Skip to content
Content type · 90 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 90 sort newestlargest fineoldest
Icelandic DPA opens formal proceedings against Isavia over ANPR parking cameras at The DPA initiated an investigation into Isavia domestic airports Ltd. (the controller) concerning the electronic monitoring of car parks in five airports: Reykjavík, Akureyri,… 2025061555 ·Iceland ·Persónuvernd Supervisory Authorities Personal Data Monitoring Sep 30, 2026
€39,000 Italian DPA: employer breached Art. 15 GDPR by ignoring access request over disciplinary The data subject, a security guard of La Patria S.p.A. (the controller), complained to the DPA about the lack of response by the controller to two access requests regarding the… Italy ·Garante ·Art. 12, 13, 15 Supervisory Authorities Right of Access Personal Data Sep 23, 2026
Persónuvernd: Icelandic Farmers’ Association breached GDPR by disclosing owner data to The DPA received a complaint from a data subject, after the Icelandic Farmers’ Association operating a database, disclosed her personal data without consent to the company… 2025010358 ·Iceland ·Art. 5, 14 Legitimate Interest Personal Data Fairness & Transparency Sep 23, 2026
€750,000 AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight Vodafone España, S.A.U., the controller, operated a service known as "Super WiFi" through a third-party processor. Following a data breach affecting the service, the DPA's… Spain ·Art. 5, 28, 32 Processors Controllers Processing Agreement Sep 23, 2026
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Data Breaches Notification Obligation Controllers Sep 22, 2026
€140 AEPD fines DIGI Telecom for issuing duplicate SIM to impersonator without consent On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Spain ·Art. 5, 6, 83 Consent Integrity and Confidentiality Principle Personal Data Sep 16, 2026
€1M AEPD sanctions Iberdrola Clientes for improper identity verification and unauthorized Iberdrola Clientes, S.A.U., an electricity retailer of the Iberdrola group (the controller), verified the identity of customers calling its call centres under an internal guide… Spain ·Art. 24, 32, 58 +1 Identification Personal Data Accountability
€3,150 APDCAT: Public body violated GDPR by disclosing audio recording to four extra recipients On 22 January 2025, an employee and trade union representative of a public-sector organisation, the data subject, emailed the DPO requesting access to and a copy of a recording of… Spain ·Art. 5, 6, 12 +1 Personal Data Right of Access Integrity and Confidentiality Principle Sep 15, 2026
€408,000 AEPD: CaixaBank requested excessive inheritance documentation from heirs A data subject and other heirs were handling the inheritance of a deceased customer through CaixaBank, S.A., the controller. In the course of the inheritance procedure, the… Spain ·Art. 13, 25, 30 Privacy by Design & Default Personal Data Privacy by Design Sep 10, 2026
€2,000 AEPD · ps-00256-2025 After receiving an in-person visit at her address, a data subject received a letter from a third party concerning a plot of land. The third party asked the data subject to… Spain ·Art. 6 Personal Data Recipient Legitimate Interest Sep 8, 2026
€5.5M Banco Bilbao Vizcaya Argentaria S.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) found Banco Bilbao Vizcaya Argentaria, S.A. (Italian branch) violated Articles 5(1)(a), 12, 21, and 24 of the GDPR by continuing to… Italy ·Garante ·Art. 5, 12, 21 +1 Right to Object Personal Data Direct Marketing Sep 3, 2026
AEPD: Canals City Council breached Art. 5(1)(f) GDPR by discarding exam papers unshredded The DPA became aware that examination papers from an employment-training programme managed by Canals City Council, the controller, had been found next to waste containers in a… PS-00506-2026 ·Spain ·Art. 5 Integrity and Confidentiality Principle Data Breaches Notification Obligation Sep 2, 2026
€7,200 UODO fines controller PLN 31,507 for failing to provide information under Art. 58(1) GDPR The DPA launched an investigation into two websites operated by the controller under case number DKN.5101.8.2025. The controller collected the names and the occupations of… Poland ·Art. 58 Controllers Personal Data Supervisory Authorities Sep 1, 2026
€825M Uber Technologies Inc.: Non-compliance with general data processing principles The Dutch Supervisory Authority for Data Protection (AP) fined Uber Technologies Inc. €824,990,000 for non-compliance with general data processing principles, specifically… The Netherlands ·AP ·Art. 13, 14, 22 Automated Decision-Making Supervision Profiling Aug 21, 2026
