Skip to content
Content type · 289 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 289 sort newestlargest fineoldest
€10,000 AEPD fines MÁS SOL ENERGÍA for marketing call to Robinson List subscriber MÁS SOL ENERGÍA 15, S.L., the controller, is a company that carries out customer acquisition through telephone calls to offer solar panel installation services. On 18 November… Spain ·Art. 4, 5, 7 +1 Personal Data IP Address Consent Sep 16, 2026
RON 10,517 Fine against Dormeo Home S.R.L Dormeo Home S.R.L. (the controller), received a request from one of its customers (the data subject) exercising their right to object to direct marketing. Despite this objection,… Romania ·ANSPDCP ·Art. 21 Right to Object Direct Marketing Personal Data
€5.5M Banco Bilbao Vizcaya Argentaria S.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) found Banco Bilbao Vizcaya Argentaria, S.A. (Italian branch) violated Articles 5(1)(a), 12, 21, and 24 of the GDPR by continuing to… Italy ·Garante ·Art. 5, 12, 21 +1 Right to Object Personal Data Direct Marketing Sep 3, 2026
€280,000 Garante · 10269624 The controller is a publishing company that sells subscriptions to consumer information services through its website. Users can sign up by filling in a registration form on the… Italy ·Art. 6, 7, 12 +2 Right to Object Personal Data Direct Marketing
RON 285,395 AMATO BESTSELLER S.R.L. A general wholesale/retail trade company (controller) failed to implement adequate technical and organisational measures, such as appropriate training of its employees, in order… Romania ·ANSPDCP ·Art. 5, 9, 12 +2 Integrity and Confidentiality Principle Personal Data Retention Period Aug 18, 2026
RON 30 Fine against There's an AI for that S.R.L In October 2025, the Romanian National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal –… Romania ·ANSPDCP ·Art. 4 Personal Data Consent Controllers
€2M Garante fines Lusha Systems Inc. over unauthorized B2B contact database Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was a… Italy ·Art. 3, 5, 6 +2 Personal Data IP Address Legitimate Interest Jul 14, 2026
Binding Decision 1/2026 On 10 August 2021, a data subject represented by noyb lodged a complaint with the Austrian DPA against Vlaamse Radio- en Televisieomroeporganisatie (VRT), the controller. The… Binding Decision 1/2026 ·European Union ·EDPB Supervision Supervisory Authorities Controllers May 28, 2026
GBP 300 ICO (UK) - KRA Consultancy Ltd The Information Commissioner, the DPA, investigated KRA Consultancy Ltd, the controller, in relation to unsolicited direct marketing SMS messages promoting debt-related services.… United Kingdom Personal Data Consent Processing May 20, 2026
€1,500 Francesco Gagliardi: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) found Francesco Gagliardi, operating as a sole proprietorship, in violation of Articles 5(1)(a) and 14 of the GDPR and Article 130… Italy ·Garante ·Art. 5, 14 Legitimate Interest Personal Data Lawful Basis May 14, 2026
HUF 15M NAIH-450-7-2026 The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Fairness & Transparency Transparency Personal Data May 12, 2026
€6,300 Advertising Agency: Insufficient legal basis for data processing Austrian Data Protection Authority (dsb) fined Advertising Agency €6,300 on 2026-03-24 for: Insufficient legal basis for data processing. Austria ·DSB ·Art. 5, 6, 13 Supervisory Authorities Processing Direct Marketing Mar 24, 2026
GBP 120,000 ICO (UK) - Allay Claims Ltd Allay Claims Ltd (the controller) sent over 4 million direct marketing text messages to individuals promoting a different entity’s services. The DPA received over 48,000… United Kingdom Direct Marketing Telecommunications Consent Jan 15, 2026
€5,000 REVMA PLUS Retail S.A.: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 5,000 on REVMA PLUS Retail S.A.. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… GREECE ·HDPA ·Art. 32 Controllers Processors Personal Data Dec 31, 2025
€10,000 Thessaloniki–Thessaly Gas Supply Company S.A.: Insufficient data processing agreement The Greek DPA has imposed a fine of EUR 10,000 on Thessaloniki–Thessaly Gas Supply Company S.A. The controller, an energy provider, used external processors for direct marketing… GREECE ·HDPA ·Art. 28, 32 Controllers Processors Supervisory Authorities Dec 31, 2025
€10,000 SIGMA & KAPPA IMPORTING SOCIÉTÉ ANONYME: Insufficient technical and organisational measures to ensure information security The Greek DPA has imposed a fine of EUR 10,000 on SIGMA & KAPPA IMPORTING SOCIÉTÉ ANONYME. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A.… GREECE ·HDPA ·Art. 32 Processors Controllers Security Dec 31, 2025
