Skip to content
Content type · 394 documents in this view · 3,634 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 394 sort newestlargest fineoldest
AEPD investigates University of Navarra over student COVID-19 vaccination status requests A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3 Consent Healthcare Health Data Jul 16, 2026
€200,000 AEPD fines Alkora, S.A. for ransomware breach exposing 40,000 individuals' data Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack. The controller notified the DPA of a personal data breach after a ransomware attack… Spain ·Art. 5, 35, 58 Privacy Impact Assessment DPIA Data Breaches Jul 16, 2026
€12,000 Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Unicredit Bank SA €12,000 on 2026-05-29 for: Insufficient technical and organisational… Romania ·ANSPDCP ·Art. 32, 33 Security Personal Data Supervisory Authorities May 29, 2026
€120,000 Isabel SA: Insufficient fulfilment of data subjects rights Belgian Data Protection Authority (APD) fined Isabel SA €120,000 on 2026-05-12 for: Insufficient fulfilment of data subjects rights. Belgium ·APD ·Art. 5, 12, 13 +2 Personal Data Insurance Supervisory Authorities May 12, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·Art. 5, 32, 33 ·Insufficient technical and organisational measures to ensure information security Security Notification Obligation Fines May 8, 2026
€4,920 Law Firm: Insufficient fulfilment of data subjects rights Belgian Data Protection Authority (APD) fined Law Firm €4,920 on 2026-05-08 for: Insufficient fulfilment of data subjects rights. Belgium ·APD ·Art. 5, 12, 13 +2 Personal Data Supervisory Authorities Insurance May 8, 2026
€6.6M Poste Italiane S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Poste Italiane S.p.a. €6,624,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 13 +4 IP Address Insurance Processing Apr 17, 2026
€5.9M Postepay S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Postepay S.p.a. €5,877,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 13 +4 IP Address Insurance Processing Apr 17, 2026
€400,000 CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined Caixabank, S.A. €400,000 for failing to implement sufficient technical and organizational measures to ensure information… Spain ·aepd ·Art. 5, 25 Privacy by Default Accountability Security Apr 15, 2026
€32M Intesa Sanpaolo S.p.A.: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) fined Intesa Sanpaolo S.p.A. €31,800,000 on 2026-03-26 for: Insufficient technical and organisational measures to ensure information… Italy ·Garante ·Art. 5, 24, 32 +1 Security Insurance Supervisory Authorities Mar 26, 2026
€4,000 ING Bank NV Amsterdam – Sucursala București S.A.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined ING Bank NV Amsterdam – Sucursala București S.A. €4,000 on 2026-03-23 for: Insufficient… Romania ·ANSPDCP ·Art. 32 Security Supervisory Authorities Personal Data Mar 23, 2026
€15,000 Bressanelli Galli Gelpi Porta & C. S.r.l.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Bressanelli Galli Gelpi Porta & C. S.r.l. €15,000 on 2026-02-12 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6, 7 +3 Insurance Processing Telecommunications Feb 12, 2026
€10,000 GENPACT ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Access Controls Controllers Feb 4, 2026
DSB Austria: No fine imposed on COVID mask shop for cookie consent failure Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop… 2026-0.043.390 ·Art. 5, 12, 13 Cookies Personal Data IP Address Jan 16, 2026
€8,000 KVIKU SPAIN, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 8,000 on KVIKU SPAIN, S.L.The controller requires customers to send a photo of themselves holding their ID card when verifying their… aepd ·Art. 5 ·Non-compliance with general data processing principles Retention Period IP Address Controllers Jan 10, 2026
€2,000 Money Seeds S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Money Seeds S.R.L. The controller failed to fulfil a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervisory Authorities Jan 8, 2026
€2,000 Money Seeds S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. De Roemeense toezichthouder ANSPDCP heeft aan Money Seeds S.R.L., een financiële en consultancyonderneming, een boete van 2.000 euro opgelegd wegens het niet honoreren van een… ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Data Controller NL Jan 8, 2026
