Skip to content
Content type · 33 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–33 of 33 sort newestlargest fineoldest
Icelandic DPA opens formal proceedings against Isavia over ANPR parking cameras at The DPA initiated an investigation into Isavia domestic airports Ltd. (the controller) concerning the electronic monitoring of car parks in five airports: Reykjavík, Akureyri,… 2025061555 ·Iceland ·Persónuvernd Supervisory Authorities Personal Data Monitoring Sep 30, 2026
€39,000 Italian DPA: employer breached Art. 15 GDPR by ignoring access request over disciplinary The data subject, a security guard of La Patria S.p.A. (the controller), complained to the DPA about the lack of response by the controller to two access requests regarding the… Italy ·Garante ·Art. 12, 13, 15 Supervisory Authorities Right of Access Personal Data Sep 23, 2026
SEK 1.8M IMY fines Miljödata SEK for Article 32 GDPR violation after ransomware breach of 2.2M An IT company that provides digital HR and occupational health services (Miljödata) detected a data breach in August 2025. In the breach, an external attacker had gained… Sweden ·Art. 32 Data Breaches Notification Obligation Controllers Sep 22, 2026
€120 Italian DPA sanctions Experian Italia for incomplete Art. 15 GDPR access responses on The DPA received several complaints from data subjects concerning Experian Italia S.p.A (the controller) an Italian credit information system. The controller was processing the… Italy ·Garante ·Art. 5, 12, 15 +1 Supervisory Authorities Privacy by Design Personal Data Sep 16, 2026
€6,000 Italian DPA: Municipality of Rieti breached GDPR by publishing 31,000 taxpayers' waste The Municipality of Rieti (the controller) published its administrative acts on its official notice board and in the "Transparent Administration" section of its website. A… Italy ·Garante ·Art. 5, 12, 24 +3 Public Authority Supervisory Authorities Integrity and Confidentiality Principle
€3,150 APDCAT: Public body violated GDPR by disclosing audio recording to four extra recipients On 22 January 2025, an employee and trade union representative of a public-sector organisation, the data subject, emailed the DPO requesting access to and a copy of a recording of… Spain ·Art. 5, 6, 12 +1 Personal Data Right of Access Integrity and Confidentiality Principle Sep 15, 2026
€5.5M Banco Bilbao Vizcaya Argentaria S.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) found Banco Bilbao Vizcaya Argentaria, S.A. (Italian branch) violated Articles 5(1)(a), 12, 21, and 24 of the GDPR by continuing to… Italy ·Garante ·Art. 5, 12, 21 +1 Right to Object Personal Data Direct Marketing Sep 3, 2026
Datatilsynet reprimands Danish Tax Administration for access request delays (2019-2024) In November 2024 the DPA started an investigation against the Danish Tax Administration (‘the controller’) for their processing time of access requests. 30 September 2025 the DPA… 2024-432-0039 ·Denmark ·Datatilsynet (DK) Right of Access Personal Data Supervisory Authorities
HUF 2M NAIH-11443-3/2026 The DPA initiated an investigation into the GDPR compliance of an online store (the controller) processing the data of its customers (the data subjects) in April 2025. The… Hungary ·Art. 12, 13 Legitimate Interest Personal Data Lawful Basis Jul 22, 2026
€500,000 Hôpital privé de la Loire: Insufficient technical and organisational measures to ensure information security The French Data Protection Authority (CNIL) sanctioned Hôpital Privé de la Loire, a Ramsay Santé group hospital, following a June 2025 personal data breach in which an attacker… France ·CNIL ·Art. 32, 34 Data Breaches Notification Obligation Healthcare Jul 21, 2026
€1.4M Garante · 484/2026 EstEnergy S.p.A. (hereinafter, the controller) is an Italian energy company supplying natural gas, electricity and related services. Before entering into contracts, the controller… Italy ·Art. 5, 13, 14 +2 Retention Period Controllers Right of Access Jul 3, 2026
IMY-2024-2904 The supervisory authority launched an investigation into the border control unit of the national police authority (the controller) at Arlanda Airport concerning the processing of… IMY-2024-2904 ·Sweden ·Art. 13 Personal Data Supervisory Authorities Information Provision Modalities and Communication Methods Jul 3, 2026
€65,000 MEDE S.A.: Non-compliance with general data processing principles The Hellenic Data Protection Authority fined MEDE S.A. €65,000 for violating general data processing principles under Article 5 GDPR, along with failures concerning transparency… Greece ·HDPA ·Art. 5, 12, 13 +2 Supervisory Authorities Accountability Right of Access Jun 12, 2026
HDPA · 12/2026 The complainant, a foreign national, submitted a complaint to the Hellenic DPA through his authorized attorney, seeking his deletion from the Hellenic the National Registry of… 12/2026 ·Greece ·Art. 23 Right of Access Criminal Data Personal Data May 13, 2026
HUF 15M NAIH-450-7-2026 The DPA initiated an investigation into the processing of personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Fairness & Transparency Transparency Personal Data May 12, 2026
The data subject was a technician employed by the controller The controller used weekly handwritten service sheets as a system for recording working time. These sheets contained the technician’s working hours, journeys, services performed… 97/2026 ·Belgium ·APD/GBA Personal Data Right of Access Controllers May 6, 2026
HUF 10M NAIH-4462-5-2026 The DPA initiated an investigation into the processing of the personal data of customers (the data subjects) by the operator of an online store (the controller) in April 2025. The… Hungary ·Art. 5, 12, 13 Personal Data Fairness & Transparency Accountability Apr 30, 2026
