Skip to content
Content type · 85 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 85 sort newestlargest fineoldest
€50,000 Italian Garante sanctions Calabrian agency for location tracking of remote workers The Calabrian Regional Agency for Agricultural Development (the controller) implemented a remote work policy that required employees to use a time-tracking application called… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 13 +3 Monitoring DPIA Privacy Impact Assessment Jul 16, 2026
€200,000 AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack… Spain ·Art. 5, 35, 58 DPIA Privacy Impact Assessment Data Breaches Jul 16, 2026
€2M Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 6 +2 Processing Controllers Personal Data Jul 14, 2026
€158,000 Italian DPA finds GDPR applies to US-based Character.AI service Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 12 +7 Controllers Representatives AI Information Duties Jul 3, 2026
Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… 2025010358 ·Iceland ·Island Monitoring Integrity and Confidentiality Principle Supervisory Authorities Jul 1, 2026
€460,000 Garante: Piaggio violated GDPR by accessing former employees' emails in disciplinary probe Two former employees (the data subjects) of Piaggio (the controller) were dismissed for just cause in March 2023. Following the termination of their employment, they asked the… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 12 +2 Fairness & Transparency Storage Limitation Personal Data Jun 18, 2026
€5,000 Italian DPA: Vasto municipality breached transparency duties over traffic cameras The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 12 +2 DPIA Privacy Impact Assessment Personal Data Jun 18, 2026
UODO (Poland) - DKN.5131.12.2022 The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Art. 5, 24, 25 +3 DPIA Data Breaches Security Jun 11, 2026
€6,000 Italian DPA: vehicle tracking by Liguria Health Agency lawful, information duties met A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller). The data subject was employed by the Ligurian Social and Health Care… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 13 +3 DPIA Privacy by Design Monitoring May 28, 2026
€55,000 Italian DPA: AgID's automatic transfer of PEC addresses to INAD index unlawful The data controller for the case is a government body called the Agency for Digital Italy (AgID). AgID is tasked with driving the adoption of digital technologies in both… Italy ·Garante per la protezione dei dati personali ·Art. 5, 12, 14 +1 Personal Data Controllers Processing May 28, 2026
PLN 21,000 UODO (Poland) - DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Art. 24, 25, 28 +1 Security Controllers Processors May 25, 2026
HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Art. 23 Personal Data Processing Criminal Data May 13, 2026
€3,000 Piacenza Bar Association: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Piacenza Bar Association €3,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6 Education Public Authority DPIA Mar 26, 2026
€3.5M Company: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 3,500,000 on a company. The controller operated a loyalty program in France and 16 other EU countries, using customer data obtained… FRANCE ·CNIL ·Art. 6, 13, 32 +1 DPIA IP Address Processing Agreement Dec 30, 2025
€6,000 Comune di Nave: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Commune di Nave. The controller has installed an automatic licence plate recognition system which processes data on when a… ITALY ·Garante ·Art. 5, 6, 12 +2 Insurance DPIA Privacy Impact Assessment Dec 18, 2025
€4.5M Telecommunicatiebedrijf (exploitant van elektronische communicatienetwerken en -diensten): Overtreding van de algemene principes van gegevensverwerking. Een boete van 4.500.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA ·azop ·Art. 5, 6, 12 +4 Controllers Data Processor Processors NL Nov 24, 2025
€6,000 Gemeente Orte: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 6.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +2 Video Surveillance Processing Education NL Nov 13, 2025
€10M Aena, S.M.E., S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 10,043,002 on Aena, S.M.E., S.A. The controller conducted a pilot project involving multiple airports, including the use of facial… SPAIN ·aepd ·Art. 35 DPIA Privacy Impact Assessment IP Address Nov 6, 2025
€10M Aena, een klein en middelgroot bedrijf (KMO), S.A.: Niet-naleving van de algemene principes voor gegevensverwerking. 10.043.002 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 35 Privacy Impact Assessment Processing Controllers NL Nov 6, 2025
€15,000 Gemeente Curtarolo: Onvoldoende wettelijke basis voor de verwerking van gegevens. Een boete van 15.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 12 +3 Video Surveillance Processing Controllers NL Oct 23, 2025
