Content type · 332 documents in this view · 3,634 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities3564 Processing Agreement2800 Processing2632 Personal Data2596 Controllers2211 Data Controller1862 Law Enforcement1540 IP Address1282 Security1024 Supervision879 Monitoring545 Consent518
€20,000 Italian DPA: Enna Health Authority violated GDPR by publishing judicial data The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Italy · ·Art. 5, 6, 10 +1 Jul 18, 2026
AEPD investigates University of Navarra over student COVID-19 vaccination status requests A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3 Jul 16, 2026
Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… 2025010358 ·Iceland · Jul 1, 2026
€450,000 VDAI (Lithuania) - 3R-1143 Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Art. 5, 24 Jun 19, 2026
UODO (Poland) - DKN.5131.12.2022 The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Art. 5, 24, 25 +3 Jun 11, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland ·Art. 5, 28, 30 +2 ·Insufficient technical and organisational measures to ensure information security Jun 11, 2026
€700 Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy · ·Art. 5, 9 May 28, 2026
€6,000 Italian DPA: vehicle tracking by Liguria Health Agency lawful, information duties met A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller). The data subject was employed by the Ligurian Social and Health Care… Italy · ·Art. 5, 6, 13 +3 May 28, 2026
HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Art. 23 May 13, 2026
AKI (Estonia) - No. 2.1-1/24/397-890-38 OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to… No. 2.1-1/24/397-890-38 ·Art. 4, 5, 6 +8 Apr 16, 2026
€2,000 Copacabana s.r.l.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Copacabana s.r.l. €2,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy · ·Art. 5, 13, 88 Mar 26, 2026
€2,000 Hanako s.r.l.: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) fined Hanako s.r.l. €2,000 on 2026-03-12 for: Insufficient technical and organisational measures to ensure information security. Italy · ·Art. 5, 13, 32 Mar 12, 2026
€2,000 MALAGASUITE SHOWROOM, S.L.: Insufficient fulfilment of data subjects rights Spanish Data Protection Authority (aepd) fined MALAGASUITE SHOWROOM, S.L. €2,000 on 2026-03-02 for: Insufficient fulfilment of data subjects rights. Spain · ·Art. 13 Mar 2, 2026
€1,500 Sole Trader: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Sole Trader €1,500 on 2026-02-12 for: Insufficient legal basis for data processing. Italy · ·Art. 5, 13, 25 Feb 12, 2026
€2,000 Sole Trader: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Sole Trader €2,000 on 2026-02-12 for: Insufficient legal basis for data processing. Italy · ·Art. 5, 6, 13 +1 Feb 12, 2026
€1,800 Landlord: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,800 on a Landlord. The landlord used video surveillance in rental apartments without having a sufficient legal basis. The original fine… SPAIN · ·Art. 6 Feb 6, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PREMIER RESTAURANTS ROMANIA SRL. The controller failed to implement adequate technical and organisational measures, resulting… ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Jan 13, 2026
€200 DSB: Medical student fined for recording dementia patient video without Art 9 GDPR basis A medical student (the controller) worked as a ward attendant at a hospital. Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the… Austria ·Art. 4, 5, 6 +1 Jan 12, 2026
€18,500 Commandant van de Stedelijke Politie van Krakau: Niet-naleving van de algemene principes voor gegevensverwerking. 18.500 euro boete - Poolse nationale autoriteit voor de bescherming van persoonlijke gegevens (UODO). POLAND · ·Non-compliance with general data processing principles Jan 9, 2026
€10,000 Headquarter of a Fire Brigade: Insufficient legal basis for data processing The Greek DPA has imposed a fine of EUR 10,000 on a Fire Brigade Head Quarter. The controller had stored health data of an employee which had been in relation with her sick leave.… GREECE · ·Art. 5 Jan 8, 2026
€50,000 Sociale verzekeringsinstantie: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 50.000 euro - van het Slowaakse databeschermingskantoor. SLOVAKIA · ·Art. 32 Dec 30, 2025
€2,000 Order of General Nurses, Midwives and Medical Assistants of Romania – Neamt Branch: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 2,000 on the Order of General Nurses, Midwives and Medical Assistants of Romania – Neamt Branch. The controller used video surveillance… ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Dec 29, 2025
€2,000 Orde van Algemene Verpleegkundigen, Verloskundigen en Medische Assistenten van Roemenië – Afdeling Neamt: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 5, 6, 12 +1 Dec 29, 2025
€6,000 Geturhotels Srl: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 6,000 on Geturhotels Srl. The controller was involved in direct marketing operations, using personal data that had not been acquired or… ITALY · ·Art. 5, 6, 17 +1 Dec 23, 2025
€32,000 EXCEL HOTELS & RESORTS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on EXCEL HOTELS & RESORTS, S.A. The controller used guards to control access to its facility. The guards regularly left documents… SPAIN · ·Art. 5 Dec 20, 2025
