Skip to content
Content type · 42 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–42 of 42 sort newestlargest fineoldest
€10,000 AEPD (Spain) - PS/00249/2025 MÁS SOL ENERGÍA 15, S.L., the controller, is a company that carries out customer acquisition through telephone calls to offer solar panel installation services. On 18 November… Art. 4, 5, 7 +1 Cookies IP Address Direct Marketing Aug 12, 2026
HUF 2M NAIH fines online store HUF 2M for unclear and incomplete privacy notice The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The… Hungary ·Art. 12, 13 Legitimate Interest Cookies Lawful Basis Jul 22, 2026
€1M CNIL fines energy supplier for mishandling data subject access and objection requests The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French… France ·Art. 12, 14, 15 +2 Right of Access Personal Data Accuracy Jul 17, 2026
€2M Italian DPA sanctions Lusha Systems for processing contact data without consent in B2B Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was an… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 6 +2 Processing Personal Data Controllers Jul 14, 2026
€1.4M Italian Garante sanctions EstEnergy for automated creditworthiness scoring in energy EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller… Italy ·Garante per la protezione dei dati personali ·Art. 5, 13, 14 +2 Controllers Retention Period Storage Limitation Jul 3, 2026
€158,000 Italian DPA finds GDPR applies to US-based Character.AI service Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Garante per la protezione dei dati personali ·Art. 3, 5, 12 +7 Controllers Representatives AI Information Duties Jul 3, 2026
€5.8M Italian Garante sanctions Hera Comm for automated credit-check refusals of contracts Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas… Italy ·Garante per la protezione dei dati personali ·Art. 5, 12, 13 +3 Controllers Processors Fairness & Transparency Jul 3, 2026
€6,600 Italian Garante: Employer's recording of locker opening and destruction of contents The case involves a worker (the data subject), his former employer (the controller), and the staffing agency that had provided the company with the worker. In late 2023 the data… Italy ·Garante per la protezione dei dati personali ·Art. 2, 4, 5 +2 Personal Data Legitimate Interest Integrity and Confidentiality Principle Jun 18, 2026
HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Art. 23 Personal Data Controllers Criminal Data May 13, 2026
HUF 15M NAIH fines online store HUF 15M for transparency and Article 12(1) GDPR violations The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Transparency Personal Data Fairness & Transparency May 12, 2026
HUF 10M NAIH fines online store HUF 10M for missing and inadequate privacy notice The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Personal Data Accountability Controllers Apr 30, 2026
€72,000 AEPD sanctions Tiger Media Inc. for installing advertising cookies without user consent Tiger Media Inc., the controller, operated an advertising platform for publishers and advertisers of adult products and services. The platform acted as an ad network, connecting… Spain ·Art. 6, 27 Legitimate Interest Cookies Direct Marketing Nov 14, 2025
€135,600 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA fined a company in the banking sector EUR 135,600. The DPA inspected the fined company and found several violations of the GDPR. First, the company failed to ensure… POLAND ·UODO ·Art. 30, 35, 38 Privacy Impact Assessment DPIA Insurance Dec 18, 2024
€1.1M Bonnier News AB: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 1.1 million on Bonnier News AB. During its investigation, the DPA found that Bonnier News collects customer data, for example, through… SWEDEN ·Art. 6 ·Insufficient legal basis for data processing Direct Marketing Marketing Consent Jun 26, 2023
€300,000 Rinascente S.p.A.: Non-compliance with general data processing principles The Italian DPA has fined Rinascente S.p.A. EUR 300,000. The DPA acted on a complaint from a customer who, following an incident with a store employee, had her long-standing… ITALY ·Garante ·Art. 5, 12, 32 +1 DPIA Social Media Privacy Impact Assessment Jun 8, 2023
