Skip to content
Content type · 261 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 261 sort newestlargest fineoldest
€30,000 Garante: Bologna University Hospital rightly refused erasure of recruitment ranking data The DPA received a complaint from a data subject, regarding the ranking list published as part of a recruitment procedure at the Bologna University Hospital IRCCS (the… Italy ·Art. 5, 6, 9 Personal Data Retention Period Healthcare Sep 29, 2026
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Data Breaches Notification Obligation Controllers Sep 22, 2026
AEPD: Data subject entitled to identity of professionals who accessed medical records Suspecting unauthorised access to his medical records, a public civil servant, the data subject, requested the Ministry of Defence, the controller, to provide a log copy of… pd-00055-2026 ·Spain ·Art. 5, 12, 15 +2 Personal Data Healthcare Right of Access Sep 15, 2026
€3,150 APDCAT: Public body violated GDPR by disclosing audio recording to four extra recipients On 22 January 2025, an employee and trade union representative of a public-sector organisation, the data subject, emailed the DPO requesting access to and a copy of a recording of… Spain ·Art. 5, 6, 12 +1 Personal Data Right of Access Integrity and Confidentiality Principle Sep 15, 2026
€24,000 Friuli Centrale University Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) found that the Friuli Centrale University Health Authority (ASUFC) violated Articles 5(1)(f), 9, 25, and 32 of the GDPR based on a… Italy ·Garante ·Art. 5, 9, 25 +1 Integrity and Confidentiality Principle Data Breaches Right of Access Sep 3, 2026
€5,320 Slovenian DPA fines controller €5,320 for leaving employee personal data documents Paper documents containing the personal data of employees (the data subjects) were meant to be destroyed at a company (the controller). The personal data in these documents… Slovenia ·IP-RS ·Art. 5, 32 Personal Data Controllers Integrity and Confidentiality Principle Sep 1, 2026
RON 285,395 AMATO BESTSELLER S.R.L. A general wholesale/retail trade company (controller) failed to implement adequate technical and organisational measures, such as appropriate training of its employees, in order… Romania ·ANSPDCP ·Art. 5, 9, 12 +2 Integrity and Confidentiality Principle Personal Data Retention Period Aug 18, 2026
Finnish DPA examines anti-doping organization's GDPR compliance over public suspension An athlete (the data subject) gave a doping sample containing a low concentration of a banned substance in August 2020. The national anti-doping organisation (the controller)… TSV/179/2021 ·Finland ·Tietosuojavaltuutettu Supervisory Authorities Personal Data Retention Period Aug 4, 2026
€10,000 Bologna University Hospital IRCCS: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Bologna University Hospital IRCCS €10,000 for processing personal data without a sufficient legal basis. The Garante found… Italy ·Garante ·Art. 5, 6, 9 Legitimate Interest Healthcare Types of Special Categories of Personal Data Jul 23, 2026
€500,000 Hôpital privé de la Loire: Insufficient technical and organisational measures to ensure information security The French Data Protection Authority (CNIL) sanctioned Hôpital Privé de la Loire, a Ramsay Santé group hospital, following a June 2025 personal data breach in which an attacker… France ·CNIL ·Art. 32, 34 Data Breaches Notification Obligation Healthcare Jul 21, 2026
€12,000 Garante · 10254256 The data subject was an employee at a detention facility run by the Italian Ministry of Justice (the controller). Following an assessment by the occupational health physician, who… Italy ·Art. 4, 5, 6 +2 Personal Data Health Data Types of Special Categories of Personal Data
€200,000 Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first… PS-00020-2025 ·Spain ·AEPD Integrity and Confidentiality Principle Data Breaches Notification Obligation Jul 16, 2026
AEPD · EXP202102529 A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3 Consent Personal Data Healthcare
€10,000 Giuliano Isontina University Health Authority: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined the Giuliano Isontina University Health Authority €10,000 for failing to implement adequate technical and organizational… Italy ·Garante ·Art. 5, 9, 25 +1 Security Healthcare Types of Special Categories of Personal Data Jul 3, 2026
