Content type · 39 documents in this view · 3,811 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3587 Processing 2635 Personal Data 2394 Controllers 2017 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
€120 Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on The DPA received several complaints from data subjects concerning Experian Italia S.p.A (the controller) an Italian credit information system. The controller was processing the… Italy · ·Art. 5, 12, 15 +1 Sep 16, 2026
HDPA orders TEIRESIAS S.A. to ensure data accuracy under Art. 5(1)(d) GDPR 29 January 2023, the data subject requested TEIRESIAS S.A. (‘the controller’) to delete an entry registered in their database, and to correct the “erroneous financial data”… 4/2026 ·Greece ·Art. 5
€15,300 10266250 The data subject received unsolicited promotional phone calls and a email containing contractual information from Green Partner (the processor), despite the data subject's phone… Italy · ·Art. 5, 6, 7 +6 Aug 19, 2026
€1M CNIL · SAN-2022-011 The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French… France ·Art. 12, 14, 15 +2
€2M Garante fines Lusha Systems Inc. over unauthorized B2B contact database Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was a… Italy ·Art. 3, 5, 6 +2 Jul 14, 2026
€100,000 ZeniΘ (Thessaloniki-Thessalia Gas Supply Company S.A.): Insufficient fulfilment of data subjects rights The Hellenic Data Protection Authority (HDPA) fined ZeniΘ (Thessaloniki-Thessalia Gas Supply Company S.A.) €100,000 for insufficient fulfillment of data subjects' rights,… Greece · ·Art. 5, 12, 15 +1 Jun 5, 2026
HDPA · 12/2026 The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Greece ·Art. 23 May 13, 2026
The data subject was a technician employed by the controller The controller used weekly handwritten service sheets as a system for recording working time. These sheets contained the technician’s working hours, journeys, services performed… 97/2026 ·Belgium · May 6, 2026
€400,000 Italian DPA finds Cerved Group failed to disclose creditworthiness scores in Art. 15 The DPA received several complaints from data subjects concerning Cerved Group S.p.A. (the controller) an Italian credit rating agency. The controller was processing the personal… Italy · ·Art. 5, 12, 15 +3 Mar 7, 2026
€20,000 Telecommunications company: Insufficient legal basis for data processing The Croatian DPA (azop) has imposed a fine of EUR 20,000 on a telecommunications company. A data subject had filed a complaint with the DPA claiming that the company was still… CROATIA · ·Art. 5, 6
€5,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The spanish telecommunications and informations agancy (SETSI) decided Vodafone had to reimburse a customer for costs he was wrongfully charged for. Nevertheless, Vodafone… SPAIN · ·Art. 5
€5,000 Vodafone España, S.A.U.: Violation of the general principles for data processing. ⇄ Een boete van 5.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN · ·Art. 5 Dec 30, 2025
€20,000 Telecommunications company: Insufficient legal basis for data processing. ⇄ The Croatian data protection authority (DPA) has imposed a fine of 20,000 euros on a telecommunications company. A data subject had filed a complaint with the DPA, claiming that… CROATIA · ·Art. 5, 6 Dec 30, 2025
DSB · 2025-0.950.759 On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Austria ·Art. 5, 6, 16 +2 Nov 24, 2025
€1,200 FOUNDATION FOR SERVICES TO USERS OF SOCIAL HOUSING IN CATALONIA: Insufficient legal basis for the processing of personal data. ⇄ 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN · ·Art. 6 Apr 22, 2025
€892,783 E.ON Energia spa: Insufficient legal basis for data processing ITALY · ·Art. 5, 6, 7 +5 Nov 27, 2024
€12,000 Company: Insufficient fulfilment of data subjects rights The Lithuanian DPA has imposed a fine of EUR 12,000 on a company providing vehicle history check services. The controller refused a data subject's request to rectify personal data… LITHUANIA · ·Art. 5, 15, 16 Jan 1, 2024
€10M Axpo Italia Spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10 million on electricity and gas supplier Axpo Italia Spa. The DPA had received numerous complaints from data subjects who complained… ITALY · ·Art. 5, 24 Sep 28, 2023
€10,000 Azienda Sanitaria dell'Alto Adige - Suedtiroler Sanitaetsbetrieb: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on Azienda Sanitaria dell'Alto Adige - Suedtiroler Sanitaetsbetrieb for failing to adequately comply with its obligation to comply… ITALY · ·Art. 12 Sep 14, 2023
54/2024 In 2020, the data subject filed a complaint with the DPA against Google LLC (the controller) for failing to fulfill their right to erasure (Article 17 GDPR) concerning links -… 54/2024 ·Greece · Jun 29, 2023
€8,000 Bank of Cyprus Public Company Ltd.: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 8,000 on Bank of Cyprus Public Company Ltd.. The controller had stored inaccurate data about a data subject in its system. ·Art. 5 ·Non-compliance with general data processing principles Jan 1, 2023
