects request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Dec 10, 2025
€5,100 Legal Entity: Insufficient fulfilment of data subjects rights The Slovenian DPA has imposed a fine of EUR 5,100 on a legal entity. The controller operated a website where natural persons could fil in their personal data in a form. The… SLOVENIA ·IP-RS ·Art. 12, 13 Personal Data Controllers Supervisory Authorities Dec 8, 2025
€1,000 Compania de Apa Oltenia S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 1,000 on Compania de Apa Oltenia S.A. The controller failed to implement adequate technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 29, 32 Security Controllers Personal Data Dec 8, 2025
€1,000 Compania de Apa Oltenia S.A.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 29, 32 Security Processing Personal Data Dec 8, 2025
€2,000 Istituto Comprensivo Centro di Casalecchio di Reno: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 2,000 on Istituto Comprensivo Centro di Casalecchio di Reno. The controller published a ranking of its teachers on its website without a… ITALY ·Garante ·Art. 5, 6 Controllers Personal Data Employees Dec 4, 2025
€2,000 Istituto Comprensivo Centro in Casalecchio di Reno: Insufficient compliance with data subjects' rights. ⇄ Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Controllers Personal Data Accountability Dec 4, 2025
€1,300 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 1,300 on a legal entity. An employee of the controller stored personal data on her work laptop without securing it, for example by… SLOVENIA ·IP-RS ·Art. 32 Encryption Security Controllers Dec 4, 2025
€12,000 Comune di Tuscania: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 12,000 on the Commune di Tuscania. The controller had been using video surveillance and licence plate recognition within its territory… ITALY ·Garante ·Art. 5, 6, 12 +5 Controllers Processors Monitoring Dec 4, 2025
€1,000 'Principe Umberto di Savoia' State Scientific and Linguistic High School: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on 'Principe Umberto di Savoia' State Scientific and Linguistic High School. The controller processed the personal data of… ITALY ·Garante ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Right of Access Controllers Dec 4, 2025
DSB · 2025-0.968.031 A data subject published a post concerning their ADHD diagnosis on a publicly accessible online forum under a pseudonym. A person (the controller) who was a follower of the data… 2025-0.968.031 ·Austria ·Art. 9 Pseudonymization Anonymization Health Data Dec 3, 2025
€3,600 RISING SUN CAR RENTAL S..L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,600 on RISING SUN CAR RENTAL S..L. The controller used video surveillance to ensure security at its facility, affecting more areas than… SPAIN ·AEPD ·Art. 5, 13 Controllers Supervisory Authorities Personal Data Dec 1, 2025
€3,600 RISING SUN CAR RENTAL S.L.: Non-compliance with the general principles for data processing. ⇄ The Spanish data protection authority (DPA) has imposed a fine of 3,600 euros on RISING SUN CAR RENTAL S.L. The controller used video surveillance to ensure security at its… SPAIN ·AEPD ·Art. 5, 13 Controllers Processing Supervisory Authorities Dec 1, 2025
€1.6M SPRINTER MEGACENTROS DEL DEPORTE, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,560,000 on SPRINTER MEGACENTROS DEL DEPORTE, S.L. The controller suffered a cyber attack due to insufficient technical and… SPAIN ·AEPD ·Art. 5, 34 Security Controllers Supervisory Authorities Nov 28, 2025
€1.5M AMERICAN EXPRESS CARTE FRANCE: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 1,500,000 on AMERICAN EXPRESS CARTE FRANCE. The controller used excessive cookies on its website and failed to adequately inform data… CNIL ·Art. 82 ·Insufficient legal basis for data processing Controllers Personal Data Cookies Nov 27, 2025
€40,000 Infobel: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 40,000 on Infobel. The controller, a data broker, sold personal data for direct marketing purposes. However, it processed the data it had… BELGIUM ·APD/GBA ·Art. 5, 6, 24 Controllers Personal Data Processing Nov 27, 2025
€400,000 Verisure Italy s.r.l.: Non-compliance with general principles for data processing. ⇄ Een boete van 400.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). Garante ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles Archiving Retention Period Controllers Nov 27, 2025
