Content type · 408 documents in this view · 3,813 in total
Enforcement
Regulatory actions, fines, warnings, and enforcement decisions
Filtering by Topic Clear filter Supervisory Authorities 3589 Processing 2636 Personal Data 2395 Controllers 2018 Processing Agreement 1114 Security 1013 Supervision 847 Healthcare 621 Law Enforcement 568 Monitoring 547 Public Authority 539 Consent 508
€5.5M Banco Bilbao Vizcaya Argentaria S.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) found Banco Bilbao Vizcaya Argentaria, S.A. (Italian branch) violated Articles 5(1)(a), 12, 21, and 24 of the GDPR by continuing to… Italy · ·Art. 5, 12, 21 +1 Sep 3, 2026
€5,320 Slovenian DPA fines controller €5,320 for leaving employee personal data documents Paper documents containing the personal data of employees (the data subjects) were meant to be destroyed at a company (the controller). The personal data in these documents… Slovenia · ·Art. 5, 32 Sep 1, 2026
ICO (UK) - ACRO Criminal Records Office ACRO Criminal Records Office, the processor, is a national police unit providing public services including Police Certificates, International Child Protection Certificates,… ACRO Criminal Records Office ·United Kingdom ·Art. 32 Aug 7, 2026
Tietosuojavaltuutettu · TSV/5059/2023 A pension insurance company (the controller) had disclosure the amount of an applicant's (the data subject's) pension accrual in euros to a physician who conducted a medical… TSV/5059/2023 ·Finland ·Art. 5 Aug 4, 2026
AEPD · EXP202102529 A student handed in a complaint against the University of Navarra because they asked the students to fill in their vaccination status. The complainant understands this as a breach… EXP202102529 ·Spain ·Art. 4, 5, 6 +3
€200,000 Alkora, S.A., the controller, is an insurance broker that was victim of a ransomware attack The controller notified the DPA of a personal data breach after a ransomware attack affected its servers, databases, email systems and employee devices. The controller first… PS-00020-2025 ·Spain · Jul 16, 2026
€120,000 NIER Ingeriegna S.p.A. SB: Insufficient technical and organisational measures to ensure information security The Italian Data Protection Authority (Garante) fined NIER Ingegneria S.p.A. SB €120,000 for failing to implement adequate technical and organizational measures to ensure… Italy · ·Art. 5, 32 Jul 14, 2026
€400,000 Cerved Group S.p.A.: Insufficient fulfilment of data subjects rights The Italian Data Protection Authority (Garante) fined Cerved Group S.p.A. €400,000 for insufficient fulfillment of data subjects' rights, including violations of Article 5(1)(a),… Italy · ·Art. 5, 12, 15 Jul 3, 2026
€120,000 Experian Italia S.p.A.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined Experian Italia S.p.A. €120,000 for violating GDPR Articles 5(1)(a) and (c), 12, 15, and 25, concerning non-compliance with… Italy · ·Art. 5, 12, 15 +1 Jul 3, 2026
€5,000 Banca Transilvania S.A.: Insufficient technical and organisational measures to ensure information security The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Banca Transilvania S.A. €5,000 on July 2, 2026, for failing to implement sufficient… Romania · ·Art. 32 Jul 2, 2026
€11,000 Ascendex Technology SRL: Insufficient fulfilment of data subjects rights The Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Ascendex Technology SRL €11,000 for insufficient fulfillment of data subjects' rights. The… Romania · ·Art. 12, 17 Jul 1, 2026
€2,760 Sole trader providing accounting and tax advisory services: Insufficient technical and organisational measures to ensure information security The Polish National Personal Data Protection Office (UODO) fined a sole trader providing accounting and tax advisory services €2,760 for failing to implement sufficient technical… Poland · ·Art. 5, 25, 32 Jun 13, 2026
€10,000 Piraeus Bank S.A.: Insufficient fulfilment of data subjects rights The Hellenic Data Protection Authority (HDPA) fined Piraeus Bank S.A. €10,000 for insufficient fulfillment of data subjects' access rights under Article 15 of the GDPR. The… Greece · ·Art. 15 Jun 5, 2026
€12,000 Unicredit Bank SA: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined Unicredit Bank SA €12,000 on 2026-05-29 for: Insufficient technical and organisational… Romania · ·Art. 32, 33 May 29, 2026
€1,000 FeGi M&A Services s.r.l.: Non-compliance with general data processing principles The Italian Data Protection Authority (Garante) fined FeGi M&A Services s.r.l. €1,000 for non-compliance with general data processing principles under Article 5(1)(a) and Article… Italy · ·Art. 5, 14 May 14, 2026
