Content type · 72 documents in this view · 3,634 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3564 Processing Agreement2800 Processing2632 Personal Data2596 Controllers2211 Data Controller1862 Law Enforcement1540 IP Address1282 Security1024 Supervision879 Monitoring545 Consent518
HRK 940,000 AZOP (Croatia) - Decision 08-03-2022 (energy company) The controller is a company that manages gas stations. The data subject tried to refuel at one of the controller's gas stations and was dissatisfied with the measurement of the… Art. 15 Aug 3, 2026
HUF 2M NAIH fines online store HUF 2M for unclear and incomplete privacy notice The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The… Hungary ·Art. 12, 13 Jul 22, 2026
€1M CNIL fines energy supplier for mishandling data subject access and objection requests The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French… France ·Art. 12, 14, 15 +2 Jul 17, 2026
€140 AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Spain ·Art. 5, 6, 83 Jul 13, 2026
€158,000 Italian DPA finds GDPR applies to US-based Character.AI service Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy · ·Art. 3, 5, 12 +7 Jul 3, 2026
€450,000 VDAI (Lithuania) - 3R-1143 Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Art. 5, 24 Jun 19, 2026
€2,760 UODO (Poland) - DKN.5131.34.2023 An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained… Art. 5, 24, 25 +1 Jun 13, 2026
€880,000 HDPA fines DEI for unlawful telemarketing calls to opt-out registered subscribers The Greek DPA (HDPA) received twelve complaints filed against DEI, the Greek Public Power Corporation, (the controller) from telephone subscribers (data subjects) regarding the… Greece ·Art. 5, 28, 29 +1 Jun 2, 2026
PLN 21,000 UODO (Poland) - DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Art. 24, 25, 28 +1 May 25, 2026
PLN 26,711 UODO (Poland) - DKE.561.4.2026 The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance extending… Art. 5 May 22, 2026
PLN 33,700 UODO (Poland) - DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Art. 5, 24, 25 +3 May 19, 2026
HUF 15M NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 May 12, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security May 8, 2026
€150,000 AEPD (Spain) - EXP202306354 (PS/00312/2024) The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U. as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested… Art. 5, 6 Feb 11, 2026
€25,500 Austrian DSB: Marketing agency violated GDPR by recording phone interviews without valid The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted… Austria ·Art. 5, 6, 12 +1 Jan 19, 2026
€850,000 Netwerk van instanties en bedrijven: Niet-naleving van algemene principes voor gegevensverwerking. 850.000 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 7 +6 Apr 10, 2025
€850,000 Network of Agencies and Companies: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 850,000 on a network of agencies and companies. The network operated on behalf of Acea Energia S.p.A. and engaged in aggresive customer… ITALY · ·Art. 5, 6, 7 +6 Apr 10, 2025
€18,000 Multiple Companies: Insufficient legal basis for data processing The Italian DPA imposed fines on 3 companies which ammount to EUR 6,000 each. The fined companies (Powerfit s.s.d.a.r.l., Soleo s.s.d.a.r.l. and Zero Due Villa s.s.d.a.r.l.) run a… ITALY · ·Art. 5, 6, 12 +1 Mar 27, 2025
€4,000 Ziekenhuis: Niet-naleving van de algemene principes voor gegevensverwerking. 4.000 euro boete - Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA · ·Art. 13, 14, 25 +1 Mar 24, 2025
€4,000 Hospital: Non-compliance with general data processing principles The Croation DPA (AZOP) has imposed a fine of EUR 4,000 on a hospital. The AZOP found that the hospital used a company which automatically retrieved personal data of vehicle… CROATIA · ·Art. 13, 14, 25 +1 Mar 24, 2025
Belgian DPA finds cookie banner without reject-all button and unequal withdrawal violates On 10 February 2023 the data subject, a trainee working at noyb – European Center for Digital Rights, visited the website of the controller, a Belgian media company. The data… 131/2024 ·Belgium · Oct 11, 2024
€35,700 Company: €35,700 fine The Croatian DPA (AZOP) has imposed fines totaling EUR 35,700 on nine companies for failing to adequately indicate their video surveillance areas and for failing to provide all… CROATIA · ·Unknown Sep 13, 2024
CROATIA DPA: Insufficient fulfilment of information obligations The Croatian DPA (AZOP) has imposed seven fines totaling EUR 16,000 on data controllers for failing to adequately mark video-monitored areas. This lack of marking resulted in… ·Art. 13, 27 ·Insufficient fulfilment of information obligations Apr 22, 2024
€273,000 Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed two fines on the medical facility “Centrum Medyczne Ujastek” totaling approximately EUR 273,000. The first fine of approximately EUR 163,000 was imposed… POLAND · ·Art. 5, 6, 9 +3 Jan 17, 2024
€41 GERMANY DPA: €41 fine The DPA of Hessen has imposed fines totaling EUR 13,486 on 41 data controllers. In its 2024 activity report, the DPA of Hesse reported a total of 47 fines that year. Six of these… Unknown Jan 1, 2024
Police employees: Insufficient legal basis for data processing The DPA of Hamburg has imposed two fines on members of the police for accessing police databases for private research purposes. GERMANY ·Insufficient legal basis for data processing Jan 1, 2024
Private individual: Insufficient legal basis for data processing The DPA of Hamburg has imposed five fines of private individuals for taking or storing photos of individuals without their consent. GERMANY ·Insufficient legal basis for data processing Jan 1, 2024
€ 2,000M AZOP (Croatia) - Decision 14-09-2023 The two companies in question, as controllers, made use of cookies on their websites, but failed to inform data subjects visiting their web pages about the legal basis for… Art. 6, 7, 13 Sep 1, 2023
