Skip to content
Content type · 3,429 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

351–400 of 3,429 sort newestlargest fineoldest
€15,000 Gemeente Curtarolo: Onvoldoende wettelijke basis voor de verwerking van gegevens. Een boete van 15.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +3 Video Surveillance Processing Data Controller NL Oct 23, 2025
€15,000 Ordine degli Avvocati di Latina: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on the Ordine degli Avvocati di Latina. The controller published a document relating to criminal proceedings that included… ITALY ·Garante ·Art. 5, 6, 10 Personal Data Education Controllers Oct 23, 2025
€865,000 Aktia Pankki Oyj: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 865.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Data Breaches Access Controls NL Oct 23, 2025
€80,000 SENDING TRANSPORTE Y COMUNICACIÓN, S.A.: Insufficient data processing agreement The Spanish DPA has imposed a fine of EUR 80,000 on SENDING TRANSPORTE Y COMUNICACIÓN, S.A. The fined entity is a subprocessor of the controller. It appointed another… SPAIN ·aepd ·Art. 28 Processing Agreement Controllers Processors Oct 22, 2025
€80,000 SENDING TRANSPORTE Y COMUNICACIÓN, S.A.: Onvoldoende overeenkomst met betrekking tot gegevensverwerking. Een boete van 80.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 28 Controllers Data Processor Processors NL Oct 22, 2025
€2,000 Bureau voor het innen van openstaande schulden S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Right of Access Personal Data Processing NL Oct 22, 2025
€2,000 Agency for Control of Outstanding Debts S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on the Agency for Control of Outstanding Debts S.R.L. The controller failed to adequatly react to a data subjects request to… ROMANIA ·ANSPDCP ·Art. 12, 15 Controllers Personal Data Supervisory Authorities Oct 22, 2025
€5,000 S.P.E.E.H. HIDROELECTRICA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on S.P.E.E.H. HIDROELECTRICA SA. A technical error in the controller's computer systems was exploited by attackers to cause a… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing Agreement Oct 20, 2025
€5,000 S.P.E.E.H. HIDROELECTRICA SA: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing NL Oct 20, 2025
€2,000 PRIME TRANSACTION SA: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Oct 16, 2025
€2.7M Experian Nederland B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 2,700,000 on Experian Nederland B.V. The controller, a company that determines individuals' creditworthiness and sells this information,… THE NETHERLANDS ·AP ·Art. 5, 6, 12 +2 Controllers Personal Data Insurance Oct 16, 2025
€2,000 PRIME TRANSACTION SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on PRIME TRANSACTION SA. The controller failed to implement adequate technical and organisational measures, resulting in a data… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Oct 16, 2025
€9.2M CAPITA PLC: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 8,000,000 (EUR 9,180,000) on CAPITA PLC. CAPITA PLC acts as the data controller for the CAPITA Group, which has suffered a cyber attack. The… UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers Processing Agreement Oct 15, 2025
€9.2M CAPITA PLC: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 9.180.000 euro boete - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers Processing NL Oct 15, 2025
€6.9M CAPITA PENSION SOLUTIONS LIMITED: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 6,000,000 (EUR 6,880,000) on CAPITA PENSION SOLUTIONS LIMITED. CAPITA PENSION SOLUTIONS LIMITED acts as the data processor for the CAPITA Group,… UNITED KINGDOM ·ICO ·Art. 32 Processors Security Controllers Oct 15, 2025
€5,000 Vellea Home SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Oct 13, 2025
€5,000 Vellea Home SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Vellea Home SRL. The controller failed to implement adequate technical and organisational measures, resulting in a data breach. ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Oct 13, 2025
AEPD sanctions 23andMe for security failures in credential-stuffing breach 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In… PS-00140-2025 ·Spain ·Art. 5, 9, 24 +2 Data Breaches Notification Obligation Integrity and Confidentiality Principle Oct 10, 2025
€10,000 Municipality of Moschato–Tavros: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 10,000 on the Municipality of Moschato–Tavros. The controller installed a video surveillance system in a depot to protect municipal… GREECE ·HDPA ·Art. 5, 12, 13 +1 Video Surveillance Monitoring Public Authority Oct 9, 2025
€6,000 Interprovincial Order of Medical Radiology Technicians and Technical Health Professions in Rehabilitation and Prevention of AQ - CH - PE - TE: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Interprovincial Order of Medical Radiology Technicians and Technical Health Professions in Rehabilitation and Prevention of… ITALY ·Garante ·Art. 5, 6, 37 Healthcare Controllers Processing Agreement Oct 9, 2025
€16,000 Order of Nursing Professions of Pisa: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 16,000 on the Order of Nursing Professions of Pisa. The controller is publishing a list of all professionals within their area of… ITALY ·Garante ·Art. 5, 6 Healthcare Controllers Processing Agreement Oct 9, 2025
€25,000 EON ENERGIE ROMANIA S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Data Breaches Controllers NL Oct 9, 2025
€5,000 FT Solutions S.r.l.: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van 5.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +7 Processing Processors Data Processor NL Oct 9, 2025
€5,000 FT Solutions S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on FT Solutions S.r.l. The fined entity had been active in direct marketing activities as a data processor. During these… ITALY ·Garante ·Art. 5, 6, 7 +7 Processors Controllers Integrity and Confidentiality Principle Oct 9, 2025
