Content type · 55 documents in this view · 3,811 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3587 Processing 2635 Personal Data 2394 Controllers 2017 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
€10,000 AEPD fines MÁS SOL ENERGÍA for marketing call to Robinson List subscriber MÁS SOL ENERGÍA 15, S.L., the controller, is a company that carries out customer acquisition through telephone calls to offer solar panel installation services. On 18 November… Spain ·Art. 4, 5, 7 +1 Sep 16, 2026
€120 Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on The DPA received several complaints from data subjects concerning Experian Italia S.p.A (the controller) an Italian credit information system. The controller was processing the… Italy · ·Art. 5, 12, 15 +1 Sep 16, 2026
AEPD: Data subject entitled to identity of professionals who accessed medical records Suspecting unauthorised access to his medical records, a public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide a log copy of… pd-00055-2026 ·Spain ·Art. 5, 12, 15 +2 Sep 15, 2026
€408,000 AEPD: CaixaBank requested excessive inheritance documentation from heirs A data subject and other heirs were handling the inheritance of a deceased customer through CaixaBank, S.A., the controller. In the course of the inheritance procedure, the… Spain ·Art. 13, 25, 30 Sep 10, 2026
Finnish DPA orders Espoo to ensure pupil data protection in Google learning tools In April 2018, the DPA received a complaint stating that the city of Espoo (the controller) was using Google's digital learning tools in a school without obtaining consent from… TSV/40/2018 ·Finland · Sep 4, 2026
€5.5M Banco Bilbao Vizcaya Argentaria S.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) found Banco Bilbao Vizcaya Argentaria, S.A. (Italian branch) violated Articles 5(1)(a), 12, 21, and 24 of the GDPR by continuing to… Italy · ·Art. 5, 12, 21 +1 Sep 3, 2026
Datatilsynet reprimands Danish Tax Administration for access request delays (2019-2024) In November 2024 the DPA started an investigation against the Danish Tax Administration (‘the controller’) for their processing time of access requests. 30 September 2025 the DPA… 2024-432-0039 ·Denmark ·
€825M Uber Technologies Inc.: Non-compliance with general data processing principles The Dutch Supervisory Authority for Data Protection (AP) fined Uber Technologies Inc. €824,990,000 for non-compliance with general data processing principles, specifically… The Netherlands · ·Art. 13, 14, 22 Aug 21, 2026
€825M AP (The Netherlands) - Uber B.V and Uber Technologies Inc. Uber B.V. and Uber Technologies Inc., the controllers, used software between 2018 and 2022 to monitor drivers’ behaviour and customer ratings. Where the system detected suspected… Art. 22 Aug 21, 2026
HUF 2M NAIH-11443-3/2026 The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The… Hungary ·Art. 12, 13 Jul 22, 2026
€300,000 CNIL fines EXTIA for failing to properly handle job applicant erasure requests EXTIA, the controller, is a French consulting company specialising in IT and engineering services. As part of its recruitment activities, the controller processed personal data of… France ·Art. 12, 17 Jul 21, 2026
€1M CNIL · SAN-2022-011 The controller is a limited liability company whose business is the supply and production of electricity and gas in France. Several data subjects sent complainants to the French… France ·Art. 12, 14, 15 +2
€2M Garante fines Lusha Systems Inc. over unauthorized B2B contact database Lusha Systems Inc. (the controller) operated a subscription-based platform that provided professional contact information through a business-to-business (B2B) database. It was a… Italy ·Art. 3, 5, 6 +2 Jul 14, 2026
€158,000 Garante · 487/2026 Character Technologies, Inc (the controller) is a company established in the US that operates the site Character.AI. Character.AI is a generative AI service that allows users to… Italy ·Art. 3, 5, 12 +7 Jul 3, 2026
€1.4M Garante · 484/2026 EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller… Italy ·Art. 5, 13, 14 +2 Jul 3, 2026
€5.8M 483/2026 Several data subjects lodged complaints with the Italian DPA (Garante) after Hera Comm S.p.A., an energy supplier (the controller), declined to conclude electricity or gas… Italy · ·Art. 5, 12, 13 +3 Jul 3, 2026
