Skip to content
Content type · 81 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 81 sort newestlargest fineoldest
€750,000 AEPD sanctions Vodafone España for inadequate Super WiFi processor agreement and oversight Vodafone España, S.A.U., the controller, operated a service known as "Super WiFi" through a third-party processor. Following a data breach affecting the service, the DPA's… Spain ·Art. 5, 28, 32 Processors Controllers Processing Agreement Sep 23, 2026
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Data Breaches Notification Obligation Controllers Sep 22, 2026
€3,150 APDCAT: Public body violated GDPR by disclosing audio recording to four extra recipients On 22 January 2025, an employee and trade union representative of a public-sector organisation, the data subject, emailed the DPO requesting access to and a copy of a recording of… Spain ·Art. 5, 6, 12 +1 Personal Data Right of Access Integrity and Confidentiality Principle Sep 15, 2026
Finnish DPA orders Espoo to ensure pupil data protection in Google learning tools In April 2018, the DPA received a complaint stating that the city of Espoo (the controller) was using Google's digital learning tools in a school without obtaining consent from… TSV/40/2018 ·Finland ·Tietosuojavaltuutettu Supervisory Authorities Controllers Personal Data Sep 4, 2026
09-07-2026 (Lyngby Boldklub) Lyngby Boldklub (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial… 09-07-2026 ·Denmark ·Datatilsynet (DK) DPIA Access Controls Prior Consultation
Datatilsynet authorises AC Horsens facial recognition at matches under conditions AC Horsens (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial recognition… 09-07-2026 ·Denmark ·Datatilsynet (DK) DPIA Access Controls Prior Consultation
09-07-2026 (Lyngby Boldklub) Lyngby Boldklub (the controller), pursuant to section 7(4) of the Danish Data Protection Act, sent an application to the DPA, asking for permission use automatic facial… 09-07-2026 ·Denmark ·Datatilsynet (DK) DPIA Access Controls Prior Consultation Sep 1, 2026
Austrian DSB: e-marketplace transfer of customer data to China and US requires valid Art. The DPA was acting upon a complaint addressing the subject matter of third country personal data transfers. The controller, established in Ireland, operates an e-marketplace… D130.2269 ·Austria ·Art. 45, 46, 49 Privacy Shield Processing Agreement International Transfer Aug 25, 2026
HDPA: Hellenic Open University found to have met breach notification duties after The Hellenic Open University (‘the controller’) submitted initial and supplementary notifications to the DPA after it was subject to a data breach resulting from a ransomware… 14/2026 ·Greece ·Art. 32, 33, 34 +1 Data Breaches Notification Obligation Integrity and Confidentiality Principle Aug 19, 2026
€200,000M 15/2026 The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information… Greece ·HDPA ·Art. 5, 28, 32 Controllers Data Breaches Integrity and Confidentiality Principle Jul 28, 2026
AEPD · EXP202102529 A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3 Consent Personal Data Healthcare
€200,000 Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first… PS-00020-2025 ·Spain ·AEPD Integrity and Confidentiality Principle Data Breaches Notification Obligation Jul 16, 2026
€450,000 VDAI fines medical company €450,000 for inadequate security measures in data breaches Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Lithuania ·Art. 5, 24 Security Data Breaches Integrity and Confidentiality Principle Jun 19, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland ·DPC ·Art. 5, 28, 30 +2 Integrity and Confidentiality Principle Notification Obligation Data Breaches Jun 11, 2026
PLN 21,000 DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Poland ·UODO ·Art. 24, 25, 28 +1 Integrity and Confidentiality Principle Security Controllers May 25, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·DPC ·Art. 5, 32, 33 Integrity and Confidentiality Principle Notification Obligation Data Breaches May 8, 2026
€2,802 IP-RS · 0609-42/2026/7 A processor was contracted by a company (the controller) to maintain an online store, fix errors, and provide support. This included ensuring that the controller had installed the… Slovenia ·Art. 32 Controllers Processors Security May 1, 2026
€10,000 FREE TECHNOLOGIES EXCOM, S.L.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 10,000 on FREE TECHNOLOGIES EXCOM, S.L. The controller had reset user passwords and communicated the new passwords to the clients via… SPAIN ·AEPD ·Art. 32 Encryption Security Controllers Feb 3, 2026
€1,300 Legal Entity: Insufficient technical and organisational measures to ensure information security The Slovenian DPA has imposed a fine of EUR 1,300 on a legal entity. An employee of the controller stored personal data on her work laptop without securing it, for example by… SLOVENIA ·IP-RS ·Art. 32 Encryption Security Controllers Dec 4, 2025
