Skip to content
Content type · 2,256 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

351–400 of 2,256 sort newestlargest fineoldest
€3,000 SC Tremend Software Consulting SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Jun 26, 2025
€3,000 SC Piramida Trade Invest SRL: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +4 Security Personal Data Data Controller NL Jun 26, 2025
€3,000 Selgros Cash & Carry SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Selgros Cash & Carry SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Processing Agreement Jun 26, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 550.000 euro - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 28 Security Telecommunications Processors NL Jun 25, 2025
€40,000 KARAMBELAS KONSTANTINOS & CO. E.E.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van 40.000 euro - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 29, 32 Security Telecommunications Personal Data NL Jun 25, 2025
€7,000 General Hospital of the University of Larissa: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 7,000 on the General Hospital of the University of Larissa. The controller failed to adequately fulfil the rights of data subjects. It… GREECE ·HDPA ·Art. 5, 14, 15 Healthcare Healthcare Controllers Jun 24, 2025
€10,000 Shield of David - K.I.D.A.F.: Niet-naleving van algemene principes voor gegevensverwerking. Boete van €10.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 12, 13 +3 Personal Data Health Data Video Surveillance NL Jun 24, 2025
€10,000 Shield of David - K.I.D.A.F.: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Shield of David - K.I.D.A.F. The controller, a day care centre for people with autism, has legally installed video… GREECE ·HDPA ·Art. 5, 12, 13 +3 Video Surveillance Controllers Healthcare Jun 24, 2025
€7,000 Algemeen Ziekenhuis van de Universiteit van Larissa: Onvoldoende naleving van de rechten van betrokkenen. Een boete van €7.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 14, 15 Health Data Healthcare Personal Data NL Jun 24, 2025
€50,000 Piraeus Bank S.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 50.000 euro - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 6 Personal Data Processing Data Controller NL Jun 23, 2025
€4,000 Vodafone Romania S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 4.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Security Data Breaches Telecommunications NL Jun 23, 2025
€3,500 Municipal Social Welfare Center Aleksandrów: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 3,500 on the Municipal Social Welfare Center in Aleksandrów. The controller did not implement sufficient technical and organisational… POLAND ·UODO ·Art. 32 Data Breaches Security Public Authority Jun 23, 2025
€125,000 Onderwijs- en opleidingsraad van de stad Dublin: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 125.000 euro boete - Ierse Autoriteit voor Gegevensbescherming. IRELAND ·Art. 5, 32, 33 +1 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Education NL Jun 23, 2025
€50,000 Piraeus Bank S.A.: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 50,000 on Piraeus Bank S.A.The controller has processed personal data even though the data subject rightfully opposed the the data… GREECE ·HDPA ·Art. 5, 6 Personal Data Controllers Insurance Jun 23, 2025
€4,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 4,000 on Vodafone Romania S.A. The controller failed to implement sufficient technical and organisational measures to ensure data… ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Telecommunications Jun 23, 2025
€125,000 City of Dublin Education and Training Board: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 125,000 on the City of Dublin Education and Training Board. The controller suffered a data breach due to insufficient technical and… IRELAND ·Art. 5, 32, 33 +1 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Education Jun 23, 2025
€24,000 COLEGIO VIRGEN DE EUROPA, S.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 24.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 6, 13 Education Personal Data Processing NL Jun 20, 2025
€24,000 COLEGIO VIRGEN DE EUROPA, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 24,000 on COLEGIO VIRGEN DE EUROPA, S.L. An employee of the controller, a school, took pictures of minor pupils without a sufficient legal… SPAIN ·aepd ·Art. 5, 6, 13 Education Controllers Personal Data Jun 20, 2025
€1,000 SC Diamir SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 1,000 on SC Diamir SRL. The controller failed to properly cooperate with the supervisory authority and also disclosed personal data to… ROMANIA ·ANSPDCP ·Art. 6, 58 Controllers Supervisory Authorities Processing Agreement Jun 19, 2025
€1,000 SC Diamir SRL: Overtreding van de algemene principes voor gegevensverwerking. Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 58 Processing Controllers Data Controller NL Jun 19, 2025
€200 Dincă Viorel George: Onvoldoende samenwerking met de toezichthoudende instantie. Een boete van 200 euro - De Roemeense nationale toezichthouder op de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Controllers NL Jun 18, 2025
€200 Dincă Viorel George: Insufficient cooperation with supervisory authority The Romanian DPA has imposed a fine of EUR 200 on a private individual. The controller failed to react to communication from the supervisory authority. ROMANIA ·ANSPDCP ·Art. 58 Supervisory Authorities Supervision Controllers Jun 18, 2025
€6,800 Waxholms Ångfartygs AB: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. 6.800 euro boete - De Zweedse Autoriteit voor Gegevensbescherming (Integritetsskyddsmyndigheten). SWEDEN ·Art. 6, 9 ·Insufficient legal basis for data processing Processing Personal Data Data Controller NL Jun 18, 2025
€550,000 Departement of Social Security: Insufficient legal basis for data processing The Irish DPA imposed a fine of EUR 550,000 on the Departement of Social Security. The controller uses the so called SAFE 2 registration process for anyone applying for a Public… IRELAND ·Art. 5, 6, 9 +2 ·Insufficient legal basis for data processing DPIA Privacy Impact Assessment Special Categories of Data Jun 12, 2025