€80,000 ONE WAY PRIVATE COMPANY: Non-compliance with general data processing principles The Greek DPA has imposed a fine of EUR 80,000 on ONE WAY PRIVATE COMPANY. The fined entity is the processor of Thessaloniki–Thessaly Gas Supply Company S.A. (ETid-3016). The… GREECE ·HDPA ·Art. 5, 6, 7 +2 Processors Controllers Personal Data Dec 31, 2025
€3.5M Company: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 3,500,000 on a company. The controller operated a loyalty program in France and 16 other EU countries, using customer data obtained… FRANCE ·CNIL ·Art. 6, 13, 32 +1 Controllers DPIA International Transfer Dec 30, 2025
€6,000 Geturhotels Srl: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 6,000 on Geturhotels Srl. The controller was involved in direct marketing operations, using personal data that had not been acquired or… ITALY ·Garante ·Art. 5, 6, 17 +1 Controllers Personal Data Processing Dec 23, 2025
€6,000 Geturhotels Srl: Violation of the general principles of data processing. ⇄ Een boete van 6.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 17 +1 Controllers Processing Personal Data Dec 23, 2025
€400,000 Verisure Italy s.r.l.: Non-compliance with general principles for data processing. ⇄ Een boete van 400.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). Garante ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles Archiving Retention Period Controllers Nov 27, 2025
€400,000 Verisure Italy s.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 400,000 on Verisure Italy s.r.l. The controller had been active in direkt marketing activities. The controller failed to ensure that the… Garante ·Art. 5, 7, 12 +3 ·Non-compliance with general data processing principles Retention Period Controllers Direct Marketing Nov 27, 2025
€40,000 Infobel: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 40,000 on Infobel. The controller, a data broker, sold personal data for direct marketing purposes. However, it processed the data it had… BELGIUM ·APD/GBA ·Art. 5, 6, 24 Controllers Personal Data Processing Nov 27, 2025
€300,000 Aimag S.p.A.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 300,000 on Aimag S.p.A. The controller offered its customers a service that allowed them to view their consumption data on the… ITALY ·Garante ·Art. 5, 6, 7 +4 Controllers Consent Supervisory Authorities Nov 27, 2025
€40,000 Infobel: Insufficient Legal Basis for Data Processing. ⇄ Een boete van 40.000 euro - De Belgische Autoriteit voor gegevensbescherming (APD). BELGIUM ·APD/GBA ·Art. 5, 6, 24 Controllers Processing Accountability Nov 27, 2025
€3,000 Cucina di Fabio S.R.L.: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 3,000 on Cucina di Fabio S.R.L. The controller was active in direct marketing activities, using personal data that had not been obtained… ROMANIA ·ANSPDCP ·Art. 6, 15, 17 +1 Controllers Personal Data Marketing Nov 26, 2025
€3,000 Cucina di Fabio S.R.L.: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 3.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 15, 17 +1 Personal Data Processing Supervisory Authorities Nov 26, 2025
€4.5M Telecommunications Company (Operator of Electronic Communications Networks and Services): Violation of the General Principles of Data Processing. ⇄ Een boete van 4.500.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·AZOP ·Art. 5, 6, 12 +4 Controllers Processors Processing Nov 24, 2025
€72,000 AEPD · PS-00480-2025 Tiger Media Inc., the controller, operated an advertising platform for publishers and advertisers of adult products and services. The platform acted as an ad network, connecting… Spain ·Art. 6, 27 Legitimate Interest Controllers Processors Nov 14, 2025
€2,000 Whitedecor SRL: Insufficient legal basis for data processing The Romanian DPA has imposed a fine of EUR 2,000 on Whitedecor SRL. The controller had sent marketing messages to customers without a sufficient legal basis. ROMANIA ·ANSPDCP ·Art. 6, 7, 12 +3 Direct Marketing Controllers Personal Data Nov 10, 2025
€2,000 Whitedecor SRL: Insufficient legal basis for the processing of personal data. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 6, 7, 12 +3 Personal Data Processing Supervisory Authorities Nov 10, 2025
€5,000 FT Solutions S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 5,000 on FT Solutions S.r.l. The fined entity had been active in direct marketing activities as a data processor. During these… ITALY ·Garante ·Art. 5, 6, 7 +7 Integrity and Confidentiality Principle Processors Controllers Oct 9, 2025
€5,000 FT Solutions S.r.l.: Non-compliance with general principles of data processing. ⇄ Een boete van 5.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +7 Processors Processing Controllers Oct 9, 2025
