Skip to content
Content type · 1,924 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 1,924 sort newestlargest fineoldest
€200,000 AEPD (Spain) - ps-00148-2025 XFERA MÓVILES, S.A.U. (XFERA), the controller, is a telecommunications provider. The data subject was a customer of the controller and held a mobile telephone line. On 24 July… Art. 6 Personal Data Controllers Legitimate Interest Aug 13, 2026
€10,000 AEPD (Spain) - PS/00249/2025 MÁS SOL ENERGÍA 15, S.L., the controller, is a company that carries out customer acquisition through telephone calls to offer solar panel installation services. On 18 November… Art. 4, 5, 7 +1 Cookies IP Address Direct Marketing Aug 12, 2026
€1,282 Slovenian DPA fines controller €1,282 for missing Art. 28(3) processor contract A company (the controller) used a service provider (the processor) to store personal data, manage a database, and provide technical support and maintenance on its behalf. A legal… Slovenia ·IP ·Art. 28 Controllers Processors Processing Agreement Aug 11, 2026
RON 108,570 ANSPDCP (Romania) - Fine against Homelux SRL HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR. The controller was operating a website on a platform… Art. 32 Data Breaches Notification Obligation Security Aug 11, 2026
HRK 940,000 AZOP (Croatia) - Decision 08-03-2022 (energy company) The controller is a company that manages gas stations. The data subject tried to refuel at one of the controller's gas stations and was dissatisfied with the measurement of the… Art. 15 Video Surveillance Right of Access Fines Aug 3, 2026
RON 523,900 ANSPDCP (Romania) - Fine against Orange Romania SA of July 17, 2026 The investigation was initiated after Orange Romania SA (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR, related to its… Art. 25, 32 Security Data Breaches Notification Obligation Jul 29, 2026
€20,000 AEPD fines El Español for disclosing minor's identity in assault video El León de El Español Publicaciones, S.A., the controller, operates the Spanish digital newspaper „El Español“. It published an article concerning an assault and embedded a video… Spain ·Art. 5, 25, 58 Privacy by Default Retention Period Privacy by Design Jul 27, 2026
€5,000 AEPD (Spain) - PS/00421/2020 The client of a financial institution lodged a complaint before the Spanish DPA (AEPD) due to the delivery of a mail for commercial purposes, even though he had expressly rejected… Art. 21 Recipient Right to Object Personal Data Jul 24, 2026
RON 30 ANSPDCP (Romania) - Fine against There's an AI for that S.R.L In October 2025, the Romanian National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal –… Art. 4 Cookies Telecommunications Direct Marketing Jul 24, 2026
€2,000 HDPA (Greece) 33/2020 — Employee's access and erasure claims against the American College The data subject was under the employment of the College for a certain period of time, during which two female students of the College filed a complaint against the complainant… Art. 4, 5, 12 +8 Personal Data Right to be Forgotten Right of Access Procedures Jul 24, 2026
HUF 2M NAIH fines online store HUF 2M for unclear and incomplete privacy notice The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The… Hungary ·Art. 12, 13 Legitimate Interest Processing Cookies Jul 22, 2026
Tietosuojavaltuutetun toimisto (Finland) - TSV/4630/2023 A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022.… TSV/4630/2023 ·Art. 5, 12, 25 Personal Data Controllers Right of Access Jul 22, 2026
€90,000 AEPD sanctions ACVIL Aparcamientos for denying access to parking surveillance footage On 13 December 2024, the DPA received a complaint against ACVIL Aparcamientos, S.L.U., the controller, concerning a request for video surveillance footage from a car park. The… Spain ·Art. 14, 15 Right of Access Procedures Retention Period Right to Restriction Jul 21, 2026
€12,000 Italian DPA: Justice Ministry unlawful disclosure of employee health data in service order The data subject was an employee at a detention facility run by the Italian Ministry of Justice (the controller). Following an assessment by the occupational health physician, who… Italy ·Garante per la protezione dei dati personali ·Art. 4, 5, 6 +2 Personal Data Healthcare Health Data Jul 20, 2026
