Skip to content
Content type · 397 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 397 sort newestlargest fineoldest
Tietosuojavaltuutetun toimisto (Finland) - TSV/5059/2023 The DPA held that a pension insurance company had not violated Articles 5(1)(c) and 25(2) GDPR by disclosing a disability pension applicant's accrued pension in euros to a… TSV/5059/2023 ·Tietosuojavaltuutettu Insurance Retention Period GDPR Article 5 Principles of Processing
2026-0.690.562 The DPA issued a reprimand against a journalist for failing to comply with the data minimisation principle pursuant to Article 5(1)(c) GDPR by publishing a court decision on his… 2026-0.690.562 ·Austria ·DSB Retention Period GDPR Article 5 Principles of Processing Social Media Oct 1, 2026
€5,000 Italian DPA: Municipality of Aprilia unlawfully disclosed whistleblower data to employer The data subject, an employee of a municipal agency, sent a certified email to the Municipality of Aprilia (the controller), requesting a meeting with its Extraordinary Commission… Italy ·Garante ·Art. 5, 6 Public Authority Supervisory Authorities Personal Data Sep 30, 2026
€30,000 Garante: Bologna University Hospital rightly refused erasure of recruitment ranking data The DPA received a complaint from a data subject, regarding the ranking list published as part of a recruitment procedure at the Bologna University Hospital IRCCS (the… Italy ·Art. 5, 6, 9 Personal Data Retention Period Healthcare Sep 29, 2026
€120 Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on The DPA received several complaints from data subjects concerning Experian Italia S.p.A (the controller) an Italian credit information system. The controller was processing the… Italy ·Garante ·Art. 5, 12, 15 +1 Supervisory Authorities Privacy by Design Personal Data Sep 16, 2026
€20,000 AEPD fines El Español for publishing video of minor assailant without anonymization El León de El Español Publicaciones, S.A., the controller, operates the Spanish digital newspaper „El Español“. It published an article concerning an assault and embedded a video… Spain ·Art. 5, 25, 58 Anonymization Privacy by Design & Default Privacy by Default Sep 16, 2026
AEPD: Data subject entitled to identity of professionals who accessed medical records Suspecting unauthorised access to his medical records, a public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide a log copy of… pd-00055-2026 ·Spain ·Art. 5, 12, 15 +2 Personal Data Healthcare Right of Access Sep 15, 2026
HDPA investigates Greek Infrastructure Ministry for SMS sent without consent or The DPA started an investigation, after receiving 83 complaints from data subjects, against the Ministry of Infrastructure and Transportation (the controller). Particularly,… 17/2026 ·Greece ·Art. 5, 14 Consent Personal Data Right to Object Sep 15, 2026
€408,000 AEPD: CaixaBank requested excessive inheritance documentation from heirs A data subject and other heirs were handling the inheritance of a deceased customer through CaixaBank, S.A., the controller. In the course of the inheritance procedure, the… Spain ·Art. 13, 25, 30 Privacy by Design & Default Personal Data Privacy by Design Sep 10, 2026
€6,500 Italian DPA sanctions Top Secret Investigazioni for unjustified email forwarding after The data subjects filed a complaint claiming that Top Secret Investigazioni e sicurezza s.r.l. (the controller) violated the protection of personal data, as a result of failing to… Italy ·Garante ·Art. 5, 13 Supervisory Authorities Retention Period Personal Data Sep 10, 2026
€10,000 Italian DPA finds Ministry of Education's disclosure of disciplinary dismissal excessive The data subject, an employee of the Ministry of Education and Merit (the controller), filed a complaint with the DPA after the controller notified various administrative branches… Italy ·Garante ·Art. 5, 6 Supervisory Authorities Personal Data Retention Period Sep 9, 2026
RON 26,237 Fine against GEROCOSSEN S.R.L. Gerocossen SRL (the controller) suffered a cyberattack that affected its IT infrastructure. As a result, unauthorised parties gained access to personal data relating to some data… Romania ·ANSPDCP ·Art. 32 Data Breaches Notification Obligation Security Sep 8, 2026
IP Slovenia: Controller breached Art. 15(1)(d) and 15(3) GDPR by denying storage info and The data subject made an access request asking for (i) a copy of their personal data processed by the controller and (ii) information on the envisaged storage period of this data.… 0602-68/2025/18 ·IP-RS ·Art. 12, 15 Right of Access Controllers Personal Data Sep 8, 2026
Finnish DPA orders Espoo to ensure pupil data protection in Google learning tools In April 2018, the DPA received a complaint stating that the city of Espoo (the controller) was using Google's digital learning tools in a school without obtaining consent from… TSV/40/2018 ·Finland ·Tietosuojavaltuutettu Supervisory Authorities Controllers Personal Data Sep 4, 2026
