Skip to content
Content type · 106 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 106 sort newestlargest fineoldest
RON 108,570 ANSPDCP (Romania) - Fine against Homelux SRL HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR. The controller was operating a website on a platform… Art. 32 Data Breaches Security Notification Obligation Aug 11, 2026
RON 523,900 ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026 The investigation was initiated after Orange Romania SA (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR, related to its… Art. 25, 32 Security Data Breaches Notification Obligation Jul 29, 2026
€5,000 AEPD (Spain) - PS/00421/2020 The client of a financial institution lodged a complaint before the Spanish DPA (AEPD) due to the delivery of a mail for commercial purposes, even though he had expressly rejected… Art. 21 Recipient Right to Object Child Consent Jul 24, 2026
Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023 A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022.… TSV/4630/2023 ·Art. 5, 12, 25 Right of Access Personal Data Controllers Jul 22, 2026
AEPD: No fine for surveillance cameras facing public road; no evidence of rights A complaint is filed against the controller for having six surveillance cameras facing public highway and private spaces without authorisation. In addition to the claim, there is… PS-00601-2021 ·Spain ·Art. 5, 12, 15 +3 Video Surveillance Retention Period Monitoring Jul 17, 2026
AEPD (Spain) - E/03783/2020 The Directorate for National Security of the Ministry of Interior issued guidelines for the police forces to monitor news and social networks to spot fake news and misinformation,… E/03783/2020 ·Art. 2 Monitoring Social Media Inspection Access Rights and Cooperation Obligations Jul 15, 2026
Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… 2025010358 ·Iceland ·Island Monitoring Supervisory Authorities Human Resources Jul 1, 2026
€450,000 VDAI (Lithuania) - 3R-1143 Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Art. 5, 24 Security Data Breaches Access Controls Jun 19, 2026
€460,000 Garante: Piaggio violated GDPR by accessing former employees' emails in disciplinary probe Two former employees (the data subjects) of Piaggio (the controller) were dismissed for just cause in March 2023. Following the termination of their employment, they asked the… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 12 +2 Monitoring Storage Limitation Personal Data Jun 18, 2026
€880,000 HDPA fines DEI for unlawful telemarketing calls to opt-out registered subscribers The Greek DPA (HDPA) received twelve complaints filed against DEI, the Greek Public Power Corporation, (the controller) from telephone subscribers (data subjects) regarding the… Greece ·Art. 5, 28, 29 +1 Controllers Personal Data Telecommunications Jun 2, 2026
€55,000 Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful The data controller for the case is a government body called the Agency for Digital Italy (AgID). AgID is tasked with driving the adoption of digital technologies in both… Italy ·Garante per la protezione dei dati personali ·Art. 5, 12, 14 +1 Personal Data Controllers Processing May 28, 2026
HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Art. 23 Personal Data Criminal Data Controllers May 13, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Security Fines Encryption May 8, 2026
€150,000 AEPD (Spain) - EXP202306354 (PS/00312/2024) The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested… Art. 5, 6 Personal Data Integrity and Confidentiality Principle Social Media Feb 11, 2026
€10,000 GENPACT ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Access Controls Security Controllers Feb 4, 2026
€1,500 Italian DPA fines butcher €1,500 for unlawful video surveillance lacking information signs The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of security… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 13 +2 Video Surveillance Controllers Fairness & Transparency Jan 16, 2026
€15M FREE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 15,000,000 on FREE. The controller suffered a data breach due to insufficient technical and organisational measures. This was caused by… FRANCE ·CNIL ·Art. 32, 34 Data Breaches Access Controls Security Jan 8, 2026
€27M FREE MOBILE: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 27 miljoen euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 5, 32 Security Data Breaches Access Controls NL Jan 8, 2026
€27M FREE MOBILE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 27,000,000 on FREE MOBILE. The controller suffered a data breach due to insufficient technical and organisational measures. This was… FRANCE ·CNIL ·Art. 5, 32 Data Breaches Access Controls Security Jan 8, 2026
