Content type · 48 documents in this view · 3,811 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3587 Processing 2635 Personal Data 2394 Controllers 2017 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
09-07-2026 (Lyngby Boldklub) Lyngby Boldklub (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial… 09-07-2026 ·Denmark ·
Datatilsynet authorises AC Horsens facial recognition at matches under conditions AC Horsens (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial recognition… 09-07-2026 ·Denmark ·
09-07-2026 (Lyngby Boldklub) Lyngby Boldklub (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial… 09-07-2026 ·Denmark · Sep 1, 2026
ICO (UK) - ACRO Criminal Records Office ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates,… ACRO Criminal Records Office ·United Kingdom ·Art. 32 Aug 7, 2026
HmbBfDI (Hamburg) - Einstellung Gerichtsverfahren in Sachen Videmo 360 Following the 2017 G20 summit in Hamburg, the Hamburg Police used automated facial recognition software to analyze video footage. A template database containing mathematical… Einstellung Gerichtsverfahren in Sachen Videmo 360 ·Germany
€500,000 Hôpital privé de la Loire: Insufficient technical and organisational measures to ensure information security The French Data Protection Authority (CNIL) sanctioned Hôpital Privé de la Loire, a Ramsay Santé group hospital, following a June 2025 personal data breach in which an attacker… France · ·Art. 32, 34 Jul 21, 2026
AEPD · EXP202102529 A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3
IMY-2024-2904 The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of… IMY-2024-2904 ·Sweden ·Art. 13 Jul 3, 2026
€10M Aena, a small and medium-sized enterprise (SME), S.A.: Non-compliance with the general principles of data processing. ⇄ 10.043.002 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN · ·Art. 35 Nov 6, 2025
€10M Aena, S.M.E., S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 10,043,002 on Aena, S.M.E., S.A. The controller conducted a pilot project involving multiple airports, including the use of facial… SPAIN · ·Art. 35 Nov 6, 2025
€96,000 SIDECU, S.A.: Non-compliance with the general principles for data processing. ⇄ Een boete van 96.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN · ·Art. 9, 13, 35 Jun 26, 2025
€550,000 Departement of Social Security: Insufficient legal basis for data processing The Irish DPA imposed a fine of EUR 550,000 on the Departement of Social Security. The controller uses the so called SAFE 2 registration process for anyone applying for a Public… IRELAND · ·Art. 5, 6, 9 +2 Jun 12, 2025
€550,000 Ministry of Social Security: Insufficient legal basis for data processing. ⇄ 550.000 euro boete - Ierse Autoriteit voor Gegevensbescherming. IRELAND · ·Art. 5, 6, 9 +2 Jun 12, 2025
€1,500 ULPIA TRAJANA ALAMEDA S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on ULPIA TRAJANA ALAMEDA S.L. During the booking process, the controller processed data that was unnecessary for the purpose, infringing on the… SPAIN · ·Art. 5, 9 Apr 24, 2025
€1,500 ULPIA TRAJANA ALAMEDA S.L.: Non-compliance with the general principles for data processing. ⇄ 1.500 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN · ·Art. 5, 9 Apr 24, 2025
€4,000 Istituto di Istruzione Superiore 'P. Galluppi' Tropea: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,500 on the Istituto di Istruzione Superiore 'P. Galluppi' Tropea. The controller processed biometric data of its employees to control… ITALY · ·Art. 5, 6, 9 Mar 27, 2025
€4,000 Istituto di Istruzione Superiore 'P. Galluppi' Tropea: Insufficient legal basis for data processing. ⇄ Een boete van 4.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 9 Mar 27, 2025
€1M LIGA NACIONAL DE FÚTBOL PROFESIONAL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1 million on LIGA NACIONAL DE FÚTBOL PROFESIONAL. The controller had introduced access controls for visitors to football stadiums using… SPAIN · ·Art. 35 Dec 20, 2024