€4.9M Edison Energia S.p.A.: Non-compliance with general data processing principles The Italian DPA has fined Edison Energia S.p.A. EUR 4.9 million. Several person had filed complaints with the DPA regarding unlawful marketing activities of the company. During… ITALY ·Garante ·Art. 5, 6, 7 +4 Right to Object Data Subject Rights Exercise Modalities and Procedures IP Address Dec 15, 2022
€55,000 Azienda Universitaria Friuli Occidentale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Friuli Occidentale. The health authority has created patient profiles using algorithms and personal… ITALY ·Garante ·Art. 2, 5, 9 +2 Health Data DPIA Healthcare Dec 15, 2022
€55,000 Azienda Universitaria Friuli Centrale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Friuli Centrale. The health authority has created patient profiles using algorithms and personal patient… ITALY ·Garante ·Art. 2, 5, 9 +2 DPIA Health Data Healthcare Dec 15, 2022
€55,000 Azienda Universitaria Giuliano Isontina: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Giuliano Isontina . The health authority has created patient profiles using algorithms and personal… ITALY ·Garante ·Art. 2, 5, 9 +2 Health Data Healthcare DPIA Dec 15, 2022
€900 LfD (Lower Saxony) - Fine EUR 900,000 against bank A commercial bank (controller) used personal data of current and former customers (data subjects) to identify customers with an affinity for digital media usage, in order to… Germany ·Art. 6 Legitimate Interest Marketing Lawful Basis Sep 28, 2022
NAIH (Hungary) - NAIH-4667-10/2022 A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Art. |, 10, 28 +1 Controllers Personal Data Right of Access Sep 22, 2022
APD/GBA (Belgium) - 117/2022 The data subject was a former customer of the controller (which remained unknown). The data subject received direct marketing from the controller. The data subject objected to the… 117/2022 ·Art. 6, 12, 15 +1 Legitimate Interest Right to Object Lawful Basis Jul 26, 2022
APD/GBA (Belgium) - 115/2022 During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor,… 115/2022 ·Art. 5, 6, 9 Personal Data Controllers Lawful Basis Jul 19, 2022
Garante per la protezione dei dati personali (Italy) - 9788429 Social media platform TikTok (the controller) provided personalized advertising to its users (the data subjects) on the legal basis of consent (Article 6(1)(a) GDPR). In June… 9788429 ·Art. 5, 6, 122 Cookies Legitimate Interest Social Media Jul 7, 2022
Austrian DPA: Court's publication of full divorce settlement in land register violates The data subject divorced her husband in a proceeding before the district court (the controller), acting in its capacity as the competent land registry court. As part of the… 2021-0.643.804 ·Austria ·DSB Integrity and Confidentiality Principle Controllers Material scope (GDPR) Jun 9, 2022
AEPD (Spain) - EXP202203606 Resolution No. R/00665/2022 is highlighted by a case concerning a claimant (namely A.A.A) and a respondent party (namely Securitas Direct España, S.A). The claimant filed against… R/00665/2022 ·Art. 17, 55 Right to Restriction Right of Access Procedures Article 19 GDPR - Notification of Rectification, Erasure or Restriction Apr 22, 2022
BfDI (Germany) - 24-191 II The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject… 24-191 II#4781 ·Art. 15, 20, 95 Telecommunications Recipient Social Media Jan 27, 2022
€2,800 EU DisinfoLab: Non-compliance with general data processing principles The Belgian DPA has fined the NGO EU DisinfoLab EUR 2,700. In 2018, the NGO published an analysis to identify the possible political origin of tweets circulating on a particularly… BELGIUM ·APD ·Art. 5, 6, 9 +5 Religious Beliefs Social Media Fairness & Transparency Jan 27, 2022
€1,200 Researcher: Non-compliance with general data processing principles The Belgian DPA has fined a researcher EUR 1,200. The fine was issued in connection with another fine against the NGO EU DisinfoLab. The researcher was employed at the NGO. In… BELGIUM ·APD ·Art. 5, 6, 9 +3 Religious Beliefs Fairness & Transparency Social Media Jan 27, 2022
