Skip to content
Content type · 332 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 332 sort newestlargest fineoldest
€20,000 Italian DPA: Enna Health Authority violated GDPR by publishing judicial data The provincial Health Authority of Enna (the controller) published a resolution that contained the personal data of a data subject (specifically related to their judicial… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 10 +1 Personal Data Fairness & Transparency Right to Restriction Jul 18, 2026
AEPD investigates University of Navarra over student COVID-19 vaccination status requests A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3 Consent Healthcare Health Data Jul 16, 2026
Persónuvernd examines BL ehf over alleged unlawful employee monitoring via shared OneDrive The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… 2025010358 ·Iceland ·Island Monitoring Integrity and Confidentiality Principle Cloud Computing Jul 1, 2026
€450,000 VDAI (Lithuania) - 3R-1143 Two medical companies (the controllers) had fallen victim to data breaches where a third party had gained access to their internal systems containing both health data and other… Art. 5, 24 Security Data Breaches Access Controls Jun 19, 2026
UODO (Poland) - DKN.5131.12.2022 The email account of an employee at a provincial specialist hospital (the controller) was hacked in December 2021. The compromised email account contained e.g. names, addresses,… DKN.5131.12.2022 ·Art. 5, 24, 25 +3 DPIA Data Breaches Security Jun 11, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland ·Art. 5, 28, 30 +2 ·Insufficient technical and organisational measures to ensure information security Notification Obligation Data Breaches Healthcare Jun 11, 2026
€700 Italian Garante: Red Cross violated Art. 9 GDPR by disclosing HIV status on meal tray A data subject brought a complaint to the DPA through a non-profit organisation (LILA) against the Italian Red Cross (the controller). While the data subject was hospitalised,… Italy ·Garante per la protezione dei dati personali ·Art. 5, 9 Personal Data Healthcare Integrity and Confidentiality Principle May 28, 2026
€6,000 Italian DPA: vehicle tracking by Liguria Health Agency lawful, information duties met A data subject filed a complaint before the DPA against the Liguria Health Protection Agency (the controller). The data subject was employed by the Ligurian Social and Health Care… Italy ·Garante per la protezione dei dati personali ·Art. 5, 6, 13 +3 DPIA Privacy by Design Monitoring May 28, 2026
HDPA (Greece) examines deletion request from National Registry of Undesirable Aliens The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Art. 23 Personal Data Controllers Processing May 13, 2026
AKI (Estonia) - No. 2.1-1/24/397-890-38 OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic. On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to… No. 2.1-1/24/397-890-38 ·Art. 4, 5, 6 +8 Controllers Processors Data Controller Apr 16, 2026
€2,000 Copacabana s.r.l.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Copacabana s.r.l. €2,000 on 2026-03-26 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 13, 88 Processing Supervisory Authorities Healthcare Mar 26, 2026
€2,000 Hanako s.r.l.: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) fined Hanako s.r.l. €2,000 on 2026-03-12 for: Insufficient technical and organisational measures to ensure information security. Italy ·Garante ·Art. 5, 13, 32 Security Supervisory Authorities Healthcare Mar 12, 2026
€2,000 MALAGASUITE SHOWROOM, S.L.: Insufficient fulfilment of data subjects rights Spanish Data Protection Authority (aepd) fined MALAGASUITE SHOWROOM, S.L. €2,000 on 2026-03-02 for: Insufficient fulfilment of data subjects rights. Spain ·aepd ·Art. 13 Personal Data Supervisory Authorities Healthcare Mar 2, 2026
€1,500 Sole Trader: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Sole Trader €1,500 on 2026-02-12 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 13, 25 Processing Telecommunications Supervisory Authorities Feb 12, 2026
€2,000 Sole Trader: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Sole Trader €2,000 on 2026-02-12 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6, 13 +1 Processing Telecommunications Supervisory Authorities Feb 12, 2026
€1,800 Landlord: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 1,800 on a Landlord. The landlord used video surveillance in rental apartments without having a sufficient legal basis. The original fine… SPAIN ·aepd ·Art. 6 Video Surveillance Controllers Monitoring Feb 6, 2026