€220,000 CARTONAJES BAÑERES, S.A: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined CARTONAJES BAÑERES, S.A. EUR 220,000. During its investigation, the DPA found that the controller had failed to grant a former employee access to their… SPAIN · ·Art. 15, 35 Nov 22, 2024
€220,000 CARTONAJES BAÑERES, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA imposed a fine of EUR 220,000 on CARTONAJES BAÑERES, S.A. following a complaint filed by a former employee. The employee had submitted a request to the controller… SPAIN · ·Art. 15, 35 Nov 22, 2024
€5M Foodinho Srl: Non-compliance with general data processing principles The Italian DPA has fined the food delivery service Foodinho Srl EUR 5 million for unlawfully processing the data of approximately 35,000 drivers and for several violations of the… ITALY · ·Art. 2, 5, 6 +11 Nov 13, 2024
€120,000 Cappello Giovanni & Figli s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 120,000 on Cappello Giovanni & Figli s.r.l.. The controller had used facial recognition technology to monitor the attendance of… ITALY · ·Art. 5, 6, 9 +1 Jun 6, 2024
€31M Clearview AI Inc.: Non-compliance with general data processing principles The Dutch DPA has fined Clearview Al Inc. EUR 30,500,000. Clearview, a company offering facial recognition services, holds a database of over 30 billion images, including those of… May 16, 2024
€365,000 CTC EXTERNALIZACIÓN, S.L: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 365,000 on CTC EXTERNALIZACIÓN, S.L.. An employee had filed a complaint with the DPA due to the fact that the controller had requested… SPAIN · ·Art. 13, 32, 35 Feb 12, 2024
€5,000 Nimbus s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on Nimbus s.r.l.. The controller had introduced a biometric attendance system at the workplace without adequately informing the… ITALY · ·Art. 5, 9, 13 Sep 14, 2023
€20,000 Ew Business Machines S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 20,000 on Ew Business Machines S.p.A.. The controller had installed a video surveillance system that not only recorded images in real… ITALY · ·Art. 5, 9, 13 +1 Jun 1, 2023
€6,000 Praktiškas UAB: Insufficient legal basis for data processing The Lithuanian DPA has fined Praktiškas UAB, the operator of SportGates sports clubs, EUR 6,000. The controller had processed biometric data of customers in the context of their… LITHUANIA · ·Art. 5, 9, 13 +2 Jan 9, 2023
€100,000 VIEC Limited: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 100,000 on the nursing home operator VIEC Limited. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. The… IRELAND · ·Art. 5, 32 Dec 22, 2022
€8,000 Comune di Vicchio: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 8,000 on Comune di Vicchio. The municipality processed biometric data of employees for the purpose of registering their attendance.… ITALY · ·Art. 5, 6, 9 Dec 15, 2022
€5,000 Comune di Borgia: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 5,000 on Comune di Borgia. The municipality processed biometric data of employees for the purpose of registering their attendance.… ITALY · ·Art. 5, 6, 9 +1 Dec 15, 2022
€20,000 Sportitalia: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on Sportitalia. The controller processed biometric data (fingerprints) of employees for the purpose of registering their… ITALY · ·Art. 5, 9, 13 +1 Nov 10, 2022
€20M Clearview Al Inc.: Insufficient fulfilment of data subjects rights The French DPA has fined Clearview Al Inc. EUR 20,000,000. The company holds a database of more than 20 billion facial images (including those of french residents and nationals)… FRANCE · ·Art. 6, 12, 15 +2 Oct 17, 2022
Belgian DPA: Employer unlawfully disclosed employee health data to colleagues (115/2022) During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor,… 115/2022 ·Belgium · Jul 19, 2022
€20M Clearview Al Inc.: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 20,000,000 on Clearview AI Inc. The non-profit organization 'Homos Digitalis' had filed a complaint with the DPA on behalf of the data… Jul 13, 2022