HRK 940,000 Decision 08-03-2022 (energy company) The controller is a company that manages gas stations. The data subject tried to refuel at one of the controller's gas stations and was dissatisfied with the measurement of the… Croatia ·AZOP ·Art. 15 Right of Access Personal Data Fines
€200,000M 15/2026 The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information… Greece ·HDPA ·Art. 5, 28, 32 Controllers Data Breaches Integrity and Confidentiality Principle Jul 28, 2026
HUF 2M NAIH-11443-3/2026 The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The… Hungary ·Art. 12, 13 Legitimate Interest Personal Data Lawful Basis Jul 22, 2026
€300,000 CNIL fines EXTIA for failing to properly handle job applicant erasure requests EXTIA, the controller, is a French consulting company specialising in IT and engineering services. As part of its recruitment activities, the controller processed personal data of… France ·Art. 12, 17 Personal Data Right to be Forgotten Right to Restriction Jul 21, 2026
€1M CNIL · SAN-2022-011 The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French… France ·Art. 12, 14, 15 +2 Right to Object Personal Data Right of Access
€158,000 Garante · 487/2026 Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Art. 3, 5, 12 +7 Child Consent Personal Data Right to Object Jul 3, 2026
2025010364 The DPA received a complaint from a data subject regarding the processing of their personal data by Borgarholtsskóli (a school and the controller) in connection with an anonymous… 2025010364 ·Iceland ·Persónuvernd Personal Data Fairness & Transparency Right to be Forgotten Jun 24, 2026
€450,000 VDAI fines medical company €450,000 for inadequate security measures in data breaches Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Lithuania ·Art. 5, 24 Security Data Breaches Integrity and Confidentiality Principle Jun 19, 2026
€2,760 UODO fines accounting firm €2,760 for email breach security failures An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained… Poland ·Art. 5, 24, 25 +1 Data Breaches Integrity and Confidentiality Principle Notification Obligation Jun 13, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland ·DPC ·Art. 5, 28, 30 +2 Integrity and Confidentiality Principle Notification Obligation Data Breaches Jun 11, 2026
UODO fines controller for refusing to cooperate and provide information in two data The DPA received two complaints against the same company (the controller) due to the unauthorised access to the data subjects’ personal data. The first complaint concerned… DKE.561.1.2026 ·Poland ·Art. 31, 58 Controllers Personal Data Supervisory Authorities Jun 1, 2026
PLN 21,000 DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Poland ·UODO ·Art. 24, 25, 28 +1 Integrity and Confidentiality Principle Security Controllers May 25, 2026
PLN 26,711 DKE.561.4.2026 The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance extending… Poland ·UODO ·Art. 5 Accountability Monitoring Personal Data May 22, 2026
PLN 33,700 DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Poland ·UODO ·Art. 5, 24, 25 +3 Data Breaches Integrity and Confidentiality Principle Notification Obligation May 19, 2026
HUF 15M NAIH-450-7-2026 The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Fairness & Transparency Personal Data Transparency May 12, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·DPC ·Art. 5, 32, 33 Integrity and Confidentiality Principle Notification Obligation Data Breaches May 8, 2026
€150,000 The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested a duplicate SIM card for the mobile line of a data subject. The request was… EXP202306354 (PS/00312/2024) ·Spain ·Art. 5, 6 Integrity and Confidentiality Principle Personal Data Controllers Feb 11, 2026
€25,500 DSB · 2025-1.049.138 The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted… Austria ·Art. 5, 6, 12 +1 Legitimate Interest Personal Data Retention Period Jan 19, 2026
€4,000 AEPD: Continuous workplace audio recording violates GDPR data minimisation principle On 22 April 2025, a data subject lodged a complaint with the DPA against BODENSE ESTRUCTURAS Y CALDELERÍA, S.L., the controller. The data subject claimed that the controller had… Spain ·Art. 5 Retention Period Monitoring IP Address Apr 22, 2025
€850,000 Network of Agencies and Companies: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 850,000 on a network of agencies and companies. The network operated on behalf of Acea Energia S.p.A. and engaged in aggresive customer… ITALY ·Garante ·Art. 5, 6, 7 +6 Supervisory Authorities Processing Agreement Processing Apr 10, 2025
€850,000 Network of agencies and companies: Non-compliance with general data processing principles. ⇄ 850.000 euro boete - Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +6 Processing Supervisory Authorities Marketing Apr 10, 2025
