Content type · 179 documents in this view · 3,811 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3587 Processing 2635 Personal Data 2394 Controllers 2017 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Sep 22, 2026
€3,150 APDCAT: Public body violated GDPR by disclosing audio recording to four extra recipients On 22 January 2025, an employee and trade union representative of a public-sector organisation, the data subject, emailed the DPO requesting access to and a copy of a recording of… Spain ·Art. 5, 6, 12 +1 Sep 15, 2026
€200,000M 15/2026 The Ministry of Social Cohesion and Family (the controller), and the Hellenic Local Development and Local Government Company (the processor) notified the DPA that information… Greece · ·Art. 5, 28, 32 Jul 28, 2026
€300,000 CNIL fines EXTIA for failing to properly handle job applicant erasure requests EXTIA, the controller, is a French consulting company specialising in IT and engineering services. As part of its recruitment activities, the controller processed personal data of… France ·Art. 12, 17 Jul 21, 2026
€12,000 Garante · 10254256 The data subject was an employee at a detention facility run by the Italian Ministry of Justice (the controller). Following an assessment by the occupational health physician, who… Italy ·Art. 4, 5, 6 +2
€200,000 Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first… PS-00020-2025 ·Spain · Jul 16, 2026
Persónuvernd (Island) - 2025010358 The data subject was an employee of the enterprise BL ehf (the controller). When she started working there, she was provided with a computer set up by the controller’s IT… 2025010358 ·Iceland ·Art. 5, 32 Jul 1, 2026
€6,600 Cosmint S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Cosmint S.p.A. €6,600 for violating general data processing principles in the employment sector, specifically under Articles… Italy · ·Art. 5, 6, 13 Jun 18, 2026
€6,000 Liguria Health Protection Authority: Insufficient legal basis for data processing The Italian Data Protection Authority (Garante) fined the Liguria Health Protection Authority €6,000 for lacking a sufficient legal basis for personal data processing in the… Italy · ·Art. 5, 6, 25 +2 May 28, 2026
PLN 21,000 DKN.5131.5.2025 A provincial government unit carrying out land consolidation and exchange work (the controller) had entrusted tasks involving the processing of landowners’ (the data subjects’)… Poland · ·Art. 24, 25, 28 +1 May 25, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland · ·Art. 5, 32, 33 May 8, 2026
The data subject was employed by an Austrian stock corporation (the controller) from August 2018 to June 2025 They worked as a manager in the controller’s finance department, with technical and disciplinary responsibility for up to five employees. The controller operated a 360-degree… 2025-0.960.016 ·Austria · Mar 20, 2026
€17M Reddit, Inc.: Non-compliance with general data processing principles Information Commissioner (ICO) fined Reddit, Inc. €16,610,000 on 2026-02-23 for: Non-compliance with general data processing principles. United Kingdom · ·Art. 5, 6, 8 +1 Feb 23, 2026
€150,000 The Spanish Data Protection Agency (AEPD) investigated Vodafone España, S.A.U as controller after a SIM swapping incident. On 21 September 2021, an unknown third party requested a duplicate SIM card for the mobile line of a data subject. The request was… EXP202306354 (PS/00312/2024) ·Spain ·Art. 5, 6 Feb 11, 2026
€25,000 Municipality of Gooise Meren: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Gooise Meren. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Hilversum: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Hilversum. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Eindhoven: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Eindhoven. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Huizen: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Huizen. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Ede: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Ede. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Zoetermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Zoetermeer. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Veenendaal: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Veenendaal. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Delft: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Delft. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Haarlemmermeer: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Haarlemmermeer. The controller, one of ten municipalities that were fined, processed data regarding the… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€25,000 Municipality of Tilburg: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 25,000 on the Municipality of Tilburg. The controller, one of ten municipalities that were fined, processed data regarding the Islamic… THE NETHERLANDS · ·Art. 6, 9 Feb 3, 2026
€1,500 10214411 The Local Territorial Agency for Residential Housing (Azienda territoriale per l’edilizia residenziale) submitted a complaint to the DPA regarding the installation of security… Italy · ·Art. 5, 6, 13 +2 Jan 16, 2026
€1.7M CNIL fines data processor €1.7M for misconfigured disability-records software causing The data protection authority (DPA) has imposed a fine of €1,700,000 on a data processor that had incorrectly configured a software program. This program processed files related… France Jan 12, 2026
€3.5M Company: Non-compliance with general data processing principles The French DPA has imposed a fine of EUR 3,500,000 on a company. The controller operated a loyalty program in France and 16 other EU countries, using customer data obtained… FRANCE · ·Art. 6, 13, 32 +1 Dec 30, 2025
€32,000 EXCEL HOTELS & RESORTS, S.A.: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 32.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN · ·Art. 5 Dec 20, 2025