€120,000 Isabel SA: Insufficient fulfilment of data subjects rights Belgian Data Protection Authority (APD) fined Isabel SA €120,000 on 2026-05-12 for: Insufficient fulfilment of data subjects rights. Belgium · ·Art. 5, 12, 13 +2 May 12, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland · ·Art. 5, 32, 33 May 8, 2026
€4,920 Law Firm: Insufficient fulfilment of data subjects rights Belgian Data Protection Authority (APD) fined Law Firm €4,920 on 2026-05-08 for: Insufficient fulfilment of data subjects rights. Belgium · ·Art. 5, 12, 13 +2 May 8, 2026
€277,500 Permanent TSB plc: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Permanent TSB plc €277,500 for failing to implement sufficient technical and organisational measures to ensure information security,… Ireland · ·Art. 5, 32, 33 Apr 30, 2026
€6.6M Poste Italiane S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Poste Italiane S.p.a. €6,624,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy · ·Art. 5, 6, 13 +4 Apr 17, 2026
€5.9M Postepay S.p.a.: Non-compliance with general data processing principles Italian Data Protection Authority (Garante) fined Postepay S.p.a. €5,877,000 on 2026-04-17 for: Non-compliance with general data processing principles. Italy · ·Art. 5, 6, 13 +4 Apr 17, 2026
€400,000 CAIXABANK, S.A.: Insufficient technical and organisational measures to ensure information security The Spanish Data Protection Authority (AEPD) fined Caixabank, S.A. €400,000 for failing to implement sufficient technical and organizational measures to ensure information… Spain · ·Art. 5, 25 Apr 15, 2026
€32M Intesa Sanpaolo S.p.A.: Insufficient technical and organisational measures to ensure information security Italian Data Protection Authority (Garante) fined Intesa Sanpaolo S.p.A. €31,800,000 on 2026-03-26 for: Insufficient technical and organisational measures to ensure information… Italy · ·Art. 5, 24, 32 +1 Mar 26, 2026
€4,000 ING Bank NV Amsterdam – Sucursala București S.A.: Insufficient technical and organisational measures to ensure information security Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) fined ING Bank NV Amsterdam – Sucursala București S.A. €4,000 on 2026-03-23 for: Insufficient… Romania · ·Art. 32 Mar 23, 2026
€15,000 Bressanelli Galli Gelpi Porta & C. S.r.l.: Insufficient legal basis for data processing Italian Data Protection Authority (Garante) fined Bressanelli Galli Gelpi Porta & C. S.r.l. €15,000 on 2026-02-12 for: Insufficient legal basis for data processing. Italy · ·Art. 5, 6, 7 +3 Feb 12, 2026
€10,000 GENPACT ROMANIA SRL: Insufficient technical and organisational measures to ensure information security The Romanian DPA has imposed a fine of EUR 10,000 on GENPACT ROMANIA SRL. The controller suffered a successful cyber attack due to insufficient technical and organisational… ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Feb 4, 2026
DSB · 2026-0.043.390 Following the first COVID-19 outbreak in March 2020, a limited liability company (the controller) decided to offer protective masks to the general public. It set up an online shop… 2026-0.043.390 ·Austria ·Art. 5, 12, 13 Jan 16, 2026
€8,000 KVIKU SPAIN, S.L.: Non-compliance with general data processing principles The Spanish DPA has imposed a fine of EUR 8,000 on KVIKU SPAIN, S.L.The controller requires customers to send a photo of themselves holding their ID card when verifying their… ·Art. 5 ·Non-compliance with general data processing principles Jan 10, 2026
€2,000 Money Seeds S.R.L.: Onvoldoende naleving van de rechten van betrokkenen. ⇄ The Romanian supervisory authority ANSPDCP has imposed a fine of 2,000 euros on Money Seeds S.R.L., a financial and consultancy company, for failing to honor a data subject's… ROMANIA · ·Art. 12, 13, 14 Jan 8, 2026
€2,000 Money Seeds S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on Money Seeds S.R.L. The controller failed to fulfil a data subject's request to exercise their rights. ROMANIA · ·Art. 12, 13, 14 Jan 8, 2026
€60,000 Debt collection agency (GESTIÓN DE COBROS, YO COBRO SL): Insufficient legal basis for the processing of personal data. ⇄ Boete van 60.000 euro - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN · ·Art. 5 Dec 30, 2025
€50,000 Social security institution: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 50.000 euro - van het Slowaakse databeschermingskantoor. SLOVAKIA · ·Art. 32 Dec 30, 2025
€3,140 UniCredit Bank Czech Republic and Slovakia, a.s.: Insufficient legal basis for data processing. ⇄ Boete van €3.140 - Tsjechische Autoriteit voor Gegevensbescherming (UOOU). ·Art. 6 ·Insufficient legal basis for data processing Dec 30, 2025