€20,000 Italian DPA: Enna Health Authority violated GDPR by publishing judicial data The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 10 +1 Personal Data Fairness & Transparency Right to Restriction Jul 18, 2026
€1M CNIL fines energy supplier for mishandling data subject access and objection requests The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French… France ·Art. 12, 14, 15 +2 Right of Access Personal Data Right to Object Jul 17, 2026
AEPD: No fine for surveillance cameras facing public road; no evidence of rights A complaint is filed against the controller for having six surveillance cameras facing public highway and private spaces without authorisation. In addition to the claim, there is… PS-00601-2021 ·Spain ·Art. 5, 12, 15 +3 Video Surveillance Retention Period Monitoring Jul 17, 2026
APDCAT sanctions Madremanya City Council for exposing applicants' sensitive data in tender On 8 May 2025, Madremanya City Council, acting as controller, published on its notice board two administrative acts concerning a tender procedure for the award of a social housing… PS-0036/2026 ·Spain ·Catalonia Anonymization Professional Secrecy Anonymization Jul 17, 2026
€50,000 Italian Garante sanctions Calabrian agency for location tracking of remote workers The Calabrian Regional Agency for Agricultural Development (the controller) implemented a remote work policy that required employees to use a time-tracking application called… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 13 +3 Monitoring DPIA Privacy Impact Assessment Jul 16, 2026
€16,000 Italian Garante: OPI of Pisa must remove residential addresses from public register The data subject, a professional registered with the OPI of Pisa, discovered while consulting the Public Register of Professionals online that the database included the… Italy ·Garante per la protezione dei dati personali ·Art. 1, 5, 6 +3 Personal Data Controllers Fairness & Transparency Jul 16, 2026
€200,000 AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack… Spain ·Art. 5, 35, 58 Privacy Impact Assessment DPIA Security Jul 16, 2026
AEPD investigates University of Navarra over student COVID-19 vaccination status requests A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3 Consent Healthcare Health Data Jul 16, 2026
€2M Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 6 +2 Personal Data Processing Controllers Jul 14, 2026
€140 AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data… Spain ·Art. 5, 6, 83 Telecommunications Accountability Personal Data Jul 13, 2026
€57,839 ANSPDCP (Romania) - Fine against Ascendex Technology SRL The Romanian DPA (ANSPDCP) launched an investigation into the cryptocurrency exchange platform Ascendex Technology SRL (the controller). The DPA was notified by the French DPA… Art. 4, 12, 17 +1 Supervisory Authorities Controllers Supervision Jul 9, 2026
€1,198 Slovenian DPA fines controller €1,198 for Art. 32 GDPR breach via pirated software A company (the controller) operates an online store. An employee of the controller used a pirated and unlicensed software when creating the website. This software contained… Slovenia ·IP ·Art. 32 Integrity and Confidentiality Principle Data Breaches Security Jul 8, 2026
€5.8M Italian Garante sanctions Hera Comm for automated credit-check refusals of contracts Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas… Italy ·Garante per la protezione dei dati personali ·Art. 5, 12, 13 +3 Controllers Processors Fairness & Transparency Jul 3, 2026
IMY reprimands Swedish Police for inadequate GDPR Article 13 info at Arlanda border The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of… IMY-2024-2904 ·Sweden ·Art. 13 Personal Data Controllers Information Provision Modalities and Communication Methods Jul 3, 2026
RON 26,172 ANSPDCP fines Banca Transilvania RON 26,172 for inadequate security over unauthorized The Romanian DPA (ANSPDCP) launched an investigation into a bank, Banca Transilvania S.A. (the controller), following a data subject’s complaint. The data subject claimed that… Romania ·Art. 32 Data Breaches Integrity and Confidentiality Principle Personal Data Jul 3, 2026
€158,000 Italian DPA finds GDPR applies to US-based Character.AI service Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 12 +7 Controllers Representatives AI Information Duties Jul 3, 2026
