Skip to content
Content type · 188 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 188 sort newestlargest fineoldest
€20,000 AEPD fines El Español for disclosing minor's identity in assault video El León de El Español Publicaciones, S.A., the controller, operates the Spanish digital newspaper „El Español“. It published an article concerning an assault and embedded a video… Spain ·Art. 5, 25, 58 Privacy by Default Retention Period Privacy by Design Jul 27, 2026
€2,000 HDPA (Greece) 33/2020 — Employee's access and erasure claims against the American College The data subject was under the employment of the College for a certain period of time, during which two female students of the College filed a complaint against the complainant… Art. 4, 5, 12 +8 Personal Data Right to be Forgotten Right of Access Procedures Jul 24, 2026
€20,000 Italian DPA: Enna Health Authority violated GDPR by publishing judicial data The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 10 +1 Personal Data Fairness & Transparency Right to Restriction Jul 18, 2026
€50,000 Italian Garante sanctions Calabrian agency for location tracking of remote workers The Calabrian Regional Agency for Agricultural Development (the controller) implemented a remote work policy that required employees to use a time-tracking application called… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 13 +3 Monitoring DPIA Privacy Impact Assessment Jul 16, 2026
€2M Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 6 +2 Controllers Processing Personal Data Jul 14, 2026
€140 AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Spain ·Art. 5, 6, 83 Telecommunications Accountability Personal Data Jul 13, 2026
€158,000 Italian DPA finds GDPR applies to US-based Character.AI service Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 12 +7 Controllers Representatives Processing Jul 3, 2026
€1.4M Italian Garante sanctions EstEnergy for automated creditworthiness scoring in energy EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller… Italy ·Garante per la protezione dei dati personali ·Art. 5, 13, 14 +2 Controllers Retention Period Storage Limitation Jul 3, 2026
Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… 2025010358 ·Iceland ·Island Monitoring Supervisory Authorities Integrity and Confidentiality Principle Jul 1, 2026
€450,000 VDAI (Lithuania) - 3R-1143 Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Art. 5, 24 Security Data Breaches Access Controls Jun 19, 2026
€2,760 UODO (Poland) - DKN.5131.34.2023 An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained… Art. 5, 24, 25 +1 Data Breaches Right of Access Security Jun 13, 2026
UODO (Poland) - DKN.5131.12.2022 The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Art. 5, 24, 25 +3 Data Breaches Security DPIA Jun 11, 2026
€55,000 Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful The data controller for the case is a government body called the Agency for Digital Italy (AgID). AgID is tasked with driving the adoption of digital technologies in both… Italy ·Garante per la protezione dei dati personali ·Art. 5, 12, 14 +1 Controllers Personal Data Processing May 28, 2026
€6,000 Italian DPA: vehicle tracking by Liguria Health Agency lawful, information duties met A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller). The data subject was employed by the Ligurian Social and Health Care… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 13 +3 DPIA Privacy by Design Monitoring May 28, 2026
PLN 21,000 UODO (Poland) - DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Art. 24, 25, 28 +1 Security Processors Controllers May 25, 2026
PLN 26,711 UODO (Poland) - DKE.561.4.2026 The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance extending… Art. 5 Monitoring Fairness & Transparency Video Surveillance May 22, 2026
PLN 33,700 UODO (Poland) - DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Art. 5, 24, 25 +3 Controllers Personal Data Supervisory Authorities May 19, 2026
HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Art. 23 Personal Data Processing Controllers May 13, 2026
HUF 15M NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Personal Data Transparency Fairness & Transparency May 12, 2026
HUF 10M NAIH fines online store HUF 10M for missing and inadequate privacy notice The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Personal Data Accountability Controllers Apr 30, 2026
AKI (Estonia) - No. 2.1-1/24/397-890-38 OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to… No. 2.1-1/24/397-890-38 ·Art. 4, 5, 6 +8 Controllers Processors Data Controller Apr 16, 2026
€400,000 CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined Caixabank, S.A. €400,000 for failing to implement sufficient technical and organizational measures to ensure information… Spain ·aepd ·Art. 5, 25 Privacy by Default Security Accountability Apr 15, 2026
€2,415 UODO (Poland) - DKN.5131.7.2022 An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone… Art. 5, 24, 25 +2 Notification Obligation Data Breaches Processors Apr 13, 2026
€150,000 AEPD (Spain) - EXP202306354 (PS/00312/2024) The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested… Art. 5, 6 Personal Data Integrity and Confidentiality Principle Social Media Feb 11, 2026
€15,000 Continental Automotive Products SRL: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Boete van €15.000 - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 32 Security Accountability Controllers NL Jan 19, 2026
DSB Austria: No fine imposed on COVID mask shop for cookie consent failure Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop… 2026-0.043.390 ·Art. 5, 12, 13 Cookies Personal Data IP Address Jan 16, 2026
