Skip to content
Content type · 202 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 202 sort newestlargest fineoldest
HmbBfDI (Hamburg) - Einstellung Gerichtsverfahren in Sachen Videmo 360 Following the 2017 G20 summit in Hamburg, the Hamburg Police used automated facial recognition software to analyze video footage. A template database containing mathematical… Einstellung Gerichtsverfahren in Sachen Videmo 360 ·Germany Video Surveillance Biometric Data Biometric Data Jul 24, 2026
€12,000 Italian DPA: Justice Ministry unlawful disclosure of employee health data in service order The data subject was an employee at a detention facility run by the Italian Ministry of Justice (the controller). Following an assessment by the occupational health physician, who… Italy ·Garante per la protezione dei dati personali ·Art. 4, 5, 6 +2 Personal Data Healthcare Health Data Jul 20, 2026
€20,000 Italian DPA: Enna Health Authority violated GDPR by publishing judicial data The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 10 +1 Personal Data Fairness & Transparency Right to Restriction Jul 18, 2026
AEPD investigates University of Navarra over student COVID-19 vaccination status requests A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3 Healthcare Consent Health Data Jul 16, 2026
€200,000 AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack… Spain ·Art. 5, 35, 58 DPIA Privacy Impact Assessment Security Jul 16, 2026
€2M Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 6 +2 Processing Controllers Personal Data Jul 14, 2026
€140 AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Spain ·Art. 5, 6, 83 Telecommunications Accountability Personal Data Jul 13, 2026
IMY reprimands Swedish Police for inadequate GDPR Article 13 info at Arlanda border The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of… IMY-2024-2904 ·Sweden ·Art. 13 Personal Data Controllers Information Provision Modalities and Communication Methods Jul 3, 2026
Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… 2025010358 ·Iceland ·Island Monitoring Cloud Computing Integrity and Confidentiality Principle Jul 1, 2026
€450,000 VDAI (Lithuania) - 3R-1143 Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Art. 5, 24 Security Data Breaches Access Controls Jun 19, 2026
UODO (Poland) - DKN.5131.12.2022 The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Art. 5, 24, 25 +3 Data Breaches Security DPIA Jun 11, 2026
€1,153 Reda Naujokaitienė: Insufficient legal basis for data processing The Lithuanian Data Protection Authority (VDAI) fined Reda Naujokaitienė €1,153 on June 5, 2026, for insufficient legal basis for personal data processing in the health care… Lithuania ·VDAI ·Art. 5, 6, 9 Personal Data Special Categories of Data Supervisory Authorities Jun 5, 2026
€700 Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy ·Garante per la protezione dei dati personali ·Art. 5, 9 Personal Data Healthcare Integrity and Confidentiality Principle May 28, 2026
HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Art. 23 Personal Data Criminal Data Processing May 13, 2026
HUF 15M NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Transparency Personal Data Information Provision Modalities and Communication Methods May 12, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Security Fines Notification Obligation May 8, 2026
AKI (Estonia) - No. 2.1-1/24/397-890-38 OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to… No. 2.1-1/24/397-890-38 ·Art. 4, 5, 6 +8 Controllers Processors Data Controller Apr 16, 2026
€10,000 Natural Person: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 10,000 on a natural person. The controller operated a website on which identity cards containing personal data, including special… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 +6 Criminal Data Personal Data Health Data Jan 30, 2026
€25,500 Austrian DSB: Marketing agency violated GDPR by recording phone interviews without valid The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted… Austria ·Art. 5, 6, 12 +1 Legitimate Interest Personal Data Consent Jan 19, 2026
€200 DSB: Medical student fined for recording dementia patient video without Art 9 GDPR basis A medical student (the controller) worked as a ward attendant at a hospital. Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the… Austria ·Art. 4, 5, 6 +1 Legitimate Interest Healthcare Personal Data Jan 12, 2026
€18,500 Komendanta Miejskiego Policji w Krakowie: Non-compliance with general data processing principles The Polish DPA has imposd a fine of EUR 18,500 on the Komendanta Miejskiego Policji w Krakowie. The controller published personal data, including health data, of a data subject… POLAND ·UODO ·Non-compliance with general data processing principles Personal Data Healthcare Health Data Jan 9, 2026
€10,000 Headquarter of a Fire Brigade: Insufficient legal basis for data processing The Greek DPA has imposed a fine of EUR 10,000 on a Fire Brigade Head Quarter. The controller had stored health data of an employee which had been in relation with her sick leave.… GREECE ·HDPA ·Art. 5 Healthcare Health Data Controllers Jan 8, 2026
Austrian DSB: sharing ADHD diagnosis from public forum post did not breach Art. 9 GDPR A data subject published a post concerning their ADHD diagnosis on a publicly accessible online forum under a pseudonym. A person (the controller) who was a follower of the data… 2025-0.968.031 ·Austria ·Art. 9 Healthcare Health Data Personal Data Dec 3, 2025
€4,750 De districtsinspecteur voor volksgezondheid in Police: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 4.750 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 24, 25 +1 Security Health Data Encryption NL Nov 15, 2025
€4,750 Powiatowego Inspektora Sanitarnego w Policach: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 4750 on the Powiatowego Inspektora Sanitarnego w Policach. The controller failed to implement adequate technical and organisational… POLAND ·UODO ·Art. 5, 24, 25 +1 Encryption Data Breaches Security Nov 15, 2025
