Skip to content
Content type · 179 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 179 sort newestlargest fineoldest
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Data Breaches Notification Obligation Controllers Sep 22, 2026
€3,150 APDCAT: Public body violated GDPR by disclosing audio recording to four extra recipients On 22 January 2025, an employee and trade union representative of a public-sector organisation, the data subject, emailed the DPO requesting access to and a copy of a recording of… Spain ·Art. 5, 6, 12 +1 Personal Data Right of Access Integrity and Confidentiality Principle Sep 15, 2026
€200,000M 15/2026 The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information… Greece ·HDPA ·Art. 5, 28, 32 Controllers Data Breaches Integrity and Confidentiality Principle Jul 28, 2026
€300,000 CNIL fines EXTIA for failing to properly handle job applicant erasure requests EXTIA, the controller, is a French consulting company specialising in IT and engineering services. As part of its recruitment activities, the controller processed personal data of… France ·Art. 12, 17 Personal Data Right to be Forgotten Right to Restriction Jul 21, 2026
€12,000 Garante · 10254256 The data subject was an employee at a detention facility run by the Italian Ministry of Justice (the controller). Following an assessment by the occupational health physician, who… Italy ·Art. 4, 5, 6 +2 Personal Data Health Data Types of Special Categories of Personal Data
€200,000 Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first… PS-00020-2025 ·Spain ·AEPD Integrity and Confidentiality Principle Data Breaches Notification Obligation Jul 16, 2026
Persónuvernd (Island) - 2025010358 The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… 2025010358 ·Iceland ·Art. 5, 32 Integrity and Confidentiality Principle Monitoring Personal Data Jul 1, 2026
€6,600 Cosmint S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Cosmint S.p.A. €6,600 for violating general data processing principles in the employment sector, specifically under Articles… Italy ·Garante ·Art. 5, 6, 13 Retention Period Supervision Supervisory Authorities Jun 18, 2026
€6,000 Liguria Health Protection Authority: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Liguria Health Protection Authority €6,000 for lacking a sufficient legal basis for personal data processing in the… Italy ·Garante ·Art. 5, 6, 25 +2 Controllers Retention Period Processing May 28, 2026
PLN 21,000 DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Poland ·UODO ·Art. 24, 25, 28 +1 Integrity and Confidentiality Principle Security Controllers May 25, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·DPC ·Art. 5, 32, 33 Integrity and Confidentiality Principle Notification Obligation Data Breaches May 8, 2026
The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025 They worked as a manager in the controller’s finance department, with technical and disciplinary responsibility for up to five employees. The controller operated a 360-degree… 2025-0.960.016 ·Austria ·DSB Legitimate Interest Personal Data Controllers Mar 20, 2026
€17M Reddit, Inc.: Non-compliance with general data processing principles Information Commissioner (ICO) fined Reddit, Inc. €16,610,000 on 2026-02-23 for: Non-compliance with general data processing principles. United Kingdom ·ICO ·Art. 5, 6, 8 +1 Processing IP Address Telecommunications Feb 23, 2026
€150,000 The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested a duplicate SIM card for the mobile line of a data subject. The request was… EXP202306354 (PS/00312/2024) ·Spain ·Art. 5, 6 Integrity and Confidentiality Principle Personal Data Controllers Feb 11, 2026
€25,000 Municipality of Gooise Meren: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Gooise Meren. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Hilversum: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Hilversum. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Eindhoven: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Eindhoven. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Huizen: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Huizen. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Ede: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Ede. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Zoetermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Zoetermeer. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Veenendaal: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Delft: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Delft. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€25,000 Municipality of Tilburg: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Tilburg. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS ·AP ·Art. 6, 9 Controllers Healthcare Personal Data Feb 3, 2026
€1,500 10214411 The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of security… Italy ·Garante ·Art. 5, 6, 13 +2 Fairness & Transparency Controllers Transparency Jan 16, 2026
€1.7M CNIL fines data processor €1.7M for misconfigured disability-records software causing The data protection authority (DPA) has imposed a fine of €1,700,000 on a data processor that had incorrectly configured a software program. This program processed files related… France Controllers Processors Processing Jan 12, 2026
€3.5M Company: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 3,500,000 on a company. The controller operated a loyalty program in France and 16 other EU countries, using customer data obtained… FRANCE ·CNIL ·Art. 6, 13, 32 +1 Controllers International Transfer DPIA Dec 30, 2025
€32,000 EXCEL HOTELS & RESORTS, S.A.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 32.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Security Controllers Accountability Dec 20, 2025
