Content type · 402 documents in this view · 3,813 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3589 Processing 2636 Personal Data 2395 Controllers 2018 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
€750,000 AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight Vodafone España, S.A.U., the controller, operated a service known as "Super WiFi" through a third-party processor. Following a data breach affecting the service, the DPA's… Spain ·Art. 5, 28, 32 Sep 23, 2026
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Sep 22, 2026
€6,000 Italian DPA: Municipality of Rieti breached GDPR by publishing 31,000 taxpayers' waste The Municipality of Rieti (the controller) published its administrative acts on its official notice board and in the "Transparent Administration" section of its website. A… Italy · ·Art. 5, 12, 24 +3
RON 108,570 Fine against Homelux SRL HOMELUX S.R.L. (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR. The controller was operating a website on a platform… Romania · ·Art. 32 Sep 16, 2026
AEPD: Data subject entitled to identity of professionals who accessed medical records Suspecting unauthorised access to his medical records, a public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide a log copy of… pd-00055-2026 ·Spain ·Art. 5, 12, 15 +2 Sep 15, 2026
€408,000 AEPD: CaixaBank requested excessive inheritance documentation from heirs A data subject and other heirs were handling the inheritance of a deceased customer through CaixaBank, S.A., the controller. In the course of the inheritance procedure, the… Spain ·Art. 13, 25, 30 Sep 10, 2026
RON 26,237 Fine against GEROCOSSEN S.R.L. Gerocossen SRL (the controller) suffered a cyberattack that affected its IT infrastructure. As a result, unauthorised parties gained access to personal data relating to some data… Romania · ·Art. 32 Sep 8, 2026
€2,000 AEPD · ps-00256-2025 After receiving an in-person visit at her address, a data subject received a letter from a third party concerning a plot of land. The third party asked the data subject to… Spain ·Art. 6 Sep 8, 2026
Garante warns ReLife Recycling for failing to timely respond to GDPR access request The data subject sent a complaint to the DPA regarding correspondence between him and the company ReLife Recycling s.r.l. (the controller), which was sent without his consent to… 515/2026 ·Italy ·Art. 12
€24,000 Friuli Centrale University Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) found that the Friuli Centrale University Health Authority (ASUFC) violated Articles 5(1)(f), 9, 25, and 32 of the GDPR based on a… Italy · ·Art. 5, 9, 25 +1 Sep 3, 2026
AEPD: Canals City Council breached Art. 5(1)(f) GDPR by discarding exam papers unshredded The DPA became aware that examination papers from an employment-training programme managed by Canals City Council, the controller, had been found next to waste containers in a… PS-00506-2026 ·Spain ·Art. 5 Sep 2, 2026
RON 15,728 Fine against Poliserv JG (PJG) SRL A personal data breach occurred because of a cyberattack made possible through a phishing method that stole the credentials of a controller account with administrator privileges.… Romania · ·Art. 32
HDPA: Hellenic Open University found to have met breach notification duties after The Hellenic Open University (‘the controller’) submitted initial and supplementary notifications to the DPA after it was subject to a data breach resulting from a ransomware… 14/2026 ·Greece ·Art. 32, 33, 34 +1 Aug 19, 2026
Datatilsynet (DK) · 2023-31-0321 A customer of a bank ('the data subject'), suspected that their former spouse, who was employed by the same bank ('the controller'), was accessing their accounts and decided to… 2023-31-0321 ·Denmark ·Art. 12, 15 Aug 18, 2026
RON 285,395 AMATO BESTSELLER S.R.L. A general wholesale/retail trade company (controller) failed to implement adequate technical and organisational measures, such as appropriate training of its employees, in order… Romania · ·Art. 5, 9, 12 +2 Aug 18, 2026
€1,000 Austrian DSB: Employee who shared customer's phone number acted as GDPR controller An employee (controller) of a company shared the telephone number of a costumer (data subject) with a third person. The third person who was a personal acquaintance of the… Austria ·Art. 4, 5, 6 +1 Aug 18, 2026
ICO (UK) - ACRO Criminal Records Office ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates,… ACRO Criminal Records Office ·United Kingdom ·Art. 32 Aug 7, 2026
RON 523,900 Fine against Orange Romania SA of July 17, 2026 The investigation was initiated after Orange Romania SA (the controller) notified the Romanian DPA (ANSPDCP) of a personal data breach pursuant to Article 33 GDPR, related to its… ·Art. 25, 32 Jul 29, 2026
€200,000M 15/2026 The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information… Greece · ·Art. 5, 28, 32 Jul 28, 2026
Finnish DPA: requesting address, ID number and strong authentication for access request A company that provides comparison services for loans and financial products (the controller) received a loan application submitted on the data subject’s behalf in October 2022.… TSV/4630/2023 ·Finland · Jul 22, 2026
HUF 2M NAIH-11443-3/2026 The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The… Hungary ·Art. 12, 13 Jul 22, 2026
€500,000 Hôpital privé de la Loire: Insufficient technical and organisational measures to ensure information security The French Data Protection Authority (CNIL) sanctioned Hôpital Privé de la Loire, a Ramsay Santé group hospital, following a June 2025 personal data breach in which an attacker… France · ·Art. 32, 34 Jul 21, 2026
€200,000 Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first… PS-00020-2025 ·Spain · Jul 16, 2026
€1,198 A company (the controller) operates an online store An employee of the controller used a pirated and unlicensed software when creating the website. This software contained malicious code, which allowed a third person to access the… 0609-36/2026/7 ·Slovenia · Jul 8, 2026