€50,000 Social Insurance Agency: Insufficient technical and organisational measures to ensure information security Applications for social benefits from Slovak citizens were sent by post to foreign authorities. These were lost by post, with the result that the whereabouts of these personal… SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Insurance Healthcare Security Dec 30, 2025
€60,000 Incassobureau (GESTIÓN DE COBROS, YO COBRO SL): Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Boete van 60.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5 Personal Data Processing Insurance NL Dec 30, 2025
€50,000 Sociale verzekeringsinstantie: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 50.000 euro - van het Slowaakse databeschermingskantoor. SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Health Data Security Healthcare NL Dec 30, 2025
€60,000 Debt collecting agancy (GESTIÓN DE COBROS, YO COBRO SL): Insufficient legal basis for data processing After the claimant did alledgedly not pay back a microcredit to an online credit agany, the claim was assigned to the debt collecting agancy. Subsequently, the latter startet… SPAIN ·aepd ·Art. 5 Insurance Processing Supervisory Authorities Dec 30, 2025
€3,140 UniCredit Bank Czech Republic and Slovakia, a.s.: Insufficient legal basis for data processing The bank established a personal bank account for a data subject without his consent or knowledge. The bank supposedly had his personal data available because the subject had… UOOU ·Art. 6 ·Insufficient legal basis for data processing Personal Data Consent Insurance Dec 30, 2025
€3,140 UniCredit Bank Tsjechië en Slowakije, a.s.: Onvoldoende juridische basis voor de verwerking van gegevens. Boete van €3.140 - Tsjechische Autoriteit voor Gegevensbescherming (UOOU). CZECH REPUBLIC ·UOOU ·Art. 6 Personal Data Processing Consent NL Dec 30, 2025
€1,600 NAROBESA INV, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,600 on NAROBESA INV, S.L. The controller failed to react to requests made by the DPA. The original fine of EUR 2,000 was reduced to EUR… SPAIN ·aepd ·Art. 58 Supervisory Authorities Supervision Law Enforcement Dec 29, 2025
€1,600 NAROBESA INV, S.L.: Onvoldoende samenwerking met de toezichthoudende instantie. 1.600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 58 Supervisory Authorities Controllers Supervision NL Dec 29, 2025
€6,000 Comune di Nave: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Commune di Nave. The controller has installed an automatic licence plate recognition system which processes data on when a… ITALY ·Garante ·Art. 5, 6, 12 +2 Insurance DPIA Privacy Impact Assessment Dec 18, 2025
€1.5M Bank: Non-compliance with general data processing principles Croatian Data Protection Authority (azop) fined Bank €1,500,000 on 2025-12-18 for: Non-compliance with general data processing principles. Croatia ·azop ·Art. 5, 6, 13 +1 IP Address Insurance Processing Dec 18, 2025
€1.5M AMERICAN EXPRESS CARTE FRANCE: Onvoldoende juridische basis voor de verwerking van gegevens. 1.500.000 euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). CNIL ·Art. 82 ·Insufficient legal basis for data processing Cookies Data Controller Controllers NL Nov 27, 2025
€1.5M AMERICAN EXPRESS CARTE FRANCE: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 1,500,000 on AMERICAN EXPRESS CARTE FRANCE. The controller used excessive cookies on its website and failed to adequately inform data… CNIL ·Art. 82 ·Insufficient legal basis for data processing Cookies Insurance Controllers Nov 27, 2025
DSB Austria: Online shop violated GDPR by ignoring request to stop gender-specific On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Art. 5, 6, 16 +2 Privacy by Design Privacy by Default Personal Data Nov 24, 2025
€865,000 Aktia Pankki Oyj: Insufficient technical and organisational measures to ensure information security The Finish DPA has imposed a fine of EUR 865,000 on Aktia Pankki Oyj. The controller changed its strong authentication process in such a way that it no longer guaranteed adequate… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Data Breaches Security Access Controls Oct 23, 2025
€865,000 Aktia Pankki Oyj: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 865.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Data Breaches Access Controls NL Oct 23, 2025
€2,000 Bureau voor het innen van openstaande schulden S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Right of Access Personal Data Processing NL Oct 22, 2025
€2,000 Agency for Control of Outstanding Debts S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on the Agency for Control of Outstanding Debts S.R.L. The controller failed to adequatly react to a data subjects request to… ROMANIA ·ANSPDCP ·Art. 12, 15 Controllers Personal Data Supervisory Authorities Oct 22, 2025
