Skip to content
Content type · 30 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–30 of 30 sort newestlargest fineoldest
HRK 940,000 AZOP (Croatia) - Decision 08-03-2022 (energy company) The controller is a company that manages gas stations. The data subject tried to refuel at one of the controller's gas stations and was dissatisfied with the measurement of the… Art. 15 Video Surveillance Right of Access Personal Data Aug 3, 2026
€450,000 VDAI (Lithuania) - 3R-1143 Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Art. 5, 24 Security Data Breaches Access Controls Jun 19, 2026
EDPB - Binding Decision 1/2026 On 10 August 2021, a data subject represented by noyb lodged a complaint with the Austrian DPA against Vlaamse Radio- en Televisieomroeporganisatie (VRT), the controller. The… Binding Decision 1/2026 ·European Union ·Art. 4, 57, 60 +3 Cookies Supervisory Authorities Supervision May 28, 2026
PLN 33,700 UODO (Poland) - DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Art. 5, 24, 25 +3 Personal Data Controllers Security May 19, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Encryption Integrity and Confidentiality Principle Security May 8, 2026
€16,600 Reykjanesbær municipality: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 16,600 on the municipality of Reykjanesbær. The municipality had used the Google Education system without sufficiently complying with… ICELAND ·Art. 5, 24, 28 ·Non-compliance with general data processing principles Processors Public Authority Education Dec 6, 2023
€13,300 City of Reykjavik: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 13,300 on the city of Reykjavik. The city had used the Google Education system in schools without sufficiently complying with data… ICELAND ·Art. 5, 24, 28 ·Non-compliance with general data processing principles Processors Processing Agreement Education Dec 6, 2023
€20,000 City of Kópavogur: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 20,000 on the city of Kópavogur. The city had used the Google Education system without sufficiently complying with data protection… ICELAND ·Art. 5, 24, 28 ·Non-compliance with general data processing principles Processing Agreement Processors Education Dec 6, 2023
€16,600 Garðabær municipality: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 16,600 on the municipality of Garðabær. The municipality had used the Google Education system without sufficiently complying with data… ICELAND ·Art. 5, 24, 28 ·Non-compliance with general data processing principles Education Processing Agreement Processors Dec 6, 2023
€18,600 City of Hafnarfjörður: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 18,600 on the city of Hafnarfjörður. The city had used the Google Education system without sufficiently complying with data protection… ICELAND ·Art. 5, 24, 28 ·Non-compliance with general data processing principles Processors Processing Agreement Education Dec 6, 2023
Belgian DPA settles with Mediafin: De Tijd cookie banner must add equal "refuse all" On 19 July 2023, a data subject, represented by noyb (European Centre for Digital Rights), filed a complaint against Mediafin, a Belgian media group, with the Belgian DPA. The… 159/2023 ·Belgium ·APD/GBA Cookies Direct Marketing Consent Nov 24, 2023
€9,600 PIONIER (law firm): Insufficient legal basis for data processing The Polish DPA has imposed a fine of EUR 9,600 on the law firm PIONIER. The law firm mainly represents victims of traffic accidents in proceedings against insurance companies and… POLAND ·UODO ·Art. 5, 6, 9 Social Media Insurance Health Data Nov 30, 2022
€15 HDPA (Greece) - 50/2022 A former teacher (the data subject) at a private primary school (the controller) submitted a complaint to the Greek DPA regarding a video surveillance system in the classrooms,… Art. 5, 6, 12 +2 Video Surveillance Legitimate Interest Personal Data Sep 9, 2022
€170,000 Mercadona S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 170,000 on the supermarket chain Mercadona S.A.. An individual had filed a complaint with the DPA. The individual had suffered an… SPAIN ·aepd ·Art. 6, 12, 15 Video Surveillance Monitoring Personal Data May 13, 2022
€36,000 City of Reykjavík: Insufficient legal basis for data processing The Icelandic DPA has imposed a fine of EUR 36,000 on the City of Reykjavík. The city had used the digital education system 'Seesaw' at several schools. The student system… ICELAND ·Art. 5, 6, 32 ·Insufficient legal basis for data processing Education IP Address Processing Agreement May 3, 2022
€70,000 Ospedale San Raffaele s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 70,000 on the healthcare facility Ospedale San Raffaele s.r.l.. The hospital had reported two data breaches to the DPA under Art. 33… ITALY ·Garante ·Art. 5, 9 Data Breaches Integrity and Confidentiality Principle Healthcare Apr 28, 2022