AEPD sanctions 23andMe for security failures in credential-stuffing breach 23ANDME, INC., the controller, is a personal genomics and biotechnology company established in the United States which offered genetic testing services to individuals in Spain. In… PS-00140-2025 ·Spain ·Art. 5, 9, 24 +2 Data Breaches Notification Obligation Integrity and Confidentiality Principle Oct 10, 2025
€7,700 Geen zorginstelling: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €7.700 - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 25, 32 Security Healthcare Data Controller NL Aug 4, 2025
€96,000 SIDECU, S.A.: Non-compliance with general data processing principles The Spanish DPA imposed a fine of EUR 96,000 on SIDECU, S.A. The controller introduced facial recognistion system as the only access method to their facilities, without offering… SPAIN ·aepd ·Art. 9, 13, 35 DPIA Privacy Impact Assessment IP Address Jun 26, 2025
€550,000 Departement of Social Security: Insufficient legal basis for data processing The Irish DPA imposed a fine of EUR 550,000 on the Departement of Social Security. The controller uses the so called SAFE 2 registration process for anyone applying for a Public… IRELAND ·Art. 5, 6, 9 +2 ·Insufficient legal basis for data processing DPIA Privacy Impact Assessment Types of Special Categories of Personal Data Jun 12, 2025
€50,000 Regio Lombardije: Onvoldoende juridische basis voor gegevensverwerking. Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 25 +3 Processing Controllers Data Controller NL Apr 29, 2025
€1,500 ULPIA TRAJANA ALAMEDA S.L.: Non-compliance with general data processing principles The Spanish DPA imposed a fine on ULPIA TRAJANA ALAMEDA S.L. During the booking process, the controller processed data that was unnecessary for the purpose, infringing on the… SPAIN ·aepd ·Art. 5, 9 Controllers IP Address DPIA Apr 24, 2025
€1,500 ULPIA TRAJANA ALAMEDA S.L.: Niet-naleving van de algemene principes voor gegevensverwerking. 1.500 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 9 Special Categories of Data Processing Data Controller NL Apr 24, 2025
€7,800 Uitvaartonderneming: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van €7.800 - van het Poolse Nationaal Bureau voor de Bescherming van Persoonlijke Gegevens (UODO). POLAND ·UODO ·Art. 5 Health Data Data Breaches Security NL Apr 15, 2025
€40,000 Real estate company: Non-compliance with general data processing principles The French DPA imposed a fine of EUR 40,000 on a real estate company for inappropriately monitoring its employees. A software program recorded “periods of inactivity” and… FRANCE ·CNIL ·Art. 5, 6, 12 +3 Monitoring DPIA Audit Logs Feb 4, 2025
€1M LIGA NACIONAL DE FÚTBOL PROFESIONAL: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1 million on LIGA NACIONAL DE FÚTBOL PROFESIONAL. The controller had introduced access controls for visitors to football stadiums using… SPAIN ·aepd ·Art. 35 DPIA Privacy Impact Assessment Security Dec 20, 2024
€135,600 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA fined a company in the banking sector EUR 135,600. The DPA inspected the fined company and found several violations of the GDPR. First, the company failed to ensure… POLAND ·UODO ·Art. 30, 35, 38 Privacy Impact Assessment DPIA Processing Agreement Dec 18, 2024
€200,000 Hospital: Insufficient technical and organisational measures to ensure information security The Belgian DPA has fined a hospital EUR 200,000. The hospital had suffered a ransomware attack through a vulnerability in the server, which paralyzed parts of the computer system… BELGIUM ·APD ·Art. 5, 24, 32 +1 DPIA Security Privacy Impact Assessment Dec 17, 2024
€220,000 CARTONAJES BAÑERES, S.A: Insufficient technical and organisational measures to ensure information security The Spanish DPA has fined CARTONAJES BAÑERES, S.A. EUR 220,000. During its investigation, the DPA found that the controller had failed to grant a former employee access to their… SPAIN ·aepd ·Art. 15, 35 DPIA Privacy Impact Assessment Employees Nov 22, 2024
€100,000 Olimpia S.r.l.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Olimpia S.r.l.. During its investigation, the DPA found that data subjects had received advertising calls on behalf of the… ITALY ·Garante ·Art. 5, 6, 24 +3 Controllers IP Address Processing Agreement Apr 11, 2024
€175,000 Greek Ministry of Immigration and Asylum: Insufficient technical and organisational measures to ensure information security The Hellenic DPA has imposed a fine of EUR 175,000 on the Greek Ministry of Immigration and Asylum. The DPA found that the controller had failed to properly carry out a required… GREECE ·HDPA ·Art. 25, 31, 35 DPIA Privacy Impact Assessment Security Apr 2, 2024
