Skip to content
Content type · 107 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 107 sort newestlargest fineoldest
€20,000 AEPD fines El Español for disclosing minor's identity in assault video El León de El Español Publicaciones, S.A., the controller, operates the Spanish digital newspaper „El Español“. It published an article concerning an assault and embedded a video… Spain ·Art. 5, 25, 58 Privacy by Default Retention Period Privacy by Design Jul 27, 2026
Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023 A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022.… TSV/4630/2023 ·Art. 5, 12, 25 Personal Data Controllers Right of Access Jul 22, 2026
€90,000 AEPD sanctions ACVIL Aparcamientos for denying access to parking surveillance footage On 13 December 2024, the DPA received a complaint against ACVIL Aparcamientos, S.L.U., the controller, concerning a request for video surveillance footage from a car park. The… Spain ·Art. 14, 15 Right of Access Procedures Controllers Retention Period Jul 21, 2026
€20,000 Italian DPA: Enna Health Authority violated GDPR by publishing judicial data The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 10 +1 Personal Data Fairness & Transparency Right to Restriction Jul 18, 2026
AEPD: No fine for surveillance cameras facing public road; no evidence of rights A complaint is filed against the controller for having six surveillance cameras facing public highway and private spaces without authorisation. In addition to the claim, there is… PS-00601-2021 ·Spain ·Art. 5, 12, 15 +3 Video Surveillance Monitoring Retention Period Jul 17, 2026
€50,000 Italian Garante sanctions Calabrian agency for location tracking of remote workers The Calabrian Regional Agency for Agricultural Development (the controller) implemented a remote work policy that required employees to use a time-tracking application called… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 13 +3 Monitoring DPIA Personal Data Jul 16, 2026
€16,000 Italian Garante: OPI of Pisa must remove residential addresses from public register The data subject, a professional registered with the OPI of Pisa, discovered while consulting the Public Register of Professionals online that the database included the… Italy ·Garante per la protezione dei dati personali ·Art. 1, 5, 6 +3 Personal Data Fairness & Transparency Controllers Jul 16, 2026
€2M Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 6 +2 Controllers Personal Data Processing Jul 14, 2026
€1.4M Italian Garante sanctions EstEnergy for automated creditworthiness scoring in energy EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller… Italy ·Garante per la protezione dei dati personali ·Art. 5, 13, 14 +2 Controllers Retention Period Processors Jul 3, 2026
€5.8M Italian Garante sanctions Hera Comm for automated credit-check refusals of contracts Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas… Italy ·Garante per la protezione dei dati personali ·Art. 5, 12, 13 +3 Controllers Processors Fairness & Transparency Jul 3, 2026
€460,000 Garante: Piaggio violated GDPR by accessing former employees' emails in disciplinary probe Two former employees (the data subjects) of Piaggio (the controller) were dismissed for just cause in March 2023. Following the termination of their employment, they asked the… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 12 +2 Fairness & Transparency Retention Period Personal Data Jun 18, 2026
€5,000 Italian DPA: Vasto municipality breached transparency duties over traffic cameras The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 12 +2 DPIA Privacy Impact Assessment Personal Data Jun 18, 2026
€700 Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy ·Garante per la protezione dei dati personali ·Art. 5, 9 Personal Data Healthcare Health Data May 28, 2026
HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Art. 23 Personal Data Processing Controllers May 13, 2026
AKI (Estonia) - No. 2.1-1/24/397-890-38 OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to… No. 2.1-1/24/397-890-38 ·Art. 4, 5, 6 +8 Controllers Processors Data Controller Apr 16, 2026
€25,500 Austrian DSB: Marketing agency violated GDPR by recording phone interviews without valid The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted… Austria ·Art. 5, 6, 12 +1 Legitimate Interest Personal Data Consent Jan 19, 2026
€8,000 KVIKU SPAIN, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 8,000 on KVIKU SPAIN, S.L.The controller requires customers to send a photo of themselves holding their ID card when verifying their… aepd ·Art. 5 ·Non-compliance with general data processing principles Retention Period IP Address Controllers Jan 10, 2026
€400,000 Verisure Italy s.r.l.: Niet-naleving van algemene principes voor gegevensverwerking. Een boete van 400.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). Garante ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles Archiving Data Controller Processing NL Nov 27, 2025