€8,000 PREMIER RESTAURANTS ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 8,000 on PREMIER RESTAURANTS ROMANIA SRL. The controller failed to implement adequate technical and organisational measures, resulting… ANSPDCP ·Art. 28, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Law Enforcement Jan 13, 2026
€200 DSB: Medical student fined for recording dementia patient video without Art 9 GDPR basis A medical student (the controller) worked as a ward attendant at a hospital. Her duties were to remain in the immediate vicinity of patients, ensure their safety and notify the… Austria ·Art. 4, 5, 6 +1 Legitimate Interest Personal Data Healthcare Jan 12, 2026
€18,500 Commandant van de Stedelijke Politie van Krakau: Niet-naleving van de algemene principes voor gegevensverwerking. 18.500 euro boete - Poolse nationale autoriteit voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Non-compliance with general data processing principles Health Data Education Personal Data NL Jan 9, 2026
€10,000 Headquarter of a Fire Brigade: Insufficient legal basis for data processing The Greek DPA has imposed a fine of EUR 10,000 on a Fire Brigade Head Quarter. The controller had stored health data of an employee which had been in relation with her sick leave.… GREECE ·HDPA ·Art. 5 Healthcare Health Data Healthcare Jan 8, 2026
€50,000 Sociale verzekeringsinstantie: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 50.000 euro - van het Slowaakse databeschermingskantoor. SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Health Data Security Healthcare NL Dec 30, 2025
€2,000 Order of General Nurses, Midwives and Medical Assistants of Romania – Neamt Branch: Non-compliance with general data processing principles The Romanian DPA has imposed a fine of EUR 2,000 on the Order of General Nurses, Midwives and Medical Assistants of Romania – Neamt Branch. The controller used video surveillance… ANSPDCP ·Art. 5, 6, 12 +1 ·Non-compliance with general data processing principles Video Surveillance Monitoring Employees Dec 29, 2025
€2,000 Orde van Algemene Verpleegkundigen, Verloskundigen en Medische Assistenten van Roemenië – Afdeling Neamt: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 5, 6, 12 +1 Video Surveillance Processing Security NL Dec 29, 2025
€6,000 Geturhotels Srl: Non-compliance with general data processing principles The Italian DPA has imposed a fine of EUR 6,000 on Geturhotels Srl. The controller was involved in direct marketing operations, using personal data that had not been acquired or… ITALY ·Garante ·Art. 5, 6, 17 +1 Controllers IP Address Direct Marketing Dec 23, 2025
€32,000 EXCEL HOTELS & RESORTS, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 32,000 on EXCEL HOTELS & RESORTS, S.A. The controller used guards to control access to its facility. The guards regularly left documents… SPAIN ·aepd ·Art. 5 Security Controllers Personal Data Dec 20, 2025
€1,000 'Principe Umberto di Savoia' State Scientific and Linguistic High School: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 1,000 on 'Principe Umberto di Savoia' State Scientific and Linguistic High School. The controller processed the personal data of… ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Right of Access Dec 4, 2025
€5,000 ACTIVOS INTELIGENTES, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5,000 on ACTIVOS INTELIGENTES, S.L. The controller is asking its guests for selfies with their ID-card to verify their identity,… SPAIN ·aepd ·Art. 5 IP Address Controllers Processing Agreement Nov 23, 2025
€1.2M IDCQ HOSPITALES Y SANIDAD, S.L.U.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 1,200,000 on IDCQ HOSPITALES Y SANIDAD, S.L.U. The controller offered MRI scans as part of its services, and patients could bring copies… SPAIN ·aepd ·Art. 6, 9, 25 Healthcare IP Address Healthcare Nov 21, 2025
€800 SOBLADA RESTAURACIÓN, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 800 on SOBLADA RESTAURACIÓN, S.L. The controller installed video surveillance without providing the necessary information signs or… SPAIN ·aepd ·Art. 5, 13 Video Surveillance Monitoring Controllers Nov 19, 2025
€2,400 AXARQUIA VELEZ DENTAL, S.L.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.400 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Health Data Video Surveillance Processing NL Nov 14, 2025
€6,000 APARELLS ORTOPEDICS CURTO, S.L: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 6.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Health Data Healthcare Data Controller NL Oct 28, 2025
€9,450 Gynaecologisch centrum: Onvoldoende naleving van de verplichtingen om datalekken te melden. Boete van €9.450 - Pools Nationaal Bureau voor de Bescherming van Persoonsgegevens (UODO). POLAND ·UODO ·Insufficient fulfilment of data breach notification obligations Data Breaches Health Data Healthcare NL Oct 27, 2025
