Skip to content
Content type · 950 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 950 sort newestlargest fineoldest
RON 108,570 ANSPDCP (Romania) - Fine against Homelux SRL HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR. The controller was operating a website on a platform… Art. 32 Data Breaches Notification Obligation Security Aug 11, 2026
RON 523,900 ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026 The investigation was initiated after Orange Romania SA (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR, related to its… Art. 25, 32 Security Data Breaches Notification Obligation Jul 29, 2026
€20,000 AEPD fines El Español for disclosing minor's identity in assault video El León de El Español Publicaciones, S.A., the controller, operates the Spanish digital newspaper „El Español“. It published an article concerning an assault and embedded a video… Spain ·Art. 5, 25, 58 Privacy by Default Privacy by Design Retention Period Jul 27, 2026
Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023 A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022.… TSV/4630/2023 ·Art. 5, 12, 25 Personal Data Controllers Right of Access Jul 22, 2026
HUF 2M NAIH fines online store HUF 2M for unclear and incomplete privacy notice The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The… Hungary ·Art. 12, 13 Legitimate Interest Processing Lawful Basis Jul 22, 2026
€20,000 Italian DPA: Enna Health Authority violated GDPR by publishing judicial data The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 10 +1 Personal Data Fairness & Transparency Criminal Data Jul 18, 2026
APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing… PS-0036/2026 ·Spain ·Catalonia Anonymization Professional Secrecy Personal Data Jul 17, 2026
AEPD investigates University of Navarra over student COVID-19 vaccination status requests A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3 Consent Healthcare Health Data Jul 16, 2026
€200,000 AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack… Spain ·Art. 5, 35, 58 DPIA Privacy Impact Assessment Security Jul 16, 2026
€140 AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Spain ·Art. 5, 6, 83 Telecommunications Personal Data Accountability Jul 13, 2026
€1,198 Slovenian DPA fines controller €1,198 for Art. 32 GDPR breach via pirated software A company (the controller) operates an online store. An employee of the controller used a pirated and unlicensed software when creating the website. This software contained… Slovenia ·IP ·Art. 32 Integrity and Confidentiality Principle Data Breaches Security Jul 8, 2026
IMY reprimands Swedish Police for inadequate GDPR Article 13 info at Arlanda border The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of… IMY-2024-2904 ·Sweden ·Art. 13 Personal Data Controllers Information Provision Modalities and Communication Methods Jul 3, 2026
RON 26,172 ANSPDCP fines Banca Transilvania RON 26,172 for inadequate security over unauthorized The Romanian DPA (ANSPDCP) launched an investigation into a bank, Banca Transilvania S.A. (the controller), following a data subject’s complaint. The data subject claimed that… Romania ·Art. 32 Integrity and Confidentiality Principle Data Breaches Security Jul 3, 2026
€158,000 Italian DPA finds GDPR applies to US-based Character.AI service Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 12 +7 Controllers Representatives Corrective Actions and Duty of Information Framework Jul 3, 2026
Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… 2025010358 ·Iceland ·Island Monitoring Cloud Computing Supervisory Authorities Jul 1, 2026
€450,000 VDAI (Lithuania) - 3R-1143 Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Art. 5, 24 Security Data Breaches Access Controls Jun 19, 2026
€2,000 SSG SELECT SOLUTIONS S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined SSG Select Solutions S.R.L. €2,000 for failing to implement adequate technical and… Romania ·ANSPDCP ·Art. 29, 32 Security Supervisory Authorities Personal Data Jun 15, 2026
€2,760 UODO (Poland) - DKN.5131.34.2023 An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained… Art. 5, 24, 25 +1 Data Breaches Notification Obligation Security Jun 13, 2026