€400,000 Verisure Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 400,000 on Verisure Italy s.r.l. The controller had been active in direkt marketing activities. The controller failed to ensure that the… Garante ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles IP Address Direct Marketing Storage Limitation Nov 27, 2025
DSB Austria: Online shop violated GDPR by ignoring request to stop gender-specific On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Art. 5, 6, 16 +2 Privacy by Design Privacy by Default Personal Data Nov 24, 2025
€4.5M Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer… CROATIA ·azop ·Art. 5, 6, 12 +4 Employees Processing Agreement Fairness & Transparency Nov 24, 2025
€33,500 Bakery Chain: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 33,500 on a bakery chain. The controller used video surveillance which affected both public areas and areas intended solely for… AUSTRIA ·dsb ·Art. 5, 6 Video Surveillance Monitoring IP Address Sep 5, 2025
€200,900 ILVA A/S: Non-compliance with general data processing principles The Danish DPA has imposed a fine of EUR 200,900 on ILVA A/S. The controller failed to implement data deletion deadlines. This led to an infringement of the principle of storage… DENMARK ·Datatilsynet ·Non-compliance with general data processing principles Storage Limitation Retention Period Controllers Sep 2, 2025
€200,900 ILVA A/S: Overtreding van algemene principes voor gegevensverwerking. Een boete van 200.900 euro - De Deense Autoriteit voor Gegevensbescherming (Datatilsynet). DENMARK ·Datatilsynet ·Non-compliance with general data processing principles Storage Limitation Retention Period Personal Data NL Sep 2, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2,000 on Linea Stampalibera Società Cooperativa r.I. The controller, who operates a news site, has disclosed too much personal… ITALY ·Garante ·Art. 5 Retention Period IP Address Healthcare Aug 4, 2025
€43,000 24/7 Communication Sp. z o.o.: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 43,000 on 24/7 Communication Sp. z o.o. The fined entity acted as the data processor for McDonald’s Polska Sp. z o.o. (see ETid: 2757).… POLAND ·UODO ·Art. 5, 25, 38 Data Breaches Controllers Processors Jul 21, 2025
€5,400 SUNERIS, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5,400 on SUNERIS, S.A. The controller processed scans of ID cards and passports of their guests, infringing the principle of data… SPAIN ·aepd ·Art. 5 Retention Period Controllers IP Address Jul 16, 2025
€50,000 Magna PT S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine on Magna PT S.p.A. Employees of the controllers were subjected to 'return to work interviews' after returning from an absence due to illness or… ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Employees Jul 10, 2025
€50,000 Magna PT S.p.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Data Controller NL Jul 10, 2025
€21,000 Menarini Silicon Biosystems SpA: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 21,000 on Menarini Silicon Biosystems SpA. The controller is conducting oncological research and has developed a software that is able to… ITALY ·Garante ·Art. 5, 13 Retention Period Health Data Healthcare May 21, 2025
€30,000 ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 30,000 on ATRESMEDIA CORPORACIÓN DE MEDIOS DE COMUNICACIÓN, S.A. The controller published a video of a violent incident, which contained the… SPAIN ·aepd ·Art. 5 Retention Period Controllers IP Address May 16, 2025
€100,000 PLATAFORMA CABANILLAS SA.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 100,000 on PLATAFORMA CABANILLAS SA. The controller is requesting criminal record certificates from potential employees before inviting them… SPAIN ·aepd ·Art. 5 Retention Period Controllers IP Address May 13, 2025
€1,200 Municipality of San Francesco al Campo: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 1,200 on the Municipality of San Francesco al Campo. The controller published the personal data of employees on its website, thereby… ITALY ·Garante ·Art. 5 Retention Period Personal Data Controllers Apr 29, 2025
€500,000 Chamber of Commerce, Industry, Services and Navigation of Spain: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500,000 on the Chamber of Commerce, Industry, Services and Navigation of Spain. Due to its function within the Spanish Executive, the… aepd ·Art. 5, 6, 14 ·Insufficient legal basis for data processing Controllers Processors Fairness & Transparency Apr 15, 2025
€5,000 Bestuur voor steun aan burgers en de landbouw: Onvoldoende wettelijke basis voor gegevensverwerking. Een boete van 5.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Storage Limitation Retention Period Processing NL Apr 10, 2025
