Skip to content
Content type · 3,589 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

351–400 of 3,589 sort newestlargest fineoldest
€500 VOX ESPAÑA: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500 on VOX ESPAÑA. The controller, a political party, posted a picture of of a receipt on its Facebook page. The picture of the recipt… SPAIN ·AEPD ·Art. 6 Personal Data Controllers IP Address Jan 10, 2026
€8,000 KVIKU SPAIN, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 8,000 on KVIKU SPAIN, S.L.The controller requires customers to send a photo of themselves holding their ID card when verifying their… AEPD ·Art. 5 ·Non-compliance with general data processing principles Retention Period Controllers Processing Jan 10, 2026
€18,500 Komendanta Miejskiego Policji w Krakowie: Non-compliance with general data processing principles The Polish DPA has imposd a fine of EUR 18,500 on the Komendanta Miejskiego Policji w Krakowie. The controller published personal data, including health data, of a data subject… POLAND ·UODO ·Non-compliance with general data processing principles Personal Data Education Public Authority Jan 9, 2026
The controller, an Austrian registered association, operates a therapy centre for psychosomatic illnesses The data subject was a patient of the controller. On 28 July 2025, the data subject sent an access request by email under Article 15 GDPR, asking for full information on all… DSB-D124.2437/25 ·Austria ·DSB Right of Access Personal Data Controllers Jan 9, 2026
€27M FREE MOBILE: Insufficient technical and organizational measures to ensure information security. ⇄ 27 miljoen euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 5, 32 Security Controllers Personal Data Jan 8, 2026
€15M FREE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 15,000,000 on FREE. The controller suffered a data breach due to insufficient technical and organisational measures. This was caused by… FRANCE ·CNIL ·Art. 32, 34 Data Breaches Security Controllers Jan 8, 2026
€2,000 Money Seeds S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Money Seeds S.R.L. The controller failed to fulfil a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervisory Authorities Jan 8, 2026
€10,000 Headquarter of a Fire Brigade: Insufficient legal basis for data processing The Greek DPA has imposed a fine of EUR 10,000 on a Fire Brigade Head Quarter. The controller had stored health data of an employee which had been in relation with her sick leave.… GREECE ·HDPA ·Art. 5 Controllers Processing Health Data Jan 8, 2026
€27M FREE MOBILE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 27,000,000 on FREE MOBILE. The controller suffered a data breach due to insufficient technical and organisational measures. This was… FRANCE ·CNIL ·Art. 5, 32 Personal Data Controllers Security Jan 8, 2026
€2,000 Money Seeds S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. ⇄ The Romanian supervisory authority ANSPDCP has imposed a fine of 2,000 euros on Money Seeds S.R.L., a financial and consultancy company, for failing to honor a data subject's… ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervision Jan 8, 2026
VDAI (Lithuania) - Decision no. 3R-1700. ⇄ Facts: The Data Protection Authority (DPA) ruled that a gambling provider had lawfully transferred data to a processor for the purpose of sending invitations to sporting events,… 3R-1700 ·Litouwen Controllers Fairness & Transparency Personal Data Jan 7, 2026
Decision No. 3R-1700. Facts: The data protection authority (DPA) ruled that a gambling operator had lawfully transferred data to a processor for the purpose of sending invitations to sporting events,… 3R-1700 ·Lithuania ·VDAI Personal Data Fairness & Transparency Processors Jan 7, 2026
€400,000 AEPD fines two telecom providers €400,000 and €300,000 for SIM card fraud Facts: The Data Protection Authority has fined a telecommunications company €400,000 for unlawfully changing the ownership of a mobile phone subscription and issuing a dual SIM… Spain ·Art. 6 Telecommunications IP Address Identification Jan 7, 2026
€6,820 Austrian media company fined €6,820 for failing to comply with order to fix cookie banner An Austrian media company has been fined €6,820 by the Data Protection Authority because it failed to implement a binding instruction to modify the cookie banner on its website.… Austria ·DSB ·Art. 58 Right to be Forgotten Supervisory Authorities Cookies Jan 7, 2026
AEPD: fines of €400,000 and €300,000 for telecom providers in SIM card fraud ⇄ Facts: The Data Protection Authority has imposed a fine of 400,000 euros on a telephone company for unlawfully changing the ownership of a mobile phone subscription and issuing a… EXP202306073 ·Spanje Telecommunications Personal Data Supervisory Authorities Jan 7, 2026
€5,000 Sole Trader: Non-compliance with general data processing principles Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Sole Trader €5,000 on 2026-01-06 for: Non-compliance with general data processing principles. Slovenia ·IP-RS ·Art. 5 Processing Supervision IP Address Jan 6, 2026
