Skip to content
Content type · 2,395 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

351–400 of 2,395 sort newestlargest fineoldest
€8,000 PGS SOFA & CO SRL: Insufficient technical and organizational measures to ensure information security. ⇄ 8.000 euro boete - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Nov 17, 2025
€8,000 PGS SOFA & CO SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PGS SOFA & CO SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures. ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Nov 17, 2025
€4,750 Powiatowego Inspektora Sanitarnego w Policach: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 4750 on the Powiatowego Inspektora Sanitarnego w Policach. The controller failed to implement adequate technical and organisational… POLAND ·UODO ·Art. 5, 24, 25 +1 Security Encryption Controllers Nov 15, 2025
€72,000 AEPD · PS-00480-2025 Tiger Media Inc., the controller, operated an advertising platform for publishers and advertisers of adult products and services. The platform acted as an ad network, connecting… Spain ·Art. 6, 27 Legitimate Interest Controllers Processors Nov 14, 2025
€4,000 Fan Courier Express S.R.L.: Insufficient Compliance with Data Subject Rights. ⇄ Een boete van 4.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +2 Personal Data Processing Supervisory Authorities Nov 12, 2025
€4,000 Fan Courier Express S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 4,000 on Fan Courier Express S.R.L. The controller failed to adequately react to a data subject's request to exercise their rights, and… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +2 Personal Data Controllers Supervisory Authorities Nov 12, 2025
€2,000 Whitedecor SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on Whitedecor SRL. The controller had sent marketing messages to customers without a sufficient legal basis. ROMANIA ·ANSPDCP ·Art. 6, 7, 12 +3 Direct Marketing Controllers Personal Data Nov 10, 2025
€2,000 Whitedecor SRL: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 7, 12 +3 Personal Data Processing Supervisory Authorities Nov 10, 2025
€1,000 Company: Insufficient fulfilment of data subjects rights The Greek DPA has imposed a fine of EUR 1,000 on a Company. The controller failed to react adequately to a data subject's request to exercise their rights. GREECE ·HDPA ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Nov 7, 2025
€7,000 Klass Wagen S.R.L.: Insufficient technical and organizational measures to ensure information security. ⇄ Boete van €7.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Nov 7, 2025
€1,000 Company: Insufficient compliance with data subjects' rights (regarding their personal data). ⇄ Boete van €1.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 12, 15 Personal Data Right of Access Controllers Nov 7, 2025
€7,000 Klass Wagen S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 7,000 on Klass Wagen S.R.L. The controller suffered a cyber incident due to a former employee exposing the login credentials of… ROMANIA ·ANSPDCP ·Art. 32 Controllers Security Personal Data Nov 7, 2025
€2,556 Municipality of Kyustendil: Insufficient legal basis for data processing Bulgarian Commission for Personal Data Protection (KZLD) fined Municipality of Kyustendil €2,556 on 2025-11-01 for: Insufficient legal basis for data processing. Bulgaria ·CPDP ·Insufficient legal basis for data processing Public Authority Education Personal Data Nov 1, 2025
€6,000 APARELLS ORTOPEDICS CURTO, S.L: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 6,000 on APARELLS ORTOPEDICS CURTO, S.L. The controller was unable to retain the data it was required to ensure the availability of,… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Supervisory Authorities Oct 28, 2025
€300,000 SIA 'ZZ Dats': Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 300.000 euro - Inspectie gegevensbescherming (DSI). LATVIA ·DSI ·Art. 32 Security Controllers Processors Oct 28, 2025
€6,000 APARELLS ORTOPEDICS CURTO, S.L: Insufficient compliance with data subjects' rights. ⇄ Een boete van 6.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Personal Data Health Data Oct 28, 2025
€9,450 Gynecological center: Insufficient compliance with obligations to report data breaches. ⇄ Boete van €9.450 - Pools Nationaal Bureau voor de Bescherming van Persoonsgegevens (UODO). POLAND ·UODO ·Insufficient fulfilment of data breach notification obligations Data Breaches Personal Data Health Data Oct 27, 2025
€9,450 Gynecological Center: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 9,450 on a Gynecological Center. The controller sufferd a data breach and failed to report this to the DPO. POLAND ·UODO ·Insufficient fulfilment of data breach notification obligations Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 27, 2025
€20,000 Multimedia News Società Cooperativa: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 20,000 on Multimedia News Società Cooperativa. The controller failed to adequatly react to a request by a data subject to exercise their… ITALY ·Garante ·Art. 12 Personal Data Controllers Supervisory Authorities Oct 23, 2025
€5,000 Court Bailiff: Insufficient fulfilment of data breach notification obligations The Polish DPA has imposed a fine of EUR 5,000 on a court bailiff. The controller forwarded a letter containing personal data to the wrong person, failing to inform either the… POLAND ·UODO ·Art. 33, 34 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Oct 23, 2025
€20,000 Multimedia News Società Cooperativa: Insufficient compliance with data subjects' rights. ⇄ Een boete van 20.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 12 Personal Data Controllers Supervisory Authorities Oct 23, 2025
€15,000 Ordine degli Avvocati di Latina: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on the Ordine degli Avvocati di Latina. The controller published a document relating to criminal proceedings that included… ITALY ·Garante ·Art. 5, 6, 10 Controllers Personal Data Processing Oct 23, 2025
€4,000 'Statista Aldo Moro' Higher Education Institute in Fara Sabina: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 4,000 on the 'Statista Aldo Moro' Higher Education Institute in Fara Sabina. The controller published a protocol of disciplinary… ITALY ·Garante ·Art. 5, 6, 37 Public Authority Personal Data Controllers Oct 23, 2025
