Skip to content
Content type · 2,636 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

351–400 of 2,636 sort newestlargest fineoldest
€7,000 Klass Wagen S.R.L.: Insufficient technical and organizational measures to ensure information security. ⇄ Boete van €7.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Nov 7, 2025
€10M Aena, a small and medium-sized enterprise (SME), S.A.: Non-compliance with the general principles of data processing. ⇄ 10.043.002 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 35 DPIA Controllers Processing Nov 6, 2025
€10M Aena, S.M.E., S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 10,043,002 on Aena, S.M.E., S.A. The controller conducted a pilot project involving multiple airports, including the use of facial… SPAIN ·AEPD ·Art. 35 DPIA Controllers Supervisory Authorities Nov 6, 2025
€2,556 Municipality of Kyustendil: Insufficient legal basis for data processing Bulgarian Commission for Personal Data Protection (KZLD) fined Municipality of Kyustendil €2,556 on 2025-11-01 for: Insufficient legal basis for data processing. Bulgaria ·CPDP ·Insufficient legal basis for data processing Public Authority Education Personal Data Nov 1, 2025
€300,000 SIA 'ZZ Dats': Insufficient technical and organisational measures to ensure information security The Latvian DPA has imposed a fine of EUR 300,000 on SIA 'ZZ Dats'. The entity that was fined was the data processor for almost all local governments in Latvia. It failed to… LATVIA ·DSI ·Art. 32 Processors Security Controllers Oct 28, 2025
€300,000 SIA 'ZZ Dats': Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 300.000 euro - Inspectie gegevensbescherming (DSI). LATVIA ·DSI ·Art. 32 Security Controllers Processors Oct 28, 2025
€1,500 Shop Owner: Insufficient legal basis for data processing Austrian Data Protection Authority (dsb) fined Shop Owner €1,500 on 2025-10-27 for: Insufficient legal basis for data processing. Austria ·DSB ·Art. 5, 6 Processing IP Address Human Resources Oct 27, 2025
€1,000 Mayor of the Municipality of Calvi Risorta: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on the Mayor of the Municipality of Calvi Risorta. The controller published citizens' health data during the Covid-19 pandemic… ITALY ·Garante ·Art. 5, 6, 9 Healthcare Types of Special Categories of Personal Data Controllers Oct 23, 2025
€15,000 Ordine degli Avvocati di Latina: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on the Ordine degli Avvocati di Latina. The controller published a document relating to criminal proceedings that included… ITALY ·Garante ·Art. 5, 6, 10 Controllers Personal Data Processing Oct 23, 2025
€4,000 Higher Education Institution 'Statista Aldo Moro' in Fara Sabina: Insufficient Legal Basis for Data Processing ⇄ Een boete van 4.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 37 Controllers Education Public Authority Oct 23, 2025
€15,000 Municipality of Curtarolo: Insufficient Legal Basis for Data Processing. ⇄ Een boete van 15.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +3 Controllers Processing DPIA Oct 23, 2025
€4,000 'Statista Aldo Moro' Higher Education Institute in Fara Sabina: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 4,000 on the 'Statista Aldo Moro' Higher Education Institute in Fara Sabina. The controller published a protocol of disciplinary… ITALY ·Garante ·Art. 5, 6, 37 Public Authority Personal Data Controllers Oct 23, 2025
€1,000 Mayor of the Municipality of Calvi Risorta: Insufficient legal basis for data processing. ⇄ Een boete van €1.000 - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 Health Data Types of Special Categories of Personal Data Healthcare Oct 23, 2025
€15,000 Comune di Curtarolo: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on the Comune di Curtarolo. The controller used surveillance footage in disciplinary proceedings against an employee, and also… ITALY ·Garante ·Art. 5, 6, 12 +3 Controllers Monitoring Supervisory Authorities Oct 23, 2025
€15,000 Bar Association of Latina: Insufficient legal basis for the processing of data. ⇄ Een boete van 15.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 10 Criminal Data Public Authority Controllers Oct 23, 2025
€80,000 SENDING TRANSPORTE Y COMUNICACIÓN, S.A.: Insufficient agreement regarding data processing. ⇄ Een boete van 80.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 28 Controllers Processors Processing Oct 22, 2025