€1,000 'Principe Umberto di Savoia' State Scientific and Linguistic High School: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on 'Principe Umberto di Savoia' State Scientific and Linguistic High School. The controller processed the personal data of… ITALY · ·Art. 5, 6, 9 +2 Dec 4, 2025
€5,000 ACTIVOS INTELIGENTES, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5,000 on ACTIVOS INTELIGENTES, S.L. The controller is asking its guests for selfies with their ID-card to verify their identity,… SPAIN · ·Art. 5 Nov 23, 2025
€1.2M IDCQ HOSPITALES Y SANIDAD, S.L.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,200,000 on IDCQ HOSPITALES Y SANIDAD, S.L.U. The controller offered MRI scans as part of its services, and patients could bring copies… SPAIN · ·Art. 6, 9, 25 Nov 21, 2025
€800 SOBLADA RESTAURACIÓN, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 800 on SOBLADA RESTAURACIÓN, S.L. The controller installed video surveillance without providing the necessary information signs or… SPAIN · ·Art. 5, 13 Nov 19, 2025
€2,400 AXARQUIA VELEZ DENTAL, S.L.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.400 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN · ·Art. 5 Nov 14, 2025
€6,000 APARELLS ORTOPEDICS CURTO, S.L: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 6.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN · ·Art. 5 Oct 28, 2025
€9,450 Gynaecologisch centrum: Onvoldoende naleving van de verplichtingen om datalekken te melden. Boete van €9.450 - Pools Nationaal Bureau voor de Bescherming van Persoonsgegevens (UODO). POLAND · ·Insufficient fulfilment of data breach notification obligations Oct 27, 2025
€6,000 Interprovinciale organisatie van medische radiologie-technici en technisch gezondheidspersoneel in revalidatie en preventie in de regio's AQ, CH, PE en TE: Onvoldoende wettelijke basis voor gegevensverwerking. Een boete van 6.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 37 Oct 9, 2025
€16,000 Orde van Verpleegkundigen van Pisa: Onvoldoende wettelijke basis voor gegevensverwerking. Een boete van 16.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6 Oct 9, 2025
€6,000 Interprovincial Order of Medical Radiology Technicians and Technical Health Professions in Rehabilitation and Prevention of AQ - CH - PE - TE: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Interprovincial Order of Medical Radiology Technicians and Technical Health Professions in Rehabilitation and Prevention of… ITALY · ·Art. 5, 6, 37 Oct 9, 2025
€1,000 Dr. Max SRL: Onvoldoende naleving van de rechten van betrokkenen. 1.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 12, 17 Sep 18, 2025
€2,670 POLEN, Autoriteit voor gegevensbescherming: Gebrek aan benoeming van een functionaris voor gegevensbescherming. Een boete van 2.670 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND · ·Art. 38 Sep 12, 2025
€12,000 Casa di Cura Città di Roma: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 12.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 9, 25 +1 Sep 11, 2025
€42,000 WORLD 2 MEET, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 42,000 on WORLD 2 MEET, S.L. The controller requires its guests to provide a copy of their identity card or passport for registration… SPAIN · ·Art. 5 Aug 14, 2025
€1,000 Orde van biochemici, biologen en chemici in het Roemeense gezondheidszorgsysteem: Onvoldoende naleving van de rechten van betrokkenen. 1.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 12, 15 Aug 5, 2025
€80,000 Ospedaliero-Universitaria Careggi: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 80,000 on the Ospedaliero-Universitaria Careggi. The controller, a university hospital, used software that allowed medical personnel to… ITALY · ·Art. 5, 9, 25 +1 Aug 4, 2025
€80,000 Ospedaliero-Universitaria Careggi: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 9, 25 +1 Aug 4, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor gegevensbescherming (Garante). ITALY · ·Art. 5 Aug 4, 2025
€5,400 SUNERIS, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5,400 on SUNERIS, S.A. The controller processed scans of ID cards and passports of their guests, infringing the principle of data… SPAIN · ·Art. 5 Jul 16, 2025
€50,000 Magna PT S.p.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 9 +2 Jul 10, 2025
€50,000 Magna PT S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine on Magna PT S.p.A. Employees of the controllers were subjected to 'return to work interviews' after returning from an absence due to illness or… ITALY · ·Art. 5, 6, 9 +2 Jul 10, 2025
€15,600 Kinderziekenhuis van de L. Zamenhof Universiteit in Białystok: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 15.600 euro boete - Poolse nationale instantie voor de bescherming van persoonlijke gegevens (UODO). POLAND · ·Art. 5, 32 Jun 30, 2025
€15,600 L. Zamenhof University Children's Clinical Hospital in Białystok: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 15,600 on the L. Zamenhof University Children's Clinical Hospital in Białystok. The controller did not implement sufficient technical and… POLAND · ·Art. 5, 32 Jun 30, 2025
€7,000 General Hospital of the University of Larissa: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 7,000 on the General Hospital of the University of Larissa. The controller failed to adequately fulfil the rights of data subjects. It… GREECE · ·Art. 5, 14, 15 Jun 24, 2025
€10,000 Shield of David - K.I.D.A.F.: Niet-naleving van algemene principes voor gegevensverwerking. Boete van €10.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE · ·Art. 5, 12, 13 +3 Jun 24, 2025