€27M FREE MOBILE: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 27 miljoen euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 5, 32 Security Data Breaches Access Controls NL Jan 8, 2026
SLOVENAKIË: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Slovaakse Autoriteit voor de Bescherming van Persoonsgegevens. SLOVAKIA ·Slovak Data Protection Office ·Art. 5, 32 Security Processing Personal Data NL Dec 30, 2025
SLOVENAKIË: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Slovaakse Autoriteit voor Gegevensbescherming. SLOVAKIA ·Slovak Data Protection Office ·Art. 5, 32 Security Accountability Privacy by Design & Default NL Dec 30, 2025
€60,000 Incassobureau (GESTIÓN DE COBROS, YO COBRO SL): Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Boete van 60.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Personal Data Processing Insurance NL Dec 30, 2025
€27,000 Vodafone España, S.A.U.: Onvoldoende naleving van de rechten van betrokkenen bij de verwerking van persoonsgegevens. Een boete van 27.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Personal Data Processing Telecommunications NL Dec 30, 2025
€9,600 Restaurant (SANTI 3000, S.L.): Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Boete van €9.600 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 6 Processing Personal Data IP Address NL Dec 30, 2025
€5,000 Vodafone España, S.A.U.: Overtreding van de algemene principes voor gegevensverwerking. Een boete van 5.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Accuracy Processing IP Address NL Dec 30, 2025
€20,000 Telecommunicatiebedrijf: Onvoldoende juridische basis voor gegevensverwerking. De Kroatische gegevensbeschermingsautoriteit (DPA) heeft een telecombedrijf een boete van 20.000 euro opgelegd. Een betrokkene had een klacht ingediend bij de DPA, waarin hij… CROATIA ·azop ·Art. 5, 6 Processing Accuracy Personal Data NL Dec 30, 2025
€60,000 ENDESA (energieleverancier): Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 60.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Professional Secrecy Integrity and Confidentiality Principle Processing NL Dec 30, 2025
€960 POLEN, Autoriteit voor Persoonsgegevens: Onvoldoende samenwerking met de toezichthoudende instantie. Een boete van 960 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 58 Personal Data Data Controller Processing NL Dec 30, 2025
SLOVENAKIË, Dataprotectieautoriteit: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Slovaakse Autoriteit voor de Bescherming van Persoonsgegevens. SLOVAKIA ·Slovak Data Protection Office ·Art. 5, 6 Personal Data Education Processing NL Dec 30, 2025
€2,000 Orde van Algemene Verpleegkundigen, Verloskundigen en Medische Assistenten van Roemenië – Afdeling Neamt: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +1 Video Surveillance Processing Security NL Dec 29, 2025
€1,600 NAROBESA INV, S.L.: Onvoldoende samenwerking met de toezichthoudende instantie. 1.600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 58 Supervisory Authorities Controllers Supervision NL Dec 29, 2025
€6,000 Geturhotels Srl: Overtreding van de algemene principes voor gegevensverwerking. Een boete van 6.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 17 +1 Processing Personal Data Data Controller NL Dec 23, 2025
€32,000 EXCEL HOTELS & RESORTS, S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 32.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Security Controllers Data Controller NL Dec 20, 2025
€300 SPAIN, DPA: Onvoldoende samenwerking met de toezichthoudende instantie. Een boete van 300 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). aepd ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Controllers Supervision NL Dec 20, 2025
€6,000 BLUE TEAM FLIGHT SCHOOL, S.L.: Onvoldoende samenwerking met de toezichthoudende instantie. Een boete van 6.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 58 Education Supervisory Authorities Controllers NL Dec 20, 2025
€600 4USPORT INSTALACIONES DEPORTIVAS, S.L.: Onvoldoende samenwerking met de toezichthoudende instantie. 600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 58 Supervisory Authorities Controllers Data Controller NL Dec 20, 2025
€2,000 Istituto Comprensivo Centro in Casalecchio di Reno: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Data Controller Personal Data Controllers NL Dec 4, 2025
€3,600 RISING SUN CAR RENTAL S.L.: Niet-naleving van de algemene principes voor gegevensverwerking. De Spaanse autoriteit voor gegevensbescherming (DPA) heeft RISING SUN CAR RENTAL S.L. een boete van 3.600 euro opgelegd. De verantwoordelijke partij gebruikte videobewaking om de… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Processing Controllers NL Dec 1, 2025
€3,600 DELAFRUIT, S.L.: Niet-naleving van de algemene principes voor gegevensverwerking. Boete van €3.600 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Video Surveillance Controllers Processing NL Dec 1, 2025
€40,000 Infobel: Onvoldoende juridische basis voor gegevensverwerking. Een boete van 40.000 euro - De Belgische Autoriteit voor gegevensbescherming (APD). BELGIUM ·APD ·Art. 5, 6, 24 Data Controller Processing Controllers NL Nov 27, 2025
DSB Austria: Online shop violated GDPR by ignoring request to stop gender-specific On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Art. 5, 6, 16 +2 Privacy by Design Privacy by Default Privacy by Design & Default Nov 24, 2025
€5,000 ACTIVOS INTELIGENTES, S.L.: Overtreding van de algemene principes voor gegevensverwerking. Boete van €5.000 - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Processing IP Address Accountability NL Nov 23, 2025