Skip to content
Content type · 1,832 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

301–350 of 1,832 sort newestlargest fineoldest
€3,000 SC Elite Conta SRL: Insufficient technical and organisational measures to ensure information security The Romainian DPA has imposed a fine of EUR 3,000 on SC Elite Conta SRL. The controller failed to implement adequate technical and organisational measures to ensure data security,… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing Agreement Aug 18, 2025
€42,000 WORLD 2 MEET, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 42,000 on WORLD 2 MEET, S.L. The controller requires its guests to provide a copy of their identity card or passport for registration… SPAIN ·aepd ·Art. 5 Controllers IP Address Processing Agreement Aug 14, 2025
€500 Sole Trader: Insufficient cooperation with supervisory authority The Slovenian DPA has imposed a fine of EUR 500 on a sole trader. The controller failed to react to a request by the DPA within the set 10-day period. SLOVENIA ·Art. 31 ·Insufficient cooperation with supervisory authority Supervisory Authorities Supervision Controllers Aug 13, 2025
€66,000 REAL SOCIEDAD DE FUTBOL S.A.D.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 66,000 on REAL SOCIEDAD DE FUTBOL S.A.D. The controller suffered a ransomwareattack due to insufficient technical and organisational… SPAIN ·aepd ·Art. 5, 32 Security Controllers Processing Agreement Aug 12, 2025
€1,600 REAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,600 on the REAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESA. The controller pubilshed personal data on its website without a sufficient legal… SPAIN ·aepd ·Art. 5 Controllers Personal Data Processing Aug 12, 2025
€3,000 'FLEXICREDIT' Vereniging voor wederzijdse hulp: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Controller Processing NL Aug 12, 2025
€3,000 'FLEXICREDIT' Mutual Aid House Association: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on 'FLEXICREDIT' Mutual Aid House Association. The controller failed to implement adequate technical and organisational measures… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Insurance Aug 12, 2025
€66,000 REAL SOCIEDAD DE FUTBOL S.A.D.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 66.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 32 Security Controllers Data Controller NL Aug 12, 2025
€1,600 REAL FEDERACIÓN ESPAÑOLA DE TENIS DE MESA: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. 1.600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Personal Data Processing Data Controller NL Aug 12, 2025
€4,800 GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 4,800 on GACM SEGUROS GENERALES, COMPAÑIA DE SEGUROS Y REASEGUROS S.A.U. The controller failed to process customer data accurately,… SPAIN ·aepd ·Art. 5 Insurance Personal Data Controllers Aug 12, 2025
€4,800 GACM SEGUROS GENERALES, een verzekerings- en herverzekeringsmaatschappij S.A.U.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 4.800 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Processing Insurance Data Controller NL Aug 12, 2025
€80,000 BIZUM, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 80,000 on BIZUM, S.L. The controller failed to implement sufficient technical and organisational measures to ensure data security,… SPAIN ·aepd ·Art. 32 Data Breaches Security Controllers Aug 11, 2025
€80,000 BIZUM, S.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 80.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 32 Security Data Breaches Controllers NL Aug 11, 2025
€6,200 Media Company: Insufficient cooperation with supervisory authority The Austrian DPA has imposed a fine of EUR 6,200 on a media company. The controller failed to comply with an order from the DPA to implement an adequate cookie banner. AUSTRIA ·dsb ·Art. 58 Supervisory Authorities Supervision Cookies Aug 6, 2025
€1,000 Order of Biochemists, Biologists and Chemists in the Romanian Health System: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on the Order of Biochemists, Biologists and Chemists in the Romanian Health System. The controller failed to adequatly respond to… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Healthcare Aug 5, 2025
€1,000 Orde van biochemici, biologen en chemici in het Roemeense gezondheidszorgsysteem: Onvoldoende naleving van de rechten van betrokkenen. 1.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Health Data Right of Access Procedures Healthcare NL Aug 5, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2,000 on Linea Stampalibera Società Cooperativa r.I. The controller, who operates a news site, has disclosed too much personal… ITALY ·Garante ·Art. 5 Retention Period IP Address Health Data Aug 4, 2025
€10,000 Gemeente Venetië: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 25 +1 Education Processing Data Controller NL Aug 4, 2025
€80,000 Ospedaliero-Universitaria Careggi: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 80,000 on the Ospedaliero-Universitaria Careggi. The controller, a university hospital, used software that allowed medical personnel to… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Healthcare Security Aug 4, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor gegevensbescherming (Garante). ITALY ·Garante ·Art. 5 Health Data Healthcare Data Controller NL Aug 4, 2025
€10,000 Comune di Venezia: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on the Comune di Venezia. The controller implemented a tourist tax, which includes exceptions for certain groups of visitors. When… ITALY ·Garante ·Art. 5, 6, 25 +1 IP Address Controllers Education Aug 4, 2025
€7,700 Geen zorginstelling: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €7.700 - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 32 Security Healthcare Data Controller NL Aug 4, 2025
€230 Police Officer: Insufficient legal basis for data processing The UK DPA has imposed a fine of £ 200 (EUR 230) on a police officer. The controller forwarded sensitive and restricted personal data that he had obtained in the course of his… UNITED KINGDOM ·ICO ·Insufficient legal basis for data processing Personal Data Controllers Education Aug 4, 2025
€7,700 Non-Public Health Care Institution: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 7,700 on a non-public health care institution. The controller offered home visits by doctors as part of its services. For this purpose,… POLAND ·UODO ·Art. 5, 25, 32 Healthcare Security Controllers Aug 4, 2025