€80,000 SENDING TRANSPORTE Y COMUNICACIÓN, S.A.: Insufficient data processing agreement The Spanish DPA has imposed a fine of EUR 80,000 on SENDING TRANSPORTE Y COMUNICACIÓN, S.A. The fined entity is a subprocessor of the controller. It appointed another… SPAIN ·AEPD ·Art. 28 Controllers Processors Supervisory Authorities Oct 22, 2025
€2,000 Agency for Control of Outstanding Debts S.R.L.: Insufficient compliance with data subjects' rights. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Processing Supervision Oct 22, 2025
€2,000 Agency for Control of Outstanding Debts S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on the Agency for Control of Outstanding Debts S.R.L. The controller failed to adequatly react to a data subjects request to… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Oct 22, 2025
€5,000 S.P.E.E.H. HIDROELECTRICA SA: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Oct 20, 2025
€5,000 S.P.E.E.H. HIDROELECTRICA SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on S.P.E.E.H. HIDROELECTRICA SA. A technical error in the controller's computer systems was exploited by attackers to cause a… ROMANIA ·ANSPDCP ·Art. 32 Controllers Security Personal Data Oct 20, 2025
€2,000 PRIME TRANSACTION SA: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Processing Oct 16, 2025
€2.7M Experian Nederland B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 2,700,000 on Experian Nederland B.V. The controller, a company that determines individuals' creditworthiness and sells this information,… THE NETHERLANDS ·AP ·Art. 5, 6, 12 +2 Personal Data Controllers Supervisory Authorities Oct 16, 2025
€2,000 PRIME TRANSACTION SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on PRIME TRANSACTION SA. The controller failed to implement adequate technical and organisational measures, resulting in a data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Oct 16, 2025
€2.7M Experian Nederland B.V.: Insufficient legal basis for the processing of data. ⇄ 2.700.000 euro boete - Nederlandse Autoriteit Persoonsgegevens (AP). THE NETHERLANDS ·AP ·Art. 5, 6, 12 +2 Personal Data Controllers Processing Oct 16, 2025
€9.2M CAPITA PLC: Insufficient technical and organizational measures to ensure information security. ⇄ 9.180.000 euro boete - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 5, 32 Security Controllers Processing Oct 15, 2025
€6.9M CAPITA PENSION SOLUTIONS LIMITED: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 6,000,000 (EUR 6,880,000) on CAPITA PENSION SOLUTIONS LIMITED. CAPITA PENSION SOLUTIONS LIMITED acts as the data processor for the CAPITA Group,… UNITED KINGDOM ·ICO ·Art. 32 Processors Controllers Security Oct 15, 2025
€6.9M CAPITA PENSION SOLUTIONS LIMITED: Inadequate technical and organisational measures to ensure information security. ⇄ Een boete van 6.880.000 euro - Informatiecommissaris (ICO). UNITED KINGDOM ·ICO ·Art. 32 Security Controllers Processors Oct 15, 2025
€9.2M CAPITA PLC: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 8,000,000 (EUR 9,180,000) on CAPITA PLC. CAPITA PLC acts as the data controller for the CAPITA Group, which has suffered a cyber attack. The… UNITED KINGDOM ·ICO ·Art. 5, 32 Controllers Security Processing Oct 15, 2025
€5,000 Vellea Home SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Vellea Home SRL. The controller failed to implement adequate technical and organisational measures, resulting in a data breach. ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Oct 13, 2025
€5,000 Vellea Home SRL: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Processing Personal Data Oct 13, 2025
AEPD · PS-00140-2025 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In… PS-00140-2025 ·Spain ·Art. 5, 9, 24 +2 Data Breaches Notification Obligation Integrity and Confidentiality Principle Oct 10, 2025
€16,000 Order of Nursing Professions of Pisa: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 16,000 on the Order of Nursing Professions of Pisa. The controller is publishing a list of all professionals within their area of… ITALY ·Garante ·Art. 5, 6 Controllers Processing Healthcare Oct 9, 2025
