Content type · 78 documents in this view · 3,634 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3564 Processing Agreement2800 Processing2632 Personal Data2596 Controllers2211 Data Controller1862 Law Enforcement1540 IP Address1282 Security1024 Supervision879 Monitoring545 Consent518
€20,000 Italian DPA: Enna Health Authority violated GDPR by publishing judicial data The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Italy · ·Art. 5, 6, 10 +1 Jul 18, 2026
€1M CNIL fines energy supplier for mishandling data subject access and objection requests The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French… France ·Art. 12, 14, 15 +2 Jul 17, 2026
€16,000 Italian Garante: OPI of Pisa must remove residential addresses from public register The data subject, a professional registered with the OPI of Pisa, discovered while consulting the Public Register of Professionals online that the database included the… Italy · ·Art. 1, 5, 6 +3 Jul 16, 2026
€2M Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an… Italy · ·Art. 3, 5, 6 +2 Jul 14, 2026
€5.8M Italian Garante sanctions Hera Comm for automated credit-check refusals of contracts Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas… Italy · ·Art. 5, 12, 13 +3 Jul 3, 2026
€460,000 Garante: Piaggio violated GDPR by accessing former employees' emails in disciplinary probe Two former employees (the data subjects) of Piaggio (the controller) were dismissed for just cause in March 2023. Following the termination of their employment, they asked the… Italy · ·Art. 5, 6, 12 +2 Jun 18, 2026
€5,000 Italian DPA: Vasto municipality breached transparency duties over traffic cameras The Municipality of Vasto (the controller) implemented a dedicated photo and video system for the purpose of detecting violations of the national provisions on traffic safety. A… Italy · ·Art. 5, 6, 12 +2 Jun 18, 2026
€6,600 Italian Garante: Employer's recording of locker opening and destruction of contents The case involves a worker (the data subject), his former employer (the controller), and the staffing agency that had provided the company with the worker. In late 2023 the data… Italy · ·Art. 2, 4, 5 +2 Jun 18, 2026
PLN 26,711 UODO (Poland) - DKE.561.4.2026 The DPA initiated an ex officio investigation against an individual (the controller) after several data subjects complained about the controller’s video surveillance extending… Art. 5 May 22, 2026
HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Art. 23 May 13, 2026
HUF 15M NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 May 12, 2026
HUF 10M NAIH fines online store HUF 10M for missing and inadequate privacy notice The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Apr 30, 2026
AKI (Estonia) - No. 2.1-1/24/397-890-38 OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to… No. 2.1-1/24/397-890-38 ·Art. 4, 5, 6 +8 Apr 16, 2026
€25,500 Austrian DSB: Marketing agency violated GDPR by recording phone interviews without valid The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted… Austria ·Art. 5, 6, 12 +1 Jan 19, 2026
€1,500 Italian DPA fines butcher €1,500 for unlawful video surveillance lacking information signs The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of security… Italy · ·Art. 5, 6, 13 +2 Jan 16, 2026
DSB Austria: No fine imposed on COVID mask shop for cookie consent failure Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop… 2026-0.043.390 ·Art. 5, 12, 13 Jan 16, 2026
€200 DSB: Medical student fined for recording dementia patient video without Art 9 GDPR basis A medical student (the controller) worked as a ward attendant at a hospital. Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the… Austria ·Art. 4, 5, 6 +1 Jan 12, 2026
€4.5M Telecommunicatiebedrijf (exploitant van elektronische communicatienetwerken en -diensten): Overtreding van de algemene principes van gegevensverwerking. Een boete van 4.500.000 euro - opgelegd door de Kroatische Autoriteit voor Gegevensbescherming (AZOP). CROATIA · ·Art. 5, 6, 12 +4 Nov 24, 2025
€4.5M Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer… CROATIA · ·Art. 5, 6, 12 +4 Nov 24, 2025
€500,000 Chamber of Commerce, Industry, Services and Navigation of Spain: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 500,000 on the Chamber of Commerce, Industry, Services and Navigation of Spain. Due to its function within the Spanish Executive, the… ·Art. 5, 6, 14 ·Insufficient legal basis for data processing Apr 15, 2025