€1,000 Mayor of the Municipality of Calvi Risorta: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on the Mayor of the Municipality of Calvi Risorta. The controller published citizens' health data during the Covid-19 pandemic… ITALY ·Garante ·Art. 5, 6, 9 Healthcare Health Data IP Address Oct 23, 2025
€1,000 Burgemeester van de gemeente Calvi Risorta: Er is onvoldoende juridische basis voor de verwerking van gegevens. Een boete van €1.000 - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 Health Data Education Data Controller NL Oct 23, 2025
AEPD sanctions 23andMe for security failures in credential-stuffing breach 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In… PS-00140-2025 ·Spain ·Art. 5, 9, 24 +2 Data Breaches Notification Obligation Integrity and Confidentiality Principle Oct 10, 2025
€12,000 Casa di Cura Città di Roma: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 12.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9, 25 +1 Health Data Healthcare Healthcare NL Sep 11, 2025
€18,000 Comune di Nichelino: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 18,000 on the Comune di Nichelino. The controller published the sensitive personal data of a former employee, including the decision to… ITALY ·Garante ·Art. 5, 6, 12 +1 Personal Data Education Controllers Sep 11, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor gegevensbescherming (Garante). ITALY ·Garante ·Art. 5 Health Data Healthcare Data Controller NL Aug 4, 2025
€80,000 Ospedaliero-Universitaria Careggi: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Health Data Security NL Aug 4, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 2,000 on Linea Stampalibera Società Cooperativa r.I. The controller, who operates a news site, has disclosed too much personal… ITALY ·Garante ·Art. 5 Retention Period Healthcare Health Data Aug 4, 2025
€10,000 SATI S.p.A.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9 Processing Controllers Data Controller NL Jul 23, 2025
€2,200 Legal Entity: Insufficient legal basis for data processing The Slovenian DPA has imposed a fine of EUR 2,200 on a legal entity. An employee of the company forwarded health data to a lawyer without sufficient grounds. The company was fined… SLOVENIA ·Art. 6, 9 ·Insufficient legal basis for data processing Health Data Healthcare Processing Agreement Jul 22, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on VALORA PREVENCIÓN, S.L.U. The controller, a company offering occupational health and safety services, failed to implement… SPAIN ·aepd ·Art. 5, 32 Healthcare Security Health Data Jul 11, 2025
€32,000 VALORA PREVENCIÓN, S.L.U.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 32.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 32 Security Health Data Healthcare NL Jul 11, 2025
€50,000 Magna PT S.p.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Processing NL Jul 10, 2025
€4,000 Istituto Comprensivo 2 C.D. “G. Modugno” S.M. “G. Galilei” in Monopoli: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 4.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 Education Data Controller Processing NL Jul 10, 2025
€80,000 Poste Vita S.p.a.: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine on Poste Vita S.p.a. The controller failed to implement adequate technical and organisational measures to ensure data security. This resulted in… ITALY ·Garante ·Art. 5, 33 Security Insurance Personal Data Jul 10, 2025
€50,000 Magna PT S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine on Magna PT S.p.A. Employees of the controllers were subjected to 'return to work interviews' after returning from an absence due to illness or… ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Controllers Jul 10, 2025
€6,800 Waxholms Ångfartygs AB: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. 6.800 euro boete - De Zweedse Autoriteit voor Gegevensbescherming (Integritetsskyddsmyndigheten). SWEDEN ·Art. 6, 9 ·Insufficient legal basis for data processing Processing Data Controller Personal Data NL Jun 18, 2025
€6,800 AB Storstockholms Lokaltrafik: Onvoldoende juridische basis voor de verwerking van gegevens. 6.800 euro boete - De Zweedse Autoriteit voor Gegevensbescherming (Integritetsskyddsmyndigheten). SWEDEN ·Art. 6, 9 ·Insufficient legal basis for data processing Processing Special Categories of Data Processing Agreement NL Jun 18, 2025
€550,000 Departement of Social Security: Insufficient legal basis for data processing The Irish DPA imposed a fine of EUR 550,000 on the Departement of Social Security. The controller uses the so called SAFE 2 registration process for anyone applying for a Public… IRELAND ·Art. 5, 6, 9 +2 ·Insufficient legal basis for data processing DPIA Privacy Impact Assessment Biometric Data Jun 12, 2025
€550,000 Ministerie van Sociale Zekerheid: Onvoldoende wettelijke basis voor gegevensverwerking. 550.000 euro boete - Ierse Autoriteit voor Gegevensbescherming. IRELAND ·Art. 5, 6, 9 +2 ·Insufficient legal basis for data processing Special Categories of Data Education Types of Special Categories of Personal Data NL Jun 12, 2025
€7,000 Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 7,000 on Health Protection Agency of the Metropolitan City of Milan, Workplace Prevention and Safety Service, Milan North. The controller… ITALY ·Garante ·Art. 5, 9 Health Data Healthcare Personal Data May 21, 2025
€21,000 Menarini Silicon Biosystems SpA: Niet-naleving van de algemene principes voor gegevensverwerking. 21.000 euro boete - Italiaanse Autoriteit voor de bescherming van persoonlijke gegevens (Garante). ITALY ·Garante ·Art. 5, 13 Health Data Healthcare Healthcare NL May 21, 2025
€21,000 Menarini Silicon Biosystems SpA: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 21,000 on Menarini Silicon Biosystems SpA. The controller is conducting oncological research and has developed a software that is able to… ITALY ·Garante ·Art. 5, 13 Healthcare Health Data Retention Period May 21, 2025