€1.5M Bank: Non-compliance with general data processing principles Croatian Data Protection Authority (azop) fined Bank €1,500,000 on 2025-12-18 for: Non-compliance with general data processing principles. Croatia ·AZOP ·Art. 5, 6, 13 +1 Supervisory Authorities Processing Human Resources Dec 18, 2025
€2,000 Nițu A. Cleopatra – Expert Accountant: Insufficient technical and organisational measures to ensure information security Thr Romanian DPA has imposed a fine of EUR 2,000 on Nițu A. Cleopatra – Expert Accountant. The controller was the target of a successful cyber attack due to the inadequate… ROMANIA ·ANSPDCP ·Art. 32 Security Controllers Personal Data Nov 27, 2025
€4.5M Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer… CROATIA ·AZOP ·Art. 5, 6, 12 +4 International Transfer Privacy Shield Controllers Nov 24, 2025
€1,500 Shop Owner: Insufficient legal basis for data processing Austrian Data Protection Authority (dsb) fined Shop Owner €1,500 on 2025-10-27 for: Insufficient legal basis for data processing. Austria ·DSB ·Art. 5, 6 Processing IP Address Human Resources Oct 27, 2025
€600 Owner of a Tesla Car: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 600 on the owner of a Tesla car. The controller's car had seven cameras installed, which filmed while the car was in use and while it… AUSTRIA ·DSB ·Art. 5, 6, 12 +1 Controllers Personal Data Supervisory Authorities Sep 29, 2025
€15,000 Vimar S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on Vimar S.p.A. The controller created an internal and personalised email account with the personal data of a third party, without… ITALY ·Garante ·Art. 5, 6, 13 Controllers Personal Data Supervisory Authorities Sep 25, 2025
€2,000 Primary School: Insufficient legal basis for data processing Croatian Data Protection Authority (azop) fined Primary School €2,000 on 2025-09-01 for: Insufficient legal basis for data processing. Croatia ·AZOP ·Art. 5, 6 Processing Education Public Authority Sep 1, 2025
€80,000 Ospedaliero-Universitaria Careggi: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 80,000 on the Ospedaliero-Universitaria Careggi. The controller, a university hospital, used software that allowed medical personnel to… ITALY ·Garante ·Art. 5, 9, 25 +1 Healthcare Controllers Security Aug 4, 2025
€80,000 Careggi University Hospital: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 9, 25 +1 Security Health Data Healthcare Aug 4, 2025
€320,000 HEP-Toplinarstvo: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined HEP-Toplinarstvo €320,000 on 2025-07-22 for: Insufficient technical and organisational measures to ensure information security. Croatia ·AZOP ·Art. 31, 32 Security Supervisory Authorities Human Resources Jul 22, 2025
€50,000 Information and Communication Company: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined Information and Communication Company €50,000 on 2025-07-22 for: Insufficient technical and organisational measures to ensure… Croatia ·AZOP ·Art. 32 Security Human Resources Supervisory Authorities Jul 22, 2025
€101,000 Croatian Insurance Bureau: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined Croatian Insurance Bureau €101,000 on 2025-07-02 for: Insufficient technical and organisational measures to ensure information… Croatia ·AZOP ·Art. 5, 32 Security Insurance Education Jul 2, 2025
€175,000 FAVORIT SPORTSKA KLADIONICA d.o.o.: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined FAVORIT SPORTSKA KLADIONICA d.o.o. €175,000 on 2025-07-02 for: Insufficient technical and organisational measures to ensure… Croatia ·AZOP ·Art. 5 Security Human Resources Supervisory Authorities Jul 2, 2025
€42,000 IBERCAJA BANCO, S.A.: Violation of the general principles of data processing. ⇄ Een boete van 42.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Controllers Processing Accountability Jun 20, 2025
€900,000 SOLOCAL MARKETING SERVICES: Insufficient legal basis for data processing The French DPA imposed a fine of EUR 900,000 on SOLOCAL MARKETING SERVICES. The controller, a company that also engages in direct marketing activities for its clients, ist using… FRANCE ·CNIL ·Art. 6, 7 Consent Controllers Personal Data May 15, 2025
€900,000 SOLOCAL MARKETING SERVICES: Insufficient legal basis for data processing. ⇄ 900.000 euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE ·CNIL ·Art. 6, 7 Consent Controllers Processing May 15, 2025
€5,000 Board for Support to Citizens and Agriculture: Insufficient legal basis for data processing. ⇄ Een boete van 5.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY ·Garante ·Art. 5, 6 Retention Period Storage Limitation Personal Data Apr 10, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Non-compliance with the general principles for data processing. ⇄ Een boete van 120.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Integrity and Confidentiality Principle Processing Personal Data Mar 28, 2025
€20,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) imposed a fine of EUR 20,000 on a hospital for failing to implement adequate technical and organizational measures to protect personal data in line with… CROATIA ·AZOP ·Art. 32 Security Personal Data Data Breaches Mar 24, 2025
€2,000 l’Istituto Alberghiero Mediterraneo di Pulsano: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 2,000 on l’Istituto Alberghiero Mediterraneo di Pulsano. The controller, a school, published a christmas video on the video platform YouTube,… ITALY ·Garante ·Art. 5, 6 Consent Controllers Processing Mar 13, 2025
€20,000 Encore Thermoengineering s.r.l.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 20,000 on Encore Thermoengineering s.r.l. The controller legally obtained employee data from another company that had gone bankrupt. The… ITALY ·Garante ·Art. 5, 6, 17 Retention Period Controllers Personal Data Mar 13, 2025