€21,600 SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed fine on SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L. The controller offers fitness courses which are recorded and published. The consent obtained for the… SPAIN ·aepd ·Art. 5, 7, 28 Storage Limitation Retention Period Controllers Mar 28, 2025
€21,600 SCHOOL FITNESS HOLIDAY & FRANCHISING, S.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 21.600 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 7, 28 Processing Education Storage Limitation NL Mar 28, 2025
€2,300 Company: Non-compliance with general data processing principles The DPA of Luxembourg has issued a fine of EUR 2,300 on a company, that is active in the retail sale of telecommunication equipement in specialised stores. The controller had… LUXEMBOURG ·CNPD ·Art. 5, 6, 13 +2 Video Surveillance Retention Period Controllers Nov 20, 2024
€190,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 190,000 on a hospital. The hospital had suffered a data breach in which radiological image files were irrevocably lost. AZOP had… CROATIA ·azop ·Art. 5, 6, 12 +4 Data Breaches Healthcare Healthcare Sep 13, 2024
€80,000 Selectra S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 80,000 on Selectra S.p.A.. A former employee had lodged a complaint with the DPA on the grounds that the controller was able to access… ITALY ·Garante ·Art. 5, 13, 88 +1 Storage Limitation Retention Period Controllers Jul 17, 2024
€4,000 Medical association: Insufficient fulfilment of data subjects rights The Italian DPA has imposed a fine of EUR 4,000 on the medical association 'Ordine dei Medici Chirurghi e degli Odontoiatri'. A patient had filed a complaint with the DPA. During… ITALY ·Garante ·Art. 12, 13, 15 Personal Data Storage Limitation Retention Period Jun 20, 2024
€6,000 EUROBOX S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on EUROBOX S.A.. A person had filed a complaint with the DPA because, after having their account with the controller blocked, they were asked to… SPAIN ·aepd ·Art. 5, 13 Retention Period IP Address Controllers Jun 5, 2024
€180 Website operator: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the operator of a website for storing data of a data subject for an excessively long period of time and contrary to the principle of storage… SPAIN ·aepd ·Art. 5 Storage Limitation Retention Period IP Address Jun 5, 2024
€15,000 Association: Non-compliance with general data processing principles The French DPA has fined an association EUR 15,000 due to a lack of data security, non-compliance with the principle of data minimisation and a failure to comply with its… FRANCE ·CNIL ·Non-compliance with general data processing principles Retention Period IP Address Security May 25, 2024
€10,000 Association: Non-compliance with general data processing principles The French DPA has fined an association EUR 10,000 due to a lack of data security, non-compliance with the principle of data minimisation and a failure to comply with its… FRANCE ·CNIL ·Non-compliance with general data processing principles Retention Period IP Address Security May 25, 2024
€856,000 Verkkokauppa.com: Non-compliance with general data processing principles The Finnish DPA has imposed a fine of EUR 856,000 on Verkkokauppa.com Plc for not specifying the retention period of customer account data of e-commerce customers. The DPA also… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25 Storage Limitation Retention Period IP Address Mar 6, 2024
€174,640 Black Tiger Belgium: Insufficient fulfilment of information obligations The Belgian DPA has imposed a fine of EUR 174,640 on Black Tiger Belgium. An individual had filed a complaint with the DPA due to the controller's failure to properly comply with… APD ·Art. 5, 6, 12 +5 ·Insufficient fulfilment of information obligations Storage Limitation Right of Access Right of Access Procedures Jan 16, 2024
€16,600 Garðabær municipality: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 16,600 on the municipality of Garðabær. The municipality had used the Google Education system without sufficiently complying with data… ICELAND ·Art. 5, 24, 28 ·Non-compliance with general data processing principles Education IP Address Processing Agreement Dec 6, 2023
€16,600 Reykjanesbær municipality: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 16,600 on the municipality of Reykjanesbær. The municipality had used the Google Education system without sufficiently complying with… ICELAND ·Art. 5, 24, 28 ·Non-compliance with general data processing principles Education Public Authority Processing Agreement Dec 6, 2023
€18,600 City of Hafnarfjörður: Non-compliance with general data processing principles The Icelandic DPA has imposed a fine of EUR 18,600 on the city of Hafnarfjörður. The city had used the Google Education system without sufficiently complying with data protection… ICELAND ·Art. 5, 24, 28 ·Non-compliance with general data processing principles Processing Agreement Processors IP Address Dec 6, 2023