€2.7M Experian Nederland B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 2,700,000 on Experian Nederland B.V. The controller, a company that determines individuals' creditworthiness and sells this information,… THE NETHERLANDS ·AP ·Art. 5, 6, 12 +2 Controllers Personal Data Processing Oct 16, 2025
€2.7M Experian Nederland B.V.: Onvoldoende juridische basis voor de verwerking van gegevens. 2.700.000 euro boete - Nederlandse Autoriteit Persoonsgegevens (AP). THE NETHERLANDS ·AP ·Art. 5, 6, 12 +2 Data Controller Processing Controllers NL Oct 16, 2025
€2,000 PRIME TRANSACTION SA: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Data Breaches Controllers NL Oct 16, 2025
€2,000 PRIME TRANSACTION SA: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 2,000 on PRIME TRANSACTION SA. The controller failed to implement adequate technical and organisational measures, resulting in a data… ROMANIA ·ANSPDCP ·Art. 32 Data Breaches Security Controllers Oct 16, 2025
€492,000 Bedrijf: Niet-naleving van algemene principes voor gegevensverwerking. 492.000 euro boete - Autoriteit voor gegevensbescherming van Hamburg (HmbBfDI). GERMANY ·HmbBfDI ·Non-compliance with general data processing principles Meaningful Human Review and Decision-Making Processing IP Address NL Sep 30, 2025
€492,000 Company: Non-compliance with general data processing principles The DPA of Hamburg has imposed a fine of EUR 492,000 on a company in the finance sector. The controller used automated systems to decide whether to approve a credit application,… GERMANY ·HmbBfDI ·Non-compliance with general data processing principles Insurance Controllers IP Address Sep 30, 2025
€1.5M SERVICIOS FINANCIEROS CARREFOUR, E.F.C.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 1,500,000 on SERVICIOS FINANCIEROS CARREFOUR, E.F.C. The controller suffered a successfull cyberattack due to insufficient technical and… SPAIN ·aepd ·Art. 5 Security Processing Agreement Insurance Sep 17, 2025
€1.8M S-Pankki Oyj: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. 1.800.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Supervisory Authorities Accountability NL Sep 8, 2025
€1.8M S-Pankki Oyj: Insufficient technical and organisational measures to ensure information security The Finish DPA has imposed a fine of EUR 1,800,000 on S-Pankki Oyj. Due to a software error, customers of the controller were able to log in to the bank accounts of other… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Processing Agreement Controllers Sep 8, 2025
€180,000 Sociedad de Gestión de Activos Procedentes de la Reestructuración Bancaria S.A.: Insufficient technical and organisational measures to ensure information security The Spanish DPA has imposed a fine of EUR 180,000 on Sociedad de Gestión de Activos Procedentes de la Reestructuración Bancaria S.A. The controller suffered a cyber attack due to… SPAIN ·aepd ·Art. 5, 28 Processors Controllers Processing Agreement Sep 4, 2025
€180,000 Sociedad de Gestión de Activos Procedentes de la Reestructuración Bancaria S.A.: Onvoldoende technische en organisatorische maatregelen om de informatiebeveiliging te waarborgen. Een boete van 180.000 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 5, 28 Security Processing Processors NL Sep 4, 2025
€1,200 GOHIPOTECA, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR on GOHIPOTECA, S.L. The controller processed data of a data subject without a sufficient legal basis. The contract used as the basis for… SPAIN ·aepd ·Art. 6 Controllers IP Address Insurance Aug 29, 2025
€1,200 GOHIPOTECA, S.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. 1.200 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·aepd ·Art. 6 Personal Data Processing Controllers NL Aug 29, 2025
€2,400 KVIKU SPAIN, S.L.: Insufficient legal basis for data processing The Spanish DPA has imposed a fine of EUR 2,400 on KVIKU SPAIN, S.L. The controller processed personal data of a data subject without sufficient consent. The original fine of EUR… aepd ·Art. 6 ·Insufficient legal basis for data processing Personal Data Controllers Processing Agreement Aug 29, 2025
€2,400 KVIKU SPAIN, S.L.: Onvoldoende juridische basis voor de verwerking van persoonsgegevens. Een boete van 2.400 euro - opgelegd door de Spaanse autoriteit voor gegevensbescherming (AEPD). aepd ·Art. 6 ·Insufficient legal basis for data processing Personal Data Processing Data Controller NL Aug 29, 2025