€5,000 Națională Poșta Română: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Națională Poșta Română €5,000 on 2026-06-12 for: Insufficient technical and organisational… Romania ·ANSPDCP ·Art. 32 Security Personal Data Supervisory Authorities Jun 12, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland ·Art. 5, 28, 30 +2 ·Insufficient technical and organisational measures to ensure information security Notification Obligation Data Breaches Healthcare Jun 11, 2026
UODO (Poland) - DKN.5131.12.2022 The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Art. 5, 24, 25 +3 Security DPIA Data Breaches Jun 11, 2026
€23,540 Minister of Justice: Insufficient technical and organisational measures to ensure information security Polish National Personal Data Protection Office (UODO) fined Minister of Justice €23,540 on 2026-06-02 for: Insufficient technical and organisational measures to ensure… Poland ·UODO ·Art. 32 Security Public Authority Personal Data Jun 2, 2026
€880,000 HDPA fines DEI for unlawful telemarketing calls to opt-out registered subscribers The Greek DPA (HDPA) received twelve complaints filed against DEI, the Greek Public Power Corporation, (the controller) from telephone subscribers (data subjects) regarding the… Greece ·Art. 5, 28, 29 +1 Controllers Personal Data Telecommunications Jun 2, 2026
€12,000 Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Unicredit Bank SA €12,000 on 2026-05-29 for: Insufficient technical and organisational… Romania ·ANSPDCP ·Art. 32, 33 Security Supervisory Authorities Personal Data May 29, 2026
€700 Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy ·Garante per la protezione dei dati personali ·Art. 5, 9 Personal Data Healthcare Health Data May 28, 2026
PLN 21,000 UODO (Poland) - DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Art. 24, 25, 28 +1 Security Controllers Processors May 25, 2026
€1,400 Elektronikus Egészségügyi Szolgáltatási Tér: Insufficient technical and organisational measures to ensure information security Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined Elektronikus Egészségügyi Szolgáltatási Tér €1,400 on 2026-05-20 for: Insufficient… Hungary ·NAIH ·Art. 5, 6, 9 Healthcare Security May 20, 2026
PLN 33,700 UODO (Poland) - DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Art. 5, 24, 25 +3 Personal Data Controllers Accountability May 19, 2026
HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Art. 23 Personal Data Controllers Processing May 13, 2026
HUF 15M NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Personal Data Transparency Fairness & Transparency May 12, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Encryption Integrity and Confidentiality Principle Notification Obligation May 8, 2026
€1.1M South Staffordshire Plc: Insufficient technical and organisational measures to ensure information security Information Commissioner (ICO) fined South Staffordshire Plc €1,112,100 on 2026-05-07 for: Insufficient technical and organisational measures to ensure information security. United Kingdom ·ICO ·Art. 5, 32 Security May 7, 2026
APD/GBA: Controller failed to provide copies of service sheets for GDPR access request The data subject was a technician employed by the controller. The controller used weekly handwritten service sheets as a system for recording working time. These sheets contained… 97/2026 ·Belgium ·Art. 12, 15 Right of Access Procedures Right of Access Accuracy May 6, 2026
€2,802 Slovenian DPA fines processor €2,802 for failing to patch known vulnerability (Art. 32) A processor was contracted by a company (the controller) to maintain an online store, fix errors, and provide support. This included ensuring that the controller had installed the… Slovenia ·IP ·Art. 32 Security Encryption Controllers May 1, 2026
€2,500 BLUE PROJECTS INDUSTRIES S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined BLUE PROJECTS INDUSTRIES S.R.L. €2,500 on 2026-04-30 for: Insufficient technical and… Romania ·ANSPDCP ·Art. 32 Security Personal Data Supervisory Authorities Apr 30, 2026
HUF 10M NAIH fines online store HUF 10M for missing and inadequate privacy notice The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Personal Data Accountability Controllers Apr 30, 2026