€124,245 Energy company (name not available at the moment): Insufficient fulfilment of data subjects rights The fined energy company owns petrol stations and sells fuel to customers. The data subject is a customer who filed a consumer complaint relating to inaccurate measuring and… CROATIA ·azop ·Art. 15 Video Surveillance Personal Data Accuracy Mar 8, 2022
€1.9M BREBAU GmbH: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine of EUR 1.9 million on the housing association BREBAU GmbH. BREBAU GmbH had processed upwards of 9,500 datasets about potential tenants without… GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Fairness & Transparency Controllers Personal Data Mar 3, 2022
€608,000 Psykoterapiakeskus Vastaamo: Non-compliance with general data processing principles The Finnish DPA has fined Vastaamo psychotherapy center EUR 608,000. In September 2020, the psychotherapy center reported an attack on its patient database to the DPA. An… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 33, 34 Integrity and Confidentiality Principle Healthcare Liability Dec 7, 2021
€496,000 Ferde AS: Non-compliance with general data processing principles The Norwegian DPA has fined Ferde AS, a Norwegian toll company, EUR 496,000. Through a report on the state-owned broadcasting company NRK, the Norwegian DPA became aware that… NORWAY ·Datatilsynet ·Art. 5, 28, 32 +1 Processors Processing Agreement Controllers Sep 27, 2021
€13,450 IDdesign A / S: Non-compliance with general data processing principles Original summary: On June 3, 2019, the Danish DPA (Datatilsynet) reported IDdesign to the police and demanded payment of a fine in the amount of EUR 200,850 for the processing of… DENMARK ·Datatilsynet ·Art. 5 Fines Administrative Fines on Union Institutions, Bodies, Offices and Agencies Storage Limitation Feb 12, 2021
€3,000 Patio Ancestral S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) imposed a fine of EUR 5,000 on Patio Ancestral S.L.. The complainant worked for a construction company and had carried out some renovation work for the… SPAIN ·aepd ·Art. 6 Controllers Personal Data Processing Agreement Feb 8, 2021
Medical clinic: Insufficient legal basis for data processing The DPA from Berlin has imposed a fine on a medical clinic. The clinic had installed 21 cameras in its premises for the purpose of protection against crime and property damage.… GERMANY ·Art. 5, 6 ·Insufficient legal basis for data processing Video Surveillance Healthcare Monitoring Jan 1, 2021
€30,000 Provincial Health Authority of Cosenza: Insufficient legal basis for data processing Publication of personal data (including first and last name, address, tax ID) on the website of the authority about persons who have claims for damages against the authority,… ITALY ·Garante ·Art. 9 Personal Data Education Healthcare Nov 17, 2020
€2,560 T.K. EOOD: Insufficient technical and organisational measures to ensure information security The fine of ca. EUR 2,557 was imposed on T.K. EOOD for unlawful processing of personal data of data subject I.S. by failure to adopt technical and organizational measures to… BULGARIA ·KZLD ·Art. 25, 32 Integrity and Confidentiality Principle Security Liability Feb 20, 2020
€5,110 Utility Company: Insufficient legal basis for data processing The fine of EUR ca. 5,113 was imposed on a Bulgarian utility company for unlawful processing of the personal data of the data subject V.V. The personal data of V.V. was unlawfully… BULGARIA ·KZLD ·Art. 6 Integrity and Confidentiality Principle Personal Data Processing Jan 6, 2020
€320,000 Doorstep Dispensaree Ltd. (Pharmacy): Insufficient technical and organisational measures to ensure information security The company had stored some 500,000 documents containing names, addresses, dates of birth, NHS numbers and medical information and prescriptions in unsealed containers at the back… UNITED KINGDOM ·ICO ·Art. 32 Healthcare Healthcare Liability Dec 17, 2019
€12,950 Sports association: Insufficient legal basis for data processing One sports association published personal data referring to judges who were granted judicial licenses online. However, not only their names were provided, but also their exact… POLAND ·UODO ·Art. 6 Personal Data Liability Controllers Apr 25, 2019
€582 CZECH REPUBLIC DPA: Insufficient technical and organisational measures to ensure information security Data was not processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental… UOOU ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Security Professional Secrecy Feb 28, 2019
€1,165 Credit brokerage: Insufficient technical and organisational measures to ensure information security Data was not processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental… CZECH REPUBLIC ·UOOU ·Art. 32 Integrity and Confidentiality Principle Security Insurance Feb 4, 2019