€4,000 Istituto di Istruzione Superiore 'P. Galluppi' Tropea: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 4.000 euro - opgelegd door de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 9 Mar 27, 2025
€4,000 Istituto di Istruzione Superiore 'P. Galluppi' Tropea: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 2,500 on the Istituto di Istruzione Superiore 'P. Galluppi' Tropea. The controller processed biometric data of its employees to control… ITALY · ·Art. 5, 6, 9 Mar 27, 2025
€50,000 Azienda regionale per lo sviluppo e per i servizi in agricoltura (ARSAC): Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 50,000 on the Regional agency for development and services in agriculture (ARSAC). The controller processed geographic data of its employees… ITALY · ·Art. 5, 6, 13 +3 Mar 13, 2025
€15M OpenAI OpCo LLC: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 15 million on OpenAI in connection with the operation of the generative AI chatbot “ChatGPT”. The DPA found that OpenAI had violated… ITALY · ·Art. 5, 6, 12 +4 Nov 2, 2024
€25,000 APD/GBA (Belgium) - 113/2024 A data subject visited four website operated by MediaHuis, namely: Gazet van Antwerpen; De Standaard; Het Nieuwsblad; Het Belang van Limburg. On each website there was a cookie… Art. 5, 6, 7 Sep 6, 2024
€2.4M Vinted: Insufficient fulfilment of data subjects rights The Lithuanian DPA has imposed a fine of EUR 2,385,276 on the second-hand online store 'Vinted'. The DPA initiated an investigation after the Polish and French DPAs forwarded… LITHUANIA · ·Art. 5, 12 Jul 2, 2024
€31M Clearview AI Inc.: Non-compliance with general data processing principles The Dutch DPA has fined Clearview Al Inc. EUR 30,500,000. Clearview, a company offering facial recognition services, holds a database of over 30 billion images, including those of… May 16, 2024
€20,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 20,000 on a data controller operating in the gambling and betting sector. The data controller collected and processed personal… CROATIA · ·Art. 6, 7, 13 Apr 22, 2024
€15,000 Betting company: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed a fine of EUR 15,000 on a data controller operating in the gambling and betting sector. The data controller collected and processed personal… CROATIA · ·Art. 6, 7, 13 Apr 22, 2024
€32M AMAZON FRANCE LOGISTIQUE: Non-compliance with general data processing principles The French DPA (CNIL) has imposed a fine of EUR 32 million on AMAZON FRANCE LOGISTIQUE for unlawful surveillance of employees. CNIL found that Amazon France equips its warehouse… ·Art. 5, 6, 12 +2 ·Non-compliance with general data processing principles Jan 23, 2024
€7,500 SLOVAKIA DPA: Non-compliance with general data processing principles The Slovak DPA has imposed a fine of EUR 7,500 on an unknown controller. The controller violated the principle of lawfulness, the principle of transparency and the principle of… ·Non-compliance with general data processing principles Jan 1, 2024
DPC (Ireland) - 06/SIU/2018 The Irish DPC started an own volition inquiry into processing operations carried out by the Galway County Council (the controller), focusing mainly into the surveillance… 06/SIU/2018 ·Art. 5, 24, 35 Aug 22, 2023
€1M Autostrade per l'Italia spa: Non-compliance with general data processing principles The Italian DPA has fined Autostrade per l'Italia spa ('ASPI') EUR 1 million for unlawfully processing the data of approx. 100,000 registered users of the toll reimbursement app… ITALY · ·Art. 5, 13, 28 Jun 22, 2023
€15M TikTok: Non-compliance with general data processing principles The UK DPA (ICO) has fined TikTok EUR 14.5 million. The ICO had found that more than one million British children under the age of 13 were using TikTok without the consent of… UNITED KINGDOM · ·Art. 5, 12, 13 Apr 4, 2023
€5.5M WhatsApp Ireland Ltd.: Insufficient legal basis for data processing The Irish DPA (DPC) has fined WhatsApp Ireland Ltd. EUR 5.5 million. The Austrian organization 'None of Your Business' (NOYB) had filed a complaint with the DPA on behalf of an… Art. 6, 12, 13 ·Insufficient legal basis for data processing Jan 19, 2023