€8,000 Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) found that Azienda Speciale per la Gestione degli Impianti Sportivi del Comune di Trento (A.S.I.S.) unlawfully installed video… Italy ·Garante ·Art. 5, 6, 12 +1 Retention Period Storage Limitation Personal Data Sep 3, 2026
€24,000 Friuli Centrale University Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) found that the Friuli Centrale University Health Authority (ASUFC) violated Articles 5(1)(f), 9, 25, and 32 of the GDPR based on a… Italy ·Garante ·Art. 5, 9, 25 +1 Integrity and Confidentiality Principle Data Breaches Right of Access Sep 3, 2026
DSB: Retailer must grant full access and delete data after third-party fraud order A retailer (controller) sent a notebook to the address of a data subject after having received an order to that address. However, the data subject has never placed the order and… DSB-D124.2016/23 ·Austria ·Art. 6, 13, 14 +2 Personal Data Right of Access Right to be Forgotten Aug 26, 2026
€23,750 Italian DPA: Il Fatto Quotidiano must erase data subject's personal data from cable car On 4 January 2024, the newspaper “Il Fatto Quotidiano” (‘the controller’) published an article pertaining to the cable car accident of the data subject. The data subject sent a… Italy ·Garante ·Art. 5, 83 Personal Data Supervisory Authorities Retention Period Aug 26, 2026
HDPA: Hellenic Open University found to have met breach notification duties after The Hellenic Open University (‘the controller’) submitted initial and supplementary notifications to the DPA after it was subject to a data breach resulting from a ransomware… 14/2026 ·Greece ·Art. 32, 33, 34 +1 Data Breaches Notification Obligation Integrity and Confidentiality Principle Aug 19, 2026
An Italian broadcasting company (controller) disseminated an episode about the murder of a woman The murder case dates back several years but gained new attention after the investigation into the murder case was re-opened. In the dissemination, the interior of the home of the… 10273026 ·Italy ·Garante Personal Data Retention Period Right to be Forgotten Aug 18, 2026
RON 285,395 AMATO BESTSELLER S.R.L. A general wholesale/retail trade company (controller) failed to implement adequate technical and organisational measures, such as appropriate training of its employees, in order… Romania ·ANSPDCP ·Art. 5, 9, 12 +2 Integrity and Confidentiality Principle Personal Data Retention Period Aug 18, 2026
Finnish DPA finds 12-year retention of rental applicant data violates minimisation The DPA began investigating the storage periods of the personal data of housing applicants (the data subjects) contained in rental housing applications during a previous… TSV/1319/2025 ·Finland ·Tietosuojavaltuutettu Retention Period Storage Limitation Privacy by Design Aug 7, 2026
€45,000 AMATO BESTSELLER S.R.L: Non-compliance with general data processing principles The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined AMATO BESTSELLER S.R.L €45,000 for non-compliance with general data processing principles.… Romania ·ANSPDCP ·Art. 5, 9, 14 +1 Integrity and Confidentiality Principle Retention Period Supervision Aug 6, 2026
Finnish DPA examines anti-doping organization's GDPR compliance over public suspension An athlete (the data subject) gave a doping sample containing a low concentration of a banned substance in August 2020. The national anti-doping organisation (the controller)… TSV/179/2021 ·Finland ·Tietosuojavaltuutettu Supervisory Authorities Personal Data Retention Period Aug 4, 2026
€200,000M 15/2026 The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information… Greece ·HDPA ·Art. 5, 28, 32 Controllers Data Breaches Integrity and Confidentiality Principle Jul 28, 2026
€6,500 Top Secrert Investigazioni e sicurezza s.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Top Secrert Investigazioni e sicurezza s.r.l. €6,500 for violating the general data processing principles under Article… Italy ·Garante ·Art. 5, 13 Retention Period Storage Limitation Processing Jul 23, 2026
Finnish DPA: requesting address, ID number and strong authentication for access request A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022.… TSV/4630/2023 ·Finland ·Tietosuojavaltuutettu Identification Personal Data Supervisory Authorities Jul 22, 2026
€90,000 AEPD · PS-00159-2025 On 13 December 2024, the DPA received a complaint against ACVIL Aparcamientos, S.L.U., the controller, concerning a request for video surveillance footage from a car park. The… Spain ·Art. 14, 15 Right to Restriction Right of Access Controllers
€20,000 Garante · 471/2026 The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Italy ·Art. 5, 6, 10 +1 Personal Data Retention Period Criminal Data Jul 18, 2026
APDCAT sanctions Madremanya City Council for inadequate redaction of sensitive data in On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing… PS-0036/2026 ·Spain ·Art. 5, 31 Integrity and Confidentiality Principle Personal Data Identification Jul 17, 2026
