Skip to content
Content type · 1,924 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

401–450 of 1,924 sort newestlargest fineoldest
€4,000 Georgescu Călin: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine on the politican Georgescu Călin. The controller failed to inform data subjects on his website regarding the processing of their data and how… ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Data Controller Jul 16, 2025
€20,000 NN Griekse levensverzekeringsmaatschappij met één aandeelhouder, anoniem: Onvoldoende naleving van de rechten van betrokkenen. Boete van 20.000 euro - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 15 Personal Data Data Controller Controllers NL Jul 11, 2025
€2,000 PAVLOS BIKOS SOLE PROPRIETORSHIP DENTAL PRIVATE CAPITAL COMPANY: Insufficient cooperation with supervisory authority The Greek DPA has imposed a fine of EUR 2,000 on PAVLOS BIKOS SOLE PROPRIETORSHIP DENTAL PRIVATE CAPITAL COMPANY. The fined party was a data processor in case ETid: 2880. During… GREECE ·HDPA ·Art. 31 Supervisory Authorities Supervision Controllers Jul 11, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on VALORA PREVENCIÓN, S.L.U. The controller, a company offering occupational health and safety services, failed to implement… SPAIN ·aepd ·Art. 5, 32 Health Data Security Healthcare Jul 11, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 32.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 32 Security Health Data Healthcare NL Jul 11, 2025
€20,000 NN Greek Single-Member Anonymous Life Insurance Company: Insufficient fulfilment of data subjects rights The Greek DPA has imposed a fine of EUR 20,000 on NN Greek Single-Member Anonymous Life Insurance Company. The controller failed to provide the data subject with the personal data… GREECE ·HDPA ·Art. 15 Right of Access Procedures Right of Access Insurance Jul 11, 2025
€10,000 Nursery School “La Combricola Dei Birichini Di Betty”: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on the Nursery School “La Combricola Dei Birichini Di Betty”. The controller only accepted new children if their parents agreed… ITALY ·Garante ·Art. 5, 6, 7 +5 IP Address Education Processing Agreement Jul 10, 2025
€3,000 Comune di Conversano: Lack of appointment of data protection officer The Italian DPA has imposed a fine of EUR 3,000 on the Comune di Conversano. The controller failed to correctly appoint a DPA. ITALY ·Garante ·Art. 37 Supervisory Authorities Public Authority Controllers Jul 10, 2025
€8,000 Università degli Studi di Cassino e del Lazio Meridionale: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 8,000 on Università degli Studi di Cassino e del Lazio Meridionale. The controller failed to delete a former employee's email address… ITALY ·Garante ·Art. 5, 6, 12 +2 Controllers IP Address Processing Agreement Jul 10, 2025
€50,000 Magna PT S.p.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Processing NL Jul 10, 2025
€4,000 Istituto Comprensivo 2 C.D. “G. Modugno” S.M. “G. Galilei” di Monopoli: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 4,000 on Istituto Comprensivo 2 C.D. “G. Modugno” S.M. “G. Galilei” di Monopoli. The controller published a list with the name of pupils… ITALY ·Garante ·Art. 5, 6, 9 Education Controllers Processing Agreement Jul 10, 2025
€4,000 Istituto Comprensivo 2 C.D. “G. Modugno” S.M. “G. Galilei” in Monopoli: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 4.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 Education Data Controller Processing NL Jul 10, 2025
€80,000 Poste Vita S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine on Poste Vita S.p.a. The controller failed to implement adequate technical and organisational measures to ensure data security. This resulted in… ITALY ·Garante ·Art. 5, 33 Security Insurance Personal Data Jul 10, 2025
€10,000 Kinderopvang "La Combricola Dei Birichini Di Betty": Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +5 Minors Education Marketing NL Jul 10, 2025
€8,000 Università degli Studi di Cassino e del Lazio Meridionale: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 8.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +2 Right to be Forgotten Data Controller Processing NL Jul 10, 2025
€80,000 Poste Vita S.p.a.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 33 Security Controllers Personal Data NL Jul 10, 2025
€50,000 Magna PT S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine on Magna PT S.p.A. Employees of the controllers were subjected to 'return to work interviews' after returning from an absence due to illness or… ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Retention Period Jul 10, 2025
€3,000 Gemeente Conversano: Gebrek aan benoeming van een functionaris voor gegevensbescherming. Een boete van 3.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 37 Education Supervisory Authorities Public Authority NL Jul 10, 2025
€6,000 CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Overtreding van de algemene principes voor gegevensverwerking. Boete van 6.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Controllers Data Controller Processing NL Jul 4, 2025
€3,000 Zougla TZI-AP, een anoniem massamediaconcern: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Boete van €3.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 31 Processing Personal Data Data Controller NL Jul 4, 2025
€6,000 CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 6,000 on CURENERGÍA COMERCIALIZADOR DE ÚLTIMO RECURSO S.A.U. The controller processed personal data in order to conclude a contract. But the… SPAIN ·aepd ·Art. 5 Controllers IP Address Processing Agreement Jul 4, 2025
€3,000 Zougla TZI-AP Anonymous Mass Media Company: Insufficient legal basis for data processing The Hellenic DPA has imposed a fine of EUR 3,000 on Zougla TZI-AP Anonymous Media Company. The controller, who operates a news website, published an article revealing the personal… GREECE ·HDPA ·Art. 5, 31 Controllers Personal Data Processing Jul 4, 2025
€900 ARCONADA 1932, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA imposed a fine of EUR 900 on ARCONADA 1932, S.L. The controller did not react adequatly to communication from the DPA. The original fine of EUR 1,500 was reduced… SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Controllers Jul 2, 2025