€6,000 Interprovincial Order of Medical Radiology Technicians and Technical Health Professions in Rehabilitation and Prevention of AQ - CH - PE - TE: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Interprovincial Order of Medical Radiology Technicians and Technical Health Professions in Rehabilitation and Prevention of… ITALY ·Garante ·Art. 5, 6, 37 Controllers Supervisory Authorities Processing Oct 9, 2025
€25,000 E.ON ENERGIE ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Processing Personal Data Oct 9, 2025
€10,000 Municipality of Moschato–Tavros: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 10,000 on the Municipality of Moschato–Tavros. The controller installed a video surveillance system in a depot to protect municipal… GREECE ·HDPA ·Art. 5, 12, 13 +1 Controllers Processing Supervisory Authorities Oct 9, 2025
€5,000 FT Solutions S.r.l.: Non-compliance with general principles of data processing. ⇄ Een boete van 5.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +7 Processors Processing Controllers Oct 9, 2025
€5,000 FT Solutions S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on FT Solutions S.r.l. The fined entity had been active in direct marketing activities as a data processor. During these… ITALY ·Garante ·Art. 5, 6, 7 +7 Integrity and Confidentiality Principle Processors Controllers Oct 9, 2025
€25,000 EON ENERGIE ROMANIA S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 25,000 on EON ENERGIE ROMANIA S.A. The controller failed to implement adequate technical and organisational measures, resulting in a… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Oct 9, 2025
€16,000 Order of Nurses of Pisa: Insufficient legal basis for data processing. ⇄ Een boete van 16.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Health Data Controllers Processing Oct 9, 2025
€10,000 Municipality of Moschato–Tavros: Insufficient legal basis for the processing of data. ⇄ Boete van €10.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 12, 13 +1 Processing Controllers Personal Data Oct 9, 2025
€30,000 THE RED KIWI, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 30,000 on THE RED KIWI, S.L. The controller created a WhatsApp group for its customers, disclosing the mobile phone numbers of other… SPAIN ·AEPD ·Art. 5, 32 Controllers Processing Processing Agreement Oct 3, 2025
€30,000 THE RED KIWI, S.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 30.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5, 32 Personal Data Processing Controllers Oct 3, 2025
€492,000 Company: Non-compliance with general data processing principles The DPA of Hamburg has imposed a fine of EUR 492,000 on a company in the finance sector. The controller used automated systems to decide whether to approve a credit application,… GERMANY ·HmbBfDI ·Non-compliance with general data processing principles Insurance Controllers Supervisory Authorities Sep 30, 2025
€492,000 Company: Non-compliance with general principles for data processing. ⇄ 492.000 euro boete - Autoriteit voor gegevensbescherming van Hamburg (HmbBfDI). GERMANY ·HmbBfDI ·Non-compliance with general data processing principles Meaningful Human Review and Decision-Making Supervisory Authorities Processing Sep 30, 2025
€600 Owner of a Tesla car: Non-compliance with general principles of data processing. ⇄ 600 euro boete - Oostenrijkse Autoriteit voor Gegevensbescherming (dsb). AUSTRIA ·DSB ·Art. 5, 6, 12 +1 Processing Personal Data Transparency Sep 29, 2025
€600 Owner of a Tesla Car: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 600 on the owner of a Tesla car. The controller's car had seven cameras installed, which filmed while the car was in use and while it… AUSTRIA ·DSB ·Art. 5, 6, 12 +1 Controllers Personal Data Supervisory Authorities Sep 29, 2025
€3,000 Comune di Isola del Gran Sasso: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 3,000 on the Comuni di Isola del Gran Sasso. The controller published a resolution on its institutional website which included the… ITALY ·Garante ·Art. 5, 6, 10 +2 Personal Data Controllers Supervisory Authorities Sep 25, 2025
€20,000 S.C. PRIMONET RO S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 20,000 on S.C. PRIMONET RO S.R.L. The controller failed to implement adequate technical and organisational measures to ensure data… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Sep 25, 2025