Skip to content
Content type · 2,636 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

301–350 of 2,636 sort newestlargest fineoldest
€1,000 'Principe Umberto di Savoia' State Scientific and Linguistic High School: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on 'Principe Umberto di Savoia' State Scientific and Linguistic High School. The controller processed the personal data of… ITALY ·Garante ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Right of Access Controllers Dec 4, 2025
€12,000 Comune di Tuscania: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 12,000 on the Commune di Tuscania. The controller had been using video surveillance and licence plate recognition within its territory… ITALY ·Garante ·Art. 5, 6, 12 +5 Controllers Processors Monitoring Dec 4, 2025
€72,000 TIGER MEDIA INC.: Insufficient legal basis for data processing Spanish Data Protection Authority (aepd) fined TIGER MEDIA INC. €72,000 on 2025-12-03 for: Insufficient legal basis for data processing. Spain ·AEPD ·Art. 6, 27 Processing Telecommunications Supervisory Authorities Dec 3, 2025
€3,600 RISING SUN CAR RENTAL S..L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,600 on RISING SUN CAR RENTAL S..L. The controller used video surveillance to ensure security at its facility, affecting more areas than… SPAIN ·AEPD ·Art. 5, 13 Controllers Supervisory Authorities Personal Data Dec 1, 2025
€3,600 DELAFRUIT, S.L.: Non-compliance with the general principles of data processing. ⇄ Boete van €3.600 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Processing Accountability Dec 1, 2025
€3,600 DELAFRUIT, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 3,600 on DELAFRUIT, S.L. The controller installed video surveillance in the staff break area and dining room, but did not put up the… SPAIN ·AEPD ·Art. 5 Controllers Processing Video Surveillance Dec 1, 2025
€3,600 RISING SUN CAR RENTAL S.L.: Non-compliance with the general principles for data processing. ⇄ The Spanish data protection authority (DPA) has imposed a fine of 3,600 euros on RISING SUN CAR RENTAL S.L. The controller used video surveillance to ensure security at its… SPAIN ·AEPD ·Art. 5, 13 Controllers Processing Supervisory Authorities Dec 1, 2025
€300,000 Aimag S.p.A.: Non-compliance with the general principles for data processing. ⇄ Een boete van 300.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +4 Controllers Consent Processing Nov 27, 2025
€1.5M AMERICAN EXPRESS CARTE FRANCE: Insufficient legal basis for the processing of data. ⇄ 1.500.000 euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). CNIL ·Art. 82 ·Insufficient legal basis for data processing Controllers Processing Personal Data Nov 27, 2025
€400,000 Verisure Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 400,000 on Verisure Italy s.r.l. The controller had been active in direkt marketing activities. The controller failed to ensure that the… Garante ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles Retention Period Controllers Direct Marketing Nov 27, 2025
€40,000 Infobel: Insufficient Legal Basis for Data Processing. ⇄ Een boete van 40.000 euro - De Belgische Autoriteit voor gegevensbescherming (APD). BELGIUM ·APD/GBA ·Art. 5, 6, 24 Controllers Processing Accountability Nov 27, 2025
€300,000 Aimag S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 300,000 on Aimag S.p.A. The controller offered its customers a service that allowed them to view their consumption data on the… ITALY ·Garante ·Art. 5, 6, 7 +4 Controllers Consent Supervisory Authorities Nov 27, 2025
€2,000 Nițu A. Cleopatra – Expert Accountant: Insufficient technical and organisational measures to ensure information security Thr Romanian DPA has imposed a fine of EUR 2,000 on Nițu A. Cleopatra – Expert Accountant. The controller was the target of a successful cyber attack due to the inadequate… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Nov 27, 2025
€1.5M AMERICAN EXPRESS CARTE FRANCE: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 1,500,000 on AMERICAN EXPRESS CARTE FRANCE. The controller used excessive cookies on its website and failed to adequately inform data… CNIL ·Art. 82 ·Insufficient legal basis for data processing Controllers Personal Data Cookies Nov 27, 2025