€25,000 EON ENERGIE ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on EON ENERGIE ROMANIA S.A. The controller failed to implement adequate technical and organisational measures, resulting in a… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Processing Agreement Oct 9, 2025
€10,000 Gemeente Moschato–Tavros: Onvoldoende juridische basis voor de verwerking van gegevens. Boete van €10.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 12, 13 +1 Processing Video Surveillance Education NL Oct 9, 2025
€16,000 Orde van Verpleegkundigen van Pisa: Onvoldoende wettelijke basis voor gegevensverwerking. Een boete van 16.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Health Data Healthcare Processing NL Oct 9, 2025
€30,000 THE RED KIWI, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 30,000 on THE RED KIWI, S.L. The controller created a WhatsApp group for its customers, disclosing the mobile phone numbers of other… SPAIN ·aepd ·Art. 5, 32 Controllers Processing Agreement Processing Oct 3, 2025
€30,000 THE RED KIWI, S.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 30.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 32 Personal Data Processing Data Controller NL Oct 3, 2025
€492,000 Bedrijf: Niet-naleving van algemene principes voor gegevensverwerking. 492.000 euro boete - Autoriteit voor gegevensbescherming van Hamburg (HmbBfDI). GERMANY ·HmbBfDI ·Non-compliance with general data processing principles Meaningful Human Review and Decision-Making Processing IP Address NL Sep 30, 2025
€492,000 Company: Non-compliance with general data processing principles The DPA of Hamburg has imposed a fine of EUR 492,000 on a company in the finance sector. The controller used automated systems to decide whether to approve a credit application,… GERMANY ·HmbBfDI ·Non-compliance with general data processing principles Insurance Controllers IP Address Sep 30, 2025
€195,000 Company: Insufficient fulfilment of data subjects rights The DPA of Hamburg has imposed a fine of EUR 195,000 on a company. The controller was active in direct marketing via post and failed to adequately respond to requests from data… GERMANY ·HmbBfDI ·Insufficient fulfilment of data subjects rights Personal Data Direct Marketing Controllers Sep 30, 2025
€195,000 Bedrijf: Onvoldoende naleving van de rechten van betrokkenen (betreffende hun persoonsgegevens). 195.000 euro boete - Autoriteit voor gegevensbescherming van Hamburg (HmbBfDI). GERMANY ·HmbBfDI ·Insufficient fulfilment of data subjects rights Personal Data Marketing Supervisory Authorities NL Sep 30, 2025
€600 Owner of a Tesla Car: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 600 on the owner of a Tesla car. The controller's car had seven cameras installed, which filmed while the car was in use and while it… AUSTRIA ·dsb ·Art. 5, 6, 12 +1 IP Address Controllers Personal Data Sep 29, 2025
€20,000 S.C. PRIMONET RO S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 20.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Privacy by Design & Default NL Sep 25, 2025
€15,000 Vimar S.p.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 15.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 13 Processing Controllers Data Controller NL Sep 25, 2025
€3,960 Comune di Pazzano: Insufficient cooperation with supervisory authority The Italian DPA has imposed a fine of EUR 3,960 on the Commune di Pazzano. The controller failed to comply with a order of the DPA. ITALY ·Garante ·Art. 12, 13, 58 Supervisory Authorities Supervision Public Authority Sep 25, 2025
€20,000 S.C. PRIMONET RO S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on S.C. PRIMONET RO S.R.L. The controller failed to implement adequate technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Processing Agreement Sep 25, 2025
€840 SERVACE S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 840 on SERVACE S.L. The controller used its employees' private email addresses for internal communication. The original fine of EUR 1,400… SPAIN ·aepd ·Art. 5, 6 Controllers IP Address Processing Agreement Sep 25, 2025
€3,960 Gemeente Pazzano: Onvoldoende samenwerking met de toezichthoudende instantie. Een boete van €3.960 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 12, 13, 58 Education Public Authority Supervisory Authorities NL Sep 25, 2025
€15,000 Vimar S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on Vimar S.p.A. The controller created an internal and personalised email account with the personal data of a third party, without… ITALY ·Garante ·Art. 5, 6, 13 Controllers IP Address Processing Agreement Sep 25, 2025
€1,000 Green.mec. s.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 1,000 on Green.mec. s.r.l. The controller failed to adequately respond to a former employee's request to exercise their data subject… ITALY ·Garante ·Art. 13, 15 Data Subject Rights Exercise Modalities and Procedures Controllers Personal Data Sep 25, 2025
€10,000 La Prima Srl: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on La Prima Srl. The controller sent direct marketing messages without a legal basis. They also failed to respond to a data… ITALY ·Garante ·Art. 6, 12, 17 +1 Direct Marketing Controllers Personal Data Sep 25, 2025
€1,000 Green.mec. s.r.l.: Onvoldoende naleving van de rechten van betrokkenen. Een boete van €1.000 - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 13, 15 Personal Data Right of Access Data Controller NL Sep 25, 2025
€10,000 La Prima Srl: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 6, 12, 17 +1 Personal Data Processing Data Controller NL Sep 25, 2025
€32,000 Provincia Autonoma di Bolzano: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 32,000 on the Provincia Autonoma di Bolzan. The controller implemented video surveillance with automated licence plate recognition… ITALY ·Garante ·Art. 5, 6, 12 +4 Video Surveillance IP Address Monitoring Sep 25, 2025
€3,000 Gemeente Isola del Gran Sasso: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 3.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 10 +2 Processing Data Controller Personal Data NL Sep 25, 2025