€2,000 Nițu A. Cleopatra – Expert Accountant: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Nov 27, 2025
€2,000 Nițu A. Cleopatra – Expert Accountant: Insufficient technical and organisational measures to ensure information security Thr Romanian DPA has imposed a fine of EUR 2,000 on Nițu A. Cleopatra – Expert Accountant. The controller was the target of a successful cyber attack due to the inadequate… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Nov 27, 2025
€1.5M AMERICAN EXPRESS CARTE FRANCE: Insufficient legal basis for the processing of data. ⇄ 1.500.000 euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). CNIL ·Art. 82 ·Insufficient legal basis for data processing Controllers Processing Personal Data Nov 27, 2025
€400,000 Verisure Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 400,000 on Verisure Italy s.r.l. The controller had been active in direkt marketing activities. The controller failed to ensure that the… Garante ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles Retention Period Controllers Direct Marketing Nov 27, 2025
€3,000 Cucina di Fabio S.R.L.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 3,000 on Cucina di Fabio S.R.L. The controller was active in direct marketing activities, using personal data that had not been obtained… ROMANIA ·ANSPDCP ·Art. 6, 15, 17 +1 Controllers Personal Data Marketing Nov 26, 2025
€3,000 Cucina di Fabio S.R.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 15, 17 +1 Personal Data Processing Supervisory Authorities Nov 26, 2025
€4.5M Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer… CROATIA ·AZOP ·Art. 5, 6, 12 +4 International Transfer Privacy Shield Controllers Nov 24, 2025
€4.5M Telecommunications Company (Operator of Electronic Communications Networks and Services): Violation of the General Principles of Data Processing. ⇄ Een boete van 4.500.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·AZOP ·Art. 5, 6, 12 +4 Controllers Processors Processing Nov 24, 2025
DSB · 2025-0.950.759 On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Austria ·Art. 5, 6, 16 +2 Privacy by Design & Default Privacy by Design Privacy by Default Nov 24, 2025
€1.2M IDCQ HOSPITALES Y SANIDAD, S.L.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,200,000 on IDCQ HOSPITALES Y SANIDAD, S.L.U. The controller offered MRI scans as part of its services, and patients could bring copies… SPAIN ·AEPD ·Art. 6, 9, 25 Controllers Healthcare Personal Data Nov 21, 2025
DSB: No processor access violation under Art. 15 GDPR when controller deleted data On 07. August 2023, the data subject made a request to the processor to provide the report and the questionnaire completed by the data subject at an information event. The… 2025-0.566.415 ·Austria ·Art. 4, 5, 12 +3 Controllers Processors Right of Access Nov 21, 2025
€16,650 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 16,650 on a legal entity. The controller stored personal data on a publicly accessible web server without taking sufficient technical… SLOVENIA ·IP-RS ·Art. 32 Security Controllers Personal Data Nov 21, 2025
€3,000 Greencorp S.R.L.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Nov 19, 2025
€3,000 Greencorp S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Greencorp S.R.L. The controller failed to implement adequate technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Nov 19, 2025
€2,000 NATIONAL ASSOCIATION OF APPRAISERS AND JUDICIAL COMPUTER EXPERTS: Insufficient compliance with data subjects' rights in the processing of personal data. ⇄ Een boete van 2.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 13, 17 Personal Data Processing Right to be Forgotten Nov 19, 2025
€2,000 ASOCIACIÓN NACIONAL DE TASADORES Y PERITOS JUDICIALES INFORMÁTICOS: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 2,000 on the ASOCIACIÓN NACIONAL DE TASADORES Y PERITOS JUDICIALES INFORMÁTICOS. The controller published a court ruling which included… SPAIN ·AEPD ·Art. 13, 17 Personal Data Controllers Supervisory Authorities Nov 19, 2025
€80 Journalist: There is an insufficient legal basis for the processing of data. ⇄ 80 euro boete - Oostenrijkse Autoriteit voor Gegevensbescherming (dsb). AUSTRIA ·DSB ·Art. 5, 6 Personal Data Controllers Processing Nov 18, 2025
€80 Journalist: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 80 on a Journalist. The controller published unnecessary private data about a data subject on social media, including their address. AUSTRIA ·DSB ·Art. 5, 6 Personal Data Controllers Processing Nov 18, 2025