Skip to content
Content type · 2,256 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

401–450 of 2,256 sort newestlargest fineoldest
€5,000 Maravet S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Health Data Data Breaches NL May 19, 2025
€1,000 Home Owner Association: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 1,000 on a home owner association. The HOA displayed the personal data of debtors in the entrance hall of a building, which infringed on the… SPAIN ·aepd ·Art. 5 Professional Secrecy Integrity and Confidentiality Principle Personal Data May 19, 2025
€200,000 ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 200,000 on ASNEF-EQUIFAX, SERVICIOS DE INFORMACIÓN SOBRE SOLVENCIA Y CRÉDITO, S.L. The controller obtained personal data from a third party… SPAIN ·aepd ·Art. 6, 17 Controllers Insurance Processing Agreement May 19, 2025
€5,000 Maravet S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Maravet S.R.L. The controller did not implement sufficient technical and organisational measures to ensure information… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Healthcare May 19, 2025
€5,000 ACCOUNTING & AUDIT CONSULTING SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on ACCOUNTING & AUDIT CONSULTING SRL. The controller did not implement sufficient technical and organisational measures to ensure… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers May 16, 2025
€5,000 ACCOUNTING & AUDIT CONSULTING SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL May 16, 2025
€30,000 ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Boete van 30.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Controllers Personal Data Processing NL May 16, 2025
€900,000 SOLOCAL MARKETING SERVICES: Insufficient legal basis for data processing The French DPA imposed a fine of EUR 900,000 on SOLOCAL MARKETING SERVICES. The controller, a company that also engages in direct marketing activities for its clients, ist using… FRANCE ·CNIL ·Art. 6, 7 Direct Marketing Controllers Processing Agreement May 15, 2025
€900,000 SOLOCAL MARKETING SERVICES: Onvoldoende juridische basis voor gegevensverwerking. 900.000 euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 6, 7 Data Controller Processing Consent NL May 15, 2025
€2,000 CVA TAX & FINANCE S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL May 14, 2025
€2,000 CVA TAX & FINANCE S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 CVA TAX & FINANCE S.R.L. The controller did not implement sufficient technical and organisational measures to ensure information… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Insurance May 14, 2025
€2,000 Romoffice Construct Holding Ag SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 Romoffice Construct Holding Ag SRL. The controller processed personal data without a sufficient legal basis. ROMANIA ·ANSPDCP ·Art. 5, 6 Controllers Processing Agreement Personal Data May 13, 2025
€2,000 Romoffice Construct Holding Ag SRL: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6 Processing Personal Data Controllers NL May 13, 2025
€2,000 CV PRO CONSULT S.R.L.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on CV PRO CONSULT S.R.L. The controller did not implement sufficient technical and organisational measures to ensure information… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers May 12, 2025
€2,000 CV PRO CONSULT S.R.L.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL May 12, 2025
€5,000 ROUMASPORT SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 5,000 on ROUMASPORT SRL. The controller accessed surveillance cameras to monitor its employees without a sufficient legal basis. The… ROMANIA ·ANSPDCP ·Art. 5, 6 Video Surveillance Monitoring Controllers May 9, 2025
€5,000 ROUMASPORT SRL: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 5.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6 Processing Video Surveillance Personal Data NL May 9, 2025
€6,600 Owner of a Pharmacy Office: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the owner of a pharmacy office. The controller processed data of residents of two geriatric centers without a sufficient legal basis. The… SPAIN ·aepd ·Art. 6, 14, 32 Controllers Encryption IP Address May 9, 2025
€6,600 Eigenaar van een apotheek: Niet-naleving van algemene principes voor gegevensverwerking. Boete van 6.600 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6, 14, 32 Health Data Data Controller Processing NL May 9, 2025
€6,600 Eigenaar van een apotheek: Overtreding van de algemene principes van gegevensverwerking. Een boete van 6.600 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6, 14, 32 Health Data Processing Data Controller NL May 8, 2025
€6,600 Owner of a Pharmacy Office: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the owner of a pharmacy office. The controller processed data of residents of geriatric centers without a sufficient legal basis. The… SPAIN ·aepd ·Art. 6, 14, 32 Encryption Controllers Healthcare May 8, 2025
€530M TikTok Technology Limited: Insufficient legal basis for data processing The Irish DPA (DPC) has fined TikTok EUR 530 million. In its decision, the DPC found, that TikTok infringed Art. 13 (1) f) GDPR and Art. 46 (1) GDPR due to the unlawful transfer… Art. 13, 46 Social Media Processing Agreement International Transfer May 2, 2025
€7,000 Bedrijf: Niet-naleving van algemene principes voor gegevensverwerking. Boete van €7.000 - Nationale Commissie voor de Bescherming van Persoonsgegevens (CNPD). LUXEMBOURG ·CNPD ·Art. 30 Processing Personal Data IP Address NL Apr 30, 2025
€40,000 MA Immobiliare S.r.l.s.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15,000 on MA Immobiliare S.r.l.s. The controller obtained personal data of potential customers by Realmaps S.r.l., which obtained the… ITALY ·Garante ·Art. 5, 6, 7 +6 IP Address Marketing Controllers Apr 29, 2025
€40,000 MA Immobiliare S.r.l.s.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 40.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +6 Data Controller Processing Controllers NL Apr 29, 2025
€2,000 Ziekenhuis Tirrenia S.r.l.: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 12, 15 Health Data Healthcare Personal Data NL Apr 29, 2025