€50,000 DPC (Ireland) - 05/SIU/2018 This case involves an own-volition investigation conducted by the Irish DPA (DPC) into Kildare County Council, the controller. In June 2018, Officers from the Special… Art. 2, 5, 6 +5 Jan 16, 2023
€390M Meta Platforms Ireland Limited: Non-compliance with general data processing principles The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 390 million. The DPA has imposed a fine of EUR 210 million for violations related to the provision of its Facebook… Jan 4, 2023
€5,000 Association for the prevention and study of crimes, abuses and negligence in information technology and advanced communications (APEDANICA): Non-compliance with general data processing principles The Spanish DPA has fined the Association for the prevention and study of crimes, abuses and negligence in information technology and advanced communications (APEDANICA) EUR… SPAIN · ·Art. 5 Nov 25, 2022
€20M Clearview Al Inc.: Non-compliance with general data processing principles The Hellenic DPA has imposed a fine of EUR 20,000,000 on Clearview AI Inc. The non-profit organization 'Homos Digitalis' had filed a complaint with the DPA on behalf of the data… Jul 13, 2022
€45,000 Senseonics Inc.: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 45,000 on Senseonics Inc. The company had reported a data breach to the DPA pursuant to Art. 33 GDPR, involving an employee accidentally… ITALY · ·Art. 5, 6, 7 +4 Jul 7, 2022
€9M Clearview Al Inc.: Non-compliance with general data processing principles The UK DPA has fined Clearview AI Inc. EUR 9 million. The company holds a database of more than 20 billion facial images (including those of UK residents and nationals) from… UNITED KINGDOM · ·Art. 5, 6, 9 +7 May 18, 2022
€1.9M BREBAU GmbH: Insufficient legal basis for data processing The DPA of Bremen has imposed a fine of EUR 1.9 million on the housing association BREBAU GmbH. BREBAU GmbH had processed upwards of 9,500 datasets about potential tenants without… GERMANY ·Art. 5, 6, 9 ·Insufficient legal basis for data processing Mar 3, 2022
€20M Clearview Al Inc.: Non-compliance with general data processing principles The Italian DPA has fined U.S.-based Clearview AI EUR 20 million after it was revealed that the company had been applying biometric surveillance techniques on Italian territory.… Feb 10, 2022
IAB Europe: Insufficient legal basis for data processing The Belgian DPA has imposed a fine of EUR 250,000 on IAB Europe. The DPA had received several complaints against IAB Europe since 2019. In the context of this complaint, the… BELGIUM · ·Art. 5, 6, 9 +8 Feb 2, 2022
€1,200 Researcher: Non-compliance with general data processing principles The Belgian DPA has fined a researcher EUR 1,200. The fine was issued in connection with another fine against the NGO EU DisinfoLab. The researcher was employed at the NGO. In… BELGIUM · ·Art. 5, 6, 9 +3 Jan 27, 2022
€2,800 EU DisinfoLab: Non-compliance with general data processing principles The Belgian DPA has fined the NGO EU DisinfoLab EUR 2,700. In 2018, the NGO published an analysis to identify the possible political origin of tweets circulating on a particularly… BELGIUM · ·Art. 5, 6, 9 +5 Jan 27, 2022
€52,000 Motor insurance center: Non-compliance with general data processing principles The Finnish DPA has fined a motor insurance center EUR 52,000. The controller had excessively requested patient data from within the healthcare system for the purpose of… FINLAND · ·Art. 5, 25 Dec 16, 2021
€100,000 Ubi Banca spa: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 100,000 on Ubi Banca spa (now Intesa Sanpaolo spa). A data subject had filed a complaint with the DPA for receiving a letter from the… ITALY · ·Art. 5 Dec 16, 2021
€51,000 Icelandic Ministry of Industry and Innovation: Non-compliance with general data processing principles The Icelandic Data Protection Authority has imposed a fine of EUR 51,000 on the Ministry of Industry and Innovation and a fine of EUR 27,200 on YAY ehf. The fine is related to a… ICELAND ·Art. 5, 6, 7 +4 ·Non-compliance with general data processing principles Nov 23, 2021
€27,200 YAY ehf.: Non-compliance with general data processing principles The Icelandic Data Protection Authority has imposed a fine of EUR 51,000 on the Ministry of Industry and Innovation and a fine of EUR 27,200 on YAY ehf. The fine is related to a… ICELAND ·Art. 5, 6, 28 +1 ·Non-compliance with general data processing principles Nov 23, 2021