AEPD · EXP202103746 A complaint is filed against the controller for having six surveillance cameras facing public highway and private spaces without authorisation. In addition to the claim, there is… PS-00601-2021 ·Spain ·Art. 5, 12, 15 +3 Retention Period Access Controls Personal Data
€16,000 10192784 The data subject, a professional registered with the OPI of Pisa, discovered while consulting the Public Register of Professionals online that the database included the… Italy ·Garante ·Art. 1, 5, 6 +3 Personal Data Retention Period Fairness & Transparency
AEPD · EXP202102529 A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3 Consent Personal Data Healthcare
€50,000 Garante · 10128005 The Calabrian Regional Agency for Agricultural Development (the controller) implemented a remote work policy that required employees to use a time-tracking application called… Italy ·Art. 5, 6, 13 +3 Personal Data Monitoring DPIA
€2M Garante fines Lusha Systems Inc. over unauthorized B2B contact database Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was a… Italy ·Art. 3, 5, 6 +2 Personal Data IP Address Legitimate Interest Jul 14, 2026
€6,000 Municipality of Rieti: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Municipality of Rieti €6,000 for violations of general data processing principles under the GDPR. The enforcement action… Italy ·Garante ·Art. 5, 12, 24 +3 Privacy by Design Retention Period Supervision Jul 14, 2026
€5.8M 483/2026 Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas… Italy ·Garante ·Art. 5, 12, 13 +3 Controllers Processors Personal Data Jul 3, 2026
€1.4M Garante · 484/2026 EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller… Italy ·Art. 5, 13, 14 +2 Retention Period Controllers Right of Access Jul 3, 2026
€1.4M EstEnergy S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined EstEnergy S.p.A. €1,400,000 for violations of general data processing principles under Article 5(1) of the GDPR, alongside… Italy ·Garante ·Art. 5, 12, 13 +3 Controllers Processors Retention Period Jul 3, 2026
€5,000 Garante · 457/2026 The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A… Italy ·Art. 5, 6, 12 +2 DPIA Personal Data Fairness & Transparency Jun 18, 2026
€460,000 Garante · 476/2026 Two former employees (the data subjects) of Piaggio (the controller) were dismissed for just cause in March 2023. Following the termination of their employment, they asked the… Italy ·Art. 5, 6, 12 +2 Retention Period Storage Limitation Personal Data Jun 18, 2026
€6,600 Garante · 462/2026 The case involves a worker (the data subject), his former employer (the controller), and the staffing agency that had provided the company with the worker. In late 2023 the data… Italy ·Art. 2, 4, 5 +2 Legitimate Interest Personal Data Integrity and Confidentiality Principle Jun 18, 2026
€6,600 Cosmint S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Cosmint S.p.A. €6,600 for violating general data processing principles in the employment sector, specifically under Articles… Italy ·Garante ·Art. 5, 6, 13 Retention Period Supervision Supervisory Authorities Jun 18, 2026
€95,000 Market-In: Non-compliance with general data processing principles The Hellenic Data Protection Authority (HDPA) fined Market-In €95,000 for violations of the general data processing principles under Article 5 GDPR, including failures related to… Greece ·HDPA ·Art. 5, 12, 13 +2 Accountability Retention Period Right of Access Jun 12, 2026
€320,000 Public Power Corporation S.A. (DEI): Insufficient legal basis for data processing The Hellenic Data Protection Authority (HDPA) fined Public Power Corporation S.A. (DEI) €320,000 for lacking a sufficient legal basis for data processing. The decision addresses… Greece ·HDPA ·Art. 5, 32 Retention Period Storage Limitation Supervisory Authorities Jun 2, 2026
€700 Italian Red Cross: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Italian Red Cross €700 for violating general data processing principles under GDPR Articles 5(1)(c), 5(1)(f), and 9. The… Italy ·Garante ·Art. 5, 9 Integrity and Confidentiality Principle Retention Period Professional Secrecy May 28, 2026
€6,000 A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller) The data subject was employed by the Ligurian Social and Health Care Agency, however, the organisation was later merged with the controller. According to the data subject, the… 382/2026 ·Italy ·Garante Privacy by Design Privacy by Design & Default DPIA May 28, 2026
€6,000 Liguria Health Protection Authority: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Liguria Health Protection Authority €6,000 for lacking a sufficient legal basis for personal data processing in the… Italy ·Garante ·Art. 5, 6, 25 +2 Controllers Retention Period Processing May 28, 2026
€700 Garante · 385/2026 A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy ·Art. 5, 9 Personal Data Retention Period Integrity and Confidentiality Principle May 28, 2026
HDPA · 12/2026 The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Greece ·Art. 23 Right of Access Criminal Data Personal Data May 13, 2026