€300,000 KONECTA BTO, S.L.: Insufficient technical and organisational measures to ensure information security Spanish Data Protection Authority (aepd) fined KONECTA BTO, S.L. €300,000 on 2026-04-22 for: Insufficient technical and organisational measures to ensure information security. Spain ·aepd ·Art. 5 Security Supervisory Authorities Apr 22, 2026
€400,000 CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined Caixabank, S.A. €400,000 for failing to implement sufficient technical and organizational measures to ensure information… Spain ·aepd ·Art. 5, 25 Privacy by Default Accountability Security Apr 15, 2026
€2,415 UODO (Poland) - DKN.5131.7.2022 An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone… Art. 5, 24, 25 +2 Data Breaches Processors Notification Obligation Apr 13, 2026
€2,500 BLUE PROJECTS S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined BLUE PROJECTS S.R.L. €2,500 on 2026-04-03 for: Insufficient technical and organisational… Romania ·ANSPDCP ·Art. 32 Security Personal Data Supervisory Authorities Apr 3, 2026
€13,491 Legal Person: Insufficient technical and organisational measures to ensure information security Slovenian Supervisory Authority (Informacijski pooblaščenec) fined Legal Person €13,491 on 2026-03-27 for: Insufficient technical and organisational measures to ensure information… Slovenia ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security IP Address Supervisory Authorities Mar 27, 2026
€32M Intesa Sanpaolo S.p.A.: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) fined Intesa Sanpaolo S.p.A. €31,800,000 on 2026-03-26 for: Insufficient technical and organisational measures to ensure information… Italy ·Garante ·Art. 5, 24, 32 +1 Security Insurance Supervisory Authorities Mar 26, 2026
€125,000 RENAULT COMMERCIAL ROUMANIE S.R.L.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined RENAULT COMMERCIAL ROUMANIE S.R.L. €125,000 on 2026-03-25 for: Insufficient technical and… Romania ·ANSPDCP ·Art. 28, 32 Security Personal Data Supervisory Authorities Mar 25, 2026
€4,000 ING Bank NV Amsterdam – Sucursala București S.A.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined ING Bank NV Amsterdam – Sucursala București S.A. €4,000 on 2026-03-23 for: Insufficient… Romania ·ANSPDCP ·Art. 32 Security Supervisory Authorities Insurance Mar 23, 2026
€150,000 ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined ALÍA GESTIÓN INTEGRAL DE SERVICIOS, S.L. €150,000 for failing to implement sufficient technical and organizational measures to… Spain ·aepd ·Art. 5 Integrity and Confidentiality Principle Security Supervisory Authorities Mar 20, 2026
Austrian DSB rules 360-degree feedback unlawful without specific works agreement The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025. They worked as a manager in the controller’s finance department,… 2025-0.960.016 ·Austria ·Art. 6, 88 Legitimate Interest Personal Data Employees Mar 20, 2026
€40,000 INPS – Istituto nazionale previdenza sociale: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) fined INPS – Istituto nazionale previdenza sociale €40,000 on 2026-03-12 for: Insufficient technical and organisational measures to… Italy ·Garante ·Art. 5, 6, 9 +2 Security Education Public Authority Mar 12, 2026
€2,000 Liceo Scientifico Morgagni di Roma: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) fined Liceo Scientifico Morgagni di Roma €2,000 on 2026-03-12 for: Insufficient technical and organisational measures to ensure… Italy ·Garante ·Art. 5, 6, 9 +1 Security Education Public Sector Mar 12, 2026
€2,000 Hanako s.r.l.: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) fined Hanako s.r.l. €2,000 on 2026-03-12 for: Insufficient technical and organisational measures to ensure information security. Italy ·Garante ·Art. 5, 13, 32 Security Healthcare Supervisory Authorities Mar 12, 2026
€650,000 IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA: Insufficient technical and organisational measures to ensure information security Spanish Data Protection Authority (aepd) fined IBERIA LÍNEAS AÉREAS DE ESPAÑA, S.A. OPERADORA €650,000 on 2026-03-11 for: Insufficient technical and organisational measures to… Spain ·aepd ·Art. 5 Security Supervisory Authorities Mar 11, 2026