Belgian DPA rules on competence in cross-border cookie consent complaint involving The respondent owns a website 'YourOnlineChoices', through which data subjects can control their ad experience online. When browsing the web and visiting different websites, they… 11/2022 ·Belgium ·APD/GBA Cookies Legitimate Interest Supervisory Authorities Jan 21, 2022
€3M CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 3,000,000 on CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.. An individual had filed a complaint against the controller. The reason… SPAIN ·aepd ·Art. 6 Insurance Marketing Automated Decision-Making Oct 21, 2021
€500,000 Unser Ö-Bonus Club GmbH: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 2,000,000 on Rewe affiliate Ö-Bonus Club GmbH. When signing up for the customer loyalty program jö Bonus Club, the controller is said to… AUSTRIA ·dsb ·Art. 6, 7, 12 Processing Agreement Marketing Controllers Aug 2, 2021
€50,000 AEPD (Spain) - PS/00259/2020 A data subject exercised their right to object to receiving commercial communications against a bank (Bankia/Caixabank), after what whose DPO confirmed that the right had been… Art. 6, 22 Legitimate Interest Marketing Right to Object Jul 6, 2021
€40,000 Electricity Authority of Cyprus: Insufficient legal basis for data processing The Cypriot DPA imposed a fine of EUR 40,000 on the Electricity Authority of Cyprus. The controller used an automated system based on the so-called Brad-Factor to manage, monitor… Art. 6, 9 ·Insufficient legal basis for data processing Employees Controllers Automated Decision-Making Mar 3, 2021
DSB (Austria) - 2020-0.743.659 The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Personal Data Right of Access Procedures Health Data Nov 19, 2020
€30,000 AEPD (Spain) - PS/00032/2020 A user of the website of Iberia, an airline, lodged a complaint before the Spanish DPA (AEPD) saying that they had not been given an option to reject the cookies when using the… Art. 22 Cookies Information Provision Modalities and Communication Methods Consent Oct 16, 2020
Privacy Appeals Board: Datatilsynet may demand information from OpenX under GDPR Art. The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app.… 20/02254 (Grindr) ·Norway ·Art. 57, 58 Telecommunications Cookies Supervision Sep 7, 2020
€72,000 Taksi Helsinki: Non-compliance with general data processing principles Among other things, the company had not assessed the risks and consequences of processing personal data before introducing a camera surveillance system that records audio and… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 6, 35 Video Surveillance Privacy Impact Assessment DPIA May 29, 2020
DSB (Austria) - D123.768/0004-DSB/2019 The complainant belongs to a political party and is a member of the city council of an Austrian municipality. In November, the municipality held a meeting on the "parking space… DSB-D123.768/0004-DSB/201 ·Art. 4, 85 Social Media Personal Data Legitimate Interest Dec 18, 2019
€10,000 LGS Handling Ltd, Louis Travel Ltd, and Louis Aviation Ltd: Insufficient legal basis for data processing The decision found that the use of the Bradford factor for profiling and monitoring sick leave constituted unlawful processing of personal data in breach of Article 6 and Article… CYPRUS ·Art. 6, 9 ·Insufficient legal basis for data processing Integrity and Confidentiality Principle Fines Audit Logs Oct 25, 2019
€2,000 LGS Handling Ltd, Louis Travel Ltd, and Louis Aviation Ltd: Insufficient legal basis for data processing The decision found that the use of the Bradford factor for profiling and monitoring sick leave constituted unlawful processing of personal data in breach of Article 6 and Article… CYPRUS ·Art. 6, 9 ·Insufficient legal basis for data processing Integrity and Confidentiality Principle Fines Audit Logs Oct 25, 2019
€70,000 LGS Handling Ltd, Louis Travel Ltd, and Louis Aviation Ltd: Insufficient legal basis for data processing The decision found that the use of the Bradford factor for profiling and monitoring sick leave constituted unlawful processing of personal data in breach of Article 6 and Article… CYPRUS ·Art. 6, 9 ·Insufficient legal basis for data processing Integrity and Confidentiality Principle Audit Logs Fines Oct 25, 2019