€550,000 Ministerie van Sociale Zekerheid: Onvoldoende wettelijke basis voor gegevensverwerking. 550.000 euro boete - Ierse Autoriteit voor Gegevensbescherming. IRELAND ·Art. 5, 6, 9 +2 ·Insufficient legal basis for data processing Types of Special Categories of Personal Data Education Special Categories of Data NL Jun 12, 2025
€10,000 Accounting Audit SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €10.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Processing NL Jun 12, 2025
€10,000 Accounting Audit SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA imposed a fine of EUR 10,000 on Accounting Audit SRL. The company failed to implement sufficient technical and organizational measures, resulting in a data breach… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Processing Agreement Jun 12, 2025
€22,000 Gemeente Kristiansand: Onvoldoende juridische basis voor gegevensverwerking. 22.000 euro boete - Noorse Toezichtsautoriteit (Datatilsynet). NORWAY ·Datatilsynet ·Art. 6, 12, 13 Education Public Authority Processing NL Jun 10, 2025
€22,000 Kristiansand municipality: Insufficient legal basis for data processing The Norwegian DPA imposed a fine of EUR 22,000 on Kristiansand municipality. The controller offers a helpline for childreen, which had become victims of violence, abuse or… NORWAY ·Datatilsynet ·Art. 6, 12, 13 Public Authority Personal Data IP Address Jun 10, 2025
€45,000 Noi Compriamo Auto.it S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 45,000 on Noi Compriamo Auto.it S.r.l. The controller contacted the data subject multiple times for direct marketing purposes via… ITALY ·Garante ·Art. 5, 6, 12 +2 Direct Marketing IP Address Marketing Jun 4, 2025
€45,000 Noi Compriamo Auto.it S.r.l.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 45.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +2 Data Controller Marketing Processing NL Jun 4, 2025
€5,000 AG-BROKER ASIGURARE S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €5.000 - De Roemeense nationale toezichthouder op de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL May 30, 2025
€42,000 LVMH IBERIA, S.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 42.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6 Personal Data Processing Controllers NL May 30, 2025
€5,000 AG-BROKER ASIGURARE S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on AG-BROKER ASIGURARE S.R.L. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Insurance May 30, 2025
€1.1M Yliopiston Apteekin: Non-compliance with general data processing principles The Finish DPA has imposed a fine of EUR 1,100,000 on Yliopiston Apteekin. The controller, who runs an online pharmacy, used various web analytics and monitoring tools. These… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 32 Controllers IP Address Audit Logs May 27, 2025
€1.4M REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 1,380,000 on REPSOL COMERCIALIZADORA DE ELECTRICIDAD Y GAS, S.L. The controller used outdated technical and organisational measures to manage… SPAIN ·aepd ·Art. 5, 32 Controllers Processing Agreement Security May 26, 2025
€1,200 Advocaat: Er is onvoldoende juridische basis voor de verwerking van gegevens. 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6 Processing Data Controller Controllers NL May 22, 2025
€1,000 MP Dumitru Viorel Focșa: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 1,000 on the MP Dumitru Viorel Focșa. The controller published a post on social media containing personal data of a third person. The… ROMANIA ·ANSPDCP ·Art. 5, 6 Social Media Personal Data Controllers May 22, 2025
€1,200 Attorney: Insufficient legal basis for data processing The Spanish DPA imposed a fine on an attorney. The controller processed data of a data subject without sufficient legal basis. The original fine of EUR 2,000 was reduced to EUR… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Agreement May 22, 2025
€1,000 MP Dumitru Viorel Focșa: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6 Data Controller Education Processing NL May 22, 2025
€21,000 Menarini Silicon Biosystems SpA: Niet-naleving van de algemene principes voor gegevensverwerking. 21.000 euro boete - Italiaanse Autoriteit voor de bescherming van persoonlijke gegevens (Garante). ITALY ·Garante ·Art. 5, 13 Health Data Healthcare Healthcare NL May 21, 2025
€7,000 Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 7,000 on Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North. The controller… ITALY ·Garante ·Art. 5, 9 Healthcare Health Data Personal Data May 21, 2025
€12,000 Data Diggers Market Research SRL: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van €12.000 - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 12, 14 +1 Data Controller Personal Data Processing NL May 21, 2025
€200,000 TELEFÓNICA MÓVILES ESPAÑA, S.A.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 200,000 on TELEFÓNICA MÓVILES ESPAÑA, S.A. The controller forwarded personal data to a third party without a sufficient legal basis. SPAIN ·aepd ·Art. 6 Processing Agreement Controllers Personal Data May 21, 2025
€12,000 Data Diggers Market Research SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 12,000 on Data Diggers Market Research SRL. The controller processed personal data without sufficient legal basis. The controller also… ROMANIA ·ANSPDCP ·Art. 6, 12, 14 +1 Personal Data Controllers IP Address May 21, 2025
€21,000 Menarini Silicon Biosystems SpA: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 21,000 on Menarini Silicon Biosystems SpA. The controller is conducting oncological research and has developed a software that is able to… ITALY ·Garante ·Art. 5, 13 Retention Period Healthcare Health Data May 21, 2025
€200,000 TELEFÓNICA MÓVILES ESPAÑA, S.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 200.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6 Processing Personal Data Data Controller NL May 21, 2025
€5,000 Maravet S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Health Data NL May 19, 2025