€1.4M Italian Garante sanctions EstEnergy for automated creditworthiness scoring in energy EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller… Italy ·Garante per la protezione dei dati personali ·Art. 5, 13, 14 +2 Controllers Retention Period Right of Access Procedures Jul 3, 2026
Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… 2025010358 ·Iceland ·Island Monitoring Cloud Computing Supervisory Authorities Jul 1, 2026
€450,000 VDAI (Lithuania) - 3R-1143 Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Art. 5, 24 Security Data Breaches Access Controls Jun 19, 2026
€5,000 Italian DPA: Vasto municipality breached transparency duties over traffic cameras The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 12 +2 DPIA Privacy Impact Assessment Personal Data Jun 18, 2026
€460,000 Garante: Piaggio violated GDPR by accessing former employees' emails in disciplinary probe Two former employees (the data subjects) of Piaggio (the controller) were dismissed for just cause in March 2023. Following the termination of their employment, they asked the… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 12 +2 Fairness & Transparency Retention Period Legitimate Interest Jun 18, 2026
€6,600 Italian Garante: Employer's recording of locker opening and destruction of contents The case involves a worker (the data subject), his former employer (the controller), and the staffing agency that had provided the company with the worker. In late 2023 the data… Italy ·Garante per la protezione dei dati personali ·Art. 2, 4, 5 +2 Personal Data Legitimate Interest Material scope (GDPR) Jun 18, 2026
€2,760 UODO (Poland) - DKN.5131.34.2023 An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained… Art. 5, 24, 25 +1 Data Breaches Right of Access Notification Obligation Jun 13, 2026
UODO (Poland) - DKN.5131.12.2022 The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Art. 5, 24, 25 +3 DPIA Security Data Breaches Jun 11, 2026
€880,000 HDPA fines DEI for unlawful telemarketing calls to opt-out registered subscribers The Greek DPA (HDPA) received twelve complaints filed against DEI, the Greek Public Power Corporation, (the controller) from telephone subscribers (data subjects) regarding the… Greece ·Art. 5, 28, 29 +1 Controllers Personal Data Direct Marketing Jun 2, 2026
€700 Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy ·Garante per la protezione dei dati personali ·Art. 5, 9 Personal Data Healthcare Health Data May 28, 2026
€6,000 Italian DPA: vehicle tracking by Liguria Health Agency lawful, information duties met A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller). The data subject was employed by the Ligurian Social and Health Care… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 13 +3 DPIA Privacy by Design Monitoring May 28, 2026
EDPB - Binding Decision 1/2026 On 10 August 2021, a data subject represented by noyb lodged a complaint with the Austrian DPA against Vlaamse Radio- en Televisieomroeporganisatie (VRT), the controller. The… Binding Decision 1/2026 ·European Union ·Art. 4, 57, 60 +3 Supervisory Authorities Cookies Telecommunications May 28, 2026
€55,000 Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful The data controller for the case is a government body called the Agency for Digital Italy (AgID). AgID is tasked with driving the adoption of digital technologies in both… Italy ·Garante per la protezione dei dati personali ·Art. 5, 12, 14 +1 Controllers Personal Data Processing May 28, 2026
PLN 21,000 UODO (Poland) - DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Art. 24, 25, 28 +1 Security Controllers Processors May 25, 2026
PLN 26,711 UODO (Poland) - DKE.561.4.2026 The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance extending… Art. 5 Monitoring Fairness & Transparency Video Surveillance May 22, 2026
GBP 300 ICO (UK) - KRA Consultancy Ltd The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related services.… United Kingdom Recipient Direct Marketing Telecommunications May 20, 2026
PLN 33,700 UODO (Poland) - DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Art. 5, 24, 25 +3 Controllers Personal Data Supervisory Authorities May 19, 2026
HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Art. 23 Personal Data Processing Criminal Data May 13, 2026
HUF 15M NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Personal Data Transparency Controllers May 12, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Fines Security Data Breaches May 8, 2026