€40,000 Infobel: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 40,000 on Infobel. The controller, a data broker, sold personal data for direct marketing purposes. However, it processed the data it had… BELGIUM ·APD/GBA ·Art. 5, 6, 24 Controllers Personal Data Processing Nov 27, 2025
€400,000 Verisure Italy s.r.l.: Non-compliance with general principles for data processing. ⇄ Een boete van 400.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). Garante ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles Archiving Retention Period Controllers Nov 27, 2025
€2,000 Nițu A. Cleopatra – Expert Accountant: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Nov 27, 2025
€3,000 Cucina di Fabio S.R.L.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 3,000 on Cucina di Fabio S.R.L. The controller was active in direct marketing activities, using personal data that had not been obtained… ROMANIA ·ANSPDCP ·Art. 6, 15, 17 +1 Controllers Personal Data Marketing Nov 26, 2025
€3,000 Cucina di Fabio S.R.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 15, 17 +1 Personal Data Processing Supervisory Authorities Nov 26, 2025
€6,600 Legal Entity: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 6,600 on a legal entity. The controller used GPS trackers to systematically and indiscriminately monitor its employees' activities… SLOVENIA ·IP-RS ·Art. 5, 6 Controllers Processing Employees Nov 26, 2025
€4.5M Telecommunications Company (Operator of Electronic Communications Networks and Services): Violation of the General Principles of Data Processing. ⇄ Een boete van 4.500.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·AZOP ·Art. 5, 6, 12 +4 Controllers Processors Processing Nov 24, 2025
€4.5M Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer… CROATIA ·AZOP ·Art. 5, 6, 12 +4 International Transfer Privacy Shield Controllers Nov 24, 2025
DSB · 2025-0.950.759 On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Austria ·Art. 5, 6, 16 +2 Privacy by Design & Default Privacy by Design Privacy by Default Nov 24, 2025
€5,000 ACTIVOS INTELIGENTES, S.L.: Breach of the general principles of data processing. ⇄ Boete van €5.000 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Processing Accountability IP Address Nov 23, 2025
€5,000 ACTIVOS INTELIGENTES, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5,000 on ACTIVOS INTELIGENTES, S.L. The controller is asking its guests for selfies with their ID-card to verify their identity,… SPAIN ·AEPD ·Art. 5 Controllers Processing IP Address Nov 23, 2025
€1.2M IDCQ HOSPITALES Y SANIDAD, S.L.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,200,000 on IDCQ HOSPITALES Y SANIDAD, S.L.U. The controller offered MRI scans as part of its services, and patients could bring copies… SPAIN ·AEPD ·Art. 6, 9, 25 Controllers Healthcare Personal Data Nov 21, 2025
DSB: No processor access violation under Art. 15 GDPR when controller deleted data On 07. August 2023, the data subject made a request to the processor to provide the report and the questionnaire completed by the data subject at an information event. The… 2025-0.566.415 ·Austria ·Art. 4, 5, 12 +3 Controllers Processors Right of Access Nov 21, 2025
€750,000 LES PUBLICATIONS CONDE NAST: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 750,000 on LES PUBLICATIONS CONDE NAST. The controller used multiple cookies on its website but failed to adequately implement them. FRANCE ·CNIL ·Art. 82 Controllers Cookies IP Address Nov 20, 2025
€750,000 CONDE NAST PUBLICATIONS: Non-compliance with general principles of data processing. ⇄ Een boete van 750.000 euro - van de Franse Autoriteit voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 82 Controllers Processing Cookies Nov 20, 2025
€2,000 NATIONAL ASSOCIATION OF APPRAISERS AND JUDICIAL COMPUTER EXPERTS: Insufficient compliance with data subjects' rights in the processing of personal data. ⇄ Een boete van 2.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 13, 17 Personal Data Processing Controllers Nov 19, 2025
€800 SOBLADA RESTAURACIÓN, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 800 on SOBLADA RESTAURACIÓN, S.L. The controller installed video surveillance without providing the necessary information signs or… SPAIN ·AEPD ·Art. 5, 13 Controllers Supervisory Authorities Processing Nov 19, 2025
€3,000 Greencorp S.R.L.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Nov 19, 2025