€6,600 Garante · 462/2026 The case involves a worker (the data subject), his former employer (the controller), and the staffing agency that had provided the company with the worker. In late 2023 the data… Italy ·Art. 2, 4, 5 +2 Jun 18, 2026
HDPA · 12/2026 The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Greece ·Art. 23 May 13, 2026
HUF 15M NAIH-450-7-2026 The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 May 12, 2026
HUF 10M NAIH-4462-5-2026 The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Apr 30, 2026
€400,000 Italian DPA finds Cerved Group failed to disclose creditworthiness scores in Art. 15 The DPA received several complaints from data subjects concerning Cerved Group S.p.A. (the controller) an Italian credit rating agency. The controller was processing the personal… Italy · ·Art. 5, 12, 15 +3 Mar 7, 2026
Slovenian DPA: Controller breached Art. 32, 15 and 34 GDPR over data breach and access A controller, not named in the original decision but presumed to be a public institution, notified the Slovenian DPA after experiencing a data breach in relation to its website.… 0612-91/2025/40 ·Slovenia · Mar 4, 2026
The controller, an Austrian registered association, operates a therapy centre for psychosomatic illnesses The data subject was a patient of the controller. On 28 July 2025, the data subject sent an access request by email under Article 15 GDPR, asking for full information on all… DSB-D124.2437/25 ·Austria · Jan 9, 2026
€72,000 AEPD · PS-00480-2025 Tiger Media Inc., the controller, operated an advertising platform for publishers and advertisers of adult products and services. The platform acted as an ad network, connecting… Spain ·Art. 6, 27 Nov 14, 2025
€135,600 Company: Insufficient technical and organisational measures to ensure information security The Polish DPA fined a company in the banking sector EUR 135,600. The DPA inspected the fined company and found several violations of the GDPR. First, the company failed to ensure… POLAND · ·Art. 30, 35, 38 Dec 18, 2024
DSB-D124.5337 In August 2021, an unprotected Excel file containing the names and PCR test results of several thousand individuals was sent from the compromised email account of the first data… 2023-0.273.912 ·Austria ·Art. 5, 6, 12 +3 Oct 6, 2023
€1.1M Bonnier News AB: Insufficient legal basis for data processing The Swedish DPA has imposed a fine of EUR 1.1 million on Bonnier News AB. During its investigation, the DPA found that Bonnier News collects customer data, for example, through… SWEDEN ·Art. 6 ·Insufficient legal basis for data processing Jun 26, 2023
€300,000 Rinascente S.p.A.: Non-compliance with general data processing principles The Italian DPA has fined Rinascente S.p.A. EUR 300,000. The DPA acted on a complaint from a customer who, following an incident with a store employee, had her long-standing… ITALY · ·Art. 5, 12, 32 +1 Jun 8, 2023
€4.9M Edison Energia S.p.A.: Non-compliance with general data processing principles The Italian DPA has fined Edison Energia S.p.A. EUR 4.9 million. Several person had filed complaints with the DPA regarding unlawful marketing activities of the company. During… ITALY · ·Art. 5, 6, 7 +4 Dec 15, 2022
€55,000 Azienda Universitaria Giuliano Isontina: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Giuliano Isontina . The health authority has created patient profiles using algorithms and personal… ITALY · ·Art. 2, 5, 9 +2 Dec 15, 2022
€55,000 Azienda Universitaria Friuli Centrale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Friuli Centrale. The health authority has created patient profiles using algorithms and personal patient… ITALY · ·Art. 2, 5, 9 +2 Dec 15, 2022
€55,000 Azienda Universitaria Friuli Occidentale: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 55,000 on Azienda Universitaria Friuli Occidentale. The health authority has created patient profiles using algorithms and personal… ITALY · ·Art. 2, 5, 9 +2 Dec 15, 2022
€900 LfD (Lower Saxony) - Fine EUR 900,000 against bank A commercial bank (controller) used personal data of current and former customers (data subjects) to identify customers with an affinity for digital media usage, in order to… Germany ·Art. 6
NAIH: School grades are personal data; failure to provide access in eKRÉTA system A minor student (the data subject) alleged that his grade had been amended before the semester grading meeting without notification. The parent of the data subject requested… NAIH-4667-10/2022 ·Hungary ·Art. |, 10, 28 +1 Sep 22, 2022