€15M ONVOLDRAAGLIJK: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. De Franse autoriteit voor gegevensbescherming (CNIL) heeft FREE een boete van 15.000.000 euro opgelegd. Het bedrijf heeft een datalek geleden als gevolg van onvoldoende technische… FRANCE ·CNIL ·Art. 32, 34 Security Data Breaches Notification Obligation NL Jan 8, 2026
€865,000 Aktia Pankki Oyj: Insufficient technical and organisational measures to ensure information security The Finish DPA has imposed a fine of EUR 865,000 on Aktia Pankki Oyj. The controller changed its strong authentication process in such a way that it no longer guaranteed adequate… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Data Breaches Security Access Controls Oct 23, 2025
€865,000 Aktia Pankki Oyj: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 865.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Data Breaches Access Controls NL Oct 23, 2025
€80,000 SENDING TRANSPORTE Y COMUNICACIÓN, S.A.: Onvoldoende overeenkomst met betrekking tot gegevensverwerking. Een boete van 80.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 28 Controllers Data Processor Processors NL Oct 22, 2025
AEPD sanctions 23andMe for security failures in credential-stuffing breach 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In… PS-00140-2025 ·Spain ·Art. 5, 9, 24 +2 Data Breaches Notification Obligation Integrity and Confidentiality Principle Oct 10, 2025
€4,000 CREMA GAMES, S.L.: Insufficient fulfilment of information obligations The Spanish DPA imposed a fine on CREMA GAMES, S.L. The controller failed to fulfill an information request from an online customer. The controller asked the data subject for an… SPAIN ·aepd ·Art. 15 Controllers Personal Data Telecommunications Mar 28, 2025
€4,000 CREMA GAMES, S.L.: Onvoldoende nakoming van de informatieverplichtingen. Een boete van 4.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 15 Data Controller Personal Data Controllers NL Mar 28, 2025
€3.5M Advanced Computer Software Group Ltd: Insufficient technical and organisational measures to ensure information security The UK DPA (ICO) has fined Advanced Computer Software Group Ltd £3.07 million (EUR 3.5 million) for insufficient IT security (infringiment of Art. 32 (1) UK GDPR). The controller… UNITED KINGDOM ·ICO ·Art. 32 Security Access Controls Healthcare Mar 26, 2025
€45M Vodafone GmbH: Non-compliance with general data processing principles The Federal Commissioner for Data Protection and Freedom of Information (BfDI) has imposed a fine of EUR 45,000,000 on Vodafone GmbH. The controller failed to properly supervise a… BfDI Controllers Processors IP Address Jan 1, 2025
€1M LIGA NACIONAL DE FÚTBOL PROFESIONAL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1 million on LIGA NACIONAL DE FÚTBOL PROFESIONAL. The controller had introduced access controls for visitors to football stadiums using… SPAIN ·aepd ·Art. 35 DPIA Privacy Impact Assessment Security Dec 20, 2024
€75,000 Azienda ospedale università di Padova: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 75,000 on Azienda ospedale università di Padova. During its investigation, the DPA found that employees had accessed patient files… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Inspection Access Rights and Cooperation Obligations IP Address May 9, 2024
€5,000 CENTRUL MEDICAL UNIREA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on CENTRUL MEDICAL UNIREA SRL. The controller had suffered a data breach in which personal data of patients and employees were… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Healthcare May 8, 2024
€2,000 Bar: Non-compliance with general data processing principles The Italian DPA has fined the owner of a bar EUR 2,000. The controller had operated video surveillance cameras in one of their premises without the required authorization.… ITALY ·Garante ·Art. 5, 13, 114 Video Surveillance Personal Data IP Address Mar 7, 2024
€5,000 EURO MINI STORAGE ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of 5,000 euros on EURO MINI STORAGE ROMANIA SRL. The controller had suffered a data breach in which customer data was accessed without… ANSPDCP ·Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Privacy by Design & Default Mar 5, 2024
€3,000 VESTA CEU ROMÂNIA SRL.: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 3,000 on VESTA CEU ROMÂNIA SRL. The controller had reported a data breach to the DPA pursuant to Art. 33 GDPR. The controller had… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Access Controls Feb 26, 2024
€800,000 NTT Data Italia S.P.A: Insufficient fulfilment of data breach notification obligations The Italian DPA has imposed a fine of EUR 800,000 on NTT Data Italia S.P.A. The fine is related to the fine imposed on UniCredit (ETid-2227). UniCredit had contracted NTT to carry… ITALY ·Garante ·Art. 28, 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Feb 8, 2024