RON 26,172 The Romanian DPA (ANSPDCP) launched an investigation into a bank, Banca Transilvania S.A (the controller), following a data subject’s complaint. The data subject claimed that their personal data associated with their bank account had been processed without their… 02/07/2026 ·Romania ·Art. 32
Persónuvernd (Island) - 2025010358 The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… 2025010358 ·Iceland ·Art. 5, 32 Jul 1, 2026
€450,000 VDAI fines medical company €450,000 for inadequate security measures in data breaches Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Lithuania ·Art. 5, 24 Jun 19, 2026
€10,000 Altex Romania S.R.L: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Altex Romania S.R.L. €10,000 for failing to implement sufficient technical and… ·Art. 32, 33, 34 ·Insufficient technical and organisational measures to ensure information security Jun 18, 2026
€2,075 Edizioni Grandangolo di Giuseppe Castaldo: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Edizioni Grandangolo di Giuseppe Castaldo €2,075 for failing to comply with general data processing principles under Articles… Italy · ·Art. 5, 12, 13 +4 Jun 18, 2026
€2,760 UODO fines accounting firm €2,760 for email breach security failures An unauthorised entity gained access to an email account belonging to an employee at an accounting, bookkeeping and tax consulting company (the controller). The account contained… Poland ·Art. 5, 24, 25 +1 Jun 13, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland · ·Art. 5, 28, 30 +2 Jun 11, 2026
UODO reprimands hospital for inadequate processor oversight and email security failures The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Poland ·Art. 5, 24, 25 +3 Jun 11, 2026
UODO fines controller for refusing to cooperate and provide information in two data The DPA received two complaints against the same company (the controller) due to the unauthorised access to the data subjects’ personal data. The first complaint concerned… DKE.561.1.2026 ·Poland ·Art. 31, 58 Jun 1, 2026
PLN 21,000 DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Poland · ·Art. 24, 25, 28 +1 May 25, 2026
PLN 33,700 DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Poland · ·Art. 5, 24, 25 +3 May 19, 2026
HDPA · 12/2026 The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Greece ·Art. 23 May 13, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland · ·Art. 5, 32, 33 May 8, 2026
€277,500 Permanent TSB plc: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Permanent TSB plc €277,500 for failing to implement sufficient technical and organisational measures to ensure information security,… Ireland · ·Art. 5, 32, 33 Apr 30, 2026
€1,790 Mayor of the City and Municipality of Myślenice: Insufficient fulfilment of data breach notification obligations The Polish DPA (UODO) fined the Mayor of the City and Municipality of Myślenice €1,790 for insufficient fulfilment of personal data breach notification obligations under Article… Poland · ·Art. 33 Apr 30, 2026
€2,415 UODO reprimands electricity seller for Art. 5, 24, 25, 28, 32 GDPR violations over An electricity sales company (the controller) had outsourced some of its operations to two processors and one sub-processor. Employees of the sub-processor had used a smartphone… Poland ·Art. 5, 24, 25 +2 Apr 13, 2026
€2,350 Housing Associaction: Insufficient fulfilment of data breach notification obligations Polish National Personal Data Protection Office (UODO) fined Housing Associaction €2,350 on 2026-04-07 for: Insufficient fulfilment of data breach notification obligations. Poland · ·Art. 33 Apr 7, 2026
Slovenian DPA: Controller breached Art. 32, 15 and 34 GDPR over data breach and access A controller, not named in the original decision but presumed to be a public institution, notified the Slovenian DPA after experiencing a data breach in relation to its website.… 0612-91/2025/40 ·Slovenia · Mar 4, 2026
€1.7M CNIL fines data processor €1.7M for misconfigured disability-records software causing The data protection authority (DPA) has imposed a fine of €1,700,000 on a data processor that had incorrectly configured a software program. This program processed files related… France Jan 12, 2026
€2,000 Money Seeds S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. ⇄ The Romanian supervisory authority ANSPDCP has imposed a fine of 2,000 euros on Money Seeds S.R.L., a financial and consultancy company, for failing to honor a data subject's… ROMANIA · ·Art. 12, 13, 14 Jan 8, 2026
€27M FREE MOBILE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 27,000,000 on FREE MOBILE. The controller suffered a data breach due to insufficient technical and organisational measures. This was… FRANCE · ·Art. 5, 32 Jan 8, 2026
€15M UNACCEPTABLE: Insufficient technical and organizational measures to ensure information security. ⇄ The French data protection authority (CNIL) has imposed a fine of €15,000,000 on FREE. The company suffered a data breach as a result of insufficient technical and organizational… FRANCE · ·Art. 32, 34 Jan 8, 2026
€27M FREE MOBILE: Insufficient technical and organizational measures to ensure information security. ⇄ 27 miljoen euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE · ·Art. 5, 32 Jan 8, 2026
€15M FREE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 15,000,000 on FREE. The controller suffered a data breach due to insufficient technical and organisational measures. This was caused by… FRANCE · ·Art. 32, 34 Jan 8, 2026
€175,000 Arnhem and Nijmegen University of Applied Sciences: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 175,000 on Arnhem and Nijmegen University of Applied Sciences. The controller suffered a data breach due to insufficient technical and… THE NETHERLANDS · ·Art. 32 Dec 15, 2025
€175,000 HAN University of Applied Sciences: Insufficient technical and organizational measures to ensure information security. ⇄ 175.000 euro boete - Nederlandse Autoriteit Persoonsgegevens (AP). THE NETHERLANDS · ·Art. 32 Dec 15, 2025