Belgian DPA: Legitimate interest can justify direct marketing to recent former customers The data subject was a former customer of the controller (which remained unknown). The data subject received direct marketing from the controller. The data subject objected to the… 117/2022 ·Belgium · Jul 26, 2022
Belgian DPA: Employer unlawfully disclosed employee health data to colleagues (115/2022) During a meeting where the data subject was not present, the data subject's manager (controller) announced her departure and read out a document issued by the company doctor,… 115/2022 ·Belgium · Jul 19, 2022
Italy Garante: TikTok switch to legitimate interest for personalized ads violates Social media platform TikTok (the controller) provided personalized advertising to its users (the data subjects) on the legal basis of consent (Article 6(1)(a) GDPR). In June… 9788429 ·Art. 5, 6, 122 Jul 7, 2022
DSB · 2021-0.643.804 The data subject divorced her husband in a proceeding before the district court (the controller), acting in its capacity as the competent land registry court. As part of the… 2021-0.643.804 ·Austria ·Art. 6, 55 Jun 9, 2022
AEPD admits claim against Securitas Direct for failure to handle access and erasure Resolution No. R/00665/2022 is highlighted by a case concerning a claimant (namely A.A.A) and a respondent party (namely Securitas Direct España, S.A). The claimant filed against… R/00665/2022 ·Spain ·Art. 17, 55 Apr 22, 2022
€2,800 EU DisinfoLab: Non-compliance with general data processing principles The Belgian DPA has fined the NGO EU DisinfoLab EUR 2,700. In 2018, the NGO published an analysis to identify the possible political origin of tweets circulating on a particularly… BELGIUM · ·Art. 5, 6, 9 +5 Jan 27, 2022
BfDI: Telekom must name all recipients, data origin and deletion dates in Art. 15 replies The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject… 24-191 II#4781 ·Germany ·Art. 15, 20, 95 Jan 27, 2022
€1,200 Researcher: Non-compliance with general data processing principles The Belgian DPA has fined a researcher EUR 1,200. The fine was issued in connection with another fine against the NGO EU DisinfoLab. The researcher was employed at the NGO. In… BELGIUM · ·Art. 5, 6, 9 +3 Jan 27, 2022
APD/GBA · 11/2022 The respondent owns a website 'YourOnlineChoices', through which data subjects can control their ad experience online. When browsing the web and visiting different websites, they… 11/2022 ·Belgium ·Art. 4, 5, 7 +2 Jan 21, 2022
€3M CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 3,000,000 on CAIXABANK PAYMENTS & CONSUMER EFC, EP, S.A.U.. An individual had filed a complaint against the controller. The reason… SPAIN · ·Art. 6 Oct 21, 2021
€500,000 Unser Ö-Bonus Club GmbH: Insufficient legal basis for data processing The Austrian DPA has imposed a fine of EUR 2,000,000 on Rewe affiliate Ö-Bonus Club GmbH. When signing up for the customer loyalty program jö Bonus Club, the controller is said to… AUSTRIA · ·Art. 6, 7, 12 Aug 2, 2021
€50,000 Caixabank S.A.: Insufficient legal basis for data processing The Spanish DPA (AEPD) has imposed a fine of EUR 50,000 on Caixabank S.A.. A data subject had filed a complaint with the DPA because he had received commercial advertising from… SPAIN · ·Art. 6 Jul 8, 2021
€40,000 Electricity Authority of Cyprus: Insufficient legal basis for data processing The Cypriot DPA imposed a fine of EUR 40,000 on the Electricity Authority of Cyprus. The controller used an automated system based on the so-called Brad-Factor to manage, monitor… ·Art. 6, 9 ·Insufficient legal basis for data processing Mar 3, 2021
DSB Austria: Restaurant contact-tracing data collected for COVID-19 qualifies as health The data subject (customer) filed a complaint against a Viennese restaurant claiming a violation of § 1 Austrian Data Protection Act (Datenschutzgesetz - DSG) and Article 6 GDPR:… 2020-0.743.659 ·Art. 4, 5, 6 +1 Nov 19, 2020
€30,000 PS/00032/2020 A user of the website of Iberia, an airline, lodged a complaint before the Spanish DPA (AEPD) saying that they had not been given an option to reject the cookies when using the… Spain · ·Art. 22 Oct 16, 2020
Datatilsynet (Norway)- 20/02254 The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app.… 20/02254 (Grindr) · ·Art. 57, 58 Sep 7, 2020