Skip to content
Content type · 35 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–35 of 35 sort newestlargest fineoldest
€1M CNIL fines energy supplier for mishandling data subject access and objection requests The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French… France ·Art. 12, 14, 15 +2 Right of Access Personal Data Accuracy Jul 17, 2026
€2M Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 6 +2 Processing Controllers Personal Data Jul 14, 2026
€880,000 HDPA fines DEI for unlawful telemarketing calls to opt-out registered subscribers The Greek DPA (HDPA) received twelve complaints filed against DEI, the Greek Public Power Corporation, (the controller) from telephone subscribers (data subjects) regarding the… Greece ·Art. 5, 28, 29 +1 Personal Data Controllers Telecommunications Jun 2, 2026
HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Art. 23 Personal Data Controllers Processing May 13, 2026
APD/GBA: Controller failed to provide copies of service sheets for GDPR access request The data subject was a technician employed by the controller. The controller used weekly handwritten service sheets as a system for recording working time. These sheets contained… 97/2026 ·Belgium ·Art. 12, 15 Right of Access Procedures Accuracy Right of Access May 6, 2026
€20,000 Telecommunications company: Insufficient legal basis for data processing The Croatian DPA (azop) has imposed a fine of EUR 20,000 on a telecommunications company. A data subject had filed a complaint with the DPA claiming that the company was still… CROATIA ·azop ·Art. 5, 6 Accuracy Personal Data Telecommunications Dec 30, 2025
€5,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The spanish telecommunications and informations agancy (SETSI) decided Vodafone had to reimburse a customer for costs he was wrongfully charged for. Nevertheless, Vodafone… SPAIN ·aepd ·Art. 5 Accuracy Telecommunications Personal Data Dec 30, 2025
€5,000 Vodafone España, S.A.U.: Overtreding van de algemene principes voor gegevensverwerking. Een boete van 5.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Accuracy Processing Telecommunications NL Dec 30, 2025
€20,000 Telecommunicatiebedrijf: Onvoldoende juridische basis voor gegevensverwerking. De Kroatische gegevensbeschermingsautoriteit (DPA) heeft een telecombedrijf een boete van 20.000 euro opgelegd. Een betrokkene had een klacht ingediend bij de DPA, waarin hij… CROATIA ·azop ·Art. 5, 6 Processing Accuracy Personal Data NL Dec 30, 2025
DSB Austria: Online shop violated GDPR by ignoring request to stop gender-specific On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Art. 5, 6, 16 +2 Privacy by Design Privacy by Default Privacy by Design & Default Nov 24, 2025
€12,000 Company: Insufficient fulfilment of data subjects rights The Lithuanian DPA has imposed a fine of EUR 12,000 on a company providing vehicle history check services. The controller refused a data subject's request to rectify personal data… LITHUANIA ·VDAI ·Art. 5, 15, 16 Accuracy Personal Data Controllers Jan 1, 2024
€10M Axpo Italia Spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10 million on electricity and gas supplier Axpo Italia Spa. The DPA had received numerous complaints from data subjects who complained… ITALY ·Garante ·Art. 5, 24 IP Address Controllers Accuracy Sep 28, 2023
€10,000 Azienda Sanitaria dell'Alto Adige - Suedtiroler Sanitaetsbetrieb: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 10,000 on Azienda Sanitaria dell'Alto Adige - Suedtiroler Sanitaetsbetrieb for failing to adequately comply with its obligation to comply… ITALY ·Garante ·Art. 12 Personal Data Accuracy Employees Sep 14, 2023
Greek DPA: Google breached Art. 17 GDPR erasure right over outdated criminal case links In 2020, the data subject filed a complaint with the DPA against Google LLC (the controller) for failing to fulfill their right to erasure (Article 17 GDPR) concerning links -… 54/2024 ·Greece ·HDPA Right to be Forgotten Personal Data Accuracy Jun 29, 2023
€8,000 Bank of Cyprus Public Company Ltd.: Non-compliance with general data processing principles The Cypriot DPA has imposed a fine of EUR 8,000 on Bank of Cyprus Public Company Ltd.. The controller had stored inaccurate data about a data subject in its system. Art. 5 ·Non-compliance with general data processing principles Accuracy Controllers Personal Data Jan 1, 2023
€100,000 Lazio Region: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Lazio Region. An individual had filed a complaint with the DPA because she had received an invitation from the regional health… ITALY ·Garante ·Art. 5, 6, 9 +4 Accuracy Personal Data IP Address Sep 15, 2022
€10,000 Piraeus Bank: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 10,000 on Piraeus Bank. The bank had mistakenly sent a document containing data of the data subject to a third party. This error was… GREECE ·HDPA ·Art. 5, 33, 34 Data Breaches Integrity and Confidentiality Principle Accuracy Apr 4, 2022
€124,245 Energy company (name not available at the moment): Insufficient fulfilment of data subjects rights The fined energy company owns petrol stations and sells fuel to customers. The data subject is a customer who filed a consumer complaint relating to inaccurate measuring and… CROATIA ·azop ·Art. 15 Video Surveillance Personal Data Accuracy Mar 8, 2022
