Skip to content
Content type · 72 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 72 sort newestlargest fineoldest
HRK 940,000 AZOP (Croatia) - Decision 08-03-2022 (energy company) The controller is a company that manages gas stations. The data subject tried to refuel at one of the controller's gas stations and was dissatisfied with the measurement of the… Art. 15 Video Surveillance Right of Access Fines Aug 3, 2026
HUF 2M NAIH fines online store HUF 2M for unclear and incomplete privacy notice The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The… Hungary ·Art. 12, 13 Legitimate Interest Cookies Processing Jul 22, 2026
€1M CNIL fines energy supplier for mishandling data subject access and objection requests The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French… France ·Art. 12, 14, 15 +2 Right of Access Personal Data Right to Object Jul 17, 2026
€140 AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Spain ·Art. 5, 6, 83 Telecommunications Accountability Personal Data Jul 13, 2026
€158,000 Italian DPA finds GDPR applies to US-based Character.AI service Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 12 +7 Controllers Representatives Corrective Actions and Duty of Information Framework Jul 3, 2026
€450,000 VDAI (Lithuania) - 3R-1143 Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Art. 5, 24 Security Data Breaches Access Controls Jun 19, 2026
€2,760 UODO (Poland) - DKN.5131.34.2023 An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained… Art. 5, 24, 25 +1 Data Breaches Security Right of Access Jun 13, 2026
€880,000 HDPA fines DEI for unlawful telemarketing calls to opt-out registered subscribers The Greek DPA (HDPA) received twelve complaints filed against DEI, the Greek Public Power Corporation, (the controller) from telephone subscribers (data subjects) regarding the… Greece ·Art. 5, 28, 29 +1 Personal Data Controllers Telecommunications Jun 2, 2026
PLN 21,000 UODO (Poland) - DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Art. 24, 25, 28 +1 Security Processors Controllers May 25, 2026
PLN 26,711 UODO (Poland) - DKE.561.4.2026 The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance extending… Art. 5 Monitoring Fairness & Transparency Video Surveillance May 22, 2026
PLN 33,700 UODO (Poland) - DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Art. 5, 24, 25 +3 Controllers Personal Data Data Breaches May 19, 2026
HUF 15M NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Personal Data Transparency Fairness & Transparency May 12, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Notification Obligation Security Encryption May 8, 2026
€150,000 AEPD (Spain) - EXP202306354 (PS/00312/2024) The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested… Art. 5, 6 Personal Data Integrity and Confidentiality Principle Access Controls Feb 11, 2026
€25,500 Austrian DSB: Marketing agency violated GDPR by recording phone interviews without valid The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted… Austria ·Art. 5, 6, 12 +1 Legitimate Interest Personal Data Consent Jan 19, 2026
€850,000 Netwerk van instanties en bedrijven: Niet-naleving van algemene principes voor gegevensverwerking. 850.000 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +6 Fines Processing Telecommunications NL Apr 10, 2025
€850,000 Network of Agencies and Companies: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 850,000 on a network of agencies and companies. The network operated on behalf of Acea Energia S.p.A. and engaged in aggresive customer… ITALY ·Garante ·Art. 5, 6, 7 +6 Fines IP Address Telecommunications Apr 10, 2025
€18,000 Multiple Companies: Insufficient legal basis for data processing The Italian DPA imposed fines on 3 companies which ammount to EUR 6,000 each. The fined companies (Powerfit s.s.d.a.r.l., Soleo s.s.d.a.r.l. and Zero Due Villa s.s.d.a.r.l.) run a… ITALY ·Garante ·Art. 5, 6, 12 +1 Right to be Forgotten Fines Direct Marketing Mar 27, 2025
€4,000 Ziekenhuis: Niet-naleving van de algemene principes voor gegevensverwerking. 4.000 euro boete - Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·azop ·Art. 13, 14, 25 +1 Health Data Healthcare Personal Data NL Mar 24, 2025
€4,000 Hospital: Non-compliance with general data processing principles The Croation DPA (AZOP) has imposed a fine of EUR 4,000 on a hospital. The AZOP found that the hospital used a company which automatically retrieved personal data of vehicle… CROATIA ·azop ·Art. 13, 14, 25 +1 Fines Healthcare Healthcare Mar 24, 2025
