Skip to content
Content type · 408 documents in this view · 3,813 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

1–50 of 408 sort newestlargest fineoldest
€5.5M Banco Bilbao Vizcaya Argentaria S.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) found Banco Bilbao Vizcaya Argentaria, S.A. (Italian branch) violated Articles 5(1)(a), 12, 21, and 24 of the GDPR by continuing to… Italy ·Garante ·Art. 5, 12, 21 +1 Right to Object Personal Data Direct Marketing Sep 3, 2026
€5,320 Slovenian DPA fines controller €5,320 for leaving employee personal data documents Paper documents containing the personal data of employees (the data subjects) were meant to be destroyed at a company (the controller). The personal data in these documents… Slovenia ·IP-RS ·Art. 5, 32 Personal Data Controllers Integrity and Confidentiality Principle Sep 1, 2026
ICO (UK) - ACRO Criminal Records Office ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates,… ACRO Criminal Records Office ·United Kingdom ·Art. 32 Controllers Processors Accountability Aug 7, 2026
Tietosuojavaltuutettu · TSV/5059/2023 A pension insurance company (the controller) had disclosure the amount of an applicant's (the data subject's) pension accrual in euros to a physician who conducted a medical… TSV/5059/2023 ·Finland ·Art. 5 Insurance Retention Period GDPR Article 5 Principles of Processing Aug 4, 2026
AEPD · EXP202102529 A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3 Consent Personal Data Healthcare
€200,000 Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first… PS-00020-2025 ·Spain ·AEPD Integrity and Confidentiality Principle Data Breaches Notification Obligation Jul 16, 2026
€120,000 NIER Ingeriegna S.p.A. SB: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined NIER Ingegneria S.p.A. SB €120,000 for failing to implement adequate technical and organizational measures to ensure… Italy ·Garante ·Art. 5, 32 Security Supervision Supervisory Authorities Jul 14, 2026
€400,000 Cerved Group S.p.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) fined Cerved Group S.p.A. €400,000 for insufficient fulfillment of data subjects' rights, including violations of Article 5(1)(a),… Italy ·Garante ·Art. 5, 12, 15 Supervisory Authorities Transparency Insurance Jul 3, 2026
€120,000 Experian Italia S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Experian Italia S.p.A. €120,000 for violating GDPR Articles 5(1)(a) and (c), 12, 15, and 25, concerning non-compliance with… Italy ·Garante ·Art. 5, 12, 15 +1 Privacy by Design Right of Access Supervision Jul 3, 2026
€5,000 Banca Transilvania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Banca Transilvania S.A. €5,000 on July 2, 2026, for failing to implement sufficient… Romania ·ANSPDCP ·Art. 32 Security Personal Data Supervision Jul 2, 2026
€11,000 Ascendex Technology SRL: Insufficient fulfilment of data subjects rights The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Ascendex Technology SRL €11,000 for insufficient fulfillment of data subjects' rights. The… Romania ·ANSPDCP ·Art. 12, 17 Supervision Supervisory Authorities Personal Data Jul 1, 2026
€2,760 Sole trader providing accounting and tax advisory services: Insufficient technical and organisational measures to ensure information security The Polish National Personal Data Protection Office (UODO) fined a sole trader providing accounting and tax advisory services €2,760 for failing to implement sufficient technical… Poland ·UODO ·Art. 5, 25, 32 Privacy by Design Security Personal Data Jun 13, 2026
€10,000 Piraeus Bank S.A.: Insufficient fulfilment of data subjects rights The Hellenic Data Protection Authority (HDPA) fined Piraeus Bank S.A. €10,000 for insufficient fulfillment of data subjects' access rights under Article 15 of the GDPR. The… Greece ·HDPA ·Art. 15 Personal Data Supervision Supervisory Authorities Jun 5, 2026
€12,000 Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Unicredit Bank SA €12,000 on 2026-05-29 for: Insufficient technical and organisational… Romania ·ANSPDCP ·Art. 32, 33 Security Supervisory Authorities Supervision May 29, 2026
€1,000 FeGi M&A Services s.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined FeGi M&A Services s.r.l. €1,000 for non-compliance with general data processing principles under Article 5(1)(a) and Article… Italy ·Garante ·Art. 5, 14 Supervision Supervisory Authorities Personal Data May 14, 2026
€120,000 Isabel SA: Insufficient fulfilment of data subjects rights Belgian Data Protection Authority (APD) fined Isabel SA €120,000 on 2026-05-12 for: Insufficient fulfilment of data subjects rights. Belgium ·APD/GBA ·Art. 5, 12, 13 +2 Personal Data Supervisory Authorities Insurance May 12, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·DPC ·Art. 5, 32, 33 Integrity and Confidentiality Principle Data Breaches Notification Obligation May 8, 2026