€1.5M Bank: Non-compliance with general data processing principles Croatian Data Protection Authority (azop) fined Bank €1,500,000 on 2025-12-18 for: Non-compliance with general data processing principles. Croatia · ·Art. 5, 6, 13 +1 Dec 18, 2025
€2,000 Nițu A. Cleopatra – Expert Accountant: Insufficient technical and organisational measures to ensure information security Thr Romanian DPA has imposed a fine of EUR 2,000 on Nițu A. Cleopatra – Expert Accountant. The controller was the target of a successful cyber attack due to the inadequate… ROMANIA · ·Art. 32 Nov 27, 2025
€4.5M Telecommunications operator (operator of electronic communications networks and services): Non-compliance with general data processing principles Following an ex officio investigation, AZOP imposed a EUR 4.5 million fine on a telecommunications operator for multiple GDPR infringements. The controller transferred customer… CROATIA · ·Art. 5, 6, 12 +4 Nov 24, 2025
€1,500 Shop Owner: Insufficient legal basis for data processing Austrian Data Protection Authority (dsb) fined Shop Owner €1,500 on 2025-10-27 for: Insufficient legal basis for data processing. Austria · ·Art. 5, 6 Oct 27, 2025
€6,000 Interprovincial organization of medical radiology technicians and technical healthcare personnel in rehabilitation and prevention in the regions AQ, CH, PE and TE: Insufficient legal basis for data processing. ⇄ Een boete van 6.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6, 37 Oct 9, 2025
€600 Owner of a Tesla Car: Non-compliance with general data processing principles The Austrian DPA has imposed a fine of EUR 600 on the owner of a Tesla car. The controller's car had seven cameras installed, which filmed while the car was in use and while it… AUSTRIA · ·Art. 5, 6, 12 +1 Sep 29, 2025
€15,000 Vimar S.p.A.: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 15,000 on Vimar S.p.A. The controller created an internal and personalised email account with the personal data of a third party, without… ITALY · ·Art. 5, 6, 13 Sep 25, 2025
€2,000 Primary School: Insufficient legal basis for data processing Croatian Data Protection Authority (azop) fined Primary School €2,000 on 2025-09-01 for: Insufficient legal basis for data processing. Croatia · ·Art. 5, 6 Sep 1, 2025
€80,000 Ospedaliero-Universitaria Careggi: Insufficient technical and organisational measures to ensure information security The Italian DPA has imposed a fine of EUR 80,000 on the Ospedaliero-Universitaria Careggi. The controller, a university hospital, used software that allowed medical personnel to… ITALY · ·Art. 5, 9, 25 +1 Aug 4, 2025
€80,000 Careggi University Hospital: Insufficient technical and organisational measures to ensure information security. ⇄ Een boete van 80.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 9, 25 +1 Aug 4, 2025
€320,000 HEP-Toplinarstvo: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined HEP-Toplinarstvo €320,000 on 2025-07-22 for: Insufficient technical and organisational measures to ensure information security. Croatia · ·Art. 31, 32 Jul 22, 2025
€50,000 Information and Communication Company: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined Information and Communication Company €50,000 on 2025-07-22 for: Insufficient technical and organisational measures to ensure… Croatia · ·Art. 32 Jul 22, 2025
€101,000 Croatian Insurance Bureau: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined Croatian Insurance Bureau €101,000 on 2025-07-02 for: Insufficient technical and organisational measures to ensure information… Croatia · ·Art. 5, 32 Jul 2, 2025
€175,000 FAVORIT SPORTSKA KLADIONICA d.o.o.: Insufficient technical and organisational measures to ensure information security Croatian Data Protection Authority (azop) fined FAVORIT SPORTSKA KLADIONICA d.o.o. €175,000 on 2025-07-02 for: Insufficient technical and organisational measures to ensure… Croatia · ·Art. 5 Jul 2, 2025
€42,000 IBERCAJA BANCO, S.A.: Violation of the general principles of data processing. ⇄ Een boete van 42.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN · ·Art. 5 Jun 20, 2025
€900,000 SOLOCAL MARKETING SERVICES: Insufficient legal basis for data processing The French DPA imposed a fine of EUR 900,000 on SOLOCAL MARKETING SERVICES. The controller, a company that also engages in direct marketing activities for its clients, ist using… FRANCE · ·Art. 6, 7 May 15, 2025
€900,000 SOLOCAL MARKETING SERVICES: Insufficient legal basis for data processing. ⇄ 900.000 euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). FRANCE · ·Art. 6, 7 May 15, 2025
€5,000 Board for Support to Citizens and Agriculture: Insufficient legal basis for data processing. ⇄ Een boete van 5.000 euro - van de Italiaanse Autoriteit voor Gegevensbescherming (Garante). ITALY · ·Art. 5, 6 Apr 10, 2025
€120,000 SERVICIOS ESPECIALES, S.A.: Non-compliance with the general principles for data processing. ⇄ Een boete van 120.000 euro - opgelegd door de Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN · ·Art. 5 Mar 28, 2025
€20,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) imposed a fine of EUR 20,000 on a hospital for failing to implement adequate technical and organizational measures to protect personal data in line with… CROATIA · ·Art. 32 Mar 24, 2025
€2,000 l’Istituto Alberghiero Mediterraneo di Pulsano: Insufficient legal basis for data processing The Italian DPA imposed a fine of EUR 2,000 on l’Istituto Alberghiero Mediterraneo di Pulsano. The controller, a school, published a christmas video on the video platform YouTube,… ITALY · ·Art. 5, 6 Mar 13, 2025
€20,000 Encore Thermoengineering s.r.l.: Non-compliance with general data processing principles The Italian DPA imposed a fine of EUR 20,000 on Encore Thermoengineering s.r.l. The controller legally obtained employee data from another company that had gone bankrupt. The… ITALY · ·Art. 5, 6, 17 Mar 13, 2025