€800 SOBLADA RESTAURACIÓN, S.L.: Violation of the general principles of data processing. ⇄ 800 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 13 Controllers Processing Supervisory Authorities Nov 19, 2025
€3,000 Greencorp S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Greencorp S.R.L. The controller failed to implement adequate technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Nov 19, 2025
€80 Journalist: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 80 on a Journalist. The controller published unnecessary private data about a data subject on social media, including their address. AUSTRIA ·DSB ·Art. 5, 6 Personal Data Controllers Processing Nov 18, 2025
€80 Journalist: There is an insufficient legal basis for the processing of data. ⇄ 80 euro boete - Oostenrijkse Autoriteit voor Gegevensbescherming (dsb). AUSTRIA ·DSB ·Art. 5, 6 Personal Data Controllers Processing Nov 18, 2025
€8,000 PGS SOFA & CO SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PGS SOFA & CO SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures. ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Nov 17, 2025
€8,000 PGS SOFA & CO SRL: Insufficient technical and organizational measures to ensure information security. ⇄ 8.000 euro boete - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Nov 17, 2025
€2,400 AXARQUIA VELEZ DENTAL, S.L.: Non-compliance with the general principles for data processing. ⇄ Een boete van 2.400 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Processing Accountability Nov 14, 2025
€2,400 AXARQUIA VELEZ DENTAL, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 2,400 on AXARQUIA VELEZ DENTAL, S.L. The controller used video surveillance to ensure security at its facility, affecting more areas than… SPAIN ·AEPD ·Art. 5 Controllers Processing Security Nov 14, 2025
€72,000 AEPD · PS-00480-2025 Tiger Media Inc., the controller, operated an advertising platform for publishers and advertisers of adult products and services. The platform acted as an ad network, connecting… Spain ·Art. 6, 27 Legitimate Interest Controllers Processors Nov 14, 2025
€40,000 Quarantadue S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 40,000 on Quarantadue S.r.l. The controller produced a television series about a criminal case which included real audio recordings that… ITALY ·Garante ·Art. 5 Controllers Processing IP Address Nov 13, 2025
€40,000 Quarantadue S.r.l.: Non-compliance with general principles for data processing. ⇄ Een boete van 40.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5 Controllers Processing Telecommunications Nov 13, 2025
€6,000 Comune di Orte: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 6,000 on the Comuni di Orte. The controller implemented video surveillance on its territory in a manner that did not comply with the… ITALY ·Garante ·Art. 5, 6, 12 +2 Controllers Monitoring Processing Nov 13, 2025
€6,000 Municipality of Orte: Failure to comply with the general principles of data processing. ⇄ Een boete van 6.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +2 Controllers Processing DPIA Nov 13, 2025
€4,000 Fan Courier Express S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 4,000 on Fan Courier Express S.R.L. The controller failed to adequately react to a data subject's request to exercise their rights, and… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +2 Personal Data Controllers Supervisory Authorities Nov 12, 2025
€4,000 Fan Courier Express S.R.L.: Insufficient Compliance with Data Subject Rights. ⇄ Een boete van 4.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +2 Personal Data Processing Supervisory Authorities Nov 12, 2025
€2,000 Whitedecor SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on Whitedecor SRL. The controller had sent marketing messages to customers without a sufficient legal basis. ROMANIA ·ANSPDCP ·Art. 6, 7, 12 +3 Direct Marketing Controllers Personal Data Nov 10, 2025
€2,000 Whitedecor SRL: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 7, 12 +3 Personal Data Processing Supervisory Authorities Nov 10, 2025
€7,000 Klass Wagen S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 7,000 on Klass Wagen S.R.L. The controller suffered a cyber incident due to a former employee exposing the login credentials of… ROMANIA ·ANSPDCP ·Art. 32 Controllers Security Personal Data Nov 7, 2025