€16,000 Orde van Verpleegkundigen van Pisa: Onvoldoende wettelijke basis voor gegevensverwerking. Een boete van 16.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Health Data Healthcare Healthcare NL Oct 9, 2025
€6,000 Interprovincial Order of Medical Radiology Technicians and Technical Health Professions in Rehabilitation and Prevention of AQ - CH - PE - TE: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Interprovincial Order of Medical Radiology Technicians and Technical Health Professions in Rehabilitation and Prevention of… ITALY ·Garante ·Art. 5, 6, 37 Healthcare Controllers Healthcare Oct 9, 2025
€1,000 Dr. Max SRL: Onvoldoende naleving van de rechten van betrokkenen. 1.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 17 Right to be Forgotten Health Data Personal Data NL Sep 18, 2025
€2,670 POLEN, Autoriteit voor gegevensbescherming: Gebrek aan benoeming van een functionaris voor gegevensbescherming. Een boete van 2.670 euro - van het Poolse nationale bureau voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 38 Health Data Supervisory Authorities Professional Secrecy NL Sep 12, 2025
€12,000 Casa di Cura Città di Roma: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 12.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9, 25 +1 Health Data Healthcare Security NL Sep 11, 2025
€42,000 WORLD 2 MEET, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 42,000 on WORLD 2 MEET, S.L. The controller requires its guests to provide a copy of their identity card or passport for registration… SPAIN ·aepd ·Art. 5 IP Address Controllers Processing Agreement Aug 14, 2025
€1,000 Orde van biochemici, biologen en chemici in het Roemeense gezondheidszorgsysteem: Onvoldoende naleving van de rechten van betrokkenen. 1.000 euro boete - Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Health Data Right of Access Procedures Healthcare NL Aug 5, 2025
€80,000 Ospedaliero-Universitaria Careggi: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 80,000 on the Ospedaliero-Universitaria Careggi. The controller, a university hospital, used software that allowed medical personnel to… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Healthcare Security Aug 4, 2025
€80,000 Ospedaliero-Universitaria Careggi: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9, 25 +1 Health Data Healthcare Security NL Aug 4, 2025
€2,000 Linea Stampalibera Società Cooperativa r.I.: Niet-naleving van de algemene principes voor gegevensverwerking. Een boete van 2.000 euro - opgelegd door de Italiaanse Autoriteit voor gegevensbescherming (Garante). ITALY ·Garante ·Art. 5 Health Data Healthcare Processing NL Aug 4, 2025
€5,400 SUNERIS, S.A.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 5,400 on SUNERIS, S.A. The controller processed scans of ID cards and passports of their guests, infringing the principle of data… SPAIN ·aepd ·Art. 5 Retention Period IP Address Controllers Jul 16, 2025
€50,000 Magna PT S.p.A.: Onvoldoende juridische basis voor de verwerking van gegevens. Een boete van 50.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Data Controller NL Jul 10, 2025
€50,000 Magna PT S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine on Magna PT S.p.A. Employees of the controllers were subjected to 'return to work interviews' after returning from an absence due to illness or… ITALY ·Garante ·Art. 5, 6, 9 +2 Health Data Healthcare Controllers Jul 10, 2025
€15,600 Kinderziekenhuis van de L. Zamenhof Universiteit in Białystok: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 15.600 euro boete - Poolse nationale instantie voor de bescherming van persoonlijke gegevens (UODO). POLAND ·UODO ·Art. 5, 32 Security Healthcare Health Data NL Jun 30, 2025
€15,600 L. Zamenhof University Children's Clinical Hospital in Białystok: Insufficient technical and organisational measures to ensure information security The Polish DPA has imposed a fine of EUR 15,600 on the L. Zamenhof University Children's Clinical Hospital in Białystok. The controller did not implement sufficient technical and… POLAND ·UODO ·Art. 5, 32 Healthcare Security Healthcare Jun 30, 2025
€7,000 General Hospital of the University of Larissa: Insufficient fulfilment of data subjects rights The Hellenic DPA has imposed a fine of EUR 7,000 on the General Hospital of the University of Larissa. The controller failed to adequately fulfil the rights of data subjects. It… GREECE ·HDPA ·Art. 5, 14, 15 Healthcare Healthcare Controllers Jun 24, 2025
€10,000 Shield of David - K.I.D.A.F.: Niet-naleving van algemene principes voor gegevensverwerking. Boete van €10.000 - Griekse Autoriteit voor Gegevensbescherming (HDPA). GREECE ·HDPA ·Art. 5, 12, 13 +3 Personal Data Health Data Video Surveillance NL Jun 24, 2025