€900 ARCONADA 1932, S.L.: Onvoldoende samenwerking met de toezichthoudende instantie. 900 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 58 Supervisory Authorities Controllers Supervision NL Jul 2, 2025
€15,600 L. Zamenhof University Children's Clinical Hospital in Białystok: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 15,600 on the L. Zamenhof University Children's Clinical Hospital in Białystok. The controller did not implement sufficient technical and… POLAND ·UODO ·Art. 5, 32 Healthcare Security Healthcare Jun 30, 2025
€15,600 Kinderziekenhuis van de L. Zamenhof Universiteit in Białystok: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 15.600 euro boete - Poolse nationale instantie voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 32 Security Healthcare Health Data NL Jun 30, 2025
€3,000 Selgros Cash & Carry SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on Selgros Cash & Carry SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Jun 26, 2025
€96,000 SIDECU, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 96,000 on SIDECU, S.A. The controller introduced facial recognistion system as the only access method to their facilities, without offering… SPAIN ·aepd ·Art. 9, 13, 35 DPIA Privacy Impact Assessment IP Address Jun 26, 2025
€96,000 SIDECU, S.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 96.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 9, 13, 35 Processing Data Controller Controllers NL Jun 26, 2025
€3,000 SC Piramida Trade Invest SRL: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 3,000 on SC Piramida Trade Invest SRL. The controller processed personal data without a sufficient legal basis and without sufficient… ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +4 Personal Data Controllers Data Subject Rights Exercise Modalities and Procedures Jun 26, 2025
€3,000 SC Tremend Software Consulting SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on SC Tremend Software Consulting SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Processing Agreement Jun 26, 2025
€25,000 Partij "Alliantie voor de Unie van Roemenië": Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 25.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 25 +1 Security Processing Education NL Jun 26, 2025
€3,000 SC Tremend Software Consulting SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Jun 26, 2025
€25,000 Alliance for the Union of Romanians Party: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 25,000 on the Alliance for the Union of Romanians Party. The controller did not implement adeqaute technical and organisational measures… ROMANIA ·ANSPDCP ·Art. 5, 6, 25 +1 Data Breaches Security Controllers Jun 26, 2025
€3,000 SC Piramida Trade Invest SRL: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +4 Security Personal Data Processing NL Jun 26, 2025
€3,000 Selgros Cash & Carry SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Jun 26, 2025
€40,000 KARAMBELAS KONSTANTINOS & CO. E.E.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 40,000 on KARAMBELAS KONSTANTINOS & CO. E.E. The processor, which was processing data for a telecommunications provider (ETid: 2878),… GREECE ·HDPA ·Art. 29, 32 Security Telecommunications Processors Jun 25, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 550,000 on Vodafone – PANAFON A.E.E.T. The controller failed to implement sufficient technical and organisational measures to ensure data… GREECE ·HDPA ·Art. 5, 28 Controllers Telecommunications Security Jun 25, 2025
€550,000 Vodafone – PANAFON A.E.E.T.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 550.000 euro - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 28 Security Telecommunications Data Processor NL Jun 25, 2025
€10,000 Shield of David - K.I.D.A.F.: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Shield of David - K.I.D.A.F. The controller, a day care centre for people with autism, has legally installed video… GREECE ·HDPA ·Art. 5, 12, 13 +3 Video Surveillance Controllers Healthcare Jun 24, 2025
€7,000 General Hospital of the University of Larissa: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 7,000 on the General Hospital of the University of Larissa. The controller failed to adequately fulfil the rights of data subjects. It… GREECE ·HDPA ·Art. 5, 14, 15 Healthcare Healthcare Controllers Jun 24, 2025
€7,000 Algemeen Ziekenhuis van de Universiteit van Larissa: Onvoldoende naleving van de rechten van betrokkenen. Een boete van €7.000 - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 14, 15 Health Data Healthcare Personal Data NL Jun 24, 2025
€20,725 Birthlink: Insufficient technical and organisational measures to ensure information security The UK DPA has imposed a fine of £ 18,000 (EUR 20,725) on Birthlink. The controller, a scottish registered charity, failed to implement sufficient technical and organisational… UNITED KINGDOM ·ICO ·Art. 5, 32, 33 Security Controllers Processing Agreement Jun 24, 2025
€10,000 Shield of David - K.I.D.A.F.: Niet-naleving van algemene principes voor gegevensverwerking. Boete van €10.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 12, 13 +3 Personal Data Health Data Video Surveillance NL Jun 24, 2025
€4,000 Vodafone Romania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 4,000 on Vodafone Romania S.A. The controller failed to implement sufficient technical and organisational measures to ensure data… ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Telecommunications Jun 23, 2025
€50,000 Piraeus Bank S.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 50.000 euro - Hellenic Data Protection Authority (HDPA). GREECE ·HDPA ·Art. 5, 6 Personal Data Processing Data Controller NL Jun 23, 2025
€4,000 Vodafone Romania S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 4.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ANSPDCP ·Art. 25 ·Insufficient technical and organisational measures to ensure information security Security Data Breaches Telecommunications NL Jun 23, 2025
€3,500 Gemeentelijk Sociaal Hulpcentrum Aleksandrów: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 3.500 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 32 Security Data Breaches Education NL Jun 23, 2025
€3,500 Municipal Social Welfare Center Aleksandrów: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 3,500 on the Municipal Social Welfare Center in Aleksandrów. The controller did not implement sufficient technical and organisational… POLAND ·UODO ·Art. 32 Data Breaches Security IP Address Jun 23, 2025