€450,000 VDAI fines medical company €450,000 for inadequate security measures in data breaches Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Lithuania ·Art. 5, 24 Security Data Breaches Integrity and Confidentiality Principle Jun 19, 2026
€450,000 InMedica UAB: Insufficient technical and organisational measures to ensure information security The Lithuanian Data Protection Authority (VDAI) fined InMedica UAB €450,000 for failing to implement sufficient technical and organizational measures to ensure information… Lithuania ·VDAI ·Art. 5, 24, 32 Integrity and Confidentiality Principle Security Personal Data Jun 19, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland ·DPC ·Art. 5, 28, 30 +2 Integrity and Confidentiality Principle Notification Obligation Data Breaches Jun 11, 2026
UODO reprimands hospital for inadequate processor oversight and email security failures The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Poland ·Art. 5, 24, 25 +3 Controllers Processors Security Jun 11, 2026
€70,518 IndaNext Hungary Kft. (legal successor of Blikk Kft.): Insufficient legal basis for data processing The Hungarian National Authority for Data Protection and the Freedom of Information (NAIH) fined IndaNext Hungary Kft., as legal successor to Blikk Kft., €70,518 for publishing… NAIH ·Art. 6, 9, 12 ·Insufficient legal basis for data processing Legitimate Interest Personal Data Controllers May 29, 2026
€700 Italian Red Cross: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Italian Red Cross €700 for violating general data processing principles under GDPR Articles 5(1)(c), 5(1)(f), and 9. The… Italy ·Garante ·Art. 5, 9 Integrity and Confidentiality Principle Retention Period Professional Secrecy May 28, 2026
€700 Garante · 385/2026 A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy ·Art. 5, 9 Personal Data Retention Period Integrity and Confidentiality Principle May 28, 2026
PLN 33,700 DKN.5131.27.2023 A municipal social welfare unit (the controller) processed the personal data of the residents of the municipality (the data subjects), including names, addresses, and information… Poland ·UODO ·Art. 5, 24, 25 +3 Data Breaches Integrity and Confidentiality Principle Notification Obligation May 19, 2026
€15,000 Monaldi-Cotugno-CTO: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined the Monaldi-Cotugno-CTO hospital entity €15,000 for violating general data processing principles under the GDPR. The… Italy ·Garante ·Art. 5, 9, 13 +2 Healthcare Types of Special Categories of Personal Data Security May 14, 2026
€12,000 Ministry of Justice: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Ministry of Justice €12,000 for insufficient legal basis for personal data processing. The enforcement action, decided on… Italy ·Garante ·Art. 5, 6, 9 Fairness & Transparency Personal Data Healthcare Apr 29, 2026
€5,000 Dr. Guzzo: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Dr. Guzzo €5,000 for processing personal data without a sufficient legal basis. The violation concerned healthcare data and… Italy ·Garante ·Art. 5, 9 Retention Period Controllers Healthcare Apr 29, 2026
€4,000 Montelibretti State Comprehensive School: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined Montelibretti State Comprehensive School €4,000 for lacking a sufficient legal basis for its data processing activities. The… Italy ·Garante ·Art. 5, 6, 9 Personal Data Healthcare Processing Apr 29, 2026
OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only… No. 2.1-1/24/397-890-38 ·Estonia ·AKI Controllers Processors Privacy by Design & Default Apr 16, 2026
€25,000 Municipality of Ede: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Ede. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Zoetermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Zoetermeer. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Tilburg: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Tilburg. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Eindhoven: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Eindhoven. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Veenendaal: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Hilversum: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Hilversum. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Huizen: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Huizen. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Delft: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Delft. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Gooise Meren: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Gooise Meren. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€10,000 Natural Person: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 10,000 on a natural person. The controller operated a website on which identity cards containing personal data, including special… ROMANIA ·ANSPDCP ·Art. 5, 6, 9 +6 Criminal Data Personal Data Types of Special Categories of Personal Data Jan 30, 2026