EDPS - 2020-1013 In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Controllers Processing Legitimate Interest Jan 5, 2022
€3,000 Société nouvelle de l’annuaire français: Insufficient fulfilment of data subjects rights The French DPA (CNIL) has fined Société nouvelle de l'annuaire français (SNAF) EUR 3,000. SNAF operates the website annuairefrancais.fr, which lists French companies based on data… FRANCE ·CNIL ·Art. 16, 17, 30 +1 Accuracy Personal Data Processing Agreement Sep 15, 2021
€2.5M Deliveroo Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined food delivery service Deliveroo Italy s.r.l. EUR 2,500,000 for unlawfully processing the personal data of approximately 8000 drivers. Garante's… Garante ·Art. 5, 13, 22 +5 ·Non-compliance with general data processing principles DPIA Privacy Impact Assessment Fairness & Transparency Jul 22, 2021
€2.6M Foodinho s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has fined Foodinho s.r.l. EUR 2,600,000. Foodinho is an Italian food delivery service. The investigation against Foodinho mainly focused on the drivers… ITALY ·Garante ·Art. 5, 13, 22 +5 DPIA Privacy Impact Assessment IP Address Jun 10, 2021
€1M Equifax Iberica S.L.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 1,000,000 on Equifax Ibérica, SL. A total of 96 complaints were filed with the DPA against the controller because it had included… SPAIN ·aepd ·Art. 5, 6, 14 Fairness & Transparency Integrity and Confidentiality Principle Personal Data Apr 23, 2021
€90,000 Irish Credit Bureau DAC: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 90,000 on Irish Credit Bureau (ICB). The fine follows a data breach reported by the controller to the DPA on August 31, 2018. The… IRELAND ·Art. 5, 24, 25 ·Insufficient technical and organisational measures to ensure information security Data Breaches Accuracy Security Mar 23, 2021
€5,000 Certime S.A.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 5,000 on Certime S.A.. The data subject had renewed her driver's license with the controller in 2009. After her address had… SPAIN ·aepd ·Art. 5 Personal Data Accuracy Controllers Mar 15, 2021
€54,000 Vodafone España, S.A.U.: Non-compliance with general data processing principles The data subject had concluded a contract with the controller (Vodafone España, S.A.U.). However, the products provided under this contract were not delivered in the name of the… SPAIN ·aepd ·Art. 5 Accuracy Telecommunications Personal Data Jan 4, 2021
€15,000 Vilnius City Municipality Administration: Non-compliance with general data processing principles During the data synchronization of the Population Information System of the Municipal Administration with the databases of the State Centre for Business Registers, the personal… LITHUANIA ·VDAI ·Art. 5 Integrity and Confidentiality Principle Personal Data Accuracy Oct 21, 2020
€3,000 Telekom Romania: Insufficient technical and organisational measures to ensure information security Inadequate security measures of the company had led to unlawful processing of personal data without verifying their accuracy. For this reason, a fine was imposed on Telekom… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Security Telecommunications Jun 11, 2020
€3,000 Telekom Romania Communications SA: Insufficient technical and organisational measures to ensure information security The company had not taken sufficient technical and organizational measures to ensure the accuracy of personal data transmitted by telephone for the conclusion of contracts. This… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Accuracy Security Telecommunications Apr 23, 2020
€3,850 Television broadcaster: Insufficient fulfilment of information obligations A TV broadcaster had provided information on its website about the processing of personal data, which was however hidden and inaccurate (links to outdated legal provisions). CZECH REPUBLIC ·UOOU ·Art. 12 Personal Data Accuracy Telecommunications Jan 1, 2020
€2,000 Telekom Romania Mobile Communications SA: Insufficient technical and organisational measures to ensure information security The company has failed to ensure the accuracy of the processing of personal data which resulted in a disclosure of a clients personal data to another client. ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Telecommunications Security Dec 18, 2019
€14,000 Hora Credit IFN SA: Insufficient technical and organisational measures to ensure information security The sanctions were applied as a result of a complaint alleging that Hora Credit IFN SA transmitted documents containing personal data of another person to a wrong e-mail address.… ROMANIA ·ANSPDCP ·Art. 5, 25, 32 +1 Notification Obligation Fines Security Dec 10, 2019
€30,000 Telefónica SA: Non-compliance with general data processing principles Telefónica had charged the complainant various fees in connection with the operation of a telephone line which the complainant had never owned. The reason for this was that the… SPAIN ·aepd ·Art. 5 Accuracy IP Address Accountability Nov 14, 2019