€20,000 Centro Riparazioni Piacentino S.p.A.: Non-compliance with general data processing principles The Italian DPA (Garante) imposed a fine of EUR 20,000 on Centro Riparazioni Piacentino S.p.A.. The controller had kept a former employee's email account active despite the… ITALY ·Garante ·Art. 5, 13 Controllers IP Address Personal Data Mar 7, 2024
€365,000 CTC EXTERNALIZACIÓN, S.L: Insufficient fulfilment of information obligations The Spanish DPA has imposed a fine of EUR 365,000 on CTC EXTERNALIZACIÓN, S.L.. An employee had filed a complaint with the DPA due to the fact that the controller had requested… SPAIN ·aepd ·Art. 13, 32, 35 DPIA Privacy Impact Assessment Controllers Feb 12, 2024
€150,000 International Card Services B.V.: Insufficient technical and organisational measures to ensure information security The Dutch DPA has imposed a fine of EUR 150,000 on International Card Services B.V. (ICS). ICS failed to carry out a data protection impact assessment before starting the digital… THE NETHERLANDS ·AP ·Art. 35 DPIA Privacy Impact Assessment Security Jan 15, 2024
€26,500 Östersund Municipality's Department for Children and Education: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 26,500 on the Östersund Municipality's Department for Children and Education. The authority had failed to carry out a data protection… SWEDEN ·Art. 35 ·Insufficient technical and organisational measures to ensure information security DPIA Privacy Impact Assessment Public Authority Nov 28, 2023
€50,000 Athens Urban Transport Organization: Non-compliance with general data processing principles The Hellenic DPA imposed a fine of EUR 50,000 on the Athens Urban Transport Organization. As part of its investigation, the DPA found that the controller had failed to comply with… GREECE ·HDPA ·Art. 5, 25, 35 Privacy by Default DPIA Privacy by Design Sep 25, 2023
DPC (Ireland) - 06/SIU/2018 The Irish DPC started an own volition inquiry into processing operations carried out by the Galway County Council (the controller), focusing mainly into the surveillance… 06/SIU/2018 ·Art. 5, 24, 35 Video Surveillance Monitoring DPIA Aug 22, 2023
€300,000 Rinascente S.p.A.: Non-compliance with general data processing principles The Italian DPA has fined Rinascente S.p.A. EUR 300,000. The DPA acted on a complaint from a customer who, following an incident with a store employee, had her long-standing… ITALY ·Garante ·Art. 5, 12, 32 +1 DPIA Social Media Privacy Impact Assessment Jun 8, 2023
€200,000 GSMA LTD.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 200,000 against GSMA LTD.. An individual had filed a complaint with the DPA because they had to transfer special categories of personal… SPAIN ·aepd ·Art. 35 DPIA Privacy Impact Assessment Processing Agreement May 3, 2023
€12,000 ALBERO FORTE COMPOSITE, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA (AEPD) has imposed a fine on ALBERO FORTE COMPOSITE, S.L.. The company had taken pictures of employees at the entrance for the purpose of recording their working… SPAIN ·aepd ·Art. 35 DPIA Privacy Impact Assessment Employees Apr 28, 2023
€6,000 Praktiškas UAB: Insufficient legal basis for data processing The Lithuanian DPA has fined Praktiškas UAB, the operator of SportGates sports clubs, EUR 6,000. The controller had processed biometric data of customers in the context of their… LITHUANIA ·VDAI ·Art. 5, 9, 13 +2 DPIA Consent Controllers Jan 9, 2023
€55,000 Azienda Universitaria Giuliano Isontina: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Giuliano Isontina . The health authority has created patient profiles using algorithms and personal… ITALY ·Garante ·Art. 2, 5, 9 +2 Health Data Healthcare DPIA Dec 15, 2022
€55,000 Azienda Universitaria Friuli Centrale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Friuli Centrale. The health authority has created patient profiles using algorithms and personal patient… ITALY ·Garante ·Art. 2, 5, 9 +2 DPIA Health Data Healthcare Dec 15, 2022
€55,000 Azienda Universitaria Friuli Occidentale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Friuli Occidentale. The health authority has created patient profiles using algorithms and personal… ITALY ·Garante ·Art. 2, 5, 9 +2 DPIA Health Data Healthcare Dec 15, 2022
€800,000 DISCORD INC.: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 800,000 on DISCORD INC.. DISCORD offers an online communication service through which users can chat or make video calls. During its… FRANCE ·CNIL ·Art. 5, 13, 25 +2 DPIA Storage Limitation Privacy by Default Nov 10, 2022
€4.3M Portuguese National Statistical Institute: Non-compliance with general data processing principles The Portuguese DPA has fined the Portuguese National Statistical Institute EUR 4,3 million. The DPA found numerous violations of the GPDR in connection with the 2021 census in… PORTUGAL ·CNPD ·Art. 5, 9, 12 +5 DPIA Privacy Shield Privacy Impact Assessment Nov 2, 2022