DSB Austria: disclosure of health data to court-appointed expert in legal dispute lawful The data subject was involved in a legal dispute before a civil court in which the findings of an expert opinion led to the dismissal of the case. The expert opinion concerned the… DSB-D124.0850/25 ·Art. 9 Health Data Healthcare Types of Special Categories of Personal Data Jan 28, 2026
€565,000 Sportadmin i Skandinavien AB: Insufficient technical and organisational measures to ensure information security The Swedish DPA has imposed a fine of EUR 565,500 on Sportadmin i Skandinavien AB. The controller suffered a sucessfull cyber attack, resulting in personal and special category… SWEDEN ·IMY ·Art. 32 Security Personal Data Controllers Jan 26, 2026
€5M FRANCE TRAVAIL: Insufficient technical and organisational measures to ensure information security The French DPA has imposed a fine of EUR 5,000,000 on FRANCE TRAVAIL. The controller suffered a successful cyber attack due to insufficient technical and organisational measures,… CNIL ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Jan 22, 2026
€200 A medical student (the controller) worked as a ward attendant at a hospital Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the nursing staff immediately when necessary. While assigned to a patient with… 2026-0.016.479 ·Austria ·DSB Legitimate Interest Personal Data Integrity and Confidentiality Principle Jan 12, 2026
€200 Medical Student: Insufficient legal basis for data processing The Austrian Data Protection Authority (dsb) fined a medical student €200 for processing personal data without a sufficient legal basis under GDPR Article 6(1)(f) and Article… Austria ·DSB ·Art. 6, 9 Legitimate Interest Types of Special Categories of Personal Data Personal Data Jan 12, 2026
€18,500 Commander of the Municipal Police of Krakow: Failure to Comply with General Data Protection Principles ⇄ 18.500 euro boete - Poolse nationale autoriteit voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Non-compliance with general data processing principles Law Enforcement Health Data Education Jan 9, 2026
€18,500 Komendanta Miejskiego Policji w Krakowie: Non-compliance with general data processing principles The Polish DPA has imposd a fine of EUR 18,500 on the Komendanta Miejskiego Policji w Krakowie. The controller published personal data, including health data, of a data subject… POLAND ·UODO ·Non-compliance with general data processing principles Personal Data Education Public Authority Jan 9, 2026
€10,000 Headquarter of a Fire Brigade: Insufficient legal basis for data processing The Greek DPA has imposed a fine of EUR 10,000 on a Fire Brigade Head Quarter. The controller had stored health data of an employee which had been in relation with her sick leave.… GREECE ·HDPA ·Art. 5 Controllers Processing Health Data Jan 8, 2026
€50,000 Social security institution: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 50.000 euro - van het Slowaakse databeschermingskantoor. SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Security Health Data Healthcare Dec 30, 2025
€1,000 'Principe Umberto di Savoia' State Scientific and Linguistic High School: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on 'Principe Umberto di Savoia' State Scientific and Linguistic High School. The controller processed the personal data of… ITALY ·Garante ·Art. 5, 6, 9 +2 Integrity and Confidentiality Principle Right of Access Controllers Dec 4, 2025
DSB · 2025-0.968.031 A data subject published a post concerning their ADHD diagnosis on a publicly accessible online forum under a pseudonym. A person (the controller) who was a follower of the data… 2025-0.968.031 ·Austria ·Art. 9 Pseudonymization Anonymization Health Data Dec 3, 2025
€4,750 Powiatowego Inspektora Sanitarnego w Policach: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 4750 on the Powiatowego Inspektora Sanitarnego w Policach. The controller failed to implement adequate technical and organisational… POLAND ·UODO ·Art. 5, 24, 25 +1 Security Encryption Controllers Nov 15, 2025