€60,000 Debt collecting agancy (GESTIÓN DE COBROS, YO COBRO SL): Insufficient legal basis for data processing After the claimant did alledgedly not pay back a microcredit to an online credit agany, the claim was assigned to the debt collecting agancy. Subsequently, the latter startet… SPAIN · ·Art. 5
€3,140 UniCredit Bank Czech Republic and Slovakia, a.s.: Insufficient legal basis for data processing The bank established a personal bank account for a data subject without his consent or knowledge. The bank supposedly had his personal data available because the subject had… ·Art. 6 ·Insufficient legal basis for data processing
€50,000 Social Insurance Agency: Insufficient technical and organisational measures to ensure information security Applications for social benefits from Slovak citizens were sent by post to foreign authorities. These were lost by post, with the result that the whereabouts of these personal… SLOVAKIA · ·Art. 32
€1,600 NAROBESA INV, S.L.: Insufficient cooperation with the supervisory authority. ⇄ 1.600 euro boete - Spaanse Autoriteit voor Gegevensbescherming (AEPD). SPAIN · ·Art. 58 Dec 29, 2025
€1,600 NAROBESA INV, S.L.: Insufficient cooperation with supervisory authority The Spanish DPA has imposed a fine of EUR 1,600 on NAROBESA INV, S.L. The controller failed to react to requests made by the DPA. The original fine of EUR 2,000 was reduced to EUR… SPAIN · ·Art. 58 Dec 29, 2025
€1.5M Bank: Non-compliance with general data processing principles Croatian Data Protection Authority (azop) fined Bank €1,500,000 on 2025-12-18 for: Non-compliance with general data processing principles. Croatia · ·Art. 5, 6, 13 +1 Dec 18, 2025
€6,000 Comune di Nave: Insufficient legal basis for data processing The Italian DPA has imposed a fine of EUR 6,000 on the Commune di Nave. The controller has installed an automatic licence plate recognition system which processes data on when a… ITALY · ·Art. 5, 6, 12 +2 Dec 18, 2025
€1.5M AMERICAN EXPRESS CARTE FRANCE: Insufficient legal basis for the processing of data. ⇄ 1.500.000 euro boete - Frans Nationaal Instituut voor Gegevensbescherming (CNIL). ·Art. 82 ·Insufficient legal basis for data processing Nov 27, 2025
€1.5M AMERICAN EXPRESS CARTE FRANCE: Insufficient legal basis for data processing The French DPA has imposed a fine of EUR 1,500,000 on AMERICAN EXPRESS CARTE FRANCE. The controller used excessive cookies on its website and failed to adequately inform data… ·Art. 82 ·Insufficient legal basis for data processing Nov 27, 2025
DSB · 2025-0.950.759 On 18 September 2023, a data subject created a customer account with a public limited company operating an online shop (the controller). It allowed customers to place orders… 2025-0.950.759 ·Austria ·Art. 5, 6, 16 +2 Nov 24, 2025
€865,000 Aktia Pankki Oyj: Insufficient technical and organisational measures to ensure information security The Finish DPA has imposed a fine of EUR 865,000 on Aktia Pankki Oyj. The controller changed its strong authentication process in such a way that it no longer guaranteed adequate… FINLAND · ·Art. 5, 25, 32 Oct 23, 2025
€865,000 Aktia Bank Plc: Insufficient technical and organizational measures to ensure information security. ⇄ 865.000 euro boete - Waarnemend ombudsman gegevensbescherming. FINLAND · ·Art. 5, 25, 32 Oct 23, 2025
€2,000 Agency for Control of Outstanding Debts S.R.L.: Insufficient fulfilment of data subjects rights The Romanian DPA has imposed a fine of EUR 2,000 on the Agency for Control of Outstanding Debts S.R.L. The controller failed to adequatly react to a data subjects request to… ROMANIA · ·Art. 12, 15 Oct 22, 2025
€2,000 Agency for Control of Outstanding Debts S.R.L.: Insufficient compliance with data subjects' rights. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 12, 15 Oct 22, 2025
€2.7M Experian Nederland B.V.: Insufficient legal basis for the processing of data. ⇄ 2.700.000 euro boete - Nederlandse Autoriteit Persoonsgegevens (AP). THE NETHERLANDS · ·Art. 5, 6, 12 +2 Oct 16, 2025
€2,000 PRIME TRANSACTION SA: Insufficient technical and organizational measures to ensure information security. ⇄ Een boete van 2.000 euro - van de Roemeense nationale toezichthoudende autoriteit voor de verwerking van persoonsgegevens (ANSPDCP). ROMANIA · ·Art. 32 Oct 16, 2025
€2.7M Experian Nederland B.V.: Insufficient legal basis for data processing The Dutch DPA has imposed a fine of EUR 2,700,000 on Experian Nederland B.V. The controller, a company that determines individuals' creditworthiness and sells this information,… THE NETHERLANDS · ·Art. 5, 6, 12 +2 Oct 16, 2025