Multiple website operators: Czech Data Protection Auhtority (UOOU) In the period from January 2023 to July 2023, the Czech DPA imposed fines totaling EUR 178,000, with the highest fine being EUR 36,000. These fines were imposed due to unlawful… CZECH REPUBLIC ·Unknown Aug 2, 2023
Real estate agency: Insufficient legal basis for data processing The DPA of Bremen has imposed five fines on a real estate agency. The controller had repeatedly sent advertising messages to a former prospect and tried to contact them by… GERMANY ·Insufficient legal basis for data processing Jan 1, 2023
Website operator: Insufficient legal basis for data processing The DPA of Bremen has imposed five fines on website operators for using the tracking tool 'Google Analytics' without the prior consent of website users. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Jan 1, 2023
Police officers: Insufficient legal basis for data processing The DPA of Bremen has imposed ten fines between EUR 100 and EUR 1,000 on police officers for unlawfully accessing police databases. GERMANY ·Insufficient legal basis for data processing Jan 1, 2023
€215,000 Humboldt Forum Service GmbH: Insufficient legal basis for data processing The DPA of Berlin has imposed fines totaling EUR 215,000 on Humboldt Forum Service GmbH. Humboldt Forum had improperly documented sensitive information about individual employees… GERMANY ·Insufficient legal basis for data processing Jan 1, 2023
€3M CNIL fines VOODOO for cookie and tracker consent failures in mobile games VOODOO ('provider') was a mobile game developer. The investigation service of the French DPA (the investigation service) carried out several checks on voodoo.io and on several of… France ·Art. 4, 5, 82 Dec 29, 2022
€10,000 SOPHIE ET VOILA, S.L: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 10,000 on SOPHIE ET VOILA, S.L..The wedding dress company had published a picture of a customer in a wedding dress on its Instagram… SPAIN · ·Art. 6 Sep 16, 2022
€15 HDPA (Greece) - 50/2022 A former teacher (the data subject) at a private primary school (the controller) submitted a complaint to the Greek DPA regarding a video surveillance system in the classrooms,… Art. 5, 6, 12 +2 Sep 9, 2022
APD/GBA (Belgium) - 115/2022 During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor,… 115/2022 ·Art. 5, 6, 9 Jul 19, 2022
Persónuvernd (Iceland) - 2020061979 The Icelandic DPA started an investigation into a genetic research company. More specifically, to assess the company's Data Protection Officer (DPO), as well as the performance of… 2020061979 ·Art. 38, 39 Jun 29, 2022
€26,000 Garante per la protezione dei dati personali (Italy) - 9794895 The Municipality of Policoro (Basilicata), implemented the use of CCTV cameras to monitor and fight waste abandonment within its territory. A data subject complained the… Art. 5, 12, 13 +3 Jun 9, 2022
€20,000 Ambuce Rescue Team: Insufficient legal basis for data processing The Belgian DPA has fined Ambuce Rescue Team EUR 20,000. The fine is related to the fines against Brussels Airport Charleroi and Brussels Airport Zaventem. Due to the Covid 19… BELGIUM · ·Art. 5, 6, 9 Apr 4, 2022
LATVIA DPA: Insufficient cooperation with supervisory authority Six fines for failing to provide information requested by the DPA during an investigation. ·Art. 58 ·Insufficient cooperation with supervisory authority Jan 1, 2022
GERMANY DPA: Insufficient legal basis for data processing Nine fines between EUR 200 and EUR 1000 for unlawful use of a dashcam. Art. 6 ·Insufficient legal basis for data processing Jan 1, 2022
LATVIA DPA: Insufficient cooperation with supervisory authority Five fines for failing to comply with orders issued by the DPA. ·Art. 58 ·Insufficient cooperation with supervisory authority Jan 1, 2022
€1.3M Lisbon City Council: Insufficient legal basis for data processing The Portuguese DPA has imposed a fine of EUR 1.25 million on the Lisbon City Council. The fine is the sum of 225 fines from various violations committed by the municipality since… PORTUGAL · ·Art. 5, 6, 9 +2 Dec 21, 2021
€6.3M Grindr LLC: Insufficient legal basis for data processing The Norwegian DPA has fined Grindr LLC EUR 6.3 million. Grindr is a location-based social networking app designed for gay, bi, trans and queer people. In 2020, the Norwegian… NORWAY · ·Art. 6, 9 Dec 13, 2021
€30,000 Ica s.r.l.: Insufficient technical and organisational measures to ensure information security The Italian DPA (Garante) has fined ICA s.r.l. EUR 30,000. The municipality of Collegno had implemented a system developed by ICA through which citizens could pay fines for… ITALY · ·Art. 5, 32 Dec 2, 2021
€30,000 Flowbird Italia s.r.l.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 30,000 on Flowbird Italia s.r.l.. The Garante had launched an investigation following a complaint from an individual who had… ITALY · ·Art. 5, 6, 30 Jul 22, 2021
€800,000 Roma Capitale: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 800,000 on Roma Capitale. The Garante had launched an investigation following a complaint from an individual who had complained… ITALY · ·Art. 5, 12, 13 +3 Jul 22, 2021
€400,000 Atac s.p.a.: Non-compliance with general data processing principles The Italian DPA (Garante) has imposed a fine of EUR 400,000 against Atac s.p.a.. The Garante had launched an investigation following a complaint from an individual who had… ITALY · ·Art. 5, 6, 30 +1 Jul 22, 2021
€8.2M Vodafone España, S.A.U.: Insufficient fulfilment of data subjects rights Since 2018, the Spanish DPA (AEPD) had received a total of 191 complaints against Vodafone España, S.A.U. The data subjects complained about advertising calls and messages (e-mail… SPAIN · ·Art. 21, 23, 24 +3 Mar 11, 2021