Belgian DPA finds cookie banner without reject-all button and unequal withdrawal violates On 10 February 2023 the data subject, a trainee working at noyb – European Center for Digital Rights, visited the website of the controller, a Belgian media company. The data… 131/2024 ·Belgium ·APD/GBA Cookies Direct Marketing Personal Data Oct 11, 2024
€35,700 Company: €35,700 fine The Croatian DPA (AZOP) has imposed fines totaling EUR 35,700 on nine companies for failing to adequately indicate their video surveillance areas and for failing to provide all… CROATIA ·azop ·Unknown Video Surveillance Fines Monitoring Sep 13, 2024
CROATIA DPA: Insufficient fulfilment of information obligations The Croatian DPA (AZOP) has imposed seven fines totaling EUR 16,000 on data controllers for failing to adequately mark video-monitored areas. This lack of marking resulted in… azop ·Art. 13, 27 ·Insufficient fulfilment of information obligations Fines Video Surveillance Controllers Apr 22, 2024
€273,000 Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed two fines on the medical facility “Centrum Medyczne Ujastek” totaling approximately EUR 273,000. The first fine of approximately EUR 163,000 was imposed… POLAND ·UODO ·Art. 5, 6, 9 +3 Encryption Healthcare Healthcare Jan 17, 2024
€41 GERMANY DPA: €41 fine The DPA of Hessen has imposed fines totaling EUR 13,486 on 41 data controllers. In its 2024 activity report, the DPA of Hesse reported a total of 47 fines that year. Six of these… Unknown Fines Supervisory Authorities Healthcare Jan 1, 2024
Police employees: Insufficient legal basis for data processing The DPA of Hamburg has imposed two fines on members of the police for accessing police databases for private research purposes. GERMANY ·Insufficient legal basis for data processing Fines Scientific Research Processing Jan 1, 2024
Private individual: Insufficient legal basis for data processing The DPA of Hamburg has imposed five fines of private individuals for taking or storing photos of individuals without their consent. GERMANY ·Insufficient legal basis for data processing Fines Consent Processing Jan 1, 2024
€ 2,000M AZOP (Croatia) - Decision 14-09-2023 The two companies in question, as controllers, made use of cookies on their websites, but failed to inform data subjects visiting their web pages about the legal basis for… Art. 6, 7, 13 Cookies Fines Personal Data Sep 1, 2023
Multiple website operators: Czech Data Protection Auhtority (UOOU) In the period from January 2023 to July 2023, the Czech DPA imposed fines totaling EUR 178,000, with the highest fine being EUR 36,000. These fines were imposed due to unlawful… CZECH REPUBLIC ·Unknown Fines Cookies Integrity and Confidentiality Principle Aug 2, 2023
Real estate agency: Insufficient legal basis for data processing The DPA of Bremen has imposed five fines on a real estate agency. The controller had repeatedly sent advertising messages to a former prospect and tried to contact them by… GERMANY ·Insufficient legal basis for data processing Personal Data Controllers Fines Jan 1, 2023
Website operator: Insufficient legal basis for data processing The DPA of Bremen has imposed five fines on website operators for using the tracking tool 'Google Analytics' without the prior consent of website users. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Fines Cookies Monitoring Jan 1, 2023
Police officers: Insufficient legal basis for data processing The DPA of Bremen has imposed ten fines between EUR 100 and EUR 1,000 on police officers for unlawfully accessing police databases. GERMANY ·Insufficient legal basis for data processing Fines Supervisory Authorities Processing Jan 1, 2023
€215,000 Humboldt Forum Service GmbH: Insufficient legal basis for data processing The DPA of Berlin has imposed fines totaling EUR 215,000 on Humboldt Forum Service GmbH. Humboldt Forum had improperly documented sensitive information about individual employees… GERMANY ·Insufficient legal basis for data processing Fines Healthcare Employees Jan 1, 2023
€3M CNIL fines VOODOO for cookie and tracker consent failures in mobile games VOODOO ('provider') was a mobile game developer. The investigation service of the French DPA (the investigation service) carried out several checks on voodoo.io and on several of… France ·Art. 4, 5, 82 Cookies Telecommunications Direct Marketing Dec 29, 2022