€20,000 Pharmaceutical wholesaler: €20,000 fine The French DPA has imposed a fine of EUR 20,000 on a pharmaceutical wholesaler due to violations of several regulations, including a lack of data security and insufficient… FRANCE ·CNIL ·Unknown Accountability Processing Agreement Controllers Jan 24, 2024
€40,000 Azienda socio sanitaria territoriale nord Milano, C.F.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 40,000 on Azienda socio sanitaria territoriale nord Milano, C.F.. During its investigation, the DPA found that a patient's spouse had… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare IP Address Processing Agreement Dec 7, 2023
€3,000 A R.L Spartan Gym: Non-compliance with general data processing principles The Italian DPA has fined A R.L Spartan Gym EUR 3,000. The controller had operated video surveillance cameras in one of their premises without the required authorization.… ITALY ·Garante ·Art. 5, 13, 114 Video Surveillance IP Address Personal Data Nov 30, 2023
€20,000 FORO ASTURIAS: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 20,000 on FORO ASTURIAS. An individual had filed a complaint with the DPA due to the fact that personal data stored by the controller had… SPAIN ·aepd ·Art. 5, 32 Personal Data Education IP Address Nov 16, 2023
€110,000 Rompetrol Downstream SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 110,000 on Rompetrol Downstream SRL. The controller had suffered a data breach in which customer data was repeatedly accessed and used… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Right of Access Nov 13, 2023
€3M Trygg-Hansa: Non-compliance with general data processing principles The Swedish DPA has fined Trygg-Hansa EUR 3 million for serious data security breaches. The security breach was discovered when a recipient of an email from Trygg-Hansa realized… SWEDEN ·Art. 5, 32 ·Non-compliance with general data processing principles Security Recipient IP Address Aug 28, 2023
€1,000 Prodav srl: Non-compliance with general data processing principles The Italian DPA has fined Prodav srl EUR 1,000. The controller had operated video surveillance cameras in one of their shops without the required authorization. Furthermore, the… ITALY ·Garante ·Art. 5, 13, 114 Video Surveillance Monitoring Controllers Jul 18, 2023
€5,000 Ristorante Francesco srl: Non-compliance with general data processing principles The Italian DPA has fined Ristorante Francesco srl EUR 5,000. The controller had operated video surveillance cameras in its premises without the required authorization.… ITALY ·Garante ·Art. 5, 13, 114 Video Surveillance IP Address Controllers Jul 6, 2023
€13,400 Sjúkratyringur Íslands: Insufficient technical and organisational measures to ensure information security The Icelandic DPA has imposed a fine of EUR 13,400 on Sjúkratyringur Íslands. During its investigation, the DPA found that the controller had failed to implement adequate… ICELAND ·Art. 5, 25, 32 ·Insufficient technical and organisational measures to ensure information security Security Healthcare Access Controls Jun 28, 2023
€2.3M Debt collection agency: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 2,265,000 on a debt collection agency. The fine is the highest ever imposed by AZOP. AZOP had received an anonymous complaint in… CROATIA ·azop ·Art. 6, 13, 28 +1 Personal Data Security Controllers May 4, 2023
€20,000 Company: Non-compliance with general data processing principles The Lithuanian DPA has fined a company EUR 20,000. The company had suffered a data breach in which personal data of 50,000 data subjects were compromised. During its… LITHUANIA ·VDAI ·Art. 5, 32 Data Breaches Security Storage Limitation Apr 20, 2023
€3,000 Store owner: Non-compliance with general data processing principles The Italian DPA has fined a store owner EUR 3,000. The controller had operated video surveillance cameras in its premises without the required authorization. Furthermore, the DPA… ITALY ·Garante ·Art. 5, 13, 114 Video Surveillance IP Address Personal Data Mar 9, 2023
€50,000 H&M Hennes & Mauritz s.r.l. EUR 50,000: Non-compliance with general data processing principles The Italian DPA has fined H&M Hennes & Mauritz s.r.l. EUR 50,000. H&M had installed numerous video surveillance systems in its Italian stores for the purpose of preventing theft… ITALY ·Garante ·Art. 5, 114 Video Surveillance Monitoring Human Resources Mar 2, 2023
€460,000 Centric Health Ltd.: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 460,000 on Centric Health Ltd.. The controller suffered a ransomware attack in which personal data such as name, date of birth and contact… IRELAND ·Art. 5, 32 ·Non-compliance with general data processing principles Security Healthcare Health Data Jan 23, 2023