€9M Clearview Al Inc.: Non-compliance with general data processing principles The UK DPA has fined Clearview AI Inc. EUR 9 million. The company holds a database of more than 20 billion facial images (including those of UK residents and nationals) from… UNITED KINGDOM · ·Art. 5, 6, 9 +7 May 18, 2022
€565,000 Dutch Foreign Ministry: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 565,000 on the Dutch Foreign Ministry. As part of its investigation, the DPA found that the National Visa Information System (NVIS)… THE NETHERLANDS · ·Art. 13, 32 Feb 24, 2022
€20M Clearview Al Inc.: Non-compliance with general data processing principles The Italian DPA has fined U.S.-based Clearview AI EUR 20 million after it was revealed that the company had been applying biometric surveillance techniques on Italian territory.… Feb 10, 2022
€20,000 DAVISER SERVICIOS, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine of EUR 20,000 on DAVISER SERVICIOS, S.L.. The company had been processing biometric data (fingerprints) of employees for access to… SPAIN · ·Art. 5 Nov 30, 2021
€16,000 SERVICIOS LOGÍSTICOS MARTORELL SIGLO XXI, S.L.: Non-compliance with general data processing principles The Spanish DPA (AEPD) has imposed a fine on SERVICIOS LOGÍSTICOS MARTORELL SIGLO XXI, S.L.. The company had installed five terminals with a fingerprint control system to record… SPAIN · ·Art. 35 Oct 26, 2021
€2.5M Mercadona S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has fined Mercadona S.A. EUR 2,520,000. The controller had installed facial recognition systems in Mercadona stores for the purpose of tracking individuals… SPAIN · ·Art. 5, 6, 9 +4 Jul 26, 2021
€20,000 UAB VS FITNESS: Non-compliance with general data processing principles The Lithuanian DPA (VDAI) has imposed a fine of EUR 20,000 on UAB VS FITNESS. After receiving a notification from an individual stating that scanning a fingerprint was necessary… LITHUANIA · ·Art. 5, 9, 13 +2 Jun 21, 2021
€30,000 Azienda sanitaria provinciale di Enna: Insufficient legal basis for data processing The Italian DPA (Garante) imposed a fine of EUR 30,000 on Azienda sanitaria provinciale di Enna. The controller processed biometric data of employees for the purpose of… ITALY · ·Art. 5, 6, 9 Jan 14, 2021
€725,000 Unknown Organisation: Insufficient legal basis for data processing The organisation had required its staff to have their fingerprints scanned to record attendance. However, as the decision of the data protection authority stated, the organisation… THE NETHERLANDS · ·Art. 5, 9 Apr 30, 2020
School in Gdansk (Danzig) (fine imposed against town of Gdansk): Insufficient legal basis for data processing Original summary: A school in Gdansk used biometric fingerprint scanners to authenticate students for the payment process in the school canteen. Although the parents had given… POLAND · ·Art. 5, 9 Mar 4, 2020
CZECH REPUBLIC DPA: Non-compliance with general data processing principles Czech Data Protection Auhtority (UOOU) ·Art. 5 ·Non-compliance with general data processing principles Jan 1, 2020
€5,000 Entirely Shipping & Trading S.R.L.: Non-compliance with general data processing principles The company processed biometric data (fingerprints) of the employees for access to certain rooms tough less intrusive means for the privacy of the data subjects could be used… ROMANIA · ·Art. 5, 6, 7 +1 Dec 13, 2019
€511,000 DSK Bank: Insufficient technical and organisational measures to ensure information security Leakage of personal data due to inadequate technical and organisational measures to ensure the protection of information security. Third parties had access to over 23000 credit… BULGARIA · ·Art. 32 Aug 28, 2019
€18,630 School in Skellefteå: Insufficient legal basis for data processing A school in Skellefteå made a trial to use facial recognition technology. The fine was imposed against the school which had used facial recognition technology to monitor the… SWEDEN ·Art. 5, 9, 35 +1 ·Insufficient legal basis for data processing Aug 20, 2019