€4,920 Law Firm: Insufficient fulfilment of data subjects rights Belgian Data Protection Authority (APD) fined Law Firm €4,920 on 2026-05-08 for: Insufficient fulfilment of data subjects rights. Belgium ·APD/GBA ·Art. 5, 12, 13 +2 Personal Data Supervisory Authorities Insurance May 8, 2026
€277,500 Permanent TSB plc: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Permanent TSB plc €277,500 for failing to implement sufficient technical and organisational measures to ensure information security,… Ireland ·DPC ·Art. 5, 32, 33 Notification Obligation Data Breaches Supervision Apr 30, 2026
€6.6M Poste Italiane S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Poste Italiane S.p.a. €6,624,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 13 +4 Supervisory Authorities Processing IP Address Apr 17, 2026
€5.9M Postepay S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Postepay S.p.a. €5,877,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy ·Garante ·Art. 5, 6, 13 +4 Supervisory Authorities Processing IP Address Apr 17, 2026
€400,000 CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined Caixabank, S.A. €400,000 for failing to implement sufficient technical and organizational measures to ensure information… Spain ·AEPD ·Art. 5, 25 Privacy by Design & Default Privacy by Default Privacy by Design Apr 15, 2026
€32M Intesa Sanpaolo S.p.A.: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) fined Intesa Sanpaolo S.p.A. €31,800,000 on 2026-03-26 for: Insufficient technical and organisational measures to ensure information… Italy ·Garante ·Art. 5, 24, 32 +1 Security Supervisory Authorities Insurance Mar 26, 2026
€4,000 ING Bank NV Amsterdam – Sucursala București S.A.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined ING Bank NV Amsterdam – Sucursala București S.A. €4,000 on 2026-03-23 for: Insufficient… Romania ·ANSPDCP ·Art. 32 Security Personal Data Supervisory Authorities Mar 23, 2026
€15,000 Bressanelli Galli Gelpi Porta & C. S.r.l.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Bressanelli Galli Gelpi Porta & C. S.r.l. €15,000 on 2026-02-12 for: Insufficient legal basis for data processing. Italy ·Garante ·Art. 5, 6, 7 +3 Processing Supervisory Authorities Insurance Feb 12, 2026
€10,000 GENPACT ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational… ANSPDCP ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Feb 4, 2026
DSB · 2026-0.043.390 Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop… 2026-0.043.390 ·Austria ·Art. 5, 12, 13 Personal Data IP Address Fairness & Transparency Jan 16, 2026
€8,000 KVIKU SPAIN, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 8,000 on KVIKU SPAIN, S.L.The controller requires customers to send a photo of themselves holding their ID card when verifying their… AEPD ·Art. 5 ·Non-compliance with general data processing principles Retention Period Controllers Processing Jan 10, 2026
€2,000 Money Seeds S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. ⇄ The Romanian supervisory authority ANSPDCP has imposed a fine of 2,000 euros on Money Seeds S.R.L., a financial and consultancy company, for failing to honor a data subject's… ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervision Jan 8, 2026
€2,000 Money Seeds S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Money Seeds S.R.L. The controller failed to fulfil a data subject's request to exercise their rights. ROMANIA ·ANSPDCP ·Art. 12, 13, 14 Personal Data Controllers Supervisory Authorities Jan 8, 2026
€60,000 Debt collection agency (GESTIÓN DE COBROS, YO COBRO SL): Insufficient legal basis for the processing of personal data. ⇄ Boete van 60.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 5 Personal Data Processing Accountability Dec 30, 2025
€50,000 Social security institution: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 50.000 euro - van het Slowaakse databeschermingskantoor. SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Security Health Data Healthcare Dec 30, 2025
€3,140 UniCredit Bank Czech Republic and Slovakia, a.s.: Insufficient legal basis for data processing. ⇄ Boete van €3.140 - Tsjechische Autoriteit voor Gegevensbescherming (UOOU). ÚOOÚ (CZ) ·Art. 6 ·Insufficient legal basis for data processing Personal Data Consent Processing Dec 30, 2025
€60,000 Debt collecting agancy (GESTIÓN DE COBROS, YO COBRO SL): Insufficient legal basis for data processing After the claimant did alledgedly not pay back a microcredit to an online credit agany, the claim was assigned to the debt collecting agancy. Subsequently, the latter startet… SPAIN ·AEPD ·Art. 5 Processing Insurance Supervisory Authorities