€80,000 Ospedaliero-Universitaria Careggi: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9, 25 +1 Health Data Healthcare Security NL Aug 4, 2025
€11,614 Legal Entity: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 11,614 on a legal entity. The controller did not delete the email address of a former employee, but rather continued to receive and… SLOVENIA ·Art. 5, 6 ·Insufficient legal basis for data processing Controllers Processing Agreement Processing Jul 29, 2025
€4,400 Entrepreneur: Insufficient cooperation with supervisory authority The Polish DPA has imposed a fine of EUR 4,400 on an Entrepreneur. The controller failed to adequatly react to a request from the DPA. POLAND ·UODO ·Art. 58 Supervisory Authorities Supervision Controllers Jul 28, 2025
€4,400 Ondernemer: Onvoldoende samenwerking met de toezichthoudende instantie. 4.400 euro boete - Pools Nationaal Bureau voor de Bescherming van Persoonsgegevens (UODO). POLAND ·UODO ·Art. 58 Supervisory Authorities Controllers Data Controller NL Jul 28, 2025
€5,020 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 5,020 on a legal entity. The controller had developed an application that allowed the exchange of personal data, but failed to… SLOVENIA ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Jul 25, 2025
€5,810 Legal Entity: Insufficient data processing agreement The Slovenian DPA has imposed a fine of EUR 5,810 on a legal entity. The controller employed a person authorised to perform clerical work. However, this person used a data… SLOVENIA ·Art. 28 ·Insufficient data processing agreement Controllers Processors Processing Agreement Jul 25, 2025
€26,400 Debt Collector: Insufficient fulfilment of data subjects rights The Hungarian DPA has imposed a fine of EUR 26,400 on a debt collector. The controller processed the personal data of a natural person, specifically data relating to a consumer… HUNGARY ·NAIH ·Art. 6, 17 Personal Data Controllers Insurance Jul 24, 2025
€5,000 Agricola International SA: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing NL Jul 23, 2025
€10,000 SATI S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on SATI S.p.A. Information about the reasons for employees' absences was displayed on boards and in emails, which were accessible… ITALY ·Garante ·Art. 5, 9 IP Address Controllers Employees Jul 23, 2025
€5,000 Agricola International SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Agricola International SA. The controller failed to implement sufficient technical and organisational measures, resulting in a… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Law Enforcement Jul 23, 2025
€10,000 Orde van de verpleegkundigen van Viterbo: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 32 Security Data Breaches Education NL Jul 23, 2025
€10,000 Order of Nursing Professions of Viterbo: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 10,000 on the Order of Nursing Professions of Viterbo. The controller suffered a data leak due to insufficient technical and… ITALY ·Garante ·Art. 5, 32 Security Education Controllers Jul 23, 2025
€10,000 SATI S.p.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9 Processing Data Controller Controllers NL Jul 23, 2025
€43,000 24/7 Communication Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 43,000 on 24/7 Communication Sp. z o.o. The fined entity acted as the data processor for McDonald’s Polska Sp. z o.o. (see ETid: 2757).… POLAND ·UODO ·Art. 5, 25, 38 Data Breaches Controllers Processors Jul 21, 2025
€43,000 24/7 Communication Sp. z o.o.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 43.000 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 38 Security Processors Controllers NL Jul 21, 2025
€4M McDonald’s Polska Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed a fine of EUR 3,955,000 on McDonald’s Polska Sp. z o.o. The controller used a third party processor (see ETid: 2758) for the purpose of managing work… POLAND ·UODO ·Art. 5, 25, 28 +1 Processors Controllers Data Breaches Jul 21, 2025
€4M McDonald’s Polska Sp. z o.o.: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van 3.955.000 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 28 +1 Controllers Security Processing NL Jul 21, 2025
€9,000 Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 9,000 on Hestia Publishers & Booksellers I. D. Kollaros & Co. S.A. The controller disclosed the identity of an anonymous author by… GREECE ·HDPA ·Art. 5, 25, 32 +2 Pseudonymization Controllers Personal Data Jul 21, 2025
€1,100 ADMINISTRACIONES BENIPON, S.L.: Onvoldoende naleving van de verplichtingen met betrekking tot het melden van datalekken. 1.100 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 28, 33 Data Breaches Notification Obligation Controllers NL Jul 18, 2025
€1,000 CLUB BALONCESTO TELDE: Onvoldoende juridische basis voor de verwerking van gegevens. 1.000 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6 Processing Consent Data Controller NL Jul 18, 2025
€1,100 ADMINISTRACIONES BENIPON, S.L.: Insufficient fulfilment of data breach notification obligations The Spanish DPA has imposed a fine of EUR 1,100 on ADMINISTRACIONES BENIPON, S.L. The processor failed to notify the controller of a data breach and also used a sub-processor… SPAIN ·aepd ·Art. 28, 33 Notification Obligation Data Breaches Article 19 GDPR - Notification of Rectification, Erasure or Restriction Jul 18, 2025
€1,000 CLUB BALONCESTO TELDE: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,000 on the club BALONCESTO TELDE. The controller published an image of a minor without the consent of the minors representative. SPAIN ·aepd ·Art. 6 Representatives Controllers Processing Agreement Jul 18, 2025
€200,000 ENDESA ENERGIA, S.A.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 200,000 on ENDESA ENERGIA, S.A.U. The controller mistakenly linked two unrelated parties, resulting in a third party having its energy… SPAIN ·aepd ·Art. 5 Controllers Processing Agreement IP Address Jul 17, 2025
€1,200 TRUEBA SPORT S.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 13 Security Data Controller Controllers NL Jul 17, 2025
€200,000 ENDESA ENERGIA, S.A.U.: Overtreding van de algemene principes voor gegevensverwerking. Een boete van 200.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Data Controller Controllers Processing NL Jul 17, 2025