€1,200 Municipality of San Francesco al Campo: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1,200 on the Municipality of San Francesco al Campo. The controller published the personal data of employees on its website, thereby… ITALY ·Garante ·Art. 5 Retention Period Personal Data IP Address Apr 29, 2025
€2,000 Tirrenia Hospital S.r.l.: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 2,000 on Tirrenia Hospital S.r.l. The controller failed to respond to a data access request from a data subject. ITALY ·Garante ·Art. 12, 15 Right of Access Procedures Personal Data Healthcare Apr 29, 2025
€2,000 Versilmagra Immobiliare di Robertelli Davide & C. S.a.s.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2,000 on Versilmagra Immobiliare di Robertelli Davide & C. S.a.s. The controller obtained personal data of potential customers by… ITALY ·Garante ·Art. 5, 6, 7 +7 IP Address Controllers Marketing Apr 29, 2025
€100,000 Energia Verde S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Energia Verde S.p.A. The controller had been active in direct marketing activities. The controller processed data without a… ITALY ·Garante ·Art. 5, 6, 7 +13 IP Address Processing Agreement Controllers Apr 29, 2025
€2,000 Versilmagra Immobiliare, gevestigd bij Robertelli Davide & C. S.a.s.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +7 Data Controller Processing Controllers NL Apr 29, 2025
€100,000 Energia Verde S.p.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 100.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +13 Data Controller Processing Security NL Apr 29, 2025
€1,000 Xiting ROM SRL: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 1,000 on Xiting ROM SRL. The controller failed to respond adequately to a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Apr 28, 2025
€1,000 Xiting ROM SRL: Onvoldoende naleving van de rechten van betrokkenen. Een boete van €1.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Right of Access Personal Data Data Controller NL Apr 28, 2025
€1,000 Sole Trader: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 1,000 on a sole trader. The controller published personal data on a website without a legal basis and despite being subject to a… SLOVENIA ·Art. 5 ·Insufficient legal basis for data processing Controllers Personal Data Processing Agreement Apr 25, 2025
€6,000 SC Travel Planner SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 6.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15, 32 +1 Data Breaches Security Controllers NL Apr 25, 2025
€6,000 SC Travel Planner SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 6,000 on SC Travel Planner SRL. The controller failed to implement sufficient technical and organisational measures, resulting in a data… ROMANIA ·ANSPDCP ·Art. 12, 15, 32 +1 Data Breaches Controllers Processing Agreement Apr 25, 2025
€10,000 Dante International SA: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 10,000 on Dante International SA. The controller failed to respond adequately to a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 17, 19 Controllers Personal Data Supervisory Authorities Apr 24, 2025
€10,000 Dante International SA: Onvoldoende naleving van de rechten van betrokkenen bij de verwerking van persoonsgegevens. Een boete van €10.000 - De Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 17, 19 Personal Data Processing Article 19 GDPR - Notification of Rectification, Erasure or Restriction NL Apr 24, 2025
€1,500 ULPIA TRAJANA ALAMEDA S.L.: Niet-naleving van de algemene principes voor gegevensverwerking. 1.500 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 9 Special Categories of Data Processing Controllers NL Apr 24, 2025
€1,500 ULPIA TRAJANA ALAMEDA S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on ULPIA TRAJANA ALAMEDA S.L. During the booking process, the controller processed data that was unnecessary for the purpose, infringing on the… SPAIN ·aepd ·Art. 5, 9 Controllers IP Address DPIA Apr 24, 2025
€6,000 Immobiliënbureau: Onvoldoende samenwerking met de toezichthoudende instantie. 6.000 euro boete - Belgische Autoriteit voor gegevensbescherming (APD). BELGIUM ·APD ·Art. 5, 6, 17 +1 Personal Data Data Controller Right to be Forgotten NL Apr 24, 2025
€6,000 Real Estate Agency: Insufficient cooperation with supervisory authority The Belgian DPA imposed a fine of EUR 6,000 on a real estate agency. The Belgian DPA had previously issued a remedy to the controller in an earlier case due to the controller… BELGIUM ·APD ·Art. 5, 6, 17 +1 Right to be Forgotten Controllers Data Subject Rights Exercise Modalities and Procedures Apr 24, 2025
€20,000 Company: Non-compliance with general data processing principles The Belgian DPA imposed a fine of EUR 20,000 on a company. The controller is a company engaging in direct marketing activities. During those activies the company failed to comply… BELGIUM ·APD ·Art. 5, 6, 12 +4 Controllers IP Address Direct Marketing Apr 22, 2025
€20,000 Bedrijf: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van 20.000 euro - De Belgische Autoriteit voor gegevensbescherming (APD). BELGIUM ·APD ·Art. 5, 6, 12 +4 Processing Personal Data Marketing NL Apr 22, 2025
€1,200 FUNDACIÓ PRIVADA DE SERVEIS PER ALS USUARIS DEL HABITATGE SOCIAL DE CATALUNYA: Insufficient legal basis for data processing The Spanish DPA imposed a fine on FUNDACIÓ PRIVADA DE SERVEIS PER ALS USUARIS DEL HABITATGE SOCIAL DE CATALUNYA. The controller processed personal data without a sufficient legal… SPAIN ·aepd ·Art. 6 Personal Data Controllers Processing Apr 22, 2025
€7,800 Funeral Home: Insufficient technical and organisational measures to ensure information security The Polish DPA has fined a funeral home EUR 7,800. The funeral home failed to implement sufficient technical and organisational measures to prevent a data breach. The funeral home… POLAND ·UODO ·Art. 5 Data Breaches Security Healthcare Apr 15, 2025
€260,000 CAMERDATA, S.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 260.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6, 14 Processing Personal Data Telecommunications NL Apr 15, 2025