€3,140 UniCredit Bank Czech Republic and Slovakia, a.s.: Insufficient legal basis for data processing The bank established a personal bank account for a data subject without his consent or knowledge. The bank supposedly had his personal data available because the subject had… ÚOOÚ (CZ) ·Art. 6 ·Insufficient legal basis for data processing Personal Data Consent Insurance
€50,000 Social Insurance Agency: Insufficient technical and organisational measures to ensure information security Applications for social benefits from Slovak citizens were sent by post to foreign authorities. These were lost by post, with the result that the whereabouts of these personal… SLOVAKIA ·Slovak Data Protection Office ·Art. 32 Security Personal Data Insurance
€1,600 NAROBESA INV, S.L.: Insufficient cooperation with the supervisory authority. ⇄ 1.600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN ·AEPD ·Art. 58 Supervisory Authorities Controllers Supervision Dec 29, 2025
€1,600 NAROBESA INV, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,600 on NAROBESA INV, S.L. The controller failed to react to requests made by the DPA. The original fine of EUR 2,000 was reduced to EUR… SPAIN ·AEPD ·Art. 58 Supervisory Authorities Supervision Controllers Dec 29, 2025
€1.5M Bank: Non-compliance with general data processing principles Croatian Data Protection Authority (azop) fined Bank €1,500,000 on 2025-12-18 for: Non-compliance with general data processing principles. Croatia ·AZOP ·Art. 5, 6, 13 +1 Supervisory Authorities Processing Human Resources Dec 18, 2025
€6,000 Comune di Nave: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Commune di Nave. The controller has installed an automatic licence plate recognition system which processes data on when a… ITALY ·Garante ·Art. 5, 6, 12 +2 DPIA Controllers Personal Data Dec 18, 2025
€1.5M AMERICAN EXPRESS CARTE FRANCE: Insufficient legal basis for the processing of data. ⇄ 1.500.000 euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). CNIL ·Art. 82 ·Insufficient legal basis for data processing Controllers Processing Personal Data Nov 27, 2025
€1.5M AMERICAN EXPRESS CARTE FRANCE: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 1,500,000 on AMERICAN EXPRESS CARTE FRANCE. The controller used excessive cookies on its website and failed to adequately inform data… CNIL ·Art. 82 ·Insufficient legal basis for data processing Controllers Personal Data Cookies Nov 27, 2025
DSB · 2025-0.950.759 On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Austria ·Art. 5, 6, 16 +2 Privacy by Design & Default Privacy by Design Privacy by Default Nov 24, 2025
€865,000 Aktia Pankki Oyj: Insufficient technical and organisational measures to ensure information security The Finish DPA has imposed a fine of EUR 865,000 on Aktia Pankki Oyj. The controller changed its strong authentication process in such a way that it no longer guaranteed adequate… FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Controllers Identification Oct 23, 2025
€865,000 Aktia Bank Plc: Insufficient technical and organizational measures to ensure information security. ⇄ 865.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND ·Deputy Data Protection Ombudsman ·Art. 5, 25, 32 Security Privacy by Design Accountability Oct 23, 2025
€2,000 Agency for Control of Outstanding Debts S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on the Agency for Control of Outstanding Debts S.R.L. The controller failed to adequatly react to a data subjects request to… ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Controllers Supervisory Authorities Oct 22, 2025
€2,000 Agency for Control of Outstanding Debts S.R.L.: Insufficient compliance with data subjects' rights. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 12, 15 Personal Data Processing Supervision Oct 22, 2025
€2.7M Experian Nederland B.V.: Insufficient legal basis for the processing of data. ⇄ 2.700.000 euro boete - Nederlandse Autoriteit Persoonsgegevens (AP). THE NETHERLANDS ·AP ·Art. 5, 6, 12 +2 Personal Data Controllers Processing Oct 16, 2025
€2,000 PRIME TRANSACTION SA: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA ·ANSPDCP ·Art. 32 Security Personal Data Processing Oct 16, 2025
€2.7M Experian Nederland B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 2,700,000 on Experian Nederland B.V. The controller, a company that determines individuals' creditworthiness and sells this information,… THE NETHERLANDS ·AP ·Art. 5, 6, 12 +2 Personal Data Controllers Supervisory Authorities Oct 16, 2025