Content type · 90 documents in this view · 3,813 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3589 Processing 2636 Personal Data 2395 Controllers 2018 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
Icelandic DPA opens formal proceedings against Isavia over ANPR parking cameras at The DPA initiated an investigation into Isavia domestic airports Ltd. (the controller) concerning the electronic monitoring of car parks in five airports: Reykjavík, Akureyri,… 2025061555 ·Iceland · Sep 30, 2026
€39,000 Italian DPA: employer breached Art. 15 GDPR by ignoring access request over disciplinary The data subject, a security guard of La Patria S.p.A. (the controller), complained to the DPA about the lack of response by the controller to two access requests regarding the… Italy · ·Art. 12, 13, 15 Sep 23, 2026
Persónuvernd: Icelandic Farmers’ Association breached GDPR by disclosing owner data to The DPA received a complaint from a data subject, after the Icelandic Farmers’ Association operating a database, disclosed her personal data without consent to the company… 2025010358 ·Iceland ·Art. 5, 14 Sep 23, 2026
€750,000 AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight Vodafone España, S.A.U., the controller, operated a service known as "Super WiFi" through a third-party processor. Following a data breach affecting the service, the DPA's… Spain ·Art. 5, 28, 32 Sep 23, 2026
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Sep 22, 2026
€140 AEPD fines DIGI Telecom for issuing duplicate SIM to impersonator without consent On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Spain ·Art. 5, 6, 83 Sep 16, 2026
€1M AEPD sanctions Iberdrola Clientes for improper identity verification and unauthorized Iberdrola Clientes, S.A.U., an electricity retailer of the Iberdrola group (the controller), verified the identity of customers calling its call centres under an internal guide… Spain ·Art. 24, 32, 58 +1
€3,150 APDCAT: Public body violated GDPR by disclosing audio recording to four extra recipients On 22 January 2025, an employee and trade union representative of a public-sector organisation, the data subject, emailed the DPO requesting access to and a copy of a recording of… Spain ·Art. 5, 6, 12 +1 Sep 15, 2026
€408,000 AEPD: CaixaBank requested excessive inheritance documentation from heirs A data subject and other heirs were handling the inheritance of a deceased customer through CaixaBank, S.A., the controller. In the course of the inheritance procedure, the… Spain ·Art. 13, 25, 30 Sep 10, 2026
€2,000 AEPD · ps-00256-2025 After receiving an in-person visit at her address, a data subject received a letter from a third party concerning a plot of land. The third party asked the data subject to… Spain ·Art. 6 Sep 8, 2026
€5.5M Banco Bilbao Vizcaya Argentaria S.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) found Banco Bilbao Vizcaya Argentaria, S.A. (Italian branch) violated Articles 5(1)(a), 12, 21, and 24 of the GDPR by continuing to… Italy · ·Art. 5, 12, 21 +1 Sep 3, 2026
AEPD: Canals City Council breached Art. 5(1)(f) GDPR by discarding exam papers unshredded The DPA became aware that examination papers from an employment-training programme managed by Canals City Council, the controller, had been found next to waste containers in a… PS-00506-2026 ·Spain ·Art. 5 Sep 2, 2026
€7,200 UODO fines controller PLN 31,507 for failing to provide information under Art. 58(1) GDPR The DPA launched an investigation into two websites operated by the controller under case number DKN.5101.8.2025. The controller collected the names and the occupations of… Poland ·Art. 58 Sep 1, 2026
€825M Uber Technologies Inc.: Non-compliance with general data processing principles The Dutch Supervisory Authority for Data Protection (AP) fined Uber Technologies Inc. €824,990,000 for non-compliance with general data processing principles, specifically… The Netherlands · ·Art. 13, 14, 22 Aug 21, 2026
HRK 940,000 Decision 08-03-2022 (energy company) The controller is a company that manages gas stations. The data subject tried to refuel at one of the controller's gas stations and was dissatisfied with the measurement of the… Croatia · ·Art. 15
€200,000M 15/2026 The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information… Greece · ·Art. 5, 28, 32 Jul 28, 2026
HUF 2M NAIH-11443-3/2026 The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The… Hungary ·Art. 12, 13 Jul 22, 2026
€300,000 CNIL fines EXTIA for failing to properly handle job applicant erasure requests EXTIA, the controller, is a French consulting company specialising in IT and engineering services. As part of its recruitment activities, the controller processed personal data of… France ·Art. 12, 17 Jul 21, 2026
€1M CNIL · SAN-2022-011 The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French… France ·Art. 12, 14, 15 +2
€158,000 Garante · 487/2026 Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Art. 3, 5, 12 +7 Jul 3, 2026
2025010364 The DPA received a complaint from a data subject regarding the processing of their personal data by Borgarholtsskóli (a school and the controller) in connection with an anonymous… 2025010364 ·Iceland · Jun 24, 2026
€450,000 VDAI fines medical company €450,000 for inadequate security measures in data breaches Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Lithuania ·Art. 5, 24 Jun 19, 2026
€2,760 UODO fines accounting firm €2,760 for email breach security failures An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained… Poland ·Art. 5, 24, 25 +1 Jun 13, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland · ·Art. 5, 28, 30 +2 Jun 11, 2026