€10,000 SOPHIE ET VOILA, S.L: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on SOPHIE ET VOILA, S.L..The wedding dress company had published a picture of a customer in a wedding dress on its Instagram… SPAIN ·aepd ·Art. 6 Personal Data Lawful Basis Social Media Sep 16, 2022
€15 HDPA (Greece) - 50/2022 A former teacher (the data subject) at a private primary school (the controller) submitted a complaint to the Greek DPA regarding a video surveillance system in the classrooms,… Art. 5, 6, 12 +2 Legitimate Interest Video Surveillance Personal Data Sep 9, 2022
APD/GBA (Belgium) - 115/2022 During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor,… 115/2022 ·Art. 5, 6, 9 Personal Data Lawful Basis Controllers Jul 19, 2022
Persónuvernd (Iceland) - 2020061979 The Icelandic DPA started an investigation into a genetic research company. More specifically, to assess the company's Data Protection Officer (DPO), as well as the performance of… 2020061979 ·Art. 38, 39 Supervisory Authorities Notified Body Responsibilities and Operational Obligations Scientific Panel Independence Jun 29, 2022
€26,000 Garante per la protezione dei dati personali (Italy) - 9794895 The Municipality of Policoro (Basilicata), implemented the use of CCTV cameras to monitor and fight waste abandonment within its territory. A data subject complained the… Art. 5, 12, 13 +3 Video Surveillance Storage Limitation Monitoring Jun 9, 2022
€20,000 Ambuce Rescue Team: Insufficient legal basis for data processing The Belgian DPA has fined Ambuce Rescue Team EUR 20,000. The fine is related to the fines against Brussels Airport Charleroi and Brussels Airport Zaventem. Due to the Covid 19… BELGIUM ·APD ·Art. 5, 6, 9 Health Data Healthcare Fines Apr 4, 2022
LATVIA DPA: Insufficient cooperation with supervisory authority Six fines for failing to provide information requested by the DPA during an investigation. DSI ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Fines Supervision Jan 1, 2022
GERMANY DPA: Insufficient legal basis for data processing Nine fines between EUR 200 and EUR 1000 for unlawful use of a dashcam. Art. 6 ·Insufficient legal basis for data processing Fines Processing Processing Agreement Jan 1, 2022
LATVIA DPA: Insufficient cooperation with supervisory authority Five fines for failing to comply with orders issued by the DPA. DSI ·Art. 58 ·Insufficient cooperation with supervisory authority Supervisory Authorities Fines Supervision Jan 1, 2022
€1.3M Lisbon City Council: Insufficient legal basis for data processing The Portuguese DPA has imposed a fine of EUR 1.25 million on the Lisbon City Council. The fine is the sum of 225 fines from various violations committed by the municipality since… PORTUGAL ·CNPD ·Art. 5, 6, 9 +2 Religious Beliefs DPIA Fines Dec 21, 2021
€6.3M Grindr LLC: Insufficient legal basis for data processing The Norwegian DPA has fined Grindr LLC EUR 6.3 million. Grindr is a location-based social networking app designed for gay, bi, trans and queer people. In 2020, the Norwegian… NORWAY ·Datatilsynet ·Art. 6, 9 IP Address Direct Marketing Fines Dec 13, 2021
€30,000 Ica s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined ICA s.r.l. EUR 30,000. The municipality of Collegno had implemented a system developed by ICA through which citizens could pay fines for… ITALY ·Garante ·Art. 5, 32 Security Fines Privacy by Design & Default Dec 2, 2021
€30,000 Flowbird Italia s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 30,000 on Flowbird Italia s.r.l.. The Garante had launched an investigation following a complaint from an individual who had… ITALY ·Garante ·Art. 5, 6, 30 Fines IP Address Processing Agreement Jul 22, 2021
€800,000 Roma Capitale: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 800,000 on Roma Capitale. The Garante had launched an investigation following a complaint from an individual who had complained… ITALY ·Garante ·Art. 5, 12, 13 +3 Controllers Processors Integrity and Confidentiality Principle Jul 22, 2021
€400,000 Atac s.p.a.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 400,000 against Atac s.p.a.. The Garante had launched an investigation following a complaint from an individual who had… ITALY ·Garante ·Art. 5, 6, 30 +1 Fines Integrity and Confidentiality Principle IP Address Jul 22, 2021
€8.2M Vodafone España, S.A.U.: Insufficient fulfilment of data subjects rights Since 2018, the Spanish DPA (AEPD) had received a total of 191 complaints against Vodafone España, S.A.U. The data subjects complained about advertising calls and messages (e-mail… SPAIN ·aepd ·Art. 21, 23, 24 +3 Right to Object Fines Telecommunications Mar 11, 2021