€2,000 Agency for Control of Outstanding Debts S.R.L.: Insufficient compliance with data subjects' rights. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Processing Supervision Oct 22, 2025
€2,000 Agency for Control of Outstanding Debts S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on the Agency for Control of Outstanding Debts S.R.L. The controller failed to adequatly react to a data subjects request to… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Oct 22, 2025
€5,000 S.P.E.E.H. HIDROELECTRICA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on S.P.E.E.H. HIDROELECTRICA SA. A technical error in the controller's computer systems was exploited by attackers to cause a… ROMANIA ·ANSPDCP ·Art. 32 Controllers Security Personal Data Oct 20, 2025
€5,000 S.P.E.E.H. HIDROELECTRICA SA: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Oct 20, 2025
€2.7M Experian Nederland B.V.: Insufficient legal basis for the processing of data. ⇄ 2.700.000 euro boete - Nederlandse Autoriteit Persoonsgegevens (AP). THE NETHERLANDS ·AP ·Art. 5, 6, 12 +2 Personal Data Controllers Processing Oct 16, 2025
€2,000 PRIME TRANSACTION SA: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Processing Oct 16, 2025
€2,000 PRIME TRANSACTION SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on PRIME TRANSACTION SA. The controller failed to implement adequate technical and organisational measures, resulting in a data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Oct 16, 2025
€2.7M Experian Nederland B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 2,700,000 on Experian Nederland B.V. The controller, a company that determines individuals' creditworthiness and sells this information,… THE NETHERLANDS ·AP ·Art. 5, 6, 12 +2 Personal Data Controllers Supervisory Authorities Oct 16, 2025
€5,000 Vellea Home SRL: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Oct 13, 2025
€5,000 Vellea Home SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Vellea Home SRL. The controller failed to implement adequate technical and organisational measures, resulting in a data breach. ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Oct 13, 2025
AEPD · PS-00140-2025 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In… PS-00140-2025 ·Spain ·Art. 5, 9, 24 +2 Data Breaches Notification Obligation Integrity and Confidentiality Principle Oct 10, 2025
€25,000 EON ENERGIE ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on EON ENERGIE ROMANIA S.A. The controller failed to implement adequate technical and organisational measures, resulting in a… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Oct 9, 2025
€25,000 E.ON ENERGIE ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Processing Personal Data Oct 9, 2025
€5,000 FT Solutions S.r.l.: Non-compliance with general principles of data processing. ⇄ Een boete van 5.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +7 Processors Processing Controllers Oct 9, 2025
€10,000 Municipality of Moschato–Tavros: Insufficient legal basis for the processing of data. ⇄ Boete van €10.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 12, 13 +1 Processing Controllers Personal Data Oct 9, 2025
€5,000 FT Solutions S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on FT Solutions S.r.l. The fined entity had been active in direct marketing activities as a data processor. During these… ITALY ·Garante ·Art. 5, 6, 7 +7 Integrity and Confidentiality Principle Processors Controllers Oct 9, 2025
€30,000 THE RED KIWI, S.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 30.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 32 Personal Data Processing Controllers Oct 3, 2025
€195,000 Company: Insufficient compliance with data subjects' rights (regarding their personal data). ⇄ 195.000 euro boete - Autoriteit voor gegevensbescherming van Hamburg (HmbBfDI). GERMANY ·HmbBfDI ·Insufficient fulfilment of data subjects rights Personal Data Direct Marketing Marketing Sep 30, 2025
€195,000 Company: Insufficient fulfilment of data subjects rights The DPA of Hamburg has imposed a fine of EUR 195,000 on a company. The controller was active in direct marketing via post and failed to adequately respond to requests from data… GERMANY ·HmbBfDI ·Insufficient fulfilment of data subjects rights Direct Marketing Personal Data Controllers Sep 30, 2025
€600 Owner of a Tesla car: Non-compliance with general principles of data processing. ⇄ 600 euro boete - Oostenrijkse Autoriteit voor Gegevensbescherming (dsb). AUSTRIA ·DSB ·Art. 5, 6, 12 +1 Processing Personal Data Transparency Sep 29, 2025
€600 Owner of a Tesla Car: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 600 on the owner of a Tesla car. The controller's car had seven cameras installed, which filmed while the car was in use and while it… AUSTRIA ·DSB ·Art. 5, 6, 12 +1 Controllers Personal Data Supervisory Authorities Sep 29, 2025
€15,000 Vimar S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on Vimar S.p.A. The controller created an internal and personalised email account with the personal data of a third party, without… ITALY ·Garante ·Art. 5, 6, 13 Controllers Personal Data Supervisory Authorities Sep 25, 2025
€3,000 Municipality of Isola del Gran Sasso: Insufficient legal basis for data processing. ⇄ Een boete van 3.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 10 +2 Public Authority Criminal Data Controllers Sep 25, 2025
€20,000 S.C. PRIMONET RO S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on S.C. PRIMONET RO S.R.L. The controller failed to implement adequate technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Sep 25, 2025
€1,000 Green.mec. s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,000 on Green.mec. s.r.l. The controller failed to adequately respond to a former employee's request to exercise their data subject… ITALY ·Garante ·Art. 13, 15 Personal Data Controllers Supervisory Authorities Sep 25, 2025
€3,000 Comune di Isola del Gran Sasso: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on the Comuni di Isola del Gran Sasso. The controller published a resolution on its institutional website which included the… ITALY ·Garante ·Art. 5, 6, 10 +2 Personal Data Controllers Supervisory Authorities Sep 25, 2025
€20,000 S.C. PRIMONET RO S.R.L.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 20.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Sep 25, 2025