UODO fines controller for refusing to cooperate and provide information in two data The DPA received two complaints against the same company (the controller) due to the unauthorised access to the data subjects’ personal data. The first complaint concerned… DKE.561.1.2026 ·Poland ·Art. 31, 58 Jun 1, 2026
PLN 21,000 DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Poland · ·Art. 24, 25, 28 +1 May 25, 2026
PLN 26,711 DKE.561.4.2026 The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance extending… Poland · ·Art. 5 May 22, 2026
PLN 33,700 DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Poland · ·Art. 5, 24, 25 +3 May 19, 2026
HUF 15M NAIH-450-7-2026 The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 May 12, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland · ·Art. 5, 32, 33 May 8, 2026
€150,000 The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested a duplicate SIM card for the mobile line of a data subject. The request was… EXP202306354 (PS/00312/2024) ·Spain ·Art. 5, 6 Feb 11, 2026
€25,500 DSB · 2025-1.049.138 The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted… Austria ·Art. 5, 6, 12 +1 Jan 19, 2026
€4,000 AEPD: Continuous workplace audio recording violates GDPR data minimisation principle On 22 April 2025, a data subject lodged a complaint with the DPA against BODENSE ESTRUCTURAS Y CALDELERÍA, S.L., the controller. The data subject claimed that the controller had… Spain ·Art. 5 Apr 22, 2025
€850,000 Network of Agencies and Companies: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 850,000 on a network of agencies and companies. The network operated on behalf of Acea Energia S.p.A. and engaged in aggresive customer… ITALY · ·Art. 5, 6, 7 +6 Apr 10, 2025
€850,000 Network of agencies and companies: Non-compliance with general data processing principles. ⇄ 850.000 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 7 +6 Apr 10, 2025
€18,000 Multiple Companies: Insufficient legal basis for data processing The Italian DPA imposed fines on 3 companies which ammount to EUR 6,000 each. The fined companies (Powerfit s.s.d.a.r.l., Soleo s.s.d.a.r.l. and Zero Due Villa s.s.d.a.r.l.) run a… ITALY · ·Art. 5, 6, 12 +1 Mar 27, 2025
€4,000 Hospital: Non-compliance with general data processing principles The Croation DPA (AZOP) has imposed a fine of EUR 4,000 on a hospital. The AZOP found that the hospital used a company which automatically retrieved personal data of vehicle… CROATIA · ·Art. 13, 14, 25 +1 Mar 24, 2025
€4,000 Hospital: Non-compliance with general principles of data processing. ⇄ 4.000 euro boete - Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA · ·Art. 13, 14, 25 +1 Mar 24, 2025
APD/GBA · 131/2024 On 10 February 2023 the data subject, a trainee working at noyb – European Center for Digital Rights, visited the website of the controller, a Belgian media company. The data… 131/2024 ·Belgium ·Art. 4, 5, 6 Oct 11, 2024
€35,700 Company: €35,700 fine The Croatian DPA (AZOP) has imposed fines totaling EUR 35,700 on nine companies for failing to adequately indicate their video surveillance areas and for failing to provide all… CROATIA · ·Unknown Sep 13, 2024
CROATIA DPA: Insufficient fulfilment of information obligations The Croatian DPA (AZOP) has imposed seven fines totaling EUR 16,000 on data controllers for failing to adequately mark video-monitored areas. This lack of marking resulted in… ·Art. 13, 27 ·Insufficient fulfilment of information obligations Apr 22, 2024
€273,000 Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed two fines on the medical facility “Centrum Medyczne Ujastek” totaling approximately EUR 273,000. The first fine of approximately EUR 163,000 was imposed… POLAND · ·Art. 5, 6, 9 +3 Jan 17, 2024
€41 GERMANY DPA: €41 fine The DPA of Hessen has imposed fines totaling EUR 13,486 on 41 data controllers. In its 2024 activity report, the DPA of Hesse reported a total of 47 fines that year. Six of these… Unknown Jan 1, 2024
Private individual: Insufficient legal basis for data processing The DPA of Hamburg has imposed five fines of private individuals for taking or storing photos of individuals without their consent. GERMANY · ·Insufficient legal basis for data processing Jan 1, 2024
Police employees: Insufficient legal basis for data processing The DPA of Hamburg has imposed two fines on members of the police for accessing police databases for private research purposes. GERMANY · ·Insufficient legal basis for data processing Jan 1, 2024
€ 2,000M Decision 14-09-2023 The two companies in question, as controllers, made use of cookies on their websites, but failed to inform data subjects visiting their web pages about the legal basis for… Croatia · ·Art. 6, 7, 13 Sep 1, 2023
Multiple website operators: Czech Data Protection Auhtority (UOOU) In the period from January 2023 to July 2023, the Czech DPA imposed fines totaling EUR 178,000, with the highest fine being EUR 36,000. These fines were imposed due to unlawful… CZECH REPUBLIC · ·Unknown Aug 2, 2023
Police officers: Insufficient legal basis for data processing The DPA of Bremen has imposed ten fines between EUR 100 and EUR 1,000 on police officers for unlawfully accessing police databases. GERMANY ·Insufficient legal basis for data processing Jan 1, 2023
Real estate agency: Insufficient legal basis for data processing The DPA of Bremen has imposed five fines on a real estate agency. The controller had repeatedly sent advertising messages to a former prospect and tried to contact them by… GERMANY ·Insufficient legal basis for data processing Jan 1, 2023
Website operator: Insufficient legal basis for data processing The DPA of Bremen has imposed five fines on website operators for using the tracking tool 'Google Analytics' without the prior consent of website users. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Jan 1, 2023