€232,379 Polish Postal Service: Lack of appointment of data protection officer The Polish DPA has imposed a fine of EUR 232,379 on the Polish Postal Service. The controller appointed a person as DPO who also held a managerial position with authority over… POLAND ·UODO ·Art. 38 Supervisory Authorities Controllers Personal Data Jan 2, 2026
€1,282 Unknown legal entity: Insufficient data processing agreement The Slovenian Supervisory Authority (Informacijski pooblaščenec) fined an unnamed legal entity €1,282 for maintaining an insufficient data processing agreement. The enforcement… Slovenia ·IP-RS ·Art. 28 Supervision Supervisory Authorities Processing Agreement Jan 1, 2026
€5,000 REVMA PLUS Retail S.A.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 5,000 on REVMA PLUS Retail S.A.. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… GREECE ·HDPA ·Art. 32 Controllers Processors Personal Data Dec 31, 2025
€6,000 I Mathisi: Insufficient fulfilment of data subjects rights Hellenic Data Protection Authority (HDPA) fined I Mathisi €6,000 on 2025-12-31 for: Insufficient fulfilment of data subjects rights. Greece ·HDPA ·Art. 12, 15, 31 Personal Data Supervisory Authorities Education Dec 31, 2025
€10,000 Thessaloniki–Thessaly Gas Supply Company S.A.: Insufficient data processing agreement The Greek DPA has imposed a fine of EUR 10,000 on Thessaloniki–Thessaly Gas Supply Company S.A. The controller, an energy provider, used external processors for direct marketing… GREECE ·HDPA ·Art. 28, 32 Controllers Processors Supervisory Authorities Dec 31, 2025
€10,000 SIGMA & KAPPA IMPORTING SOCIÉTÉ ANONYME: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 10,000 on SIGMA & KAPPA IMPORTING SOCIÉTÉ ANONYME. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A.… GREECE ·HDPA ·Art. 32 Processors Controllers Security Dec 31, 2025
€80,000 ONE WAY PRIVATE COMPANY: Non-compliance with general data processing principles The Greek DPA has imposed a fine of EUR 80,000 on ONE WAY PRIVATE COMPANY. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… GREECE ·HDPA ·Art. 5, 6, 7 +2 Processors Controllers Personal Data Dec 31, 2025
€60,000 ENDESA (energy supplyer): Insufficient legal basis for data processing The complainant's bank account was charged by ENDESA, the beneficiary of which was a third party, who had been convicted under criminal law and imposed with a two-year restraining… SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Processing IP Address
€10,000 Ikea Ibérica: Insufficient legal basis for data processing The company installed cookies on an end users terminal device without prior consent of the data subject. SPAIN ·AEPD ·Art. 6 Consent Personal Data Cookies
€20,000 Telecommunications company: Insufficient legal basis for data processing. ⇄ The Croatian data protection authority (DPA) has imposed a fine of 20,000 euros on a telecommunications company. A data subject had filed a complaint with the DPA, claiming that… CROATIA ·AZOP ·Art. 5, 6 Personal Data Processing Accountability Dec 30, 2025
€3.5M Company: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 3,500,000 on a company. The controller operated a loyalty program in France and 16 other EU countries, using customer data obtained… FRANCE ·CNIL ·Art. 6, 13, 32 +1 Controllers International Transfer DPIA Dec 30, 2025
€5,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The spanish telecommunications and informations agancy (SETSI) decided Vodafone had to reimburse a customer for costs he was wrongfully charged for. Nevertheless, Vodafone… SPAIN ·AEPD ·Art. 5 Personal Data Processing Telecommunications
€50 GERMANY DPA: Insufficient legal basis for data processing Unlawful use of a dashcam Art. 6 ·Insufficient legal basis for data processing Supervisory Authorities Processing Agreement Processing
€960 POLAND, Personal Data Protection Authority: Insufficient cooperation with the supervisory authority. ⇄ Een boete van 960 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). UODO ·Art. 58 ·Insufficient cooperation with supervisory authority Personal Data Supervisory Authorities Supervision Dec 30, 2025
€12,000 Madrileña Red de Gas: Insufficient technical and organisational measures to ensure information security The gas company did not have appropriate measures in place to verify the identity of the data subject. The person who filed the complaint alleges that the company e-mailed his… SPAIN ·AEPD ·Art. 32 Personal Data Security Law Enforcement
€9,600 Restaurant (SANTI 3000, S.L.): Insufficient legal basis for data processing A restaurant wanted to impose disciplinary sanctions on an employee using images from a mobile phone video which was recorded by another employee in the restaurant for evidence… SPAIN ·AEPD ·Art. 5, 6 Processing Employees IP Address
