Skip to content
Content type · 39 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–39 of 39 sort newestlargest fineoldest
€120 Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on The DPA received several complaints from data subjects concerning Experian Italia S.p.A (the controller) an Italian credit information system. The controller was processing the… Italy ·Garante ·Art. 5, 12, 15 +1 Supervisory Authorities Privacy by Design Personal Data Sep 16, 2026
HDPA orders TEIRESIAS S.A. to ensure data accuracy under Art. 5(1)(d) GDPR 29 January 2023, the data subject requested TEIRESIAS S.A. (‘the controller’) to delete an entry registered in their database, and to correct the “erroneous financial data”… 4/2026 ·Greece ·Art. 5 Accuracy Personal Data Right to Restriction
€15,300 10266250 The data subject received unsolicited promotional phone calls and a email containing contractual information from Green Partner (the processor), despite the data subject's phone… Italy ·Garante ·Art. 5, 6, 7 +6 Processors Controllers Personal Data Aug 19, 2026
€1M CNIL · SAN-2022-011 The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French… France ·Art. 12, 14, 15 +2 Right to Object Personal Data Right of Access
€2M Garante fines Lusha Systems Inc. over unauthorized B2B contact database Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was a… Italy ·Art. 3, 5, 6 +2 Personal Data IP Address Legitimate Interest Jul 14, 2026
€100,000 ZeniΘ (Thessaloniki-Thessalia Gas Supply Company S.A.): Insufficient fulfilment of data subjects rights The Hellenic Data Protection Authority (HDPA) fined ZeniΘ (Thessaloniki-Thessalia Gas Supply Company S.A.) €100,000 for insufficient fulfillment of data subjects' rights,… Greece ·HDPA ·Art. 5, 12, 15 +1 Processors Supervisory Authorities Controllers Jun 5, 2026
HDPA · 12/2026 The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Greece ·Art. 23 Right of Access Criminal Data Personal Data May 13, 2026
The data subject was a technician employed by the controller The controller used weekly handwritten service sheets as a system for recording working time. These sheets contained the technician’s working hours, journeys, services performed… 97/2026 ·Belgium ·APD/GBA Personal Data Right of Access Controllers May 6, 2026
€400,000 Italian DPA finds Cerved Group failed to disclose creditworthiness scores in Art. 15 The DPA received several complaints from data subjects concerning Cerved Group S.p.A. (the controller) an Italian credit rating agency. The controller was processing the personal… Italy ·Garante ·Art. 5, 12, 15 +3 Supervisory Authorities Personal Data Right of Access Mar 7, 2026
€20,000 Telecommunications company: Insufficient legal basis for data processing The Croatian DPA (azop) has imposed a fine of EUR 20,000 on a telecommunications company. A data subject had filed a complaint with the DPA claiming that the company was still… CROATIA ·AZOP ·Art. 5, 6 Personal Data Processing Telecommunications
€5,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The spanish telecommunications and informations agancy (SETSI) decided Vodafone had to reimburse a customer for costs he was wrongfully charged for. Nevertheless, Vodafone… SPAIN ·AEPD ·Art. 5 Personal Data Processing Telecommunications
€5,000 Vodafone España, S.A.U.: Violation of the general principles for data processing. ⇄ Een boete van 5.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Processing Accountability Telecommunications Dec 30, 2025
€20,000 Telecommunications company: Insufficient legal basis for data processing. ⇄ The Croatian data protection authority (DPA) has imposed a fine of 20,000 euros on a telecommunications company. A data subject had filed a complaint with the DPA, claiming that… CROATIA ·AZOP ·Art. 5, 6 Personal Data Processing Accountability Dec 30, 2025
DSB · 2025-0.950.759 On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Austria ·Art. 5, 6, 16 +2 Privacy by Design & Default Privacy by Design Privacy by Default Nov 24, 2025
€12,000 Company: Insufficient fulfilment of data subjects rights The Lithuanian DPA has imposed a fine of EUR 12,000 on a company providing vehicle history check services. The controller refused a data subject's request to rectify personal data… LITHUANIA ·VDAI ·Art. 5, 15, 16 Personal Data Accuracy Controllers Jan 1, 2024
€10M Axpo Italia Spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10 million on electricity and gas supplier Axpo Italia Spa. The DPA had received numerous complaints from data subjects who complained… ITALY ·Garante ·Art. 5, 24 Controllers Personal Data Processing Sep 28, 2023
€10,000 Azienda Sanitaria dell'Alto Adige - Suedtiroler Sanitaetsbetrieb: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on Azienda Sanitaria dell'Alto Adige - Suedtiroler Sanitaetsbetrieb for failing to adequately comply with its obligation to comply… ITALY ·Garante ·Art. 12 Personal Data Supervisory Authorities Accuracy Sep 14, 2023
54/2024 In 2020, the data subject filed a complaint with the DPA against Google LLC (the controller) for failing to fulfill their right to erasure (Article 17 GDPR) concerning links -… 54/2024 ·Greece ·HDPA Right to be Forgotten Personal Data Right to Object Jun 29, 2023
€8,000 Bank of Cyprus Public Company Ltd.: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 8,000 on Bank of Cyprus Public Company Ltd.. The controller had stored inaccurate data about a data subject in its system. Cyprus DPA ·Art. 5 ·Non-compliance with general data processing principles Controllers Personal Data Processing Jan 1, 2023
€100,000 Lazio Region: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Lazio Region. An individual had filed a complaint with the DPA because she had received an invitation from the regional health… ITALY ·Garante ·Art. 5, 6, 9 +4 Personal Data Supervisory Authorities Healthcare Sep 15, 2022