€195,000 Company: Insufficient compliance with data subjects' rights (regarding their personal data). ⇄ 195.000 euro boete - Autoriteit voor gegevensbescherming van Hamburg (HmbBfDI). GERMANY ·HmbBfDI ·Insufficient fulfilment of data subjects rights Personal Data Direct Marketing Marketing Sep 30, 2025
€195,000 Company: Insufficient fulfilment of data subjects rights The DPA of Hamburg has imposed a fine of EUR 195,000 on a company. The controller was active in direct marketing via post and failed to adequately respond to requests from data… GERMANY ·HmbBfDI ·Insufficient fulfilment of data subjects rights Direct Marketing Personal Data Controllers Sep 30, 2025
€35,000 E-Power S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 35,000 on E-Power S.r.l. The controller engaged in direct marketing activities in a way that violated general data processing principles. ITALY ·Garante ·Art. 5, 6, 7 +5 Direct Marketing Controllers Marketing Sep 25, 2025
€35,000 E-Power S.r.l.: Violation of the general principles of data processing. ⇄ Een boete van 35.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +5 Direct Marketing Processing Marketing Sep 25, 2025
€10,000 La Prima Srl: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 10,000 on La Prima Srl. The controller sent direct marketing messages without a legal basis. They also failed to respond to a data… ITALY ·Garante ·Art. 6, 12, 17 +1 Personal Data Controllers Supervisory Authorities Sep 25, 2025
€10,000 La Prima Srl: Insufficient legal basis for the processing of personal data. ⇄ Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 6, 12, 17 +1 Personal Data Processing Controllers Sep 25, 2025
€125M GOOGLE IRELAND LIMITED: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 125,000,000 on GOOGLE IRELAND LIMITED. While creating an account for the controller's services, the controller designed the cookie consent… FRANCE ·CNIL ·Art. 82 Controllers Personal Data Cookies Sep 1, 2025
€200M GOOGLE LLC: Insufficient legal basis for the processing of data. ⇄ 200 miljoen euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 82 Controllers Personal Data Processing Sep 1, 2025
€200M GOOGLE LLC: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 200,000,000 on GOOGLE LLC. While creating an account for the controller's services, the controller designed the cookie consent process in… FRANCE ·CNIL ·Art. 82 Controllers Personal Data Cookies Sep 1, 2025
€125M GOOGLE IRELAND LIMITED: Insufficient legal basis for the processing of data. ⇄ 125.000.000 euro boete - Franse Autoriteit voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 82 Controllers Personal Data Processing Sep 1, 2025
€2,000 GESTIÓN DE VENTAS IBERIA S.L.: Insufficient compliance with data subjects' rights. ⇄ Een boete van 2.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 14 Personal Data Marketing Controllers Aug 31, 2025
€2,000 GESTIÓN DE VENTAS IBERIA S.L.: Insufficient fulfilment of data subjects rights The Spanish DPA has imposed a fine of EUR 2,000 on GESTIÓN DE VENTAS IBERIA S.L. The controller contacted a data subject for direct marketing purposes, thereby violating local… SPAIN ·AEPD ·Art. 14 Personal Data Controllers Marketing Aug 31, 2025
€10,000 Nursery School “La Combricola Dei Birichini Di Betty”: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 10,000 on the Nursery School “La Combricola Dei Birichini Di Betty”. The controller only accepted new children if their parents agreed… ITALY ·Garante ·Art. 5, 6, 7 +5 Controllers Public Authority Supervisory Authorities Jul 10, 2025
€10,000 Childcare "La Combricola Dei Birichini Di Betty": Non-compliance with the general principles of data processing. ⇄ Een boete van €10.000 - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 7 +5 Marketing Controllers Processing Jul 10, 2025
€12,000 ALBOR ENERGÍA S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 12,000 on ALBOR ENERGÍA S.L. The controller used third parties acting as data processors for direct marketing purposes. The organisation of… SPAIN ·AEPD ·Art. 28 Controllers Processors Processing Jun 16, 2025
€3,000 SILVANERGIA 2022, S.L.: Insufficient legal basis for the processing of data. ⇄ Boete van 3.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6 Controllers Processing Direct Marketing Jun 16, 2025
€3,000 SILVANERGIA 2022, S.L.: Insufficient legal basis for data processing The Spanish DPA imposed a fine of EUR 3,000 on SILVANERGIA 2022, S.L.The controller, a company providing direct marketing services, processed data of potential customers without a… SPAIN ·AEPD ·Art. 6 Controllers Direct Marketing Marketing Jun 16, 2025