€100,000 Lazio Region: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Lazio Region. An individual had filed a complaint with the DPA because she had received an invitation from the regional health… ITALY · ·Art. 5, 6, 9 +4 Sep 15, 2022
€10,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Piraeus Bank. The bank had mistakenly sent a document containing data of the data subject to a third party. This error was… GREECE · ·Art. 5, 33, 34 Apr 4, 2022
€124,245 Energy company (name not available at the moment): Insufficient fulfilment of data subjects rights The fined energy company owns petrol stations and sells fuel to customers. The data subject is a customer who filed a consumer complaint relating to inaccurate measuring and… CROATIA · ·Art. 15 Mar 8, 2022
EDPS: European Parliament is sole controller for COVID testing website and failed In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Jan 5, 2022
€3,000 Société nouvelle de l’annuaire français: Insufficient fulfilment of data subjects rights The French DPA (CNIL) has fined Société nouvelle de l'annuaire français (SNAF) EUR 3,000. SNAF operates the website annuairefrancais.fr, which lists French companies based on data… FRANCE · ·Art. 16, 17, 30 +1 Sep 15, 2021
€2.5M Deliveroo Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined food delivery service Deliveroo Italy s.r.l. EUR 2,500,000 for unlawfully processing the personal data of approximately 8000 drivers. Garante's… ·Art. 5, 13, 22 +5 ·Non-compliance with general data processing principles Jul 22, 2021
€2.6M Foodinho s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Foodinho s.r.l. EUR 2,600,000. Foodinho is an Italian food delivery service. The investigation against Foodinho mainly focused on the drivers… ITALY · ·Art. 5, 13, 22 +5 Jun 10, 2021
€1M Equifax Iberica S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 1,000,000 on Equifax Ibérica, SL. A total of 96 complaints were filed with the DPA against the controller because it had included… SPAIN · ·Art. 5, 6, 14 Apr 23, 2021
€90,000 Irish Credit Bureau DAC: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 90,000 on Irish Credit Bureau (ICB). The fine follows a data breach reported by the controller to the DPA on August 31, 2018. The… IRELAND · ·Art. 5, 24, 25 Mar 23, 2021
€5,000 Certime S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Certime S.A.. The data subject had renewed her driver's license with the controller in 2009. After her address had… SPAIN · ·Art. 5 Mar 15, 2021
€54,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The data subject had concluded a contract with the controller (Vodafone España, S.A.U.). However, the products provided under this contract were not delivered in the name of the… SPAIN · ·Art. 5 Jan 4, 2021
€15,000 Vilnius City Municipality Administration: Non-compliance with general data processing principles During the data synchronization of the Population Information System of the Municipal Administration with the databases of the State Centre for Business Registers, the personal… LITHUANIA · ·Art. 5 Oct 21, 2020
€3,000 Telekom Romania: Insufficient technical and organisational measures to ensure information security Inadequate security measures of the company had led to unlawful processing of personal data without verifying their accuracy. For this reason, a fine was imposed on Telekom… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Jun 11, 2020
€3,000 Telekom Romania Communications SA: Insufficient technical and organisational measures to ensure information security The company had not taken sufficient technical and organizational measures to ensure the accuracy of personal data transmitted by telephone for the conclusion of contracts. This… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Apr 23, 2020
€3,850 Television broadcaster: Insufficient fulfilment of information obligations A TV broadcaster had provided information on its website about the processing of personal data, which was however hidden and inaccurate (links to outdated legal provisions). CZECH REPUBLIC · ·Art. 12 Jan 1, 2020
€2,000 Telekom Romania Mobile Communications SA: Insufficient technical and organisational measures to ensure information security The company has failed to ensure the accuracy of the processing of personal data which resulted in a disclosure of a clients personal data to another client. ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Dec 18, 2019
€14,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The sanctions were applied as a result of a complaint alleging that Hora Credit IFN SA transmitted documents containing personal data of another person to a wrong e-mail address.… ROMANIA · ·Art. 5, 25, 32 +1 Dec 10, 2019
€30,000 Telefónica SA: Non-compliance with general data processing principles Telefónica had charged the complainant various fees in connection with the operation of a telephone line which the complainant had never owned. The reason for this was that the… SPAIN · ·Art. 5 Nov 14, 2019