€118 GERMANY, DPA: Insufficient legal basis for data processing. ⇄ 118 euro boete - Autoriteit voor gegevensbescherming van Saarland. Art. 6 ·Insufficient legal basis for data processing Processing Supervisory Authorities Processing Agreement Dec 30, 2025
€10,000 Roumasport S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on Roumasport S.R.L The controller failed to implement adequate technical and organisational measures, resulting in multiple… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Dec 30, 2025
SLOVAKIA DPA: Insufficient legal basis for data processing Personal data have been unlawfully published on the website of a city within the framework of fulfilling its disclosure obligation under the Freedom of Information Act. However,… Slovak Data Protection Office ·Art. 5, 6 ·Insufficient legal basis for data processing Personal Data Consent Processing
SLOVAKIA DPA: Insufficient fulfilment of data subjects rights A Data Controller failed to comply with data subject´s request to access his/her personal data processed by audio recordings. Slovak Data Protection Office ·Art. 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Controllers
€27,000 Vodafone España, S.A.U.: Insufficient fulfilment of data subjects rights Although the complainant (a former Vodafone customer) had requested Vodafone to delete his data in 2015 and this request had been confirmed by the company, he received more than… SPAIN ·AEPD ·Art. 5 Personal Data Telecommunications Supervisory Authorities
€960 POLAND DPA: Insufficient cooperation with supervisory authority The Polish DPA (UODO) has fined a data controller EUR 1,450 for failing to provide information requested by the DPA during an investigation. UODO ·Art. 58 ·Insufficient cooperation with supervisory authority Supervision Supervisory Authorities Controllers
SLOVAKIA DPA: Insufficient technical and organisational measures to ensure information security Documents containing personal data were disposed of in the area of the municipal garbage dump. Slovak Data Protection Office ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Supervisory Authorities
€10,000 Roumasport S.R.L: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van €10.000 - De Roemeense nationale toezichthouder op de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Dec 30, 2025
€118 GERMANY DPA: Insufficient legal basis for data processing Illegal disclosure of personal data relating to a third party. Art. 6 ·Insufficient legal basis for data processing Personal Data Supervisory Authorities Processing Agreement
€20,000 Telecommunications company: Insufficient legal basis for data processing The Croatian DPA (azop) has imposed a fine of EUR 20,000 on a telecommunications company. A data subject had filed a complaint with the DPA claiming that the company was still… CROATIA ·AZOP ·Art. 5, 6 Personal Data Processing Telecommunications
SLOVAKIA DPA: Insufficient technical and organisational measures to ensure information security Violation of information security measures (no further information available at the moment) Slovak Data Protection Office ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Supervisory Authorities Processing Agreement
€600 GERMANY DPA: Insufficient legal basis for data processing Unlawful use of a dashcam Art. 6 ·Insufficient legal basis for data processing Supervisory Authorities Processing Agreement Processing
€300 GERMANY DPA: Insufficient legal basis for data processing Unlawful use of a dashcam Art. 6 ·Insufficient legal basis for data processing Supervisory Authorities Processing Agreement Processing
€60,000 Debt collecting agancy (GESTIÓN DE COBROS, YO COBRO SL): Insufficient legal basis for data processing After the claimant did alledgedly not pay back a microcredit to an online credit agany, the claim was assigned to the debt collecting agancy. Subsequently, the latter startet… SPAIN ·AEPD ·Art. 5 Processing Insurance Supervisory Authorities
€1,600 NAROBESA INV, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,600 on NAROBESA INV, S.L. The controller failed to react to requests made by the DPA. The original fine of EUR 2,000 was reduced to EUR… SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Controllers Dec 29, 2025
€2,000 Order of General Nurses, Midwives and Medical Assistants of Romania – Neamt Branch: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 2,000 on the Order of General Nurses, Midwives and Medical Assistants of Romania – Neamt Branch. The controller used video surveillance… ANSPDCP ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Controllers Supervisory Authorities Processing Dec 29, 2025
€2,000 Order of General Nurses, Midwives and Medical Assistants of Romania – Neamt Branch: Non-compliance with the general principles of data processing. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Processing Supervisory Authorities Supervision Dec 29, 2025
€1,600 NAROBESA INV, S.L.: Insufficient cooperation with the supervisory authority. ⇄ 1.600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 58 Supervisory Authorities Controllers Supervision Dec 29, 2025