€10,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Piraeus Bank. The bank had mistakenly sent a document containing data of the data subject to a third party. This error was… GREECE ·HDPA ·Art. 5, 33, 34 Integrity and Confidentiality Principle Data Breaches Personal Data Apr 4, 2022
€124,245 Energy company (name not available at the moment): Insufficient fulfilment of data subjects rights The fined energy company owns petrol stations and sells fuel to customers. The data subject is a customer who filed a consumer complaint relating to inaccurate measuring and… CROATIA ·AZOP ·Art. 15 Personal Data Supervisory Authorities Controllers Mar 8, 2022
EDPS: European Parliament is sole controller for COVID testing website and failed In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Controllers Processors IP Address Jan 5, 2022
€3,000 Société nouvelle de l’annuaire français: Insufficient fulfilment of data subjects rights The French DPA (CNIL) has fined Société nouvelle de l'annuaire français (SNAF) EUR 3,000. SNAF operates the website annuairefrancais.fr, which lists French companies based on data… FRANCE ·CNIL ·Art. 16, 17, 30 +1 Accuracy Personal Data Supervisory Authorities Sep 15, 2021
€2.5M Deliveroo Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined food delivery service Deliveroo Italy s.r.l. EUR 2,500,000 for unlawfully processing the personal data of approximately 8000 drivers. Garante's… Garante ·Art. 5, 13, 22 +5 ·Non-compliance with general data processing principles Privacy by Design & Default DPIA Controllers Jul 22, 2021
€2.6M Foodinho s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Foodinho s.r.l. EUR 2,600,000. Foodinho is an Italian food delivery service. The investigation against Foodinho mainly focused on the drivers… ITALY ·Garante ·Art. 5, 13, 22 +5 Retention Period Privacy by Design & Default DPIA Jun 10, 2021
€1M Equifax Iberica S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 1,000,000 on Equifax Ibérica, SL. A total of 96 complaints were filed with the DPA against the controller because it had included… SPAIN ·AEPD ·Art. 5, 6, 14 Integrity and Confidentiality Principle Retention Period Personal Data Apr 23, 2021
€90,000 Irish Credit Bureau DAC: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 90,000 on Irish Credit Bureau (ICB). The fine follows a data breach reported by the controller to the DPA on August 31, 2018. The… IRELAND ·DPC ·Art. 5, 24, 25 Controllers Security Data Breaches Mar 23, 2021
€5,000 Certime S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Certime S.A.. The data subject had renewed her driver's license with the controller in 2009. After her address had… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Mar 15, 2021
€54,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The data subject had concluded a contract with the controller (Vodafone España, S.A.U.). However, the products provided under this contract were not delivered in the name of the… SPAIN ·AEPD ·Art. 5 Personal Data Controllers Processing Jan 4, 2021
€15,000 Vilnius City Municipality Administration: Non-compliance with general data processing principles During the data synchronization of the Population Information System of the Municipal Administration with the databases of the State Centre for Business Registers, the personal… LITHUANIA ·VDAI ·Art. 5 Integrity and Confidentiality Principle Personal Data Security Oct 21, 2020
€3,000 Telekom Romania: Insufficient technical and organisational measures to ensure information security Inadequate security measures of the company had led to unlawful processing of personal data without verifying their accuracy. For this reason, a fine was imposed on Telekom… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Integrity and Confidentiality Principle Jun 11, 2020
€3,000 Telekom Romania Communications SA: Insufficient technical and organisational measures to ensure information security The company had not taken sufficient technical and organizational measures to ensure the accuracy of personal data transmitted by telephone for the conclusion of contracts. This… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Privacy by Design & Default Apr 23, 2020
€3,850 Television broadcaster: Insufficient fulfilment of information obligations A TV broadcaster had provided information on its website about the processing of personal data, which was however hidden and inaccurate (links to outdated legal provisions). CZECH REPUBLIC ·ÚOOÚ (CZ) ·Art. 12 Personal Data Telecommunications Processing Jan 1, 2020
€2,000 Telekom Romania Mobile Communications SA: Insufficient technical and organisational measures to ensure information security The company has failed to ensure the accuracy of the processing of personal data which resulted in a disclosure of a clients personal data to another client. ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Security Telecommunications Dec 18, 2019
€14,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The sanctions were applied as a result of a complaint alleging that Hora Credit IFN SA transmitted documents containing personal data of another person to a wrong e-mail address.… ROMANIA ·ANSPDCP ·Art. 5, 25, 32 +1 Notification Obligation Security Personal Data Dec 10, 2019
€30,000 Telefónica SA: Non-compliance with general data processing principles Telefónica had charged the complainant various fees in connection with the operation of a telephone line which the complainant had never owned. The reason for this was that the… SPAIN ·AEPD ·Art. 5 Accountability Processing Telecommunications Nov 14, 2019