€4,750 The District Sanitary Inspector in Police: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 4.750 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 24, 25 +1 Security Encryption Controllers Nov 15, 2025
€4,750 Powiatowego Inspektora Sanitarnego w Policach: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 4750 on the Powiatowego Inspektora Sanitarnego w Policach. The controller failed to implement adequate technical and organisational… POLAND ·UODO ·Art. 5, 24, 25 +1 Security Encryption Controllers Nov 15, 2025
€6,600 Owner of a pharmacy: Non-compliance with general principles for data processing. ⇄ Boete van 6.600 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6, 14, 32 Health Data Controllers Processing May 9, 2025
€6,600 Owner of a Pharmacy Office: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the owner of a pharmacy office. The controller processed data of residents of two geriatric centers without a sufficient legal basis. The… SPAIN ·AEPD ·Art. 6, 14, 32 Controllers Encryption Personal Data May 9, 2025
€6,600 Owner of a Pharmacy Office: Non-compliance with general data processing principles The Spanish DPA has imposed a fine on the owner of a pharmacy office. The controller processed data of residents of geriatric centers without a sufficient legal basis. The… SPAIN ·AEPD ·Art. 6, 14, 32 Controllers Encryption Personal Data May 8, 2025
€6,600 Owner of a Pharmacy: Violation of the General Principles of Data Processing. ⇄ Een boete van 6.600 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 6, 14, 32 Health Data Controllers Processing May 8, 2025
€4,000 AEPD: Continuous workplace audio recording violates GDPR data minimisation principle On 22 April 2025, a data subject lodged a complaint with the DPA against BODENSE ESTRUCTURAS Y CALDELERÍA, S.L., the controller. The data subject claimed that the controller had… Spain ·Art. 5 Retention Period Monitoring IP Address Apr 22, 2025
€358,000 POLAND DPA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 358,000 on a company. The company had inadvertently published customer data (first name, last name, email address, home address, encrypted… UODO ·Art. 5, 25, 28 +1 ·Insufficient technical and organisational measures to ensure information security Supervisory Authorities Encryption Security Nov 20, 2024
€4,700 POLAND DPA: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 4,700 on a subcontractor that was contracted to redesign the website of another company. This fine is linked to ETid-2491. Due to an error… UODO ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Supervisory Authorities Security Encryption Nov 20, 2024
€91M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 91 million on Meta Platforms Ireland Limited (MPIL). The DPC had initiated an investigation after MPIL reported that user passwords… DPC Data Breaches Encryption Security Sep 27, 2024
€26,800 Municipality of Vejen: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 26,800 on the municipality of Vejen. The municipality had suffered a security incident involving the theft of three unencrypted computers… DENMARK ·Datatilsynet (DK) ·Insufficient technical and organisational measures to ensure information security Public Authority Encryption Education Aug 14, 2024
€56,000 Res-Gastro M. Gaweł Sp. k.: Insufficient technical and organisational measures to ensure information security The Polish DPA (UODO) has imposed a fine of EUR 56,000 on Res-Gastro M. Gaweł Sp. k. The controller had reported a data breach involving the loss of an unencrypted USB stick by an… POLAND ·UODO ·Art. 24, 25, 32 Security Encryption Privacy by Design & Default Apr 29, 2024
Following an investigation in 2019-2020, the EDPS issued recommendations and the Commission modified the ILA The EDPS investigated whether these modifications were sufficient to bring processing in compliance with data protection requirements and found infringements. Data accessed by… 2021-0518 ·European Union ·Art. 5, 6, 28 +1 International Transfer Controllers Processors Mar 8, 2024
€273,000 Centrum Medyczne Ujastek Sp. z o.o.: Non-compliance with general data processing principles The Polish DPA has imposed two fines on the medical facility “Centrum Medyczne Ujastek” totaling approximately EUR 273,000. The first fine of approximately EUR 163,000 was imposed… POLAND ·UODO ·Art. 5, 6, 9 +3 Encryption Healthcare Controllers Jan 17, 2024
€15,000 Hotel: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 15,000 to a hotel. The hotel was collecting personal data from guests in excess of what would have been necessary for the… CROATIA ·AZOP ·Art. 6, 13, 32 +1 Personal Data Controllers Encryption Sep 26, 2023
€3,400 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 3,400 on a company. The controller had reported a data breach to the DPA. The company car of a senior employee had been broken into,… POLAND ·UODO ·Art. 5, 24, 25 +1 Encryption Security Privacy by Design & Default Jul 18, 2023