€18,000 Multiple Companies: Insufficient legal basis for data processing The Italian DPA imposed fines on 3 companies which ammount to EUR 6,000 each. The fined companies (Powerfit s.s.d.a.r.l., Soleo s.s.d.a.r.l. and Zero Due Villa s.s.d.a.r.l.) run a… ITALY ·Garante ·Art. 5, 6, 12 +1 Right to be Forgotten Marketing Consent Mar 27, 2025
€4,000 Hospital: Non-compliance with general data processing principles The Croation DPA (AZOP) has imposed a fine of EUR 4,000 on a hospital. The AZOP found that the hospital used a company which automatically retrieved personal data of vehicle… CROATIA ·AZOP ·Art. 13, 14, 25 +1 Privacy by Design & Default Personal Data Supervisory Authorities Mar 24, 2025
€4,000 Hospital: Non-compliance with general principles of data processing. ⇄ 4.000 euro boete - Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·AZOP ·Art. 13, 14, 25 +1 Personal Data Processing Processors Mar 24, 2025
APD/GBA · 131/2024 On 10 February 2023 the data subject, a trainee working at noyb – European Center for Digital Rights, visited the website of the controller, a Belgian media company. The data… 131/2024 ·Belgium ·Art. 4, 5, 6 Personal Data Supervisory Authorities Controllers Oct 11, 2024
€35,700 Company: €35,700 fine The Croatian DPA (AZOP) has imposed fines totaling EUR 35,700 on nine companies for failing to adequately indicate their video surveillance areas and for failing to provide all… CROATIA ·AZOP ·Unknown Fines Video Surveillance Monitoring Sep 13, 2024
CROATIA DPA: Insufficient fulfilment of information obligations The Croatian DPA (AZOP) has imposed seven fines totaling EUR 16,000 on data controllers for failing to adequately mark video-monitored areas. This lack of marking resulted in… AZOP ·Art. 13, 27 ·Insufficient fulfilment of information obligations Supervisory Authorities Controllers Processing Apr 22, 2024
€273,000 Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed two fines on the medical facility “Centrum Medyczne Ujastek” totaling approximately EUR 273,000. The first fine of approximately EUR 163,000 was imposed… POLAND ·UODO ·Art. 5, 6, 9 +3 Encryption Healthcare Controllers Jan 17, 2024
€41 GERMANY DPA: €41 fine The DPA of Hessen has imposed fines totaling EUR 13,486 on 41 data controllers. In its 2024 activity report, the DPA of Hesse reported a total of 47 fines that year. Six of these… Unknown Supervisory Authorities Fines Supervision Jan 1, 2024
Private individual: Insufficient legal basis for data processing The DPA of Hamburg has imposed five fines of private individuals for taking or storing photos of individuals without their consent. GERMANY ·HmbBfDI ·Insufficient legal basis for data processing Consent Fines Processing Jan 1, 2024
Police employees: Insufficient legal basis for data processing The DPA of Hamburg has imposed two fines on members of the police for accessing police databases for private research purposes. GERMANY ·HmbBfDI ·Insufficient legal basis for data processing Scientific Research Fines Processing Jan 1, 2024
€ 2,000M Decision 14-09-2023 The two companies in question, as controllers, made use of cookies on their websites, but failed to inform data subjects visiting their web pages about the legal basis for… Croatia ·AZOP ·Art. 6, 7, 13 Personal Data Consent Fines Sep 1, 2023
Multiple website operators: Czech Data Protection Auhtority (UOOU) In the period from January 2023 to July 2023, the Czech DPA imposed fines totaling EUR 178,000, with the highest fine being EUR 36,000. These fines were imposed due to unlawful… CZECH REPUBLIC ·ÚOOÚ (CZ) ·Unknown Integrity and Confidentiality Principle Cookies Fines Aug 2, 2023
Police officers: Insufficient legal basis for data processing The DPA of Bremen has imposed ten fines between EUR 100 and EUR 1,000 on police officers for unlawfully accessing police databases. GERMANY ·Insufficient legal basis for data processing Fines Supervisory Authorities Processing Jan 1, 2023
Real estate agency: Insufficient legal basis for data processing The DPA of Bremen has imposed five fines on a real estate agency. The controller had repeatedly sent advertising messages to a former prospect and tried to contact them by… GERMANY ·Insufficient legal basis for data processing Personal Data Direct Marketing Controllers Jan 1, 2023
Website operator: Insufficient legal basis for data processing The DPA of Bremen has imposed five fines on website operators for using the tracking tool 'Google Analytics' without the prior consent of website users. GERMANY ·Art. 6 ·Insufficient legal basis for data processing Consent Cookies Fines Jan 1, 2023