OÜ Dr Mõttus Hambaravi, the controller, is a Dental Clinic On March 2024, the DPA received a complaint from a data subject regarding the fact that the controller had failed to provide all personal data requested. The controller only… No. 2.1-1/24/397-890-38 ·Estonia ·AKI Controllers Processors Privacy by Design & Default Apr 16, 2026
€25,500 DSB · 2025-1.049.138 The controller was a digital marketing agency whose employees pre-screened potential applicants for its clients. As part of this process, applicants (data subjects) were contacted… Austria ·Art. 5, 6, 12 +1 Legitimate Interest Personal Data Retention Period Jan 19, 2026
€190,000 Hospital: Insufficient technical and organisational measures to ensure information security The Croatian DPA (AZOP) has imposed a fine of EUR 190,000 on a hospital. The hospital had suffered a data breach in which radiological image files were irrevocably lost. AZOP had… CROATIA ·AZOP ·Art. 5, 6, 12 +4 Data Breaches Retention Period Storage Limitation Sep 13, 2024
€15,000 Hotel: Insufficient legal basis for data processing The Croatian DPA (AZOP) has imposed of fine of EUR 15,000 to a hotel. The hotel was collecting personal data from guests in excess of what would have been necessary for the… CROATIA ·AZOP ·Art. 6, 13, 32 +1 Controllers Personal Data Encryption Sep 26, 2023
54/2024 In 2020, the data subject filed a complaint with the DPA against Google LLC (the controller) for failing to fulfill their right to erasure (Article 17 GDPR) concerning links -… 54/2024 ·Greece ·HDPA Right to be Forgotten Personal Data Right to Object Jun 29, 2023
€4.9M Edison Energia S.p.A.: Non-compliance with general data processing principles The Italian DPA has fined Edison Energia S.p.A. EUR 4.9 million. Several person had filed complaints with the DPA regarding unlawful marketing activities of the company. During… ITALY ·Garante ·Art. 5, 6, 7 +4 Right to Object Personal Data Direct Marketing Dec 15, 2022
€900 LfD (Lower Saxony) - Fine EUR 900,000 against bank A commercial bank (controller) used personal data of current and former customers (data subjects) to identify customers with an affinity for digital media usage, in order to… Germany ·Art. 6 Legitimate Interest Lawful Basis Personal Data
€900,000 Hannoversche Volksbank: Insufficient legal basis for data processing The DPA of Lower Saxony has imposed a fine of EUR 900,000 on Hannoversche Volksbank. The bank had analyzed data from active and former customers without their consent. For this… GERMANY ·Art. 6 ·Insufficient legal basis for data processing Consent Insurance Direct Marketing Jul 28, 2022
€50 Belgian DPA: Roularta Media Group violated cookie consent rules On 16 January 2019, the Executive-committee of the Belgian DPA (GBA) started an investigation on the use of cookies on Belgian media websites. The controller in this case is… Belgium ·APD/GBA ·Art. 4, 5, 6 +3 Consent Supervisory Authorities Personal Data May 25, 2022
EDPS: European Parliament is sole controller for COVID testing website and failed In January 2021, noyb filed a complaint against the European Parliament on behalf of six Members of the European Parliament over an internal coronavirus testing website. The… 2020-1013 ·European Union ·Art. 6, 13 Controllers Processors IP Address Jan 5, 2022
€110,000 Limerick City and County Council: Insufficient fulfilment of data subjects rights The Irish DPA has fined Limerick City and County Council EUR 110,000. As part of an investigation, the DPA conducted an audit of the processing of personal data by the council or… IRELAND ·DPC ·Art. 12, 13, 15 Right of Access Personal Data Controllers Dec 9, 2021
Facebook Ireland Limited: Insufficient fulfilment of information obligations The organization 'None of your business' (NOYB) published a draft decision of the Irish DPA (DPC) on October 13, 2021, which indicates that it proposes a fine between EUR 28… DPC ·Art. 5, 12, 13 ·Insufficient fulfilment of information obligations Supervisory Authorities Personal Data Information Provision Modalities and Communication Methods Oct 6, 2021
€225M WhatsApp Ireland Ltd.: Insufficient fulfilment of information obligations The Irish DPA (DPC) has imposed a fine of EUR 225,000,000 on WhatsApp Ireland Ltd. The DPA had started extensive investigations into the messaging service's compliance with… DPC ·Art. 5, 12, 13 +1 ·Insufficient fulfilment of information obligations Transparency Information Provision Modalities and Communication Methods Fairness & Transparency Sep 2, 2021
EDPS: CJEU violated Regulation 2018/1725 over cookies and consent on its website A data subject complained around cookies and similar technologies used in connection to audiovisual material on the website of the Court of Justice of the European Union (CJEU),… 2019-0878 ·European Union ·Art. 7 Consent Information Provision Modalities and Communication Methods Cookies May 3, 2021
€30,000 PS/00032/2020 A user of the website of Iberia, an airline, lodged a complaint before the Spanish DPA (AEPD) saying that they had not been given an option to reject the cookies when using the… Spain ·AEPD ·Art. 22 Consent Personal Data Supervisory Authorities Oct 16, 2020
€28M TIM (telecommunications operator): Insufficient legal basis for data processing Between January 2017 and 2019, the data protection authority received hundreds of notifications, in particular concerning the receipt of unsolicited commercial communications made… ITALY ·Garante ·Art. 5, 6, 17 +2 Integrity and Confidentiality Principle Direct Marketing Right to Object Jan 15, 2020