€17,600 Skåne region: Insufficient technical and organisational measures to ensure information security The Swedish DPA has fined Skåne region EUR 17,600. An employee of the region had lost an unencrypted USB stick containing the social security numbers and sensitive personal data… SWEDEN ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Encryption Personal Data Apr 26, 2023
€5,400 Disciplinary officer: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 5,400 on a disciplinary officer of the Polish Bar Association after an unencrypted USB stick containing personal data was lost. POLAND ·UODO ·Art. 5, 25, 32 Encryption Security Personal Data Apr 20, 2023
€145,000 AFIANZA ASESORES S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 145,000 on AFIANZA ASESORES S.L.. The controller had reported a data breach to the DPA, stating that a backpack containing a USB stick… SPAIN ·AEPD ·Art. 5, 32 Encryption Security Controllers Mar 16, 2023
€4,000 Partidul Uniunea Salvați România: Insufficient technical and organisational measures to ensure information security The Romanian DPA has fined the Partidul Uniunea Salvați România party EUR 4,000. The controller had suffered a phishing attack in which the attackers gained unauthorized access to… ROMANIA ·ANSPDCP ·Art. 32 Security Encryption Right of Access Mar 15, 2023
€6,400 Szczecin-Centrum District Court: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 6,400 on the Szczecin-Centrum District Court. The court had reported a data breach to the DPA involving the loss of three data carriers.… POLAND ·UODO ·Art. 5, 24, 25 +1 Encryption Privacy by Design & Default Security Jan 19, 2023
€300,000 FREE SAS: Insufficient fulfilment of data subjects rights The French DPA has imposed a fine of EUR 300,000 on FREE SAS. The DPA had received several complaints from individuals experiencing difficulties in exercising their rights to… FRANCE ·CNIL ·Art. 12, 15, 17 +2 Data Breaches Personal Data Encryption Dec 8, 2022
DKK 500,000 Danish DPA fines Sirius Lawyers DKK 500,000 for inadequate security after hacker attack A law firm was exposed to a hacker attack. Thereby, hackers received access to the firm's servers that contained personal data and encrypted them. This posed a serious risk that… Denmark ·Datatilsynet (DK) ·Art. 5, 9, 24 +2 Integrity and Confidentiality Principle Supervisory Authorities Encryption
€5,000 Curtea Veche Publishing SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 5,000 on Curtea Veche Publishing SRL. The controller had reported two data breaches to the DPA pursuant to Art. 33 GDPR. In the first… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Encryption Security Sep 21, 2022
€250,000 GIE INFOGREFFE: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 250,000 on GIE INFOGREFFE. The portal operates a website where people can access legal information about companies and order documents… FRANCE ·CNIL ·Art. 5, 32 Security Encryption Personal Data Sep 13, 2022
€20,000 Medical laboratory: Insufficient technical and organisational measures to ensure information security The Belgian DPA imposed a fine of EUR 20,000 on a medical laboratory. During its investigation, the DPA found that the laboratory had failed to conduct a data protection impact… BELGIUM ·APD/GBA ·Art. 5, 12, 13 +3 Encryption DPIA Security Aug 19, 2022
€67,200 SIRIUS (law firm): Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 67,200 on the law firm SIRIUS. The law firm had suffered a cyber attack in which hackers gained access to the firm's servers and encrypted… DENMARK ·Datatilsynet (DK) ·Art. 32 Encryption Security Integrity and Confidentiality Principle Jul 14, 2022
€13,400 Civilstyrelsen: Insufficient technical and organisational measures to ensure information security The Danish DPA has imposed a fine of EUR 13,400 on the Danish agency Civilstyrelsen. A Civilstyrelsen USB stick containing more than 800 pages of sensitive and confidential… DENMARK ·Datatilsynet (DK) ·Art. 32, 33 Encryption Data Breaches Security May 12, 2022
€1.5M DEDALUS BIOLOGIE: Insufficient technical and organisational measures to ensure information security The French DPA (CNIL) has imposed a fine of EUR 1.5 million on DEDALUS BIOLOGIE. DEDALUS distributes software solutions for medical analysis laboratories. In February, the press… FRANCE ·CNIL ·Art. 28, 29, 32 Security Encryption Personal Data Apr 15, 2022
€115,000 Tuckers Solicitors LLP: Non-compliance with general data processing principles The UK DPA (ICO) has fined law firm Tuckers Solicitors LLP EUR 115,000. Tuckers suffered a ransomware attack on its systems, which resulted in a personal data breach. As part of… UNITED KINGDOM ·ICO ·Art. 5 Security Personal Data Processing Mar 10, 2022
€28,500 Uppsala regional board: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 28,500 on the Uppsala regional board. The fine is the result of an investigation of the Uppsala region (the regional board and the… SWEDEN ·IMY ·Art. 32 Encryption Security Personal Data Jan 26, 2022